Most website downtime comes down to four things: hosting or server failures, DNS or certificate problems, cyber attacks, or plain human error. If your site’s down right now, check your monitoring dashboard or status page first, then verify your domain and SSL certificate haven’t expired, and finally contact your host or switch to a backup if one’s ready to go.
- Human error contributes to about 43% of unplanned outages, so test changes on staging, require peer review, and keep a rollback plan ready.
- Diagnose in order: confirm DNS resolution, test the TCP connection, validate TLS, then inspect the HTTP response to avoid troubleshooting the wrong layer.
- Keep immutable or offline backup copies, and test a full restore at least quarterly; cloud copies alone may be deleted during a ransomware attack.
- Run uptime checks every minute or two, add synthetic tasks and checks from multiple locations, and give your host timestamps, errors, and diagnostic results.
- A page can count as down even when it returns a successful status: shoppers may abandon a checkout that takes 15 seconds to load.
Table of Contents
- What website downtime actually means for your visitors
- Common causes of downtime: what breaks, how to spot it, and what to do
- How to detect downtime: a layered approach that narrows the fault fast
- Prevention and recovery: backups, change control and capacity planning
- What we check on client sites, week by week
- What prolonged downtime can cost you beyond lost sales
- Our take on where small businesses should actually spend their resilience budget
- How our maintenance plans keep your site from going dark
- FAQ
- Sources
What website downtime actually means for your visitors
Downtime isn’t always the dramatic “site’s completely dead” scenario. We’d split it into three flavours: a complete outage where nothing loads at all, a partial failure where some pages work and others throw errors, and degraded performance where everything technically loads but takes so long that visitors give up before it finishes.
That third one catches a lot of small business owners out. If your checkout page takes 15 seconds to load, most shoppers won’t wait around to find out if it works. From a user’s point of view, that’s downtime, even though your server logs might show a 200 status code the whole time.
Before you panic and start ringing your host, run a few quick checks:
- Clear your browser cache and try again in a private or incognito window.
- Test the site from your phone on mobile data, not just your office WiFi.
- Use a free tool like Down for Everyone or Just Me to rule out a local network issue.
- Check whether the problem is one page or the whole domain.
These take under a minute and save you from escalating a problem that was sitting on your own laptop all along.
Common causes of downtime: what breaks, how to spot it, and what to do
Most outages trace back to one of seven culprits. We’ll go through each one with the telltale signs and the first move to make.
Pro Tip: Keep a simple incident log, even a shared document, noting what time things broke, what you checked and what fixed it. It makes the next outage faster to diagnose.
-
Hosting and server failures. Shared hosting plans often buckle under resource exhaustion: too many visitors, too many processes, not enough memory allocated to your account. Scheduled maintenance on your host’s end and outright hardware faults cause the same symptom from the outside. Check your host’s status page first, then look at server resource graphs if your plan gives you access to them. If you’re on a budget shared plan and this keeps happening, it’s worth reading about how poor hosting compromises site speed and visitor satisfaction before you commit to another year on the same package.
-
Network and data-centre problems. Your host’s server might be running perfectly while the problem sits upstream: a severed fibre line, an ISP routing fault, or a power cut at the data centre. Uptime Institute’s annual outage analysis finds that power, network, or provider issues remain leading contributors to major outages, and that these incidents commonly have more than one interrelated cause rather than a single clean failure. Ask your host directly whether there’s a known carrier incident or a generator and UPS issue at their facility. This is outside your control, but confirming it quickly stops you wasting hours changing settings that were never the problem.
-
DNS and domain or SSL errors. An expired domain registration, a lapsed SSL certificate, or a misconfigured DNS record will take your site offline even though the server itself is perfectly healthy. Run
digornslookupagainst your domain to check it’s resolving to the right address, and glance at a certificate transparency log if you suspect the SSL side. This is one of the most avoidable causes on the list, and it’s exactly the kind of thing that slips through the cracks when nobody owns domain renewals. We cover the practical side of this in our domain names and DNS management service. -
Software and deployment faults. A plugin update that conflicts with your theme, a failed deployment, or a stray line of broken code can take a working site down in seconds. Check your error logs first, and if you’ve made any recent changes, revert them before doing anything else. Testing changes on a staging copy of the site before pushing to production catches most of these before they ever go live. WordPress sites are particularly prone to this, and our guide to common WordPress security issues covers several plugin-related failure points worth knowing about.
-
Traffic spikes and bot surges. A sudden rush of real visitors, or a less welcome surge of bots scraping your pages, can overwhelm a server that was sized for ordinary traffic. Check your analytics for the spike and look at user-agent patterns to see whether it’s human or automated. A content delivery network, basic rate-limiting, or autoscaling on your hosting plan all help absorb these without you noticing.
-
Cyber attacks. DDoS floods, ransomware and brute-force login attempts are a growing share of serious outages. NCSC guidance on mitigating malware and ransomware attacks stresses that backups need to be designed to resist deletion by the attacker, since cloud backups can themselves be targeted. For anything beyond a nuisance attack, contain what you can, preserve your logs rather than wiping them, and for serious incidents, NCSC’s guidance on immediate recovery activities recommends triage and considering an NCSC-assured CIR provider. Our plain-language malware guide for small business owners is a sensible starting point if this is new territory.
-
Human error and change-management failures. This one’s bigger than most people assume. Splunk’s 2026 research, reported by Cisco, found human error implicated in about 43% of unplanned downtime events, with botched deployments and misconfiguration as common patterns. A wrong environment variable, a forgotten rollback step, a change pushed straight to the live site without a second pair of eyes: these are the failures that tighter process catches. Peer review on changes, even an informal “can you just check this” to a colleague, closes a surprising number of these gaps.
How to detect downtime: a layered approach that narrows the fault fast
Professionals diagnose outages in a specific order, and it’s worth adopting the same sequence rather than guessing. Practitioner guidance from Uptime Institute recommends working through DNS, then TCP, then TLS, then HTTP, testing each layer before moving to the next. It stops you chasing a certificate problem when the real fault was DNS all along.
- DNS resolution: use
digornslookupto confirm your domain resolves to the correct IP address. - TCP handshake: a quick
telnetorcurlto the server on port 80 or 443 tells you whether the server is even accepting connections. - TLS validation: check the certificate details in your browser, or run
openssl s_client, to rule out an expired or misconfigured certificate. - HTTP response:
curl -Iyour site’s URL to see the actual status code coming back.
Monitoring essentials: uptime checks running every minute or two, synthetic transactions that simulate a real user completing a task, and multi-location checks so you’re not fooled by a regional network blip, all feed into sensible alert thresholds that tell you something’s wrong before a customer does.
You don’t need enterprise software to do this. A free or low-cost uptime monitor, access to your host’s error logs, and the command-line checks above cover most small sites. If you suspect something more technical is at play, tools built for automated website auditing can flag issues before they become outages. When you do need to contact your host or ISP, bring timestamps, the exact error messages, and the results of your dig and curl checks: it cuts the back-and-forth considerably.
Prevention and recovery: backups, change control and capacity planning
Most of this is unglamorous, and that’s precisely why it works.
Pro Tip: Test a full restore from backup at least once a quarter. A backup you’ve never restored from is a guess, not a safety net.
-
Backup strategy. Keep immutable or offline copies, not just a single cloud backup sitting next to the live site. NCSC guidance on mitigating ransomware attacks specifically warns that cloud backups can be deleted by an attacker who gains access, so a genuinely resilient setup includes copies the attacker can’t reach.
-
Change control. Use a staging environment for anything beyond a typo fix, schedule maintenance windows and tell your visitors about them in advance, run a smoke test after every deployment, and always know your rollback plan before you push a change live. Our notes on setting up maintenance windows cover how to communicate these without alarming your customers.
-
Capacity and resilience. A CDN, sensible caching and either autoscaling or simply upgrading your hosting tier before you outgrow it all reduce the odds of a traffic spike turning into an outage.
-
Incident response basics. Triage first, contain second, and keep your communications honest and timely. NCSC’s immediate activities guidance frames recovery as a balance between containment and preserving evidence for investigation, which is worth remembering before you wipe a compromised server in a panic. Test your plan before you need it.
What we check on client sites, week by week
We’ve sat with enough small business owners staring at a blank browser tab to know the panic is always the same, and the fix is almost always boring. Here’s the routine we run.
Every week: we check uptime monitoring hasn’t flagged anything, confirm SSL certificates aren’t approaching expiry, scan recent error logs for anything unusual, and verify the automatic backup actually completed rather than silently failing.
Every month: we run a real restore test from backup rather than trusting it worked, review traffic patterns for anything creeping towards capacity limits, and patch non-production environments first before scheduling anything major on the live site.
- When your team doesn’t have capacity to run this routine yourself, a managed maintenance service picks it up for you.
- When an incident turns out to be a serious cyber attack rather than routine downtime, that’s the point to bring in an incident response partner rather than handling it alone.
What prolonged downtime can cost you beyond lost sales
Downtime isn’t just a technical inconvenience. Depending on what your site does, extended outages can carry genuine legal and compliance weight.
If you run an e-commerce site, a prolonged outage during a sale period or, worse, a data breach that caused it, can trigger obligations under UK data protection law if personal data was exposed or compromised. Service-level agreements with your own customers, if you’ve signed any, often specify uptime guarantees with financial penalties attached, so it’s worth knowing what you’ve actually promised. Industries with regulatory oversight, healthcare, financial services, anything handling payment data, may have specific reporting duties if an outage affects service availability or data integrity.
NCSC’s guidance on responding to disruptive cyber attacks notes that highly disruptive incidents can take weeks or months to recover from fully, and recovery needs to prioritise business-critical systems and protect staff welfare throughout, not just get the site back up as fast as possible. That’s a longer timeline than most small business owners budget for mentally, and it’s worth having at least a rough sense of your contractual and regulatory exposure before an incident happens rather than during one. A conversation with a solicitor who understands your sector is worth more here than general guidance, ours included.

Our take on where small businesses should actually spend their resilience budget
We’d rather see a small business owner spend a Saturday testing their backup restore than another pound on a hosting upgrade they don’t need yet. Tested backups and basic monitoring catch the overwhelming majority of real-world incidents; elaborate failover systems solve problems most small sites don’t have. The gap we see most often isn’t a missing tool, it’s a backup nobody’s ever actually restored from, which isn’t a safety net at all. Start there.
— Chris
How our maintenance plans keep your site from going dark
We built our WordPress Maintenance and UK Web Hosting plans around exactly the checks we’ve described above, done for you rather than left on your own to-do list. These plans include ongoing monitoring, scheduled maintenance windows communicated in advance, backups that are tested rather than assumed to work, and a direct contact to call when something goes wrong.
- WordPress Maintenance, from £30 per month per site, covers routine patching, plugin updates and backup management.
- UK Web Hosting, from £15 per month, gives you a server we monitor rather than one you’re left checking yourself.
- Our bespoke web applications team also builds resilience considerations into anything business-critical from the start.
If your current setup has you checking your site manually out of habit, that’s usually the first sign it’s time for something managed. Get in touch through our services page and we’ll walk through what your site actually needs.
FAQ
What are the causes of downtime?
The main causes are hosting or server failures, DNS and SSL certificate problems, cyber attacks such as DDoS or ransomware, software or deployment errors, traffic spikes, and human error. Splunk’s 2026 research found human error implicated in about 43% of unplanned downtime events, making it one of the biggest single contributors.
Why are so many websites going down today?
Websites go down for a mix of reasons that rarely act alone, and Uptime Institute’s outage analysis notes that major outages commonly have multiple interrelated causes rather than one isolated fault. Power issues, network and provider faults, software errors and human mistakes during changes all remain leading contributors.
How to fix a website down issue?
Start by checking your monitoring dashboard or your host’s status page, then verify your DNS and SSL certificate haven’t expired, and check recent error logs for anything that changed. If the fault traces back to your host or network, contact them with timestamps and your diagnostic results; if it’s a cyber attack, follow NCSC’s immediate recovery guidance on triage and containment.
Why is everything going down on websites?
It’s rarely “everything” at once, more a cluster of the same few root causes recurring across many sites: ageing hosting infrastructure, unpatched software, misconfigured DNS, and human error during updates or deployments. Diagnosing in a fixed order, DNS, then TCP, then TLS, then HTTP, as Uptime Institute practitioner guidance recommends, narrows down which of these is actually responsible rather than guessing.
Sources
- The $600 billion wake-up call: new Splunk research reveals downtime is a systemic business crisis
- Annual outage analysis 2026: The causes and impacts of IT and data centre outages
- Disruptive cyber attacks, recovering: immediate activities
- Mitigating malware and ransomware attacks
Recommended
- Zero downtime for small business sites: Move your site to a new host
- Working in Minutes: SSL Certificate Setup for UK Small Businesses
- Cloudflare for small business: practical setup guide
- WordPress maintenance plans for small businesses in Derbyshire and South Yorkshire
Related reading: WordPress maintenance plans for small businesses · Microsoft 365 backup options




