Hosting security: what's keeping your website out of trouble
You tend to find out how your website was protected on the day it stops being protected. A warning page goes up in front of it, Google puts a flag next to it in the results, and the phone starts ringing.
Every site we host sits behind the same set of defences – a certificate, a firewall reading every request, daily malware scanning and a team in Bournemouth who’ll pick up. This page is the plain-English version of what all of that actually does.
Included with every site we host. Nothing to bolt on, nothing extra to buy.
Are you in the right place?
Two different jobs get called the same thing, so let’s split them now.
This page is about your website. What stops it being defaced, hijacked, knocked offline or quietly turned into somebody else’s advertising.
If you want the business itself protected – the computers your team work on, your Microsoft 365 accounts, your people and the emails they get sent – that’s a different job with a different page. Cyber Security →
Most of our clients end up with both. They’re genuinely not the same thing, and having one doesn’t give you the other.
A hacked website is a very public problem
There’s no quiet version of it. Your customers get a full-screen browser warning telling them the site is dangerous. Google drops a flag next to your listing. Somebody emails you a screenshot before you’ve noticed yourself.
Then the recovery is slow. The site has to come down, be cleaned out properly, be checked line by line, and then be reviewed by Google before the warning disappears – and all of that happens while your enquiries stop.
That’s the honest case for this page, and it’s the last of the bad news. The rest of it is what gets done about it.
What's protecting your site
An encrypted connection on every domain
Certificates come free with your hosting and cover your subdomains too, so the padlock is there from day one.
A firewall reading every request
Incoming traffic is checked for the known ways in, and the bad ones are turned away before they reach your site.
Cover against traffic floods
Attacks designed to knock a site offline by drowning it in fake visitors are absorbed before they reach you.
Daily malware scanning
Your site is scanned every day and you’re told if something turns up. You can run a scan yourself whenever you want reassurance.
WordPress checked against the original
Your WordPress files are compared with the official versions, so a change nobody made on purpose gets spotted.
File permissions watched
Wrong permissions are one of the quietest ways in. Yours are monitored and you’re told what to put right.
Login attempts monitored
Automated password guessing is picked up and blocked before it gets anywhere.
Email scanned before it lands
Viruses and spam are filtered out on the way in, and your outgoing mail is signed so it can’t easily be faked.
The certificate on your domain
Any site that collects a single thing from a visitor – a contact form, a login, a card payment – needs the connection between them and your server encrypted. That’s what a certificate does, and it’s why the address starts https:// and shows a padlock.
Without one, modern browsers say so on the screen, in front of your customer. Google also treats it as a quality signal, so it does quiet work for your search listing as well.
We include a wildcard certificate (an SSL certificate) on every domain we host, which covers your subdomains too – the shop, the staging site, the booking system – rather than just the main address. Renewals happen without you doing anything.
The firewall in front of your site
Most attacks on a business website aren’t personal. They’re automated, they run against millions of addresses at once, and they’re looking for a handful of well-known weaknesses in the software underneath.
Sitting in front of your site is a firewall that reads incoming requests and turns away the ones that look like an attack (a web application firewall, or WAF). It’s watching for the standard tricks – attempts to talk directly to your database, or to inject code into a page that then runs in your visitors’ browsers.
Traffic floods. Some attacks don’t try to break in at all. They point enormous volumes of fake traffic at your site until real visitors can’t get through (a DDoS attack). That’s absorbed upstream, with capacity measured in terabits per second, so it never reaches the server your site sits on.
Blocking visitors yourself. If you need to shut out particular countries or particular addresses – a common ask after a wave of form spam – you can, and we’ll set it up with you.
Who'd notice if something changed
This is the question most people can’t answer about their own website, and it’s the one that matters. Here’s what’s watching.
Malware scanning, daily. Your site is checked every day for anything that shouldn’t be there, and you’re alerted if it is. You can also run a scan on demand, which is the quickest way to confirm a problem is genuinely gone.
A WordPress checksum report. WordPress runs a large share of the web, which makes it the most attacked platform there is. This test compares the WordPress files on your site against the official versions in the WordPress repository and reports anything that doesn’t match. An altered core file is one of the clearest signs of a break-in, and it’s not something anybody spots by eye.
A file permissions checker. Permissions decide who’s allowed to read and change what on your server, and a single wrong setting can leave a door open for months. Yours are monitored, with a recommendation when something needs tightening.
Keeping the front door shut
The most common way into a website isn’t clever code. It’s a password.
Automated software works through thousands of guesses against your login page, usually overnight, usually from a lot of addresses at once. Our platform watches login attempts to your site and shuts that down when it sees it.
Alongside that: two-factor authentication on the hosting control panel, so a stolen password on its own isn’t enough. A generator for strong passwords, so nobody’s reusing the one from their online shopping. Password protection on any part of your site that shouldn’t be public. And FTP access locked down, because that’s the back door people forget they left open.
Email that arrives clean, and arrives as you
Two different problems, both handled at the mail server rather than on anyone’s computer.
What arrives. Incoming mail is scanned for viruses and malware before it reaches your inbox, and filtered for spam so your team isn’t wading through it.
What leaves. Our mail servers sign your outgoing messages so receiving servers can check they genuinely came from you (DomainKeys Identified Mail, or DKIM). That makes it much harder for someone to send invoices in your company’s name – one of the more expensive things that happens to small businesses.
This covers email hosted on our platform. If your email lives in Microsoft 365, it stays exactly where it is and this doesn’t apply – Microsoft 365 Protection → is the page you want.
Where your site actually lives
Everything above is software. Underneath it is a building, and that matters too.
Our data centres are certified to ISO27001:2013, the international standard for managing information security. In practice that means gated access with photo ID and swipe cards, CCTV monitored round the clock, redundant power, and a record of who went where.
If you take card payments, the servers meet the Payment Card Industry standard (PCI), audited regularly against the requirements set by Visa, Mastercard and the rest. That isn’t the whole of your compliance job, but it’s the part that depends on your host, and it’s already done.
Two things about the platform worth knowing
Both of these usually get sold as performance features. They’re security features too, which is why they’re here rather than only on the platform page.
Attacks cost you resource even when they fail. A site being hammered by a bot is burning processor and memory on requests that were never going to become customers. Because the platform adds resource automatically when demand climbs, that doesn’t turn into a slow site for the real visitors – and a neighbour on the same platform having a bad day doesn’t become your bad day.
Jobs are kept apart. Websites, databases and email each run on their own servers rather than sharing one. If something ever does get a foothold in one place, it hasn’t got the run of everything else at the same time.
The full picture of how the hardware, the failover and the scaling work sits on Our Hosting Platform →.
What's standard, and what isn't
We’d rather be straight with you about the edges.
Standard on every site we host. The certificate, the firewall, traffic-flood cover, daily malware scanning, the WordPress checksum report, the file permissions checker, login monitoring, two-factor authentication on the control panel, visitor blocking, email scanning and signing, card-payment-compliant servers and certified data centres. All of it, at no extra cost, on standard hosting.
Not included, and worth knowing. Keeping WordPress, your theme and your plugins patched is a separate ongoing job – that’s Website Maintenance →, and out-of-date plugins are the most common way a WordPress site gets broken into.
If a site is already compromised when it comes to us, cleaning it up is a piece of work in its own right. We’ll look at it, tell you what’s involved and quote you before anyone starts. No surprises on an invoice.
Where this fits
Cyber Security
Protecting the business itself – the computers, the accounts, the people. A different job from this page.
Cyber SecurityWebsite Maintenance
Keeping WordPress and its plugins patched, which is the other half of the job.
Website MaintenanceWorking with us
Website security tends to be sold as a product you buy and then never understand. We’d rather you understood it, which is roughly what this page has been for.
In practice you get all of it switched on by default, a team that looks after your computers and your website as one thing rather than two, and a phone number in Bournemouth that a person answers. When something needs your attention, you’ll hear about it in the same plain English you’ve just read.
And if the answer is “your site’s fine, don’t spend money on that” – you’ll get that too.
Getting your site looked at
1. Tell us where the site is
The address, what it’s built in, and who hosts it now. That’s enough for us to start.
2. We check it over
Certificate, firewall, WordPress version, plugins, permissions, logins. We’ll tell you what’s protected, what isn’t, and which of the gaps genuinely matter.
3. You decide what to do
Sometimes it’s a small fix where you are. Sometimes it’s worth moving the site to us. Either way you get a straight recommendation, not a quote you didn’t ask for.
Have your site checked overCommon questions
The things people ask once they start wondering whether their website is actually protected – and what happens if it turns out it isn’t.
If yours isn’t here, ask. You’ll get a proper answer rather than a sales call.
Is my WordPress site safe?
Partly, and it depends which part. The hosting layer – certificate, firewall, scanning, login protection – is handled for you. What WordPress itself is running is the other half: an out-of-date plugin is the most common way in, and that needs somebody staying on top of updates. We’ll look at both and tell you where you stand.
How would I know if my site had been hacked?
Often you wouldn’t, which is the problem. Daily malware scanning and the WordPress checksum report exist to catch it before your customers do. Without something watching, the usual first sign is a browser warning, or a client asking why your site is showing something strange.
Does this cost extra?
No. Everything listed under “standard” comes with the hosting. Website Maintenance and cleaning up a site that’s already been compromised are separate, and we’ll always tell you which one you’re looking at.
I've already got a certificate and a padlock. Isn't that enough?
A certificate encrypts the connection between your visitor and your server. It does nothing to stop somebody logging in with a guessed password, or exploiting an out-of-date plugin. It’s one layer of several, and it’s the easiest one.
Do you protect my computers and email as well?
Not from this page – this protects the website. For the computers your team use and your Microsoft 365 accounts, that’s Cyber Security →, and it can be bought on its own without a full IT contract.
Can you look at a site you don't host?
Yes. We’ll check it over and tell you what we find. If the sensible answer is to fix something with your current host rather than move, we’ll say so.
What if my site gets hacked while you're hosting it?
You ring us and a person picks up. We’ll take the site offline if it needs to come down, work out how it happened, clean it out and get it back up – then tell you what to change so it doesn’t happen twice.
Cleaning up after a compromise is quoted separately from your hosting. It’s real work, and we’d rather tell you that now than in the middle of it. Everything further up this page is the part that’s included, and it’s there to stop you ever needing this answer.
Not sure what's protecting your site?
Most people aren’t. It doesn’t take us long to find out and tell you plainly, whether you host with us or not.
01202 237 273 · service@rejuvenate.it · Bournemouth, serving Dorset and the South Coast.