1. Forced HTTPS, everywhere
Not just the login page — every page, every asset. Mixed content and unencrypted forms are still shockingly common on business sites launched in the last few years.
2. Automated dependency updates
The majority of website breaches exploit known vulnerabilities in outdated dependencies, not novel zero-days. A boring, automated update process closes most of the door.
3. A real backup you've actually tested restoring
A backup you've never restored is a hypothesis, not a plan. Test the restore process before you need it, not during an incident.
4. Rate limiting on every public form
Contact forms, login pages, and search boxes are common targets for automated abuse. Basic rate limiting stops the vast majority of it cheaply.
5. A written incident response plan
Who gets called, in what order, doing what — decided calmly in advance, not improvised during an actual breach.