“Who would bother with my little website?” is the most dangerous thought a business owner can have — and it is dangerous because it rests on the wrong picture: a hooded hacker who personally picked you out. In reality, almost none of the attacks that hit small sites have a name or a face. They come from automated programs (bots) that scan millions of sites a day, neither knowing nor caring who you are, and try the handle on every door they pass. You are not being targeted; you are simply being walked past. The good news, and the reason I am writing this without any scare tactics: a handful of basics, set up properly, close off the overwhelming majority of that risk.
Why small sites get hit at all
A compromised site has value even if you sell nothing online. Attackers want it to send spam through your server, to host scam (phishing) pages under your clean-looking name, to slip in hidden links pointing at other sites, or simply to add another machine to a network of infected ones. The most common story is not dramatic theft at all — it is one old, forgotten plugin that never got updated and quietly became a way in. That is why security has nothing to do with how big you are and everything to do with how well-kept your site is.
The six basics — in order of importance
1. SSL — the padlock in the address bar
SSL encrypts everything a visitor exchanges with your site — form entries, passwords, contact details — so no one in the middle can read it. Without it, browsers show a “Not secure” warning next to your address, and Google pushes the site down. The good part: it is now free and takes minutes to set up. There is no excuse for it to be missing in 2026.
2. Backups — automatic, not “when I remember”
A backup is the safety net that makes every other problem reversible. If the site is lost tomorrow — to an attack, to human error, or to a server failure — a proper backup is the difference between “we lost ten minutes” and “we lost everything.” Three things matter: it must be automatic (never dependent on your memory), daily, and stored somewhere other than the server itself. A backup sitting next to the site is lost along with the site.
3. Updates — the most neglected job of all
The software that runs your site — the content system, the themes, the plugins — ships security fixes constantly. Each time a hole is discovered, the fix is published alongside it; and within hours the bots start hunting for sites that have not applied it yet. A site left un-updated for months is not just “a bit behind” — it is a publicly known unlocked door. Updates should be done regularly and carefully, always with a fresh backup in hand first.
4. Strong passwords + two-factor authentication (2FA)
- A separate, long password for every account — site admin, email, hosting, domain. One shared password everywhere means a single leak opens all of them.
- A password manager so you do not have to remember them — it remembers the many, you remember one.
- Two-factor authentication (2FA) everywhere it is offered. Even if someone steals your password, without the second code from your phone they do not get in. It is the single highest-return measure you can take.
5. A firewall (WAF) standing in front of the bots
A proper wall in front of the site — a Web Application Firewall, like the Cloudflare setup we use — filters traffic before it ever reaches your server. It blocks known malicious bots, stops repeated login attempts, and absorbs overload attacks (when thousands of requests try to knock the site over). As a bonus, a good WAF often makes the site faster too, which matters more than most owners realise.
6. Least access
The fewer people who hold admin passwords, the smaller the surface for something to go wrong. Give each person only the access they genuinely need — someone who writes articles does not need administrator rights. And when a collaborator or provider leaves, the passwords change that same day, not “at some point.”
Want a site that is secure from day one?
On every project we build, all of the above comes set up from the start — SSL, automatic backups, updates, Cloudflare, monitoring. Security is not an “extra” for us; it is part of the job. Ask us about your own site.
Start a conversation →Malware: what it is and how you spot it
“Malware” is simply malicious code that has crept into your site. It is rarely dramatic — the usual case is code working quietly for weeks before anyone notices. Here are the signs that should put you on alert:
- The site opened up “wrong” — foreign ads, redirects to unrelated pages, content you never added.
- Google shows a “This site may be hacked” or “Deceptive site ahead” warning.
- A sudden drop in traffic, or emails from your domain that all land in spam.
- Your hosting provider flags unusual activity or suspends the account.
If you see any of these, do not leave it “for tomorrow.” Every hour counts — both for your customers' safety and for your standing with Google, which can take weeks to recover.
A practical checklist
Print it or drop it in a note. If you can answer “yes” to all of these, you are ahead of 95% of small sites:
- Does my site have SSL (the padlock shows, the address starts with https)?
- Are automatic, daily backups running and stored off the server?
- Is the software, along with themes and plugins, updated regularly?
- Do I use strong, separate passwords and 2FA on the site, email and hosting?
- Is there a firewall/WAF in front of the site?
- Do I know who has access — and do I change passwords when someone leaves?
- Would I even notice if something went wrong (monitoring, alerts)?
Frequently asked questions
Do I need expensive antivirus for my website?No. A site is not like your laptop. Website security is mostly good habits: updates, backups, passwords, a WAF. Those make the difference, not some “magic” program.
I collect customer data — is there a legal side too? Yes. Security and data protection go together; see our services page for how we handle both when we build and maintain a site.
I put my own site online — what should I get right first? Start with SSL, strong passwords and automatic backups; those three cover most of the ground before anything else.
I have already been hacked — what now? Take the site offline temporarily, change every password, restore from a clean backup, and only then work out how they got in. If you are unsure, get help before you touch anything — a rushed move often makes the damage worse. You can always reach us, or read more about how we work on our home page.
Want us to build it for you?
Tell us what you need — we'll get back to you within 24 hours with a concrete proposal, cost and timeline.
Let's work together