Skip to content
Cybersecurity · · 4 min read

Securing your company website: the maintenance nobody gets round to

Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.

By Limburg Cyber Group

The website was built years ago by a freelancer. It still works, so nobody looks at it. But a website is software, and software that is not kept up to date sooner or later becomes a way in. Attackers automatically search the internet for websites with known vulnerabilities; how small your business is makes no difference. A hacked site can redirect visitors to fraudsters, send spam or leak data from your contact form. The good news: most of the maintenance is straightforward.

Updates for the core, plugins and themes

Many business websites run on WordPress or a similar system. It consists of three layers that each receive updates: the core of the system, the plugins (add-ons such as a contact form) and the theme (the design). Vulnerabilities are often found in plugins.

  • Switch on automatic updates wherever you can.
  • Check every month that everything is up to date, including the software versions on the server itself. Your hosting provider can help with this.
  • If a plugin has not had an update from its maker for a long time, look for an alternative.

Why timely updating matters so much is covered in our article on updates and patch management.

Clear out what you do not use

Deactivated plugins and old themes are still on the server. Even when switched off, vulnerabilities in them can sometimes be exploited, and they tend to be forgotten when updating. Delete what you do not use rather than just deactivating it. The same goes for old test versions of the site.

Admin accounts

  • Give everyone their own account, not a shared admin account.
  • Give admin rights only to people who genuinely need them; someone who edits text does not need to install plugins.
  • Remove accounts belonging to people who are no longer involved, including the original builder if they no longer work for you.
  • Switch on two-factor authentication. For WordPress you can do this with a plugin or through your hosting provider.

Backups you have actually restored

Many hosting providers make backups, but ask how often, how long they are kept and whether they are stored separately from the server itself. A second backup in another location is sensible. And most importantly: restore a backup at least once, for example to a test environment. Only then do you know it works and how long it takes. More on this in our backup strategy.

HTTPS

The padlock in the address bar means the traffic between visitor and website is encrypted. That is now the standard, and browsers warn visitors about sites without it. Many hosting providers arrange the certificate and renew it automatically. Do check that renewal really is automatic, and that the address without the padlock redirects to the secure version. Bear in mind: HTTPS protects the traffic, not the website itself. An outdated site with a padlock is still vulnerable.

Who holds the keys?

This is often the biggest problem. Is the domain name registered to your business, or to the builder? Who can log in to the hosting, and to the company where your domain is registered? Make sure that:

  1. the domain name is registered to your business;
  2. you also have the login details for the domain, hosting and website, stored safely in a password manager;
  3. those accounts are protected with two-factor authentication;
  4. there are clear agreements about who does the updates.

When the builder can no longer be reached

First, list what you do have: invoices for hosting and the domain name, old emails with login details. If you can show that the domain and hosting belong to your business, you can often regain access through those providers. Then have someone knowledgeable look at the state of the site. Sometimes updating it is perfectly doable; sometimes a new, simpler site is less work in the long run than continuing to patch up an old one.

Get your website checked for free

Want to know whether your website runs on outdated software? Our free outdated software check gives you a plain-language report of what is visibly outdated from the outside. Would you like help clearing things up and keeping them current afterwards? See our cybersecurity service or get in touch.

Read more

Cybersecurity ·

When an employee leaves: what to arrange digitally

When someone leaves, their accounts, passwords and sharing links often keep working longer than you think. A practical checklist to close them off properly.

Read more 3 min read

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.