Keeping your server up to date is one of the most critical aspects of server security and stability. With Data Mammoth managed services, our team handles the entire update process — from assessment to application to verification. This guide explains our update methodology and what you can expect.
Why Updates Matter
Outdated software is one of the leading causes of security breaches:
- Security patches fix known vulnerabilities that attackers actively exploit.
- Bug fixes resolve issues that can cause crashes, data corruption, or performance problems.
- Feature updates provide new capabilities and improvements.
- Compliance requirements often mandate timely patch application.
Our Update Process
Step 1 — Monitoring for Updates
Our team continuously monitors for available updates across all managed servers:
- Operating system package repositories are checked regularly.
- Security advisories from OS vendors and software projects are tracked.
- Critical vulnerability databases (CVE) are monitored for relevant threats.
Step 2 — Assessment
When updates are available, our engineers assess them:
- Severity — Is this a critical security patch, a moderate fix, or a minor update?
- Impact — Will the update require a service restart or server reboot?
- Compatibility — Are there known issues with the update that could affect your services?
- Dependencies — Does the update affect other software on your server?
Step 3 — Planning
Based on the assessment, updates are categorized and scheduled:
| Category | Response Time | Downtime |
|---|---|---|
| Critical security | Within 24 hours | Brief restart may be required |
| High security | Within 48 hours | Brief restart may be required |
| Moderate updates | Next maintenance window | Minimal to none |
| Minor updates | Next routine update cycle | None expected |
Step 4 — Application
Updates are applied carefully:
Step 5 — Verification
After applying updates:
Step 6 — Documentation
Every update action is logged:
- What was updated and to which version.
- When the update was applied.
- Whether a restart or reboot was required.
- Any issues encountered and how they were resolved.
Maintenance Windows
For updates that require service restarts or server reboots, we use scheduled maintenance windows:
- Default window — A standard maintenance window (typically during off-peak hours) is assigned to each managed server.
- Custom windows — You can request a specific maintenance window that aligns with your traffic patterns.
- Emergency patches — Critical security patches may be applied outside the maintenance window if the risk of exploitation is imminent.
Requesting a Custom Maintenance Window
Submit a support ticket specifying your preferred maintenance time:
- Day of the week
- Time range (in your timezone)
- Any blackout periods (times when updates must never be applied)
What Gets Updated
Operating System Packages
All system packages from the official repositories:
- Kernel and core libraries
- System utilities
- Security frameworks (e.g., OpenSSL, OpenSSH)
Web Server Software
- Apache, Nginx, or other web servers
- PHP and PHP modules
- Python and Node.js runtimes (if managed)
Database Software
- MySQL, MariaDB, PostgreSQL
- Database security patches
Security Tools
- Fail2ban rules and software
- Firewall rule updates
- Antivirus/antimalware definitions (if installed)
What We Do NOT Update Automatically
Some components require your explicit approval before updates:
- Major version upgrades — Moving from one major version to another (e.g., PHP 8.1 to 8.3) requires your approval due to potential breaking changes.
- Application-level software — WordPress, n8n, or other applications you manage through their own update mechanisms.
- Custom software — Software you compiled or installed manually.
Communication
We keep you informed throughout the process:
- Pre-update notification — For significant updates, we notify you in advance with the planned timeline.
- Post-update summary — After updates, you receive a summary of what was applied.
- Issue notification — If an update causes any issues, we notify you immediately and work to resolve it.
Rollback Procedures
If an update causes problems:
What to Do Next
- What's Included in Managed Services? — Full service breakdown.
- Managed Services Overview — Program overview.
- Security at Data Mammoth — Our security approach.
- Backup Strategy — Snapshots, Offsite, Automated — How backups protect against update issues.