SECURITY
Web hosting security: a practical checklist
Security is a stack of controls. Look for prevention, detection, access control, backups, and a recovery path.
SSL is the baseline
HTTPS protects data in transit between the visitor and the site. It does not replace application updates, strong passwords, or malware controls.
Backups need a restore plan
Ask how often backups run, how long copies are kept, and how restores work. Keep an independent copy for important sites when practical.
Reduce account risk
Use unique passwords, multifactor authentication where available, limited user access, and prompt software updates.
Understand host level protection
Firewalls, malware scanning, brute force protection, server patching, and network defenses can reduce risk. The exact protections vary by host and plan.
Separate prevention from recovery
Firewalls and malware tools aim to reduce incidents. Backups and restore procedures help you recover when prevention fails. A sensible hosting setup needs both.
Test that you know where backups live and how restoration works before an emergency.
Your application remains part of the security boundary
A host can protect the server while an outdated plugin, weak administrator password, exposed API key, or vulnerable custom application still creates risk.
Keep software updated, remove unused components, limit privileges, and use multifactor authentication where available.