Website security is not a one-time task you complete when a site launches. Websites change over time: staff members join and leave, software is updated, forms receive submissions and third-party services are connected.
A short monthly review can help you catch common problems early and confirm that someone knows what to do if something looks wrong. It cannot guarantee that your website will never be compromised, go offline or experience a technical issue. It is a routine for reducing avoidable risk and keeping important safeguards from being forgotten.
You can complete the checks yourself, delegate them to a member of staff or ask your hosting provider, developer or maintenance service to handle them. The important part is to record what was checked and follow up on anything unusual.
1. Review who can access the website
Start with access. Administrator access means permission to make major changes to a website, such as editing content, installing software, changing settings or managing other users. These accounts need particular attention because a compromised administrator account can affect the whole site.
Review the list of website users and ask:
- Does each person still need access?
- Does each person have the right level of permission for their role?
- Are there accounts belonging to former employees, contractors or agencies?
- Are there shared logins that could be replaced with individual accounts?
Remove access promptly when an employee, contractor or agency relationship ends. Do not wait until the next convenient website project. If someone no longer needs access, their account should be removed or disabled, and any shared passwords they knew should be changed.
Use a unique, strong password for each important account. Where available, enable multi-factor authentication (MFA). MFA adds another sign-in step, such as a code from an authentication app or a security key, in addition to the password. This makes a stolen password less useful on its own.
2. Check updates before making changes
Websites often depend on a platform, content management system, plugins, themes, apps or integrations. Updates may fix bugs, improve compatibility or address security issues, but the safest update process differs by platform and setup.
During your monthly check, confirm that the software supporting the site is still supported and that available updates have been reviewed. If your site is managed by a provider, ask whether updates are included and how they are tested.
Before significant updates or other changes, take a backup or confirm that a recent, usable backup exists. Follow your provider’s safe-update guidance rather than installing changes blindly. Some platforms update automatically; others require updates to be reviewed and applied manually. Neither approach removes the need to know what is covered and what to do if an update causes a problem.
Avoid installing software simply because it offers a feature you might use later. Every plugin, app or integration adds another connection that may need maintenance.
3. Confirm that backups are available
A backup is a separate copy of website data and files that can be used to restore the site after a failure, accidental change or security incident. A backup is only useful if it includes what you need and can be accessed when the live website cannot.
Check the following each month:
- What does the backup include: website files, databases, images, product information and settings?
- How often are backups made?
- How long are older copies kept?
- Where are the copies stored?
- Who can access them?
- Does your provider offer restoration support?
Where possible, keep backup copies separately from the live hosting account. If an attacker or technical failure affects the hosting account, backups stored only there may also be unavailable or damaged.
Website backups and business email backups may be separate services. A website backup does not necessarily protect your email inboxes, calendars or shared files, so confirm those arrangements independently.
You do not need to perform a full restoration every month, but restoration support or testing should be available and reviewed occasionally. A backup that has never been checked may not work as expected when you need it.
4. Check HTTPS, forms and the visitor experience
HTTPS is the secure version of the connection between a visitor’s browser and your website. It is shown by a padlock or similar indicator in most browsers. The certificate that enables HTTPS is often called an SSL certificate, although people commonly use “SSL” as a general term for website connection security.
Open the website in a browser and check that:
- The main address uses
https://rather than onlyhttp://. - The browser does not show a certificate warning.
- Important pages load without security messages.
- Contact, booking, enquiry and checkout forms work.
- Form submissions reach the right inbox or system.
- Confirmation messages are clear and appropriate.
Do not assume that a form works just because the page loads. Submit a test enquiry where practical, then confirm that it arrives. Check that payment or booking steps work as expected without entering unnecessary real customer information.
Look for unexpected error messages, broken layouts, missing images, unfamiliar pop-ups or redirects to unrelated websites. Test the site on a phone as well as a computer if mobile visitors are important to your business.
5. Watch for warning signs
You do not need to inspect technical logs to notice every possible problem. Simple changes can be useful clues. During your monthly review, look for:
- An unfamiliar administrator or staff account.
- Website text, images or links that nobody in the business added.
- New pages, files, pop-ups or redirects.
- Unexpected changes to prices, contact details or opening hours.
- A sudden increase in spam submissions.
- Hosting, domain or platform security alerts.
- Customer reports that the site looks unusual or does not load properly.
- Traffic or enquiry patterns that seem different without a business explanation.
One unusual event does not always mean the website has been compromised. A marketing campaign, seasonal change or software update can affect traffic and appearance. Record what you found and ask the appropriate provider to review anything you cannot explain.
If you see signs of compromise, contact your host, developer or platform support promptly. Avoid making risky fixes, deleting files or reinstalling software before a backup and recovery plan are confirmed. Unplanned changes can remove evidence, make recovery harder or cause further downtime.
6. Review connected accounts and services
Your website may connect to more services than you realise. These can include the domain registrar, hosting account, business email, payment provider, booking system, analytics tools, newsletter service and social media accounts.
Once a month, confirm that:
- The domain registrar and hosting account have current contact details.
- Only the right people can access important services.
- MFA is enabled where available.
- Former staff and suppliers no longer have access.
- Payment, booking and email integrations still belong to your business.
- Old apps, test accounts and unused integrations have been removed or reviewed.
Domain access deserves special attention. The domain registrar controls the address people use to find your website. Losing control of that account can affect the website, email and customer trust, even if the website files themselves are safe.
Business email accounts also need their own security review. If someone gains access to an email account used for password resets or customer communication, they may be able to affect other services connected to it.
7. Keep a simple record
A record turns a vague responsibility into a repeatable process. It also helps when you change providers, take time off or ask someone else to manage the website.
Record:
- The date of the check.
- The person who completed it.
- Which items were checked.
- Any problems or unusual findings.
- The action required.
- The person responsible for follow-up.
- The date the issue was resolved or passed to a provider.
A spreadsheet, shared document or calendar task is enough. Keep the record somewhere your business can access even if the website is temporarily unavailable.
Printable monthly website security checklist
Copy this list into a calendar reminder:
- [ ] Review website administrator and staff accounts.
- [ ] Remove access for former employees, contractors and agencies.
- [ ] Confirm strong, unique passwords and MFA for important accounts.
- [ ] Check that the platform, plugins, themes, apps and integrations are supported.
- [ ] Review updates and follow the provider’s safe-update process.
- [ ] Confirm that a recent website backup exists and know what it covers.
- [ ] Confirm that backup access or restoration support is available.
- [ ] Check that website and business email backup arrangements are considered separately.
- [ ] Confirm HTTPS/SSL is working without browser warnings.
- [ ] Test important contact, booking, enquiry or checkout forms.
- [ ] Look for unexpected content, accounts, files, redirects or pop-ups.
- [ ] Review hosting, domain, email and third-party service access.
- [ ] Record issues, actions and the person responsible for follow-up.
Some tasks should happen less frequently or after major changes. These include testing a full restoration, reviewing every connected account in detail, checking domain ownership records and reviewing the website’s recovery plan. Ask your provider how often these checks are appropriate for your setup.
A monthly routine does not replace professional support, monitoring or a response plan. It gives you a clear way to notice changes, confirm basic safeguards and make sure unresolved issues have an owner.
If you would like help with hosting, maintenance, ongoing edits and support, SiteRook can provide these services depending on the plan. See the current options at siterook.com/pricing/.

