The most useful thing to understand about website security is that almost nothing is personal. Small business sites are rarely targeted by a person. They are found by automated scanners that sweep the whole internet looking for known vulnerabilities and weak passwords, and try the same handful of things against everyone.
That is good news, because defending against an automated sweep is far easier than defending against someone who has chosen you. A small number of basics stop the overwhelming majority of it.
The basics, in order of return
- Keep everything updated. The single highest-return item by a wide margin. Most compromises exploit a vulnerability that was patched months earlier.
- Turn on two-factor authentication for every admin account, and for the hosting and registrar accounts too. This alone defeats every stolen-password attack.
- Remove accounts nobody uses. The old developer, the intern, the agency you left. Each is a door you are not watching.
- Give people the access they need, not the access that is convenient. Someone who writes blog posts does not need administrator rights.
- Delete unused plugins and themes. Deactivated is not removed — the files are still on the server and still exploitable.
- Backups you have actually restored. Security is largely a recovery problem. A tested backup turns a disaster into an afternoon.
HTTPS is not optional any more
Certificates are free and automatic with any decent host. Without one, browsers mark the site "Not secure" to every visitor, search engines treat it as a negative signal, and anything typed into a form travels in plain text.
If your site is still on http, that is this week's job. If you have a certificate, check it renews automatically — an expired certificate produces a full-page browser warning that stops traffic dead.
Passwords, specifically
Automated attacks try common passwords against common usernames, thousands of times an hour. Two changes end that entire category of attack: a password manager generating long unique passwords, and two-factor authentication.
Also: never share one admin login across the team. When someone leaves you cannot revoke a shared account without disrupting everyone, so it never gets revoked.
The first hour if it happens
Order matters here, and the instinct to delete the bad thing first is wrong.
- Take a copy of the site as it is, compromised. You will need it to find out how they got in, and deleting the evidence means it happens again.
- Change every password — hosting, registrar, database, all admin accounts — and sign out all sessions.
- Restore a clean backup from before the compromise, which means knowing roughly when it started.
- Then find the entry point. Restoring without this just resets the clock until the same vulnerability is used again.
- Check Search Console for a security notice and request a review once you are clean. Google's warning interstitial costs more traffic than the hack itself.
What is proportionate
A brochure site with no logins and no customer data needs updates, HTTPS, strong passwords and backups. That is genuinely most of it.
A site taking orders, storing customer details or holding accounts deserves more: a web application firewall, monitoring, restricted admin access and someone specifically responsible. The line is not your company size — it is what you would lose, and what your customers would lose.
Security is part of what our maintenance work covers, because in practice the two are the same job. If you want to know what is currently exposed on your site, send us the URL — an outside look costs nothing and is usually reassuring.
