website security 2017

Why Website Security Matters – and What You Need to Know

Website security is no longer a “nice to have” – it’s a critical part of owning and managing a website.

Since 2005, WebSolutionZ has delivered website solutions via a project-based model. Once delivered, the site is handed over to the client for ongoing management. This approach worked fairly well for many years, but the rise in automated attacks and global security threats has made it clear that self-managed websites – especially those hosted on traditional platforms rather than SaaS solutions like Squarespace or Shopify – require active protection.

We recently attended the Joomla! World Conference in Vancouver, where several speakers addressed website security. One keynote (viewable here) outlined the following key points:

Why websites are attacked

  • To distribute malware or spam
  • Search engine poisoning (deliberate damage to SEO rankings)
  • To set up phishing (fake) websites
  • Defacement
  • To connect your website to a “botnet” used in larger attacks
  • To access secure data

How attacks happen

  • Brute force login attempts
  • Exploitation of software vulnerabilities or server misconfigurations
  • Distributed denial of service (DDoS) attacks
  • Cross-site contamination on shared servers

Most attacks are automated. The advice given at the conference was clear – website owners should assume when their site will be attacked, not if.

What happens after an attack?

  • Business impacts – brand damage, financial loss, emotional stress and potential liability.
  • Technical impacts – blacklisting by Google, SEO ranking drops and loss of traffic.

What you can do

If you manage your own website and hosting, here are some key steps to protect your investment:

  • Keep everything updated – CMS core files, plugins, extensions and themes. Updates often include security patches.
  • Use strong passwords and enable two-factor authentication where possible.
  • Back up regularly – ideally offsite or to cloud storage, so you can restore quickly if needed.
  • Review your hosting environment – some hosting providers include security tools in cPanel, such as malware scanning, firewall settings and brute force protection. Make sure these are enabled and configured.
  • Limit access – only give admin access to trusted users, and remove unused accounts.
  • Monitor activity – use tools or plugins to track login attempts, file changes and suspicious behaviour.

Security updates may seem tedious, but they’re your first line of defence. Once a vulnerability is identified, exploit scripts are often written within days.

Managing a website isn’t just about content and design. It’s also about keeping your digital assets safe.

If you’re unsure where to start, speak to your hosting provider or take a look at our Cyber Security & Safety service. Get in touch to discuss your options.