Back up first, update in small groups, test the pages that matter, and do it on a schedule rather than when something forces it. An unupdated site is a larger risk than an occasional broken layout.

Why businesses stop updating

Because it went wrong once.

An update broke the contact form, or changed the layout, or took the site down for an afternoon. Somebody spent a day fixing it.

The rational-seeming response is to stop updating, and it produces a site running versions with known security holes, which is a considerably larger risk.

The actual answer is not a choice between breaking things and being insecure. It is a process that makes updates routine and boring.

The risk of not updating

Worth being specific, because it feels abstract until it happens.

Security fixes are published along with a description of what they fix, which tells anybody interested exactly what to exploit on sites that have not updated.

Automated tools then scan for those versions. Nobody has to target you; they scan everything.

The outcome is usually not dramatic: injected links you cannot see, a redirect affecting some visitors, or your site quietly sending spam.

All of which damages your search visibility and your reputation long before anybody notices, and cleaning it up costs considerably more than an afternoon of updates would have.

The process that makes it safe

  1. Take a backup you have tested, immediately before.
  2. Update in small groups, not everything at once.
  3. Check the site after each group.
  4. Test the pages that matter, not just the homepage.
  5. Submit the contact form.
  6. Do it at a quiet time, not Friday afternoon.

The second is what makes recovery easy. If you update twenty things and something breaks, you have twenty suspects. Update four at a time and you have four.

The fifth is the one people skip and the one that breaks most often, because forms depend on several components at once.

A worked example

A business that had not updated its site in two years, after an update broke a booking system.

The site was eventually compromised through a known vulnerability in an outdated component, and began redirecting mobile visitors to somewhere else.

It took three weeks to notice, because the redirect only affected some devices and never the owner's.

Cleaning it, updating everything, and getting the site removed from a browser warning list took about a fortnight.

The update that had broken the booking system two years earlier would have taken an hour to resolve at the time.

They now update monthly, in groups, with a backup first, and have had two minor problems in a year, both fixed within twenty minutes.

Staging, and whether you need it

A copy of the site where changes can be tested before going live.

For a site that takes orders or bookings, it is worth having. Breaking a live shop for an hour costs real money.

For a brochure site with modest traffic, it is frequently more process than the risk justifies, and a good backup plus updating at a quiet time achieves most of the same protection.

Many hosts include a staging feature, which makes the question easier: if it is there, use it.

What matters more than staging is the backup, because staging prevents a problem and a backup fixes one.

The counter-case

Where updating immediately is wrong.

A major version change, as opposed to a security patch, which frequently introduces genuine incompatibilities. Waiting a few weeks lets other people find the problems.

Anything during a period you cannot afford disruption: a busy season, a campaign, the week before something important.

And any update to a component you know is fragile, which deserves testing rather than confidence.

Security patches are different. Those are worth applying promptly, because the window between publication of a fix and exploitation of the flaw is short.

Automatic updates

A reasonable default with one caution.

Most platforms can apply security updates automatically, which removes the remembering and closes the window quickly.

That is generally the right setting for security patches on a small business site, because the risk of an unattended update breaking something is lower than the risk of never updating.

The caution is that automatic updates should not extend to major versions, and that you need a backup arrangement that runs regardless, since an automatic update can break something while nobody is watching.

Check the site weekly if updates are automatic. That is a two-minute habit and it catches anything that went wrong unattended.

What to check after updating

A short list, always the same, which makes it quick.

The homepage and two service pages. The contact form, submitted properly. The phone number and its link. Anything interactive: a booking widget, a gallery, a shop basket.

And the site on a phone, since layout problems frequently appear only at narrow widths.

Five minutes, and it turns an update from something to worry about afterwards into something you have actively confirmed.

What to do about a site nobody maintains

The situation a lot of small businesses are actually in.

The site was built by somebody who has gone, nobody has logged in for years, and nobody knows whether it needs updating or how.

The first step is finding out what it runs on and whether anything is out of date, which somebody can tell you in an hour.

Then a decision: pay somebody a modest amount to bring it up to date and keep it there, or accept that it will eventually be compromised.

Those are the two options. Doing nothing is choosing the second while feeling like it has not been decided.

For a simple brochure site, an alternative worth considering is rebuilding it as something with nothing to update, which removes the problem permanently rather than managing it.

When something does break

The response that keeps it small.

Restore the backup if the problem is serious, rather than trying to diagnose a live site under pressure.

If it is cosmetic, note it and fix it properly rather than reverting everything.

And identify which update caused it, since that component may need attention or replacement rather than simply being avoided forever.

A component that breaks the site every time it updates is telling you something useful about whether it should still be part of the site at all.

What the backup behind all of this should look like is covered in backups nobody has tested.


Frequently asked questions

Why do businesses stop updating?

Because an update broke something once and cost a day. The response feels rational and produces a site with known security holes, which is a larger risk.

What is the risk of not updating?

Security fixes are published with descriptions of what they fix, and automated tools scan for unpatched versions. Nobody has to target you.

What does a safe process look like?

A tested backup first, updating in small groups, checking after each group, testing the pages that matter, submitting the form, and not doing it on a Friday.

Why update in small groups?

If you update twenty things and something breaks, you have twenty suspects. Four at a time gives you four.

Do I need a staging site?

Worth it for anything taking orders. For a brochure site, a good backup and a quiet time achieves most of the same protection.

Should updates be automatic?

For security patches, generally yes, with a backup that runs regardless and a weekly two-minute check that nothing broke unattended.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Stopped updating after something broke?

A backup, small groups and a five-minute check makes updates boring, which is the only sustainable version.

Start a Conversation