Chapter 7 of 9

Security & Maintenance Basics

A website is not a one-time build — it needs ongoing upkeep, or it becomes a liability. This chapter covers the non-negotiable security and maintenance basics.

SSL/HTTPS — the non-negotiable baseline

HTTPS, shown as a padlock in the browser address bar, encrypts the connection between a visitor's browser and the server, so information passed between them cannot be read or altered in transit. It is no longer optional for any modern site: browsers actively flag plain HTTP sites as "not secure," which is a poor first impression before a visitor has even seen the homepage, and it is required outright for anything handling passwords or payment details.

Most hosting providers and platforms now issue and renew SSL certificates automatically at no extra cost, so there is rarely a good reason to run a business site without it. After enabling it, confirm that every version of the address — with and without www, HTTP and HTTPS — correctly redirects to a single secure, canonical version, rather than leaving multiple accessible copies of the same page.

Backups: the insurance policy you hope never to use

A backup is the difference between a bad afternoon and a genuine disaster. Hosting failures, a bad plugin update, a hacked site, or simple human error can all destroy days or months of content and configuration in seconds — and the only real protection is a working, current, tested backup that lives somewhere other than the same server as the site itself.

  • Automate backups rather than relying on remembering to do them manually.
  • Store copies off-server — a backup sitting on the same compromised host is not a real backup.
  • Back up both files and the database — a CMS site needs both to be restorable.
  • Actually test a restore occasionally; a backup that has never been restored is unproven.
  • Keep more than one recent backup, not just the latest — some problems are not noticed immediately.

Keeping the CMS and plugins updated

Software updates exist largely to patch known security holes, and attackers actively scan the web for sites still running outdated, vulnerable versions. On WordPress and similar platforms, this means the core software, the theme, and every installed plugin — an outdated plugin is one of the most common ways a site gets compromised, even when the core software itself is current.

A practical rhythm: review and apply updates on a regular schedule rather than waiting for something to break, and back up before applying major updates in case one causes a conflict. Removing plugins and themes that are no longer actively used — even if deactivated — closes off code that could otherwise be exploited while sitting unmaintained.

Common vulnerabilities worth knowing about

Most successful attacks on small business sites do not involve anything exotic — they exploit a handful of well-known weak points, repeated across the web. Weak or reused admin passwords remain one of the most common entry points, particularly when combined with a predictable username like "admin." Outdated plugins with known, publicly documented vulnerabilities are another. Lack of a firewall or basic bot-blocking leaves login pages exposed to automated guessing attempts around the clock.

None of these require deep technical expertise to defend against — they require consistency. Strong, unique passwords managed with a password manager, two-factor authentication on admin accounts wherever the platform supports it, and limiting the number of people with administrator access all meaningfully reduce risk without any specialised security knowledge.

Basic malware-prevention hygiene

Beyond updates and passwords, a small set of ongoing habits accounts for most practical protection. A security plugin or hosting-level scanner that checks for known malware signatures catches many issues before they spread. Limiting login attempts blocks the brute-force guessing that automated bots run constantly against any public login page. Reviewing user accounts periodically catches stale or unnecessary admin access — a former employee's still-active login is a real, common risk that is easy to overlook.

🔒

If a site has not had its core software, theme and plugins updated in the last few months, that is the single highest-priority maintenance task to do before anything else — before a redesign, before new content, before anything cosmetic.