Investor Relations Websites

IR Website Hosting, Security and Reliability

VendorGroup

Evaluate IR website hosting, security, and reliability through access controls, backups, recovery plans, third-party dependencies, and measurable service terms.

IR website hosting should be evaluated through the information and services the company needs to keep available. A proposal should explain who protects publishing access, how recovery works, which dependencies are monitored, and what happens when an investor journey fails.

Separate hosting capacity, security controls, and service response. They are related, but a single uptime percentage does not describe all three.

Define what reliability means for this site

List the critical journeys: accessing results, opening filings, joining an event, using contact forms, and subscribing to alerts. Identify the services behind each one and the person responsible for coordinating a failure.

A website can load while a connected service is unavailable. Ask how the provider measures both page availability and the completion of important tasks. The monitoring and support guide develops that operating model.

If the agreement includes an availability target, review the measurement period, monitored endpoints, exclusions, reporting, and remedies. Distinguish a response-time commitment from a restoration-time commitment. Evaluate the terms as written rather than assuming that a marketing percentage covers every component.

Protect the ability to publish

Use named accounts, appropriate permissions, and a documented offboarding process. Identify who controls the domain registrar, DNS, hosting, CMS, and external integrations. The company should know how access is recovered if a key person or supplier becomes unavailable.

CISA recommends multifactor authentication, prioritizing administrative accounts and stronger methods where possible. [1] Include those requirements in the access plan and verify their implementation, rather than relying on a platform's statement that the option exists.

Keep draft and embargoed material in a protected environment. Review who can access previews and how files are delivered. Search-exclusion settings should not be treated as a substitute for access control.

Test recovery rather than counting backups

Specify what is backed up: content, assets, configuration, and any data needed to restore the agreed service. Ask how backups are protected, how long they are retained, and who performs restoration.

CISA's ransomware guidance recommends protected backups and recovery preparation. [2] The practical acceptance question is whether the operator can restore the site to a verified usable state, not simply whether a backup job reports success.

Agree on recovery objectives appropriate to the company's needs. Define the acceptable interruption and the amount of work that might need to be recreated. Record the results of a restoration exercise and the dependencies it revealed.

Review third-party dependencies

Create an inventory of filing feeds, market data, webcast platforms, alert services, analytics, and other integrations. Record the supplier, account owner, credentials owner, renewal terms, and fallback behavior for each.

The EDGAR feed guide explains why source availability and website display are separate. Test whether the filing archive remains understandable when a feed is delayed or unavailable.

Include accessibility responsibilities for connected services. The accessibility guide explains why the investor journey should be assessed across supplier boundaries. A contract should say who coordinates remediation when the issue is outside the main website platform.

Establish a practical incident process

Define severity levels using business consequences. An incorrect public document or blocked earnings-event link may require a different response from a minor visual defect. Name the company decision-maker, technical responder, and communication channel for each level.

After an incident, record the cause, resolution, and preventive action. Use the review to improve configuration, monitoring, or ownership. NIST's Cybersecurity Framework provides a broader risk-management structure; applying a framework should not be described as a website certification. [3]

Questions companies ask

Is managed hosting enough to cover all security work?

Review the actual scope. Confirm responsibilities for accounts, software, integrations, content, incident response, and recovery.

What should an uptime commitment include?

A defined service, measurement method, reporting period, exclusions, escalation process, and contractual remedy. Ask how external dependencies are handled.

How often should restoration be tested?

Set a schedule based on the site's risk and change profile. Repeat after material changes that could affect the recovery process.

Can the company retain control while outsourcing operation?

Specify ownership and access arrangements in the contract. The company should have a clear path to accounts, exports, and continuity information.

Use these evidence requests when reviewing VendorGroup's IR website services or comparing another proposal.

Related VendorGroup resources

Primary sources

  1. CISA — Require Multifactor Authentication
  2. CISA — StopRansomware Guide
  3. NIST — Cybersecurity Framework

Contact

VendorGroup®