A small-business website is connected to other important systems: business email, the domain account, forms, booking tools, payments and customer records. Security therefore depends on more than the visible pages.
No provider or checklist can guarantee that an incident will never happen. The practical goal is to reduce avoidable risk, limit access and prepare a proportionate response.
Agree who is responsible
Before launch, record who handles:
- domain renewal and account recovery;
- hosting and software updates;
- backups and restoration;
- administrator access;
- form submissions and stored customer information;
- security notifications and incident response.
If several suppliers are involved, identify the first contact when something fails. Unclear responsibility can delay action.
Protect email, domain and admin accounts
Use unique passwords and multi-factor authentication where available. Prioritise email because it is often used to reset other accounts. Give each person an individual account and remove access promptly when it is no longer needed.
The Cybersecurity and Infrastructure Security Agency provides small and medium business guidance (opens in a new tab) covering practical protective actions.
Keep systems updated
Security updates address known weaknesses. Confirm how the website software, integrations and server environment are maintained. Devices used to manage the site also need supported software and current updates.
Ask what happens if an update conflicts with an existing function and whether urgent security fixes follow a different process from routine maintenance.
Back up and test recovery
Clarify backup frequency, retention and restoration. A copy stored only with the live website may not be enough if the same account or system is affected.
The required recovery point depends on the business. A brochure site that changes monthly and a store receiving orders all day do not have the same needs.
Collect less customer information
The Federal Trade Commission’s Protecting Personal Information guide (opens in a new tab) organises its advice around five steps: take stock, scale down, lock it, pitch it and plan ahead.
Apply that thinking to the website:
- remove form fields you do not need;
- know where submissions are sent and stored;
- restrict who can read them;
- keep them only as long as needed;
- dispose of them securely under an appropriate policy.
Do not promise privacy or security practices that the business does not actually follow. The FTC’s privacy and security guidance (opens in a new tab) explains why accurate representations matter.
Review suppliers and integrations
Booking, email, analytics, chat and payment services can receive data or gain access to the website. Keep a list of active services, account owners and cancellation steps.
Before adding a new tool, ask what information it receives, whether it is necessary and who will maintain it. Remove scripts and accounts that are no longer used.
Prepare for suspicious messages and incidents
Train anyone with website access to question urgent password resets, invoice changes and domain-renewal messages. Verify requests using a known contact method rather than replying to the suspicious message.
Create a short response list with contacts for the website, domain, email and payment providers. Record what needs to be preserved and who decides whether customers or authorities must be notified. Obtain qualified advice for legal notification duties.
Before launch
- Turn on multi-factor authentication where available.
- Use individual accounts with only the access needed.
- Confirm update, backup and restoration responsibilities.
- Remove test users and unused integrations.
- Test forms and know where their data goes.
- Record an incident contact list.
Review regularly
- Check administrator and supplier access.
- Confirm backups and important forms are working.
- Review software and integration updates.
- Remove information and services no longer needed.
- Discuss suspicious messages or unexpected account activity.
Official sources
- Small and Medium Businesses — CISA (opens in a new tab)
- Cyber Guidance for Small Businesses — CISA (opens in a new tab)
- Protecting Personal Information: A Guide for Business — FTC (opens in a new tab)
- Privacy and Security — FTC (opens in a new tab)
These sources provide general guidance. Security controls should be proportionate to the information, services and risks of the particular business.