Website Development Security
Website Security: SSL, Backups and the Hack You Missed
The "Not secure" warning, backups and hacked WordPress sites without jargon: what threatens a small business site and the five steps to cover this week.
In short: small business sites get hacked not because someone targets you personally, but because automated scanners sweep the whole internet looking for unlocked doors: no SSL, outdated WordPress, default passwords, no backups. The damage isn’t theoretical — spam injected into your pages, Google blacklisting the domain, visitors scared away by a “Not secure” banner. All of it is prevented by a five-step minimum that costs hours, not thousands. This article explains each step in plain language.
The padlock first: what SSL actually does
SSL (the https:// and the padlock) does two things a business owner cares about:
- Encrypts data in transit — a form filled on your site travels to your server locked, not readable by anyone on the same Wi-Fi.
- Proves your site is really yours — no one can show your page content under your address.
That’s why browsers shout “Not secure” on pages without it. Google uses HTTPS as a ranking signal, payment services require it (online payments simply won’t work without SSL), and visitors — according to trust studies — visibly distrust it.
Cost: $0–100/year. A free Let’s Encrypt certificate covers 99% of cases; hosting control panels install it in a few clicks. There is no excuse for a business site running without SSL today — and no upside whatsoever.
What actually threatens a small business site (in order of frequency)
| Threat | How it happens | What you lose |
|---|---|---|
| Outdated CMS/plugins | nobody updated since install | vulnerability that scanners find in minutes |
| Weak/reused passwords | admin login from a leaked database | defacement, hidden redirects to spam sites |
| No backups | host wipes, hack, failed update | a new site from scratch, weeks of lost income |
| Malware from nulled plugins | “free” premium theme = gift wrapped trojan | blacklist from Google, broken trust |
| DDoS (rare for SMB) | conflict, competitor, “for fun” | downtime, lost hot-season days |
| Phishing on your own domain | expired DNS, attacker registers it | clients get a fake payment page under your name |
Scary column is the third one — and almost everything in it is prevented by hygiene, not budget.
The 5-step minimum (doable this week)
What a hack costs a small business (the honest calculation)
- Weeks offline: an average small business site that was bringing 5–15 enquiries a month goes to zero — while the rebuild takes time you didn’t plan.
- Trust reset: Google’s red warning page + spam titles in search (“Buy viagra — your kitchen renovation company”). Clients screenshot these and send to each other for years.
- Blacklist aftermath: after cleanup, re-requesting review, rebuilding trust with payment systems — days to weeks of work.
- Data liability: if client databases (orders, phones) leak from your store — legal risk plus permanent reputation damage in a niche where everyone knows each other.
The prevention bundle — SSL + backups + updates + passwords — is 2–4 hours of setup and ~$0–100/year. The ratio is obvious.
The human layer: the two most common real hacks
Not explosions and not spies. The two classic SMB stories:
- “The developer made the site and vanished.” The password reset lands in his email (because it was set to his), access quietly stays with him; or the site expires on his hosting account after he stopped paying. Owner everywhere: hosting, domain and CMS admin must be on YOUR email. Check it today.
- The nulled theme/plugin. A $3 “premium” plugin bought from a Telegram channel ships with a backdoor pre-installed. Scanners don’t even need to exploit you — they just execute the code that was handed to them for free.
What DEXA does about security
Every site we ship runs on HTTPS by default, static-first architecture (no plugin attack surface), daily backups, limited admin access, and a post-launch monitoring window. When we take over an existing WordPress site, we start with a security pass: malware check, access audit, backup setup, update plan. Maintenance and support covers exactly this — before an incident, not after.
Bottom line
Website security for a small business isn’t cybersecurity science — it’s five boring habits: SSL, backups, updates, passwords, and quarterly self-check. They cost hours a year; their absence can cost a whole quarter. Do the minimum this week, and then check who keeps the site safe for the next year — maintenance guide is the next read.
Get your site secured and maintained → — we run the security pass on existing sites and ship new ones locked by default. Read next: how to keep your site bringing leads and fix or rebuild — the honest decision.
landing from $1,100 (₴45,000)
Need the same solution for your business?
Bespoke design and lively animations on Astro, React, Vue and Angular: corporate sites, landing pages and promo sites impossible to mistake for templates.
- Custom design from scratch
- GSAP/ScrollTrigger animations
- 90+ Lighthouse speed
Get a free website audit in 48 hours
Speed, SEO, conversion — a 12-page report with a prioritized fix plan. No obligation, no spam: we show what to improve even if you never hire us.
- Core Web Vitals & speed
- SEO structure & content
- Conversion paths & UX