A website is not a finished object. It is a running system with dependencies, third-party scripts, legal obligations and an expiry date on almost every part of it. We run that system so it does not become somebody's emergency.
Website management services keep a live website or a whole estate patched, monitored, fast, accessible and legally current after launch. Green Arrow Consultancy has run this work for global consumer brands for over a decade, passing two hundred managed websites in 2022. It covers security, monitoring, consent currency, accessibility regression, content updates and estate governance.
Nothing dramatic happens to a neglected website. It does not fall over on a Tuesday. It gets one version behind, then four, then it is running a plugin whose author stopped answering issues in 2022. The certificate renews automatically until the year it does not. The consent banner keeps appearing, convincingly, while three tags fire before anyone clicks it. Nobody notices, because the failure mode of an unmanaged site is not an outage. It is a slow accumulation of risk that only becomes visible when a regulator, a penetration tester or a customer with a screen reader arrives.
That is why website management is bought late. There is no incident to point at until there is, and by then the remedial cost is several times what the maintenance would have been. The organisations that get this right are usually the ones that once had the bad quarter.
The second reason estates decay is arithmetic. A marketing team that can comfortably look after one site has no chance of looking after forty, because the work does not scale with traffic, it scales with the number of things that can expire. Domains, certificates, plugin versions, licences, policy documents, campaign pages, redirect maps, tag containers and regional privacy notices all have their own clocks, and none of them are synchronised.
We have been the party holding those clocks for over a decade. We took over more than thirty Energizer websites in 2014, passed fifty one sites in 2017, and passed two hundred managed websites in 2022 with roughly half of the client base in the USA. None of that is glamorous work. It is the reason the brands kept the phone number.
Six areas. Five of them are invisible when they are done properly, which is the central commercial problem with selling this service and the central reason it gets cut.
Core, theme, plugin and dependency updates applied in staging with a tested restore point. Vulnerability feeds watched continuously. Since 2024 we have worked with the UpGuard security platform for external attack surface and vendor risk monitoring across managed estates.
Availability, certificate expiry, error rates and Core Web Vitals field data monitored constantly, with alerts routed to a person rather than to a mailbox. Performance is tracked against the budget the site was built to, so a regression is an alert rather than a discovery.
The live tag inventory checked against the consent configuration and against the published cookie and privacy policies. Osano and OneTrust deployed and maintained. New markets mean new obligations, and the banner has to follow the jurisdiction rather than the headquarters.
New content and new templates re-tested against WCAG 2.2 AA. Most accessibility failures on a maintained site are not build defects, they are an uploaded PDF, an unlabelled campaign form or a carousel that arrived with a new agency's landing page.
Page builds, campaign landing pages, product updates, image optimisation and the small structural changes that keep a site matching the business rather than matching the org chart from three years ago.
The list of what exists: sites, domains, registrars, hosting, platforms, plugin sets, certificates, owners and renewal dates. In 2019 we ran a digital asset mapping project for a Fortune 500 client across more than a hundred websites, which is the exercise most large organisations discover they need.
A predictable cycle is the point. Reactive maintenance is more expensive and it is always more expensive at the worst moment.
Uptime, certificates, error rates, field performance data and vulnerability feeds do not wait for the cycle. They raise alerts. The cycle exists for the work that benefits from being deliberate, not for the work that has to be immediate.
Updates land in staging with a restore point already taken, then get a visual and functional regression check before promotion. Security releases jump the queue. Feature releases wait for the window.
Tag inventory against consent configuration, policies against what the site actually does, contact details, expired campaign pages, broken links, orphaned redirects and any form that has quietly stopped delivering to an inbox.
Accessibility checks on modified templates, performance against the original budget, and an end to end run of the forms and conversion paths that the business actually depends on.
Content updates, new pages, campaign builds and small enhancements, tracked against the retainer so you can see what the hours went on rather than trusting that they went somewhere.
What changed, what was found, what was deliberately deferred and why, plus the next quarter's scheduled work. A management report that only says everything is fine is not a report.
This is the default schedule. Regulated clients and high-traffic commerce estates run tighter, and we will say so during scoping rather than after an incident.
| Cadence | What is checked | Why it sits on that clock |
|---|---|---|
| Continuous | Uptime, certificate expiry, error rates, Core Web Vitals field data, vulnerability and disclosure feeds, external attack surface | These fail without warning and the cost of the failure rises by the hour |
| Weekly | Security patches, backup verification, form and checkout smoke tests, spam and comment moderation, new tag detection | Fast enough to close a known vulnerability before it is widely exploited |
| Monthly | Plugin and dependency updates in staging, broken link and redirect sweep, consent configuration against live tag inventory, performance against budget, management report | Slow enough to regression test properly, frequent enough to stop debt compounding |
| Quarterly | Accessibility regression pass on changed templates, cookie and privacy policy reconciliation, user and access review, restore test from backup | These need a person, not a script, and they are the checks organisations skip first |
| Annual | Estate register reconciliation, domain and certificate renewal forecast, platform roadmap, vulnerability assessment, accessibility statement refresh | Once a year is the only sensible interval for asking whether each site should still exist |
A restore that has never been tested is not a backup. It is a belief, and it is the single most common gap we find when auditing an inherited estate.
The pattern repeats with unnerving consistency. We are asked to look at an estate of, say, forty sites. The register we are handed lists thirty. Several of the missing ten are live campaign microsites still collecting personal data through a form that delivers to a mailbox nobody reads. One is a regional site a distributor built and pointed at the brand's domain. At least one is a staging environment left indexed by search engines.
It is almost never a novel exploit. It is an out of date content management system, an abandoned plugin with a published vulnerability, an administrator account belonging to an agency replaced years ago, a certificate expiring in eleven days, and file permissions loosened during a migration and never tightened. Every one of those is a scheduling failure rather than a technical one.
Consent drift is the most common serious finding. Tags firing before consent, categories that do not match what the scripts do, a banner with no reject option in a jurisdiction that requires one, a cookie policy listing vendors removed years ago while omitting three added last quarter. None of it is visible from the front page, and all of it is discoverable by a regulator in an afternoon. Our privacy practice came out of exactly this work.
A site can launch at WCAG 2.2 AA and fail within a year without a single line of code changing. Untagged PDFs uploaded by a product team, images published without alternative text, a video without captions, a campaign page built by another agency in a page builder that emits unusable markup. This is why accessibility belongs in the maintenance cycle rather than in a one-off audit.
Every large estate contains sites no current employee asked for. They still resolve, still collect data, still carry the brand and still have an attack surface. Retiring them properly, with redirects and a data disposal record, is one of the highest value pieces of work in this service, and it never appears on anybody's roadmap.
Green Arrow Consulting has been a strategic partner in the development and maintenance of the Energizer International Digital platform, working with our regional offices in Asia, Middle East and Africa and Europe.
Severity is defined by business impact, not by how loudly it was reported. That distinction is written into the agreement, which prevents the most common argument in managed services.
Handover is the part where the honest condition of an estate becomes visible. We would rather find it in week one than inherit it silently.
More on retainers, response times and ways of working in the full FAQ, or see the Energizer estate in detail.
Security patching and vulnerability monitoring, uptime and performance monitoring, backups with tested restores, dependency and plugin lifecycle management, content updates, accessibility regression checks, consent and privacy currency, redirect maintenance, and a report that says what changed. On an estate it also includes the register: what sites exist, what they run on, who owns them, and which ones nobody has admitted to owning yet.
A monthly retainer, priced on the number of sites, the platforms they run on, the response times you need and how much content work is included. A single well-built marketing site is inexpensive to keep current. An estate of forty sites on four platforms in nine languages is not, because the register, the release testing and the per-jurisdiction consent checks scale with the estate rather than the traffic.
Severity based, and written into the agreement rather than implied. A site down or a live security incident is acknowledged within an hour in working hours and worked until it is contained. A broken function with a workaround gets a same working day response. Scheduled work runs on the agreed cycle. We would rather commit to targets we hit than publish a number we miss.
No. Most of the estates we run were built by other people, in some cases by several other people over a decade. Taking over an inherited site starts with an audit and a stabilisation phase, because you cannot sensibly commit to a response time on a codebase you have not read. After that it joins the normal cycle.
Updates go to staging first, with a visual and functional regression check and a tested restore point before anything reaches production. Security releases move faster than feature releases. The larger discipline is the plugin register: every plugin is tracked for maintenance status, so an abandoned one is a scheduled replacement rather than a surprise.
Usually, yes. Consent configurations drift. Marketing adds a tag the banner does not categorise, a vendor changes what its script does, or the policy describes cookies that no longer exist while missing three that do. We check the live tag inventory against the consent configuration and the published policy, and we maintain Osano and OneTrust as part of the cycle.
Yes, and it is where most of our history sits. We took over more than thirty Energizer websites across the UK and Europe in 2014, ran multi-country campaigns in France, Germany, Italy and the UK in 2015, and added sixteen Asia Pacific sites in 2017 to reach fifty one or more. The hard parts of multi-region work are release coordination, local content ownership and consent by jurisdiction, not translation.
In four stages: an inventory of what actually exists, credential and asset transfer, an audit producing a risk-ranked list, then a stabilisation period before the normal cycle begins. We do not need the outgoing supplier to be cooperative, although it helps. We do need registrar, DNS, hosting and repository access, and if any of those cannot be located that is itself the first finding.
Then you take it, and we document it so you can. Everything is in your accounts and your repositories, the runbooks are written for somebody who is not us, and the register of sites, platforms, plugins, certificates and renewal dates is yours. A management contract that is hard to leave is a warning sign about the supplier, not about you.
Send us a list of your sites, or the list you think is complete. An audit will tell you what is running, what is exposed, what has drifted out of compliance and what should be retired.