Skip to content

Security updates and patches

Regular security updates and patches keep servers, CMS and packages current. Critical vulnerabilities are closed at short notice.

Risk of postponed updates

Many successful attacks exploit known vulnerabilities that were patched long ago, including in PHP, databases and application packages.

Scope

  • operating system and web server

  • PHP and database, with upgrades planned before support ends

  • CMS such as Statamic, frameworks such as Laravel, and shop systems

  • Composer and npm dependencies

  • container images where Docker is in use

Fixed maintenance windows

Regular updates are applied in fixed maintenance windows, after testing on staging and a fresh backup. Critical vulnerabilities are closed outside this schedule, as quickly as possible.

Automated checks report new vulnerabilities in the packages in use.

Approach

We first list all components and versions and flag outdated ones as risks. Major version upgrades are planned with you and estimated separately.

Every update is documented, so you can show insurers, data protection officers or auditors that your systems are maintained. The processes follow ISO 27001 without requiring certification.

Project enquiry

Back to top