Most sites aren't personally targeted: they're swept by bots exploiting known vulnerabilities and weak passwords. Protecting yourself mostly means closing those doors.
Nothing exotic here — just discipline. For advanced application authentication, see ZAIA.
01 — Transport
HTTPS everywhere, no exceptions
A free TLS certificate (Let's Encrypt), redirecting all HTTP to HTTPS, an HSTS header. A plain HTTP form exposes whatever data is entered.
02 — Updates
The leading cause of intrusion
Core, themes, plugins, libraries: apply patches fast. A published vulnerability gets exploited at scale within days.
03 — Access
Strong passwords, 2FA, least privilege
- Long, unique passwords, managed in a password manager.
- Two-factor authentication on the admin area.
- One admin account per person, roles limited to actual need.
- Removal of unused accounts.
04 — Backups
The only real insurance
Automatic backups, stored somewhere other than the server, with a restore tested at least once. A backup that's never been tested isn't really a backup.
05 — Detect and react
Seeing it coming, knowing what to do
- A web application firewall (WAF) and login attempt rate limiting.
- Logging of logins and changes.
- A written procedure: who to contact, how to isolate, how to restore.
06 — Frequently asked questions
How to secure your website in 4 steps. Understand it all in under 5 minutes (in French) — Pascal dumont
Frequently Asked Questions
My site is small — am I a target?
Yes — attacks are automated and indifferent to your size. A poorly maintained small site is an easy target.
What should I do if my site is hacked?
Isolate it (maintenance mode), restore a clean backup, change every password, update everything, then find the entry point before going back online.
Is a firewall enough?
No. It reduces the noise, but updates, passwords, and backups remain the foundation.
07 — Resources & links
Where to go, concretely
Tools
- ANSSI — best practices (French cybersecurity agency)
- Cyber hygiene guides.
- cyber.gouv.fr/publications
Related
- NEWTIV — ZAIA: key-free authentication
- Strengthening authentication without a rewrite.
- newtiv.com/article/zaia-authentification-zero-key.html

Réagissez
Commentaires