Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
By Limburg Cyber Group
The website was built years ago by a freelancer. It still works, so nobody looks at it. But a website is software, and software that is not kept up to date sooner or later becomes a way in. Attackers automatically search the internet for websites with known vulnerabilities; how small your business is makes no difference. A hacked site can redirect visitors to fraudsters, send spam or leak data from your contact form. The good news: most of the maintenance is straightforward.
Updates for the core, plugins and themes
Many business websites run on WordPress or a similar system. It consists of three layers that each receive updates: the core of the system, the plugins (add-ons such as a contact form) and the theme (the design). Vulnerabilities are often found in plugins.
- Switch on automatic updates wherever you can.
- Check every month that everything is up to date, including the software versions on the server itself. Your hosting provider can help with this.
- If a plugin has not had an update from its maker for a long time, look for an alternative.
Why timely updating matters so much is covered in our article on updates and patch management.
Clear out what you do not use
Deactivated plugins and old themes are still on the server. Even when switched off, vulnerabilities in them can sometimes be exploited, and they tend to be forgotten when updating. Delete what you do not use rather than just deactivating it. The same goes for old test versions of the site.
Admin accounts
- Give everyone their own account, not a shared admin account.
- Give admin rights only to people who genuinely need them; someone who edits text does not need to install plugins.
- Remove accounts belonging to people who are no longer involved, including the original builder if they no longer work for you.
- Switch on two-factor authentication. For WordPress you can do this with a plugin or through your hosting provider.
Backups you have actually restored
Many hosting providers make backups, but ask how often, how long they are kept and whether they are stored separately from the server itself. A second backup in another location is sensible. And most importantly: restore a backup at least once, for example to a test environment. Only then do you know it works and how long it takes. More on this in our backup strategy.
HTTPS
The padlock in the address bar means the traffic between visitor and website is encrypted. That is now the standard, and browsers warn visitors about sites without it. Many hosting providers arrange the certificate and renew it automatically. Do check that renewal really is automatic, and that the address without the padlock redirects to the secure version. Bear in mind: HTTPS protects the traffic, not the website itself. An outdated site with a padlock is still vulnerable.
Who holds the keys?
This is often the biggest problem. Is the domain name registered to your business, or to the builder? Who can log in to the hosting, and to the company where your domain is registered? Make sure that:
- the domain name is registered to your business;
- you also have the login details for the domain, hosting and website, stored safely in a password manager;
- those accounts are protected with two-factor authentication;
- there are clear agreements about who does the updates.
When the builder can no longer be reached
First, list what you do have: invoices for hosting and the domain name, old emails with login details. If you can show that the domain and hosting belong to your business, you can often regain access through those providers. Then have someone knowledgeable look at the state of the site. Sometimes updating it is perfectly doable; sometimes a new, simpler site is less work in the long run than continuing to patch up an old one.
Get your website checked for free
Want to know whether your website runs on outdated software? Our free outdated software check gives you a plain-language report of what is visibly outdated from the outside. Would you like help clearing things up and keeping them current afterwards? See our cybersecurity service or get in touch.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.
When an employee leaves: what to arrange digitally
When someone leaves, their accounts, passwords and sharing links often keep working longer than you think. A practical checklist to close them off properly.