Use unique credentials
Use unique passwords for your client account, control panel and application administration.
Keep applications updated
Outdated CMS software, plugins and dependencies are common sources of compromise.
Use HTTPS
Enable SSL for websites and avoid sending administrative credentials over unsecured connections.
Maintain backups
Keep backups appropriate to the importance and change frequency of your data, and periodically verify that they can be restored.