Quick answerA hosting decision is clearer when ownership, responsibilities, recovery, and renewal terms are visible before they are needed.
Signal 01
Put ownership and access under business control
Start by creating a simple ownership record. Name the person or business entity that controls the domain registration, hosting account, DNS settings, billing profile, website administrator access, and the email address used for recovery notices. Keep privileged access with more than one authorized business contact, document how access is recovered, and review who still has access when staff or suppliers change.
Evidence nodeAsk for the domain expiry date, renewal contact, auto-renew setting, and steps required to unlock or transfer the domain. ICANN advises registrants to know their registration terms and keep contact information current; its policy requires registrars to send renewal reminders about one month and one week before expiry. Put the relevant dates and notices into a business-controlled calendar rather than relying on a single individual’s inbox.1
- Record the registrar, account owner, recovery email, and renewal date.
- Maintain a current list of authorized administrators and their role.
- Confirm how access can be recovered if an administrator is unavailable.
Signal 02
Define the support boundary before there is an incident
A hosting arrangement needs a written boundary of responsibility. Separate the work on the hosting environment from the work on the website itself. Ask who is responsible for server and platform maintenance, certificates, website software, themes or extensions, content changes, incident communications, and restoration. Also establish the support channel, the information needed to open a case, escalation contacts, and which requests need separate approval.
Evidence nodeTreat updates as an operating responsibility, not a vague feature. CISA notes that unsupported software no longer receives security updates and recommends regular patching procedures, testing, and automatic updates where appropriate. Establish which party tracks updates, how urgent changes are assessed, whether a test environment is used, who approves release, and how a change can be rolled back.2
- Request a responsibility matrix that names the owner of each recurring task.
- Ask what is included in support and what falls outside the arrangement.
- Set a change and escalation path before a critical update is needed.
Signal 03
Judge backups by your ability to restore
Evidence nodeA backup is useful only when it supports a recovery decision. CISA describes a backup as a separate copy of critical data and recommends scheduled recovery tests to verify integrity and refine recovery point and recovery time objectives. For a website, decide how much recent change the business could accept losing and how long the site can be unavailable before the impact becomes unacceptable.3
Evidence nodeRequest a plain-language backup specification. It should identify whether website files, databases, uploads, configuration, and other business-critical assets are included; how often copies are created; how long they are retained; who can request a restore; and how a restore is tested. Keep a record of the most recent successful restore exercise and the decisions made from it.3
- Identify the files, database, uploads, and configuration needed to rebuild the site.
- Set a recovery-point and recovery-time expectation that fits normal operations.
- Schedule and record a restoration test, not only a backup check.
Signal 04
Monitor performance as a shared operating signal
Hosting is one input to website performance, but it should be evaluated alongside the website’s code, content, third-party services, and traffic patterns. Agree on what will be measured, who receives alerts, how often results are reviewed, and who investigates a decline. Useful operating signals can include availability checks, page-response errors, resource use, and user-experience measures.
Evidence nodeGoogle defines Core Web Vitals as real-world measures of loading performance, responsiveness, and visual stability, using Largest Contentful Paint, Interaction to Next Paint, and Cumulative Layout Shift. Use those measures as a shared language for tracking important pages over time, especially after a website release, content change, or configuration change. They are monitoring inputs, not a substitute for deciding what matters most to customers and operations.4
- Choose a small set of business-relevant pages and operating signals to review routinely.
- Assign an alert recipient and an investigation owner.
- Keep a baseline so changes can be compared with previous performance.
Signal 05
Read renewal terms and prepare a clean exit path
Evidence nodeReview the initial term, renewal date, auto-renew process, cancellation notice requirements, account ownership, and any separate terms for the domain and hosting service. ICANN notes that domain registrations are typically one to ten years and must be renewed before expiry to continue using the associated services. The practical task is to know which date applies to which service and who can act before it passes.1
Evidence nodeMigration readiness is a record-keeping discipline. Maintain a current inventory of domain and DNS access, website files and database exports, configuration details, software and extension licences, administrative credentials, and the procedure for placing the site elsewhere. Plan early: ICANN explains that a domain in the Redemption Grace Period must be restored before it can be transferred. A documented exit path gives the business a clearer choice if requirements change.1
- Calendar each renewal date and identify its accountable owner.
- Keep a current export and configuration inventory in a controlled location.
- Document the sequence for moving the domain, DNS, website, and related settings.
Useful follow-ups
Questions, answered clearly.
Who should control the domain registration?
The business or an authorized business representative should retain current registrar access, recovery contact details, and visibility into expiry and renewal settings.
What should a backup arrangement clarify?
Clarify what is copied, how often, retention periods, restore authorization, recovery expectations, and how restoration is tested.
Are website software updates automatically included with hosting?
Do not assume so. Confirm separately who is responsible for platform, website software, extension, and content-related updates, and how changes are approved.
What makes a hosting arrangement migration-ready?
Current access to the domain and DNS, exportable site data, configuration records, software licence details, and a documented handoff sequence make a move easier to plan.
How should performance be monitored?
Choose a small set of business-relevant pages and measures, assign alert recipients and investigation owners, and review results after significant changes.
