πŸ›‘οΈ
Security

Ransomware Protection for Websites: Practical Guide

πŸ“… 9 October 2026 ✏️ 9 October 2026 ⏱ 5 min leestijd

How do you protect a website against ransomware? Concrete measures for backups, updates, access, and recovery.

Ransomware on a website often enters through outdated software, weak passwords, or vulnerable plugins. Once inside, the attacker encrypts files or the database and demands a ransom for recovery. The best protection combines prevention (updates, access management, malware scans) with a safety net of reliable, separate backups so you never have to pay to get your site back.

How ransomware gets into a website

Most infections don’t start with an advanced hack, but with a simple mistake. Common entry points include:

  • Outdated CMS software, themes, or plugins with known vulnerabilities
  • Weak or reused passwords for FTP, the hosting panel, or CMS login
  • Phishing emails targeting administrators or staff with website access
  • Insecure file upload functions on the website itself
  • Shared hosting environments where an infected neighboring site spreads over

Once inside, the attacker often first plants a backdoor, so access remains even after a password change. Only later does the actual encryption of files follow.

WebsiteUpdates & scansSeparate backup

Preventive measures

Prevention starts with reducing the attack surface. The following measures significantly lower the risk:

  • Updates: keep CMS, plugins, themes, and server software always up to date
  • Strong, unique passwords per account, supplemented where possible with two-factor authentication
  • Limited access rights: give users only the permissions they need
  • Firewall and malware scans at the server level to block known threats before they cause damage
  • Safe email use, since phishing is often the first step toward an infection; an email service with strict spam filtering and authentication helps here

Anyone switching to a new hosting environment can use this moment to clean up outdated installations and unnecessary accounts, for example via switching to Tandata.

πŸ’‘ Tip: Remove plugins, themes, and CMS installations you no longer use. Unused software is rarely updated and is a common entry point for attackers.

Backups as the last line of defense

Even with all precautions, the risk of infection remains. A working, separate backup is therefore the most important guarantee that you’ll never have to negotiate with an attacker. When it comes to backups, pay attention to the following points:

  • Backups are made automatically and daily, without manual action
  • Backups are stored separately from the live environment, so ransomware cannot encrypt them
  • Multiple versions are available, so you can go back to a point before the infection
  • Restoring is easy to perform, without external technical help

With web hosting via Plesk, you’ll find the backup settings under the ‘Backups’ tab, where you can set both the frequency and the number of versions kept, and restore a previous version with one click.

What to do in case of an infection

If a website does become infected, acting quickly and systematically is important to limit further damage.

1

Take the site offline

Temporarily disable the website or hosting account to stop spreading to other files or visitors.

2

Change passwords

Change all passwords: hosting panel, FTP, CMS login, and linked email accounts.

3

Restore from backup

Restore a clean backup from before the infection, not the most recent one if it may already be infected.

4

Fix the vulnerability

Update the software that caused the issue and remove any remaining backdoors before the site goes live again.

5

Check and monitor

After recovery, check files and user accounts again and keep a closer eye on the site for new anomalies.

Never pay a ransom: there is no guarantee that files will actually be released, and it funds further criminal activity. If you need help with recovery, check the knowledge base or contact your hosting provider.

Frequently asked questions

Can ransomware also infect a website via email?

Not directly, but phishing emails are often used to steal administrator login credentials, which the attacker then uses to gain access to the website. A business email solution with good spam filtering reduces this risk.

Is a free SSL certificate sufficient protection?

SSL secures the connection between the visitor and the server, but does not protect against ransomware. It is, however, a basic requirement for secure data traffic and belongs on every website.

How often should a backup be made?

Daily is sufficient for most websites, as long as multiple versions are kept so you can also go back to a point before a possible infection.

Does a firewall fully protect against ransomware?

A firewall blocks many known attack patterns, but it is no guarantee. Always combine it with updates, strong passwords, and working backups.

What if my domain name also appears to be hacked?

Check the DNS settings in your domain names management for unexpected changes and reset them to the correct values if necessary.

Conclusion

Ransomware protection for websites is about combining prevention with a reliable safety net: up-to-date software, strong access control, and above all daily, separate backups that let you always recover without paying. This way, an infection remains an annoying incident instead of permanent data loss.

View web hosting β†’

Was dit artikel nuttig?