Blog
See our posts on the most important topics in and around website design - from commissioning your own website to sustainability and accessibility, we cover the things that are important to you and to us.
Why We're Applying Security Updates More Often (And Why That's a Good Thing)
If you've noticed us mentioning security updates more frequently lately, there's a reason — and it's worth explaining, because it reflects something that's changing across the whole web industry.
The threat landscape is moving faster
For years, the window between a security vulnerability being discovered and it being actively exploited by attackers was measured in weeks. That gave website owners and agencies like us time to assess, plan, and apply security patches in an orderly way.
AI has changed that. Attackers are now using AI tools to scan for vulnerabilities, analyse patches the moment they're released, and attack sites in hours rather than days. The breathing room that used to exist is shrinking fast — and the standard approach to security updates has had to change with it.
It's not just our experience. The UK's National Cyber Security Centre reported a 130% rise in nationally significant cyber attacks in 2025, and its own technical lead has warned that AI is enabling attackers to exploit vulnerabilities "at a scale and speed the industry has not seen before." The NCSC has explicitly flagged a coming "patch wave" — a surge in vulnerability disclosures that will require rapid, large-scale remediation across the industry.
A recent example
Very recently, a critical vulnerability was discovered in Joomla Content Editor — an extension used on many websites, including a number of ours. An attacker could gain access to a site and upload malicious content with no login, no credentials, and no human interaction required. In security terms, it was rated as severe as a flaw can get.
The security fix was released on 3 June 2026. Active attacks appeared almost immediately afterwards — and within 24 hours, the software we use to watch over your site had already detected and blocked intrusion attempts. We were alerted, we acted, and our clients' sites remained secure.
This is the new normal. Not every vulnerability will be this severe, but the speed at which they move from disclosure to active exploitation is now consistently fast. Waiting even a few days to apply a patch is a meaningful risk.
What we're doing about it
All of this goes on in the background as part of your hosting agreement with us — you don't need to think about it, but it's worth knowing what's happening on your behalf.
We monitor your site continuously, with real-time alerts on anything suspicious. That means we're not waiting for something to go wrong before we notice — unusual activity, unexpected file changes, blocked intrusion attempts: we see it as it happens. When a security disclosure affects a platform or extension your site uses, we apply the update as quickly as possible. We don't wait for a scheduled maintenance cycle.
The JCE example above is a good illustration of how this works in practice. The vulnerability was disclosed, we applied the patch, and our systems were already detecting and blocking live attack attempts — all within 24 hours, and without any disruption to our clients.
You don't need to do anything
Your sites are being looked after. We're raising this not to cause concern, but because we think it's worth being transparent about why security updates have become a more prominent part of how we work — and why that's the right response to how the industry is changing.
Get in touch to talk about your site's security and how we keep it safe and running.