A website is protected in four layers: access, updates, a traffic filter in front of the site, and logs with backups. The first two layers stop most attacks, because those attacks are not aimed at your company — they run down a list of known vulnerabilities automatically, across every site in reach. The rest is covered by regular review: a vulnerability that does not exist today can arrive with the next plugin update.
Key takeaways
Most often through a known vulnerability in the site's code, its plugins or the server, rather than through guessing an administrator's password. That is why a small company's site in Tashkent is exactly as interesting to an attacker as a large portal: it is found by a scanner, not by a person.
The set of typical entry points barely changes from year to year. In the current OWASP Top 10:2025 list, built on data from more than 2.8 million applications contributed by 13 organisations, the top three places went to broken access control, security misconfiguration and failures in third-party components — exactly the things that are configured by hand on a site and then forgotten.
External contractors and services are a story of their own. According to the same report, a third party was involved in 48% of breaches, and over the year that share grew by 60%. For a website, a third party means the plugin developer, the agency, the freelancer, the payment module and the analytics script: each of them gets access either to the server or to the page in the visitor's browser.
Signs of a hack are usually visible from the outside, and it is not the owners who spot them but the search engine or the customers. Check against six signs.
Google reports the problem in the Security Issues report in Search Console: the service's help pages list three categories — hacked content, malware and unwanted software, social engineering. While the label is in place, a warning appears next to the link in search results and the browser shows the visitor a full-screen warning. The label is removed after the site is cleaned and a review is requested, and the review itself takes from several days to several weeks.
Important Access to Search Console and to the Yandex.Webmaster account should be in place before an incident, not created on the day of the hack: the notification is sent only to verified site owners.
The sequence starts not with deleting malicious code but with preserving the evidence: without logs the cause cannot be found, and in a week the site will be broken into the same way.
The last step is not a formality. What counts as a breach, who is notified and within what deadline, we covered in the article on liability for a personal data leak.
Baseline protection is not a single product but eight settings that are made once and then maintained. Go through the list and mark what you are missing.
We wrote about automatic certificate reissue and uptime monitoring in the material on website technical support, and about restore testing in the article on backups of 1C and CRM. The principle is the same: a setting that has never been tested does not work on the day of the incident.
A WAF and DDoS protection solve different problems: the first filters out requests that carry the signs of an attack on the application, the second keeps a flood of traffic from taking the server down. A site with a client portal, payments or an API needs both mechanisms; a simple corporate site is covered by a filter on the content delivery network.
The value of a WAF is not that it replaces updates but that it buys time. Hours pass between the disclosure of a vulnerability and mass attacks, and pushing a plugin update to a live site untested is risky: a rule on the filter closes the hole while you test the update on a copy.
DDoS is rarely an end in itself for a business such as a shop or a clinic. More often it is a side effect: the site has landed on somebody's target list, a botnet is sweeping it, or aggressive scraping is under way. The result is the same — pages open slowly, forms stop submitting, and leads are lost without the owner noticing.
Tip Before buying a filter, hide the server: if the site's real address is visible in the DNS record history or in the headers of outgoing mail, attack traffic will bypass the filter and go straight to the server.
A contact form, a client portal or a cart means that you process personal data, and protecting it is an obligation under the law. Article 27 of the Law on Personal Data No. ZRU-547 requires the owner and the operator to take legal, organisational and technical measures: protection against interference in private life, preservation and integrity of data, confidentiality, and prevention of unlawful processing. Article 31 adds the duty to designate a responsible unit or official.
In website terms this comes down to a few concrete things: separated access rights to leads, a log of who viewed and exported the database and when, an encrypted channel, deletion of data once the purpose of processing has been met, and written notice to a person when their data is passed to a third party. It is convenient to check these requirements together with the rest of the protection: the same settings cover them.
Mistake Assuming that responsibility for visitors' data sits with the contractor who built the site. The duty rests with the owner and the operator of the database: a contract with a contractor distributes the work but does not transfer liability towards the person or the state authority.
Responsibility splits into three zones, and the gaps appear where every party treats the task as somebody else's. Lay it out in a table and make sure every row has an owner with a first and last name.
| What we protect | Hosting or cloud | Website contractor | The owning company |
|---|---|---|---|
| Hardware, network and power of the facility | Responsible | Not involved | Chooses the facility |
| Operating system and web server | Responsible on a managed plan | Configures it on its own server | Decides whose server it is |
| Updates of the system, plugins and theme | Not responsible | Installs them under a support contract | Pays for them and keeps control |
| Site code and the vulnerabilities in it | Not responsible | Fixes what is found | Orders the review |
| Passwords, second factor and access rights | Provides the mechanism | Configures the roles | Keeps the list of people and access |
| Backups and restore testing | Copies the facility | Copies the site and the database | Checks that a copy can be deployed |
| Personal data of visitors | Not responsible | Not responsible | Responsible as owner and operator |
The most common gap is the updates row. The host does not install them, the contractor built the site under a one-off agreement and closed the project long ago, and inside the company nobody knows that updates are needed at all. Six months later the site is running a plugin with a vulnerability that has been public for months.
The work splits into three services at different prices, because the tasks differ as well: first understand where the weak spots are, then close them, then keep watch.
When protection has to be checked not against a list of settings but by an actual break-in attempt, companies order penetration testing. For a website that makes sense after a major rework, before launching a client portal or payments.
At Syntra Systems we start with an audit rather than with selling protection: we look at the site, the server, access rights and integrations, collect a prioritised list of risks, and show what can be closed by a setting in a day and what needs rebuilding. Then we close what was found, set up updates, backups and logs, hand the access over to the company and, where it is needed, take the site under continuous security monitoring. We go through the report with your team in plain language — security works only when its rules are understood by more than one engineer.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
On a schedule, not by chance: updates marked as security fixes go in straight away, the rest during a regular check every one or two weeks. The median time from the disclosure of a vulnerability to mass attacks is five hours, and a "when I get around to it" routine does not fit into that window.
Partly. A rule on the filter closes a specific vulnerability and buys time to test the update on a copy, but it does not fix the site code. A site with dozens of outdated plugins stays open through the holes for which no rules exist yet.
Not if the cause has not been found. A backup returns the files to their state before the hack, but the vulnerability used to get in stays where it was. First save the logs and find the entry point, then deploy the copy and update the system, the plugins and the environment to current versions.
The owner and the operator of the database, that is the company itself. Article 27 of the Law on Personal Data requires legal, organisational and technical protection measures from them. A contract with a contractor distributes the work but does not transfer liability towards the person or the state authority.
A warning appears next to the link in search results and the browser shows the visitor a full-screen warning, so visits drop. The label is removed after the site is cleaned and a review is requested in Search Console, and the review itself takes from several days to several weeks.
Yes, if downtime costs money: leads, payments, client bookings. The target is picked by a botnet sweeping addresses in turn rather than by a person — Cloudflare mitigated 47.1 million such attacks during 2025. A simple corporate site, meanwhile, is covered by a filter on the content delivery network.
A security audit at Syntra Systems costs from $1,200 and produces a list of risks with priorities and an assessment of consequences. Fixing what was found starts at $4,000, and continuous monitoring and response at $800 per month. Penetration testing is ordered separately.
Sources