Skip to main content Scroll Top

We trusted specialists with our websites. Here’s what we found.

FTI Insights: Security

We build technology for a living. We run managed IT for our clients, we write our own software, and we’ve been on the Internet since its earliest days in Alaska. So when it came to our own marketing websites, we did what we’d tell any client to do with work outside their core: we hired a company that specialized in it.

A few years later, we checked on them. What we found changed how we think about website hosting, and it’s why we now offer secure web hosting ourselves.

What we found

We moved two of our websites, the one for our IBeXc hosted phone system and this one, off their old hosting and onto our own infrastructure. Before either went live, our team went through every file and every database table.

The IBeXc website: an active compromise

The IBeXc site was not just out of date. It was compromised, and had been for about two months:

  • Ten administrator accounts created by attackers between 19 and 26 July 2026, one of them still in use the night before we moved the site. Any one of them could have changed the site, stolen form submissions or planted more malware.
  • Two hidden back doors disguised among about 25 decoy files that load on every page, plus ten fake plugins.
  • Roughly 75 malicious program files tucked into the uploads folder, where images and documents are supposed to live.
  • A hidden installer that ran every time a page loaded, ready to put the malware back if anyone removed it, and a scheduled task that re-armed it every hour.
  • The site’s security plugin switched off by the attackers, so it could no longer raise the alarm.

The site looked normal to visitors. Nothing on the surface said anything was wrong.

This website: neglect, not yet a breach

Our own finitetech.net site was cleaner. We found no malware. What we found instead was years of neglect, the kind that turns into a breach eventually:

  • Software frozen in time. The site ran on PHP 7.4, a version that stopped receiving security fixes in November 2022, according to the PHP project. It couldn’t be upgraded because the site depended on it.
  • Premium plugins years out of date, including a page builder whose folder had been renamed, which quietly stopped it from ever receiving updates, and slider plugins with publicly known security flaws.
  • An update trap. One key plugin was installed in a way that meant a routine “update” would have silently replaced it with a different version and broken the site.
  • A forgotten administrator account from the original build, still active, protected by an outdated password format.
  • Email credentials for a cloud mail service stored in the site’s database, readable by anyone with access to the old hosting.
  • Leftovers everywhere: tools from previous hosts, plugins nobody used, and demo “lorem ipsum” text still sitting on the homepage.

Why this happens

None of this required a clever attacker or a careless owner. It’s what happens when a website is treated as a one-time project instead of a system that needs looking after.

The website was built, it worked, and everyone moved on. Updates were skipped because they might break something. Plugins were blocked from updating to keep things stable. Nobody was watching the site itself, so nobody noticed when someone else started using it. Commodity hosting doesn’t watch for these things, and a web design company isn’t always set up to run security operations.

If it happened to us, a technology company that knew to hire a specialist, it’s happening to a lot of businesses right now.

How we approached it

We didn’t just clean up the two sites and move on. We treated it the way we treat any problem for a client: find out exactly what happened, fix the cause rather than the symptom, and build something that stops it happening again.

  1. Investigate everything. Every file, account and setting was reviewed before anything was trusted. Suspicious files were quarantined and kept as evidence, not just deleted.
  2. Remove the causes. Abandoned plugins, dead accounts and exposed credentials were removed or retired. Software came up to current, supported versions.
  3. Rebuild on a platform designed for security. That became our new secure hosting facility.

What we built

We designed and built a secure hosting platform around one principle: assume every website will be attacked, and put layers of protection in front of it and around it.

  • Every website isolated. Each site runs in its own environment with its own database. A problem on one can’t reach another.
  • Protected at the edge. Visitors reach the site through a global edge network that absorbs attack traffic and provides SSL, then through a Sophos web application firewall that filters attacks aimed at websites and WordPress.
  • Locked-down access. Each website server only accepts traffic from the security layers in front of it. There is no way around them.
  • Hardened by default. Uploaded files can’t run as programs, website backups can’t be downloaded, and features the site doesn’t use are turned off.
  • Backups out of reach. Backups are kept outside the website, where a compromised site can’t touch the copies you’d restore from.
  • Built the same way, every time. Servers are defined in code and rebuilt consistently, so a setting can’t quietly drift or be forgotten.
  • AI-assisted review and operations. AI works alongside our engineers, checking every file during onboarding and watching the platform around the clock. People make the decisions; the AI helps make sure nothing slips through.

Both of our websites now run on it, and so can yours.

What this means for your website

If your website was built a few years ago and has been quietly running since, it’s worth asking a few questions. When was it last updated? Who has admin access? Where are the backups? Is anyone watching it at all?

If you’re not sure of the answers, that’s the same position we were in. The difference is that we checked. Our article on whether your website is your weakest link walks through what to look for.

How FTI helps

Our secure web hosting is the platform we built for ourselves. Every website we take on goes through the same onboarding our own sites did: a full review, a cleanup of anything that shouldn’t be there, and protection set up before it goes live. It’s not commodity hosting, and that’s the point.

Talk to us about checking your website