This document discusses steps website administrators can take to improve the performance and security of websites built with ExpressionEngine. It begins by demonstrating through benchmarks how upgrading to newer versions of PHP can significantly improve performance. It then provides recommendations for optimizing ExpressionEngine settings and plugins, and using caching, CDNs and hardware. For security, it advises keeping software updated, restricting access, using firewalls and HTTPS, and securely managing user accounts and publishing workflows. The overall message is that ongoing performance and security efforts can directly benefit websites and should be made part of the development process.