Keeping a Business Website Secure
Keeping a small business website secure is routine work rather than a product you buy, and it splits in two. Care, at EUR 100-300 a month, handles updates, monitoring, backups and small fixes, while decisions about logins, the people with access and the data your forms collect stay with you.
Neither side works alone. A site with every update applied is still open if a former employee can log in to the CMS, and strong passwords in the office do not protect a site running outdated code.
What a small business site needs to stay secure
Leave out the jargon and the basics come down to six things.
- HTTPS on every page. The padlock or site-settings icon beside the address means data travelling between the visitor and the site is encrypted. It says nothing about whether the site is up to date or who can log in to it.
- Current code. A site runs on a framework, a CMS, plugins or packages written by other people. When a security hole in one of them is fixed, the fix only reaches your site when someone applies the update.
- Few logins, each with two-factor authentication. Every login that can change the site is a way in: the CMS, the hosting, the domain registrar, and the email address that can reset all of them. A shared login cannot be taken away from one person without changing it for everyone.
- A backup to go back to. On a site with a database, such as one with customer logins or bookings, the database is the part that cannot be recreated. The code already lives in the repository.
- Forms that collect only what they need. Every field is personal data you now hold. A form that asks for a date of birth it never uses adds risk and gives you nothing.
- Scripts you know about. A chat widget or tracking tag added as a script runs inside your page and can read what is on it, form fields included. Each one should be there because someone decided it should.
What Care covers and what stays with you
The split follows one question: does the task need access to the code, or to your business?
| Task | Who handles it |
|---|---|
| Updates to the framework, the CMS and the code libraries the site uses | Care |
| Noticing when the site goes down | Care, through monitoring |
| Backups | Care |
| A broken form, a dead link, a wrong phone number | Care, as a small fix |
| Two-factor authentication on your email and CMS logins | You |
| Removing access when someone leaves your team | You, and tell whoever maintains the site |
| Knowing who holds the domain registration and when it renews | You |
| Deciding what your forms ask for | You |
| Approving a new widget or tracking script | You |
| Adding customer logins or online payments | A step 04 project, EUR 3.500-7.500 |
| A redesign, or moving off a platform that can no longer be updated | A project with its own quote, not Care |
Why the security work grows with the step
The more a site does, the more there is to keep closed. The steps on packages show it plainly.
- Step 01, single-page landing, EUR 600-900. One page, a form and analytics. The form is the one thing a visitor can send you, so spam protection and a delivery address someone reads matter most.
- Steps 02 and 03, EUR 900-1.500 and EUR 1.500-3.500. Both include a CMS, which adds a login that can change what the site says. Booking or a contact flow at step 03 puts more personal data through the site.
- Step 04, advanced site or web app, EUR 3.500-7.500. Customer logins, a dashboard, an API, a CRM connection or payments. The site now holds customer data, talks to other systems and takes money, and each of those needs its own security decisions in the scope.
- Step 05, custom SaaS platform, from EUR 7.500. Authentication, billing and an admin area are part of the product, and how they are secured is settled in discovery.
How security is handled from build to live site
Security is cheapest when it is decided before anything is built, because a login that never exists never needs guarding.
- Scope. Which logins exist, who gets them, what data the forms and database hold, and which outside services connect. A fixed quote follows scoping.
- Build. 1-2 weeks for a single-page landing, 2-3 weeks for a mini-site, 3-6 weeks for a business website and 6-12 weeks for an advanced site or web app. A custom SaaS platform is timed after discovery.
- Launch checks. HTTPS on every address, forms tested end to end, test users and unused logins removed, and every script on the page accounted for.
- Live. Care takes over the routine: updates, monitoring, backups and small fixes. Your side runs alongside it.
Your side, as a checklist
None of this needs a developer.
- Turn on two-factor authentication for your email, the CMS and the domain registrar.
- Stop sharing logins. Give each person their own, so one can be removed without resetting the rest.
- When someone leaves, remove their access the day they go and tell whoever maintains the site.
- Find out who holds the domain registration and when it renews. A lapsed domain takes down the website and any email on that domain together. How the pieces connect is covered in domain and DNS explained.
- Treat an email asking you to verify a site login with suspicion, and log in by typing the address yourself.
- Before adding a widget or tracking tag, ask what it can see.
When to spend less
If you have a single-page landing with one form and nothing on it is about to change, the security work is small and you may not need a monthly plan. Keep two-factor authentication on your logins, know where the repository is, and ask for help when something breaks.
Do not add customer logins, a portal or stored data to look more established. Every login and every stored record has to be protected for as long as the site exists. If a form and a phone number bring the enquiry in, that is the more secure site as well as the cheaper one, and saying no to a feature is a security decision too.
And do not buy a bigger build because the current site feels unsafe. If it runs on code that can still be updated, bringing it current is update work, not a rebuild. A rebuild earns its price when what sits underneath can no longer be updated.
Questions buyers ask
Is an SSL certificate enough to call a site secure?
No. HTTPS encrypts what travels between the visitor and the site, which matters for every form. It does nothing about outdated code, a former employee's login or a script reading your pages. Treat it as the starting point.
Is a coded Next.js site more secure than WordPress?
Neither is secure by default, and neither stays secure without updates. WordPress relies on plugins, and each plugin is code from a separate author that needs its own updates. A coded Next.js site has no plugin marketplace, but it still depends on open-source packages that need updating.
Does a contact form bring GDPR into it?
Yes, because names, email addresses and messages are personal data. Ask only for what you need to reply, know where submissions end up, and cover the form in your privacy statement. What the regulation asks of a small business site is set out in GDPR and your website.
What happens to security if I stop Care?
You own the code, the repository and the database, so the site is yours to hand to another developer. Updates, monitoring and backups stop until someone else takes them on. That matters more on a step 04 build with logins and payments than on a single-page landing.
Tell us what your site runs on and who can log in to it, and we will tell you which side needs attention first: get in touch.
Building something?
JP Studio designs and builds websites, storefronts and product interfaces.