CYBERVMsTHE HOSTING FIELD GUIDEINDEPENDENT BY DESIGN ↗

FIELD GUIDE / CYBERSECURITY

Security starts
with responsibility.

A security badge is less useful than a clear answer to “Who handles this, and how do we recover?”

Protect the control accounts

Ask whether multi-factor authentication is available for the registrar, DNS, hosting and administrator accounts. Prefer phishing-resistant options where supported. Keep recovery methods secure and limit who has administrator access. CISA’s guidance explains the importance of strong authentication.

Ask about recovery, not just backups

Find out what is backed up, where copies are kept, how long they remain available and how a restore works. Ask about restore costs and test recovery. A backup claim without a workable restore process is hard to rely on. CISA recommends protected backups and restoration testing.

Divide the update work

Make a list: operating system, runtime, CMS, plugins and application dependencies. Assign an owner to each. A managed host may handle only some layers; confirm its support scope before assuming maintenance is covered.

Understand what HTTPS proves

TLS protects information in transit; it does not secure every endpoint or application. See the OWASP TLS guidance. The FTC also warns that encrypted sites can still be fraudulent. Check the actual company, terms and account controls.

When you need more than a checklist

Workloads with sensitive data, complex access or specific obligations deserve a qualified assessment of the whole system. This guide is a set of buying questions, not a security audit or certification.