A small-business website is attacked by bots, not people. Keeping it boring and updated wins.
Basics
HTTPS everywhere (free certificates exist); CMS, theme and plugin updates automatic; strong admin password with 2FA; the admin URL changed from the default; unused plugins deleted; backups by the host plus your own.
Forms and payments
Spam protection on forms; never collect card numbers — use a licensed payment gateway's link or checkout; store only what you need from enquiries and say so in the privacy page.
The legal page
Business name, address, contact and grievance officer (the Consumer Protection e-commerce rules), a privacy notice (DPDP), returns and refund terms if you sell.
If it is hacked
Restore from a clean backup, change all passwords, update everything, remove unknown admin users, ask the host to scan, and — if customer data was exposed — follow the breach guide.
Checklist
- ☐HTTPS with auto-renewal
- ☐Automatic updates on
- ☐Admin 2FA + non-default admin URL
- ☐Unused plugins removed
- ☐Backups tested
- ☐No card data handled on the site
- ☐Legal + privacy pages present