What "keeping it running" actually means after software goes live

The day a new website, customer portal, CRM or automation goes live tends to feel like the finish line. The build is signed off, the team has been shown round it, and everyone moves on to the next thing. What is easy to miss in that moment of relief is that go-live is not the end of the job. It is the start of a different one: the quiet, never-quite-finished work of keeping the thing running. That work is mostly invisible, which is exactly why it gets under-resourced, and why the bill for skipping it usually arrives at the worst possible time.
Go-live is when the real work starts
Building software gets all the attention because it is the visible part. It has a start, a budget, and a launch. Owning it, by contrast, has no obvious milestones, so it is easy to assume the spending is over once the build is paid for. The long-held industry rule of thumb runs the other way: across a system’s life, keeping it running tends to cost more than building it did, often by a wide margin. The exact split is debated and varies enormously by system, so it is better treated as a direction than a precise figure. The direction is reliable, though, and it is the one most budgets forget: the cheque for the build is the smaller, shorter part of owning a piece of software.
This is not a fault in how the software was made. Anything connected to the internet, holding customer data, or relying on other systems needs ongoing attention simply because the world around it keeps moving. Browsers change, platforms update, security flaws are found and fixed, and the business itself changes what it needs. A system that is left untouched does not stay still. It quietly drifts out of date.
The four jobs that never finish
Strip “ongoing support” back to what it actually involves, and there are four jobs underneath it. None is glamorous. All four have to happen, more or less forever, for as long as the system is in use.
Updates and patches. Software needs feeding. Vendors release updates to fix security flaws, keep up with the platforms they depend on, and add capability. Patching matters because, in the NCSC’s words, patches fix known flaws in products that attackers can use to compromise devices 3. The NCSC Small Business Guide puts it more plainly still, calling keeping software up to date one of the most important things a business can do, the IT equivalent of eating your fruit and veg 4. Speed is part of it: once a fix is published, attackers study it to find the hole it plugs, then go looking for systems that have not applied it yet 3. The guidance is to install updates promptly, ideally within a few days, and to turn on automatic updates wherever that is sensible 3.
Small fixes and changes. Every live system generates a steady trickle of work. A form stops submitting after a plugin updates. A report needs a new column. A page reads oddly on a phone. Alongside the breakages sit the requests, the “can we just” jobs that arrive once people are actually using the thing. It is worth separating the two. A fix restores something that was meant to work and stopped. A change asks the system to do something new. Both are normal and neither stops coming, but knowing which is which keeps expectations and budgets honest.
A named owner. This is the single most skipped item, and the one that quietly undoes the other three. Someone has to be responsible for the system: not “whoever happens to be free,” but a named person or provider whose job it actually is. The NCSC frames this as the core of any support arrangement, advising that a contract should define what the provider takes responsibility for and what remains with the customer 2. The owner is the person who notices the update is overdue, tracks when a platform is approaching the end of its life, and knows where the backups are. Without one, every job above becomes nobody’s job, which means it happens late or not at all.
Backups you have actually tested. A backup that nobody has ever restored is a hope, not a backup. Plenty of businesses discover, at the worst moment, that their backups were incomplete, out of date, or could not actually be recovered. The NCSC’s advice is to identify the essential data first, back it up regularly, keep a copy off-site or offline, and make sure you can genuinely recover from it 4. Recovery is the real test, and backups are described by the NCSC as the most effective way to recover from a ransomware attack 2. A useful habit is to back up before applying a major update 4, so there is always a known-good point to fall back to.
What good ongoing support actually covers
Turn those four jobs into a real arrangement and the shape of decent support becomes concrete. The NCSC’s guidance on choosing a provider is a useful neutral checklist, because it describes what good looks like without selling anything.
A real support arrangement has defined response times, so an urgent issue is dealt with on a known timescale rather than whenever someone gets to it 2. It applies updates on a schedule, with the NCSC pointing to patching critical and high-risk vulnerabilities within 14 days of release 2. It keeps regular off-site backups, tests that they recover, and can explain how it would get the business back up after something like a ransomware attack 2. It uses sensible access controls, including two-step verification and least-privilege access, so the system is not one leaked password away from trouble 2. And it watches the horizon: someone tracks when the platforms a business relies on are heading for the end of their supported life, and plans the replacement before support runs out rather than after 2.
That last point is not abstract. Windows 10 reached the end of its support on 14 October 2025; after that date, those devices no longer receive technical support, software updates, or security fixes from Microsoft 5. The machines keep switching on, which is exactly the trap: nothing visibly breaks, so the risk builds up unseen. Keeping an old system limping along is not free either. Microsoft’s paid Extended Security Updates for Windows 10 are priced to rise sharply, doubling in each successive year for up to three years 6, which is the cost of putting off the replacement made explicit.
The other thing good support makes clear is the line. The NCSC’s central point about providers is that the contract should spell out what they handle and what stays with the customer 2. Most disputes about support are really disagreements about where that line sits, so it is worth agreeing it in plain words at the start.
A short, honest self-assessment
None of the above requires a buying decision. Anyone running a live system can check their current arrangement, whether that is in-house, a freelancer, or a managed provider, against five questions:
- Is there a named owner? Someone whose actual job it is to keep this running, not “whoever’s free.”
- Are updates applied on a timescale rather than when someone happens to notice? The NCSC’s benchmark of within 14 days for critical fixes is a reasonable yardstick 2.
- Has a backup actually been restored in a test this year? Not “do backups run,” but “have we proven we can get the data back.”
- Is it written down who is responsible for what? The split between what a provider covers and what stays with the business 2.
- Does anyone track when the platforms in use stop being supported, the way Windows 10 just did 5, and plan the replacement before the date, not after?
A confident yes to all five is real support. A run of “well, sort of” is a phone number with good intentions attached, which is a different and riskier thing.
The cost of skipping it
The honest case for this work is not a scare story. It is that the maintenance is cheap insurance against an avoidable problem. Around four in ten UK businesses, 43%, reported a cyber breach or attack in the past year, rising to roughly two-thirds of medium-sized firms; the rate is lower for the very smallest businesses, so the headline overstates the risk for a micro-business 1. The most common cause is mundane rather than exotic: phishing accounts for the overwhelming majority of incidents, reported by 85% of those affected 1. And the typical bill is modest rather than ruinous, with the average cost of the single most disruptive breach put at around £1,600 for a business 1. That figure is an average, and it skews small for small firms, which is rather the point. The damage is usually avoidable, and the thing that avoids it is the boring maintenance most businesses are tempted to defer.
Most of the time, of course, nothing happens. The updates apply, the backups sit unused, the owner has a quiet week. That is not wasted effort. It is what success looks like for this work: good support is largely the cost of nothing going wrong. The trouble is that “nothing going wrong” feels like an easy line to cut, right up until the morning it would have saved the day.
For a small team, the realistic answer is rarely to do all four jobs in-house and never miss one. It is to be honest about which of them are genuinely being covered, and to make sure none of them is quietly nobody’s job. That is the work hirevolution treats as a service in its own right, not an afterthought to the build.
See how hirevolution helps keep things running once they go live
Sources
- UK Cyber Security Breaches Survey 2025, DSIT / Home Office official statistics. [link]
- NCSC, ‘Choosing a managed service provider (MSP)’. [link]
- NCSC Device Security Guidance, ‘Keeping devices and software up to date’. [link]
- NCSC Small Business Guide. [link]
- Microsoft, ‘Windows 10 support has ended on October 14, 2025’ (official support). [link]
- Microsoft Learn, ‘Extended Security Updates (ESU) program for Windows 10’. [link]