39Design FAQ

Website security FAQs for business owners.

Security is not a single plugin. It is a set of controls covering the website, hosting, identities, software, backups and the people who administer it.

Website securityUpdated August 2026
Frequently asked questions

Clear answers, without the jargon.

Does HTTPS mean my website is secure?

No. HTTPS encrypts traffic between the visitor and website, which is essential, but it does not prove the application is patched, malware-free or protected from account takeover.

Should website administrators use MFA?

Yes where the platform supports it. Admin accounts can change content, access customer information and install code, so a stolen password can have serious consequences. MFA is one of the most useful controls against credential theft.

How often should website software be updated?

Security updates should be assessed promptly and unsupported components should be replaced. For business-critical sites, changes should be tested and backed by a rollback plan rather than applied blindly in production.

How many admin accounts should a website have?

Only as many as are operationally required. Give people the lowest privilege they need, remove old agency/staff accounts and avoid shared “admin” credentials that make activity impossible to attribute.

Are backups a security control?

Yes, particularly for recovery from malware, ransomware, failed updates and accidental changes. Keep backups separate enough that a compromise of the website cannot automatically destroy every recovery copy.

Do I need website security monitoring?

Monitoring should at least cover availability and important failures. Higher-risk sites may also monitor file changes, authentication, malware indicators, WAF activity and unusual administrative behaviour.

Should I hide my WordPress login URL?

Changing a login URL can reduce noise but should not be treated as a primary defence. Strong passwords, MFA, patching, least privilege, rate limiting and a WAF are more meaningful controls.

Who is responsible for website security: the host or the web agency?

Responsibilities should be written down. Hosting, application maintenance, plugin licences, backups, WAF configuration, DNS and incident response may be split across suppliers. Gaps appear when everyone assumes somebody else owns the task.

Specialist next steps

Useful services beyond the guide.

Keep exploring

Related website FAQs.

Need this applied to your own website?

© 2026 39 Design Ltd · Company 11113271 · MatthewSouthgate.co.uk · 39D.co.uk · Build 0.2.2