← Back to Blog

Website Security Basics: A Practical Checklist for Small Businesses

A practical, platform-neutral website security checklist for small-business owners, covering accounts, updates, access, backups, monitoring, and what to do when something looks wrong.

A website does not need to be famous to attract unwanted attention. Automated tools continually look for weak passwords, outdated software, exposed accounts, spam opportunities, and poorly maintained websites. The result might be a compromised administrator account, unwanted redirects, contact-form spam, or a website that becomes unavailable.

That does not mean you need to become a security specialist. No checklist can guarantee complete protection, but routine security basics can reduce common risks and make problems easier to detect and recover from.

Start by identifying who is responsible

Website security is usually shared between several people and services. Depending on your setup, your hosting company, website platform, developer, maintenance provider, and business may each control different parts of the work.

For example:

  • A hosting provider may manage server security and some platform updates.
  • A website platform such as Shopify, Wix, or Squarespace may manage much of the underlying infrastructure.
  • A developer or maintenance provider may handle website updates, backups, and fixes.
  • Your business may still be responsible for administrator accounts, domain access, email security, and approving changes.

Ask your provider to confirm, in plain English, who is responsible for:

  • Website, plugin, theme, integration, or platform updates
  • Hosting and server maintenance
  • Backups and restoration
  • Security monitoring
  • Domain and DNS changes
  • Responding to a suspected compromise

Keep the answers somewhere your business can access. A hand-coded website, WordPress site, Shopify store, Wix site, Squarespace site, or another setup will have different maintenance arrangements, but every business benefits from knowing who owns each task.

Protect every important account

Your website is only one part of your online presence. Treat the following as separate accounts that may need their own secure login:

  • Website administration
  • Domain registrar, where your domain name is registered
  • Hosting account
  • Business email
  • Analytics and advertising accounts
  • Payment and e-commerce accounts
  • Website platform or app integrations

Use a unique, strong password for each account. Reusing one password means a breach at one service could put other accounts at risk. A password manager can create and store unique passwords without requiring you to memorise them all.

Turn on two-factor authentication, often called 2FA, wherever it is available. It adds a second verification step, such as an authenticator app or security key, after your password. This is particularly important for email, domain, hosting, website administrator, and payment-related accounts.

Make sure recovery email addresses and phone numbers belong to the business rather than one person’s private account. Store backup codes securely and ensure more than one trusted person knows how to access essential business accounts if the primary administrator is unavailable.

Remove access that is no longer needed

Review who can access your website and related services. Former employees, previous agencies, freelancers, suppliers, and temporary contractors should not retain access after their work ends.

Where possible, give each person an individual login instead of sharing one administrator password. Individual accounts make it easier to remove one person’s access without disrupting everyone else and provide a clearer record of changes.

Give people the lowest level of access they need. Someone who only edits page text may not need permission to manage domains, install extensions, change payment settings, or create new administrator accounts.

Review access after staff changes, when a supplier relationship ends, and periodically as part of normal maintenance.

Keep software and integrations current

Updates often include security fixes as well as new features. Keep the parts of your website and online services current, including:

  • Website software or content management systems
  • Plugins, themes, apps, and extensions
  • Payment, booking, email, and analytics integrations
  • E-commerce components
  • Server-supported software, where your provider manages or exposes that responsibility

The exact process depends on your setup. Hosted platforms may update much of their underlying software for you, while a site with separate plugins or integrations may require more active maintenance. A hand-coded site can still depend on hosting, libraries, services, or integrations that need review; being hand-coded does not automatically make a site secure.

Before a significant update, confirm that you have a recent backup and that the update is compatible with your website. If you are unsure, ask your developer or maintenance provider to handle it. Avoid leaving updates indefinitely just because the website appears to be working normally.

Check access to your domain and hosting

Your domain name and hosting account are especially important because control of them can affect the whole website. Keep these accounts under business control, not solely under a former employee, freelancer, or agency.

Use a business-owned email address where practical, enable two-factor authentication, and know how to reach the registrar or host if an urgent change is needed. Be cautious about unexpected requests to change domain settings, payment details, DNS records, or account ownership. Confirm sensitive requests through a trusted channel rather than relying only on an email message.

Keep HTTPS working and watch for warning signs

HTTPS is the secure connection used when a browser communicates with a website. It is supported by an SSL/TLS certificate, which helps protect information exchanged between the visitor and the site.

Make sure your certificate remains active and that visitors do not see browser warnings. Your host, platform, or maintenance provider may manage certificate renewal, but you should still know who is responsible.

You do not need to inspect the website constantly. Add simple checks to your routine and look for:

  • Browser warnings or messages that the site is not secure
  • Unexpected redirects to another website
  • New administrator accounts you do not recognise
  • Unfamiliar pages, posts, products, or changes to contact details
  • A sudden increase in contact-form or comment spam
  • Password reset messages or login alerts you did not request
  • Unexpected changes to domain, hosting, email, payment, or analytics settings

Some of these signs can have harmless explanations, but they are worth investigating promptly.

Treat backups as part of security

A backup is a copy of your website and, depending on the setup, its database, media, configuration, or store information. Backups help you recover after an accident, failed update, compromised account, or other serious problem.

Backups are not a substitute for prevention. If a backup is connected to the same compromised account or overwritten immediately, it may not help when you need it. Ask whether your provider keeps an independent copy and how long backups are retained.

You should also know how restoration works. A backup that has never been tested may not contain everything your business needs. Ask your provider to test restoration periodically, or arrange a review if your website is important to daily operations. Keep records of any information that may not be included in a website backup, such as payment-platform settings or email data.

What to do if something looks wrong

If you notice suspicious changes or receive an unexpected security alert:

  1. Stop making unnecessary changes. Avoid repeatedly logging in, deleting files, or installing fixes before the situation is understood.
  2. Document what you see. Save screenshots, messages, times, affected URLs, and any unusual account activity.
  3. Use a clean device if possible. From a device you trust, change affected passwords and revoke unfamiliar sessions. Prioritise email, domain, hosting, website administration, and payment-related accounts.
  4. Contact your host, developer, or maintenance provider. Ask them to investigate, preserve relevant information, and explain what they recommend.
  5. Check related accounts. A website problem may involve email, domain access, integrations, or payment settings as well.
  6. Restore carefully. Do not restore a backup until you have considered how the problem happened. Otherwise, the same weakness may remain or the unwanted change may return.
  7. Escalate when necessary. If customer information, payment data, email accounts, or business systems may be affected, seek specialist advice promptly and follow any relevant reporting obligations.

A simple website security routine

Save this checklist and adapt it to your setup.

Every week

  • Check that the website loads normally and uses HTTPS.
  • Look for unexpected redirects, content changes, new users, or unusual form activity.
  • Review important security alerts and login notifications.

Every month

  • Confirm that website software, apps, plugins, themes, and integrations are current or that your provider is managing them.
  • Check that backups are completing and that you know where they are stored.
  • Review administrator and supplier access.
  • Check domain, hosting, email, analytics, and payment accounts for unfamiliar activity.

Every quarter

  • Test or arrange a backup restoration review.
  • Confirm who is responsible for updates, monitoring, backups, and incident response.
  • Review two-factor authentication and recovery details.
  • Remove old accounts and reduce permissions that are no longer needed.
  • Check that your business, rather than an individual supplier, controls essential domain and hosting access.

Security is an ongoing maintenance responsibility, not a one-time installation. If you want help confirming responsibilities, keeping a site maintained, or responding to routine website issues, see SiteRook’s current maintenance, hosting, and support options.

Ready to talk about your website?

Tell us what your business needs and SiteRook can recommend a practical next step.

Get Started