Skip to content

Infrastructure

What managed hosting should actually include

“Managed hosting” can mean anything from a do-it-yourself dashboard to a team that answers at 3am. A plain-English checklist of what to expect, and what to ask your provider.

By Overslep · · 5 min read

Your hosting is where your website lives: the server, the computer that shows your site to the world. “Managed” hosting should mean someone looks after that server for you, but the word gets stretched a long way. For some providers it means a dashboard and a padlock certificate (your site's secure connection) that renews itself. For others it means a team that applies updates, keeps watch, takes backups and steps in when something breaks. Both are sold under the same label, so it is worth knowing what to ask for.

This is the checklist we use when we take over a website or online system, and the standard we hold our own hosting to. You don't need to be technical to use it. At the end there is a short list of questions you can put to any provider.

1. Updates on a schedule, with a safety net

Everything that runs your website needs updating. That includes the site itself: if it is built with WordPress, a widely used system for building websites, that means WordPress and every plugin (add-on) it uses. It also includes the layers of software on the server that you never see. Ask who applies each of these, how often, and what happens first. The right answer is a schedule, a backup taken just before, and a check afterwards that your site still works.

2. Backups you know will work

  • Copies are kept away from the server they protect, ideally with a different company.
  • They include both your files and your site's data, such as pages, orders and customer accounts, copied together so the two match.
  • Old copies are kept long enough to recover from a problem noticed late, such as a hacked plugin found weeks afterwards.
  • Restoring is tested: someone actually puts a copy back to check it works. A backup that has never been restored is a hope, not a plan.

3. A person warned when something goes wrong

As a minimum, there should be automatic checks, made from outside, that your site is online. There should also be warnings before the padlock certificate expires, before the server runs out of space, and when the site shows errors. For systems your business can't do without, add security monitoring on the server itself, which looks out for signs of a break-in. Then ask the question that matters: when a warning goes off, who receives it, and what do they do?

4. Knowing who can get into your server

Every person and every system that can get into your server should have its own named account and its own key. With shared passwords and a single master login, it is impossible to know who changed what, or to remove someone's access when they leave. Ask for a list of who can get into your server today.

5. Security built in, not bolted on

  • A firewall that keeps everything closed except what the public needs to reach.
  • Admin screens reachable only through safe, private access for your team, not open to the whole internet.
  • Sensible settings for the secure connection (the padlock), and for the security instructions your site gives to browsers.
  • A protective filter in front of public websites, to soak up abusive traffic before it reaches your server.
  • Each site and service kept separate, so if one is broken into, it cannot be used to read everything else.

6. Speed tuned to your kind of site

An online shop built with WooCommerce (the shop add-on for WordPress), a simple company website and a custom system each need a different setup to be fast. Take caching, which keeps ready-made copies of pages to show instantly. Set aggressively, it speeds up a simple website but can break the basket and customer accounts on a shop. Good managed hosting is set up for the software it actually runs, not with one template for everyone.

7. Email that lands in the inbox

If email goes out under your domain name (the part after the @ in your email address), from your team's mailboxes or from your website, your domain settings need a few email records. They must match the services actually sending it, and your provider will know them as SPF, DKIM and DMARC. Without them, your quotes and password reset emails end up in spam. This is often overlooked because it sits between the hosting, the email and the website, so check who is responsible for it.

8. Written instructions, and a way out

Ask for documentation: what is installed, how changes go live, where the backups go and how to restore them. Then ask how you would leave. Could you get a complete copy of your site, its data and your email, in standard formats another provider can use? A provider who makes leaving easy is usually confident you won't want to.

Questions to ask any hosting provider

  1. Who applies the updates, and when was the last one?
  2. When did you last restore one of my backups, and how long did it take?
  3. Who is warned if something stops working outside office hours?
  4. Who can get into my server right now?
  5. In which country is my data stored, and is there a data processing agreement (the contract that covers how you handle it)?
  6. If I leave, what do I get, and in what format?

You don't need the top plan to get good answers. What matters is that someone is clearly responsible for every point on this list. If you are not sure who looks after some of them today, it is worth finding out before something breaks. If you'd like us to check your current setup against the list, get in touch.

Managed hosting

Your website and business email hosted, updated, backed up and monitored, with one team to call.

Explore

Infrastructure

Servers, networks, backups and safe remote access, set up properly and kept running.

Explore

Have something to build, automate or fix? Let's talk.

A few lines are enough. We reply personally, usually with a couple of questions or a time to talk. No obligation, no automated sales sequence.