Website Security Basics Every Small Business Should Know
Keep the platform and extensions supported and use trusted sources for updates.
- Map the accounts and information you must protect
- Reduce software and administrator exposure
- Prepare backups and evidence before an incident
- Contain an incident without destroying the only evidence
- Example: a contact form still works but sends elsewhere
- Questions about this guide
- Further reading
- Related help
- Terms in this area
- Read next
- Tell us about your own situation.
- Services
- Resources
- Company
- Get in touch
Keep the platform and extensions supported and use trusted sources for updates. A compromised business website can change contact details, send visitors elsewhere or expose information submitted through a form. The risks are broader than whether the homepage still looks normal. Domain, hosting, administrator accounts, plugins and external services all form part of the system. This guide prioritises controls a small business can understand and verify: ownership, access, software updates, independent backups and an incident plan. It is not a claim that one security plugin makes a website safe or legally compliant. The maintenance article covers recurring work; this page explains which security boundaries that work should protect. Map the accounts and information you must protect List the domain registrar, DNS management, hosting, CMS administrators, form delivery and any shop or booking provider. Losing one of these accounts can affect the whole site even if the CMS password remains safe. Keep named owners and recovery contacts, and check that a departing contractor no longer holds sole access. Protect the business email used for password resets too. Identify what the website collects and where it goes: mailbox, database, booking platform or analytics provider. Remove unnecessary fields and restrict access to submitted data. Do not leave test exports in publicly reachable folders. Security and privacy are connected but separate reviews; a technically protected form can still collect more information than the business needs. Reduce software and administrator exposure Use maintained software from genuine sources and remove unused plugins, themes and accounts. A disabled component left on the server may still create a risk depending on how its files are reachable. Keep an inventory so updates cover the actual installed components rather than only the main CMS. Avoid unlicensed “nulled” commercial plugins whose modifications you cannot trust. Give each person only the role they need. Someone editing opening hours usually does not need to install plugins or change the hosting account. Use unique credentials and supported MFA, and remove access when responsibilities change. Shared administrator passwords make it difficult to attribute changes and revoke one person without disrupting everyone. A web application firewall can add protection, but does not replace timely patching or application access control. Prepare backups and evidence before an incident Back up bot
What should I ask a website maintainer about account access?
Ask who has administrator access, how sign-ins are protected and how people who have left are removed. Named accounts with just the permissions each person needs work best.
How do I know backups are useful after a website incident?
Ask for a documented restoration test and for where the protected copies are kept. A backup job that reports success does not show that the whole site can actually be restored.
Can a backup replace security updates?
No. A backup gives you a way to recover, but it does not close the weakness that caused the incident. Restore into a suitable clean environment, find out how the attacker got in and update or remove the affected software before going back to normal service.