Cybersecurity
Website security basics every owner should know
Understand the practical security habits that protect a business website: updates, access control, backups, monitoring, and recovery planning.
Security is an ongoing set of habits. Know who owns updates, who has access, and how the website will be restored if something goes wrong.
HTTPS is the beginning, not the whole plan
An HTTPS connection encrypts data travelling between a visitor and your website. It is essential, but it does not prove the site is free of vulnerabilities or protect an account whose password has been stolen.
A useful security plan covers the website, hosting, domain registrar, email accounts, and connected services. Start by identifying who is responsible for each. A forgotten account or expired renewal can disrupt the business even when the visible website looks fine.
Protect access to important accounts
Use unique passwords stored in a reputable password manager, and enable multi-factor authentication wherever it is available. Give each team member their own account rather than sharing one administrator login.
People should have only the permissions they need. A person updating articles usually does not need full control over hosting or billing. Remove access promptly when a contractor finishes or an employee leaves, and keep ownership of your domain and key service accounts in your business's name.
Keep software maintained and reduce the surface area
For WordPress, keep core software, themes, and plugins maintained. For custom websites, the application and its dependencies also need updates. Review the effect of an update in a suitable testing environment and have a recovery option available.
Remove unused plugins, old accounts, and abandoned integrations. Install software only from trusted sources. Website developers should validate inputs and enforce permissions on the server; hiding an admin link does not prevent someone from trying to access it directly.
Make backups recoverable
A backup is only useful if it can be restored. Confirm what is backed up, how often copies are created, how long they are retained, and whether a separate copy remains available if the main account is compromised.
Schedule restoration tests rather than relying on a reassuring success message. A shop that processes orders all day may need a different backup frequency from a brochure website. Agree on how much recent data the business can afford to lose and how quickly it needs to recover.
- Confirm website files and relevant data are included.
- Keep access to backups restricted and recovery instructions available.
- Test a restore without overwriting the live website.
- Document who to contact if the website or an account is compromised.
Prepare for problems before they happen
Monitoring can help identify downtime, suspicious activity, or unexpected changes, but someone needs to receive and act on alerts. Keep support contacts and account-recovery methods current. Treat unexpected requests for passwords or urgent payment changes as possible phishing attempts.
If you suspect a compromise, contact the responsible developer or hosting provider, preserve useful evidence, and follow a recovery plan. Simply changing a visible page may leave the underlying problem in place. No provider can promise zero risk; the aim is to reduce exposure and recover responsibly.
Plan the right website for your business
Discuss your goals, your current website, and the next step with KIAVEX.