Syntra Systems
Cases Services Products About Blog IT Caravan
+998 70 010 68 44 +7 999 900 22 12
RusEngUzb
Close-up of a steel locking wheel on a dark background — illustration for an article about protecting a website from hacking
Security

How to protect your website from hacking: a checklist for business

By Nikita Zhulin · · 9 min read

A website is protected in four layers: access, updates, a traffic filter in front of the site, and logs with backups. The first two layers stop most attacks, because those attacks are not aimed at your company — they run down a list of known vulnerabilities automatically, across every site in reach. The rest is covered by regular review: a vulnerability that does not exist today can arrive with the next plugin update.

Key takeaways

  • Most break-ins start not with password guessing but with a publicly described vulnerability: according to Verizon DBIR 2026, 31% of breaches begin that way.
  • The median time from the disclosure of a vulnerability in the WordPress ecosystem to mass attacks is five hours, so updates go in on a schedule rather than now and then.
  • After a hack you first save a copy of the site and the logs and only then clean up: without evidence the cause stays unknown and the site is broken into the same way.
  • Article 27 of the Law on Personal Data requires legal, organisational and technical measures from the owner and the operator — for a site with a contact form that is an obligation.
  • A security audit at Syntra Systems costs from $1,200, fixing what was found from $4,000, and monitoring and response from $800 per month.

How sites are most often broken into

Most often through a known vulnerability in the site's code, its plugins or the server, rather than through guessing an administrator's password. That is why a small company's site in Tashkent is exactly as interesting to an attacker as a large portal: it is found by a scanner, not by a person.

The set of typical entry points barely changes from year to year. In the current OWASP Top 10:2025 list, built on data from more than 2.8 million applications contributed by 13 organisations, the top three places went to broken access control, security misconfiguration and failures in third-party components — exactly the things that are configured by hand on a site and then forgotten.

External contractors and services are a story of their own. According to the same report, a third party was involved in 48% of breaches, and over the year that share grew by 60%. For a website, a third party means the plugin developer, the agency, the freelancer, the payment module and the analytics script: each of them gets access either to the server or to the page in the visitor's browser.

How to tell that a site has already been hacked

Signs of a hack are usually visible from the outside, and it is not the owners who spot them but the search engine or the customers. Check against six signs.

Google reports the problem in the Security Issues report in Search Console: the service's help pages list three categories — hacked content, malware and unwanted software, social engineering. While the label is in place, a warning appears next to the link in search results and the browser shows the visitor a full-screen warning. The label is removed after the site is cleaned and a review is requested, and the review itself takes from several days to several weeks.

Important Access to Search Console and to the Yandex.Webmaster account should be in place before an incident, not created on the day of the hack: the notification is sent only to verified site owners.

What to do if your site has been hacked

The sequence starts not with deleting malicious code but with preserving the evidence: without logs the cause cannot be found, and in a week the site will be broken into the same way.

  1. Save a copy of the site exactly as you found it, together with the server logs. This is the material for the investigation and must not be overwritten with a clean copy.
  2. Put up a holding page or restrict access if the site takes payments or collects personal data.
  3. Change passwords everywhere: hosting panel, database, site admin, FTP and SSH, mail on the domain, accounts of employees and contractors.
  4. Revoke API keys and integration tokens — payments, mailings, CRM. The password is changed, but a live token keeps the door open.
  5. Deploy a copy in a separate environment and compare the files with the reference distribution of the system and the plugins: that is how added code is found.
  6. Update the content management system, plugins, theme and server environment to current versions.
  7. Check accounts and settings: new administrators, substituted email addresses, scheduler jobs, redirect rules, SSH keys.
  8. Turn on the second factor, restrict admin access and request a review in Search Console.
  9. Assess whether personal data reached outsiders: your obligations under the law depend on that.

The last step is not a formality. What counts as a breach, who is notified and within what deadline, we covered in the article on liability for a personal data leak.

A website security checklist: what to check first

Baseline protection is not a single product but eight settings that are made once and then maintained. Go through the list and mark what you are missing.

We wrote about automatic certificate reissue and uptime monitoring in the material on website technical support, and about restore testing in the article on backups of 1C and CRM. The principle is the same: a setting that has never been tested does not work on the day of the incident.

Does a site need a WAF and DDoS protection?

A WAF and DDoS protection solve different problems: the first filters out requests that carry the signs of an attack on the application, the second keeps a flood of traffic from taking the server down. A site with a client portal, payments or an API needs both mechanisms; a simple corporate site is covered by a filter on the content delivery network.

The value of a WAF is not that it replaces updates but that it buys time. Hours pass between the disclosure of a vulnerability and mass attacks, and pushing a plugin update to a live site untested is risky: a rule on the filter closes the hole while you test the update on a copy.

DDoS is rarely an end in itself for a business such as a shop or a clinic. More often it is a side effect: the site has landed on somebody's target list, a botnet is sweeping it, or aggressive scraping is under way. The result is the same — pages open slowly, forms stop submitting, and leads are lost without the owner noticing.

Tip Before buying a filter, hide the server: if the site's real address is visible in the DNS record history or in the headers of outgoing mail, attack traffic will bypass the filter and go straight to the server.

What the personal data law in Uzbekistan requires

A contact form, a client portal or a cart means that you process personal data, and protecting it is an obligation under the law. Article 27 of the Law on Personal Data No. ZRU-547 requires the owner and the operator to take legal, organisational and technical measures: protection against interference in private life, preservation and integrity of data, confidentiality, and prevention of unlawful processing. Article 31 adds the duty to designate a responsible unit or official.

In website terms this comes down to a few concrete things: separated access rights to leads, a log of who viewed and exported the database and when, an encrypted channel, deletion of data once the purpose of processing has been met, and written notice to a person when their data is passed to a third party. It is convenient to check these requirements together with the rest of the protection: the same settings cover them.

Mistake Assuming that responsibility for visitors' data sits with the contractor who built the site. The duty rests with the owner and the operator of the database: a contract with a contractor distributes the work but does not transfer liability towards the person or the state authority.

Who is responsible for website security: you, the host or the contractor?

Responsibility splits into three zones, and the gaps appear where every party treats the task as somebody else's. Lay it out in a table and make sure every row has an owner with a first and last name.

What we protectHosting or cloudWebsite contractorThe owning company
Hardware, network and power of the facilityResponsibleNot involvedChooses the facility
Operating system and web serverResponsible on a managed planConfigures it on its own serverDecides whose server it is
Updates of the system, plugins and themeNot responsibleInstalls them under a support contractPays for them and keeps control
Site code and the vulnerabilities in itNot responsibleFixes what is foundOrders the review
Passwords, second factor and access rightsProvides the mechanismConfigures the rolesKeeps the list of people and access
Backups and restore testingCopies the facilityCopies the site and the databaseChecks that a copy can be deployed
Personal data of visitorsNot responsibleNot responsibleResponsible as owner and operator

The most common gap is the updates row. The host does not install them, the contractor built the site under a one-off agreement and closed the project long ago, and inside the company nobody knows that updates are needed at all. Six months later the site is running a plugin with a vulnerability that has been public for months.

What it costs to put things in order and how we do it

The work splits into three services at different prices, because the tasks differ as well: first understand where the weak spots are, then close them, then keep watch.

When protection has to be checked not against a list of settings but by an actual break-in attempt, companies order penetration testing. For a website that makes sense after a major rework, before launching a client portal or payments.

At Syntra Systems we start with an audit rather than with selling protection: we look at the site, the server, access rights and integrations, collect a prioritised list of risks, and show what can be closed by a setting in a day and what needs rebuilding. Then we close what was found, set up updates, backups and logs, hand the access over to the company and, where it is needed, take the site under continuous security monitoring. We go through the report with your team in plain language — security works only when its rules are understood by more than one engineer.

Let’s discuss your project

Tell us what you need, and we will estimate the timeline and cost and suggest a solution.

Order a security audit

Frequently asked questions

How often should plugins and the content management system be updated?

On a schedule, not by chance: updates marked as security fixes go in straight away, the rest during a regular check every one or two weeks. The median time from the disclosure of a vulnerability to mass attacks is five hours, and a "when I get around to it" routine does not fit into that window.

Will a WAF protect a site that has not been updated for a long time?

Partly. A rule on the filter closes a specific vulnerability and buys time to test the update on a copy, but it does not fix the site code. A site with dozens of outdated plugins stays open through the holes for which no rules exist yet.

Can we restore the site from a backup and call the incident closed?

Not if the cause has not been found. A backup returns the files to their state before the hack, but the vulnerability used to get in stays where it was. First save the logs and find the entry point, then deploy the copy and update the system, the plugins and the environment to current versions.

Who is responsible before the law for the personal data of site visitors?

The owner and the operator of the database, that is the company itself. Article 27 of the Law on Personal Data requires legal, organisational and technical protection measures from them. A contract with a contractor distributes the work but does not transfer liability towards the person or the state authority.

What happens to search traffic if Google flags the site as hacked?

A warning appears next to the link in search results and the browser shows the visitor a full-screen warning, so visits drop. The label is removed after the site is cleaned and a review is requested in Search Console, and the review itself takes from several days to several weeks.

Does a small website need DDoS protection?

Yes, if downtime costs money: leads, payments, client bookings. The target is picked by a botnet sweeping addresses in turn rather than by a person — Cloudflare mitigated 47.1 million such attacks during 2025. A simple corporate site, meanwhile, is covered by a filter on the content delivery network.

How much does it cost to check a site and fix what is found?

A security audit at Syntra Systems costs from $1,200 and produces a list of risks with priorities and an assessment of consequences. Fixing what was found starts at $4,000, and continuous monitoring and response at $800 per month. Penetration testing is ordered separately.

Cover photo: Raul Ling, Pexels

Read also