Web Security

Website security basics every small business site needs

Five habits from the FTC, CISA, and WordPress cover the basics, and MFA alone can block over 99.9 percent of account attacks.

On this page
  1. The five habits that carry most of the weight
  2. What federal guidance asks small businesses to do
  3. What WordPress recommends for your site
  4. The security checklist for your website
  5. What to do this week, in order

Website security for a small business comes down to five habits: turn on automatic updates, back up your files, require multi-factor login, keep admin accounts few, and delete plugins you don't use. These steps cover the basics that federal guidance and WordPress ask for.

The five habits that carry most of the weight

You don't need an IT department to protect a small business website. A short set of habits covers the basics. The advice below comes straight from federal guidance and from WordPress itself, so it fits a WordPress or similar site well.

Each habit closes a common gap. Updates patch known holes. Backups give you a way back after a bad day. Multi-factor login guards the front door. Fewer admins and fewer plugins shrink the surface an attacker can reach.

What federal guidance asks small businesses to do

Government agencies publish plain advice for owners without a security team. The FTC tells small businesses to turn on automatic updates, back up important files regularly to the cloud or an external hard drive, require multi-factor authentication, and restrict sensitive information to only those who need it to do their jobs.

Login protection earns its own spotlight. CISA says multifactor authentication adds an extra layer of protection by requiring two or more ways to verify a user's identity. That means a stolen password alone won't let someone in.

The payoff is large. The Microsoft Security Blog reported in August 2019 that MFA can block over 99.9 percent of account compromise attacks.

What WordPress recommends for your site

WordPress has built-in tools that make two of these habits easier. WordPress.org notes that WordPress has had automatic updates since version 3.7, and its hardening guide tells you to keep plugins updated and delete any plugin you aren't using.

Unused plugins are a quiet risk. Every plugin adds code that can carry flaws, so an old one you forgot about becomes an open window. Removing what you don't need keeps the site smaller and safer. Less code, less worry.

The security checklist for your website

Print this list or keep it open while you work. Each item pairs a habit with the reason behind it, drawn from the sources above.

  • Turn on automatic updates. The FTC tells small businesses to turn on automatic updates, and WordPress.org notes WordPress has offered them since version 3.7.
  • Back up your files regularly. The FTC says to back up important files regularly to the cloud or an external hard drive, so you can recover after trouble.
  • Require multi-factor login. CISA says MFA adds a layer by requiring two or more ways to verify identity, and the Microsoft Security Blog reported it can block over 99.9 percent of account compromise attacks.
  • Keep admin accounts few. The FTC says to restrict sensitive information to only those who need it to do their jobs, which means fewer people with full control.
  • Delete unused plugins. WordPress.org tells you to keep plugins updated and delete any plugin you aren't using.

What to do this week, in order

These steps put your effort where it protects the site fastest. Work top to bottom. Then check your results.

  1. Log in and confirm automatic updates are on for WordPress core, themes, and plugins.
  2. Set up a regular backup to the cloud or an external hard drive, and test that you can restore it.
  3. Turn on multi-factor authentication for every login that offers it, starting with your admin account.
  4. Review the list of admin accounts, and lower the access of anyone who doesn't need full control.
  5. Open your plugin list, update what you keep, and delete every plugin you aren't using.
  6. Write down the date you did this, and put a reminder on your calendar to repeat the review.

Security is ongoing care. Small habits, done often, keep your site steady while you focus on customers. Our team can set these up so they keep working in the background.

Want help securing and building your site? See our AI development service.

Share this post

AI Development

Websites and apps ready for production use

WordPress, Laravel, and custom development made for live use.

See AI Development