An afternoon security check for a small business website

Small business websites rarely get attacked because someone picked them. They get attacked because automated tools scan millions of sites a day looking for the same handful of weaknesses: old software, weak passwords, forgotten accounts. Nobody is targeting your bakery. They are trying every door on the street.
That is actually good news. It means a short list of checks closes most of those doors. Set aside an afternoon.
1. HTTPS, everywhere, renewing on its own
Your address bar should show a secure connection on every page, not just the homepage. Check that the certificate renews automatically. An expired certificate puts a full page warning in front of every visitor.
2. Software that is up to date
If your site runs on WordPress or a similar system, outdated plugins and themes are one of the most common ways in. Update the core software, every plugin and the theme. Then delete the plugins you no longer use. A deactivated plugin can still be a risk, so remove it entirely.
If a plugin has not been updated by its maker in years, look for a maintained replacement.
3. Accounts: who still has the keys?
List everyone with admin access to the site, the hosting, the domain registrar and your email. Remove former staff, old freelancers and anyone you do not recognize. Then:
- Give every remaining person their own login instead of a shared one.
- Use long, unique passwords stored in a password manager.
- Turn on two step verification everywhere it is offered, starting with the domain registrar and email.
4. Backups you have actually tested
Backups should run automatically, be stored somewhere other than the server the site lives on, and go back far enough to predate a problem you might not notice for weeks. Then do the part almost everyone skips: restore one, somewhere safe, to prove it works.
A backup you have never restored is a hope, not a backup.
5. The domain itself
Turn on auto renew, make sure the contact email is one you read, and switch on the registrar's transfer lock. Losing your domain takes your website and your email down together.
6. Forms
Add spam protection to every form. Never ask for card numbers, health details or passwords through an ordinary contact form. If you accept file uploads, limit them to the types and sizes you actually need.
7. Email authentication
Three settings on your domain, called SPF, DKIM and DMARC, tell inboxes which services are allowed to send mail as your business. Without them it is easier for someone to send fake invoices that look like they came from you, and your real emails are more likely to land in spam. Your email provider has instructions for adding them.
8. Third party scripts
Chat widgets, old tracking codes, abandoned marketing tools: every script on your site runs with the same access as your own code. Remove the ones you no longer use.
Signs your site may already be compromised
- Visitors, especially on phones, get redirected to sites you have never heard of.
- Google shows "This site may be hacked" under your listing, or Chrome shows a red warning page.
- Searching
site:yourdomain.caon Google turns up pages you did not create, often in other languages or selling things. - Admin users appear that nobody added.
- Your host suspends the account, or your emails start bouncing.
If it has been hacked
Do not just delete the visible symptom. Attackers usually leave a way back in. The safe order is: take a copy of the current site for evidence, restore from a backup made before the attack, change every password, update everything, check for unknown admin users, and then ask Google to review the site through Search Console once it is clean.
If that list sounds like a lot, it is exactly what our one time Fix & Secure service is for. It starts at $349 for bug fixes plus a security and health check, and we tell you what we changed. A hacked site is quoted in writing once we have seen how deep the problem goes, before any work starts.
Turn on two step verification for your domain registrar and email, update everything on the site, delete unused plugins, and confirm the domain is set to auto renew.
Send us the link. We will tell you which of these checks it fails and what we would fix first. Call 647 846 6561 or email hello@bootstrappedstudios.com.
See Fix & Secure pricing