A WordPress site serving businesses in Bern sits next to the Bundeshaus at Bundesplatz, canton Bern administration and Swisscom headquarters in Bern-Ost. That proximity does not turn a marketing site into admin.ch. It does mean updates, backups, logs and form integrations are discussed before the first production change, not as an appendix after an incident that triggers a question from legal about nFADP and the Federal Data Protection and Information Commissioner (FDPIC, EDÖB in German).
WPPoland delivers ongoing WordPress maintenance from a senior Polish team for businesses, public-sector suppliers and organisations with a base, branch or client base in Bern. Scope is WordPress maintenance: tested updates, daily backups, security and performance monitoring, incident response under a written SLA, and up to four hours of small development changes per month. Custom theme builds and plugin development are separate topics, described on the WordPress developer in Bern page.
#WordPress maintenance in Bundesstadt and canton Bern
Bern is not Basel with pharma and the stock exchange, nor Geneva with the UN and WTO. It is Bundesstadt: seat of the Federal Council, parliament and key federal offices around Bundesplatz. Canton Bern adds its own administration, universities and a dense network of IT suppliers serving public procurement. Swisscom, headquartered in Bern-Ost, is one of the city’s largest technology employers, but a maintenance brief here rarely reads “monitor us like a telecom operator”. More often it reads: inherited install with three multilingual plugins, German text appearing on the French version after a Core update, editorial team in Poland, and a reviewer in Bern asking whether the consent plugin sends IP addresses to the US without legal basis.
For WordPress maintenance those facts translate into three recurring requirements. First, update discipline: Core, plugins and themes ship through staging, with regression checks in both DE and FR before production promotion. Second, decision trail: who approved the update, what changed, what was rolled back, and what remains in the monthly report. Third, residency and retention: backup location, log retention and processor documentation are recorded in the runbook, not assumed because hosting sits in Switzerland.
Bern Digital Hub at Wylerstrasse and nearby coworking spaces (Impact Hub Bern, Biel/Bienne in the agglomeration) add reviewers who ask whether restore was tested last quarter and whether wp-admin logs show who installed a plugin on Friday afternoon. The University of Bern (Universität Bern) and Bern University of Applied Sciences (BFH) produce people who can tell theme from plugin and know that Polylang does not replace an editorial process. Commuters from Biel/Bienne, Thun and Solothurn work in one office in German and French, so a DE/FR front with Polish editorial back office is more common here than a purely Polish front with a German panel.
The typical brief that reaches maintenance does not read “keep it updated somehow”. It reads: last Core update was eight months ago, backup plugin shows green but nobody has restored since 2022, WPML or Polylang serving German text on the French version after a patch, and a new official publication broke layout because someone updated Elementor without staging. That is an operations and process problem, not a marketplace-theme problem.
WPPoland is not a contractor for admin.ch or canton Bern. Proximity to the Bundeshaus sets the bar for documentation, roles and bilingual delivery. It does not set a list of government references.
#What the monthly maintenance package includes
Maintenance in Bern is a written SLA, not a vague “we look after the site”. The monthly package covers:
- Tested updates: WordPress core, plugins and themes updated on staging first. Regression checks cover front templates, forms, DE/FR language pairs, consent banners and critical user journeys. Production promotion follows a documented step with rollback path.
- Daily backups with 30-day retention: automated backups stored in geographically separate locations. Restore is tested on staging at onboarding and at least quarterly thereafter. A backup that has never been restored is decoration, not recovery.
- Security monitoring: malware scanning, file integrity checks, login attempt monitoring, WAF rules tuned for WordPress attack vectors, and quarterly security review of plugin inventory and admin accounts.
- Uptime and performance monitoring: synthetic checks at one-minute intervals, PageSpeed and Core Web Vitals tracking on templates that actually exist (not only the homepage), alerts via Slack and email.
- Small development hours: typically two to four hours per month for content-model tweaks, block fixes, form adjustments, accessibility patches and editorial workflow improvements without opening a separate project.
- Priority support: sub-four-hour weekday response for priority tickets. Confirmed security incidents and production outages trigger the SLA workflow outside hours where the contract covers it.
- Monthly status report: metrics (uptime, backup success, update log, performance trend), decisions taken, remaining risks, and incident summary if applicable.
Pricing is individual and delivered in writing after scope is agreed. There is no rate card on this page.
#Onboarding audit and inherited installs
Every engagement in Bern starts with an onboarding audit, usually about one hour on the live install plus follow-up on staging setup. The audit documents:
| Area | What is checked |
|---|
| Plugin inventory | active plugins, last update dates, known CVEs, overlap with consent and cache layers |
| Hosting | PHP version, memory limits, object cache, TLS, CDN, CH residency if contract requires it |
| Backups | schedule, retention, last successful restore test, off-site copy |
| Security | admin accounts, 2FA, file permissions, XML-RPC, file editor, secrets in Git |
| DE/FR setup | Polylang or WPML configuration, hreflang, broken language pairs, string sync |
| Performance | Lighthouse baseline on homepage, CPT archive and a representative landing in both languages |
| Compliance hooks | consent plugin behaviour, form data flows, log retention, privacy policy links |
Inherited installs are common. The first month often involves more remediation than routine maintenance: patching vulnerable plugins, fixing broken backups, removing malware, stabilising a DE/FR pair that drifted apart, or moving secrets out of wp-config.php in Git history. Remediation is listed with priorities before steady cadence begins. Steady maintenance does not start on a site where restore has never been verified.
#Tested updates and staging discipline
The most expensive maintenance failure in Bern is not a missed minor plugin update. It is a Core or major plugin update pushed to production on a Thursday because “it looked fine on localhost”, breaking the French version of a federal publication template the day before a public-consultation deadline.
Staging is a production copy with anonymised data. WP-CLI search-replace on URL, separate keys, crons that send mail to real addresses disabled. Editorial and IT click through staging with real Gutenberg patterns in both languages, not on the developer’s laptop. Multilingual regression, form submission and keyboard navigation happen here.
Production promotion is a documented step: tag or merge, asset build, cache warmup, rollback path to the previous tag. The team does not “quick upload” one PHP file over SFTP, because nobody can reconstruct what was on production on Friday before a canton Bern publication goes live.
Update cadence follows risk, not calendar superstition. Security patches for actively exploited CVEs move faster than cosmetic plugin updates. Major version jumps (PHP, Core, WooCommerce if present) get their own written plan and acceptance criteria. WooCommerce stores are a separate scope; if the brief includes checkout, see WooCommerce developer in Bern.
#Backups, restore and hosting in Switzerland
Hosting “in Switzerland” is a jurisdiction argument in procurement, not a magic shield. A form collecting personal data without legal basis is not fixed by a server in Bern-Ost alone. Maintenance still records where backups live, whether off-site copies cross borders, and what the client’s processor agreement requires.
Practical backup rules written into the runbook:
- Daily automated backup of files and database, 30-day retention minimum unless contract says otherwise.
- Off-site copy in a separate region or provider from production.
- Restore test on staging at onboarding, then quarterly. The test produces a timestamped note in the monthly report.
- Backup encryption at rest where the hosting stack supports it.
- Documented recovery time objective agreed in the SLA, not invented after an outage.
If the client requires backups to remain in CH, that is a contract topic checked at onboarding against the actual provider configuration, not an assumption from the TLD.
#Security, nFADP, FDPIC and GDPR in cross-border briefs
Proximity to the Bundeshaus and Swisscom does not turn a marketing WordPress site into a federal classification system. WPPoland does not claim “ISO 27001 compliant” or “NCSC certified” unless the client ran that audit. Maintenance delivers inventory, access trail and update discipline the client can paste into procurement or processor-agreement documentation, not an agency compliance stamp.
Posture maintainable in code and process:
- No secrets in Git. Keys, database passwords and CRM tokens go through environment variables or outside the repo.
- Admin accounts use 2FA. Polish editors do not get install_plugins on production. Roles are cut to what Gutenberg requires.
- XML-RPC stays disabled unless a justified client needs it. File editor in the admin too.
- Headers: HTTPS, HSTS where certificate and CDN allow, CSP matched to real scripts (consent, tag manager, fonts).
- Dependencies: pinned plugin versions, CVE awareness, updates on staging before production. Unpatched Core is worse than skipping a new “security” plugin.
- Logs: who logged into wp-admin, which plugin change shipped when. Retention agreed with nFADP and client policy, not “keep everything forever”.
The revised Swiss Federal Act on Data Protection (nFADP) and, where EU data subjects are involved, GDPR are separate layers. Maintenance supports the data controller with evidence: what personal data the site processes through forms and analytics, which subprocessors touch it, where backups and logs sit, and what happened during an incident. After a personal-data breach the client may need to notify FDPIC; logs and the incident timeline must fit a notification workflow. WPPoland documents interventions with timeline, root cause and remediation steps. It does not file on behalf of the data controller.
Penetration tests are mentioned only when the client has or orders them from a lab. Hardening WordPress is a set of operational decisions recorded in the monthly report, not a slide about zero incidents.
#DE/FR bilingual maintenance
The most common post-update regression in Poland-Bern collaboration is not PHP fatal errors. It is the French version showing German strings because a plugin update reset language mappings or because someone edited the DE page and the FR copy was never synced.
Maintenance for bilingual sites in Bern includes:
- Regression checks in both language versions after every staging update cycle.
- Monitoring for hreflang errors and broken language switcher links.
- String-level awareness: consent banners, form errors and aria-labels must stay aligned across DE and FR.
- Editorial freeze windows recorded in the runbook (parliamentary session, public-procurement deadline) when production changes require explicit approval.
- Monthly report note when a language pair was touched, what was verified, and what remains for client-side FR or DE approval.
Polylang and WPML solve hreflang and language copies. They do not solve process: who approves German text, who approves French, before production. The maintenance runbook records whether approval sits with the client in Bern, with the Polish content lead, or both in parallel.
#Monitoring, SLA and incident response
Monitoring combines synthetic uptime checks, application-level alerts and security scanning. Alerts route to Slack and email with enough context to triage without logging into five dashboards.
Incident management follows ITIL-lite: detection, triage, resolution, post-mortem. Every confirmed incident gets a root cause summary within 48 hours. SLA compliance is tracked against the contracted uptime tier, with monthly reports surfacing target and actual rather than a marketing number.
Priority tickets: sub-four-hour response on weekdays. Confirmed security incidents and production outages: response outside hours where the SLA covers it. The intervention is logged with timeline, containment steps, remediation and follow-up risks. That log is what legal and IT in Bern need when asking “what happened between 14:00 and 16:30 on Tuesday”.
Communication runs through a written ticketing channel. Calls unblock decisions; they do not replace the audit trail.
#Performance maintenance
Speed in Bern is not vanity. Public-sector suppliers and B2B firms compete on credibility; a site that loads in four seconds on mobile loses form completions and signals neglect to reviewers accustomed to federal project standards.
Performance maintenance includes:
- Core Web Vitals tracking on real templates: homepage, CPT archive, single, hero pattern page in DE and FR.
- Image pipeline review: AVIF/WebP delivery, responsive srcsets, lazy loading without breaking LCP.
- Cache layer health: object cache hit rate, CDN cache rules, transient bloat from abandoned plugins.
- Database hygiene: autoloaded options audit, revision limits, orphaned post meta from retired plugins.
- Quarterly performance trend in the monthly report with before/after when a change was shipped.
Performance budgets are set at onboarding and checked against lab and, where available, CrUX field data. Regressions after updates are caught on staging, not discovered by the client on Monday morning.
#Relationship to development and handover
Maintenance is the steady state after launch, or the rescue lane for a site that outgrew DIY updates. If the site needs a new block theme, custom plugin or large refactor, scope moves to WordPress developer in Bern. If the site needs checkout, TWINT or product catalogues, scope moves to WooCommerce developer in Bern.
Development engagements end with a runbook: how to add a pattern, how to ship a branch, how to rebuild staging, whom to call when the editor will not save. Maintenance picks up that runbook and keeps it current as Core, plugins and hosting evolve. A handover without a runbook is a support ticket waiting to happen.
#Bern Digital Hub and the local tech scene
Bern Digital Hub at Wylerstrasse 60A is a reference point for Bern’s digital ecosystem: meetups, networking, projects linking administration, startups and IT suppliers. It is not a WPPoland sales argument. It is a barometer: editorial and IT teams in Bern ask about restore tests and staging because they heard those questions at local meetups and in BFH corridors.
Impact Hub Bern and nearby initiatives add reviewers who read monthly reports, not only marketing copy. Swisscom as an employer sets the bar for suppliers in the chain: questions about data location and log retention appear earlier than on a typical Polish B2B market. For Bern, DE/FR bilingual delivery, public-sector adjacency and canton Bern procurement culture matter more than pretending to be Zurich banking or Geneva diplomacy.
#How to start maintenance in Bern
A short brief is enough to begin: which theme and plugins exist today, who edits (PL/DE/FR), when backups last restored successfully, whether the front is bilingual, where hosting sits and whether backups must stay in CH, and whether Bern IT requires Git and staging from day zero. WPPoland reviews the install, lists risks (unpatched Core, secrets in repo, broken DE/FR pair, consent plugin sending data outside CH) and proposes a plan with acceptance criteria and SLA terms.
Contact: WPPoland contact form. The service pillar without city in the slug remains at WordPress maintenance. Custom development in Bern is at WordPress developer in Bern.