Small businesses often depend on websites for leads, sales, payments and customer communication. Basic security controls can reduce many common risks without requiring a large security team.
1. Use HTTPS everywhere
Install a trusted certificate, redirect HTTP to HTTPS and monitor certificate renewal.
2. Keep software updated
Apply updates to the operating system, web server, runtime, framework, CMS, themes, plugins and third-party packages.
3. Protect administrator accounts
- Use unique passwords.
- Enable multi-factor authentication.
- Remove unused accounts.
- Limit administrative access.
4. Maintain tested backups
Store backups outside the public website directory. Test restoration regularly and protect backup storage with separate credentials.
5. Configure email authentication
Publish valid SPF and DMARC records, enable DKIM through sending services and review DMARC reports before increasing enforcement.
6. Add browser protections
Review CSP, HSTS, clickjacking protection, nosniff, Referrer-Policy and Permissions-Policy.
7. Remove unnecessary disclosure
Disable development debugging, public logs, directory indexing and unnecessary product-version headers.
8. Monitor website changes
Review uptime, certificate expiry, DNS changes, administrator logins, file changes and application errors.
9. Run regular external scans
External scans help identify public configuration drift. Run a new assessment after major deployments, DNS changes or server migrations.
10. Prepare an incident plan
Document who should respond, how access can be revoked, where backups are stored and how affected customers will be informed.