Skip to main content

Security essentials

Website Security Checklist

Website security is a routine business process, not a one-off plugin or badge. Start by knowing what you own, reducing unnecessary access and making recovery possible.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

A small business website can hold enquiry data, customer accounts, administrator credentials and trusted links to email, payments or booking services. Losing control can disrupt trading even when the site itself looks simple.

The most useful checklist connects prevention with recovery. Updates and strong sign-in controls reduce avoidable risk, while tested backups, monitoring and named responsibilities shorten the response when something still goes wrong.

Know the exposure

Common risks

01

Unclear ownership

Domains, hosting or administrator accounts registered to a former supplier or employee can delay urgent changes.

02

Neglected software

Old platforms, plugins, themes and server components may retain publicly known weaknesses.

03

Recovery that exists only on paper

A backup is not dependable until its coverage, separation, retention and restore process have been checked.

Investigate, do not ignore

Warning signs

  • No current list of the domain registrar, DNS provider, host, website platform and account owners
  • Shared administrator logins or accounts without multi-factor authentication
  • Updates are applied irregularly and nobody records what changed
  • Backups are stored only beside the live website or have never been restored
  • Certificate, uptime, form and security alerts go to an unmonitored inbox

Reduce likelihood and impact

Practical steps

  1. 01

    Create an ownership register

    Record the domain, DNS, hosting, CMS, repositories, third-party services, renewal dates and named account owners.

  2. 02

    Protect every privileged account

    Use individual accounts, unique passwords, MFA and the minimum role needed. Remove access promptly when responsibilities change.

  3. 03

    Maintain the full stack

    Schedule supported software updates, test important changes and remove unused plugins, themes, accounts and integrations.

  4. 04

    Verify HTTPS and safe data handling

    Redirect traffic to HTTPS, remove mixed content, minimise form data and keep secrets out of source code and public repositories.

  5. 05

    Build and test recovery

    Keep suitably separate backups, practise a restore, define incident contacts and monitor the services that matter to customers.

Defined website support

How AHANIX can help

AHANIX can help turn the checklist into a scoped website improvement plan where the relevant systems and access are available.

  • Review the public website, HTTPS route and visible technical configuration
  • Map website ownership, maintenance, backup and monitoring responsibilities
  • Prioritise practical website changes and coordinate with an existing host or supplier

Clear limits

What this cannot guarantee

  • A checklist reduces common gaps but cannot prove that a website is free from vulnerabilities or future attacks.
  • AHANIX website reviews are not a penetration test, security certification, compliance audit or continuous managed security service.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Security checklist questions

How often should the checklist be reviewed?

Review it on a regular schedule and after material changes such as a launch, supplier handover, new integration, staff departure or security incident. High-risk items such as alerts and backups need more frequent operational checks.

Does a small brochure website need all of this?

The controls should be proportionate, but even a brochure site depends on a domain, hosting and administrator access and may collect enquiries. Ownership, updates, HTTPS, backups and recovery contacts remain relevant.

Does completing the checklist make a website secure?

No. It creates a sound baseline and identifies obvious gaps, but no checklist can guarantee protection against every vulnerability, account compromise or supplier failure.

A scoped next step

Turn the checklist into a clear action plan

Tell AHANIX how the website is hosted and maintained. We can identify the website work we can handle and the items that need a specialist or existing provider.

Discuss website security

Continue in the Security Centre