Services · Managed

Website management services for estates that never stand still

A website is not a finished object. It is a running system with dependencies, third-party scripts, legal obligations and an expiry date on almost every part of it. We run that system so it does not become somebody's emergency.

200+ sites managedSince 2012UK · USA · EU · APAC
Quick answer

Website management services keep a live website or a whole estate patched, monitored, fast, accessible and legally current after launch. Green Arrow Consultancy has run this work for global consumer brands for over a decade, passing two hundred managed websites in 2022. It covers security, monitoring, consent currency, accessibility regression, content updates and estate governance.

The premise

Why estates decay quietly

Nothing dramatic happens to a neglected website. It does not fall over on a Tuesday. It gets one version behind, then four, then it is running a plugin whose author stopped answering issues in 2022. The certificate renews automatically until the year it does not. The consent banner keeps appearing, convincingly, while three tags fire before anyone clicks it. Nobody notices, because the failure mode of an unmanaged site is not an outage. It is a slow accumulation of risk that only becomes visible when a regulator, a penetration tester or a customer with a screen reader arrives.

That is why website management is bought late. There is no incident to point at until there is, and by then the remedial cost is several times what the maintenance would have been. The organisations that get this right are usually the ones that once had the bad quarter.

The second reason estates decay is arithmetic. A marketing team that can comfortably look after one site has no chance of looking after forty, because the work does not scale with traffic, it scales with the number of things that can expire. Domains, certificates, plugin versions, licences, policy documents, campaign pages, redirect maps, tag containers and regional privacy notices all have their own clocks, and none of them are synchronised.

We have been the party holding those clocks for over a decade. We took over more than thirty Energizer websites in 2014, passed fifty one sites in 2017, and passed two hundred managed websites in 2022 with roughly half of the client base in the USA. None of that is glamorous work. It is the reason the brands kept the phone number.

Scope

What estate management covers

Six areas. Five of them are invisible when they are done properly, which is the central commercial problem with selling this service and the central reason it gets cut.

Security and patching

Core, theme, plugin and dependency updates applied in staging with a tested restore point. Vulnerability feeds watched continuously. Since 2024 we have worked with the UpGuard security platform for external attack surface and vendor risk monitoring across managed estates.

Uptime and performance monitoring

Availability, certificate expiry, error rates and Core Web Vitals field data monitored constantly, with alerts routed to a person rather than to a mailbox. Performance is tracked against the budget the site was built to, so a regression is an alert rather than a discovery.

Consent, privacy and legal currency

The live tag inventory checked against the consent configuration and against the published cookie and privacy policies. Osano and OneTrust deployed and maintained. New markets mean new obligations, and the banner has to follow the jurisdiction rather than the headquarters.

Accessibility regression

New content and new templates re-tested against WCAG 2.2 AA. Most accessibility failures on a maintained site are not build defects, they are an uploaded PDF, an unlabelled campaign form or a carousel that arrived with a new agency's landing page.

Content and editorial work

Page builds, campaign landing pages, product updates, image optimisation and the small structural changes that keep a site matching the business rather than matching the org chart from three years ago.

Estate register and digital asset management

The list of what exists: sites, domains, registrars, hosting, platforms, plugin sets, certificates, owners and renewal dates. In 2019 we ran a digital asset mapping project for a Fortune 500 client across more than a hundred websites, which is the exercise most large organisations discover they need.

Rhythm

The monthly cycle

A predictable cycle is the point. Reactive maintenance is more expensive and it is always more expensive at the worst moment.

  1. 01

    Monitoring runs underneath everything

    Uptime, certificates, error rates, field performance data and vulnerability feeds do not wait for the cycle. They raise alerts. The cycle exists for the work that benefits from being deliberate, not for the work that has to be immediate.

  2. 02

    Patch in staging, promote on evidence

    Updates land in staging with a restore point already taken, then get a visual and functional regression check before promotion. Security releases jump the queue. Feature releases wait for the window.

  3. 03

    Check what has drifted

    Tag inventory against consent configuration, policies against what the site actually does, contact details, expired campaign pages, broken links, orphaned redirects and any form that has quietly stopped delivering to an inbox.

  4. 04

    Re-test what changed

    Accessibility checks on modified templates, performance against the original budget, and an end to end run of the forms and conversion paths that the business actually depends on.

  5. 05

    Do the requested work

    Content updates, new pages, campaign builds and small enhancements, tracked against the retainer so you can see what the hours went on rather than trusting that they went somewhere.

  6. 06

    Report, then re-plan

    What changed, what was found, what was deliberately deferred and why, plus the next quarter's scheduled work. A management report that only says everything is fine is not a report.

Cadence

What gets checked, and how often

This is the default schedule. Regulated clients and high-traffic commerce estates run tighter, and we will say so during scoping rather than after an incident.

CadenceWhat is checkedWhy it sits on that clock
ContinuousUptime, certificate expiry, error rates, Core Web Vitals field data, vulnerability and disclosure feeds, external attack surfaceThese fail without warning and the cost of the failure rises by the hour
WeeklySecurity patches, backup verification, form and checkout smoke tests, spam and comment moderation, new tag detectionFast enough to close a known vulnerability before it is widely exploited
MonthlyPlugin and dependency updates in staging, broken link and redirect sweep, consent configuration against live tag inventory, performance against budget, management reportSlow enough to regression test properly, frequent enough to stop debt compounding
QuarterlyAccessibility regression pass on changed templates, cookie and privacy policy reconciliation, user and access review, restore test from backupThese need a person, not a script, and they are the checks organisations skip first
AnnualEstate register reconciliation, domain and certificate renewal forecast, platform roadmap, vulnerability assessment, accessibility statement refreshOnce a year is the only sensible interval for asking whether each site should still exist

A restore that has never been tested is not a backup. It is a belief, and it is the single most common gap we find when auditing an inherited estate.

Findings

What an unmanaged estate looks like when you audit it

The pattern repeats with unnerving consistency. We are asked to look at an estate of, say, forty sites. The register we are handed lists thirty. Several of the missing ten are live campaign microsites still collecting personal data through a form that delivers to a mailbox nobody reads. One is a regional site a distributor built and pointed at the brand's domain. At least one is a staging environment left indexed by search engines.

Security findings are rarely exotic

It is almost never a novel exploit. It is an out of date content management system, an abandoned plugin with a published vulnerability, an administrator account belonging to an agency replaced years ago, a certificate expiring in eleven days, and file permissions loosened during a migration and never tightened. Every one of those is a scheduling failure rather than a technical one.

The legal findings are the ones that cost money

Consent drift is the most common serious finding. Tags firing before consent, categories that do not match what the scripts do, a banner with no reject option in a jurisdiction that requires one, a cookie policy listing vendors removed years ago while omitting three added last quarter. None of it is visible from the front page, and all of it is discoverable by a regulator in an afternoon. Our privacy practice came out of exactly this work.

Accessibility regressions arrive with content, not with code

A site can launch at WCAG 2.2 AA and fail within a year without a single line of code changing. Untagged PDFs uploaded by a product team, images published without alternative text, a video without captions, a campaign page built by another agency in a page builder that emits unusable markup. This is why accessibility belongs in the maintenance cycle rather than in a one-off audit.

And then there is the orphan problem

Every large estate contains sites no current employee asked for. They still resolve, still collect data, still carry the brand and still have an attack surface. Retiring them properly, with redirects and a data disposal record, is one of the highest value pieces of work in this service, and it never appears on anybody's roadmap.

Track record

Where this discipline came from

30+Energizer UK and EU websites taken over in 2014
51+Sites under management by 2017, after adding Asia Pacific
100+Websites mapped in a 2019 Fortune 500 digital asset project
200+Managed websites passed in 2022

Green Arrow Consulting has been a strategic partner in the development and maintenance of the Energizer International Digital platform, working with our regional offices in Asia, Middle East and Africa and Europe.

DavidSenior Brand Manager, Energizer Holdings
Service levels

Severity levels and response

Severity is defined by business impact, not by how loudly it was reported. That distinction is written into the agreement, which prevents the most common argument in managed services.

Severity 1: down, or actively exploited
The site is unavailable, checkout is failing, or there is a live security incident or data exposure. Acknowledged within an hour during working hours, worked continuously until contained, and followed by a written account of what happened and what changes as a result.
Severity 2: broken, with a workaround
A significant function is failing but the site is trading and a workaround exists: a form not delivering, a template broken in one browser, a payment method unavailable. Same working day response, resolution planned with you rather than assumed.
Severity 3: degraded or non-urgent defect
Something is wrong but nothing important is blocked: layout faults, a slow page, a broken link, an accessibility defect on a low-traffic template. Scheduled into the current cycle.
Severity 4: requests and scheduled work
Content updates, new pages, campaign builds, enhancements and anything with a date attached. Queued and delivered against the retainer, with the queue visible to you.
Out of hours
Severity 1 cover outside working hours is priced separately, because an honest out-of-hours commitment requires a rota rather than a hopeful clause in a contract. If your estate takes revenue at 3am, buy it. If it does not, do not.
Transition

Taking over from another supplier

Handover is the part where the honest condition of an estate becomes visible. We would rather find it in week one than inherit it silently.

Questions

Frequently asked questions

More on retainers, response times and ways of working in the full FAQ, or see the Energizer estate in detail.

What do website management services actually include?

Security patching and vulnerability monitoring, uptime and performance monitoring, backups with tested restores, dependency and plugin lifecycle management, content updates, accessibility regression checks, consent and privacy currency, redirect maintenance, and a report that says what changed. On an estate it also includes the register: what sites exist, what they run on, who owns them, and which ones nobody has admitted to owning yet.

How much do website management services cost?

A monthly retainer, priced on the number of sites, the platforms they run on, the response times you need and how much content work is included. A single well-built marketing site is inexpensive to keep current. An estate of forty sites on four platforms in nine languages is not, because the register, the release testing and the per-jurisdiction consent checks scale with the estate rather than the traffic.

What are your response times?

Severity based, and written into the agreement rather than implied. A site down or a live security incident is acknowledged within an hour in working hours and worked until it is contained. A broken function with a workaround gets a same working day response. Scheduled work runs on the agreed cycle. We would rather commit to targets we hit than publish a number we miss.

Do you only manage websites you built yourselves?

No. Most of the estates we run were built by other people, in some cases by several other people over a decade. Taking over an inherited site starts with an audit and a stabilisation phase, because you cannot sensibly commit to a response time on a codebase you have not read. After that it joins the normal cycle.

How do you update WordPress without breaking things?

Updates go to staging first, with a visual and functional regression check and a tested restore point before anything reaches production. Security releases move faster than feature releases. The larger discipline is the plugin register: every plugin is tracked for maintenance status, so an abandoned one is a scheduled replacement rather than a surprise.

Our cookie banner was set up years ago. Is that a problem?

Usually, yes. Consent configurations drift. Marketing adds a tag the banner does not categorise, a vendor changes what its script does, or the policy describes cookies that no longer exist while missing three that do. We check the live tag inventory against the consent configuration and the published policy, and we maintain Osano and OneTrust as part of the cycle.

Can you manage sites across several countries and languages?

Yes, and it is where most of our history sits. We took over more than thirty Energizer websites across the UK and Europe in 2014, ran multi-country campaigns in France, Germany, Italy and the UK in 2015, and added sixteen Asia Pacific sites in 2017 to reach fifty one or more. The hard parts of multi-region work are release coordination, local content ownership and consent by jurisdiction, not translation.

How does handover from our current supplier work?

In four stages: an inventory of what actually exists, credential and asset transfer, an audit producing a risk-ranked list, then a stabilisation period before the normal cycle begins. We do not need the outgoing supplier to be cooperative, although it helps. We do need registrar, DNS, hosting and repository access, and if any of those cannot be located that is itself the first finding.

What if we want to bring management back in-house later?

Then you take it, and we document it so you can. Everything is in your accounts and your repositories, the runbooks are written for somebody who is not us, and the register of sites, platforms, plugins, certificates and renewal dates is yours. A management contract that is hard to leave is a warning sign about the supplier, not about you.

Written and reviewed by the Green Arrow Consultancy team, led by Darren Tyler, founder and chief executive.

Green Arrow Consultancy Ltd, Cardiff, Wales. Company number 12491770. ICO registration ZA822868. Member of the International Association of Privacy Professionals. Last reviewed .

Ask us what is actually on your estate

Send us a list of your sites, or the list you think is complete. An audit will tell you what is running, what is exposed, what has drifted out of compliance and what should be retired.