The Hacker Fortified Standard
ISO 27001 was written for big companies. We rewrote it for your website.
Ten areas. Every one traced back to ISO/IEC 27001, the international benchmark for information security, and to ISO 9001 where it's about treating customers right. Nothing your website doesn't need.
Sooner or later, someone is going to ask whether your website is secure.
Maybe it's a bigger customer, with a security questionnaire that asks "Are you ISO 27001 certified?" Maybe it's an insurer. Maybe it's you, at 2 a.m., after reading about another site that got hacked.
"I think so" is not an answer anyone wants to give.
ISO/IEC 27001 is how serious organizations answer that question. But it was written for whole companies, with offices, departments and auditors. Full certification takes months, a certification body and a budget most website owners don't have.
So we did the hard part for you. We took every requirement that protects a website, its data and its customers, and organized it into ten areas we audit every time. Each area points back to the ISO clauses it comes from, so nothing is made up and nothing is missed.
Then we added something most security firms leave out.
The ISO 9001 difference
Most breaches don't start with a genius hacker. They start with a sloppy habit.
The plugin nobody was responsible for updating. The former contractor whose login still works. The customer complaint about "weird emails" that sat in an inbox for three weeks.
ISO 9001 is the international standard for running a business that serves its customers consistently. Its habits, like clear ownership, written procedures, listening to complaints and fixing root causes, close exactly the gaps attackers love. So area ten of our standard checks them. A website run soundly is a website that's harder to break into, and quicker to recover when something does go wrong.
We hold ourselves to the same habits. Every conversation is written and tracked, every engagement has a written scope before work starts, every report is checked against a quality checklist, and every complaint gets a root cause and a fix.
The ten areas
What we audit, and where it comes from.
References are to ISO/IEC 27001:2022 (clauses 4 to 10 and Annex A controls) and ISO 9001:2015.
| Area | ISO/IEC 27001 | ISO 9001 |
|---|---|---|
| 01 · Scope and ownershipWhat your site is, what data it holds, and who is responsible for keeping it safe. | 4.1–4.3, 5.1, 5.3, A.5.2, A.5.9 | 4.1–4.3, 5.1, 5.3 |
| 02 · Risk assessmentA written list of what could go wrong, how likely it is, how bad it would be, and what you'll do about it. | 6.1, 8.2, 8.3 | 6.1 |
| 03 · Access and passwordsWho can log in to the admin, hosting and email; multi-factor login; no shared or leftover accounts. | A.5.15–A.5.18, A.8.2, A.8.5 | — |
| 04 · Patching and configurationUp-to-date software, plugins and server; secure settings, encryption and security headers. | A.8.8, A.8.9, A.8.20, A.8.21, A.8.24 | — |
| 05 · Application securityHands-on testing of your logged-in site against the OWASP Top 10, and a safe way to make changes. | A.8.25–A.8.29, A.8.32 | 8.5.6 |
| 06 · Data protection and privacyCollect only what you need, keep it only as long as you need it, protect it while you have it. | A.5.33, A.5.34, A.8.10–A.8.12 | 7.5 |
| 07 · Suppliers and pluginsYour host, payment processor, email provider, plugins and agencies, and what each one can reach. | A.5.19–A.5.23 | 8.4 |
| 08 · Backups and monitoringBackups that are tested, logs that are kept, and someone who notices when something looks wrong. | A.8.13, A.8.15, A.8.16, A.5.29, A.5.30 | 7.1.3 |
| 09 · Incident responseA plan for the bad day: who does what, how customers hear from you, and how you learn from it. | A.5.24–A.5.28, A.6.8 | 8.2.1, 10.2 |
| 10 · Sound operationsWritten procedures, a real complaint process, customer feedback, fixing root causes, and a yearly review. | 7.5, 9.1–9.3, 10.1–10.2 | 7.5, 8.2, 9.1.2, 9.3, 10.2, 10.3 |
Hacker Fortified Certified
How a website earns the badge. And how it loses it.
A badge anyone can buy is worth nothing. So ours has rules, and they're published right here.
To earn it
- Complete a Certification Audit covering all ten areas.
- Fix every critical and high-risk finding. We retest to confirm.
- Fix every medium finding, or sign a written, dated plan to fix it.
- Have the core documents in place: scope, risk register, access rules, backup and recovery procedure, incident response plan, supplier list and complaint procedure. We give you templates.
- Sign a short commitment to keep these controls in place.
To keep it
- The badge is valid for 12 months from your audit, or continuously while you're on Fortified Watch, which includes the yearly re-audit.
- It's suspended if a new critical finding stays unfixed for 30 days, if it isn't renewed, or if a breach is traced to a control that was dropped.
- Each badge covers one domain and links to a public verification record, so a copied badge exposes itself.
What the badge is not. Hacker Fortified Certified is our own certification against our own standard. It is not an ISO/IEC 27001 certificate, which only accredited certification bodies can issue. It means your website has been independently audited against practices drawn from ISO/IEC 27001 and ISO 9001, and that every serious issue we found was fixed. No website is unhackable, and we never claim otherwise.
Questions
About the standard.
Is the Hacker Fortified Standard an ISO standard?
No. It is our own audit standard, built on ISO/IEC 27001:2022 and ISO 9001:2015 and scoped to what a website owner controls. We reference the ISO clause and control numbers so you can see exactly where each requirement comes from.
Can I get ISO 27001 certified through you?
Not directly. Only accredited certification bodies can issue an ISO/IEC 27001 certificate, and they audit your whole organization, not just your website. What we can do is get your website and the practices around it aligned first, so that if you go for formal certification later you start well ahead.
Why include ISO 9001 in a security audit?
Because many breaches start with sloppy operations rather than clever hackers: nobody owns the updates, complaints get lost, changes go live untested. ISO 9001 is the international standard for running a business that consistently serves its customers well, and its habits make a website safer too.
Does the standard cover physical security?
Mostly no. If your site is hosted with a provider, the data center is their responsibility, so we cover it by reviewing your hosting supplier rather than your office locks.
Where does your site stand?
Find out in ten minutes, free. Or ask us to look.
Score your own site with our free checklist, or start a written conversation and a person will reply within one business day.