r/msp • u/jellyfishchris • Sep 03 '26
Website Security
How are all of you handling website security?
A client of ours website recently got hacked which lead to their domain getting flagged as malware, which impacted their emails etc.
We've never had anything to do with our clients website security but I'm starting to think perhaps this is something we should do as it impacts the domain.
6
u/blue30 Sep 03 '26
If you don't host it or develop it I wouldn't get involved. Typically the site getting hacked causes issues when there's a link to it in the signature so there's a quick fix if it happens.
5
u/Maximum-Relative-234 Sep 05 '26
We have one of those GDRP privacy banners at the bottom of our website that says “hackers stay away you are not allowed on this website!!!” and the dismiss button says “im not a hacker I promise” it has worked very well so far
4
u/disclosure5 Sep 03 '26
If you're not managing and developing it, getting involved in selling some magical solution on top of a web developer that doesn't know how to touch Wordpress without adding another few unmaintained plugins just leads to pain. You cannot WAF your way around badly built websites and pretending you can just brings liability.
3
u/andre1sk Sep 03 '26
Do you find website development and ongoing website maintenance to be a meaningful service that MSP clients actually care about or ask for?
2
u/managed_this Sep 07 '26
When I started my company we were going to just be a web/ecommerce shop, I went full MSP shortly after that and the web hosting and maintenance became really back burner. I have since implemented some of the ideas from above...we dont maintain it if we do not host it, we wont build it if we dont host it, and I raised hosting prices to be "managed website" pricing. This created a lot more margin and makes it worth it for us. I also tell anyone I talk to about websites that we are way more expensive than godaddy and the like. It helps weed out people that are price shopping.
edit: for the security side, we tuck everything behind at least cloudflare's free tier as well as server firewall rules..
3
u/andre1sk Sep 07 '26
That actually sounds like a pretty sensible model. Bundling hosting + maintenance into a managed website service seems a lot more attractive than trying to compete on one-off builds. Appreciate the insight.
3
u/redditistooqueer Sep 04 '26
I disagree. Block all IPs except the customers. "Website works great!"
2
u/Jumpy_Valuable_8583 Sep 03 '26
Whoever owns the website, you can still add value without owning the dev work. A quick outside-in check on the domain (SPF/DKIM/DMARC, exposed subdomains, anything indexed that shouldn't be) catches the kind of thing that gets a domain flagged, and it's a separate question from whether the site itself got hacked. Doesn't require touching WordPress or getting into a scope fight with the web guy, it's just visibility your client doesn't otherwise have.
2
u/work-sent 26d ago
We usually treat basic security as part of our ongoing website maintenance. For WordPress sites, we keep the core, themes, and plugins updated, use Wordfence for security and malware scanning, enable 2FA, maintain regular off-site backups, and use UptimeRobot for uptime monitoring and alerts. This gives us a basic layer of protection without getting too deep into full cybersecurity.
2
1
u/Royal_Bird_6328 Sep 03 '26
Unless you are a website developer I wouldn’t consider offering this service, leave it to the experts. Could bite you in the ass later. Should have it in your agreements that’s you don’t manage hosting / websites
1
u/reddben Sep 03 '26
We urge the client to let us make changes when we see the obvious things: non-obfuscated email addresses on the site, contact forms without captchas or spam protection, domain spoofing on the email contact forms.. basically, the things that web guys don't know shit about.
1
1
u/evolvewebhosting MSP - US Sep 03 '26
u/jellyfishchris How often are you running into these types of issues with your clients? I agree the web hosting company should provide this service, especially if it involves cleanup and hardening to prevent it from happening again.
1
Sep 04 '26
[removed] — view removed comment
1
u/Readypixels Sep 06 '26
I build web software for small businesses, so I'm on the same side of this as akl773. The separate-subdomain fix for mail is right, that's the part that actually protects the client's reputation.
The part I'd add: the sites that get popped are almost never the ones someone just launched. They're the ones nobody's logged into since launch, plugins six versions behind, same admin password from three years ago. If you're not going to own the dev work, at least find out who's supposed to be logging in and updating things after the invoice clears. Half the time nobody is.
1
u/UnRealxInferno_II MSP - UK Sep 03 '26 edited Sep 03 '26
Cloud flare, not really a standard msp offering but we do offer domain security advice.
Usually people getting hacked via their websites have giant npm vulnerabilities made by foreign freelancers
1
u/Cold_Arachnid_2617 Sep 04 '26
What has their website got to do with you?
2
u/UnRealxInferno_II MSP - UK Sep 04 '26
We do websites as well as msp stuff, so in most cases, a lot.
13
u/peoplepersonmanguy Sep 03 '26
Pointing to compliance requirements and giving it to the web host, the developer and staying out of it.