Website Security Checklist
For small business owners. Tick each one off; most take minutes and cost nothing.
1. Accounts
- Two-step sign-in on: hosting, domain, email, website admin, payments, social media
- A password manager, with a different password for every account
- Backup codes stored in the password manager (not in Downloads)
- Former staff and freelancers removed from every account
2. Website updates
- Platform, plugins and theme up to date
- Automatic update alerts on (for example GitHub Dependabot)
- Unused plugins, test pages and old demo sites removed or offline
- Every page on HTTPS (the padlock)
- Settings files and backups not reachable from a web address
3. Backups
- Automatic backups, daily if possible
- Database included, not just files
- One restore tested, to a separate copy
- A monthly copy kept away from your host
4. Email (stop fakes)
- SPF lists every service that sends as your domain
- DKIM signing turned on with your email provider
- DMARC set up with reports; all real email passing
- DMARC moved from "none" to "quarantine"
5. Forms and inbox
- A human check on your forms (for example Cloudflare Turnstile)
- Links in form messages checked before clicking
- Unexpected "shared folder" or "proposal" links verified another way
- Email provider quarantining messages that fail SPF/DKIM/DMARC
6. Your domain
- Auto-renew on, with a current payment card
- Registrar lock on
- Renewal date in your calendar, with a reminder a month ahead
Only three things this week?
- Two-step sign-in on your email and your hosting
- Check your backups include your database
- Set your domain to auto-renew