CIS Controls v8.1, the website owner's edition

Your website is the part you can see. Hackers go after the parts you can't.

The server underneath it. The domain that points to it. The email that goes out in your name. The backups you hope are there. Here are the CIS Controls that protect all of it, in plain English, with a 24-point self-check.

Nobody breaks in through the front page.

They don't have to. Your homepage is the one part of your website everybody looks at, so it's the one part that's usually fine.

The trouble is everything behind it. A server still running a version of PHP its makers stopped fixing years ago. A domain registrar account with a password from 2017 and no second step at login. An email setup that lets anyone on earth send a convincing invoice "from" you.

None of it shows on the page. All of it shows up in the breach report.

The Center for Internet Security, a nonprofit, publishes a list of the security practices that stop most real attacks. They call them the CIS Controls. Version 8.1 has 18 Controls and 153 specific Safeguards, and it's one of the most respected checklists in the business.

It was written for whole companies, though. Laptops, office Wi-Fi, USB sticks. Most of it has nothing to do with your website.

So we went through every Safeguard and kept only the ones that protect a website and the services it runs on. Then we turned them into 24 plain yes-or-no questions, grouped by the six places attackers actually go.

Tick the ones that are true today. It takes about ten minutes, and you might need to ask whoever looks after your hosting.

The CIS Controls website self-check

1. Know what you're running

You can't protect what you've forgotten you own. That's why the CIS Controls start with lists, before any lock or alarm.

On a real site: a developer set up old.yoursite.com for a redesign three years ago. Nobody updated it since. It still has a copy of the customer database, and it's the first thing an attacker's scanner finds.

In our audit: Standard area 01 (scope) and 04 (patching). We build the inventory with you, then check it from the outside to find what's missing.

2. The server

Most websites live on a Linux server, either your own or a slice of your host's. It runs 24 hours a day, and so do the bots knocking on it.

On a real site: the server accepts password logins for the root account from anywhere in the world. Bots try thousands of passwords an hour. One day, one of them works.

In our audit: Standard area 03 (access) and 04 (configuration and patching). We review the server's settings against an industry hardening baseline and scan it from the outside.

3. The website itself

Your code, your CMS, your plugins and your logins. The OWASP Top 10 guide goes deep on this layer. Here are the four CIS basics.

On a real site: a scanner flagged a vulnerable plugin in March. The report went to an inbox nobody reads. In June, the plugin was how they got in.

In our audit: Standard area 04 (configuration) and 05 (application security), together with hands-on testing against the OWASP Top 10.

4. Your domain and DNS

Your domain name is the master key. Whoever controls it can point your visitors, and your email, anywhere they like. Without touching your server at all.

On a real site: an attacker phishes the registrar login, changes two DNS records, and for six hours your customers type their passwords into a perfect copy of your site.

In our audit: Standard area 03 (access) and 07 (suppliers). We review the registrar and DNS accounts and check every record in your zone.

5. Email

Your website sends receipts and password resets. Your customers trust anything that arrives from your domain. Scammers know that.

On a real site: with no DMARC record, a criminal emails your customers a "new bank details" notice from your exact address. It lands in their inbox, not spam.

In our audit: Standard area 03 (access) and 04 (configuration). We read your DNS records, send a test message through your site and inspect what arrives.

6. Backups, logs and the bad day

Every defense on this page can fail. This layer decides whether a bad day costs you an afternoon or the business.

On a real site: ransomware encrypts the server. The host's backups sit on the same account, so they're encrypted too. The last clean copy is on a developer's laptop from last year.

In our audit: Standard area 08 (backups and monitoring) and 09 (incident response). We test a restore with you instead of taking it on trust.

0 / 24

Tick each statement that is true for your site.

Send my score for a free review

Now ask who checked.

Most of these answers come from memory. "The host handles backups." "The developer turned on two-step login." "I'm sure the domain auto-renews."

Maybe. But attackers don't work from memory. They look. And the layers on this page are the ones website owners look at least, because nothing on them shows on the homepage.

Our Certification Audit looks for you. A real person checks your server, domain, DNS, email, backups and logs, alongside hands-on testing of the site itself, aligned with ISO/IEC 27001. You get a written report in plain English, a fix list ranked by risk, one free retest, and the Hacker Fortified Certified badge when the serious issues are gone.

Already fixed? Fortified Watch keeps checking every month: software support dates, certificate and domain expiry, DNS changes, email records and backup freshness.

Nobody ever wished they'd checked the back door later.

Start a free written conversation

All 18 CIS Controls

How much each one matters to a website.

Our own rating, from the point of view of a website and the services behind it. Every Control matters to a company. Not every Control matters to a website.

CIS ControlFor your websiteSelf-check
1 · Inventory and Control of Enterprise AssetsKnow every server and service the site runs on.Mediumc1, c4, c15
2 · Inventory and Control of Software AssetsUnsupported software on the server is one of the most common problems we find.Highc1, c2, c4
3 · Data ProtectionCustomer data, encryption on the way in and at rest, deleting what you don't need.Highc3, c9
4 · Secure Configuration of Enterprise Assets and SoftwareServer hardening, firewalls, default accounts, unused services.Highc6, c7
5 · Account ManagementEvery login for hosting, server, database, CMS, registrar, DNS and email.Highc7, c13, c16
6 · Access Control ManagementSecond login step on everything exposed and every admin account.Highc7, c10, c13, c19
7 · Continuous Vulnerability ManagementPatching on a schedule, scanning from the outside, fixing by a deadline.Highc5, c11
8 · Audit Log ManagementKeeping logs long enough to find out what happened, and reading them.Highc16, c23
9 · Email and Web Browser ProtectionsThe email half matters a lot (DMARC, filtering). The browser half is about staff computers.Mediumc17–c19
10 · Malware DefensesMalware scanning and exploit protection on the server.Mediumc8
11 · Data RecoveryBackups that are automatic, separate and tested.Highc21, c22
12 · Network Infrastructure ManagementMostly your host's job, unless you run your own server or cloud network.Lowc6
13 · Network Monitoring and DefenseFile-change alerts and a web application firewall are the website parts.Mediumc8
14 · Security Awareness and Skills TrainingThe phishing that targets website owners specifically.Mediumc20
15 · Service Provider ManagementYour host, registrar, email, payments, plugin makers and agency.Highc1, c14
16 · Application Software SecurityThe OWASP Top 10 covers most of this.Highc11, c12
17 · Incident Response ManagementWho does what on the day the site is hacked.Highc24
18 · Penetration TestingSomeone qualified attacking the site on purpose, at least once a year.MediumOur audit

Questions

About the CIS Controls.

What are the CIS Controls?

The CIS Critical Security Controls are a prioritized set of security practices published by the Center for Internet Security, a nonprofit. Version 8.1 has 18 Controls made up of 153 specific Safeguards, grouped into three Implementation Groups so smaller organizations know where to start.

Do the CIS Controls apply to a small website?

Many of them do. The Controls were written for whole organizations, so some are about laptops and office networks. But the ones about servers, software updates, accounts, logs, backups, email and suppliers apply directly to the server, domain and services behind any website.

What is CIS Implementation Group 1 (IG1)?

IG1 is the first and smallest set of Safeguards, 56 of the 153 in version 8.1. CIS describes it as essential cyber hygiene: the minimum every organization should have in place, whatever its size. Most of the self-check above comes from IG1.

Do the CIS Controls cover DNS and domain security?

Only indirectly. The general Safeguards on accounts, multi-factor login, inventories, logs and suppliers all apply to your registrar and DNS provider, but there is no Safeguard specifically about registrar locks, domain renewal or dangling DNS records. We check those anyway.

My host says they handle security. Isn't that enough?

Your host secures their part: the building, the network, sometimes the operating system. Your accounts, your software, your DNS, your email records and your backups are usually yours. Read your hosting agreement for the exact line. Most website owners are surprised where it falls.

Is Hacker Fortified affiliated with CIS?

No. We're an independent website security firm. This page is our own plain-English guide; it's not CIS content and isn't endorsed by CIS. For the official Controls, go to cisecurity.org/controls.

CIS Critical Security Controls® and CIS Controls® are registered trademarks of the Center for Internet Security, Inc. Control names and Safeguard numbers refer to CIS Controls v8.1, © Center for Internet Security, licensed under CC BY-NC-ND 4.0. The current version is always at cisecurity.org/controls.