Managed usually covers the server, its software, security patching, and backups of the account. It rarely covers your site's plugins, themes, custom code, or content, which stay yours.

The word does a lot of work

Managed sounds like somebody is looking after your website, which is what most people buying it believe they are getting.

What it usually means is that somebody is looking after the machine your website sits on.

Those are different, and the distance between them is where the unpleasant conversations happen: a site is broken, the host says the server is fine, and both statements are true.

Establishing where the line sits is a ten-minute conversation at signup and an expensive discovery during an incident.

What is usually included

That is a genuine service and worth paying for, particularly on anything beyond shared hosting, since keeping a server patched is real work that most small businesses cannot do.

What is usually not

The other half of the list, and the one that is rarely read.

Your website's own software: the platform, plugins, themes, and any updates to them.

Anything custom that was built for you, including scripts and integrations.

Your content, your configuration, and any settings inside the site rather than on the server.

Performance problems caused by how the site is built rather than by the server.

And email in many cases, which is frequently a separate product even where it sits on the same infrastructure.

All of that remains yours, or your supplier's, and a managed host will confirm the server is healthy and stop there.

The overlap that causes arguments

Some things sit on the boundary and are worth settling explicitly.

A site consuming enough resource to be throttled is a site problem with a server symptom, and the host's remedy is usually to sell you a larger plan.

A compromised site is your responsibility to clean and their responsibility to contain, and both parties frequently expect the other to lead.

A slow site can be either, and establishing which requires measurement that neither party is obviously responsible for.

Ask, at signup, who handles each of those three, since they are the incidents that actually occur.

A worked example

A business moved to managed hosting after an outage, believing they had bought somebody to look after the website.

Eight months later the site began returning errors after an automatic plugin update, and they raised a ticket.

The reply confirmed the server was operating normally, noted that plugin issues were outside the scope of the plan, and suggested contacting their developer.

That was accurate and matched what they had signed, which nobody had read closely.

They had no developer, having assumed the host filled that role, and the site was broken for four days while they found somebody.

They subsequently added a small monthly maintenance arrangement with a supplier, which is what they had believed managed hosting was.

The hosting had been fine throughout. The expectation had been wrong.

Fully managed platforms are different

Worth distinguishing, because the term covers two quite different products.

Platform-specific managed hosting, built around one system, frequently does handle updates to that platform, caching, and some application-level support.

That is closer to what people imagine, and it costs more, and it comes with constraints on what you can install and change.

General managed hosting on a standard server does not, regardless of the word.

The question that separates them is whether they update your platform and its plugins for you, and what happens when one of those updates breaks something.

Backups are the item to check hardest

Because everybody assumes they are covered and the details vary considerably.

Ask how often, how far back they go, whether the database is included, whether they are stored somewhere other than the same server, and whether restoring is self-service or a support request.

Then ask what a restore costs, since some hosts charge for it, and how long it takes.

A daily backup retained for seven days is a different product from a weekly one retained for a month, and neither is wrong until you need the one you do not have.

Keep your own regardless, since a backup held by the same company as the site is a single point of failure.

Get the line in writing

The practical action, and it is short.

Ask for a plain answer to five questions: who updates the platform, who fixes it when an update breaks the site, who cleans a compromise, what the backup arrangement is, and what falls outside the plan entirely.

Any competent host will answer those in a few sentences, and the answers frequently already exist in documentation.

Keep the reply, because it is what you will refer to during an incident and because the person who told you may not be there.

Where a host is evasive about the boundary, that is itself an answer.

The counter-case

Managed hosting is frequently worth its price and this is not an argument against it.

Server maintenance is genuinely specialised, patching matters, and an unmanaged server run by somebody who does not administer servers is a considerably worse arrangement than a managed one with a clear boundary.

There is also a version of this where a business becomes suspicious of the term and buys unmanaged hosting to save money, then has nobody applying security updates at all.

The problem is never that managed hosting does too little. It is that people buy it expecting website maintenance and do not arrange website maintenance.

Buy both, from whoever is appropriate for each, and know which is which.

Before signing

  1. Ask who updates the platform and its plugins.
  2. Ask who fixes it when an update breaks the site.
  3. Ask who cleans a compromised site.
  4. Ask the backup detail, including where they are stored.
  5. Ask what restoring costs and how long it takes.
  6. Get the answers in writing and keep them.
  7. Arrange site maintenance separately.

Step seven is the one that prevents the situation above, and it is a separate purchase from hosting however the plan is described.

Rehearsing a restore is covered in backups you have never restored.


Frequently asked questions

What does managed hosting cover?

Usually the server and its uptime, operating system patching, server software, network security, account backups, and certificates. That is genuine work and worth paying for.

What does it not cover?

Your platform, plugins, themes, custom code, content, configuration, performance caused by how the site is built, and frequently email. Those remain yours.

Why do arguments happen?

Because a site can be broken while the server is fine, and both statements are true. The gap between managing a machine and managing a website is where surprises live.

Which situations sit on the boundary?

A site consuming enough resource to be throttled, a compromised site, and a slow site. Ask who handles each of those three at signup, since they are what actually occur.

Are all managed plans the same?

No. Platform-specific managed hosting often does update your platform and plugins. General managed hosting on a standard server does not, regardless of the word.

What should I check hardest?

Backups: how often, how far back, whether the database is included, where they are stored, whether restoring is self-service, what it costs, and how long it takes.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Buying managed hosting?

Ask who fixes the site when an update breaks it. That one answer tells you what you are actually buying.

Start a Conversation