Nobody buys a maintenance plan because they are excited about it. They buy one after the third outage in a quarter, usually on a Friday afternoon, usually during a sale.
The Challenge
Verano runs nine stores and an online shop that accounts for just under half of revenue. Their web platform had been built well three years earlier by an agency that then moved on. Nobody owned it afterwards.
By the time they called us they had recorded eleven unplanned outages in twelve months, averaging just over two hours each. Two of those landed on promotional weekends. The e-commerce platform was fourteen minor versions behind, the SSL certificate had lapsed twice, and the last verified backup restore had been attempted precisely never.
What made it worse was the invoice. They were paying three separate suppliers — a hosting reseller, a freelance developer on call, and a security scanning subscription nobody had logged into in eight months.
What the first audit found
We spent two weeks looking before touching anything. Four findings mattered:
- Backups existed but were not restorable. The nightly job had been failing silently for five months because the destination bucket had filled up. The dashboard reported "last run: success" because the script exited zero regardless.
- Most outages shared one root cause. Seven of the eleven traced back to the same memory leak in an image-processing routine that only surfaced under promotional traffic.
- Nobody was watching. There was no uptime monitoring at all. Every outage was discovered by a customer phoning a store.
- The spend was duplicated. Two of the three suppliers were billing for overlapping services, and the security subscription covered a scan the hosting provider already ran.
What We Did
We started with monitoring rather than fixes. Uptime checks from three regions, error-rate alerting, disk and memory thresholds, and certificate expiry warnings at sixty, thirty and seven days. Within a week we could see problems forming instead of hearing about them afterwards.
Then backups. New destination, verified restore to a staging environment every month, and an alert that fires when a backup does not arrive rather than when one fails — a distinction that matters more than it sounds, because a silent job produces neither.
The memory leak took four days to isolate and one afternoon to fix. It had been costing them roughly fourteen hours of downtime a year.
Patching moved to a schedule: security updates within seventy-two hours, minor versions monthly on a staging environment first, major versions planned quarterly with a rollback path agreed in advance.
Finally we consolidated the three suppliers into one plan. Not because we wanted the whole contract, but because splitting responsibility across three parties is exactly how a lapsed certificate goes unnoticed for a fortnight.
What a care plan actually covers
Clients often ask what they are paying for in a month when nothing breaks. This is the honest answer:
- Monitoring — uptime, error rates, resource thresholds, certificate expiry.
- Backups — daily, off-site, with a verified monthly restore.
- Security patching — on a defined schedule, tested on staging before production.
- Change requests — four hours a month for small edits, rolling over one month.
- Quarterly review — performance, uptime and a plain-language report on what changed.
Roughly seventy per cent of the work is invisible. That is the point of it.
The Outcome
Eighteen months in: zero unplanned outages. There have been four planned maintenance windows, all outside trading hours, all announced in advance.
Median response time to an alert is four minutes, because alerts now reach a person rather than an inbox. Security patches land within seventy-two hours in 98.7% of cases; the remainder were deliberately delayed pending a compatibility test.
Total IT spend fell 21% against the previous year, despite adding monitoring and verified backups that did not exist before. Consolidating three suppliers into one paid for the entire plan and left change.
We used to find out our site was down when a store manager called. Now we find out from an email that also says it has been fixed.
Elena Marquez — Head of Operations, Verano Retail Group
The uncomfortable arithmetic
Eleven outages at just over two hours each is roughly twenty-three hours offline a year. On a shop turning over what Verano's does, that is a five-figure revenue gap before you count the customers who tried once and went elsewhere.
The care plan costs a fraction of that. Maintenance is not a cost centre that sits next to the build budget — it is insurance on the build budget you already spent, and skipping it is the most expensive saving in this industry.
What we would do differently
We should have tested a backup restore in week one, not week three. For those two weeks we assumed backups worked because a dashboard said so, and if a serious incident had happened in that window we would have discovered the truth in the worst possible way.
Now the first action on every new support engagement is a restore test, before monitoring, before patching, before anything. If backups are broken, nothing else you do that month matters.
Running a site nobody owns? A
starts with a free audit — we will tell you what is actually at risk before you commit to anything.
