Website security is six layers, not one plugin.
Almost nobody is targeted personally. Sites get hacked because automated bots scan the whole internet for known vulnerabilities and find one that was never patched. Website security is the unglamorous discipline of making sure they find nothing, and of being able to restore in an hour if they ever do.
Perimeter clearScanned daily, blocked constantly
The six layers of website security
A security plugin is one layer, and it is the fourth most useful of the six. Real protection is depth, so that any single failure is caught by the next thing behind it.
The edge firewall
Traffic is filtered before it ever reaches your server. Known bad actors, bot networks and automated vulnerability scanners are refused at the edge, which stops most attacks costing you anything at all.
Access control
Two factor authentication enforced, individual accounts rather than one shared login, correct role levels, and login attempts rate-limited. Weak credentials remain the most common way in.
Patching discipline
Core, plugins and themes updated weekly on staging first. Vulnerabilities published in the CVE database get exploited within hours, so the gap between a fix existing and you applying it is the whole risk.
Scanning and integrity checks
Daily malware scans plus file integrity monitoring, which flags any file that changed when it should not have. That is usually how an intrusion gets caught early rather than weeks later.
Tested backups
Nightly, off-site, thirty day retention, with restores actually performed rather than assumed to work. This is the layer that turns a disaster into an inconvenience.
Response
If something does get through, we clean it, restore, find the entry point and close it, then handle the Google review request if the domain was flagged. Included on every plan.
Depth, so that any single failure is caught by the layer behind it.
The five ways website security fails in South Africa
In rough order of frequency. None of them involve anyone deciding to target your business specifically.
| Route in | How common | What stops it |
|---|---|---|
| Outdated plugin with a published exploit | Most common by far | Weekly patching on staging |
| Weak or reused admin password | Very common | Two factor, enforced |
| Nulled or pirated premium plugin | Common | Licensed plugins only |
| Abandoned plugin no longer maintained | Common | Audit and replace |
| Compromised shared hosting neighbour | Less common | Isolated container |
What a compromised site actually costs you
- Google flags the domain. Visitors get a red interstitial warning instead of your site, and it stays until a review is requested and passed.
- Rankings drop. Malware and spam injections get sites demoted quickly, and recovery takes longer than the cleanup does.
- Email deliverability suffers. If the server was used to send spam, your domain reputation goes with it and legitimate mail starts landing in junk.
- Customer data exposure. On a store or any site collecting personal information, that becomes a POPIA matter with reporting obligations attached.
- The clean-up bill. Emergency remediation from an agency you have no relationship with typically runs R6,000 to R20,000, and more if there is no backup.
Website security and POPIA
If your website collects names, numbers, email addresses or anything else identifying a person, you are processing personal information and POPIA applies to you. The Act requires reasonable technical measures to protect it, and a breach carries a duty to notify both the Information Regulator and the people affected.
Reasonable safeguards
Encryption in transit through SSL, access control, patching and monitoring. All of it is the same work as ordinary website security, which is why compliance mostly falls out of doing this properly.
Retention limits
Form submissions and enquiry records should not sit in a database forever. We configure retention so old personal information is cleared rather than accumulating indefinitely.
Breach readiness
Knowing what was accessed matters as much as fixing it. Logging and file integrity monitoring mean a breach can be described accurately rather than guessed at.
Website security pricing
Website security is not an add-on. All six layers are on every maintenance plan, including the cheapest, because selling half a security posture would be worse than selling none.
On every plan
All six layers, daily scanning, cleanup included, from the Essential plan upward.
Emergency cleanup
For a site already compromised and not on a plan. Infection removed, entry point found and closed, Google review requested, then hardened.
Security audit
A full review of an existing site: exposure, outdated components, access weaknesses and backup reality. Credited against your first three months.
Plan comparison on website maintenance packages, and the infrastructure behind it on managed hosting.
Website security questions we get asked
What does website security cost in South Africa?
Website security is included on every maintenance plan from R1,250 a month. Standalone, emergency cleanup of an already-hacked site starts at R4,500, and a once-off security audit is R2,500. Prevention is dramatically cheaper than remediation, which is the whole argument for a plan.
Is WordPress less secure than other platforms?
No, but it is the most attacked because it runs a large share of the web, so bots target it by default. Core WordPress is well maintained. Almost every compromise we see comes from an outdated third-party plugin rather than WordPress itself.
Is a security plugin enough on its own?
A plugin is one useful layer of website security out of six. A plugin cannot filter traffic before it reaches your server, cannot enforce your password habits, and cannot restore a site once the database is gone. It helps, and it is not a strategy.
How do I know if my site has been hacked?
Common signs are unexpected redirects, spam pages appearing in Google results for your domain, browser warnings, sudden traffic spikes from odd countries, or admin users you did not create. Often the first sign is a customer telling you, which is exactly what monitoring prevents.
My site is hacked right now. What do I do?
Do not delete anything, because the evidence of how they got in matters as much as the cleanup. Send us the address and we will assess it. Emergency cleanup starts at R4,500 and normally takes a day, plus a few days for Google to lift a warning once the review is filed.
What are nulled plugins and why do they matter?
Pirated copies of premium plugins, distributed free with the licence check removed. A large share of them have backdoors added deliberately. It is one of the fastest ways to hand someone full access to your site, and the saving is never worth it.
Do you offer penetration testing?
Not formal penetration testing, which is a specialist discipline with its own certifications. Our security audit covers configuration, exposure, outdated components and access control, which is what actually matters for a business website.
How often are backups taken and are they tested?
Nightly, stored off-site, kept thirty days. Restores are tested rather than assumed, because an untested backup is a hope rather than a plan and plenty of businesses only discover the difference at the worst moment.
Will security measures slow my site down?
The opposite, usually. Edge filtering means bad traffic never reaches your server, and the same edge network caches your pages closer to visitors. Sites typically get faster after being properly secured.
What if a hack happens while I am on a plan?
We clean it at no extra charge, restore from backup if needed, find and close the entry point, and file the Google review. Charging extra to fix something we were being paid to prevent would be indefensible.
Do I need two factor authentication?
Yes, and it is the single highest-value thing you can do in five minutes. Stolen and reused passwords are one of the two most common routes in, and two factor closes that route almost entirely.
Does website security affect my SEO?
Substantially. A flagged domain loses traffic immediately, injected spam pages get you demoted, and recovery takes longer than cleanup. A secure, fast site is also easier for Google to crawl, so the work supports SEO rather than sitting apart from it.
The rest of what we do
Website security is one part of what we do. Start from website design company in South Africa for the overview.
Find out what is currently exposed.
Send us your web address and we will run a free security scan: outdated components, known vulnerabilities, SSL configuration, exposed login endpoints and whether your backups are real. Written plainly, and yours to keep.