What website security for small business actually is
Website security is not one product. It is a group of separate services sold
together: scanning that looks for malicious code,
removal that cleans it out, a firewall that filters
traffic before it reaches your site, backups you can restore from,
and monitoring that tells you when something has changed.
They overlap far less than the packaging suggests. A scanner will not stop a
break-in. A firewall will not fix one. A backup will not tell you anything is wrong.
Knowing which gap each covers is the whole point of this page.
Worth separating out too: an SSL certificate protects the
connection between a visitor's browser and your site and removes the "not secure"
label. It says nothing about whether the site is clean, and a site can be perfectly
encrypted and thoroughly compromised at once. The files themselves sit on your
web hosting, which is what an attacker is reaching for.
How small business sites actually get compromised
The mental picture most owners have is a person deciding to attack their company.
That is rarely it. What happens is a program working through millions of addresses
looking for one known weakness, finding it on your site, and taking it with no human
involved until much later. The way in is nearly always one of these:
- An out-of-date plugin, theme or CMS. When a vulnerability is
published, automated scanning for it starts within days. Sites that update in that
window are fine. Sites nobody has touched in two years are not.
- A reused password. An unrelated service is breached, the password
list gets traded, and software tries the same combination on your admin login, your
hosting control panel and your FTP account.
- An admin account nobody removed. The designer from four years
ago, the intern, the plugin that quietly created a user. Every one is a working
key, and so are FTP details saved on a laptop that later picks up malware.
What they want is rarely your customer list. It is your server and your reputation:
somewhere to send spam from, a hidden page imitating a bank, injected links, or a
redirect that only fires for phone visitors. That is why so many owners have no idea.
The homepage looks normal on their own screen.
What a compromise costs in practice
The damage is rarely the hacking itself. It is what happens around it over the
following few days.
- Search engines flag the site. A hacked-site label in the results,
or removal from them, plus a review process to get back. Traffic stops before you
know why.
- Browsers put a warning in front of it. A full-screen red page
telling visitors your site is dangerous. Very few click past it, and the ones who
do remember.
- The host suspends the account. Hosts shut down accounts that send
spam or serve malware, because the alternative is the whole server being
blacklisted. If your email runs on that account, the email goes too.
- Mail deliverability suffers. Once a server has sent spam,
ordinary messages from the domain start landing in junk folders.
If your website is a lead source, those are days of enquiries you do not get back.