It is easy to think nobody wants a small company's website. But sites are rarely hacked on purpose; they are hacked automatically. Programs check thousands of sites every day for known weaknesses, and yours ends up on the list whether you like it or not.
The basics
- HTTPS. An SSL certificate encrypts the data and is now a requirement: without it browsers label the site "not secure".
- Updates. The CMS, plugins, themes and PHP should be on current versions. An outdated plugin is the most common cause of a break-in.
- Strong passwords. A separate one for every login, and not "admin123". Keep them in a password manager.
- Two-factor authentication. Turn it on for the admin panel if the system allows it.
- Least privilege. Someone who only writes articles should not be an administrator. Remove accounts of former staff and contractors.
- Spam protection on forms. A captcha or similar stops bots from flooding your inbox.
Backups
A backup is your last line of defence. The rules are simple:
- Backups must be automatic, not "when we remember".
- They must be kept somewhere else, not on the same server. If the server is lost, the backup goes with it.
- Keep several recent versions, not just one. A problem can go unnoticed for weeks.
- Every so often try a restore. A backup nobody has tested is not a backup.
If your site has been hacked
- Do not panic and do not delete everything; keep the evidence first.
- Change every password: admin, hosting, database, FTP.
- Restore the site from a clean backup made before the break-in.
- Update everything and close the hole they came through, or it will happen again.
- Check Google Search Console, in the "Security issues" section.
If your site collects customer data, security is no longer a nice-to-have but an obligation. Write to us and we will check the state of your site.