A beautiful site is an asset. But The look is only one layer. Underneath it sit a domain, DNS records, hosting, a security certificate, backups and admin passwords. When one of them isn't in order, the site goes down or disappears, and sometimes it takes the company email with it.
Design is the part you see
Your designer or studio owns the look, the experience and the messaging. That is a profession in its own right, and we stay out of it. What actually happens is that after launch, questions remain that nobody has claimed as theirs. Who renews the domain. Who checks that the backup works. Who gets the alert when the site goes down on a Saturday morning.
Most businesses find out the answers on the bad day. The site goes down, the phone starts ringing, and it turns out the domain is registered to the personal account of someone who left the company 2 years ago. A check that should have taken half an hour turns into a week.
- Who the registered owner of the domain is, and when it renews
- Where the site is hosted and who pays for the hosting
- Who holds the admin passwords and the backups
- Who is responsible for system and plugin updates
- Where the contact form submissions go
This is not meant to scare anyone. The answers simply belong in one written place, not in someone's head. It is the difference between a 20-minute outage and one that drags on for a week.
The domain and DNS, who really owns them
The domain is the asset. The website is just what sits on it. If the domain is registered to a vendor rather than to the company, you are renting your own address instead of owning it. Switching vendors in that situation becomes a negotiation, instead of a 10-minute technical task.
- Check the registration records for who is listed as owner and who is the contact
- Make sure the email address on file belongs to the company, not to an individual
- Move the registration to a company-owned account, with at least 2 contacts
- Turn on auto renewal and put the expiry date in the calendar
- Save a snapshot of the DNS records table before every change
DNS records are the domain's control panel. One small change there, say a record pointing to a different server, can take down the site and the email with it. That is why every change is made with a backup of the previous table, by hands that know what they are doing.
One more small thing that saves a lot. Keep a list of every domain the company owns, including the ones you once bought for a campaign and forgot. An expired domain is up for grabs by anyone, and sometimes it gets taken precisely because of your name.
Hosting, backup and who brings the site back online
Ask your vendor one simple question. If the site were wiped at noon today, what would you restore it from, and how long would it take. If the answer stumbles, there is no backup. A backup nobody has ever tried to restore from is not a backup, it is a promise.
| What needs to be in order | Who actually owns it |
|---|---|
| Design, content, and page development | Your designer or studio |
| Domain, DNS records and renewals | MO-TECH, with the domain registrar |
| Hosting, backup and recovery | MO-TECH, together with the hosting provider |
| Security certificate and system updates | MO-TECH, with continuous monitoring |
| Business email and employee mailboxes | MO-TECH, within Microsoft 365 |
For every client we build IT management dashboard that brings exactly these things together in one place. Domains, mailboxes, software subscriptions and equipment by employee. That way nobody has to keep in their head when the domain renews.
It also pays to agree on timing in advance. How long a full restore takes, who keeps customers updated in the meantime, and who signs off at the end that the site is back. Without that agreement, everyone waits on everyone else while the site is down.
Certificate, updates and admin passwords
HTTPS is not an add-on. Without a valid certificate the browser shows a warning, and the visitor leaves before ever seeing the design. Certificates renew automatically in most cases, but renewal breaks quietly after a hosting migration or a DNS change. That is why you need monitoring that alerts a day before expiry, not a week after.
- WordPress and every plugin installed on it are an attack surface. An abandoned plugin is an open door
- Updates are tested in a staging environment first, and only then on the live site
- A personal admin user for each person, no shared accounts
- Two-factor authentication on every admin account, including at the hosting provider
- Editor permissions for content writers, not administrator rights
Passwords are the sensitive part. If the site password currently lives in a WhatsApp thread with a freelancer, that is a problem in itself. Admin passwords go into a managed company password vault, and anyone who leaves loses access the same day, not 6 months later.
If your site also takes payments, the bar goes up. There, every payment plugin, every unnecessary permission and every exposed password is a direct risk to revenue, not just a technical inconvenience.
Speed, accessibility and form privacy
Speed is mostly about images. A rich design saved as heavy files becomes a site that loads slowly on mobile, and that is where most of the audience in Israel is. Correctly sized images, a modern format and proper compression solve most of the problem without touching the design itself.
Accessibility is a legal requirement in Israel, not a nice-to-have. Color contrast, full keyboard navigation, alt text for images and an accessibility statement on its own page. Settle this with the designer at the specification stage, because fixing it afterwards always costs more.
Another point that keeps coming up for us is third-party scripts. Every tracking pixel or chat widget pasted into the site loads another company's code. It slows down loading and also passes visitor data along, so it is worth going through the list once a year and removing whatever is no longer in use.
Every inquiry that comes in through the site is someone's personal data. Find out where it is stored, who can read it and how long it stays there. A privacy policy page that describes this accurately is part of the site, not an appendix.
Company email lives on the same domain
This is where a small mistake becomes a critical outage. The website and email share the same domain, but they are completely different records. A vendor who migrates hosting and rewrites the table without noticing takes down email for the entire company. A business can survive a day without a website. Without email, it simply stops working.
That is why we ask to be in the loop before any migration. The designer works on the site, and we look after the mail records, permissions and backups. Under managed IT services we have a binding SLA, response within 10 minutes and a critical outage within 30 minutes, at any hour.
we also manage the hardware and the employees' mailboxes in the same place, so there is no scenario where the site is up and the office is stuck. We run a computer repair lab, and you can order computer and mobile equipment through us at importer prices.
A beautiful site that will not load, or email that went down because of a domain change, is not a design bug.
FAQ
Who should be registered as the owner of the website's domain?
The company itself, always. The registration should sit in an account with a company email address and more than one contact. If the domain is currently registered to a vendor or an employee, request a transfer before any new project.
Our site is built on WordPress. What is the risk there?
The plugins. Every plugin is someone else's code running on your site, and a plugin that is not updated becomes an open door. We reduce the number of plugins, test updates in a staging environment before the live site and monitor file changes.
Does MO-TECH build or design websites?
No, and that is deliberate. Design and development stay with your designer or studio. We take care of everything around it: domain, DNS, hosting, certificates, backups, information security and business email. Both sides work well together when each does its part.
How often should you verify that the website backup works?
At least once a quarter, and always after a major change. A real test is a restore to a separate environment, not a glance at a file list. We log the date of the last test in the dashboard, so there is no room for doubt.
Related to: Managed IT services for businesses · IT management dashboard · What business IT services include · Talk to us