Introduction
Website security is a process, not one plugin or firewall.
A small business may not consider itself an attractive target, but automated attacks do not need to know the size of the company.
The goal is to reduce unnecessary exposure, protect critical accounts and make recovery possible when prevention fails.
This checklist focuses on practical controls business owners can understand and verify.

1. Protect the Domain Account
Use a strong unique password and multi-factor authentication for the domain registrar.
Keep recovery information controlled by the business.
An attacker with domain or DNS access may be able to redirect website or email traffic without touching the CMS.
Domain security belongs in the website security plan.
2. Protect Hosting Access
Limit hosting access to people who need it.
Use individual accounts where the provider supports them rather than sharing one master password widely.
Enable multi-factor authentication.
Remove old contractors and staff promptly.
3. Keep Software Updated
CMS platforms, plugins, frameworks and server packages receive security fixes.
Use a controlled update process and remove abandoned software.
Complex sites should test major changes before production.
Running old code indefinitely creates avoidable risk.

4. Use Least Privilege
Not every website user needs administrator permissions.
Give people the minimum access needed for their role.
This limits accidental changes and reduces the impact of a compromised account.
Review permissions periodically.
5. Maintain Reliable Backups
Backups are part of security because prevention is never perfect.
Keep recent off-site copies and test restoration.
For frequently changing websites, use a schedule that protects recent business data.
Do not leave backup archives publicly accessible on the website.
6. Use HTTPS Correctly
Serve the website over HTTPS and redirect old HTTP URLs appropriately.
Monitor certificate renewal.
Fix mixed-content warnings caused by insecure assets.
HTTPS protects data in transit but does not make an otherwise insecure application safe by itself.
7. Secure Forms and Inputs
Developers should validate and sanitize user input appropriately.
Forms should include reasonable anti-spam and abuse controls.
Custom applications should use secure development practices around authentication, sessions and database queries.
Security needs to be designed into functionality, not added after launch.
8. Protect Secrets and API Keys
Do not expose private API keys in client-side JavaScript or public code repositories.
Use environment variables or secure secret-management patterns appropriate to the platform.
Rotate credentials when staff or developers with access leave.
Document which services depend on each credential.

9. Monitor Availability and Important Alerts
Use uptime monitoring and review security alerts from hosting or application tools.
Alerts need a responsible recipient.
Too many low-value notifications can create alert fatigue.
Prioritize incidents that require real action.
10. Have an Incident Plan
Know who controls the domain, hosting, backups and business email before an emergency.
Document how the site can be taken offline, restored and communicated about if necessary.
For businesses handling sensitive information, additional legal or regulatory obligations may apply.
Planning recovery in advance is far easier than improvising during an incident.
Frequently Asked Questions
Do small businesses really get hacked? — Automated scanning and credential attacks affect sites of all sizes, so basic security hygiene is worthwhile.
Is a security plugin enough? — No. Security also depends on accounts, hosting, updates, backups and development practices.
Should website passwords be shared with staff? — Prefer individual accounts and role-based access where possible.
What is the most important security step? — There is no single control. Protect critical accounts, keep software maintained and preserve reliable recovery options.