Most owners choose a web host on price and a vague sense of brand familiarity, then never think about it again. But your host controls the machine your business runs on. When something goes wrong at 2 a.m. — a hack, a crash, a deleted file — the quality of that $10-a-month decision determines whether you're down for an hour or a week. Here are the questions that separate a real host from a cheap one, in the order they'll matter.
How isolated is my site from other customers?
On budget shared plans, hundreds of sites share one server, and weak isolation means a compromise of any of them can reach yours. Ask directly: if another customer on my server is hacked, can their processes read or write my files? You want to hear about account isolation or containerization, explained plainly. A salesperson who can't answer is an answer.
What do your backups actually restore?
Everyone says 'daily backups.' Push further: how far back do they go, are they stored on separate infrastructure, and can you restore a single file or only the whole site? Then the question that exposes the pretenders: have you tested a restore recently, and how long does one take? A backup that's never been restored is a rumor. Ideally, keep your own independent backup too — hosts have lost customer backups along with customer sites.
Who patches what?
The server runs an operating system, a web server, PHP or similar, and database software — all of which need security updates just like your plugins do. Ask who is responsible for patching each layer and how quickly critical fixes are applied. On managed plans the host should own all of it; on unmanaged plans that's your job, whether you realized it or not.
What happens when I'm hacked?
Ask what support does if your site is compromised: will they help identify the entry point, is malware cleanup included or a paid add-on, and what's the guaranteed response time for a security emergency? A written SLA measured in hours beats a marketing page that says '24/7 support' — those are different promises. Bonus points for hosts that proactively notify you when they detect malicious activity on your account.
Red flags worth walking away from
Be wary of hosts that charge extra for HTTPS certificates (free ones are standard now), still default to plain FTP instead of encrypted transfer, make it deliberately painful to migrate away, or bury renewal pricing that triples after year one. How a company handles your exit tells you how it will handle your emergencies.
Even the best host only secures the building — the site inside is yours to watch. Trust Guard's daily scanning covers that layer, alerting you to vulnerabilities and malware no matter whose server you're on.
Comments
No comments yet. Be the first to share your thoughts!