It’s launch day. Everyone applauds, says “job well done,” and secretly hopes they won’t have to think about “the website thing” again anytime soon.
For us, a website is finished when it works well for users and clients. At that point, it has been thoroughly tested across the operating systems, devices, and browsers that matter. It has passed our privacy and accessibility audits. And the editorial team can manage the site independently, without needing support for day-to-day tasks.
The catch? That state rarely lasts forever.
Here are some of the reasons why – and why it pays to plan ahead and choose the right maintenance setup.
Security updates
Regular CMS and plugin updates are essential for fixing bugs and closing security vulnerabilities. Most CMS platforms separate updates into minor and major releases. Major releases often introduce structural changes – such as modified field types in the backend – which can require more substantial adjustments.
In some cases, a new major release also marks the end of security support for older CMS versions, as is common with WordPress. Other platforms, such as TYPO3, Craft, or Kirby, continue supporting one or more previous versions for a longer period.
Security updates are non-negotiable. We handle them proactively as part of our core maintenance services because known vulnerabilities remain one of the biggest security risks for websites.
Changing technical requirements
A website depends on a surprisingly large ecosystem of technology working together: server infrastructure and its software stack, third-party services such as newsletters, ticketing systems, or analytics tools, as well as the operating systems and browsers used by the people visiting the site.
Changes happen regularly – especially with third-party services and their APIs, but also with browser requirements and web standards.
The result is often the classic “bug”: something no longer works correctly or suddenly looks strange. In most cases, these issues can be resolved quickly through routine support requests.
Where appropriate, automated testing can continuously monitor key website functions and trigger alerts whenever something breaks.
New organizational or legal requirements
Changes in legislation around privacy, accessibility, personality rights, or advertising disclosure can directly affect website operators.
This includes regulations such as the GDPR and related federal and state laws, as well as the lesser-known Telecommunications Digital Services Data Protection Act (TDDDG), which governs the storage of data – such as cookies – on users’ devices. The podcast “Rechtsbelehrung” with legal expert Dr. Nina Herbort provides a good overview (German only).
Accessibility has also become a major focus in recent years. In Germany, the Accessibility Strengthening Act (BFSG) has significantly increased awareness (and has fundamentally changed the way we approach website projects).
Internal organizational changes can also have an impact. Pursuing certifications – such as ISO 27001, which is based on the IT security standards developed by Germany’s Federal Office for Information Security (BSI) – may require adjustments to forms, login systems, or security processes.
The good news is that legislative changes usually come with long lead times. We keep an eye on upcoming developments so that clients can prepare early – for example, the ongoing evolution of accessibility standards under WCAG 3.0 or the EU’s currently discussed “Digital Omnibus” initiative.
Because these requirements are often legally binding, websites eventually need to be adapted – even when implementation is technically demanding. Planning ahead helps. Major legal or compliance updates are often best addressed as part of a website relaunch or a CMS major-version upgrade.
Training and support
Whenever new colleagues join the team – or a feature hasn’t been used in a while – questions tend to come up (“where was that permissions checkbox again …”)
For tools with a broader user base, support is practically unavoidable. Good training videos and internal FAQs can significantly reduce support effort, especially for projects that evolve gradually over time. Some seemingly simple questions are often valuable. They can reveal usability issues that are easy to solve with small interface improvements. And let’s be honest: people enjoy using a product more when they can get a quick, competent answer when they need one.
Continuous improvement
Usage data, user feedback, and new business requirements often reveal opportunities to improve a website.
Smaller feature requests can often be implemented as part of ongoing maintenance. Larger enhancements are typically grouped together and delivered as a dedicated sprint or project.
...And what happens if my website gets hacked? 👻
For businesses and public institutions alike, this is now a very real concern. At the same time, budgets for highly sophisticated security solutions are often limited.
A useful point of reference is the IT Grundschutz (a baseline protection framework) published by Germany’s Federal Office for Information Security (BSI).
Many effective measures are surprisingly straightforward: Regular security updates, strong authentication, clearly defined user roles and permissions as well as secure password policies and proper protection for forms and file uploads.
In general, data-minimization principles can also reduce the impact of a successful attack. For example, booking processes or payment transactions can be handled by dedicated systems rather than the website infrastructure itself. Hosting providers also play an important role. They are responsible for tasks such as database and file backups, monitoring suspicious activity, and managing large-scale traffic from AI crawlers or botnets.
Many managed hosting solutions already include strong baseline protection and active support in these areas.
No website can ever be made 100% hack-proof. But a combination of sensible technical and organizational measures can significantly reduce both the likelihood of an incident and its consequences. We're always happy to help with the setup.
Questions? Get in touch: info@diebrueder.com