If you run a small business, your website is probably your best salesperson. It works nights, weekends and holidays. So it is worth spending one afternoon making sure it does not get hijacked, defaced or wiped out.
The good news: website security basics for small business owners are not technical. Most of the protection comes from about ten decisions, and most of them are handled once and then left running in the background. This guide explains each one in plain English: what it does, roughly what it costs, and who should actually do it (you, someone on your team, your hosting company, or your web agency).
Why small business websites get attacked in the first place
A common objection sounds like this: “We are a five person plumbing company, nobody is targeting us.” Correct. Nobody is targeting you personally. That is exactly the problem.
The overwhelming majority of website attacks are automated. Bots scan millions of sites looking for one known weakness: an outdated plugin, a login page with no protection, a password like admin2024. They do not care what you sell. Once they get in, they typically:
- Inject spam links or redirect your visitors to scam pages
- Use your server to send bulk email, which destroys your email deliverability
- Install a card skimmer on your checkout page
- Encrypt or delete your files and ask for money
- Sit quietly and use your site to attack other sites
The real cost is rarely the ransom. It is the downtime, the Google “this site may be hacked” warning, the lost enquiries, and the invoice to clean it up. Prevention is dramatically cheaper than recovery.

The 10 website security basics every small business should cover
1. HTTPS with a valid SSL certificate
What it does: An SSL certificate encrypts the connection between your visitor’s browser and your website, so contact form details, passwords and card numbers cannot be read in transit. It also turns on the padlock and the https:// prefix.
Why it matters beyond security: browsers now actively warn visitors on pages without HTTPS, and HTTPS has been a Google ranking signal for years. A site without it looks broken and untrustworthy.
Typical cost: free. Almost every decent host includes a Let’s Encrypt certificate at no charge and renews it automatically. Paid certificates (roughly 50 to 200 per year) only make sense in specific cases, such as an Organisation Validated certificate for finance or healthcare trust requirements.
Who handles it: your host or your agency. You just need to confirm it exists and that every page redirects to the HTTPS version, including old URLs.
How to check in 30 seconds
- Type your domain without “https” and press enter. It should jump to the secure version.
- Click the padlock and check the certificate expiry date.
- Look for a “mixed content” warning, which means some images or scripts are still loading insecurely.
2. Hosting that takes security seriously
What it does: Your host is the foundation. Cheap shared hosting often means hundreds of sites on one server, outdated PHP versions, no isolation between accounts, and support that cannot help you when something breaks.
What good hosting includes:
- Account isolation so a neighbour’s hacked site cannot infect yours
- Current PHP and database versions, updated regularly
- Server level firewall and malware scanning
- Daily off-server backups you can restore yourself
- A staging environment for testing updates
- Free SSL and automatic renewal
- Real humans in support, ideally 24/7
Typical cost: 5 to 15 per month for basic shared hosting, 25 to 60 per month for quality managed hosting. For a business that generates leads or sales, managed hosting is the single highest value upgrade on this list.
Who handles it: the business owner decides and pays; the agency recommends and migrates.
3. A real admin password policy
What it does: Stops the most common attack of all, which is a bot simply guessing your login. Weak and reused passwords remain the number one way small business sites are compromised.
The rules that actually matter:
- Long beats complicated. A 16 character passphrase such as
coffee-tuesday-anchor-92is stronger and easier to remember thanP@ssw0rd! - Never reuse a password between your website, your email and your bank
- Delete the username “admin” and any old accounts from former staff or freelancers
- Use a password manager so nobody stores logins in a spreadsheet or on a sticky note
- Give each person their own account with the lowest role they need. Your content writer does not need administrator access, an Editor account is enough
Typical cost: 0 to 4 per user per month for a password manager. Free tiers are fine for very small teams.
Who handles it: you. This is the one item you cannot outsource, because it depends on team behaviour. Put it in writing, one page, and have everyone follow it.
4. Two factor authentication on everything that matters
What it does: Adds a second step to login, usually a six digit code from an app on your phone. Even if a password leaks, the attacker is stuck. Reference: https://kaspersky.com.
Turn it on for your website admin, hosting account, domain registrar, business email and payment gateway. The domain registrar is the one people forget, and losing control of your domain is worse than losing the site.
Typical cost: free. Use an authenticator app rather than SMS where you have the choice, since SMS codes can be intercepted.
Who handles it: agency sets it up on the website, you enable it on the accounts you own.
5. Plugin, theme and core updates on a schedule
What it does: Closes known holes. When a plugin vulnerability is published, automated scanners start hunting for unpatched sites within hours. Outdated plugins are the leading cause of WordPress compromises.
A sane routine for a small business:
- Security patches: apply within 24 to 72 hours
- Everything else: a scheduled monthly maintenance window
- Always take a backup first, and test major updates on staging if you run e-commerce or bookings
- Delete what you do not use. An inactive plugin is still code sitting on your server. Fewer plugins means a smaller attack surface
- Only install from official repositories or the developer’s own site. Free “nulled” premium plugins are the most reliable way to get malware
Typical cost: free if you do it yourself and accept the risk of a broken layout, or 40 to 150 per month as part of an agency care plan that includes checking the site afterwards.
Who handles it: your agency, or one clearly named person internally. “Everyone” means nobody.
6. Automated backups stored somewhere else
What it does: Backups are your insurance policy. Every other measure on this list reduces the chance of a disaster. Backups are what turn a disaster into an inconvenience.
What a usable backup looks like:
- Automatic, daily at minimum, and more often for shops taking orders
- Off-server, meaning stored somewhere other than the hosting account itself. A backup on a hacked server is not a backup
- Retained for at least 30 days, because some infections stay hidden for weeks
- Includes both files and database
- Tested. Restore one to a staging site at least twice a year. An untested backup is a hope, not a plan
Typical cost: often included with managed hosting, otherwise 5 to 25 per month for a dedicated backup service.
Who handles it: host or agency configures, you verify the restore test actually happened.
7. A web application firewall
What it does: A Web Application Firewall (WAF) sits in front of your site and filters traffic before it arrives. Think of it as a doorman who recognises known troublemakers and turns them away. It blocks common attack patterns such as SQL injection and cross site scripting, filters out bad bots, and absorbs traffic floods.
A cloud WAF has a useful side effect: it usually comes with a CDN, which makes your pages load faster around the world.
Typical cost: capable free tiers exist and are genuinely good enough for a brochure site. Paid plans run roughly 20 to 30 per month and add stronger rules, bot management and better reporting. Some managed hosts include a WAF in the plan.
Who handles it: agency or host. This one needs a small amount of configuration to avoid blocking legitimate visitors, so it is not a good DIY project. me.uk has covered this at length.
8. Login page protection
What it does: Your login page is the front door and bots knock on it constantly. Login protection makes brute force guessing pointless.
The measures worth having:
- Rate limiting: block an IP address after a handful of failed attempts
- Change the default login URL so automated scanners cannot find it easily
- CAPTCHA on login and on contact forms, which also cuts spam enquiries
- Restrict admin access by IP if your team all works from one office
- Disable file editing from the dashboard, so a stolen login cannot be used to edit code
- Alerts on new admin accounts, one of the clearest signs of a breach
Typical cost: free to 100 per year. Reputable security plugins cover most of this in one place.
Who handles it: agency, or a confident in-house person following documentation.
9. Malware scanning and uptime monitoring
What it does: Tells you there is a problem before your customers do. A scanner checks your files for injected code and unexpected changes. An uptime monitor pings your site every few minutes and emails or texts you when it stops responding.
Also worth doing: add your site to Google Search Console. It is free and Google will notify you directly if it detects malware or spam on your pages.
Typical cost: free monitoring tools cover the basics; scanning plus monitoring bundles run 10 to 30 per month.
Who handles it: agency sets up, alerts go to two people so nothing is missed during holidays.
10. Access hygiene and a one page incident plan
What it does: Limits the damage a single compromised account can do, and stops panic from making things worse.
Access hygiene, twice a year:
- Review who has access to the website, hosting, domain and analytics
- Remove ex-employees, ex-freelancers and any test accounts
- Confirm you, not your agency, are the registered owner of the domain and hosting. This is a critical point that catches a lot of businesses out
- Downgrade anyone who does not need administrator rights
Your incident plan needs only four things:
- Who to call first, with the phone number written down offline
- Where the backups live and who can restore them
- Logins for host, registrar and website, stored in the password manager and accessible to a second person
- What you will tell customers if data was exposed, and any reporting obligations you have
Typical cost: an hour of your time.
Who handles it: you, with input from your agency.

Cost and ownership at a glance
| Measure | Typical cost | Best owner | Priority |
| SSL / HTTPS | Free | Host or agency | Essential |
| Secure hosting | 25 to 60 / month | Owner decides | Essential |
| Password policy | 0 to 4 / user / month | Owner and team | Essential |
| Two factor authentication | Free | Owner and agency | Essential |
| Updates and maintenance | Free to 150 / month | Agency or named person | Essential |
| Automated backups | 0 to 25 / month | Host or agency | Essential |
| Web application firewall | 0 to 30 / month | Agency or host | High |
| Login protection | 0 to 100 / year | Agency | High |
| Scanning and monitoring | 0 to 30 / month | Agency | Medium |
| Access review and plan | Your time | Owner | Medium |
Costs are indicative ranges in your local currency for a typical small business site and will vary by provider and by how much traffic you get.
A realistic 30 day rollout
You do not need to do all ten at once. Here is the order that removes the most risk for the least effort.
Week 1: the free wins
- Confirm HTTPS works site-wide and the certificate auto-renews
- Enable two factor authentication on website, hosting, domain and email
- Change every admin password to a long unique passphrase in a password manager
- Delete unused accounts and any account named “admin”
Week 2: the safety net
- Set up or verify daily off-server automated backups
- Actually restore one backup to staging to prove it works
- Add uptime monitoring and connect Google Search Console
Week 3: the walls
- Install and configure a web application firewall
- Add login rate limiting, CAPTCHA and a non-default login URL
- Remove every plugin and theme you are not using
Week 4: make it a habit
- Book a recurring monthly maintenance window, or sign a care plan
- Write your one page incident plan and share it with a second person
- Diarise a six-monthly access review
- Review whether your hosting is genuinely good enough for what the site earns you

Warning signs your site may already be compromised
- Google shows a “this site may be hacked” or deceptive site warning
- Pages redirect somewhere strange, but only for visitors arriving from search or on mobile
- Admin accounts you did not create
- Sudden unexplained slowness or server resource spikes
- Your business email starts landing in spam folders everywhere
- New files with random names in your site directories
- Search results showing pages you never published, often in another language
If you see any of these, do not simply delete files and hope. Take a full copy for evidence, change all passwords from a clean device, and get a professional clean-up. Attackers usually leave a hidden way back in, and missing it means you get hacked again a week later.

What you can safely skip
Small business security advice often drifts into enterprise territory. For a typical site with a few hundred visitors a day, you almost certainly do not need penetration testing every quarter, a dedicated security operations service, an expensive Extended Validation certificate, or five overlapping security plugins fighting each other.
Ten fundamentals done consistently will stop the automated attacks that cause the vast majority of small business incidents. Consistency beats sophistication every time.
Frequently asked questions
What is the best security for a website?
There is no single product. The strongest setup is layered: HTTPS, quality hosting, unique passwords with two factor authentication, prompt updates, tested off-site backups, a web application firewall and login protection. If you can only do one thing today, enable two factor authentication. If you can only do two, add automated off-server backups.
What are the 5 basic security principles?
Most frameworks come down to five ideas: confidentiality (only the right people see data), integrity (data is not altered without permission), availability (the site stays online), authentication (people are who they claim to be) and non-repudiation or accountability (actions are logged and traceable). Every item in this guide serves at least one of them.
What are the 5 C’s in security?
The 5 C’s are commonly listed as change, compliance, cost, continuity and coverage. In practical terms for a small business: can you adapt when threats evolve, do you meet the rules that apply to you, is the spend proportionate, can you keep trading after an incident, and are all your important assets actually protected rather than just the obvious ones.
What is the 80/20 rule in cybersecurity?
Roughly 20 percent of the effort prevents about 80 percent of the incidents. For websites, that 20 percent is strong unique passwords, two factor authentication, keeping software patched and having working backups. Those four cover the bulk of real-world attacks and cost very little.
Do I need a security plugin if my host already provides security?
Usually a light one, yes. Host level protection guards the server; a security plugin guards the application layer, adding login limits, file change detection and user alerts. Just do not run several at once, as they conflict and slow the site down.
How much should a small business budget for website security?
A reasonable range is 40 to 120 per month all in, covering quality hosting, backups, a firewall and maintenance. Compare that to a professional malware clean-up plus lost enquiries during downtime, which typically costs several hundred to a few thousand in one go.
Is a website builder platform safer than WordPress?
Hosted platforms handle patching for you, which removes one big risk, but they also limit your control and portability. WordPress is not inherently insecure; the problems come from neglected plugins and weak logins. A well maintained WordPress site is safer than an abandoned site on any platform. For the wider picture, see Secure Your Business.
Who should be responsible for website security in a small business?
Split it clearly. The owner owns passwords, access reviews, domain ownership and the budget. The host owns server hardening, SSL and platform backups. The agency owns updates, firewall configuration, login hardening, monitoring and clean-up. Write down who does what, because unclear ownership is itself a vulnerability.
Next step
Run through the Week 1 list on your own site this morning. It takes under an hour and closes the doors attackers use most. If you would rather have someone confirm your site is properly protected, or you want updates, backups, firewall and monitoring handled for you, get in touch and we will review your setup and tell you exactly what is missing.
