CIS Controls v8.1, the website owner's edition
Your website is the part you can see. Hackers go after the parts you can't.
The server underneath it. The domain that points to it. The email that goes out in your name. The backups you hope are there. Here are the CIS Controls that protect all of it, in plain English, with a 24-point self-check.
Nobody breaks in through the front page.
They don't have to. Your homepage is the one part of your website everybody looks at, so it's the one part that's usually fine.
The trouble is everything behind it. A server still running a version of PHP its makers stopped fixing years ago. A domain registrar account with a password from 2017 and no second step at login. An email setup that lets anyone on earth send a convincing invoice "from" you.
None of it shows on the page. All of it shows up in the breach report.
The Center for Internet Security, a nonprofit, publishes a list of the security practices that stop most real attacks. They call them the CIS Controls. Version 8.1 has 18 Controls and 153 specific Safeguards, and it's one of the most respected checklists in the business.
It was written for whole companies, though. Laptops, office Wi-Fi, USB sticks. Most of it has nothing to do with your website.
So we went through every Safeguard and kept only the ones that protect a website and the services it runs on. Then we turned them into 24 plain yes-or-no questions, grouped by the six places attackers actually go.
Tick the ones that are true today. It takes about ten minutes, and you might need to ask whoever looks after your hosting.
The CIS Controls website self-check
Now ask who checked.
Most of these answers come from memory. "The host handles backups." "The developer turned on two-step login." "I'm sure the domain auto-renews."
Maybe. But attackers don't work from memory. They look. And the layers on this page are the ones website owners look at least, because nothing on them shows on the homepage.
Our Certification Audit looks for you. A real person checks your server, domain, DNS, email, backups and logs, alongside hands-on testing of the site itself, aligned with ISO/IEC 27001. You get a written report in plain English, a fix list ranked by risk, one free retest, and the Hacker Fortified Certified badge when the serious issues are gone.
Already fixed? Fortified Watch keeps checking every month: software support dates, certificate and domain expiry, DNS changes, email records and backup freshness.
Nobody ever wished they'd checked the back door later.
All 18 CIS Controls
How much each one matters to a website.
Our own rating, from the point of view of a website and the services behind it. Every Control matters to a company. Not every Control matters to a website.
| CIS Control | For your website | Self-check |
|---|---|---|
| 1 · Inventory and Control of Enterprise AssetsKnow every server and service the site runs on. | Medium | c1, c4, c15 |
| 2 · Inventory and Control of Software AssetsUnsupported software on the server is one of the most common problems we find. | High | c1, c2, c4 |
| 3 · Data ProtectionCustomer data, encryption on the way in and at rest, deleting what you don't need. | High | c3, c9 |
| 4 · Secure Configuration of Enterprise Assets and SoftwareServer hardening, firewalls, default accounts, unused services. | High | c6, c7 |
| 5 · Account ManagementEvery login for hosting, server, database, CMS, registrar, DNS and email. | High | c7, c13, c16 |
| 6 · Access Control ManagementSecond login step on everything exposed and every admin account. | High | c7, c10, c13, c19 |
| 7 · Continuous Vulnerability ManagementPatching on a schedule, scanning from the outside, fixing by a deadline. | High | c5, c11 |
| 8 · Audit Log ManagementKeeping logs long enough to find out what happened, and reading them. | High | c16, c23 |
| 9 · Email and Web Browser ProtectionsThe email half matters a lot (DMARC, filtering). The browser half is about staff computers. | Medium | c17–c19 |
| 10 · Malware DefensesMalware scanning and exploit protection on the server. | Medium | c8 |
| 11 · Data RecoveryBackups that are automatic, separate and tested. | High | c21, c22 |
| 12 · Network Infrastructure ManagementMostly your host's job, unless you run your own server or cloud network. | Low | c6 |
| 13 · Network Monitoring and DefenseFile-change alerts and a web application firewall are the website parts. | Medium | c8 |
| 14 · Security Awareness and Skills TrainingThe phishing that targets website owners specifically. | Medium | c20 |
| 15 · Service Provider ManagementYour host, registrar, email, payments, plugin makers and agency. | High | c1, c14 |
| 16 · Application Software SecurityThe OWASP Top 10 covers most of this. | High | c11, c12 |
| 17 · Incident Response ManagementWho does what on the day the site is hacked. | High | c24 |
| 18 · Penetration TestingSomeone qualified attacking the site on purpose, at least once a year. | Medium | Our audit |
Questions
About the CIS Controls.
What are the CIS Controls?
The CIS Critical Security Controls are a prioritized set of security practices published by the Center for Internet Security, a nonprofit. Version 8.1 has 18 Controls made up of 153 specific Safeguards, grouped into three Implementation Groups so smaller organizations know where to start.
Do the CIS Controls apply to a small website?
Many of them do. The Controls were written for whole organizations, so some are about laptops and office networks. But the ones about servers, software updates, accounts, logs, backups, email and suppliers apply directly to the server, domain and services behind any website.
What is CIS Implementation Group 1 (IG1)?
IG1 is the first and smallest set of Safeguards, 56 of the 153 in version 8.1. CIS describes it as essential cyber hygiene: the minimum every organization should have in place, whatever its size. Most of the self-check above comes from IG1.
Do the CIS Controls cover DNS and domain security?
Only indirectly. The general Safeguards on accounts, multi-factor login, inventories, logs and suppliers all apply to your registrar and DNS provider, but there is no Safeguard specifically about registrar locks, domain renewal or dangling DNS records. We check those anyway.
My host says they handle security. Isn't that enough?
Your host secures their part: the building, the network, sometimes the operating system. Your accounts, your software, your DNS, your email records and your backups are usually yours. Read your hosting agreement for the exact line. Most website owners are surprised where it falls.
Is Hacker Fortified affiliated with CIS?
No. We're an independent website security firm. This page is our own plain-English guide; it's not CIS content and isn't endorsed by CIS. For the official Controls, go to cisecurity.org/controls.
CIS Critical Security Controls® and CIS Controls® are registered trademarks of the Center for Internet Security, Inc. Control names and Safeguard numbers refer to CIS Controls v8.1, © Center for Internet Security, licensed under CC BY-NC-ND 4.0. The current version is always at cisecurity.org/controls.