ExIQWebGet a quote
Guide · How websites work

Website security for small businesses: the essentials.

Short answer

Most small-business websites are compromised through the same few gaps: out-of-date software and plugins, weak or shared passwords, and no recent backups. The essentials are HTTPS on every page, software kept up to date, strong unique passwords with multi-factor authentication, regular tested backups, spam protection on forms, and monitoring so problems are spotted quickly.

Why small sites get attacked

Most attacks are automated. Bots scan the web for known weaknesses, such as an outdated plugin or a default admin login, and they don’t care how big your business is. A compromised site can be used to send spam, host scams or redirect your visitors elsewhere, and browsers and search engines may warn people away from it.

The essentials

Cover these and you have closed the most common doors:

  • HTTPS on every page, with a certificate that renews automatically
  • Software, themes and plugins kept up to date
  • Strong, unique passwords and multi-factor authentication for your hosting, domain, email and website logins
  • Daily backups stored separately, and a restore you have actually tested
  • Spam protection on forms
  • Uptime and security monitoring, with alerts

Protect what surrounds your website

Your website is only as safe as the accounts around it:

  • Your domain: lock it at the registrar and keep the renewal details current
  • Your email: set up SPF, DKIM and DMARC so others can’t easily send email pretending to be you
  • Your accounts: remove access for former staff and suppliers

How architecture helps

Sites built as static pages on an edge network have less to attack: there is no database or admin panel behind every page. That doesn’t remove the need for good passwords and backups, but it closes off many common routes in.

Free Australian guidance

The Australian Cyber Security Centre publishes free, practical guidance for small businesses at cyber.gov.au, including its Small Business Cyber Security Guide.

Questions

Straight answers.

Do I need a security plugin?

On WordPress-style sites one can help, but it is no substitute for updates, strong logins and backups. On static sites, most of what security plugins do isn’t needed.

What should I do if my site is hacked?

Change all passwords, contact your web provider or host, restore from a clean backup, find and fix how the attacker got in, and check Google Search Console for security warnings.

Is HTTPS enough?

No. HTTPS protects information travelling between the visitor and your site. It doesn’t stop attacks on outdated software or stolen passwords.

Let’s talk about your website.

Tell us a little about your business and we’ll come back with a fixed quote, usually the next business day.