The business case
Why it matters
A small business website can hold enquiry data, customer accounts, administrator credentials and trusted links to email, payments or booking services. Losing control can disrupt trading even when the site itself looks simple.
The most useful checklist connects prevention with recovery. Updates and strong sign-in controls reduce avoidable risk, while tested backups, monitoring and named responsibilities shorten the response when something still goes wrong.
Know the exposure
Common risks
Unclear ownership
Domains, hosting or administrator accounts registered to a former supplier or employee can delay urgent changes.
Neglected software
Old platforms, plugins, themes and server components may retain publicly known weaknesses.
Recovery that exists only on paper
A backup is not dependable until its coverage, separation, retention and restore process have been checked.
Investigate, do not ignore
Warning signs
- No current list of the domain registrar, DNS provider, host, website platform and account owners
- Shared administrator logins or accounts without multi-factor authentication
- Updates are applied irregularly and nobody records what changed
- Backups are stored only beside the live website or have never been restored
- Certificate, uptime, form and security alerts go to an unmonitored inbox
Reduce likelihood and impact
Practical steps
- 01
Create an ownership register
Record the domain, DNS, hosting, CMS, repositories, third-party services, renewal dates and named account owners.
- 02
Protect every privileged account
Use individual accounts, unique passwords, MFA and the minimum role needed. Remove access promptly when responsibilities change.
- 03
Maintain the full stack
Schedule supported software updates, test important changes and remove unused plugins, themes, accounts and integrations.
- 04
Verify HTTPS and safe data handling
Redirect traffic to HTTPS, remove mixed content, minimise form data and keep secrets out of source code and public repositories.
- 05
Build and test recovery
Keep suitably separate backups, practise a restore, define incident contacts and monitor the services that matter to customers.
Defined website support
How AHANIX can help
AHANIX can help turn the checklist into a scoped website improvement plan where the relevant systems and access are available.
- Review the public website, HTTPS route and visible technical configuration
- Map website ownership, maintenance, backup and monitoring responsibilities
- Prioritise practical website changes and coordinate with an existing host or supplier
Clear limits
What this cannot guarantee
- A checklist reduces common gaps but cannot prove that a website is free from vulnerabilities or future attacks.
- AHANIX website reviews are not a penetration test, security certification, compliance audit or continuous managed security service.
Continue with existing resources
Relevant tools and guides
These links use existing AHANIX tools and guides for the next useful check or deeper explanation.
SSL Checker
Check whether a public address reaches HTTPS and review visible certificate, redirect and mixed-content signals.
Open tool AHANIX ToolPassword Generator
Generate a strong random password or passphrase locally in your browser.
Open tool AHANIX ToolPassword Strength Checker
Review length and predictable patterns locally without sending the password to AHANIX.
Open tool AHANIX GuideWhat is HTTPS?
Understand what an encrypted browser connection protects and what it does not.
Open guide AHANIX GuideWhat happens if a website gets hacked?
Use the existing incident guide for immediate context, containment and recovery priorities.
Open guide AHANIX GuideWhat is website hosting?
Understand where a website runs and which responsibilities sit with the host, platform and site owner.
Open guideCommon questions
Security checklist questions
How often should the checklist be reviewed?
Review it on a regular schedule and after material changes such as a launch, supplier handover, new integration, staff departure or security incident. High-risk items such as alerts and backups need more frequent operational checks.
Does a small brochure website need all of this?
The controls should be proportionate, but even a brochure site depends on a domain, hosting and administrator access and may collect enquiries. Ownership, updates, HTTPS, backups and recovery contacts remain relevant.
Does completing the checklist make a website secure?
No. It creates a sound baseline and identifies obvious gaps, but no checklist can guarantee protection against every vulnerability, account compromise or supplier failure.
A scoped next step
Turn the checklist into a clear action plan
Tell AHANIX how the website is hosted and maintained. We can identify the website work we can handle and the items that need a specialist or existing provider.
Continue in the Security Centre