Back to all articles
USSecurity4 min read19 September 2026

Small Business Website Security: A Practical US Checklist

A practical division of website-security responsibilities using guidance from CISA and the Federal Trade Commission.

A small-business website is connected to other important systems: business email, the domain account, forms, booking tools, payments and customer records. Security therefore depends on more than the visible pages.

No provider or checklist can guarantee that an incident will never happen. The practical goal is to reduce avoidable risk, limit access and prepare a proportionate response.

Agree who is responsible

Before launch, record who handles:

  • domain renewal and account recovery;
  • hosting and software updates;
  • backups and restoration;
  • administrator access;
  • form submissions and stored customer information;
  • security notifications and incident response.

If several suppliers are involved, identify the first contact when something fails. Unclear responsibility can delay action.

Protect email, domain and admin accounts

Use unique passwords and multi-factor authentication where available. Prioritise email because it is often used to reset other accounts. Give each person an individual account and remove access promptly when it is no longer needed.

The Cybersecurity and Infrastructure Security Agency provides small and medium business guidance (opens in a new tab) covering practical protective actions.

Keep systems updated

Security updates address known weaknesses. Confirm how the website software, integrations and server environment are maintained. Devices used to manage the site also need supported software and current updates.

Ask what happens if an update conflicts with an existing function and whether urgent security fixes follow a different process from routine maintenance.

Back up and test recovery

Clarify backup frequency, retention and restoration. A copy stored only with the live website may not be enough if the same account or system is affected.

The required recovery point depends on the business. A brochure site that changes monthly and a store receiving orders all day do not have the same needs.

Collect less customer information

The Federal Trade Commission’s Protecting Personal Information guide (opens in a new tab) organises its advice around five steps: take stock, scale down, lock it, pitch it and plan ahead.

Apply that thinking to the website:

  • remove form fields you do not need;
  • know where submissions are sent and stored;
  • restrict who can read them;
  • keep them only as long as needed;
  • dispose of them securely under an appropriate policy.

Do not promise privacy or security practices that the business does not actually follow. The FTC’s privacy and security guidance (opens in a new tab) explains why accurate representations matter.

Review suppliers and integrations

Booking, email, analytics, chat and payment services can receive data or gain access to the website. Keep a list of active services, account owners and cancellation steps.

Before adding a new tool, ask what information it receives, whether it is necessary and who will maintain it. Remove scripts and accounts that are no longer used.

Prepare for suspicious messages and incidents

Train anyone with website access to question urgent password resets, invoice changes and domain-renewal messages. Verify requests using a known contact method rather than replying to the suspicious message.

Create a short response list with contacts for the website, domain, email and payment providers. Record what needs to be preserved and who decides whether customers or authorities must be notified. Obtain qualified advice for legal notification duties.

Before launch

  • Turn on multi-factor authentication where available.
  • Use individual accounts with only the access needed.
  • Confirm update, backup and restoration responsibilities.
  • Remove test users and unused integrations.
  • Test forms and know where their data goes.
  • Record an incident contact list.

Review regularly

  • Check administrator and supplier access.
  • Confirm backups and important forms are working.
  • Review software and integration updates.
  • Remove information and services no longer needed.
  • Discuss suspicious messages or unexpected account activity.

Official sources

These sources provide general guidance. Security controls should be proportionate to the information, services and risks of the particular business.

Share this article

Continue reading

USAccessibility4 min read

An Accessible Website Checklist for Muslim-Owned Small Businesses

Practical ways to make a small-business website easier to use, with cautious context and official ADA guidance.

Read article
USPricing4 min read

How Much Does a Small Business Website Cost in the US?

A practical framework for comparing US website proposals, total ongoing costs and ownership without relying on invented averages.

Read article
UKSecurity3 min read

Small Business Website Security: A Practical UK Checklist

Practical website-security responsibilities for UK small businesses, based on National Cyber Security Centre guidance.

Read article