Website maintenance is one of the few things businesses buy without ever seeing the product. A monthly amount leaves the account, nothing visibly happens, and everyone assumes that means it is working. Sometimes it does. Often the retainer covers an automated backup that has never been tested and very little else.
- Maintenance is not one job. It is five distinct workstreams: security, backups, performance, content accuracy and functional testing.
- An untested backup is not a backup. The restore is the product, and most retainers have never proven one.
- The most valuable maintenance work is the part nobody automates: checking that the enquiry form still delivers.

There is a particular way websites fail that no retainer seems to catch. Nothing crashes. Nothing gets hacked. The site simply drifts: the enquiry form stops delivering to one address, a page acquires a broken link, the phone number in the footer is two numbers out of date, and nobody notices for seven months because nobody was looking.
Why this matters now
The reason maintenance is bought badly is that its value is entirely counterfactual. You are paying for things that do not happen. When maintenance is working, the outcome is an ordinary month, which is indistinguishable from the outcome when maintenance is not happening at all. That makes it nearly impossible to evaluate without a specification.
The result is a market where the average retainer has drifted toward the cheapest thing that can be described as maintenance. An automated backup that runs nightly and has never been restored. Plugin updates applied without testing, which is how a working site becomes a broken one. A monthly uptime report showing 99.9%, which tells you the server responded and nothing about whether the site worked.
The gap that matters is between technical availability and commercial function. A site can be perfectly available, fully patched, backed up nightly, scoring well on every automated check, and still be failing commercially because the enquiry form has been silently dropping submissions since a DNS change in March. No uptime monitor detects that. It is the single most expensive failure a website can have and it is invisible to every automated tool.
There is also a compounding cost to deferred maintenance that businesses consistently underestimate. Small problems left alone become structural. An unpatched component becomes a compromise. An unreviewed page becomes a legal exposure. A slowly degrading load time becomes a ranking problem. We covered the wider version of this in the real cost of a cheap website, and maintenance is where that cost usually lands.
None of this argues for spending more. It argues for knowing what you are buying, which is a different thing and frequently cheaper.
Common mistakes to avoid
The mistakes here are mostly about accepting a proxy for the real thing.
- Treating a backup as proven because it runs. A backup that has never been restored is a file of unknown quality. Restores fail for ordinary reasons: incomplete database dumps, missing uploads, an unnoticed permissions problem. The restore is the product and it needs testing at least annually.
- Accepting uptime monitoring as maintenance. Uptime tells you the server answered. It does not tell you the form delivered, the checkout completed, or the page rendered correctly. It is the cheapest thing to sell and the least informative thing to buy.
- Applying updates without a staging step. Automatic updates on a live site trade one risk for another. An update that breaks your layout on a Friday evening is worse than a patch applied on Monday after testing.
- Never testing the enquiry form. The highest-value check available and almost nobody schedules it. Forms break silently after DNS changes, hosting migrations, plugin updates and staff email changes.
- Assuming the developer who built it is maintaining it. A build contract and a maintenance contract are different things. Many businesses assume ongoing care they are not paying for and have not been promised.
There is a specific failure worth calling out because it is so common and so avoidable. When somebody leaves the business, their email address frequently remains on the enquiry form notification list, and sometimes it is the only address on it. Enquiries then arrive at an inbox nobody reads. Every maintenance schedule should include a check of who actually receives form notifications, and it takes thirty seconds.
The other frequent error is scope confusion. Maintenance keeps the site working. It does not mean unlimited content changes, new features, or design work. Many disputes between businesses and suppliers come from an unwritten assumption on one side and a different unwritten assumption on the other. Write down what is included, and what is charged separately.
Quick Strategic Tip
Send a test enquiry through your own website from an external email address right now, and check that it arrives at every address that should receive it. This single test catches the most expensive failure mode a website has, takes two minutes, and a surprising number of businesses discover something wrong the first time they run it.
Step-by-step plan
Build the schedule around five workstreams, on sensible frequencies. This is the specification, whether you do it yourself or hand it to a supplier.
- Weekly: functional checks. Submit a test enquiry and confirm delivery to every recipient. Check the phone number is correct and tappable. Confirm the site loads on a phone. Five minutes, and it covers the failures that cost real money.
- Weekly: security patching with a staging step. Apply security updates promptly, but apply them somewhere safe first and check the site still works. Prompt is more important than immediate, and tested is more important than fast.
- Monthly: backup restore verification. Not that the backup ran. That it restores. Restore to a staging environment, load the site, confirm the database and uploads are intact. Quarterly at absolute minimum, monthly if you take payments.
- Monthly: broken link and error scan. Internal and external links, 404s in your server logs, and errors reported in Search Console. Broken links accumulate silently and are trivially fixable once you can see them.
- Monthly: performance check. Field data from Search Console rather than a lab score. Watch for gradual degradation, which is the usual pattern as plugins and third-party scripts accumulate. Our piece on why your site feels slow even when it scores fast covers what to look at.
- Quarterly: content accuracy audit. Prices, staff names, opening hours, service areas, accreditations, the copyright year. Outdated information is both a credibility problem and, where prices or claims are involved, a potential legal one.
- Quarterly: access and notification review. Who has admin access, who receives form notifications, whose email addresses still work. Remove people who have left. This is the check that prevents the silently misrouted enquiry.
- Quarterly: third-party script audit. Every analytics tag, chat widget and pixel, with a named owner and a confirmed purpose. Delete anything nobody can account for. This is performance work and privacy work at the same time.
- Annually: full disaster recovery rehearsal. Restore the entire site to a clean environment from backups alone and time it. You are testing your recovery time, not just your files. Most businesses discover their real recovery time is considerably longer than they assumed.
- Annually: legal and compliance review. Privacy policy, cookie consent, accessibility conformance, terms. Regulations move, and a policy written in 2021 is unlikely to still be accurate.
The weekly items are the ones that matter most and cost least. If you do nothing else on this list, do the enquiry form test and the security patching, because between them they cover the two failure modes that actually destroy value.
If you are buying this rather than doing it, this list is your specification. Ask a prospective supplier which of these ten they perform, at what frequency, and what evidence you receive. The answers separate a genuine maintenance service from a monthly backup with an invoice attached.
Maintenance specification checklist
Hold your supplier, or yourself, to this.
- Test enquiry submitted and delivery confirmed, weekly.
- Security updates applied via staging, weekly.
- Backup restore verified, monthly or at minimum quarterly.
- Broken links and server errors scanned, monthly.
- Field performance data reviewed, monthly.
- Content accuracy audited, quarterly.
- Admin access and notification recipients reviewed, quarterly.
- Third-party scripts audited against named owners, quarterly.
- Full recovery rehearsed and timed, annually.
- Legal and compliance pages reviewed, annually.
- A written report is produced, listing what was done and what was found.
- Scope is written down, including what is charged separately.
How to measure impact
Maintenance is measured by absence, which makes it awkward. Measure the work and the readiness rather than the outcome.
Recovery time, actually measured. How long from total loss to a working site, demonstrated rather than estimated. This is the single most important number in your maintenance relationship and almost nobody knows theirs.
Time to patch. The gap between a security update being released and it being live on your site. Days is acceptable, weeks is not, and months is how sites get compromised.
Issues found per cycle. A maintenance report that never finds anything is a warning sign, not a good result. Real checks on a real site find small things constantly. Zero findings usually means nobody looked.
Form delivery success. Track your weekly test. One missed delivery caught early pays for a year of maintenance many times over.
Performance trend. Not a snapshot. Compare quarter on quarter, because the characteristic failure here is slow degradation rather than a sudden drop, and only a trend line reveals it.
Key terms in plain English
Staging environment: A private copy of your site where changes are tested before going live. The difference between a safe update and a risky one.
Restore verification: Actually rebuilding the site from a backup to prove the backup works. The part almost everybody skips.
Recovery time: How long it takes to get back to working after total failure. Should be measured, not estimated.
Uptime monitoring: Checking the server responds. Useful, and not a substitute for checking the site functions.
Patch window: The gap between a security fix being available and being applied. Every day in that gap is exposure.
Functional check: Confirming the things that make you money still work, particularly the enquiry form. The highest-value item on any maintenance schedule.
Conclusion and next move
Maintenance is bought on trust because its value is invisible, and that is precisely why it drifts toward the cheapest thing that can be invoiced. The fix is a specification. Once you can name the ten things that should be happening and how often, you can tell in one conversation whether you are buying maintenance or buying a backup script.
Do two things this week. Send a test enquiry from an external address and confirm it reaches everyone it should. Then ask your supplier, in writing, when a restore was last tested and how long it took. The answers to those two questions tell you almost everything about whether your website is actually being looked after.
What to do this week
Send a test enquiry from an external email address and confirm delivery to every recipient. Then ask your supplier in writing when a restore was last successfully tested.
What to do this quarter
Write down the maintenance specification, agree it with whoever performs the work, and get a written report each cycle listing what was checked and what was found. Rehearse a full recovery once.