What Is Web Hosting? How It Works and How To Secure Your Website

Learn how shared, VPS, cloud, dedicated, and WordPress hosting work, plus the web hosting security features that help protect your website.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Web hosting is where your website lives. It can be on a computer in your office, or (as is more likely) on a server managed by a hosting company. I’m here to explain how it works, what a web host provides, what it protects, and what you’re responsible for securing yourself.

If you want to know how hosting works and how to keep your website safe, start here. Maybe grab something to drink. I’m having tea.

In this web hosting guide
What is web hosting?
How to pick a web host
What your web host secures, and what you secure
Web hosting security features, explained
Common web hosting security risks
Types of web hosting
Bottom line
FAQs

5.0
Editorial Rating
Start for Free
On Wix's website
Website Hosting
Wix
  • Web hosting with 100% uptime and a 48ms average server response time in our testing
  • Passed stress testing with 250 simulated users and zero HTTP failures
  • PCI-compliant with DDoS protection, 2FA, and a Site History tool to roll back changes

What is web hosting?

Here’s the short, short version: web hosting is the space you rent on someone else’s computer/server where you put your website. That makes the website available to the whole internet.

If you want to know more about how web hosting works, here’s a more detailed example:

A party typically consists of a host and guests. The host provides the venue, while the guests make up the party. Without a venue, the party can't happen. Similarly, web hosting is like the host providing space on the internet, and the website's files are the guests. These website files need a place to live, and web hosting provides that space. A website can't exist without web hosting.

We surveyed 1,000 U.S. adults and found that most Americans haven't used web hosting services and only vaguely understand what web hosting is.

A graphic calling out statistics about web hosting usage and comprehension

Web hosting vs. web builder

Web hosting is the service that allows your website to exist. Meanwhile, a web builder helps you create a professional website. It may involve predesigned templates or drag-and-drop functionality to create a custom look. Some web builders even offer comprehensive AI tools to help you design your website.

Many web builders include hosting in their services. They may also offer additional features, such as robust ecommerce tools, email hosting, and a content management system for blogging. Consider whether you need these features when picking a hosting provider or web builder.

With traditional web hosting, you're generally responsible for securing your website and its software, while the host protects the underlying infrastructure. Website builders typically manage more of the technical security for you, although you're still responsible for things like your account credentials and how you handle sensitive data.

Web hosting vs. domain name

Going back to our earlier example, if your web host is a house, a domain name is the address to that house. Your browser uses the domain name to find the server, locate the website, and display it.

There are two different types of domains. A custom domain is an address that you own and fully control. It helps to establish your brand identity. A custom domain typically appears as www.example.com.

If you don't have a custom domain, you end up with a subdomain. The address includes your hosting provider. It looks like this: www.yourbusiness.hostingprovider.com.

Free web building platforms, such as Wix or WordPress, typically offer a subdomain with their free plans. This lets the platform gain more visibility while giving users an affordable web builder.

Learn more about the differences between web hosting and domains.

How to pick a web host

Several factors influence which web host best suits your website. Price may get the most attention, but it isn't the only thing to consider. In our survey, 80% of hosting users cited cost as a top factor when choosing a provider, followed by ease of setup (46%) and security and backups (39%).

Bar chart showing top reasons for choosing a web host

Some web hosting features to consider:

  • Support: 24/7 technical support can provide quick and knowledgeable assistance. Check whether the web hosting service offers support via phone, live chat, or email.
  • Control panel: Opt for a user-friendly interface, especially if your team lacks technical expertise. For more complex environments, you may need to hire an expert to manage them.
  • Scalability: As your online business grows, your website needs to keep pace. Choose a hosting provider that can handle increased traffic and data on your site.
  • Performance and uptime: A website that loads slowly will cost you customers. Look for a 99% uptime guarantee to ensure your website is accessible.
  • Storage space: Check storage capacity for your website. If you plan to post images and videos, ensure that your site has sufficient space for them.
  • Bandwidth: Bandwidth determines how much traffic your website can handle. Unmetered bandwidth is ideal for handling traffic fluctuations and preventing slowdowns.
  • Shared vs. dedicated hosting: You can share a hosting server with other users, which reduces your costs. But it may limit your bandwidth. A dedicated server means you get the space all to yourself, but it's a pricey choice. Learn more about how shared and dedicated hosting compare.

Of course, security is also a major factor, and we can't cover it in a single bullet point. That’s what this next part of the article is for.

What your web host secures, and what you secure

Getting hosting from a hosting company splits security responsibility in two. You’ll need to work together to keep your data safe, but that division isn't always obvious. In our survey of 1,000 U.S. adults, more than 1 in 5 respondents confused web hosting with services such as website design, email, or security features.

What the web host should handle on their end:

  • Basic server security. Firewalls, underlying server software updates, malicious traffic scanning, antivirus scanning, and backups are things your host should handle, especially on shared hosting. But if you go with a virtual private server as opposed to shared hosting, you’ll need to do some of this stuff yourself. More on that below.
  • Separation of concerns. Sometimes your website can get hacked because someone else on the same server had an insecure website. The best hosts use technologies such as containers or virtual machines to essentially keep everybody’s sites separate, so this can’t happen.
  • Account security. Your host should provide common-sense security features like requiring strong passwords, multi-factor authentication, and other tools to keep your account safe. If an attacker gains access to your hosting account, they also have access to your website.

What you handle on your end:

  • Build a secure website, designed to resist hacking. This particularly applies to sites built on dynamic content management systems or web apps such as WordPress or Ghost. Static pages usually can’t be hacked directly; they can only be changed if the server they run on has been hacked. But the caveat is that if you bought a package where the host promises to build your whole site for you (and not just install a CMS like WordPress), then they are responsible for this as well.
  • Secure storage of all sensitive data, including user data. It’s not just good business; it’s a legal liability.
  • Web software security updates. Again, if you’re using software like WordPress, you’ll need to keep it up to date to keep it secure. While many hosts offer automatic security upgrades for WordPress and similar CMS options, especially with managed hosting, you still need to double-check that it’s working.

5.0
Editorial Rating
Start for Free
On Wix's website
Website Hosting
Wix
  • Web hosting with 100% uptime and a 48ms average server response time in our testing
  • Passed stress testing with 250 simulated users and zero HTTP failures
  • PCI-compliant with DDoS protection, 2FA, and a Site History tool to roll back changes

Web hosting security features, explained

I mentioned a lot of security features above, so let’s look at each one in a little more detail. These are things that hosts can either do automatically or provide the means for you to do them yourself, just as long as they come included:

Account isolation

Account isolation helps prevent activity or security problems on one website from affecting other websites sharing the same server. Hosting providers can use technologies such as containers, virtual machines, and other isolation measures to separate customer environments and reduce the risk of one compromised account affecting another. Any hosting company worth the money will ensure one badly maintained website can’t take down the whole server.

Ask your host how it isolates customer accounts and websites from others sharing the same server.

Automated backups

You want to recover your website if anything goes wrong. Not all hosts offer this feature, though most major shared hosting providers do. People with VPS or dedicated hosting plans may have to pay extra or set up their own backup solution, which is inconvenient, but still necessary.

Check whether backups are included with your plan, how often they run, how long they’re retained, and how you restore one if something goes wrong.

DDoS mitigation

Distributed Denial-of-Service (DDoS) attacks are when thousands upon thousands of machines try to connect to your server at once, clogging up the connection. Almost all hosts these days take measures to protect their servers from these attacks. I’d go so far as to say that if you’re considering a host that doesn’t have it, look elsewhere. You can implement your own solutions, but you shouldn’t have to.

Check whether DDoS protection is included with your plan and whether there are any limits or additional charges for mitigation.

Malware scanning and removal

Just like desktop PCs, servers can get viruses. Malware can infect servers and websites, compromising your site or putting visitors at risk. Some web hosts provide automatic malware scanning to detect malicious files, while malware removal or remediation may depend on your plan or cost extra.

Find out whether your host only scans for malware or also removes it, and whether remediation costs extra.

Multi-factor authentication (MFA)

MFA is when you sign in to the host’s admin panel and have to click a link in an email. Or input a token from an authenticator app or any one of a number of different methods for confirming that you are, in fact, the owner of the account.

Because access to your hosting account can give someone significant control over your website, prioritize hosts that let you protect the account with MFA in addition to a password. Look for MFA on the hosting account and control panel, especially for accounts with administrative access. But definitely don’t settle for anything less than two-factor authentication (2FA).

Look for a host that offers MFA for your hosting account and control panel, especially for accounts with administrative access.

Software updates

Outdated software can leave known vulnerabilities unpatched, so find out which updates your host handles and how quickly it applies critical security patches. Most hosts maintain the underlying server software, while updates to your CMS (like WordPress), plugins, themes, or other website software may still be your responsibility. Some hosts automate those updates, particularly with managed hosting, so check exactly what your plan includes.

Ask your host which software it updates automatically, how quickly it applies critical security patches, and which updates you're still responsible for.

SSL/TLS Certificates

SSL/TLS certificates allow your website to be accessed via Hypertext Transfer Protocol Secure (HTTPS). This means that all connections to your website are encrypted, helping to protect your site and your users’ data. Every website needs HTTPS in some form, so your host should offer either their own free SSL certificates or the means to install them via Let's Encrypt, etc.

Check whether SSL/TLS certificates are included for free, whether they renew automatically, and whether HTTPS is easy to enable across your site.

Web Application Firewalls

Regular firewalls are great, but if you’re building a web application, you want a Web Application Firewall. These monitor traffic to and from your application, check for common attacks, and stop them before they happen. A WAF isn’t needed for every website, but if yours has advanced app-like functionality, then you want one.

If your site needs a WAF, check whether one is included with your hosting plan or available as an add-on, and what types of traffic or attacks it filters.

Common web hosting security risks

And these are the things you’ll want to look out for when hosting a website:

  • Neighbors on a shared server. While this is slowly becoming less of a problem as separation of concerns becomes more common, it’s still worth watching. If other people don’t update their CMS, for example, an attacker might find a way to get in and gain access to the rest of the server. It happens.
  • No working backup. No system is perfect, and eventually your website will go down. You usually want a couple of backups, if you can, including one stored somewhere other than the server your site is hosted on. Ideally, it should be in an entirely different data center, in another city. Just like in the old days of Word, save early, and save often.
  • Outdated software. I harp on updates because they’re that important. Developers constantly discover and patch new vulnerabilities in all software, including plugins and themes for your CMS. Having the latest version thus means that you’re less likely to get hacked. (The main exception to this rule seems to be Windows 11.) Always, always update.
  • Unencrypted file transfer. Any unencrypted traffic between your website and your users can potentially be hijacked to cause harm to one or both parties. HTTPS and SSL certificates solve this problem. If you transfer website files to and from your hosting server, avoid protocols that send your login credentials or files without encryption. Traditional FTP doesn't encrypt the connection, leaving that information vulnerable to interception. Use an encrypted option such as SFTP instead, and check which secure file transfer methods your web host supports.
  • Unused software installs. If you installed, for example, an extra CMS on your hosting server just to try it out, and you didn’t use it in the end, make sure to delete/uninstall it later. Unused and unmaintained software has the same problem as any other outdated software: it can open ways for attackers to get in and mess up your main website.
  • Weak or reused credentials. Watch out for this one. Multi-factor authentication helps, but it's not infallible. Don’t use the same password for everything, alright? Get yourself a password manager, and use it. That way, if one service you use gets hacked, bad actors can’t access every service you use.

5.0
Editorial Rating
Claim Deal
On Hostinger's website
2026 Editors’ Choice
Best Overall Web Hosting Service
Website Hosting
Hostinger
SPECIAL OFFER: 79% Off Unlimited Plan
  • Web hosting service rated best overall in our hands-on testing of 20+ providers
  • Hit 100% uptime and a 99/100 page speed score across all three test locations
  • Includes an AI content creator, image generator, and WordPress troubleshooter alongside the web builder

Types of web hosting

Of course, the security tools available to you and what you have to do to protect your site can vary wildly according to a number of factors. One big factor is the type of hosting you choose. With shared hosting, for example, the provider handles more (including security). With virtual private servers, you have more control and can install pretty much any kind of web software you like, but you also (usually) handle more of your own maintenance and security.

Here’s a quick overview of the different types of hosting available out there, and what they entail:

Shared hosting

Shared hosting means multiple websites share the same server resources. The main benefit of shared web hosting is its cost-effectiveness for low-traffic sites. Small businesses and personal websites can often run well on shared hosting. Another benefit is that your provider manages the server, so you don't need technical expertise.

Because you share processing power, other sites on your server could slow your website during traffic spikes. Likewise, if your site gets heavy traffic, your hosting provider may throttle performance to manage server resources.

Security-wise, you’re also (potentially) exposed to the security vulnerabilities in every other website on the server. If someone else on the same host as you isn’t keeping their software updated, your site could be compromised too. This is becoming less of a problem as more hosts adopt practices that minimize risk, but it’s still worth considering.

Pros
  • Cost effective
  • Ideal for small businesses or personal sites
  • Hosting provider manages the server
  • No technical expertise needed
Cons
  • Not a scalable web hosting solution
  • Other sites on the shared server could impact your performance
  • Other sites on the server could impact your site’s security

Virtual Private Server (VPS) hosting

VPS hosting is similar to shared hosting. The difference is that VPS hosting creates separate partitions for each website. Each site receives a dedicated reserve of processing power, storage, and memory. Unlike shared hosting, websites are less likely to affect each other if one experiences a sudden surge in traffic.

VPS hosting offers more configuration options and controls than shared hosting. You may welcome the customization, but it does require technical expertise. Overall, VPS hosting suits medium-sized businesses that need features such as ecommerce and blogs.

VPS hosting is, for the most part, fully under your control. You can often choose what operating system you want to run, and all the software you want to run on top of that. That also means that security is mostly up to you. But if you get your VPS from a host with managed hosting, they’ll actually take care of most of that stuff for you, but it may cost more.

Pros
  • Other sites are less likely to impact your performance
  • More server control
  • Dedicated space
Cons
  • More technical and security management may be required
  • Costs more than shared hosting

Cloud hosting

Instead of physical servers, cloud hosting uses multiple virtual servers. Large businesses benefit from cloud hosting because there's little downtime. If your site experiences an increase in traffic, other virtual servers step in to keep the site operational. Another benefit of cloud hosting is scalability. It can grow or shrink as your website's needs change.

Cloud hosting is a bit all over the place when it comes to responsibility. Some cloud hosting providers offer a service similar to VPS hosting, where you have a lot of control and nearly all responsibility for your own security. Others offer a much more limited experience, like shared hosting. Make sure you know what you’re getting before you dive in.

Pros
  • Easy to scale
  • Extremely reliable
  • Low chance of downtime
Cons
  • May have limited control
  • Security responsibilities vary by provider and hosting setup

Dedicated hosting

Dedicated hosting means your site gets an entire server, so you don't have to worry about other sites crashing your party. Your dedicated host server has you covered. It gives businesses complete control over server configurations. Large sites will find dedicated hosting ideal for reliability and uptime.

Dedicated hosting also gives you near-complete control over the system. Beyond whatever firewalls protect the network, the machine is your responsibility. Install whatever you want, build whatever you want, and protect it yourself. Now, a couple of hosts provide managed dedicated hosting where they’ll handle many technical and security concerns for you, but it’s typically quite expensive.

Pros
  • More customization options
  • Greater reliability
  • Full control of the server
  • Can host multiple websites
Cons
  • Most expensive hosting option
  • Server maintenance and security may be your responsibility

WordPress hosting

WordPress is a popular content management system (CMS), but it requires a hosting service. A dedicated WordPress hosting provider can offer easy site management, enhanced security, and optimized performance.

In practice, “enhanced security” usually means that they install WordPress along with a few plugins designed to harden your website against attack. They may also include a suite of server security tools specifically designed to work with WordPress. In both cases, these solutions often come from third-party vendors, and they’re usually pretty good. A few hosts have developed proprietary WordPress plugins to better integrate with their in-house security solutions, and that’s also a valid approach.

Pros
  • Optimized for WordPress
  • Specialized WordPress support
  • Simplifies site management
  • May include WordPress-specific security tools and managed updates
Cons
  • Only works with WordPress
  • May need more technical skills

Bottom line: What to look for in web hosting

The right web host depends on how much traffic, control, and technical responsibility you're prepared to handle. Shared and managed hosting generally put more server maintenance in the provider's hands, while VPS and dedicated hosting can give you greater control but may also leave more security work to you.

Before choosing a host, check what it provides for backups, DDoS protection, malware scanning, account isolation, software updates, HTTPS, and account security. Just as importantly, find out what it doesn't include. A secure host can protect the infrastructure your website runs on, but keeping your website software, accounts, and sensitive data secure may still be your responsibility.

FAQs

Why do I need web hosting?

You need web hosting to make your website available on the internet. A web host stores the files your website needs to function and provides the server infrastructure that makes them accessible to visitors. Depending on your plan, your host may also provide tools for performance, backups, security, and site management, although you're still responsible for some aspects of securing and maintaining your website.

Which type of web hosting should I choose?

The right type of hosting depends on your website's size, traffic, budget, technical expertise, and how much control you need. Shared hosting is typically simpler and more affordable for smaller sites, while VPS hosting provides more resources and control but may require more technical and security management. Dedicated hosting gives you an entire server and the most control, but it's also more expensive and typically requires greater technical expertise. Managed hosting can be a good option if you want the provider to handle more of the maintenance and security for you.

How much does web hosting cost?

Web hosting costs vary by hosting type, provider, and the features included with your plan. In our survey, roughly six in 10 Americans expected web hosting to cost $25 per month or less. Shared hosting is generally the least expensive option, while VPS and dedicated hosting typically cost more in exchange for additional resources and control. When comparing prices, check what's included with the advertised rate, such as backups, SSL/TLS certificates, security features, support, and renewal pricing.

Can I host my website for free?

Yes, some providers offer free web hosting, but free plans typically limit storage, bandwidth, features, and support. Check the security features carefully, too. A free plan may not include protections or services such as automated backups, SSL/TLS certificates, malware scanning, or hands-on support that are included with paid hosting plans. Make sure you understand what the provider handles and what you'll need to secure or maintain yourself.

Is shared hosting safe?

Shared hosting can be a safe option when the provider properly maintains its servers and isolates customer accounts. Because multiple websites share the same physical server, vulnerabilities or poor security practices on another account can potentially create additional risk. Look for a reputable shared hosting service that provides account isolation, regular server updates, malware protection, backups, and strong account security.

What security features should a web host include?

Look for features such as account isolation, automated backups, DDoS protection, malware scanning, multi-factor authentication, regular security updates, and SSL/TLS certificates. Depending on your website, a web application firewall may provide additional protection. Also check which security features are included with your plan, which cost extra, and which protections you must manage yourself.

4.9
Editorial Rating
See Price
On Bluehost's website
2026 Editors’ Choice
Best Web Host for Small Businesses
Website Hosting
Bluehost
  • Web hosting built around WordPress, with an AI site builder included on every plan
  • Free SSL, CDN, and domain (first year) come with every plan, no upgrade required
  • Plans start at $2.79/mo, with a 30-day money-back guarantee if it's not the right fit

Author Details
Ezequiel Bruni has spent more than 12 years building websites and writing about web technology — a combination that lends credibility to his hosting reviews that most reviewers can't match. At All About Cookies, he conducts hands-on testing and has authored more than 36 reviews, comparisons, and buyer's guides covering web hosting, web building, and domains. His work has appeared in Web Designer Depot and Website Planet, and he is an active contributor to the Rocky Linux open-source project.
Sara J. Nguyen has spent more than five years covering data privacy, identity theft protection, and online safety. She approaches the beat with a public relations background that gives her a particular eye for the gap between how companies present their products and what those products actually do for users. She has authored more than 140 articles for All About Cookies and has been published in Frontier Communications, Hootsuite, Zapier, and LogRocket.