Blog Website

Website security isn't a plugin. It's a job nobody owns.

Website security isn't a plugin. It's a job nobody owns.

Gabriel Espinheira

Website security for a small business is not a product you install once. It's a maintenance job someone has to own, and on most owner-operated sites, nobody does.

Think about the site you're taking a break from to read this. A freelancer built it, maybe two years ago. They promised the SEO would "kick in around month three," then went quiet. Since launch, has anyone logged into the admin panel? Updated the plugins? Checked that the contact form still goes somewhere? On most small sites the honest answer is no, and that gap, not a hacker in a hoodie, is what actually gets you.

One of the most repeated lines in owner-operator forums is blunt: "It was built in WordPress and there were numerous glitches and errors." The glitches are the visible half. The half you can't see is the one that costs you.

TL;DR: For an owner-operated site, security isn't a firewall or a "security plugin" you buy once. It's ongoing maintenance that has to be someone's job. The real danger isn't a dramatic hack; it's a quiet compromise you never notice until Google or a customer does. Assign an owner before you add a tool.

Yes, small sites get hit, just not the way you picture it

Two in five small UK businesses (42%) reported a cyber breach or attack last year, according to the government's 2025 Cyber Security Breaches Survey. Most of that is phishing, not website defacement, so don't read it as "42% of small sites got hacked." Read it as this: you are not too small to be a target. Nobody picked you.

The attacks that reach small sites are automated. Bots crawl thousands of sites an hour, testing known plugin holes and weak logins, and they don't check your revenue first. A brochure site for a six-person firm outside Porto and a national retailer look identical to a script scanning for one outdated plugin. "I'm too small to bother with" isn't caution. It's the assumption the bot is built on.

A hacked small-business site rarely looks hacked

Here's the part the checklist posts skip. When a small site is compromised, it almost never announces it. No skull on the homepage, no ransom note. The people who do this for money want the opposite of attention.

The common payload is SEO spam. Your site quietly starts serving pages about pharmaceuticals or counterfeit trainers, but only to Google's crawler. Load your homepage and it looks exactly as it did on launch day. Google loads it and sees a pharmacy. Other compromises use a conditional redirect that fires only when someone clicks through from a search result, never when you type the address yourself. So you check the site, it's fine, and you get on with your day, while it's been working against you for three weeks.

A hacked small-business site rarely looks hacked. That's the whole point, and it's why "it looks fine to me" is worth nothing as a security check.

The risk isn't "WordPress." It's the plugins nobody's touched

When something goes wrong, the reflex is to blame the platform. WordPress runs a huge share of small-business sites, and it dominates the hacked-site numbers too. The security firm Sucuri found it in roughly 95% of the infections it cleaned in 2023. But that's about its share of the market, not proof it's uniquely unsafe.

The number that actually matters is the next one: close to four in ten of those hacked sites were running outdated software at the point of infection. And the outdated software is rarely the core. Patchstack counted 7,966 new vulnerabilities across the WordPress ecosystem in 2024, up 34% on the year and roughly 22 a day. Almost all of them sat in third-party plugins and themes, not the core. WordPress core mostly updates itself now. The booking plugin, the gallery slider, the cookie banner, the form add-on you installed once and forgot: those don't.

Which is the awkward thing about the standard advice to "install a security plugin." A security plugin is one more plugin to keep updated. Bolt on five security tools that nobody maintains and you haven't hardened the site. You've widened it. More than half the time, Patchstack found, the plugin's own developer hadn't shipped a fix before the hole was made public. Tools don't maintain themselves. People do.

What a quiet compromise actually costs you

Set the data risk aside for a second, because the invisible compromise is also a conversion leak, the part that shows up on the invoice.

Google's Safe Browsing flags compromised sites, and when it does, the browser throws a full-page red "Deceptive site ahead" wall in front of your homepage. Organic visitors hit it and bounce. Your Meta and Google ads keep spending, except now they're sending expensive clicks to a warning screen, or the platform stops approving them because the destination is flagged. The links in your email footer get marked unsafe.

You don't see a hack. You see a bad week. Enquiries dip, the ad dashboard still says "active," and you assume the market went quiet. It didn't go quiet. It got blocked. This is the same failure mode as a slow page or a dead contact form: the site keeps taking your traffic and your budget and quietly hands back nothing.

In the EU, "I didn't know" is the failure

If your site collects anything personal, a contact form, a newsletter signup, a checkout, then a compromise isn't just downtime. Under GDPR it's a personal-data breach, and the clock is specific. You have 72 hours to notify your data protection authority from the moment you become aware of it (Article 33). Not from when you fix it. From when you know. Failing to report can carry a fine of up to €10 million or 2% of global turnover, on top of whatever the breach itself did.

Now read that back against the section before it. If the compromise is built to stay invisible, and no one is watching for it, "I didn't know" isn't a defence. It's the precise failure the rule is written about. The 72 hours don't wait for you to notice. For an owner-operated European business, "nobody was really looking after it" is the sentence you least want to be saying to a regulator.

Website security is an ownership question, not a shopping list

So the honest fix isn't a bigger security stack. It's answering three boring questions, out loud, about your own site.

Who patches it, as a standing job, on a schedule, not "when we remember"? Who holds the logins (hosting, domain, CMS admin, plugin licences), and could you get back in tomorrow if the person who set it all up vanished? And what is actually watching it, for the silent stuff, the crawler-only spam and the conditional redirect, not just for whether the homepage loads?

Answer those and you'll notice the cost isn't a subscription to a tool. It's a person. Managed hosting and auto-updates help, and you should use them, but they patch what already has a patch and watch only what they're told to. They don't notice that the freelancer holding your domain login stopped replying, or decide which abandoned plugin to rip out before it's exploited. That judgement is the job. Real protection means giving up the comfortable idea that a website is "done" at launch. Someone has to own the upkeep as a standing line, the way you'd never leave the books unreconciled for a year and call it a filing system.

That's the actual difference between a build-and-disappear vendor and a partner. The vendor hands you a site and a plugin list and moves on. A partner keeps the thing patched, watched, and yours. It's why our own conversion-first websites don't end at launch, and why the SharpOS workspace inside every SharpHaw subscription keeps the ongoing work visible: the audits, the changes, what shipped this week, instead of something you hope someone remembered.

The 15-minute ownership check

You don't need a penetration test to find your gap. You need fifteen minutes and the willingness to answer honestly. Do this today:

  • Open your CMS admin and look at the update count. A stack of pending plugin and theme updates, or not remembering the login at all, is your exposure in one screen.
  • List who holds every key: hosting, domain, CMS, plugin licences. If any of them sits with a freelancer who's gone quiet, you don't fully own your site yet.
  • Search site:yourdomain.com on Google and skim the results. Pages you didn't write, odd product names or other languages, are SEO spam you can't catch any other way.
  • Decide whose job the patching is, starting this week. A name, not "we should sort that out." If the honest answer is "no one," you've found the real vulnerability.

None of that costs money. What costs money is the three weeks before you looked.

Website security for a small business was never a product you could buy your way out of. It's maintenance, and maintenance is someone's job. Give it a name: a person, or a partner who treats your site as a system to keep sharp, not a file to hand over and forget.

Plan. Build. Iterate.

Book a 30-min call, bring the site you're not sure anyone's maintaining, and get an honest read. Every price is on our Plans page, with no annual lock-in, so the upkeep never turns into another contract you're trapped in.

Plan. Build. Iterate.

A focused 30 minutes, not a sales pitch.

Read more