Joomla! World Conference 2026

The recent wave of hacks on CMS-powered websites has brought into sharp focus the question of whether a site can be attacked. 
Let’s get the uncomfortable question out of the way right away: It’s not “Will my site be hacked?” but “When will my site be hacked?”


After more than fifteen years of fixing hacked Joomla sites, I can tell you without hesitation that the question almost always arises too late, and the owner wasn’t prepared.

Everyone feels safe, but almost no one is prepared.

Ask any website owner (or any developer, for that matter) if their site is secure: They’ll tell you it is. Up-to-date software, a strong password, two-factor authentication, an application firewall, a properly configured security plugin: they’ve checked all the boxes and feel safe.

From what can be observed, it’s not the least-protected sites that suffer the most when an attack occurs. It’s the sites whose owners were most convinced they had done everything necessary. Confidence in prevention itself becomes a blind spot: we’ve locked the door so securely that we never imagined what we’d do if, despite everything, someone broke in through the window.

Prevention and survival are not the same thing

This is where I think we’re all going wrong (including industry professionals): everything we write, everything we sell, and everything we install is focused on preventing attacks but almost never on managing their consequences.

These are two different tasks that complement each other. The first reduces the likelihood that it will happen. The second determines how much time, money, and stress it will cost you on the day that, despite everything, it happens anyway. Almost no one is seriously working on the second one, because working on it means admitting that the first one won’t be enough. It’s an unpleasant feeling that people would rather avoid.

In short: We're fighting this battle with well-defended sites that aren't prepared to lose it.

A few examples

I can think of three very different stories that all tell the same thing.

The first: a nonprofit organization. No backups - just the web host, or so we thought. The emails warning about updates? Ignored. The email announcing that hosting would be suspended due to malicious files? Ignored as well. The day the site was wiped out, all that was left were tears. We spent days hunting down content here and there to reconstruct what no longer existed anywhere in a usable form.

Those lot hadn’t planned anything, apart from relying on luck – a whole lot of luck, in fact!

The second: a very conscientious site owner. Everything up to date, backups on the host’s end, backups on the site, backups downloaded locally: on paper, a model student. The site went down on a Friday night. Panic!! He initiated a restore, then a second one, into the wrong folders of course. He tried to fix everything himself: deleting suspicious files, rushing through a reinstallation. He overwrites elements we would have needed and forgets others. By the time I got to the case, the evidence of the intrusion had already disappeared. We had to start from scratch, blindly, without ever knowing exactly where the attacker had gained entry.

The third: a much more modest site, less well-equipped on paper. But it had a backup that had actually been tested, and the hosting provider’s contact information was written down somewhere and could be found in thirty seconds. And most importantly: nothing happened that first evening. The owner knew who to contact. He waited until the next morning, sent me a clear message describing the symptoms he’d observed, and the incident was resolved before noon.

The difference between the last two wasn't technical. It was the level of preparation for what came after, not for the attack itself.

Are you ready or just confident?

Now, here are the real questions you should ask yourself; not just when it happens:

  • If your website went down tonight, would you know what to do first, who to contact; and would you know what you absolutely shouldn't do? 
  • Has your latest backup ever actually been restored (at least once)or is it just a file you hope you'll never have to open?
  • If you were asked for your hosting account credentials within the next thirty seconds, would you have them? Would you at least know how to access them quickly?

If you hesitate on any of these questions, it’s not your prevention efforts that are at issue, but your preparation for what comes next; and those are two different things.

So, what are you going to do?

I don’t have a magic list to give you as a reassuring conclusion because every case is unique. That wouldn’t be honest: everyone talks about prevention, everyone sells it, everyone equips themselves with it. What no one really talks about is what happens next in the minutes, hours, and days following the discovery of the damage.

You will be hacked one day. Maybe in ten years, maybe tonight; and the question that really matters isn’t whether you’ll have prevented it, but what you’ll do when you haven’t been able to prevent it.

You can't judge a good captain on a calm sea: that is when the storm hits, it's already too late to learn how to navigate.


Inspired by : 
https://brian.teeman.net/joomla/1025-prepare-to-be-hacked
https://www.web54.fr/le-blog-d-une-agence-web-lorraine/pensez-pirate-avant-de-letre

About the author

Some articles published on the Joomla Community Magazine represent the personal opinion or experience of the Author on the specific topic and might not be aligned to the official position of the Joomla Project

Comments