Protect the accounts that control the site
A website may depend on accounts for its domain, hosting, content management system, email, analytics and payment provider. Identify who has access to each account, use unique credentials and enable multifactor authentication where the provider supports it. Remove access promptly when responsibilities change.
Keep recovery details current and store them in an approved password manager. Avoid shared administrator logins when individual accounts are available, because named accounts make it easier to investigate changes and revoke one person’s access without disrupting everyone.
Maintain software and reduce unnecessary access
Updates can correct bugs and security issues in the operating system, framework, content management system, plugins and integrations. Create a routine for reviewing updates, testing them and confirming the site works afterwards. Software that no longer has a maintainer deserves a replacement plan.
Limit installed components to what the site actually needs. Give each account and integration only the permissions required for its job. Remove unused accounts, API keys and plugins rather than leaving them dormant and forgotten.
Backups should be recoverable
A backup is only useful if the business can restore it. Keep copies separated from the primary service where appropriate, protect access to them and test restoration periodically. Decide how much recent work the business can afford to lose and how long the site can be unavailable.
Document what is included: files, databases, uploads, configuration, domain settings and the information needed to restore connected services. Confirm who can initiate recovery and how customers or staff will be informed if an incident affects service.
Know what to do when something looks wrong
Agree how to report a suspicious login, unexpected page change, malware warning or outage. Preserve relevant logs and contact details, avoid deleting evidence, and know who can disable compromised credentials or take a site offline if necessary.
No checklist prevents every incident. A clear inventory, limited access, maintained software and tested backups make problems easier to contain and recover from. Businesses that handle personal or regulated data should also understand their applicable reporting and notification obligations.
Sources & further reading
Have a factual correction or a source to suggest? Contact the editorial desk.



