30 Jun 2026

A Simple Website Security Checklist for Small Businesses

The large majority of small-business website compromises come from a handful of avoidable gaps, not sophisticated attacks. This checklist covers the ones worth fixing first.

HTTPS everywhere. If your site still serves any page over plain HTTP, fix that first — it's free with most hosting providers now and browsers actively warn visitors away from unencrypted sites.

Keep software patched. WordPress core, plugins, themes, and the server's own OS packages — outdated software is the single most common way sites get compromised. Automated patching (part of proper server management) removes the human forgetfulness factor.

Use strong, unique admin passwords — and change any default credentials immediately after setup. A shocking number of breaches start with unchanged default logins.

Limit who has admin access, and review it periodically. Former employees or contractors with lingering access is a common, quietly dangerous gap.

Take backups you've actually tested. A backup that has never been restored is a guess, not a safety net.

Put a firewall and basic malware scanning in front of anything public-facing. This is standard on any properly managed server and catches a large share of automated attack attempts before they matter.

None of this requires a large budget — it requires consistency. That consistency is exactly what managed server support is meant to provide.

Questions about your own setup?