Opens in a new tab

The boring discipline that keeps sites out of trouble.

Most website security incidents aren’t dramatic. Nobody’s targeting you specifically. A bot finds an outdated plugin with a known vulnerability, exploits it, and your site starts sending spam or hosting content for someone else’s scam. By the time you notice, your domain reputation is already taking damage.

Avoiding that is mostly about doing the unglamorous things consistently – updates, backups, access discipline, sensible hosting. I set those up properly and keep them running.

Tell me what you're worried about

Sounds familiar?

Your hosting provider sent you a warning

Suspicious activity on your account, malware detected, account suspended pending review. That email usually arrives at the worst possible moment, and the hosting support team can only do so much from their side.

You took over a WordPress site from a previous developer or agency, and you have no idea what’s running on it, who has access, when it was last updated, or what shape the backups are in. Until you know, every day is a small bet.

You've been hit before

Site got hacked, defaced, or used to send spam. You got it back online but you’re not confident it won’t happen again – and you’re tired of finding out about problems through customer complaints.

Compliance or insurance is asking questions

A regulator, an enterprise client, or your business insurance is asking what security measures you have in place. You need a real answer, not a guess.

General unease

You read about a breach in the news, looked at your own setup, and realised you don’t know how secure it is. That’s a reasonable place to start from.

Audit

What I look at

Hosting environment, SSL configuration, DNS setup, WordPress core and plugin versions, theme code, any custom code, the database, file permissions, user accounts and roles, login security, backup setup, and what’s currently watching for problems. The full surface area, not just the parts that are easy to check.

Vulnerability scanning

I run the site through several tools to check for known vulnerabilities in WordPress core, plugins, and themes – including ones the plugin authors haven’t patched yet. The scan finds things visual review misses, especially on sites with thirty or forty plugins where keeping track manually is impractical.

The deliverable

You get a written audit covering what’s there, what’s working, what’s at risk, and what I’d recommend doing about each. Plain language. If something’s a ticking clock, I say so. If something’s actually fine, I say that too. No padding the report to justify the cost.

No work starts without your sign-off

The audit is the basis for the estimate. You see what’s there before you commit to fixing it. If you decide not to proceed, you keep the audit – it’s useful even if I never touch the site.

Hardening

Updates with discipline

WordPress core, plugins, and themes get updated on a regular cadence – weekly is the usual rhythm. Every update is preceded by a backup and followed by a check that nothing broke. If a plugin update introduces a regression, I roll it back and figure out what to do next. This is the boring work that prevents 80% of security incidents and exactly the work that gets neglected when nobody’s specifically responsible for it.

Hosting and the SSL/firewall layer

A lot of security depends on choices made before any code runs. Quality hosting with proper isolation between sites – not the cheapest shared plan where one neighbour’s compromise becomes yours. SSL configured correctly across the whole site, not just the homepage. Cloudflare in front of the site for DDoS protection, bot filtering, and a web application firewall that blocks common attack patterns. If your current hosting is a problem, I’ll say so and help with the migration.

Access discipline

Strong unique passwords stored in a password manager (1Password is what I recommend most often). Two-factor authentication on every admin account – not optional. Separate user accounts for each team member, with the right permission level for what they need to do. When someone leaves the team, you disable one account instead of changing every password. Boring, effective, hard to argue with once it’s set up.

Backups that actually work

Daily automated backups stored externally – not just on the same hosting account where they’re useless if the host has a problem. Restore tested at least once before you ever need it. WPvivid handles this well for most WordPress sites. Two backup destinations where the data is critical, because hosting support’s “we have backups” is the kind of promise that fails at the worst possible moment.

If your site is already compromised

If you’re emailing me because the site has been hacked, defaced, or is sending spam, that’s a different conversation. I’ll work to clean it, restore it, and harden it against the same thing happening again. If the damage is bad enough that recovery costs more than rebuilding, I’ll tell you – and at minimum I can extract the content you’ll need to rebuild somewhere clean.

Maintenance

Keeping it secure over time

Hardening is a state. Maintaining that state is what most clients pay for monthly. Weekly updates, backup verification, uptime and integrity monitoring, vulnerability scanning, and an hour or two of small changes. When something needs attention, you hear from me first – not from a customer.

Things worth thinking about beyond the site

Some of the most common security incidents start outside the site itself – a team member’s laptop with no antivirus, someone logging into the admin from a coffee shop’s open Wi-Fi, a phishing email pretending to be from a supplier asking for a payment redirect. I can’t see any of that from where I sit, so I won’t catch it for you. What I will do is raise these topics when we set things up, recommend a baseline that covers the obvious risks, and answer questions when something looks off. The fixes are usually simple. The hard part is just knowing what to ask about.

Security audit from €400. Hardening work scoped from the audit, usually €600-€2,000 depending on what’s there. Ongoing maintenance retainers from €100/month follow the hardening work – I don’t take on security retainers for sites I haven’t audited and hardened first.

All retainers include the security work as standard once we’re underway.

Process

Step 1
You email me with what's worrying you. A description of the situation is fine.

Step 2
I do a paid audit, usually within a week. You get a written document covering what's there and what I recommend.

Step 3
Based on the audit, I send you an estimate for the hardening work.

Step 4
If we agree, the work starts. For urgent compromises, faster.

For hardening projects, it’s a fixed scope and price based on the audit. For ongoing protection, I move to a monthly retainer once the hardening is complete – the hardening comes first because I need to know what I’m protecting. Either way, you know what you’re paying for.

Once we start, I send regular progress updates and you review at key milestones. Two or three rounds of revisions come with the project; past that, I’ll scope extra rounds separately. When the work is complete, you get documentation of what changed and a written record of how the site is now configured.

Tell me what you need

What they say

“We had a disaster with someone who literally broke our website and couldn’t get it back. Hosting support couldn’t help, and the software company for the plugin we used couldn’t help. Needless to say I was having a few sleepless nights. They sorted it all out in under an hour!”

Luke Sherrell, CEO
AMN Academy

Let's talk

Tell me what's worrying you. I'll tell you if I can help.

A few sentences is enough. What platform the site is on, what’s prompted the concern, whether there’s an active incident, any deadlines pressing. I’ll ask follow-up questions if I need more detail. For active incidents I usually reply same day; otherwise within a day or two.

Get in touch