FREE forever · no login for checks and guides

Business Website Security Checklist

HTTPS, updates for WordPress / plugins, admin URL and 2FA, backups, form spam, a payment gateway instead of collecting cards, and the privacy page the law expects.

A small-business website is attacked by bots, not people. Keeping it boring and updated wins.

Basics

HTTPS everywhere (free certificates exist); CMS, theme and plugin updates automatic; strong admin password with 2FA; the admin URL changed from the default; unused plugins deleted; backups by the host plus your own.

Forms and payments

Spam protection on forms; never collect card numbers — use a licensed payment gateway's link or checkout; store only what you need from enquiries and say so in the privacy page.

The legal page

Business name, address, contact and grievance officer (the Consumer Protection e-commerce rules), a privacy notice (DPDP), returns and refund terms if you sell.

If it is hacked

Restore from a clean backup, change all passwords, update everything, remove unknown admin users, ask the host to scan, and — if customer data was exposed — follow the breach guide.

Checklist

  • ☐HTTPS with auto-renewal
  • ☐Automatic updates on
  • ☐Admin 2FA + non-default admin URL
  • ☐Unused plugins removed
  • ☐Backups tested
  • ☐No card data handled on the site
  • ☐Legal + privacy pages present

Questions people ask

Our site was defaced.

Restore from backup, change every admin password, update everything, and check for a rogue admin user; report to your host and, if data was taken, follow the breach guide.

Been hit and need a human?

Our team helps you draft, file and follow up with the bank and the cyber cell — leave your number for a free callback.

The Cyber Desk provides educational tools, checklists and self-help drafts — not legal advice. For serious or high-value fraud, also consult the police and a qualified lawyer.