Skip to main content
HostingSeller
Shop plans

Trade Desk

One client's neglect is forty clients' problem

A single-site owner who gets compromised has a bad week; a reseller who gets compromised has a bad week multiplied by every customer on the pool.

Straight answer first

Buy hosting where isolation, server-level defences and genuine backups sit beneath whatever your clients install on top — security comes in layers, and the bottom layers are the ones you are buying rather than building.

The reseller-specific point is blast radius. You are not protecting one site; you are making sure that the client who has not updated a plugin since 2019 cannot become an incident for the thirty-nine who did. Isolation is what converts a shared platform from a shared risk into a set of separate ones, and it is the single most important thing on this page.

Written by the Hosting Seller staff · Checked 4 August 2026

24/7

Support that replies, day or night

1-click

WordPress setup, one click

Free

Certificates on every client site

Daily

Backups across the pool

For resellers and agencies carrying other people's websites. Your exposure is not really technical; it is that you will be the one explaining it, to several people at once, on a day you had planned to spend doing something else.

Infection spreading from one account to another defined the insecure years of shared hosting. Modern isolation such as CageFS put a stop to it, which means the architecture your supplier chose is a security decision every one of your clients inherits without ever hearing about it.

What isolation actually buys you

Accounts walled off from each other with CloudLinux-style containment, a firewall and malware response running at server level of the Imunify class, and separation that means a compromised account is a compromised account rather than a compromised server.

Translate that into your working life: one client to telephone instead of forty, one account to suspend, one restore to run. That is the entire commercial value of isolation, and it only becomes visible on the one day it matters — which is exactly why it has to be bought in advance.

The parts that remain yours

The platform contains the explosion; habits stop it starting. Updates, credentials, least-privilege access and a healthy suspicion of abandoned plugins are the application layer, and on a client book the application layer belongs to whoever the contract says.

Say which. Either you maintain plugins and themes under a care plan with a stated cadence, or the client does and you have told them so in writing. What you must never have is a book of forty sites where nobody has ever said out loud whose job the updates are.

The clean-up, and who pays for it

Decide the answer before you need it. A reasonable split: the platform-level response is your supplier's, the containment and restore is inside your retainer, and a full forensic clean of a client's application is billable work at a stated rate.

Backups are what make that affordable. A backup runs daily on every plan and restores from the panel in minutes, so the usual remedy is a restore to a known-good point plus an update, rather than an open-ended investigation with no ceiling on the hours.

The letter you send afterwards

Have a template ready: what happened, when it was contained, what was restored, what has changed to prevent a repeat, and what you need from them. Written calmly on the day, it turns an incident into evidence of competence.

Send it even when the fault was theirs. Especially then — a client who receives a clear account of their own neglect handled professionally becomes a client who approves the care plan they previously declined.

A shield icon standing in for site security and DDoS filtering

The supplier writing this would like the account

There is no affiliate arrangement behind this recommendation and no fee for its position. We host, we would like the account, and the page is more useful with that stated than implied.

Bring an existing site and we shift it across at no charge — usually inside 24 hours, with nothing going dark while we work.

  • Tests you can run before you commit a client
  • One trade price, held at renewal
  • Free migration for the sites you already host
  • A refund policy with no small print

Why Hosting Seller

On every plan, as standard

Accounts walled off from each other

CloudLinux-style containment means one neglected client site cannot become an incident for the rest of your book.

Imunify360 on every site

A firewall and malware response running at server level rather than a plugin somebody has to remember to renew.

Matched to this verdict

The Elite plan is this page's recommendation made concrete — one flat price, essentials included, upgradeable in place.

Restores you run yourself

A daily backup and a panel restore in minutes turns most incidents into a rollback rather than an open-ended investigation.

Suspension in one action

WHM gives you the switch, so containing a problem account does not require a ticket or a wait.

Cover behind your helpdesk

Real engineers on the counter at every hour, because incidents are not considerate about timing.

First Steps

From choosing to live

  1. 1

    Write down who owns updates

    Per client, in the contract. A care plan with a stated cadence, or an explicit statement that the client maintains their own applications. Silence always resolves to your fault.

  2. 2

    Rehearse a restore before you need one

    Restore a client backup onto a staging copy and time it. The number you get is the number you can promise, and the exercise finds the gaps while they are cheap.

  3. 3

    Keep the incident letter drafted

    What happened, when it was contained, what was restored, what changed, what you need. Written in advance, it takes ten minutes on the day instead of two hours.

In the Box

Packed with every plan

  • Accounts isolated from one another at the platform level
  • Imunify360 on guard on every client site
  • A backup taken daily, with restores you run yourself
  • DDoS filtering handled at the network edge for the whole estate
  • Suspension and resource limits under your control in WHM
  • Free SSL on every client site, reissued before it lapses
  • PHP versions picked per site, so one legacy client is contained
  • NVMe SSD storage on every shelf, not just the top one
  • A 99.9% uptime target, watched by monitoring day and night
  • Real people on the counter, every hour of every day

Across the Counter

Things people ask us all the time

If one client site is compromised, are my other clients exposed?

Not with proper isolation, which is the entire reason to care about the architecture your supplier chose. Accounts are walled off from one another, so the incident is confined to the account it started in. Your job then is containment and restore for that client, not an audit of the whole book.

Who should pay to clean up a hacked client site?

Set the split in advance: platform response from your supplier, containment and restore inside your retainer, and a full application clean as billable work at a stated rate. Backups keep that affordable, because the usual remedy is a restore to a known-good point rather than open-ended forensics.

Should I sell a maintenance plan or leave updates to the client?

Either, provided it is written down. A care plan with a stated cadence is better business and better security; leaving it to the client is defensible if you have said so plainly. The only indefensible position is a book of sites where nobody has ever decided.

What happens to a client's files if they leave me?

They stay the client's. A full backup pulls from the panel at any time, before or during cancellation, and domains remain registered in whoever's name they were registered in for the term paid, moving to another registrar once the registry's standard 60-day window has passed.

Read next

  • Hosting With a Money-Back Guarantee

    Knowing where the exit is before you commit a client book to a supplier, and what the guarantee actually covers.

  • Hosting for High-Traffic Blogs

    Publishers whose posts draw real crowds, and what a sudden stampede does to a pool you are responsible for.

  • Secure Hosting

    Imunify360, account isolation and hardened defaults for security-first sites.

  • CMS Hosting

    A quick, guarded home for WordPress, Joomla, Drupal and every major CMS.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Contain the incident before it happens.

Account isolation, Imunify360 on every site, daily backups you restore yourself, and a suspension switch that is yours.

See Secure Hosting plans