[ Journal ]

Website security: the basics that really must be in place

Most hacked sites do not fall to a brilliant attack, but to overdue maintenance. What the basics are that really must be in place.

  • beveiliging
  • onderhoud

Security sounds like a topic for specialists, but most hacked sites do not fall to a brilliant attack. They fall to an outdated plugin, a weak password or a missing update. Getting the basics right covers most of the risk.

Where most hacks come from

Attackers rarely target your site specifically; they scan automatically for known vulnerabilities. A CMS or plugin that has not been updated for months is an open door. So it is less about clever defence and more about not falling behind.

The basics that really must be in place

These things cover most of the risk:

  • Updates: keep CMS, plugins and dependencies current, structurally.
  • Backups: automatic and tested, so restoring actually works.
  • Strong authentication: good passwords and two-factor where possible.
  • HTTPS and secure headers: on by default, not optional.
  • Fewer plugins: every extension is a possible vulnerability; keep it light.

Why maintenance and security are the same

Security is not a one-off project but a habit. A well-maintained site is a lot safer by itself, because updates and backups are simply kept up. Let a site sag and the risk piles up.

How we handle it

With a bespoke setup the attack surface is already smaller: fewer loose plugins, more control. On top of that we keep up updates, backups and monitoring structurally, so you do not have to wait until something goes wrong.

That is part of our maintenance and development: keeping healthy what we build.