Contact
Managed Hosting

Managed Website Hosting in Australia: What to Look For

A practical buyer's guide to managed website hosting in Australia: what "managed" should actually include, where most Australian hosts stop, and the operational inclusions to demand before you sign. Written for IT managers, digital leads and marketing managers responsible for a website that generates revenue or leads.

What "managed" actually means, and where most hosting stops

"Managed hosting" is not a defined term. It is a marketing label applied to everything from a shared cPanel account with automatic WordPress updates to a fully operated cloud environment with a 24/7 on-call engineer. The word tells you almost nothing, so the only useful question is where the provider draws the boundary of responsibility.

In most Australian managed hosting agreements, that boundary sits at the operating system. The provider will patch the kernel, keep PHP and the web server current, renew TLS certificates, take nightly snapshots and restore the server if the hypervisor fails. That is real work and it has real value. But it stops precisely where your risk begins.

Consider what happens when a critical vulnerability is published for your CMS or one of its modules. The server is patched and healthy. The application is exploitable. Your host will tell you, correctly, that application updates are outside scope. Your web agency, if you still have one on retainer, may quote the work and schedule it for a fortnight's time. Meanwhile the CVE is being scanned for across the internet within days of disclosure.

That gap between infrastructure and application is the single most common failure in Australian website operations, and it is almost always invisible until something breaks.

The server boundary problem: who patches the application?

Write down every layer of your stack and put a vendor name next to each one. A typical enterprise site looks something like this:

  • Network edge: CDN, DNS, WAF, DDoS protection
  • Infrastructure: compute instances, load balancer, managed database, object storage
  • Operating system: kernel, packages, TLS certificates, cron
  • Runtime: PHP or Node.js version, extensions, memory and process limits
  • Application: CMS core, modules and plugins, Composer or npm dependencies
  • Custom code: themes, templates, integrations, scheduled jobs
  • Content and configuration: user accounts, permissions, redirects, form handlers

Most organisations can name a vendor for the top four and go quiet on the bottom three. When the person answering "who upgrades the CMS?" is a marketing manager with a credit card and a developer contact from three years ago, the site is unmanaged in every sense that matters.

The test of a genuine managed service is whether the provider will take responsibility for a change they did not originally build. Upgrading a CMS minor release can break a third-party module. Bumping PHP can break a legacy integration. A provider who will only patch what cannot break is not carrying operational risk, they are avoiding it. Our breakdown of what website managed services actually include, and what they do not sets out where that line should sit.

Data residency, latency and why Australian infrastructure matters

There are three separate arguments for hosting in Australia and they are often conflated.

Legal and procurement requirements

Australian Privacy Principle 8 in the Privacy Act 1988 governs cross-border disclosure of personal information, and government procurement frequently adds explicit data residency conditions on top of it. If your site collects enquiry forms, member records or job applications, where that data physically rests is a compliance question, not a preference. Ask which Australian region and availability zones your data sits in, and whether backups and logs stay onshore too. Backups leaking offshore is a common oversight.

Latency and Core Web Vitals

Trans-Pacific round trip times are typically 150ms and up. For static assets a CDN hides most of that, but every uncached request, every authenticated page, every form POST and every database-backed API call pays the penalty in full. Sites with logged-in areas, portals or checkouts feel noticeably slower on offshore origins, and Largest Contentful Paint suffers where the document itself cannot be cached.

Support in your timezone

A provider whose engineers are asleep during your business hours will hand you a ticketing system instead of a person. For a website that drives sales or lead generation, the practical difference between an AEST on-call rotation and an offshore follow-the-sun queue shows up on the day you need an emergency deployment.

Inclusions checklist: what a managed hosting agreement should specify

Vague scope is where disputes come from. Insist that the agreement names the following in writing.

Patching and upgrade windows

Who patches the OS, the runtime and the application, on what cadence, and inside which maintenance window. What the emergency process is for a critical CVE outside that window. Whether upgrades are tested on a staging environment first, and who fixes the site if an upgrade breaks something. Continuous CVE scanning and vulnerability monitoring is what turns a patching policy into something you can evidence to an auditor.

Backups, retention and restore testing

Backup frequency, retention period, whether copies are stored off the production infrastructure, and the stated recovery point and recovery time objectives. Crucially: when was a restore last actually performed, and will they perform one on request?

Security controls

WAF in front of the application with rules tuned to your stack rather than left at defaults, DDoS mitigation, TLS configuration and automated certificate renewal, enforced multi-factor authentication on CMS and server access, and file integrity monitoring. Ask who tunes WAF false positives when a legitimate form submission starts getting blocked.

Monitoring and response commitments

What is monitored, from where, how often, and what constitutes an incident. Response and resolution targets by severity, published uptime commitment, and how service credits work. A 99.9% target allows roughly 43 minutes of downtime a month; 99.99% allows about four. Those are very different engineering commitments and should be priced as such. Our guide to website support SLAs for enterprise and government covers how severity tiers are normally defined.

Change and access management

Deployment process, rollback procedure, environment separation, who holds credentials, how access is revoked when staff leave, and whether you retain administrative ownership of DNS, the registrar and the cloud account.

Comparison: shared hosting, cloud IaaS, managed hosting and managed hosting plus website management

Responsibility Shared / reseller hosting Cloud IaaS (self-run) Managed hosting Managed hosting + website management
OS and runtime patching Provider You Provider Provider
CMS core and module updates Not covered You Usually excluded Provider
Fixing a site broken by an update Not covered You Not covered Provider
WAF tuning and security response Generic rules only You Varies, often generic Tuned to the application
Backup restore testing Rarely evidenced You Sometimes evidenced Rehearsed and documented
Named uptime SLA Marketing claim Cloud provider SLA only Yes, infrastructure scope Yes, application scope
Out-of-hours escalation to an engineer No Your team Sometimes Yes
Best suited to Brochure sites Teams with in-house DevOps Stable, low-change sites Revenue or lead-critical sites

Backups that have actually been restored

Every host takes backups. Far fewer can tell you the last time one was restored end to end, and that is the only number with any value. Untested backups fail for predictable reasons: the database dump was taken while a migration was mid-flight, user-uploaded files live outside the backup path, the snapshot captured an encrypted volume without the key, or retention quietly rolled the good copy off before anyone noticed the corruption.

For a site that matters, ask for six-hourly database backups with copies held off the production infrastructure, a retention schedule you have agreed rather than inherited, and a documented restore rehearsal into a staging environment. If the provider cannot describe how long a full restore takes, you do not have a recovery time objective, you have a hope.

Monitoring, alerting and who gets woken up at 2am

Plenty of monitoring setups check whether the home page returns HTTP 200 every five minutes from a single location. That configuration will happily report a healthy site while the checkout throws a 500, the login form is broken, the CMS is returning cached pages from a dead database, or the TLS certificate expired an hour ago.

Useful monitoring covers synthetic transactions through the paths that actually earn money, checks from multiple geographic points to avoid false alarms, content assertions rather than status codes alone, certificate and domain expiry, disk, memory and queue depth, and error rate thresholds from application logs. Then it needs an escalation path with a human at the end of it. Uptime monitoring that actually detects outages is the difference between finding out from a dashboard and finding out from your head of sales.

Ask the direct question: at 2am on a Sunday, who receives the alert, what is their authority to act, and are they permitted to deploy a fix without waiting for your approval?

Three engagement models

Not every organisation wants to move infrastructure to get operational discipline. UnDigital delivers managed hosting for enterprise websites under three models.

Model Infrastructure sits with What we take responsibility for Typical fit
Hosting + Management UnDigital, on dedicated Australian infrastructure Full stack: infrastructure, OS, application, security, monitoring, support SLA Organisations that want one accountable vendor
Hosting Only UnDigital Infrastructure, OS, backups, edge security and uptime, with your team or agency owning the application Clients with capable in-house developers
Management Only Your own AWS, Azure or other cloud account Operating the environment you already own: patching, hardening, monitoring, releases, incident response Enterprises and government with mandated cloud tenancies

Questions to ask a prospective Australian host

  1. Which Australian region holds the production data, and do backups and logs stay onshore?
  2. Do you patch the CMS and its modules, or only the operating system?
  3. If a patch you applied breaks the site, who fixes it and at whose cost?
  4. When did you last restore a backup for a client, and will you demonstrate one for us?
  5. Is the WAF tuned per application, and who resolves false positives on forms?
  6. What are the response and resolution targets by severity, and what happens when they are missed?
  7. Who is on call out of hours, in what timezone, and can they deploy a fix unilaterally?
  8. Do we retain ownership of the DNS, registrar and cloud account?
  9. What does an exit look like, and will you hand over a documented environment?

If the answers arrive as a feature list rather than a named process, keep asking. Our longer framework for how to evaluate a managed web services provider turns these into a scorable checklist you can run across multiple vendors.

Frequently Asked Questions

What does managed website hosting include in Australia?

At minimum it should include provisioning and operating the server, operating system and runtime patching, TLS certificate management, backups with a stated retention period, and infrastructure monitoring with an uptime commitment. Most Australian providers stop there and exclude the CMS, plugins and custom code. If you need the application layer covered as well, that is website management and it must be scoped explicitly in the agreement.

Is managed hosting the same as a website maintenance agreement?

No. Managed hosting covers the infrastructure the website runs on. A website maintenance or management agreement covers the application itself: CMS and module upgrades, security patches at the code level, performance work and content support. Buying one and assuming you have both is the most common reason an organisation discovers an unpatched CMS after an incident.

Does my website data have to be hosted in Australia?

Not always, but Australian Privacy Principle 8 imposes obligations on cross-border disclosure of personal information, and government and enterprise procurement often mandates onshore residency outright. Onshore hosting also removes 150ms or more of trans-Pacific latency on every uncached request, which matters for portals, logged-in areas and checkouts. Confirm that backups and log data stay onshore too, not just the production database.

What backup frequency and retention should I expect?

For a site that takes enquiries or orders, six-hourly database backups with copies stored off the production infrastructure is a reasonable baseline, with retention agreed against your recovery point objective. Nightly-only backups mean accepting up to a day of lost data. Whatever the frequency, insist the provider has performed and documented a full restore rather than simply confirming backups exist.

Can UnDigital manage hosting we already run on AWS or Azure?

Yes. Under the Management Only model, the cloud account and billing stay with you and UnDigital operates the environment: hardening, patching, monitoring, release management, backup verification and incident response under an agreed SLA. This suits enterprises and government agencies with mandated cloud tenancies or existing committed spend.

What uptime SLA is realistic for an Australian website?

A 99.9% monthly target permits roughly 43 minutes of downtime and suits most business-critical sites. A 99.99% target permits about four minutes and requires redundant infrastructure, automated failover and a fully staffed on-call rotation, which changes both the architecture and the cost. Check whether the commitment covers only the server or the website being genuinely available, and what service credits apply when it is missed.

Talk to UnDigital about managed hosting

Hosting providers and website providers are rarely the same company, and the gap between them is where outages, unpatched vulnerabilities and finger-pointing live. UnDigital runs both sides: dedicated Australian infrastructure with 24/7 monitoring, six-hourly backups, WAF and DDoS protection, plus the development capability to patch, upgrade and fix the application on top of it, across WordPress, Silverstripe, Drupal and custom web applications.

Every engagement is scoped individually and starts with an infrastructure audit, so you get a written view of what is currently covered, what is not, and what it would take to close the gap. If you would rather not wait for the next incident to find out, including emergency break/fix support when something is already wrong, start with a conversation about your current arrangement.

Get your hosting arrangement audited

Reviews from our client partners.

"Thanks so much for your comprehensive strategy and execution of our digital ecosystem.

I can finally sleep at night knowing that everything is under control, secure and scalable.

Thank you!!!".

Corporate Marketing Manager, Sekisui House

"Thanks for all your help. This project was in such good hands from the beginning. We really appreciate all your hard work and expertise!!"

Retail Marketing Manager, West Village

Talk to an Australian managed hosting team

@undigital