Security updates and patches
Regular security updates and patches keep servers, CMS and packages current. Critical vulnerabilities are closed at short notice.
Why postponed updates are a risk
Regular security updates close the known vulnerabilities behind many successful attacks on websites. Updates for these gaps have often been available for a long time. The operating system and CMS are not the only concern. PHP, the database and the many packages an application relies on need updates too. Postponing them means carrying a growing risk.
What is kept up to date
operating system and web server
PHP and database, including timely planning before end of support
CMS such as Statamic, frameworks such as Laravel, and shop systems
dependencies from Composer and npm
container images where Docker is in use
Versions at the end of their support are particularly critical, because they no longer receive security updates. Upgrades are therefore planned early, and you know the dates and effort in advance.
Fixed maintenance windows
Regular updates are applied in fixed maintenance windows. Beforehand, we test them on the staging environment and create a backup. Critical vulnerabilities are closed outside this schedule, as quickly as possible.
Automated checks report new vulnerabilities in the packages in use, so we hear about them before an attacker can exploit them.
Approach
First, we list all components in use and their versions. Outdated versions and those close to end of support are flagged as risks. Major version upgrades are planned with you and estimated separately.
Every update is documented. This lets you demonstrate to insurers, data protection officers or auditors that your systems are maintained. The processes follow ISO 27001 without requiring certification.