Blog / security monday
Notes from the field.
Short, practical pieces on the problems we fix most often. No trends, no fluff.
3 min
What a hacked site looks like from the server side
The signs we see on our servers when a site is compromised, from outbound spam to rogue admins, and why cleanup fails without finding the way in.
3 min
SSL beyond the padlock
Getting a certificate is the easy part: this Security Monday covers redirects, HSTS in plain terms, mixed content and keeping renewals boring.
3 min
Backups that actually restore
A backup only counts if it restores, so this Security Monday covers restore testing, retention, offsite copies and what your host does and does not do.
3 min
Nothing is broken: why you still need updates
Most hacked sites we clean up were running software with a known, already-patched hole, so here is how to update without fear of breaking things.
3 min
Passkeys, 2FA and your hosting account
Your hosting account controls email, DNS and every file on your site, so here is how we lock ours down and who should still have access to yours.
3 min
The five WordPress security habits that stop most hacks
The five habits we see separating clean WordPress sites from hacked ones on our servers, and how to make each one part of your routine.