To defend your site against intrusion, keep an eye on your log files, FTP logs and order logs.
Create passwords that will be hard to guess - ideally a random sequence of letters and numbers of more than eight characters. Change your account password at a regular basis.
Before you install any scripts (including shopping carts) on your site, apply any security patches and search the web for known weaknesses.
We have included best practice tips here for your consideration:
1. Updated platform
Keeping your platform, whether Joomla, WordPress, or something else, up to date is a great step in security. Outdated versions have known security issues and these issues are disseminated among the hacking community. If you are unable to keep up with the latest feature release try to at the least keep up with the latest security release.
2. Minimum permissions
Files with elevated permissions allow hackers to write scripts onto the server and then cause them to be run remotely. A file with read, write and execute permissions are generally a bad idea. Keeping permissions to the lowest possible is the best idea. 600 permissions, meaning readable and writeable only by you, is the best general permission set.
3. Updated extensions
Many users will use old extensions just because the original developer did not continue to update. This leaves another security hole and can cause issues. The cost of updating the page every year or two is much less than the cost of the site going down in most cases.