On this page
- The three things to fix first
- HTTPS: why it's non-negotiable now
- Multi-factor authentication on every account that matters
- Backups you have actually tested
- What to do in the following weeks
- Email authentication: the quiet fix that protects your name
- Choosing a host that helps instead of hurts
- What the law actually requires
- A monthly review that catches most problems
Almost nobody attacking a small business website is targeting that business specifically. Most attacks are automated scans crawling the internet for known weaknesses: unpatched software, default passwords, missing encryption, accounts with no second layer of protection. Fixing the basics does not make you unhackable, but it does take you out of the pool of easy targets the scanners actually find.
The three things to fix first
- HTTPS active across the entire site, not just a checkout page.
- Multi-factor authentication on your host, domain registrar, CMS admin and email.
- A backup of your files and database that you have actually restored somewhere, not just scheduled.
CISA's small business cybersecurity guidance puts multi-factor authentication and current software updates at the top of its four core essentials for businesses without dedicated IT staff, alongside phishing awareness and strong passwords. The FTC's cybersecurity basics guidance says the same thing in different words: back up files regularly, require multi-factor authentication on any account with access to sensitive information, and keep software patched with automatic updates turned on. Neither agency treats these as advanced measures — they're the floor.
HTTPS: why it's non-negotiable now
HTTPS encrypts what travels between a visitor's browser and your server. Without it, anyone on the same network as your visitor can potentially see form submissions, login details and payment information in plain text. Most reputable hosts issue a free certificate automatically today; if yours doesn't offer that, treat it as a sign to look at other hosts, not a reason to skip encryption. Confirm every page redirects to HTTPS, not just your homepage or checkout — mixed HTTP/HTTPS content is a common gap that automated scanners look for specifically.
Multi-factor authentication on every account that matters
A stolen or guessed password is the single most common way small business accounts get taken over. Multi-factor authentication (MFA) adds a second check — a code from an app or a physical key — so a leaked password alone isn't enough to get in. Turn it on for your web host, domain registrar, CMS admin login, and business email, in that order of priority, since losing control of any one of those can cascade into losing the others.
Backups you have actually tested
A backup nobody has restored is a guess, not a safety net. Set a schedule that matches how often your site changes — a low-traffic brochure site can reasonably back up weekly, while an e-commerce site taking orders daily needs a tighter interval. Then, at least once, actually restore that backup to a separate environment and confirm the site comes back intact. This is also the point where CISA's broader guidance is worth taking seriously: ransomware recovery plans fail most often not because backups don't exist, but because nobody checked they could be restored before the day they were needed.
What to do in the following weeks
- 01Update your CMS core, plugins and themes to current versions, and turn on automatic updates for minor releases.
- 02Run a malware scan using your host's built-in tool or a reputable third-party scanner.
- 03Review every account with access to your site and remove anyone who no longer needs it.
- 04Turn on a web application firewall if your host offers one.
- 05Set up basic monitoring: uptime alerts and login notifications, so you find out about a problem the same day it happens.
Email authentication: the quiet fix that protects your name
SPF, DKIM and DMARC are DNS records that tell receiving mail servers whether an email claiming to be from your domain is legitimate. Without them, it's easier for someone to spoof your domain in a phishing email sent to your customers or vendors — a scam that damages your reputation even though your systems were never actually breached. The FTC's guidance lists email authentication as a standard part of a small business security setup, not an advanced option. Most domain registrars and email providers walk you through adding these records; it typically takes under an hour once you know where to look.
Choosing a host that helps instead of hurts
Hosting cost differences often reflect real differences in security posture, not just support quality. Before choosing or renewing a host, ask directly: is a TLS certificate included free and renewed automatically, are security patches applied automatically or is that on you, is a web application firewall available, and how frequently are backups taken and how do you restore one. A host that can't answer these clearly is a bigger risk than the extra few dollars a month a better one costs.
What the law actually requires
There is no single federal law that mandates specific website security controls for every small business. What exists instead is a patchwork: state data breach notification laws that trigger once certain personal information is exposed, sector rules like the FTC Safeguards Rule for certain financial-adjacent businesses, and general FTC enforcement authority against companies that make security claims they don't back up. None of this is a substitute for legal advice — if you handle payment data, health information or a regulated category of personal data, a lawyer or compliance professional should tell you which specific rules apply to your business, not a blog post.
A monthly review that catches most problems
- Confirm HTTPS is still active and the certificate hasn't lapsed.
- Check the list of user accounts with access and remove anyone who's left or no longer needs it.
- Confirm the last backup ran and spot-check that it's restorable.
- Review login notification and uptime alerts for anything unusual in the past month.
- Confirm plugins, themes and CMS core are on current versions.
None of this requires a security specialist on staff. It requires doing the boring things on a schedule instead of when something already went wrong — which, for the overwhelming majority of small business websites, is the entire difference between being an easy target and not being one.
Source: CISA
Source: Federal Trade Commission
Source: Federal Trade Commission
Source: Federal Trade Commission
Hosting, maintenance and security updates are part of the monthly membership cycle, so these basics get handled instead of postponed.
See how the membership works