
Website Security Basics Every Small Business Should Have
Website security basics for small business owners are simpler than the subject sounds, because almost nothing that happens to a small business website is targeted. Nobody chose you. Automated scanners crawl the internet looking for known weaknesses, and sites that have them get hit — regardless of size, industry, or whether anyone would want your data. That is good news: defending against an automated scan is far easier than defending against a person who wants in.
Here are the five things that stop nearly all of it.
1. Keep everything updated
The overwhelming majority of small business site compromises exploit a known vulnerability in an out-of-date plugin, theme, or platform — one that was patched months earlier.
The scanner is not clever. It is checking whether you applied the update.
What to do: apply updates on a schedule rather than when something breaks. If you cannot commit to that, this is the strongest single argument for a maintenance plan — not the support, the updates.
And remove what you do not use. An inactive plugin still sitting there is still code that can be exploited. Sites accumulate these for years.
2. Have backups you have actually tested
Backups are not security; they are what turns a disaster into an afternoon.
Three properties matter:
- Automated. Manual backups do not happen during busy periods, which is when you need them.
- Off-site. A backup on the same server is gone when the server is.
- Tested. An untested backup is a hope. Restore one, once, and find out.
That third point is the one almost everybody skips. Businesses discover their backup was broken at the exact moment they need it.
3. Strong, unique passwords and two-factor authentication
Most "hacks" are not hacks. Someone reused a password that leaked from an unrelated service years ago, and an automated tool tried it.
- A password manager, so every login is different and long.
- Two-factor authentication on your site admin, your hosting, your domain registrar, and the email account that can reset all of them.
- Remove old accounts. The freelancer from two years ago probably still has admin.
Your email is the master key. Anyone with it can reset everything else. Secure that first.
4. A valid certificate
The padlock. It encrypts what visitors send you and, when it lapses, browsers show a warning that makes your business look unsafe to everyone.
These are usually free and automatic now. The failure mode is renewal quietly breaking — which is why it belongs on a monthly check rather than being assumed.
5. Limit who can do what
Not everyone needs administrator access. Someone updating text needs to update text.
This is not about distrust. It is that a compromised low-privilege account does far less damage than a compromised admin one.
Website security basics for small business: the monthly ten minutes
| Check | Why |
|---|---|
| Updates applied | Closes the vulnerability scanners look for |
| A backup exists and is recent | Confirms the automation is still running |
| Certificate valid | Catches silent renewal failures |
| No unknown admin users | Catches an intrusion you have not noticed |
| Contact form still delivers | Not security, but it breaks the same way — silently |
Ten minutes, once a month, attached to something you already do. This covers more real-world risk than any security product a small business is likely to be sold.
What actually happens when a small site is compromised
Rarely dramatic. Usually one of three things:
Spam pages injected, invisible to you and visible to search engines, which then flags your site as unsafe. You find out when traffic collapses.
Redirects sending some visitors elsewhere, often only on mobile, often not for logged-in users — which is why the owner is the last to notice.
Your email being used to send spam, damaging your ability to reach customers' inboxes.
Note what is missing: someone reading your data. For most small businesses the damage is reputational and operational, and the recovery is a clean restore plus updated everything — which is why backups matter more than any monitoring tool.
FAQ
Am I too small to be a target?
You are too small to be chosen, and that is not the same thing. Automated scanning does not care who you are.
Do I need a security plugin?
Basic hardening helps. It is far less important than updates, backups, and strong passwords, and no plugin compensates for missing those.
What if I take payments?
Use a reputable payment provider and never store card details yourself. Let them carry that obligation.
How do I know if I have been compromised?
Search your own site name and look for pages you did not create; check for unknown admin users; watch for unexplained traffic changes. Your hosting provider often notices first.
What is the single most important thing?
Two-factor authentication on the email account that can reset everything else. It is free and it closes the most common route in.
Want this checked?
If you cannot say when your site was last updated, whether a backup exists, or who still has admin access, those three answers are worth finding today rather than after something goes wrong.
We handle this as part of keeping a site healthy — the layer that is genuinely not optional. If you want a straight read on where yours stands, you can start it here.
Want this built for you?
Pick a plan and we start this week — content, website, and ads, run by our AI team. You own everything.
Not sure which? Get a free plan first →