Most small business sites aren't hacked by a genius targeting them personally. They're hit by bots scanning millions of sites for one old plugin, one reused password or one exposed admin panel. The good news: the defences against that are boring, cheap and mostly one-time work.
I use this checklist for every client site I build or take over. Work through it top to bottom.
Domain and hosting
- Lock your domain. Turn on registrar lock and two-factor authentication at your domain registrar. Losing the domain means losing email and website at once.
- Know who has access. List every person and agency with hosting, domain, DNS and CMS logins. Remove anyone who no longer needs it — ex-freelancers are a classic hole.
- Use managed hosting or a platform like Vercel or Netlify where the OS is patched for you, unless you have someone who genuinely maintains servers.
- Serve everything over HTTPS with an automatic certificate (Let's Encrypt, or your host's built-in one). Redirect all HTTP traffic to HTTPS.
- Turn on HSTS once HTTPS works everywhere, so browsers never try plain HTTP again.
- Update the CMS, themes and plugins weekly, or enable automatic updates for minor versions. On WordPress, out-of-date plugins are the number-one way sites get compromised.
- Delete what you don't use. Deactivated plugins and old themes are still attack surface.
- Update dependencies in custom code (
npm audit, Dependabot or Renovate).
- Unique passwords from a password manager for every account. See my guide to password managers, passkeys and 2FA.
- Two-factor authentication on the CMS, hosting, domain, email and payment accounts — authenticator app or passkey, not SMS where you can avoid it.
- Limit login attempts and hide or protect the admin URL (e.g. a login rate limiter plugin, or allow-listing office IPs).
- Least privilege: content writers get Editor, not Administrator.
- Automatic daily backups, stored somewhere else than your host — a different provider or cloud bucket.
- Test a restore at least twice a year. A backup you've never restored is a hope, not a backup.
- Keep 30 days of history, so you can go back to before an infection you didn't notice immediately.
- Protect forms from spam and abuse with a honeypot field, rate limiting or Cloudflare Turnstile.
- Set up SPF, DKIM and DMARC on your domain so scammers can't easily send email pretending to be you. Start DMARC at
p=none to monitor, then tighten to quarantine. - Collect only the data you need, and know where it's stored. India's Digital Personal Data Protection Act applies to personal data you collect, so treat customer data as a liability as well as an asset.
- Add basic security headers. Even a static site benefits:
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
X-Frame-Options: DENY
Permissions-Policy: camera=(), microphone=(), geolocation=()
Add a Content-Security-Policy when you can — it's the strongest defence against injected scripts. Check your site at securityheaders.com.
- Know when something's wrong: an uptime monitor, Google Search Console (it warns about hacked content and malware), and alerts for new admin users or file changes if your platform supports it.
- Don't panic, and don't just delete random files.
- Take the site offline or into maintenance mode.
- Change every password: hosting, CMS, database, FTP/SFTP, email.
- Restore from a clean backup from before the compromise, then update everything.
- Find how they got in (usually an old plugin or a leaked password), otherwise it will happen again.
- Request a review in Google Search Console if the site was flagged.
Twenty items sounds like a lot, but most are one-time switches. An afternoon of work closes the doors the bots are knocking on — and you can check your uptime any time on a status page.