A hacked site can destroy years of reputation: homepage replaced, customer data stolen, SEO destroyed. In Morocco, law 09-08 strictly regulates personal data protection. Here are the best practices.
1. HTTPS obligatoire. The padlock in the address bar is the first sign of trust for your customers — and a Google ranking criterion. All our sites are delivered with a free SSL certificate.
2. Passwords and access. Strong password for the administrator, two-factor authentication if possible, and access limited to the necessary people only. It's the #1 cause of intrusions.
3. Regular updates. A static showcase site (like the ones we deliver) is naturally safer than a site with dozens of plugins. If you use WordPress, update theme, plugins and core as soon as a release comes out.
4. Automatic backups. Back up your site and database every week, and test the restore. A backup you've never tested is worthless.
5. Compliance with law 09-08. Display a clear privacy policy (collection, use, individuals' rights), get consent for cookies and limit collected data to what's necessary.
6. Surveillez. A monitoring service (uptime + change detection) alerts you to problems before your customers notice.
Our plans include secure hosting, SSL and maintenance (from 190 MAD/month) with weekly backups. The showcase site starts at 2,499 MAD — security isn't an option, it's a standard.
Also read
Get a free quote → ← Back to blogThe attacks that really target small sites
A Moroccan showcase site is almost never hit by a targeted attack. It's hit by automatic sweeps looking for easy targets: outdated extensions, reused passwords, forms open to mass submissions. These bots don't choose their victims — they scan.
That changes the answer: securing a showcase site isn't about expensive firewalls, it's about basic hygiene applied regularly.
The five genuinely useful measures
None of these measures requires advanced technical skills. What makes them effective is regularity, not sophistication.
What to do the day the site is hit
- Take it offline to prevent spreading.
- Change all passwords, from an uninfected device — never from the site itself.
- Restore a backup from before the intrusion, and verify it's clean.
- Identify the entry point before putting the corrected version back online.
- Notify the host, and monitor the following days.
A restore is only useful if it was tested before the incident. A never-restored backup is an assumption, not protection.
The weak point is almost never the site
In most incidents we see on small-business sites, the entry point isn't a sophisticated flaw in the site itself — it's an account. A password reused on another compromised service, a hacked office mailbox, an admin access shared between former and current providers.
| Type of access | Risque courant | Mesure utile |
|---|---|---|
| Compte d'administration du site | Password shared between several people | Named accounts, separate rights, 2FA |
| Company mailbox | Entry point to password resets | 2FA et mot de passe unique |
| Hosting access | Forgotten and never revoked after changing providers | Access review once a year |
| Compte du nom de domaine | Domain theft or e-mail hijacking | Domain lock, contacts up to date |
| Comptes d'anciens prestataires | Access kept indefinitely | Revocation at the end of each assignment |
A fully updated showcase site can be compromised by an e-mail without two-factor authentication. Protection must therefore cover all access, not just the site.
Spotting an attempt before it succeeds
- An e-mail asking for your credentials, even if it looks like your host. No serious provider asks for a password by e-mail.
- A login alert from a country you've never been to. Deal with it the same day, not the following week.
- Unknown files in the site's space, or a URL that opens content you never published.
- Messages from your contacts reporting a strange e-mail sent from your address.
An isolated sign deserves a check; two simultaneous signs require immediate action, even before identifying the cause.
Reducing risk outside the site
Searching for your company on search engines also exposes exploitable information: plain-text e-mail address, org chart, names of software used. This data makes a credible phishing message easier.
A few habits are enough to reduce this surface: a general contact address rather than an individual one, a form rather than a public address on the site, and systematic verification of unusual requests through a second channel. A supplier asking to change bank details by e-mail only must always be confirmed by phone, at a known number.
Protect the domain as much as the site
The domain name is the hardest asset to recover. A domain left with a provider, whose contact e-mail is a forgotten address, becomes very difficult to take back if the relationship sours.
Three precautions are enough: register the domain in the company's name, keep the associated e-mail address up to date, and activate the domain lock against unauthorized transfers. These three steps take minutes and cover a risk that can cost years of history.