Knowledgebase

Reseller Account Security Checklist Print

  • resellerhosting, reseller, security, password, whm, email, domain, ftp, malware, twofactor
  • 0

Your account holds access to every client you host. Treat it accordingly.

YOUR ACCESS

Long, unique password on WHM, and a different one on the Client Area Two-factor authentication on both API tokens for billing integrations, never your password, scoped to what the integration needs Remove API tokens for systems no longer in use

YOUR PACKAGES

Max Email per Hour set on every package Real quotas, never unlimited Feature lists that do not expose anything clients should not have

YOUR ACCOUNTS

Unique passwords per client account, never a shared pattern Client contact emails set to addresses not on the domain being hosted Periodic review for accounts running abandoned software

YOUR OWN MACHINE

Kept patched and clean. Malware on your computer hands over every client you host in one go. Do not save WHM or FTP passwords unprotected in a client that stores them in plain text.

YOUR STAFF

Separate logins where possible, and revoke access promptly when someone leaves.

REVIEW QUARTERLY

Accounts, tokens, staff access, and abandoned client sites. Fifteen minutes, four times a year.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot