5 Minute Guide to Website Security

Most small business owners never think about website security until something goes wrong. Then it is a very bad week. Your site goes offline, Google slaps a red warning screen in front of it, customers ring up asking why your homepage is advertising dodgy pharmaceuticals, and your enquiries dry up overnight.


The good news is that you do not need to be technical to spot the big risks. Grab a coffee, open your website in a browser, and answer these five questions. It takes about five minutes, one minute per question.


Minute 1: Is there a padlock next to your web address?


Look at the top of your browser, just to the left of your domain name. You should see a small padlock icon. Click on it and it should tell you the connection is secure.


Why it matters: that padlock means you have an SSL certificate, which encrypts anything visitors type into your site. Without it, browsers show a "Not secure" warning right next to your business name, and anything typed into your contact form travels in plain text.


If the answer is no: you need an SSL certificate installed. Most decent hosting includes one free these days, so this is usually a quick fix rather than an expensive one.


Bonus check: type your address with `http://` at the front instead of `https://`. It should automatically redirect you to the secure version. If it loads the insecure version and stays there, the redirect has not been set up properly.


Minute 2: When did you last update your website software?


If you are on WordPress, log in and look at the top left of your dashboard. Any little red circles with numbers in them are pending updates. Check three things: WordPress itself, your theme, and your plugins.


Why it matters: this is the single most common way small business sites get hacked. Outdated plugins are the front door. When a security hole gets discovered, it is published publicly so that developers can patch it, which means the bad guys get the list too. Automated bots then crawl the web looking for sites still running the old version. It is nothing personal, and it does not matter how small your business is.


If you are behind: back up first, then update. Start with plugins, then the theme, then the core software. Check the site still works afterwards.


While you are in there: delete any plugins or themes you are not using. An inactive plugin can still be a security risk, and every one you remove is one less thing to keep patched.


Minute 3: Who can log in to your website?


In WordPress, go to Users. Look at the full list. Can you name every single person there and explain why they need access?


Why it matters: old staff, a web designer you stopped working with in 2021, a marketing agency you trialled for a month. Every account that still exists is a way in. Unknown accounts you definitely did not create are a red flag that something has already happened.


Three quick wins:


1. Delete accounts belonging to people who no longer need access.

2. Give people the lowest role that lets them do their job. Not everyone needs to be an Administrator. Someone who writes blog posts only needs Editor or Author.

3. Turn on two factor authentication so a stolen password is not enough on its own. There are free plugins that handle this in a few clicks.


And while we are here, if your admin password is your business name with an exclamation mark on the end, or the same password you use for everything else, change it today. Use a password manager so you do not have to remember it.


Minute 4: If your site disappeared right now, could you get it back?


Ask yourself three things. Do you have a backup? Where is it stored? When was the last one taken?


Why it matters: backups are what turn a disaster into an inconvenience. Hacked, broken by a bad update, accidentally deleted, hosting account closed. It all has the same fix if you have a recent copy of the site.


What good looks like: automatic backups running at least weekly, or daily if you run an online shop or publish often. Crucially, they should be stored somewhere other than your web server. A backup sitting on the same server as the site is not much use if the whole server is the problem.


The question almost nobody asks: has anyone ever tested restoring one? A backup you have never restored is a guess, not a safety net. Ask your host or developer to confirm it actually works.


Minute 5: Has Google already flagged your site?


Open Google and search for `site:yourdomain.com.au`, using your own domain. Have a look at what comes back.


What you are looking for: pages you do not recognise, gibberish titles, foreign language listings, or anything mentioning products you do not sell. Those are classic signs of a compromised site being used to host spam pages.


Also worth doing: set up Google Search Console if you have not already. It is free and it will email you if Google detects malware or spammy content on your site. Most business owners find out they have been hacked because a customer tells them. Search Console tells you first.


So how did you go?


Five yeses. You are in good shape. Put a reminder in your calendar to run through this again every three months.


Three or four. Pretty typical, and the gaps are usually easy to close. Sort them this week while it is fresh in your mind.


Two or fewer. Your site is exposed. Nothing has gone wrong yet, but you are relying on luck rather than anything you have actually put in place. Worth getting help sooner rather than later.


A last word on why this matters more than it used to.


Your website is often the first thing a potential customer sees. A browser warning telling them your site is not secure does more damage than most people realise, because it makes them question everything else about your business before they have even read a word.


Website security is not really about hackers. It is about making sure the thing you spent good money on keeps working, keeps bringing in enquiries, and keeps making you look like a business worth dealing with.


Not sure where you stand, or found something in this list you would rather not deal with yourself?


We look after websites, hosting and security for businesses across the Northern Rivers and Australia wide. Give us a call on 1300 288 407 or email support@owlweb.com.au and we will take a look for you.


Owl Web. More Than Just a Website.