Who Is Actually Responsible for Your Website Security?

Many businesses believe their website security is already being handled by someone else. The hosting provider runs the server, the original agency built the website and WordPress offers automatic updates. From the owner’s perspective, it may seem reasonable to assume that critical issues will be resolved automatically.

Who Is Actually Responsible for Your Website Security?

In practice, responsibility is often unclear. The hosting provider may secure the infrastructure without maintaining the application. The original agency may no longer have an active agreement. Automatic updates may have been disabled to avoid compatibility problems. Each party may assume that another party is responsible, while nobody is actively checking the site. 

What the Hosting Provider Actually Protects

A hosting provider typically maintains the technical environment where the website runs. This may include servers, storage, backups, connectivity and some infrastructure-level security controls.

The WordPress installation itself is a separate layer. Its core software, themes, plugins, custom code and administrator accounts are usually controlled by the customer or by a maintenance provider acting on the customer’s behalf.

A hosting company may introduce firewall rules to block a known attack method, but this does not make the website fully secure. Attackers can modify their methods, and temporary rules may not cover every way the vulnerability can be exploited. Hosting-level protection is valuable, but it does not replace application maintenance.

What Happens After the Original Agency Leaves?

Many SME websites are delivered as one-time projects. The agency builds the site, provides a limited support period and then the relationship gradually ends. The site may continue running for years with the same plugins, themes and user accounts.

Over time, the situation becomes less clear. The employee who ordered the website may leave the company. The original project contact may no longer work at the agency. Security notifications may be sent to an old email address. Nobody may know whether automatic updates are enabled or whether backups can be restored.

Because the site still appears to work, this lack of ownership can remain hidden until a serious vulnerability, failed update or security incident forces the issue.

Every Website Needs a Named Security Owner

Every public website should have a clearly identified person or provider responsible for its maintenance and security. Someone must know who installs updates, who investigates failed updates, who reviews unusual activity and who responds when a serious vulnerability is announced.

These responsibilities should not be assumed based on a hosting invoice or an old development contract. They should be confirmed directly and documented.

A useful starting question is - “Who is currently responsible for maintaining and security-testing this website?”. If the answer is vague, the organization probably has a gap.

Outsourcing Security Does Not Remove Accountability

A company does not need to manage WordPress internally. The technical work can be outsourced to an agency, hosting partner or specialist maintenance provider. What cannot be outsourced completely is accountability.

The business still needs a way to verify that maintenance is actually happening and that serious risks are being addressed. Grawlr can support this by providing an independent external view of the website’s attack surface through regular automated security testing.

This changes the conversation from “we think everything is updated” to “the website was tested, these weaknesses were identified and these actions were completed.”

Website security can be delegated, but responsibility cannot disappear. If nobody can clearly explain who maintains the site and how its security is verified, the company should treat that uncertainty as a risk in itself.

← Zurück zum Blog