# Small-Business Website Security and Risk Reduction

<!-- Generated by scripts/generate-public-markdown.ts. Do not edit directly. -->

> Protect website accounts and customer information, understand provider responsibilities, and prepare a practical response to suspicious activity.

Canonical: https://vassalmarketing.com/information/website-stewardship/small-business-website-security/

**Maintained by Vassal Marketing** · Last updated on September 26, 2026

Reviewed at least quarterly and whenever a platform or rule it cites changes.

General information, not legal or professional advice. Check rules that affect your business with a qualified professional.

Website security starts with knowing who can change your site, which software it depends on, and where customer information goes. Protect those connections, give alerts an owner, and agree what your team will do if something looks wrong.

## Why this matters

A site with no customer login still depends on domain, hosting, deployment, and administrator accounts. It may also connect to forms, analytics, maps, and booking services. HTTPS protects the connection to the website, but it does not prevent someone with a stolen administrator login from changing the site.

The right controls depend on what your site does. A basic informational site and a system accepting customer files have different exposure. Your provider should explain the important risks in plain language, reduce unnecessary features, and make sure there is someone to contact when a warning needs investigation.

## Responsible practices

### Reduce what you have to protect

Remove unused plugins, abandoned test sites, obsolete integrations, and former staff accounts. This reduces the attack surface: the places someone could try to gain access or misuse the system. Ask the provider to check that backups, private files, and administrative tools are not accidentally public.

### Limit powerful accounts

Use individual logins and multifactor authentication, especially for the registrar, email, hosting, and website administration. Least privilege means giving each person only the permissions their work needs. Prefer phishing-resistant sign-in methods where supported, and keep a recovery route that the business controls. At the registrar, turn on registrar lock and automatic renewal so the domain cannot be moved or lapse without notice.

### Agree on a security baseline

The security baseline is the set of protections your provider expects to remain in place: supported software, appropriate permissions, HTTPS, protected secrets, backups, and suitable monitoring. Have the provider recheck it after changes. Tools that publish the site need protection too; a locked-down website can still be altered through a poorly protected deployment account.

### Follow customer information to where it ends up

Ask what a form collects, where the information is stored, who can read it, and when it is removed. Collect only what the request needs. Your technical provider should validate incoming data and limit abuse without making the form unusable. Sensitive submissions should not spill into analytics, public URLs, or unnecessary logs.

### Give warnings an owner and a response plan

Choose alerts someone can act on, such as unexpected administrator changes, failed delivery, and relevant software advisories. Keep an incident runbook: a short set of contacts, authority, and response steps for a suspected problem. It should address evidence preservation, containment, recovery, and any customer-data questions that need qualified help.

## Worked example: If you receive an unexpected administrator alert

Illustrative response exercise. The right action depends on the service and the suspected incident; use your agreed incident plan and the provider's verified support channels.

### Verify the warning

Open the service through its known login address rather than a link in an unexpected message. Contact your named responder through a trusted channel.

### Record what you noticed

Note the time, account, warning, and visible changes. Preserve relevant messages and screenshots; avoid deleting records that may help the investigation.

### Contain with the responder

An authorized responder assesses sessions, accounts, keys, and affected systems, then revokes or rotates access as needed. Use a trusted device and communication channel.

### Recover and check

Before reopening affected functions, verify the recovery point, remove the cause where understood, and retest the site. Escalate possible customer-data exposure for qualified assessment.

The useful preparation is knowing whom to call and who can authorize action. An owner should not have to improvise technical incident response.

## Security baseline checklist

### What you can check

1. Confirm who can change the domain, website, and hosting account.
2. Enable suitable multifactor authentication and review former staff or provider access.
3. Turn on registrar lock and automatic renewal for your domain.
4. Ask whether SPF, DKIM, and DMARC email records protect your domain from impersonation.
5. Identify an emergency contact route that does not depend entirely on the website or its email.
6. Ask the provider to explain the response plan for an unexpected login or altered page.

### What to ask your provider to handle

1. Review exposed services, permissions, software support, secret handling, and the production security baseline.
2. Test forms, monitoring, and recovery arrangements using safe sample data.
3. Investigate incidents, preserve useful evidence, and coordinate containment and clean recovery with the business.

## Avoid these failures

- Leaving old accounts, unused integrations, or public backup files exposed.
- Putting production secrets in public code, browser scripts, or ordinary shared documents.
- Sending alerts to an unattended inbox.
- Erasing evidence or restoring an unverified copy during a suspected compromise.

Good website care lowers risk, but no provider can guarantee uninterrupted service.

## Questions business owners ask

### Does HTTPS mean the whole site is secure?

HTTPS protects the connection to the configured website. Administrator accounts, application code, stored data, forms, and outside services still need their own protections.

### Does a static website need security care?

Yes. Its domain, hosting, repository, deployment, forms, and other service accounts still matter. The scope can be simpler than for a custom application, but those connections need appropriate access and recovery controls.

### Who should receive security alerts?

A named person who can assess them or reach the responsible technical provider. Agree a backup contact, expected response process, and how alerts are handled outside normal support availability.

### Can a provider guarantee the site will never be hacked?

No website can be made perfectly secure. Ask which controls the provider operates, what it monitors, how incidents are handled, and what recovery help is included.

## Primary guidance

- [CISA: Secure Your Business](https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business)
- [NIST SP 1300: Cybersecurity Framework 2.0 Small Business Quick-Start Guide](https://csrc.nist.gov/pubs/sp/1300/final)
- [OWASP Top 10:2025 — Security Misconfiguration](https://owasp.org/Top10/2025/A02_2025-Security_Misconfiguration/)
- [OWASP Application Security Verification Standard](https://owasp.org/www-project-application-security-verification-standard/)
- [ICANN: EPP status codes, including registrar transfer lock](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en)

## Connected guidance

- [Domain, hosting, and account ownership](https://vassalmarketing.com/information/website-stewardship/domain-hosting-account-ownership.md): Find the accounts behind your site and confirm who can access or recover them.
- [Ongoing website maintenance](https://vassalmarketing.com/information/website-stewardship/ongoing-website-maintenance.md): Agree on routine care, urgent response, and a report you can understand.
- [Website backups and restoration](https://vassalmarketing.com/information/website-stewardship/website-backups-and-restoration.md): Check what your backups include and practice restoring a working site.
- [Business email authentication](https://vassalmarketing.com/information/website-stewardship/business-email-authentication.md): Set up SPF, DKIM, and DMARC so email from your domain is trusted and harder to fake.
- [Review privacy and customer data](https://vassalmarketing.com/information/reviews-reputation/review-privacy-and-customer-data.md): Handle customer details carefully when requesting and responding to reviews.
