Website Security Checklist for Small Businesses

Cybersecurity · Published 2026-06-20

Most small business owners in India assume they are too small to attack. That assumption is the vulnerability. Attacks are overwhelmingly automated: bots scan the entire internet for known weaknesses and do not check your turnover before exploiting one.

What attackers actually want

Rarely your business secrets. Usually:

  • Your server, to send spam or host phishing pages under your domain's reputation.
  • Your traffic, redirected to scam or affiliate sites.
  • Your customer data, sold in bulk.
  • Your money, through ransomware or payment interception.
  • Your SEO authority, via hidden spam links injected into your pages.

Many owners discover a breach only when Google flags the site as deceptive and organic traffic collapses overnight.

The essential checklist

1. HTTPS everywhere

Free through Let's Encrypt. Enforce it — redirect all HTTP traffic to HTTPS and enable HSTS. Without it, browsers warn visitors and Google downgrades you.

2. Strong, unique passwords with 2FA

Reused passwords are the leading cause of small business compromise. Use a password manager, generate long unique passwords for hosting, CMS, database, email, and domain registrar, and enable two-factor authentication on every account that supports it — starting with your domain registrar, whose loss is the hardest to reverse.

3. Keep everything updated

Outdated plugins and themes are the most exploited vector on the web. Enable automatic security updates, review monthly, and delete anything unused rather than leaving it deactivated. Deactivated code is still code on your server.

4. Automated, tested backups

Daily automated backups stored off-site, retained for at least thirty days — and restored to a test environment at least once. An untested backup is a hope, not a plan. Backups stored only on the same server disappear with the server.

5. Protect the admin area

Change the default admin URL where possible, limit login attempts, never use "admin" as a username, restrict access by IP if your team works from fixed locations, and remove accounts for people who have left.

6. Validate every form

Contact forms, search boxes, and file uploads are entry points. Validate and sanitise input server-side, restrict upload types and sizes, and use CAPTCHA or honeypot fields against bots.

7. Correct file permissions

Directories at 755, files at 644, configuration files more restrictive still. Never 777 — a permanent open door, no matter what a forum post from 2014 suggests.

8. Security headers

Add Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Cheap to implement and they close entire classes of attack.

9. Monitor for change

File integrity monitoring and uptime alerts tell you within minutes when something changes unexpectedly. Early detection is the difference between a nuisance and a disaster.

10. Train the people

Technology fails at the human layer. Teach your team to verify unexpected payment requests by phone, to distrust urgent messages that appear to come from you, and never to reuse passwords between personal and business accounts.

If you are already hacked

  1. Take the site offline or into maintenance mode to protect visitors.
  2. Change every password — hosting, CMS, database, FTP, email, registrar.
  3. Preserve a copy for investigation before you clean anything.
  4. Identify the entry point; restoring without closing it guarantees reinfection.
  5. Restore from a known-clean backup, or clean the infection thoroughly.
  6. Update everything, then request a review in Google Search Console.
  7. Notify affected customers if personal data was exposed — under India's Digital Personal Data Protection Act this may be a legal obligation.

What this costs

HTTPS, strong passwords, 2FA, updates, and basic hardening cost almost nothing but attention. A professional security audit for a small business site typically runs ₹10,000 – ₹25,000. Recovering from a serious breach — cleanup, lost sales, blacklist removal, and reputational damage — routinely costs several times that.

RaSo Group provides cybersecurity assessments and hardening for Indian businesses, and our maintenance plans keep updates, backups, and monitoring running on schedule.

Keep reading

Related guides

Need help implementing this?

RaSo Group builds and maintains websites for businesses across India.