Website protection: 12 steps in order of value and how they tie to the law
What an owner should do to avoid a break-in and a fine: 12 steps from HTTPS to a leak plan, with a free generator for each step.
Checked against sources: 12 October 2026

- 12protection steps in order of value
- 72 hoursEU breach notification deadline (GDPR Art. 33)
- 3items to start with this week
Steps that remove most of the risk
- HTTPS on every page, automatic certificate renewal and HSTS.
- Security headers and a CSP: start in report-only mode (the headers generator).
- Secret files closed: .env, .git, dumps and backups are not on a public path.
- Updates: the engine, plugins and libraries no older than a few months; unused plugins removed.
- Two-factor sign-in for the admin and the host, unique passwords, access only for those who need it.
- Backups not on the same server and a tested restore.
- A cookie consent that really blocks trackers until consent, and a reject button as easy as accept.
- A privacy policy, consent on forms and return terms for a shop.
- SPF, DKIM and DMARC for email, CAA for certificates (the DNS records generator).
- security.txt with a contact for vulnerability reports.
- Customer data stored where your country’s law requires.
- A leak plan: who decides, whom to notify, how and by when.
A plan for a leak
In the EU the controller must notify the supervisory authority within 72 hours of becoming aware of a breach that threatens people’s rights (GDPR Art. 33). Check the deadlines and procedure in other countries against local law and decide in advance who in the company is responsible. A leak you learn of from customers costs more than one you report yourself.
How not to burn out
You do not need to do it all in a day. Run an Awe Check scan, take the three heaviest items from “What to fix” and close them this week. Then work down the list. If you need help the report has a “Fix it for me” button.
Frequently asked
Where to start with little time?
Three things: close secret files, turn on two-factor sign-in for the admin and make a backup off the server. That removes the most common causes of break-ins.
Do I need a WAF or a vulnerability scanner?
They help but do not replace the base: updates, passwords, closed files and headers. Start with the base.
How can I tell the site is already hacked?
Signs: unfamiliar pages and links, browser and search warnings, customers reporting spam in your name, a sharp traffic drop. Change passwords at once, check the files and restore from a clean copy.
