Securantis

Getting Started

Recommended initial secure configuration

Step-by-step walkthrough to activate Securantis: sign in, run the first scan, observe the firewall, enable 2FA, configure alerts and plan backups.

← Back to help center

Securantis how-to guide

Purpose of the article

This guide walks you, step by step, through the initial secure configuration of a site protected by Securantis (all platforms: WordPress/WooCommerce/PrestaShop). Objective: verify the connection, run an initial full scan, observe WAF behaviour in observation mode before automatic blocking, enable two‑factor authentication (2FA), configure alerts and prepare a backup strategy. The workflow minimizes false positives and reduces the risk of service disruption.

Prerequisites

  • Active Securantis license linked to the site.
  • Administrator access to the CMS and access to the Securantis dashboard (module/plugin installed and activated).
  • Recent backup of the site (files + database) prior to any changes.
  • For WooCommerce/PrestaShop: prefer an off‑peak commercial window for actions that may impact checkout.

Recommended steps (numbered)

  1. Verify connection and synchronization status

1.1 Open the Securantis dashboard from your CMS or the SaaS interface. Confirm that the license and report synchronization are active. If the interface shows detailed statuses (recent scans, WAF activity), note them.

Expected result: connection OK, last synchronization recent (< 30 min) or message indicating a report is queued.

  1. Perform an initial read‑only scan

2.1 Launch a full/quick scan according to the available option. The scanner inspects the environment, files, modules/extensions, executable media files and compares to a baseline.

2.2 During the first scan, do not enable automatic WAF blocking yet — use observation mode to collect events without impacting visitors.

Expected result: report with score and a list of alerts classified (critical, warning, info). The report also indicates whether a baseline has been created.

  1. Review and handle scan alerts

3.1 Review each alert: description, affected file/rule, category. For each suspicious item, decide: ignore (false positive), mark for manual quarantine, restore from backup, or keep under observation.

3.2 Security reminder: quarantining, deleting or restoring a file always requires a human decision. Securantis suggests actions; you choose.

Caution: if unsure, export the affected file off the server (secure download) and then contact support or your technical team.

  1. Observe the WAF in practice (observation mode)

4.1 Leave the firewall in observation mode for 24–72 hours depending on traffic. This allows collection of triggered rules, identification of false positives on forms or commercial endpoints, and adjustment of allowlists.

Platform differences:

  • WordPress: pay particular attention to login pages, XMLRPC and the REST API. Do not immediately block IPs if in doubt (risk of blocking an administrator).
  • WooCommerce: monitor checkout endpoints and webhooks; exclude or relax rules that impact cart/checkout.
  • PrestaShop: monitor sensitive front/back office controllers related to checkout and the API, checking compatibility with third‑party modules.

Expected result: list of WAF events with frequency and justification; recommendations for allowlist entries identified.

  1. Gradually enable WAF blocking

5.1 After observation, enable blocking for categories unlikely to cause false positives (e.g., obvious SQL injection attempts).

5.2 Keep sensitive rules (forms, payment APIs) in observation until fully validated.

5.3 Implement a policy for immediate reopening (fail‑open) or a quick disable button in case a rule breaks an essential flow.

  1. Enable two‑factor authentication (2FA)

6.1 Enable 2FA for all administrator accounts. Prefer TOTP methods or email according to availability. Ensure each administrator registers a recovery method (backup codes or a second method).

Platform:

  • WordPress: enable 2FA for administrator accounts via the dedicated panel; verify the recovery procedure.
  • PrestaShop: enable 2FA globally for the back‑office if available and follow the per‑account activation step.

Caution: do not remove all recovery methods simultaneously. Test 2FA on a minor account before global deployment.

  1. Configure alerts and notifications

7.1 Enable critical notifications (critical scan alerts, blocking WAF events, repeated 2FA failures). Choose channels: email, webhook to an external tool, or in‑interface notifications.

7.2 Define summary frequency (immediate for incidents, daily/weekly for reports). Verify email deliverability (SPF/DKIM) if you are not receiving alerts.

  1. Backups and restoration plan

8.1 Ensure you have a complete backup (files + database) taken immediately before the first intervention. Test restoration on a staging environment if possible.

8.2 Document the restoration procedure and keep multiple restore points (weekly, 24h, pre‑update). Quarantine and deletion actions must be coordinated with backups.

Common errors and quick troubleshooting

  • No access to the Securantis dashboard: check license key, status of the module/plugin, and outbound connectivity to Securantis services. Restarting the module sometimes resolves synchronization.
  • Scan that stops or exceeds time limits: reduce the number of files scanned or run the scan in multiple passes. On PrestaShop, a tight time budget can be increased from the module settings.
  • WAF false positives on checkout: revert to observation mode, add the rule to the allowlist, then retry. Always test on a purchase flow before applying permanently.
  • Loss of administrator access after enabling a protection: use the administrator bypass/key procedure provided by Securantis (or restore from backup). Never share your passwords with support.

Important precautions

  • Never mass‑delete files reported without human review.
  • Do not provide your passwords by email or chat; Securantis will never ask for them.
  • For interventions requiring direct server access, credentials must be provided only via the secure client area and after a service agreement.

When to contact Securantis support

Contact support if:

  • The scan reveals a critical risk you do not know how to handle.
  • The WAF blocks essential flows despite allowlisting.
  • You suspect an active compromise and need assistance for triage (note: support offers paid interventions requiring access via the secure client area).

Conclusion and best practices

  • Change only one critical setting at a time and measure the impact.
  • Use the WAF observation mode initially, then enable blocking progressively.
  • Enable 2FA for every admin account and keep recovery codes.
  • Automate backups and regularly test restoration.

If you have doubts about items in the scanner report or WAF alerts, export the suspicious items and contact support with the alert number and a precise description to speed up assistance.

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active