Work through this list once, and re-check it every few months. Most compromised accounts we deal with had skipped two or three of these.
- Use a long, unique password for cPanel, and a different one for your Client Area.
- Enable two-factor authentication on both cPanel and the Client Area.
- Keep your cPanel contact email on a different domain, so warnings still reach you if the account fills up or mail breaks.
- Keep all website software updated: WordPress core, themes, plugins, and any custom framework.
- Delete software you no longer use. Inactive plugins and old installations are still attackable code.
- Never install nulled or cracked premium software.
- Give developers their own FTP account limited to one folder, not your main cPanel login.
- Remove FTP accounts, email accounts and admin users for people who have left.
- Set file permissions to 755 for folders and 644 for files. Never 777.
- Run AutoSSL on every domain and force HTTPS.
- Keep off-server backups you have actually tested restoring.
- Scan with ImunifyAV periodically and act on what it reports.
- Keep your own computer patched and free of malware. A keylogger on your laptop defeats every server-side control.
If you are unsure about any item, open a ticket and we will check it with you.