Most business websites that get hacked are not chosen by a determined attacker. They are found by automated tools that scan the internet for out-of-date software, weak passwords and forgotten files. The good news is that the basics stop most of these attacks.
Go through this checklist with whoever manages your website.
1. Keep everything up to date
Your website runs on a framework or CMS, plugins or libraries, and a server with its own software. All of them receive security fixes. Ask how often updates are applied, and who is responsible. Unused plugins and themes should be removed, not just switched off.
2. Use strong passwords and two-step login
- Every admin account should have its own login. Shared passwords make it impossible to remove one person's access.
- Use long, unique passwords and a password manager.
- Turn on two-step verification for your hosting account, domain registrar, email and website admin wherever it is offered.
- Remove accounts for people who have left.
3. Protect the hosting account and domain
Your hosting control panel and domain registrar are the keys to everything. Keep them in the company's name, with a company email address, and make sure more than one trusted person can access them.
4. Keep secret files out of reach
Configuration files hold database passwords and keys. They should never be reachable from the web, and old backups, zip files and test pages should not be left in the website folder. Upload folders should never run code.
5. Back up, and test the backups
Keep regular backups of the website files and the database, stored away from the hosting account itself. A backup only counts if you have restored it at least once and checked that it works.
6. Use HTTPS everywhere
Every page should load over HTTPS, and plain HTTP should redirect to it. Certificates are available free, so there is no reason to skip this.
7. Protect your forms
Contact and enquiry forms attract spam and abuse. Rate limits, hidden spam traps and a bot check keep them clean without annoying real visitors.
8. Protect your email domain too
Attackers often send fake emails that appear to come from your domain, asking customers to pay into a different account. Ask your email provider to set up SPF, DKIM and DMARC records for your domain. They help receiving mail servers reject messages that pretend to be from you.
Signs your site may be hacked
- Pages redirect to unfamiliar websites, especially on mobile or from Google.
- Google search results show strange titles or spam pages under your domain.
- Unknown files appear in the website folder, such as PHP or zip files you did not add.
- Your hosting provider or Google Search Console sends a security warning.
If you see any of these, change all passwords, ask your hosting provider to scan the account, and restore clean files from a trusted source rather than trying to delete suspicious code one piece at a time.
Our cybersecurity and compliance and support and maintenance services cover updates, backups and monitoring. Contact us for a security check of your website.