The Complete Website Security Checklist for Small Businesses
Use this checklist to see how safe your website really is. Each item is simple to check, and together they cover the gaps hackers use most often.
What should a website security checklist include?
A website security checklist should cover your domain and DNS, hosting and server, admin logins, software updates, HTTPS, forms and data, backups, a firewall and monitoring. Key checks are two-factor login, removing unused plugins and users, daily off-site backups with restore tests, updated software, and alerts for file changes, downtime and Google security warnings.
Key takeaways
- Secure the domain and hosting accounts first; they control everything else.
- Use two-factor login and remove unused admin users and plugins.
- Keep core software, themes and plugins updated every week.
- Store backups off the server and test a restore.
- Add a firewall, uptime alerts and file change monitoring.
- Run this checklist every quarter and after any big change.
How to use this website security checklist
Go through each part of this website security checklist and mark what is done, not done or not sure. Anything marked 'not sure' should be treated as not done until checked.
The list is written for business owners and managers, not only developers. You do not need to do every step yourself. Use it to ask your developer, agency or hosting company the right questions.
| Area | Why it matters | How often to check |
|---|---|---|
| Domain and DNS | Whoever controls these controls your site and email | Every 6 months |
| Hosting and server | Weak hosting puts every site on it at risk | Every quarter |
| Logins and users | Stolen logins are a top cause of hacks | Every quarter and when staff leave |
| Updates | Old plugins and software are the most common way in | Weekly |
| Backups | Your last line of defence | Daily backups, monthly restore test |
| Monitoring | You hear about problems before customers or Google | Always on |
Domain and DNS security checklist
Your domain is the base of your website and email. If someone takes over the domain account, they can move your site and read your mail.
- Domain is registered in the business name, not a former developer's account
- Registrar account uses a strong password and two-factor login
- Domain lock (transfer lock) is turned on
- Auto-renew is on and the payment card is valid
- Contact email on the domain is one you actively check
- DNS records reviewed; no unknown records or old subdomains pointing to unused services
- Email records (SPF, DKIM, DMARC) set up to reduce spoofing of your domain
Many small businesses find their domain was registered by a freelancer years ago. Moving it to your own account is one of the most useful security steps you can take.
Hosting and server security checklist
Your hosting should be updated, separated from other sites and protected by strong logins. Cheap shared hosting with many old sites on one account is a common source of reinfection.
- Hosting control panel uses two-factor login
- PHP or server software is a supported, current version
- Each website has its own account or is isolated from others
- Old test sites, staging copies and unused sites are removed
- SFTP or SSH used instead of plain FTP
- File permissions are correct; no folders writable by everyone
- Database is not open to the internet
- Server error messages are hidden from public visitors
If you use a VPS or cloud server, also check the firewall rules, open ports and automatic security updates. Our cloud security service covers this.
Login and user account checklist
Every person should have their own login, the lowest access they need and two-factor login. Remove old users quickly.
- Two-factor login on all admin accounts
- No shared 'admin' account used by several people
- Strong, unique passwords stored in a password manager
- Unused and former staff or agency accounts removed
- Editors and authors do not have admin rights
- Login attempts limited to slow down password guessing
- Admin login page protected by the firewall
Check the user list every quarter. Hackers often create an admin user with a normal-looking name so it stays hidden.
Software updates and plugins checklist
Keep the core software, themes and plugins updated, and remove anything you do not use. Old plugins are the most common way small business sites get hacked.
- Core software (WordPress, Shopify apps, Laravel packages) is current
- All plugins and themes updated within the last week or two
- Unused plugins and themes deleted, not just turned off
- No nulled or pirated themes or plugins
- Plugins come from trusted sources and still get updates
- Updates tested on a staging copy for important sites
Auto-updates: good for
- Small sites with few plugins
- Security releases that must go out fast
- Owners with no developer on call
Auto-updates: watch out for
- Stores and complex sites where an update can break checkout
- Custom themes that may clash with new versions
- Sites with no backup taken before updates
For WordPress-specific steps, see WordPress security.
HTTPS, forms and data checklist
Every page should load over HTTPS, and forms should collect only the data you need and store it safely.
- Valid SSL certificate with auto-renewal
- All pages redirect from http to https
- No mixed content warnings in the browser
- Forms have spam protection
- Forms ask only for the details you really need
- Form entries are not kept forever in the website database
- File uploads (if any) are limited by type and size
- Privacy notice explains what data you collect and why
If you run an online store, payment pages need extra care. Read ecommerce security. Collecting less data also helps with the DPDP Act.
Backup checklist: can you restore your site?
A good backup is automatic, stored away from the website server, kept for several days or weeks and tested. Without a tested restore, you do not really know you have a backup.
- 1
Back up files and database daily
Busy stores may need backups more often.
- 2
Store backups off the server
Use a separate cloud storage account, not the same hosting account.
- 3
Keep several versions
Keep at least a few weeks of history, because hacks can go unnoticed for days.
- 4
Protect the backup account
Use two-factor login and a different password from the hosting account.
- 5
Test a restore
Restore to a test location every month or quarter and check the site works.
See our backup and disaster recovery service if you want this handled for you.
Firewall and monitoring checklist
A firewall blocks common attacks, and monitoring tells you quickly when something changes or goes wrong.
- Website firewall (WAF) active, at server, plugin or DNS level
- Uptime monitoring with alerts by email or phone
- File change alerts for core files and themes
- Regular malware scans
- Google Search Console set up with email alerts for security issues
- Login alerts for admin accounts
- Activity log that records who changed what
Our security monitoring and website malware protection services set these up and watch them for you.
Common website security mistakes to avoid
Most hacked small business sites we see share the same few mistakes. Avoiding them closes the gaps attackers use most.
- Keeping the domain or hosting in a former developer's or freelancer's account
- Turning off plugins instead of deleting them, so old code stays on the server
- Keeping backups only on the same hosting account as the website
- Giving every staff member and agency full admin rights
- Ignoring Google Search Console emails about security issues
- Leaving old staging copies and test sites online and unupdated
Each of these is easy to fix once you know about it. Add them to your review list and check them every quarter.
What to do if your checklist shows gaps
Fix the quick, high-impact items first: two-factor login, removing old users and plugins, and setting up off-site backups. Then plan the rest.
- Fix domain and hosting logins today
- Take a fresh off-site backup before any big change
- Update or remove old plugins and themes
- Set up a firewall and monitoring
- Book a professional security audit for anything you are unsure about
- Put regular checks on a calendar or move to a security maintenance plan
If you see signs of a hack, such as strange pages, redirects or a Google warning, stop and get help with malware removal. SI Cyber is powered by Shivah Web Tech, with 24x7 emergency support for hacked sites. Contact us for a free check.
Related Pages
Website Security
Harden, update and protect your business website every day.
WordPress Security
Lock down WordPress logins, plugins, themes and hosting.
Security Audit
A clear report of your security gaps and how to fix them.
Resources
Free cybersecurity checklist for business owners: website safety, hacked site first aid, passwords, phishing, staff exits and backups. Use it today.
Frequently Asked Questions
How do I know if my website is secure?
Go through a checklist like this one: domain and hosting logins with two-factor security, updated software, no unused plugins or users, HTTPS on all pages, off-site backups with restore tests, a firewall and monitoring. Also check Google Search Console for security issues. If you are not sure about several items, a professional security audit gives you a clear answer.
How often should I check my website security?
Updates should happen weekly, backups daily and monitoring all the time. Run through the full checklist every quarter, and again after big changes such as a redesign, new plugin, new developer or staff leaving. Important sites, such as stores and portals, benefit from a deeper professional audit at least once a year.
What is the most important website security step?
There is no single step, but two-factor login on hosting, domain and admin accounts plus regular updates block a large share of attacks. Off-site backups with restore tests are the safety net when something still goes wrong. If you can only do three things this week, do these three.
Is a security plugin enough to protect a WordPress site?
A good security plugin helps with firewall rules, login limits and scans, but it cannot fix weak hosting, old plugins, shared passwords or missing backups. It is one item on the checklist, not the whole list. Combine it with updates, two-factor login, off-site backups and monitoring for real protection.
Does a small brochure website really need all these checks?
Most of them, yes, because hackers attack small sites automatically to host spam and phishing pages. A small site can cover the list quickly: secure logins, few plugins, updates, HTTPS and backups. Some items, like file upload rules or payment page checks, may not apply if your site does not use those features.
Can I check my website security myself for free?
Yes, you can go through most of this checklist yourself using your hosting panel, website admin and Google Search Console. Free online scanners can show some surface issues, but they cannot see inside your files, users or settings. For a full picture, especially for stores or sites with customer data, a professional audit is worth it.
What should I do if I find something suspicious during the check?
Do not delete files in a hurry. Take a full backup first, change your hosting and admin passwords from a clean device and write down what you saw. Then ask a security team to review it. Rushed changes can break the site or remove the clues needed to find how a hacker got in.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.