IT Security
Website Security Checklist for Small Businesses
You don’t need a security team to run a safe website. These ten habits block most of the problems small businesses actually run into - and most take less than an hour to set up.
Why small business websites get targeted
Most attacks on small websites are not personal. Automated tools scan the internet around the clock looking for outdated software, weak passwords and unprotected forms. If your site has one of those gaps, it can be used to send spam, show unwanted ads or steal visitor data, and search engines may warn people away from it. The good news: the same automation means the basics stop most of it.
The checklist
- Use HTTPS everywhere. Your site should load with a padlock on every page, and plain
http://addresses should redirect tohttps://. Most hosts offer free certificates. - Keep everything updated. Your CMS (for example WordPress), themes and plugins all receive security fixes. Turn on automatic updates where you can and remove plugins you no longer use.
- Use strong, unique passwords and a password manager. Every admin, hosting and email account should have its own long password.
- Turn on two-factor authentication (2FA) for your hosting panel, domain registrar, website admin and business email. This one step blocks the majority of account takeovers.
- Give people only the access they need. A freelancer who writes blog posts doesn’t need full admin rights. Remove accounts when people leave.
- Back up automatically. Follow the 3-2-1 rule: three copies, on two different types of storage, one kept off-site. Test a restore at least once a year.
- Protect your forms. Add spam protection such as reCAPTCHA to contact forms and never show technical error messages to visitors.
- Add basic security headers. Headers such as Strict-Transport-Security tell browsers to always use a secure connection. Your developer or host can add them in minutes.
- Watch your site. Free uptime monitors email you when the site goes down, and Google Search Console alerts you if Google detects a security problem.
- Know your privacy duties. If you collect names or emails, explain how you use them in a privacy policy and only keep data as long as you need it.
Quick wins you can do today
15 minutes
Turn on 2FA for your email and hosting accounts.
20 minutes
Delete unused plugins and old admin accounts.
30 minutes
Check that automatic backups are running and where they are stored.
10 minutes
Add your site to Google Search Console to get security alerts.
What to do if something goes wrong
If your site suddenly shows strange content, redirects visitors elsewhere or your host suspends it, stay calm and work through these steps:
- Change the passwords for your hosting, website admin and email accounts, starting with email.
- Contact your hosting provider; many can scan and restore your site for you.
- Restore a clean backup from before the problem started, then update everything.
- If customer data may have been exposed, check your legal obligations (for example under GDPR) and get advice.
Tip
Write down where your backups, passwords and hosting contacts are before you need them. It turns a stressful day into a manageable one.
When to get professional help
If you handle payments, customer accounts or sensitive data, or if you simply don’t have time to keep up with updates, a short professional review is worth it. We check your setup against this list and more, and explain what to fix in plain language. Book a consultation or read what happens in a security audit.
Frequently Asked Questions
Is a small business website really at risk?
Is HTTPS enough to make my website secure?
How often should I back up my website?
Do I need a privacy policy?
Key takeaways
- Most attacks on small sites are automated, so the basics stop most of them.
- HTTPS, updates, unique passwords and two-factor login are the essentials.
- Automatic, tested backups turn a disaster into an inconvenience.
- Monitor your site and know who to call before something goes wrong.