Skip to main content

AHANIX working resource

Website Security Checklist

Prioritise website ownership, accounts, updates, encryption, forms, backups, monitoring and incident readiness.

For: Business website owners completing a practical risk review.

Section 01

Accounts and access

  • List administrator, hosting, registrar, DNS, email and third-party accounts.
  • Remove unused access and give each person only the permissions they need.
  • Use unique passwords stored in a reputable password manager.
  • Enable multi-factor authentication wherever it is supported.

Section 02

Website controls

  • Maintain supported software, plugins, dependencies and server components.
  • Use HTTPS throughout and review secure cookie and form handling.
  • Restrict uploads, validate input and use proportionate spam controls.
  • Review security headers, logs and public error messages for the chosen platform.

Section 03

Recovery

  • Keep protected backups separate from the live website.
  • Test that a backup can be restored and document who can perform it.
  • Monitor important availability and integrity signals.
  • Write an incident contact, containment, evidence and communication plan.