Articles.
Plain answers about websites, brands and marketing for small businesses, from Jack and Carly in Somerset.
Nobody targets a small business website on purpose. That is the thing most owners get wrong about security. The attacks that take down a plumber in Wells or a clinic in Bath are never personal. They are automated, running constantly across the whole internet, looking for one known weakness on any site at all.
Which is oddly reassuring, because the defence is not clever either. Keep things updated, control who can get in, take backups you have tested, and remove what you are not using. Do those four and you are past the point where the automated stuff bothers with you.
What actually happens when a small site gets hacked
It is rarely dramatic. There is usually no ransom note. The common outcomes:
- Spam pages appear in a folder you never look at, quietly using your domain's reputation. You find out when Google flags the site.
- Redirects are injected so visitors from search get bounced elsewhere, while you, logged in on your own computer, see nothing wrong.
- The site becomes a mail relay, sending spam until your domain lands on a blacklist and your business email stops arriving.
- Everything is encrypted and you are asked to pay, which is the rarest and the worst.
The costs are the same in each case: your site down or untrusted, warnings in search results, weeks of ranking recovery, and a cleanup bill. Nearly always more than prevention would have been.
The five things that matter most
1. Keep everything updated
Out-of-date software is the way in for the overwhelming majority of small site compromises. When a vulnerability is published, automated scanners start hunting for sites still running the old version within hours.
If you are on WordPress, that means the core, the theme and every plugin, plus the PHP version underneath. Turn on automatic updates for security releases at the very least. If you have a plugin that has not been updated by its author in two years, replace it. Abandoned code is a liability sitting on your server.
2. Control the front door
Weak and reused passwords are the second route in. Fix it properly:
- Long unique passwords in a password manager, not a spreadsheet or a note by the monitor.
- Two factor authentication on the website admin, the hosting account, the domain registrar and the email account that can reset them all. This is the single highest-value change on the list.
- Remove old accounts. The designer from 2019, the marketing agency you left, the intern. Check the user list twice a year.
- Give people the lowest access level that lets them do their job. A staff member who writes blog posts does not need administrator rights.
3. Take backups, and test them
An untested backup is a hope, not a plan. Three rules: back up automatically on a schedule, keep at least one copy somewhere other than the server it came from, and restore one occasionally to prove it works. People discover their backup was broken at exactly the moment they need it. Half an hour restoring to a test environment once a year is the cheapest insurance you will ever buy.
4. Reduce what you are running
Every plugin, theme and script is more code that can go wrong. Deactivating a plugin is not enough, because the files stay on the server and can still be exploited. Delete anything you are not using, including old themes and the staging copy somebody left in a subfolder three years ago. A forgotten WordPress in /old, unpatched since 2021, has been the entry point for plenty of otherwise well-maintained sites.
5. Get the basics of hosting right
Cheap shared hosting can put you on a server with hundreds of neglected sites. Ask your host what they do about isolation, patching and malware scanning. Make sure you have HTTPS across the whole site with a certificate that renews automatically, because an expired one makes browsers warn people off. A web application firewall in front of the site is inexpensive and worth having.
The risks that are not really about hackers
Losing control of your domain. If it is registered in an old agency's account, or renews to a card that expired, your website and your email disappear together. Check who owns the registration, put the renewal on a card that works, and turn on the registrar's lock. This is the most common self-inflicted outage we see.
Form spam and data. Your contact form collects personal data, so someone should know where it goes and how long you keep it. Spam protection is worth adding, because unprotected forms get abused to send mail through your domain.
How to check where you stand
An hour's work, no specialist tools:
- Check for pending updates, and note anything not updated by its developer in over a year.
- Delete anyone who no longer needs access, downgrade anyone with more than they need.
- Turn on two factor authentication for the admin, the host and the registrar.
- Confirm where backups go, how often, and when one was last restored.
- Check your certificate is valid and renews automatically.
- Look up your domain's expiry date and check the contact email on it is one you still use.
- Search your own domain in Google with the site operator and scan for pages you do not recognise.
Fewer moving parts, fewer problems
There is a reason we build on our own content management system rather than assembling a site from third-party plugins. The most common weakness in a small business website is not the core platform, it is the twenty-odd extensions bolted on, each written by a different person, each updating on its own schedule, any one of which can open a door.
Whatever you build on, someone has to be responsible for keeping it patched. That is the practical value of a care plan: not the reassurance, but the fact that the updates happen every month whether or not anyone remembers.
If it has already happened
Take the site into maintenance mode. Change every password, starting with hosting and the registrar. Restore from a backup taken before the compromise. Then find how they got in, because restoring without patching the hole gets you reinfected within days. If you are not confident doing that, get help early, because a half-cleaned site tends to come back.
Common questions
Is WordPress insecure?
The core software is well maintained and reasonably secure. The risk sits in plugins, themes and neglect. A carefully maintained WordPress site with few plugins is fine. A site with thirty plugins and no updates for two years is not, and that describes a lot of small business websites.
How often should updates be applied?
Security updates as soon as they are released, ideally automatically. Everything else monthly, on a site you can test before it goes live. The gap between a fix being published and it being applied is the window attackers use.
Want someone to keep an eye on it?
Updates, backups, monitoring and certificate renewals are the jobs that get forgotten until the week they matter. If you would rather they were somebody else's problem, have a word with us.
Add a comment:
Your
move
Tell us what you are building and we will tell you, honestly, whether we are the right people for it. A call, an email, or a message. Whichever you prefer.
