View 39Security training events
Practical cyber security training for business owners, directors and teams.
View 39Security training events →Security is not a single plugin. It is a set of controls covering the website, hosting, identities, software, backups and the people who administer it.
No. HTTPS encrypts traffic between the visitor and website, which is essential, but it does not prove the application is patched, malware-free or protected from account takeover.
Yes where the platform supports it. Admin accounts can change content, access customer information and install code, so a stolen password can have serious consequences. MFA is one of the most useful controls against credential theft.
Security updates should be assessed promptly and unsupported components should be replaced. For business-critical sites, changes should be tested and backed by a rollback plan rather than applied blindly in production.
Only as many as are operationally required. Give people the lowest privilege they need, remove old agency/staff accounts and avoid shared “admin” credentials that make activity impossible to attribute.
Yes, particularly for recovery from malware, ransomware, failed updates and accidental changes. Keep backups separate enough that a compromise of the website cannot automatically destroy every recovery copy.
Monitoring should at least cover availability and important failures. Higher-risk sites may also monitor file changes, authentication, malware indicators, WAF activity and unusual administrative behaviour.
Changing a login URL can reduce noise but should not be treated as a primary defence. Strong passwords, MFA, patching, least privilege, rate limiting and a WAF are more meaningful controls.
Responsibilities should be written down. Hosting, application maintenance, plugin licences, backups, WAF configuration, DNS and incident response may be split across suppliers. Gaps appear when everyone assumes somebody else owns the task.