Who gets attacked (spoiler: you)
Small Egyptian business sites are attacked automatically, not personally. Bots scan the entire internet for WordPress versions with known holes, weak admin passwords and unmaintained plugins. 'We're too small to matter' is precisely why the attacks are automated — volume, not value. The average compromised small-business site hosts phishing pages, sends spam, or gets held for ransom within weeks of being forgotten.
The seven moves that matter
1. HTTPS everywhere — free via Let's Encrypt on any decent host; browsers now shame plain-HTTP sites.
2. Update discipline — CMS core, plugins and themes within days of security releases, or automatically. Most compromises we audit trace to a component that was 18 months out of date.
3. Backups that restore — a backup you've never test-restored is a rumor. Keep off-site copies (different provider/account) on a schedule matching how much data you can afford to lose.
4. Admin hygiene — unique strong passwords with a manager, 2FA on CMS admin/hosting/domain registrar, and no shared 'admin' account for three staff members.
5. Fewer plugins, fewer doors — every WordPress plugin is supply chain; delete what you don't actively use (deactivated isn't deleted).
6. Right-sized hosting — the EGP 50/month oversold shared host is where neighbor-site attacks become your problem; isolation costs a little more and sleeps better.
7. A recovery plan on one page — who has the credentials, where backups restore from, what to tell customers. Written before you need it, at 2 AM, in a panic.
Three myths that cause real breaches
'Our host handles security.' The host secures the machine; you secure the application, passwords and updates. Different layers, shared responsibility.
'We have nothing worth stealing.' Your site's reputation is worth stealing — phishing pages on a trusted Egyptian domain convert beautifully for criminals, and your SEO ranking dies with the cleanup.
'We're compliant, so we're secure.' Compliance (important!) is a floor drawn in paperwork; attackers don't read the audit, they read the attack surface.
If you've already been compromised
Contain first: take the site offline or to a maintenance page — serving malware to customers is worse than an hour of downtime. Preserve evidence for forensics. Rotate every credential, including domain registrar and email. Clean or restore from a pre-incident backup (clean is safer than patched-if-you're-unsure). Then close the hole — usually an outdated component — before relaunch. Google Search Console's security review comes last, or your traffic stays flagged.
Security is maintenance, not a product
There's no one-time purchase; there's a habit. We run care plans that handle updates, backups, monitoring and patching for client sites — but if you self-manage, put a monthly 30-minute 'update and verify backup' ritual on the calendar. That single habit defeats the majority of automated attacks.
Want a second pair of eyes? Ask us for a security review of your current site — we'll check the seven points above and tell you plainly where you stand.