Website security services south africa

Website security is six layers, not one plugin.

Almost nobody is targeted personally. Sites get hacked because automated bots scan the whole internet for known vulnerabilities and find one that was never patched. Website security is the unglamorous discipline of making sure they find nothing, and of being able to restore in an hour if they ever do.

Perimeter clearScanned daily, blocked constantly

Security statusNo threats found
firewall_edge
1,482 blocked
login_attempts
94 refused
malware_scan
clean 06:00
file_integrity
no changes
core_updates
current
two_factor
enforced
ssl_grade
A
restore_point
tested 02:14
Scanning around the clockCleanup included, always
6 layersFrom the edge firewall inward to backups
DailyMalware scans and file integrity checks
IncludedCleanup if anything ever gets through
30 daysBackup retention, restores tested
Capability

The six layers of website security

A security plugin is one layer, and it is the fourth most useful of the six. Real protection is depth, so that any single failure is caught by the next thing behind it.

Layer 01

The edge firewall

Traffic is filtered before it ever reaches your server. Known bad actors, bot networks and automated vulnerability scanners are refused at the edge, which stops most attacks costing you anything at all.

Layer 02

Access control

Two factor authentication enforced, individual accounts rather than one shared login, correct role levels, and login attempts rate-limited. Weak credentials remain the most common way in.

Layer 03

Patching discipline

Core, plugins and themes updated weekly on staging first. Vulnerabilities published in the CVE database get exploited within hours, so the gap between a fix existing and you applying it is the whole risk.

Layer 04

Scanning and integrity checks

Daily malware scans plus file integrity monitoring, which flags any file that changed when it should not have. That is usually how an intrusion gets caught early rather than weeks later.

Layer 05

Tested backups

Nightly, off-site, thirty day retention, with restores actually performed rather than assumed to work. This is the layer that turns a disaster into an inconvenience.

Layer 06

Response

If something does get through, we clean it, restore, find the entry point and close it, then handle the Google review request if the domain was flagged. Included on every plan.

The six layers of website security services in South Africa, from edge firewall through to incident response

Depth, so that any single failure is caught by the layer behind it.

How it actually happens

The five ways website security fails in South Africa

In rough order of frequency. None of them involve anyone deciding to target your business specifically.

Route inHow commonWhat stops it
Outdated plugin with a published exploitMost common by farWeekly patching on staging
Weak or reused admin passwordVery commonTwo factor, enforced
Nulled or pirated premium pluginCommonLicensed plugins only
Abandoned plugin no longer maintainedCommonAudit and replace
Compromised shared hosting neighbourLess commonIsolated container

What a compromised site actually costs you

  • Google flags the domain. Visitors get a red interstitial warning instead of your site, and it stays until a review is requested and passed.
  • Rankings drop. Malware and spam injections get sites demoted quickly, and recovery takes longer than the cleanup does.
  • Email deliverability suffers. If the server was used to send spam, your domain reputation goes with it and legitimate mail starts landing in junk.
  • Customer data exposure. On a store or any site collecting personal information, that becomes a POPIA matter with reporting obligations attached.
  • The clean-up bill. Emergency remediation from an agency you have no relationship with typically runs R6,000 to R20,000, and more if there is no backup.
Compliance

Website security and POPIA

If your website collects names, numbers, email addresses or anything else identifying a person, you are processing personal information and POPIA applies to you. The Act requires reasonable technical measures to protect it, and a breach carries a duty to notify both the Information Regulator and the people affected.

Requirement

Reasonable safeguards

Encryption in transit through SSL, access control, patching and monitoring. All of it is the same work as ordinary website security, which is why compliance mostly falls out of doing this properly.

Requirement

Retention limits

Form submissions and enquiry records should not sit in a database forever. We configure retention so old personal information is cleared rather than accumulating indefinitely.

Requirement

Breach readiness

Knowing what was accessed matters as much as fixing it. Logging and file integrity monitoring mean a breach can be described accurately rather than guessed at.

Cost

Website security pricing

Website security is not an add-on. All six layers are on every maintenance plan, including the cheapest, because selling half a security posture would be worse than selling none.

On every plan

R1,250 per month

All six layers, daily scanning, cleanup included, from the Essential plan upward.

Emergency cleanup

from R4,500

For a site already compromised and not on a plan. Infection removed, entry point found and closed, Google review requested, then hardened.

Security audit

R2,500 once-off

A full review of an existing site: exposure, outdated components, access weaknesses and backup reality. Credited against your first three months.

Plan comparison on website maintenance packages, and the infrastructure behind it on managed hosting.

Straight answers

Website security questions we get asked

What does website security cost in South Africa?

Website security is included on every maintenance plan from R1,250 a month. Standalone, emergency cleanup of an already-hacked site starts at R4,500, and a once-off security audit is R2,500. Prevention is dramatically cheaper than remediation, which is the whole argument for a plan.

Is WordPress less secure than other platforms?

No, but it is the most attacked because it runs a large share of the web, so bots target it by default. Core WordPress is well maintained. Almost every compromise we see comes from an outdated third-party plugin rather than WordPress itself.

Is a security plugin enough on its own?

A plugin is one useful layer of website security out of six. A plugin cannot filter traffic before it reaches your server, cannot enforce your password habits, and cannot restore a site once the database is gone. It helps, and it is not a strategy.

How do I know if my site has been hacked?

Common signs are unexpected redirects, spam pages appearing in Google results for your domain, browser warnings, sudden traffic spikes from odd countries, or admin users you did not create. Often the first sign is a customer telling you, which is exactly what monitoring prevents.

My site is hacked right now. What do I do?

Do not delete anything, because the evidence of how they got in matters as much as the cleanup. Send us the address and we will assess it. Emergency cleanup starts at R4,500 and normally takes a day, plus a few days for Google to lift a warning once the review is filed.

What are nulled plugins and why do they matter?

Pirated copies of premium plugins, distributed free with the licence check removed. A large share of them have backdoors added deliberately. It is one of the fastest ways to hand someone full access to your site, and the saving is never worth it.

Do you offer penetration testing?

Not formal penetration testing, which is a specialist discipline with its own certifications. Our security audit covers configuration, exposure, outdated components and access control, which is what actually matters for a business website.

How often are backups taken and are they tested?

Nightly, stored off-site, kept thirty days. Restores are tested rather than assumed, because an untested backup is a hope rather than a plan and plenty of businesses only discover the difference at the worst moment.

Will security measures slow my site down?

The opposite, usually. Edge filtering means bad traffic never reaches your server, and the same edge network caches your pages closer to visitors. Sites typically get faster after being properly secured.

What if a hack happens while I am on a plan?

We clean it at no extra charge, restore from backup if needed, find and close the entry point, and file the Google review. Charging extra to fix something we were being paid to prevent would be indefensible.

Do I need two factor authentication?

Yes, and it is the single highest-value thing you can do in five minutes. Stolen and reused passwords are one of the two most common routes in, and two factor closes that route almost entirely.

Does website security affect my SEO?

Substantially. A flagged domain loses traffic immediately, injected spam pages get you demoted, and recovery takes longer than cleanup. A secure, fast site is also easier for Google to crawl, so the work supports SEO rather than sitting apart from it.

Next step, no cost

Find out what is currently exposed.

Send us your web address and we will run a free security scan: outdated components, known vulnerabilities, SSL configuration, exposed login endpoints and whether your backups are real. Written plainly, and yours to keep.

Scroll to Top