We are spending more on managing servers than on the servers themselves.
Hosting brings in roughly $42,000 a year and costs about $20,700 to deliver. Over half of that cost is people, not machines — and most of the people cost traces back to one unsolved technical problem: nothing stops a single site from taking down everything next to it.
Annual revenue$41,998
Annual cost$20,728
Gross margin51%
Cost / account / mo$20.81
Unpriced riskServer management rests on Andy, Cloudflare rests on John. If either is unavailable, all 88 sites are exposed — and no line in this report captures it.
What we run today
Three servers, named for months
Each is an AWS Lightsail 2XLarge — 8 vCPU, 32 GB memory, 640 GB SSD, 7 TB transfer, at $164 a month. All three run cPanel/WHM and Imunify360, with per-site backups to Backblaze B2. Clients pay $33 a month plus $110 a year for SSL.
November
Lightsail 2XL · cPanel Premier
43 accounts
Paying sites43
Server cost / mo$258.74
Cost per account$6.02
Carrying its weight. Densest server, lowest unit cost.
October
Lightsail 2XL · cPanel Premier
35 accounts81%
Paying sites35
Server cost / mo$258.74
Cost per account$7.39
Healthy. Room for another 8 sites before anything changes.
September
Lightsail 2XL · cPanel Pro
1023%
Paying sites5 of 10
Server cost / mo$242.74
Cost per paying site$48.55
Held deliberately light. Heavy sites live here so they don't crowd the others — isolation bought with hardware, at 8× November's unit cost.
Meter fill compares account count against November, the fullest server. Server cost combines the Lightsail instance, its cPanel licence and Imunify360.
September is doing real work — just expensively
It's kept sparse on purpose: a handful of resource-hungry sites are spread across servers rather than stacked on one, so they don't starve their neighbours. That's a sound instinct, and it's the correct response to the tooling we have. But it means we're buying isolation in $164 increments of hardware, when per-site limits do the same job in software for $13–16 a month across the whole fleet.
Two more sites land on September before year end, taking it to 12 accounts and 7 paying. That tips it from a small monthly loss to roughly $52 a month positive — still at $34.68 per paying site against November's $6.02. The gap is what hardware-based isolation costs.
Where the money goes
Labour is 54% of the cost of operations
Licensing gets all the attention because the invoices arrive on a schedule. But cPanel is the fourth-largest line in the business. The two labour lines together are nearly five times bigger.
Infrastructure $9,603 (46%) · Labour $11,125 (54%) · Total $20,728
Line item
Basis
Monthly
Annual
Client fees
83 paying sites × $33
$2,739
$32,868
SSL fees
83 sites × $110/yr
$761
$9,130
Revenue
$3,500
$41,998
AWS Lightsail
3 × 2XLarge @ $164
$492
$5,904
cPanel/WHM
2 × Premier, 1 × Pro
$194
$2,328
Imunify360
3 servers @ $24.75 — to retire
$74
$891
Backblaze B2
actual billed rate — S3 target, portable
$40
$480
Andy — server upgrades
$750 × 3.5 rounds
$219
$2,625
Andy — emergencies & general
midpoint of range
$250
$3,000
Security team
Imunify & Cloudflare rules
$458
$5,500
Total cost
$1,727
$20,728
Gross margin
51%
$1,773
$21,270
Clients are invoiced annually, with bills going out between November and early January. Revenue is shown as a monthly average for comparison against costs, which are genuinely monthly. Labour lines use the midpoint of the ranges given.
What's actually wrong
Three cost problems, one root cause
Expensive fix
We isolate with hardware
$164/mo
Heavy sites get spread across servers so they don't crowd their neighbours. It works, but a whole instance is the most expensive unit of isolation available — software limits do the same job fleet-wide for a tenth of it.
Not working
Spreading sites isn't isolation
43 sites
Three servers exist partly to contain blast radius. But without per-site limits, one bot storm on November still takes down the other 42 sites with it. We're paying for a safety strategy that doesn't hold.
Rework
Security time is mostly cleanup
$5,500/yr
Storm hits, someone writes a blunt Cloudflare rule to stop it, the rule breaks normal site behaviour, someone unwinds it. That loop is a symptom of missing isolation, not security work — and Imunify, tuned for WordPress, is not catching enough to break the cycle.
The pattern worth naming
Every expensive line traces back to the same gap: no per-site resource ceiling. It drives the emergency callouts, it drives the Cloudflare rule churn, and it's why we spread heavy sites across whole servers instead of capping them individually. None of these are mistakes — they're the right moves given the tooling. But they're all workarounds for one missing capability, and fixing that capability is the only change that moves several lines at once.
Key-person risk
Our bus factor is one. Twice.
Every other problem in this report costs money. This one can stop the business. Splitting work between server management and security feels like redundancy, but each half still rests on one person — so the split shared the workload without sharing the risk. Imunify is the exception, and it shows what the rest should look like.
AndyBus factor 1
Server management · deployment · Imunify
Only Andy can
Run the upgrade cycle across all servers
Respond to a server-down emergency
Build and provision a new server from scratch
Diagnose anything below the cPanel interface
If unavailable: no upgrades, no new client onboarding, and an outage lasts until we find and brief an outside contractor on infrastructure nobody has documented.
JohnBus factor 1
Cloudflare security
Only John can
Write and unwind Cloudflare rules under pressure
Tell which of 88 zones has which custom configuration
Judge whether a traffic spike is an attack or a customer
Undo a rule that has broken a live site, quickly
If unavailable: bot storms get met with guesswork, and 88 zones of per-site tuning become undocumented state nobody can safely change. Nothing in this column is shared with anyone.
Malware & server securityCovered — two people
Both Andy and the owner can run Imunify, so this is the one area where losing a person does not stop work. It shows the fix is not complicated: a second person who has actually done the task, not read about it. Imunify is being retired, so the point to carry forward is the arrangement rather than the tool — whatever replaces it gets set up by two people from day one. Everything above needs to look like this.
Why the migration is the moment to fix this
Right now the knowledge is tribal: it lives in two heads and in the accumulated hand-tuning of 88 Cloudflare zones and three hand-built servers. A platform change forces all of it into the open, because everything has to be rebuilt deliberately rather than remembered.
That cuts both ways. Done carelessly, migrating to Enhance increases the exposure — a new platform only Andy understands is worse than an old one only Andy understands. Done deliberately, with two people learning it side by side and a runbook written as we go, it is the cheapest chance we will get to fix this.
What actually reduces the exposure
Two people in every pilot session. Not a handover afterwards — a second person present while the platform is being learned, doing the work rather than watching. Handover documents written after the fact are the ones nobody can follow.
Templated Cloudflare rules replace tribal knowledge with a file. This is a second, larger reason to do the rule templating first. One versioned rule set pushed by API is readable by anyone; 88 hand-tuned zones are readable by John.
Automated panel updates shrink the job. Both Enhance and Ploi handle server updates themselves, so the recurring upgrade cycle stops depending on one person remembering the sequence. It reduces the dependency rather than removing it.
Write the SOPs during training, not after. Provisioning a server, restoring from Backblaze, onboarding a client, pushing a Cloudflare rule, responding to a storm. The person being trained writes the document as they are walked through the task — that way the gaps show up immediately, while the expert is still in the room. Procedures written afterwards by the person who already knew how are the ones nobody else can follow.
Keep the SOPs in Google Docs and Strattum. Google Docs for drafting and comments during training, Strattum as the durable home the team actually works from. Two locations only helps if one is clearly the source of truth — worth deciding now which that is, and having a rule that a procedure is not finished until it lands there.
A named outside fallback. Even with cross-training, two people is thin. Worth identifying a contractor or agency who could pick up the platform cold — which is far more realistic on a documented Enhance cluster than on three bespoke cPanel boxes.
Options
Four ways forward, priced
Each option is cumulative, and every row below folds September’s sites onto the remaining servers. Important ordering note: that consolidation is only safe after per-site limits are in place. Doing it first would put the heavy sites next to 35 unprotected neighbours — exactly the risk September exists to avoid.
Do nothing3 servers · cPanel
$20,728baseline
Consolidate only2 servers · no isolation
$17,190−$3,538
Add CloudLinux2 servers · cPanel + LVE
$15,574−$5,154
Replace cPanel with Enhance2 servers · containers · no Imunify
$11,718−$9,010
Option
Infra
Andy
Security
Total
Margin
Do nothing
$9,603
$5,625
$5,500
$20,728
51%
Consolidate to 2 servers
$6,690
$5,000
$5,500
$17,190
59%
+ CloudLinux LVE limits
$7,074
$4,000
$4,500
$15,574
63%
+ Enhance, Imunify retired
$4,968
$2,750
$4,000
$11,718
72%
What each option changes
Consolidate to two servers. Move September's accounts onto the remaining boxes. October stays well inside cPanel Premier's 100-account tier, so licensing doesn't change, and we delete a $164 instance, a $53.99 licence and a $24.75 Imunify seat. The saving is real, but this is not risk-free on its own — the heavy sites lose the elbow room they currently have. It only works paired with limits.
CloudLinux. $16 per server per month at the 2–4 server tier. Adds LVE resource ceilings per cPanel account, so a hammered site throttles itself instead of the server. Installs on top of what we already run — the conservative path if we want isolation without changing how the team works.
Enhance. $0.15 per site per month with no per-server fee — about $13 a month for all 88 sites, replacing a $140 cPanel bill. Every site runs in its own container, so isolation is native rather than layered on. Its importer pulls cPanel accounts over SSH or the WHM API with databases, mail and DNS intact. Backups are included at no extra cost: incremental, deduplicated with hard links so only changed files copy, with frequency, retention, initial delay and minimum backup age all configurable — nightly is straightforward. They target a server in the cluster or any S3-compatible provider, so our Backblaze setup survives the move. Restores are granular: a whole site, a single file, a database or a mailbox, and clients can self-serve them from the UI.
Deliberately not recommended: splitting into more servers. Holding every server under 30 accounts would drop them all from Premier to Pro licensing, saving $32 a month. But each server we keep costs $164 in compute and roughly $73 a month of Andy's upgrade time. Once labour is priced in, fewer larger servers beat more small ones — the opposite of what the licence tiers alone suggest.
Replacing Imunify
Imunify is $891 a year and, by our own experience, underperforms. A good part of why: its headline features — CMS core-file cleanup, vulnerability patching, the WordPress toolkit angle — are built around WordPress, Joomla and OpenCart. We run Contao. We are paying full price for a product whose best work does not apply to our stack.
Dropping it does not mean dropping protection. Two layers replace it, and between them they cover more than we have now:
Enhance covers the structural half natively. It ships ModSecurity with pre-configured OWASP rules across Apache, Nginx and LiteSpeed, brute-force protection, optional 2FA for end users, and per-website caps on CPU, I/O, IOPS, processes, swap, inodes and memory. Critically, every site runs in its own container, which stops malware spreading between sites rather than merely detecting it after the fact.
cPFence covers scanning and cleanup, and is built for Enhance. $0.10 per website per month with a $5 minimum — about $9 a month for our whole cluster, against $74 for Imunify. It runs on every Enhance role including email and database-only servers, adds real-time malware detection with automatic cleaning, DDoS protection and an abusive-IP blocklist. Only main domains count; staging and service domains are free, same as the Enhance licence.
The alternatives worth knowing about: cPGuard supports Enhance and cPanel both, so it is the option if we stay on cPanel; operators migrating from Imunify to it report finding genuine embedded backdoors that Imunify had missed for years, which matches our own sense that it is not catching much. BitNinja costs more and one operator who tested all three rated it highest, with per-website pricing available for Enhance hosts. Any of the three is a defensible pick; cPFence is the cheapest and the most tightly built for the platform.
What we gain and what we give up
Net saving is $785 a year on licensing, but that is the least interesting part. The real change is that malware containment stops depending on a scanner noticing something and starts being a property of how sites are run — each one in its own container, unable to reach its neighbours. Detection becomes the second line rather than the only one.
What we give up is a single WHM-integrated dashboard. cPFence runs its own web console rather than living inside the Enhance UI, so the team works in two places. Worth confirming during the pilot that this is acceptable day to day, because it is a workflow cost rather than a licensing one.
Candidate review
What Enhance actually gives us
Everything below is what the platform ships as standard, gathered in one place so the team can pick it apart. Treat it as a starting position rather than a decision — if someone has used a panel that does this better, that is worth more than anything in this document.
01 Isolation
A container per website
Every site runs in its own lightweight Linux container, even under the same subscription. This is the thing we are actually buying — malware cannot cross between sites and a storm cannot spill sideways.
Per-website resource caps
CPU, I/O bandwidth, IOPS, process count, swap, inodes and memory, each overridable per site. Heavy sites get bigger ceilings instead of their own server.
Move sites between servers on the fly
Relocate a site or swap its web server without reconfiguration, so rebalancing stops being a migration project.
02 Backups
Nightly incremental, included
Frequency, retention, initial delay and minimum backup age are all configurable. Deduplicated with filesystem hard links, so only changed files copy.
Backblaze keeps working
Targets a server inside the cluster or any S3-compatible provider. Our existing B2 destination carries over rather than being rebuilt.
Granular, self-service restores
A whole site, one file, a database or a mailbox. Clients can restore themselves from the panel, including sites they have deleted, which takes those requests off our desk.
Server loss recovery
Restore sites onto a different server in the cluster from the latest backup.
03 Security
ModSecurity with OWASP rules
Pre-configured across Apache, Nginx and LiteSpeed rather than hand-tuned per server.
Brute-force protection and 2FA
Built in, with optional TOTP that end users can turn on themselves.
Written in Rust
Rules out memory-safety bug classes at the compiler level. Not a feature we will ever notice working, which is the point.
cPFence covers scanning
$0.10/site/mo · ~$9/mo for the cluster
Real-time malware detection and cleanup, DDoS protection, abusive-IP blocklist. Runs on every role including mail and database-only servers.
04 Operations & cost
No per-server licence
$0.15/site/mo · ~$13/mo for all 88
One cluster licence covers unlimited servers. Staging sites, addon and alias domains, service domains and soft-deleted sites are never billed — so our five dev accounts likely cost nothing.
Single-command server deployment
New servers join the cluster and inherit global service settings automatically. This is the line that attacks Andy’s $500 setup fee and the $750 upgrade rounds.
cPanel importer
Pulls accounts over SSH or the WHM API with databases, mail and DNS intact.
Full REST API
Every function is scriptable, which is what makes fleet-wide changes repeatable instead of manual.
Client panels and email included
Client-facing accounts and mail hosting, no add-on licence.
05 What to push back on
It expects more sysadmin depth than cPanel
Consistently reported by practitioners. This is the main reason to run the pilot with two people and budget real ramp-up time.
Multi-server is the design assumption
Control panel, web, database and backup are separate roles. A single box is fine to evaluate, not to run production. No per-server fee makes this cheap, but it is more moving parts than three cPanel machines.
Cloudflare needs the panel IPs whitelisted
Inter-server traffic gets challenged otherwise, and we lock ourselves out of our own backend. Worth knowing before day one rather than during it.
S3 backup target is still beta
Run the native cluster backups alongside it and prove a Backblaze restore before relying on it.
cPFence lives outside the Enhance UI
Its own console, so the team works in two places. A workflow cost, not a licensing one.
The WordPress toolkit is dead weight for us
Bundled free, and we are a Contao shop. Worth naming so nobody counts it as value in the comparison.
Questions worth bringing to the review
Does anyone have hands-on time with Ploi, RunCloud or Enhance in production? Is there a panel that gives per-site isolation with a gentler operational learning curve? And is there a reason to keep cPanel that we have not accounted for — a client expectation, an integration, a workflow the team depends on that would cost more to rebuild than the licence saves?
Recommended sequence
Four moves, and the order matters
Ordered so that isolation is proven before we rely on it, and so that no step deepens our dependence on one person. The consolidation saving is tempting to take first, but it is the one move that depends on everything else working.
The billing calendar sets the window
Invoices go out between November and early January, so clients pay for the year up front. That means two things: the migration work should land between February and October, well clear of billing season, and any savings we capture mid-year drop straight to margin without touching a single invoice. It also means the November cycle is the natural moment to communicate anything client-visible.
Now · targets $5,500/yr
Template the Cloudflare rules
Eighty-eight zones are currently tuned by hand. Build one standard rule set — rate limits on expensive paths, Contao-aware cache rules, AI crawler blocks — and push it to every zone through the Cloudflare API. Roughly 20 hours against the single largest labour line. It depends on nothing else and pays off whichever panel we end up on — and it converts John’s per-zone knowledge into a versioned file anyone can read, which is the cheapest key-person fix available to us. Write the SOP for pushing and rolling back a rule at the same time.
February onward · proves the thesis
Pilot Enhance on one new server
Stand up a fresh instance and migrate 10–15 lower-stakes Contao sites. Then deliberately load-test one of them to confirm the containers hold and the neighbours stay up. That test is the whole decision — if per-site limits genuinely contain a storm, every other saving follows. Run this with two people, not one, and write the SOPs as you go. Enhance expects more sysadmin depth than cPanel, so budget $1,000–1,500 of ramp-up — spend it on two people learning together, with the second person drafting each procedure in Google Docs while Andy walks it through. Anything that cannot be written down clearly is a gap worth finding now rather than during an outage.
Only after step 2 passes
Move the heavy sites, then retire September
Once limits are proven, September's resource-hungry sites can share a box safely and the instance comes out — $2,913 a year in compute, licence and Imunify seat. Doing this before the limits are proven would undo the exact protection September currently provides, so the order here is not negotiable. Note the two new sites landing on September before year end may make it simpler to place them on the pilot server from the start.
By October · locks in $9,100/yr
Migrate the rest and retire cPanel
Move the remaining sites, drop the cPanel licences, and move the SOP set from Google Docs into Strattum as the finished reference. Wrap up before the November invoices go out so the new platform gets a quiet quarter ahead of billing season. The exit test has two parts: the second person provisions a server and onboards a client working only from the SOPs with Andy out of the room, and we restore one real site from a Backblaze backup end to end. If that works, the migration is done and the key-person problem is genuinely fixed. If it does not, we have found the gap cheaply.
Open questions
What we should check before committing
Does the replacement scanner actually catch more? We are dropping Imunify because it underperforms, so the pilot should test that claim rather than assume it. Run cPFence against a site with a known injected file and confirm both the detection and the automatic cleanup before trusting it across the fleet. Cheap to do, and it is the one decision here we would be taking partly on other operators’ word.
Enhance’s S3 backup target is still marked beta. Its own cluster-to-cluster backup service is mature and can run alongside S3, so the sensible pilot posture is both: cluster backups as the working restore path, Backblaze as the off-site copy. Confirm during the pilot that a Backblaze-sourced restore actually completes, rather than assuming it. A backup nobody has restored from is not a backup.
Which sites are the heavy ones, and how heavy? Before we size anything we should know what the resource-hungry sites actually consume at peak. That number sets the per-site ceilings and tells us whether two servers is genuinely enough once September folds in. It is now the last real unknown in the model.
The SSL line is our most fragile revenue. $9,130 a year — 22% of the top line — for certificates that both cPanel AutoSSL and Enhance issue free through Let's Encrypt. Nothing to fix today, but it's a bigger number than the entire security labour budget, and it only survives as long as no client prices it independently.
Annual billing hides the monthly burn. Roughly $42,000 arrives between November and January and has to cover twelve months of costs that leave every month. That is not a problem at current margins, but it means a mid-year cost increase has no revenue response until the next billing cycle — another argument for fixing the labour lines now rather than after they grow.
AWS is not the cheapest floor. A Hetzner AX42 gives 8 dedicated cores and 64 GB for around €99 — roughly half our per-server compute cost. Hetzner has raised prices four times in 2026, so the gap is narrower than it was, but it's still real. Worth revisiting after the panel change is proven, not alongside it.