Unique identities
Give each administrator an individual account. Shared credentials remove accountability and make offboarding unreliable.
Website security is an operating practice, not a plugin or a launch task. This checklist helps a business identify who owns each account, reduce avoidable access, maintain supported software, protect customer interactions, test recovery, and prepare for incidents.
Many website incidents become business crises because no one can reach the registrar, hosting account, backups, or deployment system. Ownership is a security control.
Give each administrator an individual account. Shared credentials remove accountability and make offboarding unreliable.
Require multi-factor authentication for registrar, DNS, hosting, content management, repository, deployment, email, analytics, and support systems.
Grant only the access required for the role and task. Separate content editing from site administration and infrastructure control.
Protect recovery email, phone, codes, and backup administrators. Test recovery before an emergency and after staff or vendor changes.
Use supported operating systems, runtimes, content systems, themes, plugins, libraries, and integrations. Subscribe to security notices for critical components. Test and apply updates through a defined process, with backups and rollback for changes that could affect production.
Remove unused software rather than leaving it disabled indefinitely. Minimize third-party scripts because each one adds code, data flow, availability, and supply-chain risk. Restrict deployment permissions and protect the main branch or production release process from casual changes.
Configuration matters as much as versions. Review file permissions, secret storage, database access, administrative paths, directory listing, error output, development tools, default accounts, sample content, and exposed backups.
| Control area | Checklist |
|---|---|
| HTTPS | Redirect all public traffic to HTTPS, monitor certificate expiry, and remove mixed content. |
| Forms | Validate input, limit data collection, control uploads, prevent abuse, secure delivery, and define retention. |
| Sessions | Use secure cookies, appropriate timeouts, protection against request forgery, and careful error messages. |
| Payments | Use reputable payment services and avoid collecting or storing payment data the business does not need. |
| Secrets | Keep API keys, passwords, and tokens out of public code, browser scripts, logs, and downloadable backups. |
| Privacy | Know which data each form and third party receives, why it is needed, where it goes, and who can access it. |
Back up the website files, databases, content, configuration, DNS, redirect rules, and other components required to rebuild service. Keep copies separate from the production account so one compromised or failed system cannot destroy both the site and its backup.
Define recovery point and recovery time expectations based on business impact. Protect backups from unauthorized access, record retention, and test restoration. A successful backup notification does not prove the website can be recovered.
North Star provides website maintenance, hosting and care, and broader cybersecurity services for Canadian businesses.
There is no single control, but business ownership of critical accounts, MFA, supported software, tested backups, and a named response owner prevent many common failures from becoming prolonged outages or permanent losses.
Review security notices and available updates continuously through a defined maintenance process. The appropriate installation timing depends on severity, exposure, compatibility, testing, and rollback readiness rather than an arbitrary calendar alone.
No. HTTPS protects data in transit between the visitor and the website. It does not replace secure software, access control, input validation, backups, monitoring, safe configuration, incident response, or protection of administrative accounts.
Not as the only copy. Keep recoverable backups separate from the production environment and protect them with access control and retention. Test restoration so the business knows the backup contains everything required.
The business should control the registrar account, administrative contacts, renewal, MFA, and recovery process. A trusted provider may manage the domain, but ownership and the ability to transfer or recover it should remain with the business.
North Star designs, rebuilds, hosts, and supports business websites remotely across Canada. Bring the checklist or brief to a scope call and we will translate it into a clear proposal.
Request a Website ScopeExplore Web Design