Most small-business website problems aren't sophisticated attacks. They're an outdated plugin, a reused password, a domain that lapsed, or an SSL certificate nobody renewed. This checklist covers the things that prevent most of them. You don't need to be technical to work through it; for a few items you'll ask your web developer or host.

Access and accounts

  1. Turn on two-factor authentication everywhere it matters: your domain registrar, hosting, website admin (WordPress or similar), email, and DNS provider (such as Cloudflare). Whoever controls these controls your business online.
  2. Use unique passwords from a password manager. Reused passwords leaked from other sites are still the most common way in.
  3. Remove old accounts. Former staff, past agencies and freelancers often still have admin access. Keep a short list of who has access to what.

Software and updates

  1. Keep your CMS, themes and plugins updated, and turn on automatic updates for security releases where you can. Most hacked WordPress sites are hacked through an outdated plugin.
  2. Delete plugins and themes you don't use. Deactivated isn't enough; old code on the server can still be attacked.
  3. Use supported software. An old PHP version or a CMS that no longer gets security updates is a risk even if nothing looks wrong.

HTTPS and browser protection

  1. Serve every page over HTTPS and redirect http:// to https://. Make sure your SSL certificate renews, and check that it actually did: here's what happens when it doesn't.
  2. Add basic security headers. HSTS (always use HTTPS), clickjacking protection (X-Frame-Options or a frame-ancestors policy) and a content security policy make common attacks harder. Your host or developer can add these in an hour.

Domain and email

  1. Set your domain to auto-renew with a payment method that won't expire, and turn on the registrar lock. A lapsed domain takes your website and email down at once, and expired domains get bought up quickly.
  2. Protect your email with SPF, DKIM and DMARC. Without them, anyone can send email that appears to come from your business, which is how many invoice scams start. Check your domain for free, then follow our guides for Google Workspace or Microsoft 365.

Recovery and monitoring

  1. Keep backups you can actually restore. Automatic daily backups, stored somewhere other than your web server, and a test restore every few months. A backup you've never restored is a hope, not a plan.
  2. Monitor your site, so you hear about problems before customers do. Downtime, an expiring certificate, a missing security header or an email record that disappeared are all easy to fix early and costly to discover late.

Do it once, then let it run

Most of this list is a one-off setup. The part that needs ongoing attention is noticing when something changes: a plugin update that breaks the site, a renewal that fails, a DNS change that removes your email records.

Daily Website Report checks your website every day for SSL, security settings, email authentication, SEO and uptime, and tells you in plain English what's wrong and exactly how to fix it. It's free for one website, and setup takes about a minute.