Website Security Basics Every Owner Should Know
You don’t need to be a target to be hacked — most attacks are automated and indiscriminate, quietly sweeping the web for any site that’s easy to break into.
A lot of small-business owners assume hackers only go after big companies with something worth stealing. In reality, the vast majority of website break-ins are carried out by bots, not people. These programs crawl the internet around the clock, testing thousands of sites an hour for known weaknesses. They don’t care whether you’re a law firm in Sandton or a bakery in Bloemfontein — if the door is unlocked, they walk straight in.
The good news is that the same thing that makes attacks so common also makes them easy to avoid. Bots go for the low-hanging fruit: out-of-date software and weak passwords. A handful of sensible habits will keep you out of the easy-target pile entirely, and not one of them requires you to be technical.
Start With SSL (the Padlock)
An SSL certificate is what puts the little padlock next to your web address and changes it from “http” to “https”. It encrypts the information passing between your visitor and your site, so anything they type — a contact form, a login, card details — can’t be read by anyone listening in transit.
You need it even if you don’t sell anything online. Modern browsers now slap a “Not Secure” warning on sites without SSL, which is enough to scare most visitors away before they read a single word, and Google factors it into search rankings too. The good news: a basic SSL certificate is free and should be included with any decent hosting as standard.
Keep Everything Updated
If your site runs on a platform like WordPress, it’s built from a core system plus a collection of plugins and a theme. Each of those gets regular updates, and many of those updates exist specifically to close security holes that have been discovered and made public. Skip them and you’re leaving known, published weaknesses wide open — which is exactly what the bots are scanning for.
Turn on automatic updates wherever you can, and delete any plugins or themes you’re not actually using. Every extra piece of software is another potential way in, so a lean site is a safer site. This is the single most neglected step we see, and it’s the one that catches the most people out.
Lock Down Your Logins
Weak and reused passwords are behind a huge share of break-ins. “Admin” and “Password123” can be guessed by a bot in seconds, and if you reuse the same password everywhere, a single leak somewhere else hands over your website along with it. A few simple rules close that door:
- Use a long, unique password for every account — a password manager makes this effortless
- Turn on two-factor authentication so a stolen password isn’t enough on its own
- Avoid the default “admin” username, and give staff their own logins rather than a shared one
- Remove access promptly when someone leaves or a freelancer finishes a job
Back Up, and Add a Firewall
Even with everything locked down, things can still go wrong — a server fails, an update misbehaves, or someone slips through. That’s why a recent, automatic backup you can actually restore is non-negotiable. It turns a disaster into a mere inconvenience: if your site is ever compromised, you simply roll back to a clean copy and carry on.
A web application firewall adds another useful layer, quietly blocking malicious traffic and known bad actors before they ever reach your site. Many good hosts include one as standard, along with malware scanning that flags trouble early — ideally before you’d ever notice it yourself.
A Word on POPIA
If your site collects any personal information — names, email addresses or phone numbers through a contact form — South Africa’s POPIA expects you to take reasonable steps to keep that data safe. The basics above are exactly the kind of reasonable steps it has in mind, so good security is also good compliance. It’s rarely about doing something clever; it’s about doing the simple things consistently.
And that’s really the heart of it. Security for a small business is just maintenance, kept up — the boring stuff that never feels urgent until the day it suddenly does. Get the handful of basics right and you’ve dealt with the overwhelming majority of the risk.
If you’d rather have it handled and simply not think about it, our managed hosting includes SSL, backups and security as standard. Get a tailored quote and we’ll take care of it for you.
Comments
Turning on automatic updates and backups gave us real peace of mind. Simple but effective.
Do I really need an SSL certificate if I do not sell anything online?
Yes, Karabo. Even without a shop, browsers now flag sites without SSL as Not Secure, which scares visitors off, and Google factors it into rankings. The good news: SSL is free and included on all our hosting.
Did not know about the Not Secure warning — getting SSL sorted, thanks.
Auto-updates and backups are boring, but they have saved us more than once.
Boring is good when it comes to security, Yolandi. Set-and-forget is the goal.