The human side of website security
When people talk about website security, they often focus on the technology.
Is WordPress up to date? Are the plugins patched? Is the website behind a firewall? Is the hosting environment secure?
All of those things matter. But they only address part of the risk.
A website can be fully updated, professionally hosted and protected by multiple security tools, and still be compromised if somebody gains access to a legitimate administrator account. That’s because one of the biggest security risks isn’t always the technology. It’s the people who have access to it.
This is also an area where a good web agency can help. At TWK, we don’t just think about the security of the website itself; we also consider how access is managed and where we can put sensible safeguards in place. That can include reviewing user accounts, encouraging appropriate permissions and putting additional protection around privileged accounts.
A stolen password can be more risky than a technical vulnerability
Attackers don’t necessarily need to find a flaw in your website. If they already have a valid username and password, they can often simply log in through the front door.
From the website’s point of view, that activity can initially look completely legitimate. The user has supplied the correct credentials, WordPress has authenticated them, and they now have access to whatever permissions are associated with that account.
If it’s an Administrator account, that can include installing plugins, managing users and, depending on how the site is configured, modifying website code.
This is why technical website security and user security have to be considered together.
How do website credentials get stolen?
There are several common routes, and many of them happen completely outside the website itself.
Password reuse
One of the biggest risks is using the same password across multiple services.
If an unrelated website or online service suffers a data breach, attackers may obtain combinations of email addresses and passwords. Those credentials can then be tested against other services, including WordPress websites.
Your website doesn’t need to have been hacked for its administrator password to have been exposed somewhere else.
Every privileged account should therefore use a strong, unique password that isn’t shared with any other service. Where appropriate, we can also help clients put policies and technical controls around website access, rather than relying entirely on individual users to make the right decision every time.
Phishing
Phishing attacks have also become increasingly convincing.
An email might appear to come from Microsoft, Google, your hosting provider or even somebody within your own organisation. The recipient is directed to what looks like a genuine login page and enters their credentials, which are then captured by the attacker.
This is particularly relevant for marketing and communications teams, who often have access to a wide range of platforms including websites, CRM systems, email marketing tools, analytics and social media. One compromised login can potentially open the door to several systems.
Compromised devices
There is another risk that receives less attention: the computer or phone itself.
Information-stealing malware can collect credentials stored in browsers, saved passwords and active login sessions. In that situation, simply changing a website password may not be enough if the underlying device remains compromised.
That’s why a security response sometimes needs to extend beyond the website and include checks on the devices used by affected users.
Why two-factor authentication matters
This is where two-factor authentication (2FA) makes an enormous difference.
With a traditional login, the password is the key. Anyone who possesses it can potentially access the account.
With 2FA, knowing the password isn’t enough. The user also needs a second form of verification, typically an authenticator app, security key or another trusted method.
So even if a password is stolen through phishing, password reuse or a compromised device, the attacker still faces another barrier.
For privileged website accounts, particularly Administrators, 2FA should increasingly be considered a basic security requirement rather than an optional extra. It’s something we actively encourage and help our clients implement.
Do you really need Administrator access?
Another important question is how much access people actually need.
WordPress Administrator accounts have considerable power. That makes sense for developers and a small number of people responsible for managing the website, but many day-to-day users don’t need that level of control.
Someone responsible for updating news stories, editing pages or publishing content can often work perfectly well with an Editor-level account.
A good website access review should therefore ask:
- Who currently has access?
- Does each person still need it?
- Are there accounts belonging to people who have left the organisation?
- Are any accounts shared by multiple people?
- Is 2FA enabled for privileged users?
These are simple questions, but they can significantly reduce risk.
As part of ongoing website management, we can help clients review who has access, what level of access they need and whether old or unnecessary accounts should be removed. Keeping those permissions under control reduces the number of accounts that could potentially become a route into the website.
Security tools are important, but they aren’t the whole answer
Firewalls, malware scanners, secure hosting and regular software updates all play an important role. But none of them completely remove the risk associated with a legitimate account being compromised.
An attacker using valid credentials may initially look very similar to a genuine administrator. They can log in through the normal login page and potentially use legitimate website features to make malicious changes.
That is why good security also involves monitoring behaviour.
Useful controls can include alerts when new administrator accounts are created, logging successful logins, monitoring unexpected plugin installations and reviewing changes to sensitive website files.
These are the kinds of controls we consider when managing the security of client websites. The exact approach depends on the website and its hosting environment, but the aim is the same: to make unusual activity easier to spot and reduce the opportunity for a compromised account to cause damage.
Website security is a shared responsibility
It’s tempting to think of website security as something that sits entirely with developers, hosting providers or IT teams.
In reality, it crosses all of those areas.
Web agencies need to keep the platform secure and help manage website access. Hosting providers need to protect the infrastructure. IT teams need to manage devices and organisational access. And website users need to protect their credentials.
Our role at TWK is to take as much of the website-side responsibility away from individual users as we reasonably can: keeping WordPress and its components maintained, managing access appropriately, applying available security controls and helping clients understand where their own processes and people form part of the security picture.
That doesn’t mean everyone needs to become a cybersecurity expert. It does mean adopting a few sensible habits:
- Use unique passwords
- Enable 2FA
- Be cautious with unexpected login requests
- Don’t share accounts
- Remove access when somebody leaves
- Keep Administrator permissions to a minimum
- Raise unusual website behaviour quickly
How we protect our clients’ websites
Website security shouldn’t depend entirely on users remembering to follow best practice. As part of managing WordPress websites, TWK actively helps clients:
- Keep WordPress, themes and plugins maintained and up to date
- Review user accounts and permissions
- Encourage and implement 2FA for privileged accounts
- Reduce unnecessary Administrator access
- Monitor for unusual or potentially malicious activity
- Apply appropriate security controls to the website and hosting environment
- Identify when a security issue may involve users, devices or wider organisational access
The exact measures we use depend on the website, its hosting environment and the organisation’s requirements. But the aim is always the same: to make security something that’s managed proactively, rather than something that’s only addressed after an incident.
The strongest website security combines technology and people
Keeping software updated, using secure hosting and deploying security tools are all essential. But they protect only one side of the equation.
The other side is making sure that the people who have access to the website, and the credentials they use, are protected too.
Because sometimes an attacker doesn’t need to break into your website at all.
They just need to log in.