The Challenge
Meridian doesn't have "a website." It has a fleet — and at that scale, the dangerous question isn't "can we build sites?" It's "who's watching them after they launch?"
The honest answer was: nobody.
- Sites went dark and nobody knew. With 740+ properties spread across eleven hosting vendors, there was no shared uptime monitoring. Outages were discovered by patients, sales reps, or search rankings — not by anyone responsible for the sites.
- Hacks sat for days. When a site was compromised, it took an average of nine days for anyone to notice, because detection depended on whichever agency happened to look. For patient-facing properties in a regulated industry, nine days of injected spam or a defaced page is not a hypothetical risk — it's a headline.
- Paying a dozen vendors to not watch. Between eleven hosts and a tangle of per-agency maintenance retainers, the company was spending a blended $139 per site per month — about $1.2M a year — and none of it bought fleet-wide visibility.
- Accessibility exposure. A sample audit found only 38% of patient-facing sites met WCAG 2.2 AA. Inaccessible patient information is both a legal and an ethical problem.
- No consistent governance. Medical, legal, and regulatory (MLR) review existed on paper, but with every agency using a different publishing workflow, there was no enforcement that approved copy was the copy that actually shipped.
Meridian didn't need another agency. It needed someone whose whole job was keeping the fleet healthy — and proof, every day, that it was.
The Approach
TopSyde migrated the fleet onto a single managed WordPress platform, then put every site under continuous watch.
Step 1 — Inventory and consolidate the fleet
Before moving anything, TopSyde built a complete inventory: every site, its host, its stack, its traffic, and what it was costing. Sites were then migrated in waves onto the managed platform — same hardened core, same vetted plugin set — while preserving each site's design and content. Eleven vendor relationships and a dozen agency retainers collapsed into one flat per-site rate.
Step 2 — Turn on 24/7 monitoring, fleet-wide
Every site got uptime and performance monitoring with alerting that pages TopSyde — not a brand manager — when something breaks. For the first time, "are all 740 sites up right now?" became a dashboard, not a research project.
Step 3 — Put the whole fleet under Sentinel
Every site was placed under TopSyde Sentinel, our AI-driven security layer. Sentinel scans from outside each site, daily — verifying WordPress core against official checksums, diffing plugins against their official packages, and sweeping for backdoors, rogue admins, and injected content. In the first 60 days it surfaced 147 serious findings across the fleet, from abandoned vulnerable plugins on long-forgotten campaign sites to injected SEO spam on a regional product site — none of which the prior per-agency tooling had reported.
Step 4 — Bring the fleet to accessibility and governance standard
As part of the migration, every site was brought up to WCAG 2.2 AA, with automated accessibility checks in the publishing workflow so new content can't quietly regress. The MLR workflow became a hard gate: approved content is versioned, and what ships is provably what was reviewed.
The Results
Within the first two quarters, the fleet went from a liability nobody was watching to an asset with a heartbeat monitor:
- Time to catch a hacked or broken site fell from ~9 days to under 24 hours, because every site is now scanned and monitored daily instead of whenever an agency happened to look.
- The cost of running the fleet fell roughly in half — from a blended $139 per site per month to a flat $67, over $600K a year back — while coverage went from partial to total.
- 147 serious security holes were found and fixed in the first 60 days, every one invisible to the old per-site scanners.
- 100% of the fleet reached WCAG 2.2 AA, up from 38%, closing a standing legal exposure on patient-facing properties.
- All 740+ sites report into one portal — uptime, security status, and cost in a single view instead of eleven vendors' worth of guesswork.
Why It Worked
- Watching is a job, not a feature. Uptime monitoring plus daily outside-in security scanning on every site is the only way to keep a 740-site fleet honest without hiring a standing web-operations team.
- Consolidation paid for the upgrade. Collapsing eleven vendors and a dozen retainers into one flat rate cut spend in half — and the savings funded strictly better coverage, not just a cheaper version of the same neglect.
- Governance built into the path of least resistance. Accessibility and MLR checks live inside the publishing workflow, so doing it the fast way is also doing it the compliant way.
Frequently Asked Questions
How can one team watch 740+ sites at once?
Automation does the watching; people do the fixing. Every site gets automated uptime checks around the clock and a full Sentinel security scan daily, all reporting into one portal. Humans get paged when something needs judgment — which is how detection went from ~9 days to under 24 hours without Meridian hiring anyone.
Where did the cost savings come from?
Deduplication. Eleven hosting vendors and a dozen per-agency maintenance retainers added up to a blended $139 per site per month. One managed program at TopSyde's volume rate of $67 flat cut that roughly in half — over $600K a year — while adding the monitoring and daily scanning the old spend never included.
Did consolidating hundreds of sites disrupt the brand teams?
No. Migration happened in waves, and each site kept its design and content — only the platform underneath changed. Brand teams kept publishing throughout; what changed is that their sites are now watched, scanned, and backed up every day.
What did Sentinel find that the previous tools missed?
Across the first 60 days: 147 serious issues, including abandoned vulnerable plugins on dormant campaign sites, injected SEO spam, and outdated cores. The old per-agency tools only ever looked at one site at a time — and only from the inside, where malware can hide from them. The fleet-level picture had never existed before.
The Stack — Named, Not Hidden
We tell you exactly what runs underneath. No proprietary black box.
Business Outcomes
- →A hacked or broken site now gets caught within hours instead of sitting unnoticed for over a week — on every one of 740+ patient-facing properties.
- →Cut the cost of keeping the fleet running roughly in half — over $600K a year back — by replacing 11 vendors and a dozen agency retainers with one flat per-site rate.
- →The first 60 days of daily scanning found and fixed 147 serious security holes that the old per-site tools had never reported.
- →Brought 100% of the fleet up to accessibility standards (WCAG 2.2 AA), up from 38% — closing legal exposure on patient-facing sites.

DevOps & Security Lead
12+ years DevOps, Linux & cloud infrastructure certified
Marcus leads infrastructure and security at TopSyde, managing the server fleet and AI monitoring systems that keep client sites fast and protected. Former sysadmin turned WordPress hosting specialist.



