An online shop ran an outdated plugin. An attacker got admin, dropped malware and exfiltrated customer data. Costs: forensics, notifications, downtime, reputation — easily six figures in CZK.
A checklist that should have been done
- CMS / plugin / dependency updates
- 2FA on every admin account
- Least privilege
- Offsite backups + restore tests
- WAF / rate limits on login
- File-change and anomaly monitoring
- Separated staging / production secrets
Conclusion
Security isn’t a one-off audit. It’s hygiene. Cheaper than an incident.
_Want a website security review?_ We’ll walk the stack and deliver a prioritised plan.
Keywords
website security
site hack
protect website
website backups
WordPress security