Small business websites are rarely targeted personally. They’re found by automated tools that scan the internet for known weaknesses: outdated software, weak passwords, exposed admin pages. The good news is that the basics block a large share of these attacks. No website can be made perfectly secure, but you can make it a much harder target and recover quickly if something happens.
1. Keep software updated
Your CMS, themes, plugins and server software all receive security fixes. Apply updates promptly, and remove plugins or themes you don’t use; they can still be exploited when inactive.
2. Control who has access
- Give each person their own account; never share logins.
- Use the lowest role that lets someone do their job.
- Remove accounts for people who have left or finished a project.
- Use strong, unique passwords and a password manager.
- Turn on two-factor authentication for administrators.
3. Use HTTPS everywhere
An SSL certificate encrypts data between visitors and your site. It’s expected by browsers and customers, and many hosts provide it free.
4. Protect your forms
Forms are a common entry point for spam and abuse. Validate input on the server, add spam protection, limit file uploads to safe types and sizes, and store uploads where they can’t be executed or browsed publicly.
5. Have backups you have actually tested
Backups should be automatic, stored off the server, kept for long enough to go back before a problem started, and restored successfully at least once. A backup you have never restored is a hope, not a plan.
6. Watch for changes
Monitoring alerts you to unexpected file changes, new admin accounts or suspicious logins, so you can act before customers notice.
7. Know what you’ll do in an incident
Write down who to call, where backups are, and who can access hosting and domain accounts. In an incident, those first hours matter.
Want a second pair of eyes? We offer security assessments, hardening and monitoring for business websites, only ever on systems you own or are authorised to test.