Website Security Basics for Businesses
The handful of measures that prevent most website compromises.
How do I keep my website secure?
Most website compromises are prevented by a short list: keep software updated, use strong unique credentials with two-factor authentication, take verified off-site backups, limit administrative accounts, serve the site over HTTPS, and remove unused plugins, themes and accounts. Sophisticated attacks are rare compared with unpatched known vulnerabilities.
Website security for most businesses is not about advanced threats. It is about routine maintenance that nobody owns, which is why the same handful of causes produce most incidents.
How do websites actually get hacked?
Most commonly through an outdated plugin, theme or CMS with a publicly known vulnerability. After that: weak or reused administrative passwords, compromised hosting or FTP credentials, and malware on a computer used to access the site.
Attacks are generally automated and opportunistic, scanning for known vulnerable versions rather than targeting a specific business.
What are the most effective protections?
Prompt updates, unique strong passwords with two-factor authentication on administrative accounts, removing unused plugins and accounts, and verified off-site backups. These four cover the great majority of realistic risk for an ordinary business website.
Removing unused components matters more than it sounds. Deactivated plugins still contain code that can be exploited in some cases.
Is a security plugin enough?
It helps with hardening and monitoring but does not replace updates. A security plugin on a site with an unpatched vulnerable component provides limited protection, because the vulnerability remains open.
Where a plugin is genuinely useful is alerting you to file changes and login attempts, which shortens the time between compromise and discovery.
How should backups be handled?
Automatically, off-site, with periodic test restores. A backup that has never been restored is unproven. Host backups are useful but live on the same infrastructure, so an independent copy protects against account-level problems.
Keep enough history to go back beyond an undetected compromise. A single previous night's backup is useless if the site was compromised a week ago.
What should I do if my site is hacked?
Take a forensic copy before changing anything, then clean files and database, identify and close the entry point, rotate all credentials, and request a search engine review if the site was flagged. Cleaning without closing the entry point leads to reinfection.
Resist the urge to restore a backup immediately. If the entry point is still open, or the backup already contains the infection, the problem repeats within days.
Services related to this topic
Related solutions
More on technical
Related comparisons
Want help applying this?
Tell us your situation and we will tell you what we would actually do first.