1 min read

Ten checks that stop the most common attacks. None of them needs a security team.
Attackers rarely pick a target by hand. Automated tools scan millions of sites for the same few weaknesses. These ten checks close most of them.
- Update everything. The content system, plugins, themes and the server itself.
- Use unique passwords and a password manager. One reused password is enough to lose a site.
- Turn on two-factor authentication for every admin account.
- Remove what you do not use. Old plugins, test pages and forgotten accounts are open doors.
- Serve everything over HTTPS and renew certificates automatically.
- Back up daily to a second location and test a restore twice a year.
- Limit admin access. Give each person their own account with only the rights they need.
- Protect your forms against spam and automated submissions.
- Watch your logs. Repeated failed logins are an early warning.
- Know who to call. Write down who reacts when something goes wrong.
Where to start
If you only do three things this week: update, turn on two-factor authentication and check that your backup restores. The rest can follow.
A professional security review goes further, but these basics already stop the attacks most small businesses actually face.




