AppWTAppWT Library
AppWTManuals › The AppWT Cyber Security Manual
The AppWT Cyber Security Manual cover
NEW RELEASE

The AppWT Cyber Security Manual

A Plain-English Security Playbook for Small Business

Written by Anthony “Tony” Paris · Published by AppWT Web & AI Solutions (AppWT LLC, a family company)

Almost nothing gets picked any more. Software scans the whole internet, finds a door left open, and walks in. It does not know whether it found a bank or a bakery. This manual closes the doors, in language you do not need a technical background to follow.

133Pages
17Chapters
7Real attacks
PDFInstant download

Exactly what you are buying

  • Format. One PDF file, 133 pages, US Letter, designed to read on a screen and to print cleanly at home or at a print shop.
  • Delivery. Instant download after payment. The file is yours to keep, with no subscription and no expiry.
  • Contents. 17 chapters in three parts, plus a one-page checklist, a plain-English glossary and a full contents index.
  • Language. Written at a plain reading level for business owners, and spelled for the United States, Canada, the United Kingdom and Australia.
  • License. One copy for you and your team. Each download is watermarked with the buyer's name and order number, so please do not redistribute it.
  • What it is not. It is not a subscription, not a video course, not software, and not a guarantee that a system cannot be attacked.
$67$0.97Launch price until 31 July
Read a free sample

133 pages, instant PDF download the moment payment clears. Secure checkout by Stripe, we never see your card details. The launch price runs to 31 July 2026, after which this manual returns to its regular $67.

The sample includes the introduction, the full contents, and the first 10 pages of chapter one. Questions before you buy: call +1 (888) 565-0171 or email sales@appwt.com  ·  Business facts.

What is inside

17 chapters, in three parts

Part One explains what actually happens. Part Two is the work that closes the doors. Part Three is the runbook for the morning something goes wrong.

Part OneWhat Actually Happens

  1. 1The Five Attacks We Actually SeeWhat our own incident ledger shows, and why safety is a habit rather than a purchase
  2. 2Break-In: Fake Plugins and Hidden Back DoorsWhat a real WordPress compromise looked like, and the fifteen-minute check that finds one
  3. 3The Neighbor Problem: One Weak Site Infects the OthersShared hosting, shared databases, and the doors between your own sites
  4. 4Card Testing: When Thieves Use Your Checkout as a CalculatorWhy a working payment page is a target, whatever you sell
  5. 5The Flood: Too Much Traffic on PurposeDenial of service in plain language, and the posture that holds it back.
  6. 6Junk at the Door: Form Spam and InjectionWhy the guards on your contact form have to live on your server
  7. 7The New Risk: When Your AI Says Too MuchWhat AppWT's own newsletter leak teaches about automation nobody is watching
  8. 8Scare Mail, Spoofing and Cold SpamHow to read a hostile inbox calmly, and block what actually repeats

Part TwoClosing the Doors

  1. 9The First Hour: A Sixty-Minute Hardening PassEight steps, one hour, and a business that is measurably harder to break into.
  2. 10The WordPress Hardening ChecklistThe same checks we run on every WordPress site we look after
  3. 11The Front Desk: Passwords, Two-Factor and Admin AccountsWho holds a key to your business, and how strong that key really is
  4. 12Email Posture: SPF, DKIM and DMARC in Plain EnglishThree small records decide whether a stranger can send mail in your name.
  5. 13Backups, and the Backup File That Leaks Your CodeHow to keep copies that work, and where you must never keep them
  6. 14Payments: Making Your Checkout a Bad TargetPractical hardening for anyone who takes money online

Part ThreeWhen It Happens

  1. 15Incident Response Runbook: The First HourWhat to do in the sixty minutes after you find something wrong
  2. 16Indicators of Compromise: What to Look ForThe quiet signs that someone else holds a key
  3. 17Getting Help, and What to Tell ThemHow to ask for help so you get the right help, fast
A look inside

Designed to be read, not endured

Every chapter opens with original artwork, and the deeper technical detail sits in separate notes so the main text stays readable.

Chapter artwork showing a locked website with an open back door

Chapter 2. A locked front door means little if the back one is open.

Chapter artwork showing automated traffic filtered at a door

Chapter 5. Telling a real customer from automated traffic.

Chapter artwork showing an AI assistant mailing its own working notes

Chapter 7. When your AI sends its own working notes to customers.

Who it is for

Written for owners

  • Small business owners who are responsible for a website but do not run it themselves.
  • Office managers and staff who hold the logins.
  • Web admins who want an ordered checklist instead of a scattered blog post.
  • Anyone who takes payments online.
  • Anyone who has started using AI tools in their business.
Why this one

Written from real work

  • Every attack described is one AppWT handled, not a textbook example.
  • Two chapters cover mistakes we made on our own websites, named openly.
  • Client identities stay private. The lessons are what we publish.
  • Nothing is invented. Where a detail was never verified, the manual says so.
  • No scare tactics and no promises that risk can be removed entirely.
Questions

Before you buy

What format is the manual?

A PDF you download and keep. It is designed to read on a screen and to print cleanly on standard paper.

Do I need to be technical to use it?

No. The main text is written in plain English for business owners. The deeper technical detail sits in separate italic notes you can forward to whoever looks after your website.

Is the spelling American or British?

Both. Where a word differs between countries, both spellings appear the first time the word is used, like color/colour. The manual is written for readers in the United States, Canada, the United Kingdom and Australia.

Are the incidents in the manual real?

Yes. Every incident described is work AppWT actually performed. Client identities are kept private. Two of the incidents are mistakes we made on our own websites, and we named ourselves for those.

Will this make my business impossible to attack?

No, and any provider who tells you otherwise is not being straight with you. Security reduces risk. This manual closes the gaps that let in almost every incident we have cleaned up.

Start with the first hour

Chapter 9 is a single ordered pass through the highest-value work, sized to fit one sitting. Most owners finish it in an afternoon and close the gaps that let in almost every incident we have cleaned up.

Order the manual, $47