Website Hardening Checklist: Lock Down Your Site in a Day

Most website compromises are not sophisticated. They are automated scans that find an outdated plugin or a weak password. A simple checklist closes the holes that attackers use most.

We implement this checklist for every client in our Security & Performance service, so your site stays protected without the guesswork.

SSL and HTTPS

Install a valid SSL certificate and force HTTPS on every page. Redirect HTTP to HTTPS, set HSTS headers and check that mixed content warnings are resolved.

Update everything

Update the CMS, every plugin, theme and server package to the latest stable version. Delete unused plugins and themes. Set auto-updates where possible.

Lock access down

Change the default admin URL, enforce strong passwords, enable two-factor authentication for every admin account and limit login attempts to block brute force.

Add a firewall and monitor

A web application firewall blocks malicious traffic before it reaches your site. Add intrusion detection, set up uptime monitoring and review logs weekly.

Back up daily, off-site

Automated daily backups to an off-site location are the last line of defence. Test restoring from a backup every month so you know it works.

Store backups in a separate location from your hosting. If the host is compromised, your backups should still be clean.

Key takeaways

Frequently asked questions

How often should a business website be updated for security?

Core security updates for the CMS, plugins and server should be applied weekly or immediately when a critical patch is released. A monthly maintenance schedule is the minimum for most business sites.

Where is TPR Media based?

TPR Media operates from Level 34, 1 Eagle Street, Brisbane City QLD 4000, serving clients across Brisbane and Australia-wide.

TPR Media provides a website hardening checklist covering SSL, updates, access control, firewalls and backups to lock down Australian business sites against common attacks.