We're proud to share that Skpr, PreviousNext's managed Drupal hosting platform, has joined Drupal Steward as a Platform partner, one of only four in the world.
Every site hosted on Skpr now has protection from critical vulnerabilities before the public security advisory goes live whenever it is possible via Drupal Steward.
What is Drupal Steward?
Every Drupal security release follows the same pattern: Security issues are reported to the Drupal Security Team (DST). They follow a well-defined process based on the severity of the issue. Once a fix has been created, the DST publishes an advisory. At that moment, everyone is made aware of the fix at the same time.
From there it's a race:
- Bad actors work (now with the assistance of AI!) to reverse engineer an exploit from the fix and use it to attack Drupal sites.
- At the same time, website owners are trying to roll out the patch across their portfolio of sites. Highly critical vulnerabilities can be exploited within hours of disclosure. Most organisations need days or weeks to test and deploy a patch through proper change management.

Drupal Steward helps to close that gap. It's a Web Application Firewall (WAF) based solution built by the DST engineers who write the advisories. During the coordinated disclosure process, they write a protection rule alongside the fix. The moment the advisory goes public, Drupal Steward is already live - blocking the exact traffic that would exploit the vulnerability.
For Australian and New Zealand teams, this matters more than most. Drupal security advisories are typically published overnight AEST/NZST, timed around US Eastern evening hours. Without Drupal Steward, that means a choice. Set an alarm for 4am to assess and respond. Or start the day as normal, and hope an exploit hasn't already been developed while you slept.
With Drupal Steward, that choice disappears. The protection rule is already live before the advisory goes public - which, in AEST/NZST, is hours before most teams even log on. You wake up already covered.
Think of it as a virtual patch. Your team still applies the real fix, but on your own schedule, without the fire drill.
Here's an overview of the program:
https://www.youtube.com/watch?v=YpUT7UF0Q20
Why this matters for Skpr clients
As a Platform partner, Skpr receives Drupal Steward's protection rules directly, with advance notice ahead of each public advisory. That means:
- Every site on Skpr is protected the instant an advisory drops
- No individual client needs to sign up, configure DNS, or manage a separate service
- Protection happens at the platform level, invisible and automatic
This is on top of the security work Skpr already does: hardened runtimes, automated patching pipelines, industry-wide CVE triage, and 24/7 monitoring from a Drupal and SysOps team based in Australia. Drupal Steward adds one more signal to that picture - direct, advanced visibility into Drupal-specific threats from the team that writes the fixes.
Steward covers the class of highly critical, mass-exploitable vulnerabilities that can be blocked at the network layer - it complements patching, it doesn’t replace it.
Built on genuine Drupal expertise
Drupal Steward requires a proven track record of contribution to the Drupal project and a meaningful number of sites under management.
We’ve invested in Drupal since 2009. We’re Australia’s only Top Tier Drupal Certified Partner, and our team includes members of the Drupal Security Team, Lee Rowlan and Mohit Aghera, Drupal core maintainers, Kim Pepper, Adam Bramley, Michael Strelan, Daniel Veza and previous Drupal Association Board Chair Owen Lansbury. We contribute 5% of our annual revenue - over 2,000 hours a year - directly into Drupal’s codebase and community.
Joining Drupal Steward as a Platform partner through Skpr is recognition of that investment. It also means our clients benefit from the same trust the Drupal Security Team places in us as contributors.
What you need to do
If your site is hosted on Skpr, nothing. Protection is already active across the platform.
If you're evaluating Drupal hosting and want a provider with direct, verified standing in the Drupal Security Team's own protection program, get in touch with us.