Your website is the front door to your business. You would not leave the office unlocked overnight, so it is a bit odd that so many people are still logging into their CMS with "admin123".
Security is not glamorous. It is the boring stuff done consistently. Here are five things you can do this week to make sure your site stays yours.
1. Use Passwords That Are Not Rubbish
The single most common way a website gets compromised is still a weak or reused password. If your login is "admin" and your password is the name of your dog, you are not a target, you are a formality.
Use a password manager. Generate a long, random string for every account. Never reuse the same password across your CMS, hosting panel, email and domain registrar, because the moment one of them leaks, everything else falls with it.
Turn on two factor authentication wherever it is offered. It is not bulletproof, but it adds a genuinely useful layer that stops the vast majority of automated attacks dead.
Advertisement
2. Keep Everything Updated
Outdated software is an open invitation. Every plugin, theme and core update patches holes that attackers already know about. The longer you sit on an old version, the wider the door swings open.
This applies to your CMS, your plugins, your server software and anything else that runs your site. Set updates to install automatically where you trust the source, and check in regularly for the things that need a human eye.
If a plugin has not been updated in two years, ask yourself whether you actually need it. Abandoned code is a liability, not a feature.
3. Force HTTPS Everywhere
If your site is still serving pages over plain HTTP in 2026, that is a problem. HTTPS is not just for checkout pages any more. It encrypts everything between your visitor and your server, which means logins, form data and cookies cannot be quietly intercepted.
Get a certificate, force the redirect from HTTP to HTTPS, and set a Strict Transport Security header so browsers remember to stick to the secure version. Most hosts now throw in a free certificate, so there is no excuse left.
Search engines also prefer HTTPS, so it is one of those rare security wins that quietly helps your SEO too.
Advertisement
4. Tighten Up Who Has Access (and Cut Them Off When They Leave)
This is the one most businesses get wrong. You hand out admin logins to a freelancer, an intern, a marketing agency and the person who built the site three years ago. Then they move on, and nobody removes the keys.
Give people the lowest level of access they actually need to do the job. Not everyone needs to be an administrator. Most people only need to edit content, and that is a very different permission level from being able to delete the whole site.
The moment someone leaves the company or finishes a project, remove their access the same day. Not next week. Not when you get around to it. The same day.
As Mark Dodds from Compex IT, a Birmingham based IT firm, puts it:
Our number one step to keeping a site secure is the same as with any cyber security: make sure everyone who has access keeps their password safe, shares it with no one, and is removed the moment they leave the company.
It sounds obvious because it is. It is also the step that gets skipped the most often, and it is the one that causes the most avoidable damage when it goes wrong.
5. Back Up Properly, and Then Test the Backups
A backup you have never restored is a wish, not a backup. Plenty of businesses have a backup system ticking away in the background, only to discover at the worst possible moment that it has been quietly failing for months, or that it only stored the database and not the uploaded files.
Keep backups offsite, somewhere separate from your hosting. If your server and your backups live in the same place, a single compromise takes both of them down.
Then, once a quarter, actually restore one into a test environment and confirm it works. It is ten minutes of mild inconvenience that saves you from a catastrophe later.
The Bottom Line
None of this is rocket science. Strong passwords, regular updates, HTTPS, sensible access control and tested backups. Five boring habits that, done consistently, keep the vast majority of attacks away from your front door.
If you want a hand tightening any of this up, or you just fancy a second pair of eyes on your setup, get in touch and we will talk it through.
Chris from Pixelbricks
Web designer at Pixelbricks Design in London. Built WEBP Converter to help designers and developers optimise their images for free, right in the browser — no uploads, no limits, no cost.
Visit Pixelbricks Design →Related articles
Core Web Vitals Explained: A Practical Guide for 2026
LCP, INP, and CLS are the three metrics Google uses to judge your page experience. Here is what each one measures, the thresholds you need to hit, and how to actually improve them.
AVIF vs WebP: Which Next-Gen Image Format Should You Use?
Both AVIF and WebP crush JPEG and PNG. But which one should you actually serve in 2026? A practical comparison of compression, browser support, and when to use each.
Ready to optimise your images?
Try our free WebP converter and see the difference for yourself. Unlimited conversions, no registration required.
Start converting →