Looking after one website is a task you can hold in your head. Looking after twelve is an operation, and the failure mode is different: nothing dramatic goes wrong, things simply drift.
Agencies, franchises, multi-brand businesses and property groups all end up here. Managing multiple websites introduces problems a single site never has, and most of them are organisational rather than technical.
What actually changes at scale
The weakest site sets your risk
Eleven well-maintained sites and one forgotten microsite from a campaign three years ago. That microsite is your exposure — and if they share hosting, a compromise there can reach the others.
The abandoned sites are almost always the ones that get hit. Nobody logs in, so nobody updates, and nobody notices.
Shared credentials multiply a single breach
It is convenient to use the same admin password across a portfolio. It also means one leaked credential compromises everything at once, and the clean-up is twelve clean-ups.
One vulnerability hits everything
Portfolios tend to standardise on the same theme and plugin stack. That is good for maintenance and bad for blast radius — when a vulnerability is disclosed in a plugin you run everywhere, every site is exposed simultaneously.
Standardisation makes maintenance easier and incidents bigger. It is still the right choice — it just means patch speed matters far more than it does for a single site.
Nobody owns any of it
The most common failure and the least technical. Each site was someone's responsibility once. Staff changed, agencies changed, and now no one person can say who watches which site.
Start with an inventory
You cannot secure what you have not listed, and most organisations with a portfolio do not have a current list.
For each site, record: the domain and its registrar, expiry date, where it is hosted, what it runs on, who has administrator access, whether backups exist, whether anything monitors it, its business importance, and — crucially — who is responsible for it.
Two things routinely surface from this exercise. Sites nobody remembered still being live, and domains expiring sooner than anyone realised.
Deal with the forgotten sites deliberately. If a site no longer serves a purpose, take it offline properly and redirect the domain. An unused site kept online out of vague caution is pure liability.
Separate what should be separated
Two decisions materially reduce how far an incident spreads.
Do not stack everything on one hosting account. Cross-contamination between sites on a shared account is common. Separate accounts, or genuinely isolated containers, contain the damage.
Never reuse credentials across sites. Unique generated passwords per site, in a shared password manager with proper access controls. This is the single highest-value change for a portfolio, and it costs nothing but discipline.
Standardise deliberately
Consistency is what makes a portfolio manageable. Aim for the same core plugin stack, the same security configuration, the same backup approach, the same monitoring, and the same update rhythm everywhere.
When every site is configured differently, every task becomes bespoke and things get skipped. When they are consistent, one person can maintain twelve sites in the time it used to take to maintain four.
The trade-off is real though. Standardising means a disclosed vulnerability affects everything at once — so pair it with the ability to patch quickly across the whole portfolio.
Centralise the monitoring
Checking twelve dashboards individually does not happen. It requires someone to remember, and after a busy fortnight it stops.
What works is one place showing the status of everything: update status, file integrity alerts, uptime, certificate and domain expiry, and blacklist checks across the portfolio.
The important shift is from pull to push. Nobody should have to log in to discover a problem — the problem should come to them.
A routine that scales
Daily, automated: uptime, malware scanning, file integrity, security update alerts.
Weekly, about an hour for a dozen sites: apply minor updates, confirm backups ran, review any alerts.
Monthly: apply major updates via staging, review admin users across all sites, check performance, and confirm forms are still delivering.
Quarterly: test a restore on at least one site, audit the plugin inventory, review domain and certificate expiry dates, and update the inventory itself.
That form check deserves emphasis. Across a portfolio, a broken contact form can run for months before anyone connects a quiet quarter to a technical fault.
Plan the incident before it happens
With one site you can improvise. With twelve you need to have decided in advance: how you determine whether an incident affects one site or all of them, who is called, in what order sites are restored, and — if these are client sites — who tells the client and how quickly.
Where personal data is involved there are notification deadlines attached, generally 72 hours under GDPR and comparable windows under PDPL. Working out your process during an incident is how those deadlines get missed.
For agencies specifically
If these are client sites, two additional points matter.
Be explicit about what you cover. A great deal of friction comes from a client assuming security was included in hosting, and an agency assuming the client handled updates. Put it in writing.
Access should be documented and revocable. When a staff member or contractor leaves, you need to remove their access from every site — which means knowing where they had it.
How we work with portfolios
We manage security across multi-site portfolios regularly, including for agencies who prefer to hand the security layer to a specialist rather than build the capability internally.
Our security monitoring service covers continuous scanning, file integrity alerts, a managed firewall and prompt patching across every site — with one point of contact and a person reading the alerts.
Where sites also need general upkeep, our managed website plans cover updates, backups and performance too.
Tell us how many sites you have and what state they are in. We will tell you honestly where the real exposure sits.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.