Security updates and patches
Regular security updates and patches keep servers, CMS and packages current. Critical vulnerabilities are closed at short notice.
Risk of postponed updates
Many successful attacks exploit known vulnerabilities that were patched long ago, including in PHP, databases and application packages.
Scope
operating system and web server
PHP and database, with upgrades planned before support ends
CMS such as Statamic, frameworks such as Laravel, and shop systems
Composer and npm dependencies
container images where Docker is in use
Fixed maintenance windows
Regular updates are applied in fixed maintenance windows, after testing on staging and a fresh backup. Critical vulnerabilities are closed outside this schedule, as quickly as possible.
Automated checks report new vulnerabilities in the packages in use.
Approach
We first list all components and versions and flag outdated ones as risks. Major version upgrades are planned with you and estimated separately.
Every update is documented, so you can show insurers, data protection officers or auditors that your systems are maintained. The processes follow ISO 27001 without requiring certification.