Protect your website and domain: a security checklist for small businesses

Most small business websites are not lost to clever hackers. They are lost to simpler things: a domain that expired, a reused password that leaked, or a former developer who registered everything in their own name and stopped answering the phone.

The good news is that the fixes are mostly free and take an afternoon. We follow this same checklist for our own studio accounts.

1. Make sure you own your domain

Your domain (like yourbusiness.com or yourbusiness.pk) is the address customers type and the name on your email. If it is registered in someone else's account, you do not fully control your business online.

  • Ask whoever set up your website: which registrar is the domain with, and whose account is it in?
  • Ideally the domain sits in an account in your name, with your email address. A developer can be given access, but you should be the owner.
  • Check that the contact details on the domain are yours and up to date, because renewal and transfer emails go there.

2. Turn on auto-renew and keep the payment method current

An expired domain takes your website and email offline. If it is not renewed in time, someone else can register it. Turn on auto-renew, keep a valid card on the account, and put the expiry date in your calendar anyway.

3. Lock the domain

Most registrars offer a transfer lock (sometimes called registrar lock or domain lock). While it is on, the domain cannot be moved to another registrar without you switching it off first. Check that it is enabled.

4. Turn on 2-step verification everywhere important

2-step verification (also called two-factor authentication or 2FA) means a password alone is not enough to sign in. You also need a code from your phone. It blocks most account takeover attempts.

Turn it on for these accounts first:

  1. Your business email, because every other account can be reset through it.
  2. Your domain registrar.
  3. Your hosting and website admin (for example WordPress).
  4. Your Google account used for Search Console, Google Business Profile and Analytics.
  5. Facebook, Instagram and WhatsApp Business.

Use an authenticator app (like Google Authenticator or Microsoft Authenticator) where you can. It works without mobile signal and is safer than SMS codes if your SIM is ever lost or swapped.

When you turn on 2-step verification, you are usually offered backup codes. Write them on paper and keep them somewhere safe. Never share them, and never send a screenshot of the setup QR code to anyone.

5. Use a different password for every account

If one small website you signed up to is hacked, criminals try the same email and password on email, banking and social media. Reusing one password turns one leak into many.

  • Use a password manager. The one built into Chrome and your Google account is free, and there are good independent ones too.
  • Let it generate long random passwords, so you do not need to remember them.
  • Run its password checkup to find passwords that are reused, weak or already leaked, and change the important ones first.
  • Do not keep passwords in a text file, a notes app or photos on your phone.

6. Make sure your site uses HTTPS

Look at your website address in the browser. It should start with https:// and show no security warning. Free certificates (for example from Let's Encrypt) are included with most modern hosting, so there is no reason to go without one.

7. Keep backups you can actually restore

Ask your host or developer: how often is the site backed up, where are the backups kept, and how long would it take to restore? A backup stored on the same server as the website can be lost together with it. For sites built with WordPress, also keep the core, theme and plugins updated, and remove plugins you no longer use.

8. Review who has access

Over the years, many people collect logins: past employees, a nephew who helped once, an old agency. Once a year, go through your registrar, hosting, website admin, Google and social accounts and remove anyone who no longer needs access. Give each person their own login instead of sharing yours.

The one-afternoon checklist

  1. Domain is in your account, with your contact details
  2. Auto-renew is on and the payment method is valid
  3. Transfer lock is on
  4. 2-step verification is on for email, registrar, hosting, Google and social media
  5. Backup codes are written down and stored safely
  6. Every important account has its own password, stored in a password manager
  7. Website loads with https:// and no warning
  8. Backups exist, are stored separately and have been tested
  9. Old users and ex-staff have been removed

If you are not sure who controls your domain, hosting or logins, we can help you check your setup and put it in order. See our web development service or email hello@auravestudio.com.

Related service

Web Development

We build fast, secure websites and web apps, from a clean company site to online booking, ordering and staff dashboards. Everything is hand-built with Next.js, not squeezed into a template.

About our Web Development service
Keep reading

More guides.