What our security baseline covers on your hosting

Security is layered. We handle the infrastructure and platform layers. Some layers depend on choices you make, and it is worth being clear about where the line sits.

What we configure and maintain

  • Patching. Operating system and server stack updates applied on a regular cycle, with urgent security fixes brought forward.
  • Firewalling. Only the ports that need to be open are open. Administrative services are restricted.
  • Transport security. SSL certificates installed with automatic renewal, and traffic redirected to https.
  • Isolation. Accounts separated so one site cannot read another site's files.
  • File permissions. Set so that web accessible directories are not writable where they should not be.
  • Brute force protection. Rate limiting and blocking of repeated failed login attempts.
  • Backups. Automated on the schedule stated on your plan, which is what turns a serious incident into an inconvenience.
  • Monitoring. Uptime and resource checks, with alerts to our team.

What depends on you

  • Strong unique passwords and two factor authentication on your accounts.
  • Keeping WordPress core, themes and plugins updated, which we handle under a maintenance plan.
  • Not installing plugins or themes from unofficial or pirated sources. Nulled software very frequently contains backdoors.
  • Removing access for staff who leave.
  • Keeping the devices you log in from free of malware.

What a baseline cannot do

No baseline prevents an attacker who has valid credentials, or a vulnerability in application code that has not yet been disclosed. That is why backups, least privilege access and monitoring matter as much as prevention. Security is about limiting the blast radius as well as keeping people out.

Going further

If your site handles payments, personal data at scale or has compliance obligations, we can discuss a web application firewall, stricter access controls and more frequent backups.

To review the security posture of your service, reply to your email thread or contact [email protected].

Did you find this article useful?