30 Jun 2026
A Simple Website Security Checklist for Small Businesses
The large majority of small-business website compromises come from a handful of avoidable gaps, not sophisticated attacks. This checklist covers the ones worth fixing first.
HTTPS everywhere. If your site still serves any page over plain HTTP, fix that first — it's free with most hosting providers now and browsers actively warn visitors away from unencrypted sites.
Keep software patched. WordPress core, plugins, themes, and the server's own OS packages — outdated software is the single most common way sites get compromised. Automated patching (part of proper server management) removes the human forgetfulness factor.
Use strong, unique admin passwords — and change any default credentials immediately after setup. A shocking number of breaches start with unchanged default logins.
Limit who has admin access, and review it periodically. Former employees or contractors with lingering access is a common, quietly dangerous gap.
Take backups you've actually tested. A backup that has never been restored is a guess, not a safety net.
Put a firewall and basic malware scanning in front of anything public-facing. This is standard on any properly managed server and catches a large share of automated attack attempts before they matter.
None of this requires a large budget — it requires consistency. That consistency is exactly what managed server support is meant to provide.