What you’ll need
- Client area, DirectAdmin and website admin access
- A password manager
- An authenticator app
Most compromises exploit a reused password or outdated software. An hour spent now closes the common routes in.
Steps
Step 1: Unique passwords everywhere
Generate new passwords for the client area, DirectAdmin, each mailbox and the website admin. Strong passwords and password managers
Step 2: Two-factor authentication
Turn it on at your domain registrar, your personal email and your website admin.
Step 3: Account email
Make sure the client area and registrar use an email address that isn’t on the hosted domain.
Step 4: HTTPS
Confirm the certificate and force HTTPS. Make your site secure with HTTPS
Step 5: Permissions
Check folders are
755and files644; nothing777. File permissions explained (644, 755 and why never 777)Step 6: Harden WordPress (if used)
Disable file editing, block PHP in uploads, limit logins and remove unused plugins and themes. How to secure a WordPress site
Step 7: Security headers
Add the safe starting set of headers. Adding security headers with .htaccess
Step 8: Remove leftovers
Delete test files, phpinfo pages, old installs, and zip or SQL files in
public_html.Step 9: Schedule the routine
Put a weekly reminder to apply updates and a monthly reminder to download a full backup. Keeping website software updated
Check it worked
Every login is unique and stored in your password manager, HTTPS is enforced, no 777 permissions or stray archives remain, and your update and backup reminders exist.
If something goes wrong
| What happens | What to do |
|---|---|
| Site breaks after adding headers | Remove X-Frame-Options or Permissions-Policy if the site embeds itself or uses those features. |
| Locked out of WordPress by a login limiter | Rename the plugin’s folder to disable it. Can’t log in to WordPress: fixes for common login problems |