The Website Ownership Gap: Responsibility Without Understanding
A website can look perfectly healthy while something is going badly wrong underneath it.
It can load quickly. The design can look professional. WordPress can show only a handful of recently released updates awaiting review. Customers can browse, complete forms and place orders. The business owner can use the site every day and reasonably believe that everything is being looked after.
But who is actually looking after its technical health?
Who is responsible for the software, security, hosting environment, access controls, monitoring and recovery of the complete system? I am not talking about clicking to update WordPress plugins.
If you do not know who is doing that, chances are nobody is.
That is the website ownership gap.
Business owners carry enormous responsibility for their websites and the information entrusted to them, but the website industry has done a dreadful job of helping them identify, understand and fulfil it.
So, let us try to address some of that gap in this article.
If your website were a car
Before a new car reaches the road, it goes through extensive testing. Manufacturers test the brakes, steering, body structure, safety systems and mechanical components. There are crash tests, stress tests and quality-control checks.
They also inspect the finish. The paintwork matters. The doors need to line up and the interior should look as intended. But nobody would suggest that attractive bodywork proves the vehicle is safe.
Website quality control can look similar, up to a point.
Before launch, a website may be checked to make sure it matches the approved design, displays correctly on a phone, contains the right wording and allows somebody to submit a form or complete a purchase.
Those launch checks matter, but they mainly establish whether the website looks good and functions as intended on the day it goes live. They do not establish how it will remain safe tomorrow.
Once a car leaves the forecourt, we understand that it will require servicing, repairs and, in time, regular MOTs. Tyres wear out, brakes need attention and faults can develop even when the car still starts and looks fine. We do not expect it to remain roadworthy forever simply because it was safe when we bought it.
The same principle applies to a website. It operates in a constantly changing environment. New vulnerabilities are discovered. Software support ends. Plugins and themes are updated or abandoned. PHP versions reach the end of their supported life. Hosting environments change. New services are connected. User accounts accumulate. The methods used by criminals evolve rapidly.
But there is no equivalent mandatory technical check for a website. No routine point at which every business must establish that its website is running supported software, its security is being monitored, its essential functions work, its backups can be restored and somebody is responsible for responding when something goes wrong.
The changes happening beneath the surface do not necessarily create an obvious warning light for the owner. A website can continue looking and behaving exactly as it did yesterday while its technical condition deteriorates or something harmful remains hidden.
We inherited a website that had been compromised more than a year earlier, and its owner had no idea. It had continued loading, functioning and looking exactly the same, giving no clear outward indication that anything was wrong. For more than a year, the owner had no visible reason to suspect that malicious code was present, but it was and the consequences were not pleasant for anyone.
A website that loads is not necessarily healthy, just as a car that starts is not necessarily safe to drive.
Protecting more than the owner
An MOT is not only intended to protect the vehicle owner. An unsafe vehicle can endanger passengers, pedestrians and other road users.
An unsafe website can also affect more than the business that owns it. It may place customers, employees, contractors and members of the public at risk. It can affect connected systems and, depending on the hosting arrangement, potentially other websites sharing the same environment.
We have encountered malicious code that displayed a convincing message urging website visitors to open PowerShell on their computers. Had somebody followed the instructions, they could have allowed malicious commands or software to run on their own device. Fortunately, the problem was detected very quickly, but it demonstrates why website security is not only about protecting the website owner. Other less monitored sites may have caused these malicious files to transfer to a user’s device and from there? Well who knows, but nothing good.
Websites are not unregulated. Businesses already have responsibilities relating to personal information, payment security and consumer protection. They are expected to take appropriate steps to protect the information entrusted to them. Yet the extent of those responsibilities, and the support available when things go wrong, often becomes apparent only after an incident.
Cybercrime officers, the Information Commissioner’s Office, payment providers, hosting companies, legal advisers and technical specialists may then become involved. Their support matters, but by that point harm may already have occurred. It cannot replace the understanding the business owner needed beforehand.
Even active monitoring, regular reviews and properly managed security cannot guarantee that an attacker will never get in. Security reduces risk and improves the chance of detecting and containing a problem. It does not create invulnerability. If a well-maintained website can still be targeted, imagine the exposure of an important business asset that nobody is actively looking after.
The owner carries responsibility but may never have been shown how to recognise the risks, assess the condition of the website or establish whether somebody is looking after it properly.
Where is the accessible support that helps an ordinary business owner understand and manage these risks before an incident occurs?
Guidance exists, but it is fragmented, technical and rarely presented in a way that helps an owner understand what looking after a website should involve. Instead, they are left trying to make sense of services whose names do not reliably describe the work being done.
Website maintenance can mean almost anything
Part of the problem is the language used by our industry.
“Website maintenance” and “website management” are used to describe fundamentally different services, from content updates to responsibility for the complete technical environment.
A business owner hears that their website is being maintained and reasonably assumes the whole vehicle is being kept roadworthy. The provider may be delivering exactly what was agreed while substantial responsibilities sit outside that agreement.
Neither party has necessarily done anything wrong. But if the owner does not know what is included, what is excluded and who looks after the rest, the agreement can leave a gaping hole.
The ambiguity itself creates risk because the owner cannot evaluate a service when its name does not reliably explain what it includes.
Who is actually looking after the technical health of your website?
This is the question every website owner needs to ask.
Not who uploads the blogs.
Not who changes the photographs.
Not who improves the SEO.
Not who adds new products.
Not even simply who clicks the WordPress update buttons.
Who is responsible for the health of the complete technical environment your website operates within?
Who checks whether the underlying software remains supported? Who identifies plugins and themes that have been abandoned? Who monitors for vulnerabilities, malicious files and unexpected changes? Who reviews administrator access? Who receives security warnings, understands what they mean and acts on them?
Who tests whether forms, checkouts, booking systems and connected services complete the full journey? Who knows whether the backups can actually be restored? Who understands the wider hosting environment? Who leads the response when something goes wrong?
Your hosting provider may maintain the server without managing your individual website. Your IT company may protect your email and devices without touching WordPress. Your developer may make changes when requested without continuously monitoring the site. Your marketing agency may manage content, SEO and visibility without being responsible or even aware of security.
Every provider may be completing the work they agreed to do correctly. Yet substantial gaps can remain between them.
Often, the missing responsibility was never understood, identified or assigned.
The answer does not have to be one mythical person who personally performs every task. It does need to identify somebody who understands the complete environment, knows where each responsibility sits and makes sure warnings, vulnerabilities and failures do not disappear between different providers.
Technical maintenance is the work. Technical ownership is the accountability that makes sure the right work is happening. In practice, that means knowing who looks after each part of the website, checking that the work happens and making sure somebody acts when a problem is found.
Far too often, new clients come to us with no idea that these are two different things, or that nobody has taken responsibility for either.
If you are unsure where your own website stands, start by asking your current providers what they monitor, what they test, which alerts they respond to and what falls outside their remit. You do not need to solve every technical issue yourself. First, you need to see where responsibility sits and where the gaps are.
This is business continuity
If your website is essential for generating revenue, taking orders, receiving enquiries or serving customers, its technical maintenance is part of business continuity. It is not simply a website expense.
The real question is not only how much it costs to look after the website.
The question is: how long could your business continue operating normally if the website stopped working or could no longer be trusted?
For an ecommerce business, the website is part of the sales operation, payment journey and customer-service infrastructure. For a service business, a failed contact form can sever the primary route through which new customers make contact (and how would you know).
Technical maintenance can feel expensive when everything is working. It becomes considerably more expensive when enquiries disappear, orders stop, evidence must be preserved or the business has to take its online operation completely off the road.
You should not need to become a developer
The answer is not to expect every business owner to understand PHP, inspect server logs or recognise malicious code.
You do not need to know how to test a car’s brakes to understand that somebody qualified must check them.
Website owners do need clarity. They should be able to get plain-English answers to these questions:
- What does our maintenance or management service include, and what is excluded?
- Who is responsible for each technical layer of the website?
- Who receives alerts, reviews them and responds?
- Are the functions our business depends on tested from start to finish?
- How long are backups kept, and when were they last restored and verified?
- Who tracks software that is approaching the end of its supported life?
- Who takes control during an incident?
- Who holds overall technical responsibility when several providers are involved?
The answers should be specific enough that you know who will act, not merely which company provides a service. If a responsibility belongs to another provider, that should be clear too.
There are no easy villains here. The website owner may reasonably believe the site is being looked after, and every individual provider may be completing the work they were asked to do. Everyone can be present while nobody owns the technical health of the complete system.
That is the website ownership gap.
Business owners have been handed responsibility for systems they were never taught how to evaluate. The solution is to make technical responsibility visible, defined and accountable.
If your website is essential to your business, you deserve to know exactly who is looking underneath the bonnet, what they are checking and who will act when they find a problem.
Part of the Marketing Clarity Series
This article is part of the Marketing Clarity series from The Last Hurdle, exploring the thinking behind clearer, more effective marketing.
From visibility and customer journeys to AI discovery and meaningful measurement, the series looks beyond the numbers to consider whether your marketing is reaching the right people, for the right reasons, and contributing to what your business is actually trying to achieve.




