You pay for a security plugin, a firewall, maintenance — and your password is the company name plus 123. Here are the five minutes that make the biggest difference.
1. Two-factor login (2FA) — right now
Even if someone learns your password, they cannot get in without the second step. How: install a plugin (WP 2FA, Wordfence Login Security or Two Factor) → pick an app (Google Authenticator, Authy) → scan the code → store the backup codes somewhere safe.
Rule: 2FA on EVERY administrator account. Not a suggestion.
2. A password manager
Nobody remembers 40 different passwords — so everyone reuses one, and that is the real problem: one breached service means everything is breached. Bitwarden (free) or similar: one master password, the rest it remembers and fills in.
3. Which passwords to change NOW
- WordPress admin · cPanel/hosting · email · the database (if you set it manually) · FTP
- Anywhere you reuse a password from somewhere else
4. What a good password looks like
Long beats complicated: four random words are stronger and easier than Pa$$w0rd1. Better still: let the manager invent it — you never need to know it.
5. The details bots exploit
- The admin username — rename it; half of all attacks try only that one
- Limit login attempts — after 5 wrong tries, a pause
- Do not send passwords over chat or email; if you must, change them right after
- When an employee leaves: delete the account, do not just change the password
The reality
90% of the sites we clean were entered through an old version or a weak password — not an advanced attack. So: updates plus 2FA plus a password manager = a calm sleep, for free.