Optimal Website Security – Tips from the Pros
First published in 2014, rewritten in 2026 so the advice holds today.
Finding out your website has been compromised is one of the worst moments in running an online business. If customer data is involved, it's worse again: under UK GDPR you may have a legal duty to report a serious breach to the ICO within 72 hours, and to tell affected customers. Even a minor intrusion is unsettling, because you rarely know straight away how far it's gone or whether it can be fully undone.
Prevention is still the best strategy. That means choosing a hosting provider or platform you trust, and keeping a handful of good habits in place. Most of the advice below hasn't changed much since this article was first written, though how you apply it has moved on.
Third-party plug-ins and apps
It's tempting to add plug-ins, apps or extensions that promise extra features, but every one you install is a potential way in for an attacker. This is still true whether you're running WordPress, WooCommerce, Shopify or another platform. Well-known extensions have been compromised before, either through the developer's account being hacked or through a bought-out plug-in being quietly updated with malicious code.
- Only install plug-ins or apps from verified developers, ideally through your platform's official marketplace.
- Check when an extension was last updated. Anything abandoned for a year or more is a risk, not a bargain.
- Remove anything you're not actively using. An inactive plug-in is still a door left unlocked.
- If you use a hosted platform such as Shopify, favour apps with a strong review history over ones that are cheap or new.
Keep up with what's new in security
Security discussion still happens everywhere: vendor blogs, developer forums, industry newsletters. The National Cyber Security Centre (NCSC) is a good, UK-specific source for small business guidance, and most major platforms (Shopify, WordPress, Adobe Commerce) publish their own security advisories. Following these costs nothing and takes a few minutes a week.
Accept updates, and automate them where you can
When an update is offered, install it. It rarely changes what customers see, but it often closes a security hole you didn't know existed.
The big shift since 2014 is that you no longer have to remember to do this manually. Fully hosted platforms like Shopify and BigCommerce patch the core platform for you automatically. If you run a self-hosted site on WordPress or Magento/Adobe Commerce, turn on automatic updates for core software and trusted plug-ins, and keep a monthly check in the diary for anything that needs manual attention, including PHP and server-level updates.
Should you jump on brand-new software?
Being an early adopter of a new plug-in, app or theme still carries risk. Anything not yet tested by a large number of users can hide bugs and security flaws that haven't surfaced yet, and you don't want your live store to be the one that finds them. Give new releases time to settle, check for reviews and reported issues, and only adopt once there's a reasonable track record.
One thing worth adding since the original article: turn on two-factor authentication everywhere it's offered, for your CMS, hosting account, domain registrar and payment provider. It's a far bigger practical barrier to unauthorised access than most other single measures on this list, and it costs nothing.
Back up properly, not just once
Backing up your data every day is still essential, and the advice to keep more than one copy still stands. The standard approach now is the 3-2-1 rule: keep at least three copies of your data, on two different types of storage, with at least one copy stored off-site or in the cloud. That way a server failure, a ransomware attack or a fire at your hosting provider can't wipe out every copy at once.
| Backup approach | Good for | Watch out for |
|---|---|---|
| Platform's built-in backups (Shopify, BigCommerce) | Convenience, no setup needed | May not cover everything, check retention period |
| Automated cloud backup service | Self-hosted sites, frequent changes | Test restores regularly, don't assume it works |
| Manual off-site copy | Extra safety net for critical data | Easy to forget, needs a recurring reminder |
A backup you've never tested restoring isn't really a backup. Set a reminder to do a test restore at least twice a year.
The takeaway
The core advice from a decade ago still holds: be careful what third-party code you install, keep everything patched, resist the urge to be first in line for untested software, and never rely on a single backup. What's changed is that managed platforms now do more of this for you automatically, two-factor authentication is a cheap and effective addition, and a serious breach carries real legal obligations under UK GDPR as well as the obvious commercial damage. Treat security as ongoing maintenance rather than a one-off task, and it's far less likely to become a crisis.