Most small business websites don't get hacked because someone targeted them. They get hit by automated tools that scan thousands of sites a day looking for an outdated plugin, a reused password, or an expired certificate. That's actually good news: it means most of the risk comes down to a short list of habits, not an expensive security program.
Here's the checklist we walk owners through. None of it requires you to become technical — it just requires knowing what to ask, and making sure someone owns each item.
The Basics That Stop Most Problems
- HTTPS on every page. Your address bar should show a padlock everywhere, not just on the contact form. Make sure your certificate renews automatically so it never lapses on a Friday night.
- Updates on a schedule. If your site runs WordPress or another content system, the core software, theme, and plugins all need regular updates. Outdated plugins are one of the most common ways small sites get compromised.
- Remove what you don't use. Every inactive plugin, old test page, and forgotten admin account is one more door. If nobody can say why it's there, it probably shouldn't be.
Passwords and Access
- One unique password per account, stored in a password manager — never reused between your email, hosting, and website login.
- Two-factor authentication on anything that controls the site: your hosting account, domain registrar, website admin, and business email.
- Know who has access. Keep a short list of everyone with an admin login, and remove former employees and past vendors the day they stop working with you.
If a former contractor still has the keys to your website, you don't have a security plan — you have a hope.
Backups You Can Actually Restore
A backup only counts if you can restore it. Keep automatic backups stored somewhere other than the web server itself, keep more than one copy going back several weeks, and test a restore at least once a year. Finding out a backup was broken on the day you need it is the most expensive way to learn that lesson.
Your Domain Is an Asset — Treat It Like One
- Register it in your business's name, with an email address you control — not a former web designer's or an employee's personal account.
- Turn on auto-renew and registrar lock so the domain can't lapse or be transferred away without you knowing.
- Keep your login details somewhere safe, alongside your hosting account information.
Know Who to Call
The last item isn't technical at all: decide now who you'll call if the site goes down, starts redirecting somewhere strange, or your email gets flagged as spam. Hours matter in those situations, and "we'll figure it out then" usually means a slower, more expensive fix.
Security and backup management is part of our Custom Development & IT work, and it's the kind of thing we'd rather set up once, correctly, than troubleshoot after the fact. If you're not sure where your site stands on this list, that's a good place to start the conversation.
Ready to Talk?
Twenty minutes, no pressure, no pitch deck. Let's find out if we're the right fit for your business.
Book Your Discovery Call →