Wall & Fifth
Skip to content

Wall & FifthHosting & Infrastructure

A solid platform.
A clearer picture.

Your product depends on more than its code. Hosting, domains, databases and business accounts each need the right configuration and a clear owner.

Designed with purpose. Built with care.Security is part of the product.

The principle

The foundations deserve a proper brief.

A reputable hosting provider is a starting point. What matters next is how the product is configured, who controls the accounts, what is exposed publicly and how the services are kept running.

Infrastructure security is shared between the hosting provider, the application team and the business operating the product. Managed hosting provides useful capabilities, but application permissions, account access and configuration still need attention.

Shared responsibilities

Know what the platform covers.

Managed hosting can take responsibility for parts of the underlying infrastructure. Its protections, limits and support arrangements vary by provider and plan. They need to be checked against the product’s needs rather than assumed from the provider’s reputation.

The application still has its own responsibilities: permissions, validation, private data access and correct configuration. A provider’s security certification does not certify the application running on its platform.

Platform provider
The infrastructure and features covered by the selected service agreement.
Application team
The application logic, deployment configuration and controls in the build scope.
Your business
Account ownership, staff access and the operational responsibilities agreed at handover.

Configuration & access

Keep the right things private.

Production accounts, source repositories and deployment settings need controlled access. Individual accounts, appropriate permissions and stronger authentication help avoid a situation where one shared login controls the entire business.

The hosting plan should cover encrypted connections, production secrets, database access, file permissions and separation between development and live environments. Test environments should not expose production information or publish administrative tools by accident.

Account ownership also matters commercially. Domains, hosting and connected services need a documented owner, a recovery route and a clear handover plan. The business should understand how access can be removed or transferred when a working relationship changes.

Traffic & abuse

Protection that fits the exposure.

Public products can attract spam, automated requests and attempts to misuse expensive features. Forms, sign-in endpoints, uploads and paid APIs need their own abuse considerations. Rate limits, request validation and provider protections address different risks.

A web application firewall or traffic-protection service can be useful, but neither replaces correct application permissions. The selected controls should be proportionate to the traffic, costs and information at stake, with a decision about who reviews alerts and changes settings.

Email, domains & devices

A wider business needs wider protection.

Business email, domain administration and team devices sit alongside the website. If one of those systems is compromised, rebuilding the website does not automatically remove the attacker’s access. The affected service and its accounts need to be investigated directly.

Email authentication records such as SPF, DKIM and DMARC help receiving systems assess messages using your domain. They do not, by themselves, secure a mailbox account. Account access, recovery settings, forwarding rules and device protection require separate consideration.

If this is part of your project, include it in the brief so the relevant provider, administrator or specialist has a defined role. Urgent incidents should go through your established support route and the affected provider; a general project enquiry is not an emergency-response service.

Define the support your business needs

Clarity from the start

The right protection.
The right agreement.

Your product’s risks, controls and support needs belong in the project conversation. We’ll help you define the brief and identify what needs a separate assessment or specialist input.

Talk through your requirements

Straight answers

Before you
put your trust in it.

Does HTTPS mean a website is secure?

HTTPS protects the connection between the browser and the website. It does not establish whether permissions, database queries, uploads or business accounts are secure. Those require separate controls.

Does managed hosting remove the need for maintenance?

No. The provider may maintain its own infrastructure, while application dependencies, configuration, integrations and user access still need an owner. Responsibilities vary with the service and support agreement.

Will moving my website fix a hacked email account?

Not by itself. Email compromise needs investigation of the affected account and email service, including access and recovery settings. Moving a website or changing its framework does not automatically fix that separate issue.

Are a firewall and DDoS protection included?

Availability, configuration and coverage depend on the provider and plan selected for your project. Confirm what is enabled, what it covers, any limits or additional costs and who responds to alerts.

Keep exploring

The rest of the picture.

Back to Security & Support