After-Incident Checklist (Security + Validation)
-
Verify service functionality:
-
Website loads and admin login works.
-
ERP login works (if applicable).
-
-
Rotate credentials (recommended after major incidents):
-
Client area password
-
Hosting control panel password
-
WordPress admin passwords
-
FTP/DB user passwords
-
-
Update software:
-
WordPress core/plugins/themes
-
Remove unused plugins/themes
-
-
Scan for malware indicators:
-
Unexpected admin users
-
Unknown files in uploads
-
Suspicious redirects
-
-
Purge cache/CDN
-
Purge LiteSpeed cache and any CDN cache if used.
-
-
Monitor for 24–48 hours:
-
Errors, performance issues, failed emails, or abnormal traffic patterns
-