Website security basics every business owner should know
Security · 5 min read
Website security basics every business owner should know
You don’t need to become a security expert to run a safe website — but you do need to know which five questions to ask, because most small-business breaches aren’t clever attacks. They’re bots walking through doors nobody remembered to close. Here’s the owner’s checklist, in plain language.
1. Updates are the whole ballgame
The overwhelming majority of website compromises exploit a known hole in an outdated plugin, theme, or platform — a hole that was patched months before, by an update nobody applied. Someone must own the monthly ritual: update, then click through the site. Unmaintained plugins are worse than outdated ones; if it hasn’t seen an update in a year, replace it. (This ongoing care is precisely the “keeping the lights on” bucket from our maintenance budget guide.)
2. Logins: unique passwords, second factor, fewer admins
Bots try stolen password lists against your login page around the clock. A password manager, two-factor authentication for every admin account, and a hard look at who actually needs admin rights closes that door. Departed employees and old vendor accounts should lose access the day the relationship ends.
3. Backups you’ve actually restored
A backup you’ve never test-restored is a hope, not a plan. You want automatic daily backups, stored somewhere other than the website’s own server, and one rehearsed restore so you know the recovery takes an hour — not a panicked weekend. Ask your host or your developer to show you, not tell you.
4. HTTPS everywhere, forms included
The padlock isn’t decoration — it encrypts what visitors type into your forms. Every page should force HTTPS, and anything a form collects should arrive by an authenticated route (and only collect what you actually need — the safest data is the data you never stored).
5. Someone is watching
Uptime monitoring, login-attempt limits, and a monthly glance at users and file changes turn “we were hacked for six weeks” into “we caught it Tuesday.” None of this requires enterprise budgets — it requires an owner: a person (or your development partner) whose job description includes these five items.
Five questions for whoever runs your site: Who applies updates, and when? Is two-factor on? When did we last restore a backup? Is HTTPS forced? Who would notice a break-in? Confident answers to all five put you ahead of most of the internet.
