SERVICE 06 — 網站支援及維護

Website Support & Maintenance in Hong Kong.

A website is not finished at launch. Platforms update, plugins break, threats change and your business moves on. Our care plans keep your site secure, current and improving — under a clear SLA, with a named team that knows your setup.


The cost of a site nobody maintains

Most hacked websites are not targeted. They run an unpatched plugin that a bot found. Every unmaintained site is one update behind a breach, an outage or a broken checkout — and the repair always costs more than the plan that would have prevented it.

Support that actually answers

A care plan is a promise about response time, and we put it in writing. You get a named contact, a response SLA by severity, and a monthly summary of what was patched, what was fixed and what we recommend next — so the site keeps getting better, not just staying alive.

What’s covered

Security & Updates

Core, plugin and dependency patching on a schedule, tested on staging before it touches production. Firewall and malware scanning included. We also fix the findings from security scans and SRAA (Security Risk Assessment and Audit) reports, harden the site and support the re-test.

保安及更新

Monitoring & Fixes

Uptime, performance and error monitoring with a human on the alerts. Bugs fixed under SLA, not added to a backlog.

監察及修復

Content & Small Changes

A monthly allowance of hours for edits, new pages, banner swaps and the small things that would otherwise wait months.

內容及小型修改

Improvement Roadmap

Quarterly review of analytics, speed and SEO with concrete recommendations — so the site keeps earning, not just running.

持續優化

Care plan tiers

Every plan includes patching, monitoring and backups. Tiers differ in response time, included hours and how much proactive improvement work is built in.

Essential

Patching, monitoring, backups and a next-business-day response. For brochure sites that need to stay safe and up.

Business

Everything in Essential, plus monthly change hours, same-day response and a quarterly improvement review.

Enterprise

Priority SLA with emergency response, dedicated hours, staging environment and named engineers. For sites the business depends on.

Emergency

Site down, hacked or broken and no plan in place? One-off recovery and hardening, then we talk about a plan.

process

From handover to steady state.

Platform, plugins, security posture, backups and performance — we find what is at risk before it fails.

Outstanding updates applied, backups verified, monitoring and access sorted.

A plan tier, an SLA by severity, and a named contact on both sides.

Scheduled patching, monitoring, fixes and your monthly change hours.

Quarterly review and a roadmap of what to improve next, with the numbers behind it.

Platforms we support

These are the platforms we support most often, not everything we know. If your site runs on another language or platform, let’s talk.

WordPressDrupalJoomlaUmbracoNext.jsLaravelWooCommerceCloudflareTwill CMSCodeIgniterReact.jsVue.jsJava.NET

Why VICOSYS for support

The team that built it

No hand-off to a maintenance shop that has never seen the code. The people who know your site are the people who maintain it.

An SLA in writing

Response times by severity, in the contract. You know what you are buying, and we are accountable to it.

Staging before production

Updates are tested on a copy of your site first. The update that breaks the checkout is caught before customers see it.

Sites that keep improving

Maintenance is the floor. The quarterly review is where the site gets faster, ranks better and converts more.


FAQ

Can you maintain a site you did not build?+

Yes. We start with an audit of the platform, plugins, security and backups. If it needs stabilising before we can take it on safely, we quote that separately and tell you why.

What does the SLA cover?+

Response and resolution targets by severity — site down, major fault, minor fault, change request. The tiers above set the times; the contract puts them in writing.

How are updates tested?+

On a staging copy of your site first, then rolled to production. If an update breaks something, you never see it.

What if we use up our monthly hours?+

Unused hours roll for a period; extra work is quoted before we do it. No surprise invoices.

Our site has already been hacked. Can you help?+

Yes — the Emergency tier exists for this. We contain it, clean it, harden it and restore from a clean backup, then we talk about a plan so it does not happen again.

Can you fix the findings in our SRAA or security scan report?+

Yes. Send us the SRAA (Security Risk Assessment and Audit) or vulnerability scan report and we triage each finding, fix and harden the site or system, then support the re-scan or re-audit until it is cleared. Government and public-body websites need an SRAA before launch, so this is routine work for us. We scan for vulnerabilities with Nessus, or work from a third-party scan report you provide, and complete the security fixes either way.

Or call us directly — +852 3460 1888