Website Security Checklist for Business Owners
A plain-English website security checklist built around four pieces of evidence: an access register, maintenance record, restore test and incident contact.
A business website can load normally, show a padlock in the browser and still have serious security gaps. An old contractor account, a delayed software update or a backup that has never been restored can be enough to turn a manageable problem into lost orders, downtime or damaged customer trust.
A business owner does not need to understand every server setting. They do need clear answers to four questions: who has access, who maintains the software, whether the site can be recovered and who responds when something goes wrong.
This website security checklist turns those questions into four pieces of evidence that an owner can request from an internal team, developer, agency or hosting provider.
Quick answer: Ask for four proofs: a current access register, a maintenance record, the result of a backup restore test and a named incident contact. These provide more useful evidence than a padlock, a security plugin or a verbal assurance that the website is “covered”.
The Four Proofs Every Business Owner Should Request
Most small-business website security issues can be organised around four areas:
1. Access
Who can reach the website dashboard, hosting account, domain, backups and payment services?
2. Maintenance
Who updates the website software, when was it last checked and what was tested afterwards?
3. Recovery
How much data could be lost, and has a backup successfully restored the website?
4. Response
Who receives an alert, contains the problem and reports back to the business?
What this framework adds: each area ends with evidence the owner can verify. The review therefore produces more than a generic answer such as “security is handled”.
How Urgent Is the Security Review?
Act today
You find an unknown administrator, altered content, redirects to another website, malware warnings or orders and messages you do not recognise. Restrict access and preserve evidence for investigation before deleting files.
High priority
Updates are overdue, passwords are shared, former suppliers still have access, multi-factor authentication is disabled or backups exist only on the same hosting account.
Planned review
The website appears normal, but nobody can produce a recent access review, maintenance record, recovery test or alert test. Document these while there is no active incident.
Why HTTPS and the Browser Padlock Are Not Enough
HTTPS encrypts the connection between a visitor's browser and the website. It helps protect information while it travels between them and is essential for forms, customer logins and payments.
HTTPS does not tell you whether an administrator password has been stolen, a plugin contains a known vulnerability, the hosting environment is misconfigured or a backup is unusable. A compromised website can still have a valid SSL certificate and display a padlock.
What the padlock proves: the connection to that web address is encrypted. It is not a certificate for the overall security or trustworthiness of the website.
1. Access: Who Can Change the Website?
List every account that can affect the site: the content management system, hosting, domain registration, database, business email, backups and payment services. A content management system, or CMS, is the software used to edit pages, products and articles. WordPress is a common example.
Each person should have an individual account. This allows the business to remove one person's access when a contract ends and to identify who made a change. A shared “admin” login removes that accountability.
Enable multi-factor authentication, commonly called MFA or 2FA, on critical accounts. It requires a second form of verification in addition to the password, usually a temporary code from an authentication app.
Evidence to request: a dated list containing each user, their level of access, the last review date and whether MFA is enabled. The list must never contain their passwords.
2. Maintenance: Who Fixes Known Software Problems?
The CMS, plugins, design theme and third-party software components need updates when their publishers fix bugs or security weaknesses. Software that is no longer supported may need to be replaced rather than left installed indefinitely.
A safe update process is more than pressing “update all”. The responsible person takes a backup, applies the changes and then tests the functions the business depends on: key pages, contact forms, customer login, basket and payment where applicable.
Unused plugins and accounts should be removed. Deactivating a plugin is not always the same as removing its files, and forgotten software can remain an avoidable entry point.
Evidence to request: the date of the last maintenance session, what changed, who completed it and which business-critical functions were tested afterwards.
3. Recovery: Can the Website Actually Be Restored?
A useful backup is recent, includes both files and website data, has another copy outside the main hosting account and has been tested. A backup stored only beside the live website can be lost during the same hosting failure or account compromise.
The schedule should reflect how much data the business can afford to lose. An online shop receiving orders every hour needs more frequent backups than a brochure website that changes once a month.
Creating a backup and restoring one are different tasks. A restore test proves that the archive opens, contains the expected information and can return the website to operation within an acceptable period.
Evidence to request: the latest backup time, its second storage location, the last successful restore-test date and the estimated time required to bring the site back online.
4. Response: Who Will Notice and What Happens Next?
Monitoring only helps if an alert reaches someone who knows what to do. Useful alerts may cover downtime, unexpected changes to important files, repeated failed logins or malware detected by the host or another trusted service.
System logs are records of events, actions and errors. They help a technical specialist establish when a problem started and what may have been affected. Do not delete them in a rush when a compromise is suspected.
The response plan can be short, but it should name who restricts access, who preserves evidence, who restores service and who decides whether customers, insurers or relevant authorities need to be informed.
Evidence to request: a named contact with a telephone number, the events that trigger an alert, who receives it and the date of the last alert test.
Additional Checks Based on What the Website Does
Hosting
Hosting is the service that keeps the website on an internet-connected server. Ask who updates that server, how customer accounts are separated, which protections are included and what support is available during an incident.
Forms, Logins and File Uploads
Contact forms, customer accounts and upload fields accept information from visitors. They need controls on file type and size, limits on repeated attempts and protection against automated spam or abuse.
Online Shops and Payments
An ecommerce site also needs monitoring around orders, customer accounts, the payment-provider connection and unusual transaction patterns. A burst of small failed payments can be card testing: automated attempts to discover whether stolen card details work. Our guide explains how to respond to WooCommerce spam orders and card testing without creating unnecessary friction for genuine customers.
A 15-Minute Website Security Check for the Owner
Ask the website manager to answer these questions and show the corresponding record. You do not need to change technical settings yourself.
- Access: Who currently has access, and who has full administrator privileges?
- Access: Is MFA enabled on the website, hosting, domain and business email accounts?
- Maintenance: When was the last maintenance session, and what was tested afterwards?
- Recovery: When was the latest backup, and when did a restore test last succeed?
- Response: Who receives security alerts, and what number is used outside normal hours?
- Critical functions: When were the form, login, basket or payment journey last tested?
“It is automatic” is not a complete answer without a date, responsible person or test result. If two or more records are missing, arrange a structured review.
What a Useful Website Security Audit Should Deliver
A security audit should reflect what the website actually does. It should not end with an automated score or a long report written only for developers. The deliverable should state:
- what was found and which business function it affects
- whether it needs immediate action or a planned correction
- who owns the fix: the business, developer, agency or hosting provider
- what change is recommended and whether that change introduces another risk
- how the completed fix will be verified
A free online scanner can find some issues visible from the public internet. It will not necessarily see internal user permissions, the database, private code, operational procedures or whether a backup can restore the site.
Are One or More of the Four Proofs Missing?
Start by requesting the access register, maintenance record, restore-test result and incident contact. Missing evidence shows whether the next step is an account change, routine maintenance, a recovery test or a wider technical review.
If you need a technical assessment for a WordPress site, ecommerce store or custom web application, contact CCDesign to define the functions and risks that should be reviewed first.
Conclusion
A business owner does not need to become a security engineer, but should be able to verify ownership and evidence. A current access register, maintenance record, successful restore test and named incident contact provide a practical starting point.
Once those foundations are documented, deeper technical testing can focus on the real functions, data and risks of the individual website.
Frequently Asked Questions
Is an SSL certificate enough to secure a website?
No. An SSL certificate enables the encrypted HTTPS connection. It does not review user accounts, updates, backups, custom code or hosting settings.
Does every WordPress website need a security plugin?
Not necessarily. A reputable plugin may support monitoring and block some malicious attempts, but it does not replace updates, MFA, appropriate permissions or tested backups.
How often should a business website be backed up?
Base the schedule on the amount of data the business can afford to lose. If losing one day of orders is unacceptable, a weekly backup is clearly insufficient. The backup schedule and restore testing should be planned together.
How can I tell whether a website has been compromised?
Warning signs include unknown users, altered content, redirects, malware warnings, unexpected files, unusual email activity or transactions you do not recognise. Preserve the available evidence and request an investigation before attempting a rushed clean-up.
What is the first security step for a small business website?
Request the four proofs described in this guide. The missing records will show whether the immediate priority is access, maintenance, recovery or incident response.
Sources
- CISA - cybersecurity resources for small and medium-sized businesses
- US Federal Trade Commission - cybersecurity guidance for small businesses
- OWASP Top 10 - major security risks for web applications
- WordPress.org - official WordPress hardening guidance
- Google Chrome - what browser connection-security indicators mean