Cybrial
Independent design. Ongoing growth.Manchester · Working everywhere

Guide · Building

How to Keep a Small Business Website Secure: Six Things, None of Them Expensive

By Measured 5 September 2026

Small business websites are not hacked by someone targeting them. They are hacked by automated scans that find an unpatched plugin or a weak password. Six habits close almost every door.

The short answer

To keep a website secure: apply updates promptly (platform, theme and plugins, weekly on WordPress); use long unique passwords with two-factor authentication on the admin login, the hosting account and the domain registrar; keep daily off-site backups and test a restore; host on a managed platform with a firewall and malware scanning rather than the cheapest shared plan; remove every plugin and account you do not need; and monitor so you know within hours, not months, if something changes. HTTPS is necessary but protects only the connection, not the site. If compromised: take it offline, restore a clean backup, change every password, update everything, and find out how they got in before going back live.

How small business sites actually get hacked

Not by a person who chose you. By scripts that scan millions of sites for known weaknesses: a plugin version with a published vulnerability, an admin login with a guessable password and no second factor, a forgotten test site on the same hosting account. When they find one, they install code that sends spam, redirects your visitors to scams, hides pharmacy links in your pages for search engines to find, or holds the site to ransom. You usually find out from a customer, from Google flagging the site, or from your host suspending it.

Because the attacks are automated, the defence is habit rather than expertise. Every one of the six below is something a managed host or a care plan does routinely, which is most of what such a plan is for.

The six things

What prevents nearly every compromise, and how often
#Do thisHow oftenWhy
1Apply updates: platform, theme, pluginsWeekly on WordPress; hosted platforms do it for youMost compromises exploit a vulnerability with a patch already available
2Long, unique passwords and two-factor authentication on admin, hosting and registrarOnce, then for every new accountCredential stuffing and brute force are the second door
3Daily off-site backups, and a test restoreDaily; test quarterlyTurns a disaster into an hour
4Managed hosting with a web application firewall and malware scanningOnce, when choosing a hostBlocks most automated attacks before they reach the site
5Remove unused plugins, themes, users and old test sitesQuarterly auditEvery unused thing is an unwatched door
6Monitoring: uptime, file changes, blacklist statusContinuousHours to detection instead of months

Source: Cybrial’s hosting and care practice, September 2026, and the pattern of compromises seen on sites taken over from other suppliers.

What HTTPS does and does not do

The padlock encrypts the connection between visitor and server so nothing is read or altered in transit. Every site needs it, and it is free. It does nothing for the site itself: an out-of-date WordPress with a vulnerable plugin is exactly as hackable with a padlock as without. Treat HTTPS as the floor and the six above as the building.

WordPress specifically

  • Most WordPress compromises come through plugins, not the core software. Fewer plugins, from reputable sources, kept updated, is the rule.
  • Do not use “admin” as a username. Limit login attempts. Add two-factor authentication with a plugin or through the host.
  • Keep the database prefix and file permissions as the host recommends; managed WordPress hosts set these correctly.
  • Turn on automatic updates for minor releases and plugins where the host offers it, with backups taken before each.
  • Delete inactive themes and plugins entirely; deactivated is not removed.

If it happens

  1. Take the site offline or put it in maintenance mode so visitors are not harmed and Google stops indexing the damage.
  2. Change every password: admin users, hosting, database, FTP, registrar, and the email accounts associated with them. Turn on two-factor where it was off.
  3. Restore from a clean backup taken before the compromise, or have the host or a specialist clean the files.
  4. Update everything, remove anything unused, and find the entry point; a cleaned site with the same hole is reinfected within days.
  5. Request a review in Search Console if Google flagged the site, and check the Security Issues report.
  6. Tell affected customers if personal data may have been exposed; under UK GDPR, notifying the ICO within 72 hours may be required.

Sources

Everything this page relies on.

  1. Search demand and click-price data: DataForSEO (Google Ads data, United Kingdom), read 4–5 September 2026. The specific phrases and figures are Cybrial’s own research and are not published.

  2. Cybrial hosting and care practice, correct at 5 September 2026: managed hosting with firewall and malware scanning, weekly updates, daily off-site backups, uptime and security monitoring, included in the £50-a-month fee.

  3. Information Commissioner’s Office guidance on personal data breaches under UK GDPR, including the 72-hour notification requirement where applicable.

  4. W3Techs usage statistics: WordPress used by roughly two-fifths of all websites.

Common questions

Questions people actually search for.

How do I keep my website secure?

Apply updates weekly, use long unique passwords with two-factor authentication on admin, hosting and registrar, keep daily off-site backups and test them, host on a managed platform with a firewall, remove unused plugins and accounts, and monitor for changes.

How do websites get hacked?

Almost always by automated scans finding a known vulnerability in an unpatched plugin or a weak admin password. Not by someone targeting the business. The defence is routine, not expertise.

Does SSL make my website secure?

It secures the connection, not the site. An unpatched site is as hackable with a padlock as without. HTTPS is necessary and free; updates, passwords, backups, hosting, pruning and monitoring are the security.

Is WordPress secure?

A maintained WordPress on a managed host is as secure as anything else. Its reputation comes from being the most-used platform and from unmaintained installs on cheap hosting. Most compromises come through plugins, so keep few and keep them updated.

What should I do if my website is hacked?

Take it offline, change every password and turn on two-factor, restore a clean backup or have it cleaned, update everything and find the entry point, request a Search Console review if Google flagged it, and consider your UK GDPR notification duties if personal data was exposed.

How often should I back up my website?

Daily, stored somewhere other than the site’s own server, with a test restore every quarter so you know it works before you need it. Managed hosts and care plans do this automatically; check yours does.

Want the six checked on your site?

Send the address. I will tell you the platform and plugin versions it is running, whether it is on a blacklist, whether backups exist, and which of the six doors is open.