top of page
Editorial illustration of a Belgian SME website monitored through a maintenance dashboard.

A website is not a deliverable you file away on the day it goes live. It is an installation permanently connected to the outside world: hosting, a certificate, modules, browsers that change every month. Without upkeep, a site almost never breaks down all at once. It degrades bit by bit, and you find out the day a client tells you they never got a reply to their message.

The pace has picked up. According to Patchstack, which tracks flaws in the WordPress ecosystem, 11,334 new vulnerabilities were published there in 2025, 42 % more than in 2024, with 91 % of them in third-party extensions. The Centre for Cybersecurity Belgium, for its part, recorded 556 cyber incidents in 2025, 58 % more than the previous year, and notes that the average delay between the disclosure of a flaw and its first active exploitation has fallen to five days, with a third exploited within 24 hours.

For an SME or a self-employed professional, the issue is not the fear of a spectacular hack. It is more mundane: a form that no longer delivers, a page that takes eight seconds to load on a phone, an expired certificate that shows your prospects a red warning. None of these incidents announce themselves. All of them can be spotted in a few minutes a month when someone is looking after the site.

A site almost never breaks down all at once: it degrades in small steps that nobody is watching.

What degrades when nobody is watching

Flaws move faster than calendars

The most telling figure in the 2025 report from the Centre for Cybersecurity Belgium is not the number of incidents, it is the speed: five days on average between the disclosure of a flaw and its first real exploitation. An update postponed to next month is therefore no longer a small administrative delay, it is an open window.

A second point often overlooked: according to Patchstack, 46 % of the vulnerabilities published in 2025 still had no patch available at the time of disclosure. In other words, applying updates is not always enough. You also need to know which modules are installed on your site, which ones are no longer maintained by their author, and which can be replaced or simply removed. An unused module left in place is still a door.

Certificates need renewing more and more often

This is the most concrete change of the coming years, and almost nobody outside technical teams talks about it. In April 2025, the CA/Browser Forum, the body that brings together browsers and certificate authorities, voted to progressively shorten the lifetime of TLS certificates (the familiar padlock). The schedule is set: a maximum of 200 days since 15 March 2026, 100 days in March 2027 and 47 days in March 2029.

Editorial illustration of a technical monitoring calendar with a certificate renewal countdown.

The practical consequence is simple: renewing manually once a year becomes impossible to sustain. Renewal has to be automated and monitored, otherwise your visitors will sooner or later see a warning screen instead of your home page. We explained why that padlock also weighs on your search visibility in our article on HTTPS and visitor trust.

Speed erodes without warning

A site that is fast on delivery day does not stay that way. You add uncompressed photos, a tracking script, a banner, a review widget, and the page grows heavier month after month. Measurements from the Web Almanac (HTTP Archive), published in January 2026 based on July 2025 field data, show that only 48 % of sites score green on all three Core Web Vitals in mobile browsing. That is one site in two delivering an experience Google considers insufficient, most of the time without the owner knowing. The topic is covered in detail in our article on loading speed and its commercial effects.

The six checkpoints of a living site

Useful maintenance comes down to six checks. They do not require a permanent technical team, but they do require a routine.

  1. Updates: core, modules, theme, hosting. Monthly at the very least, immediately when a critical flaw is announced.

  2. Backups: automatic, stored off-site (not on the same server as the site) and above all tested. A backup you have never restored is an assumption, not a safety net.

  3. The certificate and the domain name: automatic renewal enabled, an alert at least 30 days before expiry, billing details kept up to date.

  4. Forms: send a real test once a month, from a device outside the company, and check that the message lands in the inbox and not in the spam folder.

  5. Speed and errors: a quarterly reading of the Core Web Vitals and of 404 pages, especially after adding content or changing visuals.

  6. Compliance: a working cookie banner, legal notices and terms kept current, accurate contact details and company number.

Editorial illustration of a website maintenance checklist with backups and speed indicators.

What it costs, and what it prevents

In Belgium, maintenance of an SME brochure site is usually contracted as a modest monthly retainer: updates, backups, uptime monitoring and a small pool of hours for routine changes. The price varies with the number of pages, the presence of a shop and the expected responsiveness, but the order of magnitude bears no comparison with the cost of putting a neglected site back in shape.

Because the real cost of a neglected site rarely shows up on a technical invoice. It shows up in enquiries that never arrive, in rankings you spent a year earning and then lost, in visitors who close a tab that is too slow. Nothing turns red in your accounts: the revenue line simply drops a notch.

For a simple, stable site, a planned quarterly review with a written checklist and a short report does the job perfectly well. Less responsive than a retainer, but infinitely better than waiting for something to break. If your site has gone several years without attention, the question is no longer upkeep but a full rebuild, and our redesign checklist for keeping your search rankings helps you avoid the classic mistakes.

The real cost of a neglected site does not show up on a technical invoice, but in enquiries that never arrive.

Frequently asked questions

Do I really need a maintenance contract for a simple brochure site?

A contract is not mandatory, a routine is. If nobody in the company knows where the hosting sits, who renews the domain and when the last backup was tested, then a retainer is the simplest way to avoid an unpleasant surprise. An SME with someone technically comfortable can perfectly well keep the checklist in house.

How often should a website be updated?

A monthly pass over updates covers most cases, with immediate action as soon as a critical flaw is announced in a component you use. Given the five-day average between disclosure and exploitation recorded by the Centre for Cybersecurity Belgium, waiting for the next quarter is a pointless gamble.

Who is responsible if my site gets hacked?

That depends on what your contract says, which is precisely why you should read it before the incident. Host, provider and site owner do not carry the same obligations. Check in writing who applies the updates, who holds the backups and within what timeframe a restore is guaranteed. If you are unsure about the legal or insurance implications, have the contract reviewed by your usual adviser.

How do I know whether my site is still healthy?

Three five-minute checks, no technical skills needed: open your site on a phone over 4G and time it, send a message through your own contact form, and check the expiry date of your domain name. If one of the three is off, the rest deserves an audit.

Editorial illustration of a website maintenance action plan with numbered steps.

Priority action plan

  1. Take inventory: host, domain registrar, administrator access, installed modules. Write it in a document at least two people can open.

  2. Secure the backups: enable a daily, automatic, off-site backup, then test a restore once. Once is enough to know whether it works.

  3. Automate the certificate: check that renewal is automatic and set an alert at 30 days, because the 200-day then 100-day schedule will not forgive an oversight.

  4. Test your forms this month, from an outside address, and put a recurring reminder in your calendar.

  5. Schedule the routine: a fixed date each month for updates, one each quarter for speed and errors. What is not scheduled does not happen.

A well-maintained site goes unnoticed, and that is exactly the point. It loads fast, it delivers its messages, it holds its rankings, and it lets you think about your business rather than your server. The companies that win over the long run are not the ones rebuilding their site every two years, they are the ones that never had to do it in a hurry.


Is your site ageing and you are not sure where to start? We audit and maintain websites for Belgian SMEs, from website design and build to monthly upkeep.

Website

April 25, 2026

8 min read

Website maintenance for an SME: what quietly degrades when nobody looks after it.

Editorial illustration of a Google Ads dashboard where a target cost per acquisition slider moves up towards its target value.

Advertising

8/8/26

5 min read

Google Ads changes its rules on 17 August 2026: what budget limited campaigns stand to lose.

Editorial illustration of an interface flagging content generated by artificial intelligence, symbolising the AI Act transparency obligations.

Automation

8/1/26

9 min read

AI Act: what the 2 August 2026 transparency obligation changes for a Belgian SME using AI.

Editorial illustration of a contact form on a web page, with a message ready to send.

Website

7/25/26

6 min read

Your website's contact form: why it loses you requests, and how to fix it.

You might also like these articles

bottom of page