Short answer: Agencies can manage client website security with a repeatable five-stage process: run a baseline audit on every site you take on, agree in writing who is responsible for hosting, domain, updates and backups, fix the high-impact findings first, monitor certificates, HTTPS, headers and key pages continuously, and send clients a short, plain-language report on a regular schedule. This keeps clients safer, prevents embarrassing outages such as expired certificates, and turns security from an unpaid favour into a clear, billable service.
For web agencies and freelancers, client website security is an awkward topic. Clients assume “the agency handles it”, while the contract often says nothing about it. Then a certificate expires on a Friday evening, a plugin vulnerability is exploited, or a client’s e-mail starts landing in spam – and the agency gets the call. A simple, consistent process avoids most of these situations and makes the value of your work visible. This guide describes one that works for small and medium agencies.
The first week with a new client site
Taking over a site from another agency or an in-house developer is the moment when most hidden problems surface. A short onboarding routine makes sure you start from a known state:
- Collect access to the domain registrar, DNS, hosting, CMS, analytics and e-mail provider, each with a personal login for your team where possible. Ask the client to remove the previous provider’s access once the handover is complete.
- Take a full backup of files and database before you change anything, and store it off the server.
- Run the baseline audit and save the report.
- List all users with admin or editor rights and confirm with the client who still needs access.
- Inventory plugins, themes and integrations, noting which are outdated, abandoned or unused.
- Check domain and certificate expiry dates and put them in your monitoring.
- Send the client a short summary: what you found, what you will fix under the agreement, and what needs a separate decision.
This week of work pays for itself the first time it prevents an argument about who broke what.
Stage 1: Baseline audit for every site
Start with a baseline audit whenever you take on a new client or site, and for every existing site you manage. It gives you and the client a shared picture of where things stand before you change anything – which also protects you from being blamed for problems that already existed. A useful baseline covers:
- HTTPS: certificate validity and expiry, names covered, HTTP to HTTPS redirect, mixed content.
- Security headers: HSTS, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy, Content-Security-Policy.
- Software exposure: visible version numbers, outdated CMS, plugins and themes.
- E-mail authentication: SPF, DKIM, DMARC and MX records for the client’s domain.
- Basics beyond the scan: who has admin access, whether 2FA is used, where backups are stored, who owns the domain and hosting accounts.
Save the report with the date. It becomes the “before” picture for your later reports.
Stage 2: Agree who is responsible for what
Most security incidents at agency clients happen in the gaps between responsibilities. Write down, per client, who handles:
| Area | Typical options |
|---|---|
| Domain registration and renewal | Client owns and pays; agency has access |
| DNS changes | Agency, with client approval |
| Hosting and server updates | Hosting provider, agency or client’s IT |
| CMS, plugin and theme updates | Agency under a maintenance plan |
| Backups and restore tests | Host plus agency verification |
| SSL certificates | Host auto-renewal, monitored by agency |
| E-mail and its authentication | Client’s e-mail provider or IT, agency advises |
| Incident response | Agency first responder, within agreed hours |
Put the result into the maintenance agreement. Clients generally appreciate the clarity, and it prevents disputes when something goes wrong in an area nobody was paid to watch.
Stage 3: Fix in order of impact
Resist the temptation to fix everything at once. Prioritise:
- Anything causing or about to cause an outage – certificates close to expiry, broken HTTPS redirects, a domain near expiry.
- Known vulnerabilities – outdated plugins or themes with published security fixes, unsupported PHP versions.
- Access security – remove old admin accounts, enable 2FA, rotate shared passwords.
- Quick configuration wins – basic security headers, hiding version numbers, disabling directory listing.
- Longer projects – Content Security Policy, e-mail authentication tightening, backup improvements – planned and quoted separately.
Group related findings into tasks the client can approve, with a short explanation of the risk in business terms.
Stage 4: Monitor continuously
An audit is a snapshot; sites change every week. Monitoring catches regressions after updates, hosting changes or a client’s own edits. At minimum, monitor for every client site:
- certificate expiry, with alerts two to three weeks ahead;
- HTTPS availability and redirects;
- security headers and exposed versions after deployments;
- e-mail authentication records, which clients and their IT providers change more often than you might expect;
- key pages returning errors.
Route alerts to a shared agency inbox or channel with a named person on duty, not to whoever set up the tool years ago.
Stage 5: Report in plain language
Clients rarely read technical scan output. A short monthly or quarterly report works better:
- A one-line status: “All good”, “Two items need attention” or “Action required”.
- What was done in the period: updates applied, issues fixed, alerts handled.
- What is open, with a recommended next step and, where relevant, a quote.
- A simple trend, such as the audit score compared with the previous report.
Reports under your own brand reinforce that the maintenance fee buys real work, and they create natural moments to propose improvements.
When something goes wrong on a client site
Even with good processes, incidents happen: a hacked plugin, an expired certificate the host failed to renew, e-mail suddenly rejected because someone changed DNS. A prepared response keeps the damage and the stress small:
- Acknowledge quickly. Tell the client you are on it and when they will hear from you next, even before you know the cause.
- Contain first – maintenance mode, password changes, blocking the bad traffic – then investigate.
- Keep notes of times, findings and actions. They are essential for the client’s own obligations, for example if personal data may be involved.
- Fix the cause, not only the symptom, and re-run the audit to confirm the site is back to its baseline.
- Write a short follow-up: what happened, what was done, what will prevent it next time, and whether anything falls outside the current agreement.
Clients remember how an incident was handled far longer than the incident itself. Calm, transparent handling often strengthens the relationship.
Turning security into a service line
Many agencies give security work away for free, reacting to emergencies without billing. A structured offer changes that:
- Entry level: monitoring and alerts, monthly report, updates.
- Standard: adds backups with restore tests, security headers, access reviews, incident response within business hours.
- Premium: adds faster response, Content Security Policy work, e-mail authentication management, annual deeper review.
An audit of a prospect’s current site is also an honest, low-pressure sales tool: it shows concrete problems in plain language and what fixing them involves, without exaggeration.
Common agency pitfalls
- Domains registered in the agency’s or a former employee’s name.
- One shared admin login for the whole agency team, without 2FA.
- Staging copies left publicly accessible and never updated.
- Alerts going to a personal inbox of someone who has left.
- No written scope, so every incident becomes a negotiation.
- Forgetting DNS records for campaign subdomains after the campaign ends.
How Site AI Audit helps agencies
Site AI Audit covers the baseline and monitoring stages in one tool: SSL certificate and expiry, HTTPS redirect, security headers, exposed software versions, e-mail authentication (SPF, DKIM, DMARC, MX), SEO and speed, with every finding explained in plain words and ranked by impact. The Agency plan adds several websites per account, daily SSL and e-mail checks, reports with your own logo and an embeddable audit form you can use for lead generation on your own site. See the plans.
Related reading
- Website Security Scan vs Penetration Test: What You Need
- SSL Certificate Monitoring: How to Never Miss an Expiry Again
- Domain Hijacking: How to Protect Your Domain Name and DNS
The bottom line
A repeatable process – baseline audit, written responsibilities, fixes by impact, continuous monitoring and plain-language reports – protects client websites and the agency’s reputation at the same time. It turns security from an unpaid emergency service into a visible, billable part of maintenance, and it catches the most common problems, such as expiring certificates and outdated plugins, long before clients notice them.
KKK
Should agencies take responsibility for client website security?
Only for what is agreed in writing. Define which areas the agency handles, such as updates, monitoring and backups, and which remain with the client or their host, so expectations are clear when something happens.
How often should client sites be audited?
Run a baseline audit when you take on a site, monitor continuously, and review a full report monthly or quarterly depending on the maintenance plan. Re-check after every major update or hosting change.
Who should own the client’s domain?
The client’s company should be the registrant, in an account the client controls. The agency can be given access to manage DNS, which keeps ownership clear if the relationship ends.
How do I explain security findings to non-technical clients?
Translate each finding into its business effect, such as “visitors will see a warning page in 10 days”, and pair it with the fix and the effort needed. Keep the technical detail in an appendix.
Can audits help win new clients?
Yes, when used honestly. A clear audit of a prospect’s site shows concrete issues and what fixing them involves, which builds trust more effectively than generic sales claims.



