Update with a rollback plan
Apply CMS, plugin, theme and server updates on a controlled schedule. Back up first and test business-critical functions after changes.
Security is a process, not one plugin. Keep software current, control access, maintain recoverable backups, monitor important changes and know who is responsible for each layer.

Apply CMS, plugin, theme and server updates on a controlled schedule. Back up first and test business-critical functions after changes.
Give each person only the access they need. Remove unused accounts, avoid shared administrator logins and use multi-factor authentication where available.
A backup helps recovery; it does not stop compromise. Confirm frequency, retention, restore access and whether copies are isolated from the website account.
Unexpected administrators, redirects, changed files, outbound spam, browser warnings and unexplained resource spikes deserve investigation.
Keep payment processing with reputable gateways, validate forms server-side, use HTTPS and avoid collecting sensitive information you do not need.
Know what the hosting provider covers, what the website maintainer covers and what remains the business owner's responsibility.
Backups, DNS, email, testing and rollback.
Read the guide →Find the cause before changing everything.
Read the guide →Recovery, access, updates and shared responsibility.
Read the guide →Product pages, categories, technical SEO and measurement.
Read the guide →Build costs, running costs and extras.
Read the guide →Choose the right amount of work.
Read the guide →Find the cause before choosing a fix.
Read the guide →Use the Hosting Plan Finder → · Open the customer help centre →
No. HTTPS encrypts traffic between the visitor and website. Application updates, access control, backups and monitoring are separate security responsibilities.
There is no universal interval. Review security and compatibility updates promptly, schedule routine maintenance, and test important functions after changes.
Only if a known-good restore point exists and the cause of compromise is removed. Restoring an infected or vulnerable copy can recreate the problem.
Responsibility is shared across hosting, website software, administrators and third-party services. The written service scope should state who manages each layer.