Most small business websites aren't attacked by someone who has picked them out. They're
found by automated programs that scan millions of sites a day, looking for an old plugin, a
reused password or an inbox that will click the wrong link. The good news: the fixes are
mostly free, mostly one-time, and none of them needs a technical background. Here's the
checklist we use on our own sites and our clients'.
Your website is only as safe as the accounts that control it: your hosting, your domain, your email and anything that takes payments.
Turn on two-step sign-in everywhere. Hosting, domain registrar, email, website admin, payment processor (Stripe, Square, PayPal) and social media. A code from an app on your phone means a stolen password alone isn't enough to get in.
Use a password manager. One strong, different password per account, remembered for you. It also refuses to fill in your password on a fake login page, which quietly protects you from phishing.
Store your backup codes safely. When you turn on two-step sign-in you get one-time backup codes. Keep them in your password manager, not in a file in your Downloads folder.
Remove people who no longer need access. Former staff, past designers and old freelancers: take them off your hosting, website and social accounts.
2. Keep the website itself up to date
Out-of-date software is the most common way into a small business site.
Apply updates promptly. Your site platform, its plugins and its theme. If your site has a code repository, turn on automatic update checks (for example GitHub's Dependabot) so you hear about security fixes as soon as they're out.
Delete what you don't use. Old plugins, test pages and forgotten demo sites are still doors, even if nobody visits them. Take unused sites offline.
Make sure every page uses HTTPS. The padlock in the address bar. It's free with most hosts and it's expected by visitors and search engines.
Keep private files private. Settings files, database exports and old backups should never be reachable from a web address.
3. Have backups you've actually tested
A backup you've never restored is a hope, not a plan.
Back up automatically. Daily is ideal. Check that your host backs up your database as well as your files; they're often separate.
Test a restore once. Restore a backup to a separate copy and check that your content is all there. Then you know it works before you need it.
Keep a copy somewhere else. Once a month, keep a copy away from your host, so one company having a bad day can't take everything with it.
4. Stop people from faking your email address
Without these settings, anyone can send an email that looks like it came from your business, and your real emails are more likely to land in spam.
SPF: a public list of the services allowed to send email as your domain (your email provider, your newsletter tool, your online store).
DKIM: a digital signature your email provider adds, proving a message really came from you. Your provider gives you a record to add.
DMARC: tells other inboxes what to do with fakes. Start at "none" with reports turned on, check that all your real email passes, then move to "quarantine".
5. Protect your forms and your inbox
Contact forms are a favourite route for spam and for phishing aimed at you.
Add a human check to your forms. A mostly invisible check such as Cloudflare Turnstile stops automated junk without annoying real people.
Be suspicious of links in form messages. A message that flatters your work and points you to a "shared folder" or "proposal" link is a classic phishing trick. Check the sender's actual address, and if in doubt, contact them another way.
Turn on your email provider's protections. Most providers can quarantine messages that fail SPF, DKIM or DMARC checks, or that use your own name from an outside address.
6. Don't lose your domain
If your domain lapses, your website and your email stop, and someone else can buy it.
Turn on auto-renew and keep the payment card on file current.
Turn on the registrar lock so your domain can't be moved to another company without your say-so.
Put the renewal date in your calendar with a reminder a month ahead, just in case.
Where to start
If you only do three things this week: turn on two-step sign-in for your email and
your hosting, check that your backups include your database, and set your domain to
auto-renew. Those three alone close the doors most small businesses get caught by.
Rather not think about it?
Websites hosted with Peniche Communications come with an SSL certificate, automated
backups and security patches applied for you, so the technical half of this list is
handled. Or grab the free printable checklist and work through it at your own pace.