You don’t need to be a security expert to keep your website safe — most attacks exploit a short list of basics. Cover these and you eliminate the vast majority of risk.
The Non-Negotiables
- Update your CMS, plugins, and themes — the #1 cause of hacked sites is outdated software with known vulnerabilities.
- Use strong, unique passwords — for hosting, client area, admin panels, FTP, and email. A password manager makes this easy.
- Enable HTTPS — install your free SSL certificate (see our SSL guide).
- Keep backups — schedule automatic backups and keep copies off the server (see our backup guide).
Important Extras
- Enable 2FA on your Client Area account and CMS admin logins.
- Limit admin access — only give admin rights to people who need them; remove old accounts.
- Delete unused software — old test installs, inactive plugins, and forgotten subdomains are common entry points.
- Watch file permissions — never leave files or folders at 777 (world-writable).
Habits That Pay Off
- Check your site periodically — defacements and injected spam links are often visible.
- Keep your computer clean too — malware on your PC can steal FTP passwords and infect your site.
- Don’t click “password reset” links you didn’t request — phishing is the easiest way in.
Suspect something already? Don’t panic — see our guide on what to do if your website gets hacked.

Entry Level
Dedicated Server
Email Service
Design Services
Marketing Services
Domains
Billing
Support
Tools
Company
Support
Tools