Most small-business websites are compromised through the same few gaps: out-of-date software and plugins, weak or shared passwords, and no recent backups. The essentials are HTTPS on every page, software kept up to date, strong unique passwords with multi-factor authentication, regular tested backups, spam protection on forms, and monitoring so problems are spotted quickly.
Why small sites get attacked
Most attacks are automated. Bots scan the web for known weaknesses, such as an outdated plugin or a default admin login, and they don’t care how big your business is. A compromised site can be used to send spam, host scams or redirect your visitors elsewhere, and browsers and search engines may warn people away from it.
The essentials
Cover these and you have closed the most common doors:
- HTTPS on every page, with a certificate that renews automatically
- Software, themes and plugins kept up to date
- Strong, unique passwords and multi-factor authentication for your hosting, domain, email and website logins
- Daily backups stored separately, and a restore you have actually tested
- Spam protection on forms
- Uptime and security monitoring, with alerts
Protect what surrounds your website
Your website is only as safe as the accounts around it:
- Your domain: lock it at the registrar and keep the renewal details current
- Your email: set up SPF, DKIM and DMARC so others can’t easily send email pretending to be you
- Your accounts: remove access for former staff and suppliers
How architecture helps
Sites built as static pages on an edge network have less to attack: there is no database or admin panel behind every page. That doesn’t remove the need for good passwords and backups, but it closes off many common routes in.
Free Australian guidance
The Australian Cyber Security Centre publishes free, practical guidance for small businesses at cyber.gov.au, including its Small Business Cyber Security Guide.