Website security involves protecting your website, administrator accounts, software and visitors from common security threats. No single security measure protects every website, so use several layers of protection.
1. Keep your software updated
Keep your website platform, themes, plugins and other software updated with supported versions.
Updates can include security fixes as well as feature and compatibility improvements.
Remove software that you no longer need rather than leaving unused plugins or components installed.
2. Use strong account security
Use strong, unique passwords for administrator and hosting accounts. Enable multi-factor authentication (MFA) where your provider supports it.
Give users only the permissions they need. Avoid sharing administrator credentials between multiple people.
3. Enable HTTPS
Use an SSL/TLS certificate so your website is available over HTTPS.
HTTPS encrypts data transmitted between the visitor’s browser and the website and helps protect information from interception while in transit.
4. Protect your website with backups
Maintain regular backups of important website files and databases.
Keep backups separate from the live website where practical and make sure you know how to restore them. A backup is particularly important if your website is compromised or data is accidentally deleted.
5. Secure your hosting environment
Use a reputable hosting provider and secure your hosting account with strong credentials and MFA where available.
Review unnecessary services, accounts and access permissions. Keep server software supported and updated according to your hosting environment.
6. Protect forms and user data
Collect only information your website genuinely needs. Use appropriate validation and spam protection for public forms.
If your website stores personal information, follow the data-protection and privacy requirements that apply to your organisation and location.
7. Monitor for problems
Regularly check your website for unexpected changes, suspicious accounts, broken functionality and security warnings.
If you suspect that your website has been compromised, avoid simply deleting suspicious files. Isolate the issue, preserve relevant evidence where appropriate, change compromised credentials and follow a reliable incident-response or recovery process.

Salesforce

