AHANIX working resource
Website Security Checklist
Prioritise website ownership, accounts, updates, encryption, forms, backups, monitoring and incident readiness.
For: Business website owners completing a practical risk review.
Section 01
Accounts and access
- List administrator, hosting, registrar, DNS, email and third-party accounts.
- Remove unused access and give each person only the permissions they need.
- Use unique passwords stored in a reputable password manager.
- Enable multi-factor authentication wherever it is supported.
Section 02
Website controls
- Maintain supported software, plugins, dependencies and server components.
- Use HTTPS throughout and review secure cookie and form handling.
- Restrict uploads, validate input and use proportionate spam controls.
- Review security headers, logs and public error messages for the chosen platform.
Section 03
Recovery
- Keep protected backups separate from the live website.
- Test that a backup can be restored and document who can perform it.
- Monitor important availability and integrity signals.
- Write an incident contact, containment, evidence and communication plan.