Website assurance

Maintenance that keeps risk visible.

A website needs the same operational discipline as every other business-critical system: a clear owner, a patch cycle, continuous oversight and an audit trail. Choose the level of assurance that fits your site, sector and risk.

Why retained maintenance matters

A standing operational load. Not an annual task.

The exposure sits in the stack around the site. Retained maintenance turns published fixes into applied ones — and security claims into evidence.

96%

of WordPress vulnerabilities disclosed in 2024 were found in plugins.

65%

had a fix available. A fix that is never applied protects nobody.

2,213

new WordPress vulnerabilities were published in Q4 2025 alone.

48%

of UK businesses use an external cyber-security provider.

Sources: Wordfence 2024 Annual WordPress Security Report; Wordfence Q4 2025 Threat Intelligence Report; UK Cyber Security Breaches Survey 2025/26.

The tiers

Choose the level that matches the risk.

Essential

£150 +VAT / mo
For lower-risk, lower-change sites that still need to stay up and patched.
Security patching & updates
Uptime monitoring
Annual review

Managed

£250 +VAT / mo
For regulated, public-facing sites where change and visibility matter.
Everything in Essential
Continuous security monitoring
Monthly plain-English reporting
Change & access tracking
Quarterly review

Assured

£500 +VAT / mo
For high-assurance defence and supply-chain contexts.
Everything in Managed
Supply-chain vetting
Scheduled security reviews
Priority technical support
Monthly review

Custom

Bespoke
For complex estates, multi-site programmes and non-standard requirements.
Everything in Assured
Multiple sites & environments
Custom SLAs & integrations
Dedicated technical contact
Tailored governance & reporting
Not sure which?

Match the plan to the risk.

Tell us about the site, its operating context and the assurance you need. We will recommend the right plan — or define a bespoke service.