Hosts are generally responsible for the server, the network, and their own infrastructure. The site, its software, its content, and usually its backups remain yours, and assuming otherwise is how sites are lost.

The split

Roughly, and it varies by provider and plan.

Theirs: the physical machine, the network, the operating system on managed plans, the control panel, and keeping the server reachable.

Yours: the site itself, whatever software it runs on, extensions and themes, the content, user accounts, and in most cases the backups.

The confusion arises because hosting is sold on uptime, which is the part they do handle, and businesses reasonably assume the rest comes with it.

It does not, and the gap is discovered during an incident.

Backups, which is the important one

The single most misunderstood item.

Many hosts take backups. Those backups exist for their benefit, meaning restoring after a server failure, and several qualifications usually apply.

They may be taken less frequently than you assume. They may be retained for a short period. Restoring may be chargeable. Restoring may replace everything rather than one file. And the backup lives on the same infrastructure as the site.

That last point is the one that matters. A backup on the same system is not protection against the system being compromised or the account being suspended.

Which means a business needs its own backup, held somewhere else, tested at least once. That is the difference between an incident and a loss.

Security, and where the line falls

Hosts secure the server. They do not secure your site.

An out-of-date content system, a vulnerable extension, a weak administrator password, or a theme from an unknown source are all yours, and they are how the overwhelming majority of small business sites are compromised.

Some hosts offer scanning or firewalls, frequently as paid additions, which help and do not transfer responsibility.

The practical consequence: if your site is compromised, the host will generally suspend it to protect their network and other customers, and cleaning it is your problem.

A suspension for a compromised site is a common experience and it arrives without warning, which is why the maintenance is worth doing rather than deferring.

Email deliverability

A specific gap worth knowing about.

A host provides mailboxes and the ability to send. Whether your mail reaches anybody depends on your domain's sender records, your sending behaviour, and the reputation of the shared infrastructure.

On shared hosting, other customers on the same address range affect that reputation, which is outside your control and is not something the host guarantees.

Which is a reason many businesses send through a dedicated mail service rather than through the web host, particularly for anything that matters such as form notifications and order confirmations.

What is in the agreement

Worth reading once, since the useful parts are specific.

That last one deserves attention. A card that expires while somebody is away can result in a suspended account, and the window before deletion is shorter than most people expect.

The resource limit problem

Specific to shared hosting and frequently unexplained.

Shared plans advertise generous storage and transfer, and the limits that actually bind are processing and memory, which are rarely stated prominently.

A site exceeding them may be throttled or suspended, and the response from the host is generally an upgrade rather than a diagnosis.

Which is worth knowing because the cause is frequently something fixable, such as an inefficient extension or unoptimised images, rather than genuine growth requiring a larger plan.

Filling the gap

What a business needs to arrange itself.

  1. An independent backup, stored elsewhere and tested.
  2. A maintenance routine for updates, with a way to reverse them.
  3. Monitoring, so you know the site is down before a customer tells you.
  4. Certificate expiry monitoring, which is separate from uptime monitoring.
  5. Mail sent through a proper service rather than the web server.
  6. Someone responsible for each of the above, named.

Most small businesses have none of these arranged, and the reason is reasonable: nobody told them the host was not doing it.

The last item is what makes the rest happen, and the question of who answers when something breaks is the same one that should have decided the host in the first place, as covered in judging a host by its support.


Frequently asked questions

What is the host responsible for?

The physical machine, the network, the operating system on managed plans, the control panel, and keeping the server reachable.

Are the host's backups enough?

Usually not. They may be infrequent, briefly retained, chargeable to restore, all-or-nothing, and they live on the same infrastructure as the site.

Who is responsible if my site is hacked?

You. Out-of-date software, vulnerable extensions, and weak passwords are yours, and the host will generally suspend the site to protect their network.

Why does email deliverability matter here?

A host provides mailboxes but does not guarantee delivery, and on shared hosting other customers affect the sending reputation, which is outside your control.

What binds on shared hosting?

Processing and memory rather than the advertised storage and transfer. Exceeding them brings throttling and an upgrade offer rather than a diagnosis.

What should I arrange myself?

An independent tested backup, a maintenance routine, uptime and certificate monitoring, mail through a proper service, and somebody named as responsible.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Assuming your host backs everything up?

We check what their backups actually cover and set up the independent copy, which is the difference between an incident and a loss.

Start a Conversation