For most businesses, the website is the front door. If it goes down, slows to a crawl or gets compromised, enquiries and sales stop and customer trust takes a hit. That’s why security isn’t a box we tick at launch at Adao. It’s built into how we design, develop, host and look after every site for its whole lifetime.
Here’s a look at what that means in practice.
Regular updates, with live vulnerability alerts
WordPress powers a huge share of the web, and its core is constantly audited and pentested by a large global community. When they find a weakness, a fix is released. That fix only protects you if it’s actually installed.
Under our support and maintenance agreements, we update WordPress core, themes and plugins every month. Every update is logged, recording exactly which versions moved from what to what, so we always have a clear history if something needs investigating.
Monthly isn’t always fast enough, though. Through our hosting and security partners, we receive live alerts when a plugin on one of our sites is flagged as vulnerable. When an urgent security patch lands, we apply it the same day rather than waiting for the next scheduled round.
Fewer plugins, trusted sources, no legacy code
Every plugin added to a site is another piece of code someone else wrote, and another potential way in. So we keep the list short and deliberate. A standard Adao build uses a small set of well-established, actively maintained plugins.
Before anything new goes on a site, we check who maintains it, how often it’s updated and its security track record. If a plugin is abandoned by its developer, we replace it. Inactive themes and plugins are removed entirely, because code that sits unused still carries risk.
The same applies to our own codebase. We build to clear coding standards using current web technologies, and avoid discontinued libraries or legacy code that no longer receives security fixes. When something is deprecated, it’s written so it can be swapped out cleanly.
Secure by design: testing before launch
Security starts long before a site goes live. Every build goes through a penetration testing phase where we actively look for weaknesses, the same way an attacker would.
That includes making sure:
- Every user input, from contact forms to search boxes, is sanitised and validated
- Nothing on the front end can expose or query the database in ways it shouldn’t
- Forms, file uploads and custom features follow WordPress and wider industry best practice
- Sites are served over SSL, with certificates we obtain, install and renew for you
After launch, we carry out quarterly audits covering security alongside performance and accessibility, so standards don’t slip over time.
Two-factor authentication on accounts
A strong password is no longer enough on its own. We make sure users with access to a site’s admin area have two-factor authentication (2FA) set up, and on some WordPress sites we enforce it so no one can log in without it.
We apply the same thinking to our own access. Admin credentials are stored in a secure password manager and cycled regularly, and hosting accounts are protected with multi-factor authentication and single sign-on where available.
Hosting that’s built for WordPress
Where a site is hosted matters as much as how it’s built. We recommend WP Engine, a managed hosting provider whose servers are optimised specifically for WordPress.
On standard plans, that brings:
- Firewall protection and active threat blocking, with Cloudflare providing CDN, DDoS protection and a web application firewall
- Patching and plugin risk scans by dedicated security experts
- Annual SOC 2 audits and ISO 27001 certification
- A choice of hosting region, including the UK and Europe, to support data-residency requirements
For enterprise sites, the Global Edge Security add-on adds a further layer of protection.
Fallbacks for when things go wrong
No system is ever 100% immune, so we plan for the moment something does go wrong.
- Uptime monitoring watches every site around the clock and alerts us the moment one stops responding, often before your customers notice.
- Daily backups which are kept for up to 60 days, and a one-click restore takes around five minutes. Our clients can access these restore points from their hosting account.
- Internal backups on our own servers run daily as a second layer, retained for up to two weeks.
Only storing what a site needs
The safest data is data you never hold. Our sites are deliberately built not to store sensitive customer information.
- No payment details. Card data is handled entirely by a dedicated, PCI-compliant payment gateway or booking engine, never stored by the website itself.
- No identity documents. Where a form allows file uploads, we restrict what can be submitted and don’t allow forms of ID or sensitive personal documents to be stored on the site.
- Minimal personal data. Forms only collect what’s needed, which keeps the impact of any incident small and supports GDPR compliance.
A clear plan if a site is breached
If the worst happens, speed and a clear process are what limit the damage. Our response follows a set order:
- Contain. Lock down access, reset credentials and take affected parts of the site offline if needed.
- Assess. Identify how the attacker got in and what, if anything, was accessed.
- Restore. Roll back to the most recent clean backup, typically within minutes.
- Fix. Close the vulnerability so the same route can’t be used again.
- Communicate. Keeping our clients informed throughout and providing a report.
We also provide clients with emergency points of contact. Outside of office hours we have recommended providers who can offer the site 24/7 support.
Training our team and our clients
Technology only goes so far. Many breaches start with a weak password, a phishing email or a well-meaning mistake.
Every member of our team is trained on our company security policy, and it forms part of every new starter’s induction. We also help clients’ teams stay safe, covering things like setting up 2FA, spotting suspicious emails, managing user roles and knowing when to get in touch. A secure site is a shared responsibility, and we make sure everyone involved knows their part.
Peace of mind, built in
Secure, stable websites don’t happen by accident. They come from careful builds, trusted tools, strong hosting, constant monitoring and a clear plan for when things go wrong. That’s the standard we hold every Adao site to, so our clients can focus on running their business.
Want to know how your current website measures up? Get in touch with our team for a security review.