Skip to content

Security updates and patches

Regular security updates and patches keep servers, CMS and packages current. Critical vulnerabilities are closed at short notice.

Why postponed updates are a risk

Regular security updates close the known vulnerabilities behind many successful attacks on websites. Updates for these gaps have often been available for a long time. The operating system and CMS are not the only concern. PHP, the database and the many packages an application relies on need updates too. Postponing them means carrying a growing risk.

What is kept up to date

  • operating system and web server

  • PHP and database, including timely planning before end of support

  • CMS such as Statamic, frameworks such as Laravel, and shop systems

  • dependencies from Composer and npm

  • container images where Docker is in use

Versions at the end of their support are particularly critical, because they no longer receive security updates. Upgrades are therefore planned early, and you know the dates and effort in advance.

Fixed maintenance windows

Regular updates are applied in fixed maintenance windows. Beforehand, we test them on the staging environment and create a backup. Critical vulnerabilities are closed outside this schedule, as quickly as possible.

Automated checks report new vulnerabilities in the packages in use, so we hear about them before an attacker can exploit them.

Approach

First, we list all components in use and their versions. Outdated versions and those close to end of support are flagged as risks. Major version upgrades are planned with you and estimated separately.

Every update is documented. This lets you demonstrate to insurers, data protection officers or auditors that your systems are maintained. The processes follow ISO 27001 without requiring certification.

Project enquiry

Back to top