Website Builder Studio
Learn

Website security basics

Most website security advice is written for systems a small business does not run. On a hosted site, the provider handles nearly all of it, and the remaining risk is concentrated in two places.

Short answer

On a hosted site, your provider handles server security, patching and certificates. What remains yours is account access and the data you collect. Strong unique passwords with a second factor, and collecting no more personal data than you need, covers most of the real risk.

What your host handles

Server patching, network protection, the certificate that encrypts traffic, and the software your site runs on. On a hosted platform none of that is your work and none of it should be.

That is a genuine advantage of a hosted site over a self-managed one. The failures that make news are usually unpatched software, and a hosted platform removes that category entirely.

Confirm your site loads over a secure connection and that the certificate renews automatically. Our page on secure connections covers what that padlock does and does not mean.

Ask your provider what they cover if you are not sure. A clear answer about where their responsibility ends is genuinely useful, and a provider who cannot give one has told you something important.

Account access is the real risk

Nearly every small business site compromise starts with a login rather than a technical exploit. A reused password from an unrelated breach is the commonest route.

Use a unique password for your website account and turn on a second factor. That single pair of actions removes the large majority of realistic risk.

And review who has access. Old contractors, former staff and an agency you stopped working with frequently still hold accounts nobody revoked.

Give each person their own login rather than sharing one. A shared password cannot be revoked for one person, and nobody can tell afterwards who changed what.

What is actually yours to do

The list below is the whole of it for a hosted small business site. Anything beyond this is either the provider's job or is not proportionate to the risk.

  • A unique password on the website account
  • A second factor turned on
  • Access removed when somebody leaves
  • No more personal data collected than needed
  • Form submissions not left sitting indefinitely
  • A secure connection confirmed on every page
  • Anything added to the site from a source you trust

Collect less

Data you never collected cannot be exposed. A form asking for a date of birth or an address you do not need is a risk taken for nothing.

The same applies to holding submissions forever. Our page on form data and retention covers how long to keep enquiries and why a policy matters.

This is the item most often skipped because it feels like a legal question rather than a security one. It is both, and reducing what you hold improves both at once.

Go through your forms once and remove every field you do not act on. Most business forms have accumulated two or three questions that nobody has read an answer to in years.

Be careful what you add

Every script, widget and plugin added to a site runs code you did not write. That is the one way a hosted site can still be compromised by something other than a login.

Add only what you need, from sources you would name to a customer. Our page on third-party scripts covers the privacy half of the same decision.

Remove what you stopped using. An abandoned widget keeps running and keeps being a route in, long after anybody remembers installing it.

Keep a short list of what is installed and why. Without one, nobody can tell an abandoned widget from a load-bearing one, so nothing ever gets removed.

What to do if something goes wrong

Change the password and revoke sessions first, before investigating anything. Nearly every incident on a site like yours is an access problem and that step ends it.

Then contact your provider. They can see things you cannot and they have handled the situation before, which is worth more than an hour of your own searching.

Then restore from a known-good copy rather than trying to clean in place. Our page on backups and versions covers why that copy needs to have been tested.

Then tell anybody affected. If personal data was involved there may be an obligation to notify, and the time limits on that are shorter than most businesses expect.

Questions people ask

Is my hosted website secure?

The server, the patching and the certificate are your provider's responsibility and are handled. What remains yours is account access and the personal data you choose to collect.

How do small business sites actually get compromised?

Almost always through a login rather than a technical exploit, usually a password reused from an unrelated breach. A unique password with a second factor removes most of the realistic risk.

Do I need a security plugin or service?

On a hosted platform, usually not. Adding software to a site is itself a route in, so the safer default is to add only what you need and remove what you stopped using.

What should I do first if something looks wrong?

Change the password and revoke active sessions before investigating anything else, then contact your provider. Most incidents on small sites are access problems, and that step ends them.

See your website built from a conversation

15-day free trial. Card required. Cancel before day 15 and you pay nothing.

Build my website
Every plan starts with a 15-day free trial. Card required.See plans and pricing