Why is website security an ongoing job?
Attackers don't pick websites one by one; they scan thousands of sites with automated tools looking for known vulnerabilities. When a flaw is announced in a content management system or plugin, sites that haven't been updated become targets within a short time. That's why security isn't something you set up once and forget, but maintenance you do regularly. Even a small brochure site gets its share of these scans; thinking there's nothing worth stealing on our site ignores the fact that your server can be used to attack others.
The signs of an attack aren't always visible. Spam links can be quietly added to your site, visitors can be redirected to other websites, or your server can be used to send junk email. Often the first sign is a warning from a search engine, or your emails starting to land in recipients' spam folders.
Update management
Updates happen on three layers: server software (operating system, PHP, database), the content management system, and plugins or modules. Every update carries some risk too; an incompatible plugin can break part of the site.
Here's the method we follow:
- A full backup is taken before any update.
- Security updates take priority and are applied without delay.
- Major version upgrades are tested in a staging environment first.
- After updating, we check the main pages, forms and, if there are any, the payment steps.
- Plugins that are no longer maintained are identified, and we recommend alternatives.
Access and permission control
A large share of security holes come not from software but from access. Examples include an admin account still active for an employee who left years ago, a shared password everyone knows, or permissions broader than necessary. As part of maintenance we regularly review admin accounts and use strong passwords and, wherever possible, two-factor authentication.
Security monitoring
Monitoring tracks whether the site is reachable, whether files have changed unexpectedly, bursts of failed login attempts and SSL expiry. When a problem is detected, we first contain the damage, then clean up and close the hole that caused it. If needed after cleanup, the site is restored from a clean backup; for details, see the backup and recovery page.
If your site processes personal data, there are also steps you must take when a breach is suspected. We handle these obligations together with our KVKK compliance work (KVKK is Türkiye's Personal Data Protection Law).
Checklist
- Are the content management system and plugins up to date?
- Have unused plugins and themes been removed?
- Have the accounts of departed employees been closed?
- Do admin logins use two-factor authentication?
- Are forms protected against automated submissions?
- Are file changes and uptime being monitored?
Frequently asked questions
What should we do if our site has been hacked?
Changing passwords right away is the first step, but it isn't enough. The malicious code has to be cleaned out, and the vulnerability found and closed. Give us a call and walk us through what happened.
Isn't it enough to just leave automatic updates on?
It helps for small security updates. For major version upgrades, though, unchecked automatic updates can break the site, so they should be done under supervision.
For the big picture, head back to the hosting and maintenance page or contact us.