Most attacks are not aimed at a particular company, but at a known vulnerability. If you know the ways in, you can close most of them.
Two websites with the same vulnerability. Only one of them gets the update from June 2.
Using lists from other sites' data leaks. A password that is also used elsewhere falls first.
They sit for years with both sender and recipient. Whoever opens either mailbox has the website.
Pirated premium versions often come with malware. Deactivated plugins remain open to attack.
An attack is usually meant to go unnoticed. Still, it shows in these four places.
A red warning in the browser before your website appears
Strange terms or languages in search results for your company
An admin user that nobody created
Unknown links or redirects to someone else's offers
Sent in plain text for years.
Since then: one-time links only.
Active for months after a change of provider.
Since then: a checklist, review after 30 days.
Login protection blocks after failed attempts.
Most common support case: quickly solved.
If the site is only cleaned and the way in stays open, the malware comes back. That is why there is a fixed order.
The cycle starts over.
The incident is closed.
Updates, good passwords and a protected login area prevent most incidents. Every way in has a fixed countermeasure.