Tailored Digital Solutions · For Australian Clinics
Medlink Connect™ · New ASD ACSC Critical Alert · 9 July 2026

Your practice website is now a target. Hosting alone won't protect it.

The Australian Signals Directorate has issued a critical alert: attackers are running a large-scale automated campaign against website content management systems — and many small Australian businesses are already compromised. Keeping a practice website patched, monitored and secure is now a real obligation, and it sits outside your hosting. SENTRY is the Medlink Connect service that takes it on.

01 · What's happening

A national alert, aimed squarely at websites like yours

On 9 July 2026, the ASD's Australian Cyber Security Centre issued a Critical Alert. Attackers are scanning the internet at scale for vulnerable content management systems and planting webshells — hidden backdoors that hand them remote control of the web server.

Once a site is compromised, the alert warns, they use it to deface or disrupt the website, capture data entered by your website's users, serve malware and scams to your own visitors, and use that foothold as a pathway deeper into your network. The exploited vulnerabilities span seventeen named WordPress plugins and CMS products — the everyday building blocks of ordinary business websites.

~5 hrs
Median time to mass exploitation for heavily exploited WordPress vulnerabilities (Patchstack, 2026, on 2025 data)
16+
CMS platforms & plugins named in the alert with actively-exploited vulnerabilities
SMBs
Small & medium Australian businesses are explicitly named as impacted
AI
Five Eyes agencies warn AI is accelerating the speed and scale of these attacks

The critical shift is speed. A newly-disclosed flaw is now exploited in hours, not weeks — and a "we'll update it next month" cycle can't keep pace.

1. Automated scan finds a vulnerable plugin→ 2. Webshell uploaded to the server→ 3. Remote control established→ 4. Data captured · visitors served malware · a pathway deeper into the network

02 · The gap you may not know exists

Where website hosting ends, and security maintenance begins

Most of our clients host their website with us, on secure, backed-up infrastructure. But hosting has never included the ongoing security maintenance of the website software itself — and that distinction matters more now than it ever has. Here's exactly where the line sits.

Included in your hosting

Keeping the site online, on our infrastructure

  • Server & infrastructure uptime
  • Data-centre & physical security
  • Backups of the hosting environment
  • SSL certificate provisioning
  • Bandwidth & availability

Not included — needs active management

Keeping the site safe, at the software layer

  • WordPress / CMS core updates
  • Plugin & theme updates
  • Malware & webshell scanning
  • Vulnerability patching
  • Login & MFA hardening
  • Security-header configuration
  • Active threat monitoring
  • Incident detection & response
In plain terms Everything in the right-hand column is the responsibility of the website owner. For most practices, that work simply isn't happening — not through neglect, but because it takes specialist attention and continuous monitoring a busy clinic can't sustain in-house. SENTRY takes ownership of that entire column.

03 · Why it matters for your practice

A practice website is a patient-trust surface — and a compliance obligation

Your website carries your practice details, appointment and new-patient forms, and often collects information directly from patients. If it's compromised, the consequences aren't abstract.

Attackers can capture what patients enter, deface your public face, quietly serve scams and malware to the people who trust you, or use the site as a stepping stone toward your wider systems. Beyond the operational damage, an unmanaged, known-vulnerable public website is difficult to reconcile with a practice's information-security obligations.

How this maps to accreditation

  • RACGP C6.4 Information security — the criterion a practice is accredited against for protecting health information and its electronic systems.
  • C6.4A A team member responsible for the practice’s electronic systems. SENTRY gives them evidence for the website; the role itself stays with the practice.
  • C6.4D A practice-wide business-continuity and information-recovery plan. Our verified website backups are one input to it, not the plan itself.
  • RACGP guidance Information security in general practice, the guide C6.4 directs practices to.
  • Privacy Act APP 11 requires reasonable steps to protect personal information; a breach may be notifiable under the NDB scheme.

SENTRY's monthly report is designed to serve as ready-made evidence for your accreditation file.

04 · Introducing the service

Medlink Connect SENTRY

A single monthly service that takes full ownership of your website's security — continuously monitored and patched, hardened against attack, backed up, and reported on in plain English. It's driven by an AI-assisted monitoring platform, with our engineers making the judgement calls and doing the remediation.

Pairs with ThreatIQ

SENTRY guards your website. ThreatIQ trains your team. Together they close both sides of the ACSC's warning — the technical layer and the human layer — under one RACGP-aligned Medlink Connect umbrella.

Firewall & malware protection

A managed web application firewall and content-delivery layer filters malicious traffic before it reaches your site, plus continuous malware and webshell scanning.

Managed patching

Core, plugin and theme updates monitored, tested and applied — with actively-exploited vulnerabilities prioritised and patched fast, not left for a monthly cycle.

24/7 monitoring

Round-the-clock monitoring with AI anomaly detection, watching for the file changes and suspicious requests that signal an attack in progress.

Access hardening

Multi-factor authentication, brute-force protection and login lockdown, so a stolen or guessed password isn't enough to get in.

Encryption & header assurance

SSL/TLS kept valid and correctly configured, with security headers checked and maintained to modern standards.

Vulnerability scanning

Scheduled scans of your site and its components against live vulnerability feeds — so weaknesses are found on our watch, not the attacker's.

Immutable backups & DR

Daily immutable backups plus air-gapped disaster-recovery copies, with test-restores verified — so a clean, known-good version is always ready.

AI threat triage

When a national alert like the ACSC's lands, we cross-reference it against your exact stack and tell you — in plain English — whether you're affected and what we've done.

Incident response

If something does get through, we isolate, clean and restore — and give you a clear account of what happened and how it's been closed.

05 · What you receive every month

Proof it's working — and evidence for your accreditation file

You shouldn't have to take security on faith. Every month you get a plain-English report showing exactly what we did, what we caught, and where you stand. The figures below are an illustration, not a real practice — the kind of documentation a surveyor is looking for.

SENTRY · monthly security report · EXAMPLE
Security patches applied14 applied · 0 pending
Malicious requests blocked3,812
Malware & webshell scansClean
Vulnerabilities found → remediated2 → 2
Backup test-restore verifiedPassed · 04 Jun
SSL / security headersValid · A rating
National alerts affecting you1 reviewed · not affected
Overall security postureStrong ▲

06 · Why AI-driven

The attackers are using AI. Your defence should too.

The ACSC points to advice that advances in AI are accelerating cyber operations generally. A defence that runs at human pace — checking each site by hand every few weeks — was never going to keep up. SENTRY is built to move at the same tempo as the threat.

Every site, watched continuously

AI keeps every client's site under constant watch at once — not on a rotation, and not only when someone remembers to look.

New threats matched to your exact stack

The moment a vulnerability is disclosed, it's cross-referenced against your specific plugins and versions — so we know instantly whether it affects you.

The disclosure-to-patch window, closed

By triaging automatically, we cut the gap between a flaw becoming public and your site being protected from weeks to hours.

Human judgement where it counts

AI does the tireless watching and triage. Our engineers make the calls, test the fixes and handle remediation. A force-multiplier — not a black box.

07 · Plans & pricing

Three plans. The one we recommend is the cheapest

That looks like a catch, so here is the reason. A website with no plugins and no login is dramatically cheaper for us to keep safe than a WordPress site under constant automated attack. We would rather pass that saving on and have fewer sites we are worried about. Prices are per website, billed monthly, and include hosting with us on the first two.

Recommended
Managed Website
We rebuild your site on our own platform — and then look after all of it
$50/ mo +GST
$55 inc GST · per website · hosting included
  • Your site rebuilt, keeping your content and your look
  • No plugins and no public login to attack
  • Hosting, certificate and daily backups
  • Managed firewall and content-delivery layer
  • Round-the-clock monitoring
  • An editor for your hours, staff, photos and fees, behind multi-factor sign-in
  • Your own page showing visitors and security
  • Monthly security report
  • Minor changes included — wording and pictures on your existing pages
Choose Managed Website
Managed WordPress
You keep WordPress, we keep it patched and watched
$80/ mo +GST
$88 inc GST · per website · hosting included
  • Hosting, certificate and daily backups
  • Managed firewall and content-delivery layer
  • Managed core, plugin & theme patching
  • Malware & webshell scanning
  • Round-the-clock monitoring
  • Multi-factor sign-in and login hardening
  • Monthly security report
  • Changes to the site quoted separately
Choose Managed WordPress
Remote Cover
For a website hosted somewhere other than with us
$95/ mo +GST
$104.50 inc GST · per website · hosting not included
  • Certificate, headers, email records and speed, watched from outside
  • On WordPress, our security plugin goes on so we can see inside the site
  • Malware & webshell scanning and patch monitoring
  • Multi-factor sign-in and login hardening
  • Monthly security report
  • No firewall or hosting, because the server is not ours — we advise rather than act
  • On platforms other than WordPress we can see what the world sees, not what is on the server
Choose Remote Cover
No joining fee, and no lock-in. There is nothing to pay up front on any plan. On Managed Website we rebuild your site at our cost. The value of that rebuild is agreed in writing before any work starts and reduces by one twenty-fourth for every completed month, so if you leave early only the remainder is payable, and after twenty-four months it is nil. Your domain is billed separately, as it is today.
no joining fee

08 · Our recommendation

The honest advice is to get off WordPress

This is not about how any particular website was built. In July 2026 the ASD’s Australian Cyber Security Centre issued a critical alert about a large-scale campaign targeting content management systems, and WordPress sites are now under continuous automated attack whoever built them and however well. Keeping one safe is a permanent, rising cost, and the attacks are getting through to practices that had done nothing wrong.

So for most practices we recommend Managed Website. We rebuild your site keeping your content and your look, on a platform with no plugins and no login — which removes the way in rather than watching it. You get an editor for the things you would actually want to change yourself, and it costs less than keeping the same site on WordPress under cover. Where a practice genuinely needs a full content management system, Managed WordPress is there and we will keep it patched and watched.

Where a practice chooses not to proceed To keep the line clear: website security maintenance — CMS and plugin updates, patching, malware scanning and monitoring — remains the responsibility of the website owner and sits outside your hosting agreement. Where a practice declines managed cover, we will ask you to acknowledge this in writing, so there is no ambiguity about where that responsibility rests. A compromised website on a shared server puts every other site on it at risk, so we reserve the right to suspend one immediately, and any clean-up is quoted and invoiced at our incident-response rate.