A Global Lesson On Automated Software Updates
Today’s Cloudstrike chaos that caused IT outages across the globe is an excellent example of the risks that come with software updates. Particularly automated updates.
Oops! We could not locate your form.
Today’s Cloudstrike chaos that caused IT outages across the globe is an excellent example of the risks that come with software updates. Particularly automated updates.
Today’s Cloudstrike chaos that caused IT outages across the globe is an excellent example of the risks that come with software updates. Particularly automated updates. Thankfully it had no impact on our IT infrastructure.
Whilst updates are important for security, functionality and software progressing, how software updates are carried out is key.
This is true of CMS and plugin updates for your website. Whilst your site going down might not ground flights and stop trains, it can massively impact your business and bottom line.
The CEO of Cloudstrike, George Kurtz, said that the problem was caused by a bug in a single update that created a ‘negative interaction” between the update and Microsoft’s OS. This is something that can happen with a single bug in a CMS or plugin update.
Many in our industry use auto updates to handle WordPress Core, WooCommerce and plugin updates on live websites in their care. Those auto updates can happen at any time of the day or night.
Yet updates aren’t always straightforward, as the Crowdstrike example illustrates. If there is an issue with an update to your site, this could take your site down, or break important functionality, disrupting your business and potentially lose you revenue.
There are so many moving parts to any website, including integrations and third party tools/APIs. Bugs, code incompatibility issues, or tools/plugins not playing well together can break functionality or take a site down.
With Enterprise websites, many tools that are used to power business operations are often integrated into the website, but are not part of the WordPress ecosystem. This requires manual intervention to test for any potential conflicts, as these tools may be critical to the website and business. Simply automating updates without testing first can cause panic among a brand’s C Suite or management team, with the prospect of their website going down.
Impact are somewhat of a rarity in the WordPress Support and Maintenance space, as we do not use auto updates on live sites. We place the functionality and stability of our clients’ sites above the temptation and ease of auto updates.
Some say that auto updates are the way forward, as any security patches are quickly implemented. This is great for sole traders and small businesses managing their own websites, as they may not be able to stay on top of regular updates. Even some web agencies state that they’d rather use automatic updates, as the risk of downtime may only be minimal or any downtime wouldn’t really affect the business financially.
Ultimately, any brand that is investing in marketing or advertising is fundamentally driving traffic to their website. This makes their website a critical cog in their sales and marketing. Downtime does not only damage potential financials, but can damage reputation too. Yesterday Crowdstrike was an unheard of entity, tomorrow it might well be remembered.
For mid sized, large and enterprise businesses with professional agencies managing their website maintenance, keeping on top of regular updates shouldn’t be an issue. Security patches should always be a top priority for these agencies and dealt with quickly.
With our process, updates are carried out quickly by our expert team, but tested thoroughly first. We always prioritise security patches and updates. Combined with our rigorous security setup, we can ensure both the security and stability of our clients’ websites.
We test every update on the client’s staging environment (clones of these sites hosted on a different server). Testing allows us to ensure that these updates will not create any issues. Where issues are identified, we find a solution to them. Updates are only pushed to our clients’ live or production websites once we know nothing is going to break.
Another key policy we deploy at Impact is “Never Push On A Friday”, the chaos it can cause if something does slip through the net, when most businesses only have Mon-Fri 9am-5pm support, meaning waiting for Monday for a fix (not great if you’re in B2C.)
We do however provide an out of hours support service, so if your business is looking for weekend support, we do have an option for you 🙂
So if you’re looking for a WordPress Maintenance partner who values security and stability, get in touch today.
PS. Crowdstrike will be taking some immense slack today, but regardless of the route cause of the issue, issues do happen and they happen frequently, just perhaps not as newsworthy. With the evolution of technology and the digital space, we are all using and relying on so many different partners and businesses to work each day. We all love to moan when things go wrong, but we never seem to appreciate these tools when they are all working as they should. So a personal message to the Crowdstrike team, we hope people appreciate that it’s the speed and responsiveness of how a business deals with a problem or corrects the error that is remembered more than the issue itself. I’m sure your team will come through.

If you’d like to learn more about our WordPress & WooCommerce Support & Maintenance plans, drop us an email or give James a call.
Our plans provide a holistic solution to your website’s performance, reliability and security, and are inclusive of premium tools and services.