Keeping a Business Website Secure

en 7 min read

Keeping a Business Website Secure

Keeping a small business website secure is routine work rather than a product you buy, and it splits in two. Care, at EUR 100-300 a month, handles updates, monitoring, backups and small fixes, while decisions about logins, the people with access and the data your forms collect stay with you.

Neither side works alone. A site with every update applied is still open if a former employee can log in to the CMS, and strong passwords in the office do not protect a site running outdated code.

What a small business site needs to stay secure

Leave out the jargon and the basics come down to six things.

What Care covers and what stays with you

The split follows one question: does the task need access to the code, or to your business?

TaskWho handles it
Updates to the framework, the CMS and the code libraries the site usesCare
Noticing when the site goes downCare, through monitoring
BackupsCare
A broken form, a dead link, a wrong phone numberCare, as a small fix
Two-factor authentication on your email and CMS loginsYou
Removing access when someone leaves your teamYou, and tell whoever maintains the site
Knowing who holds the domain registration and when it renewsYou
Deciding what your forms ask forYou
Approving a new widget or tracking scriptYou
Adding customer logins or online paymentsA step 04 project, EUR 3.500-7.500
A redesign, or moving off a platform that can no longer be updatedA project with its own quote, not Care

Why the security work grows with the step

The more a site does, the more there is to keep closed. The steps on packages show it plainly.

How security is handled from build to live site

Security is cheapest when it is decided before anything is built, because a login that never exists never needs guarding.

  1. Scope. Which logins exist, who gets them, what data the forms and database hold, and which outside services connect. A fixed quote follows scoping.
  2. Build. 1-2 weeks for a single-page landing, 2-3 weeks for a mini-site, 3-6 weeks for a business website and 6-12 weeks for an advanced site or web app. A custom SaaS platform is timed after discovery.
  3. Launch checks. HTTPS on every address, forms tested end to end, test users and unused logins removed, and every script on the page accounted for.
  4. Live. Care takes over the routine: updates, monitoring, backups and small fixes. Your side runs alongside it.

Your side, as a checklist

None of this needs a developer.

When to spend less

If you have a single-page landing with one form and nothing on it is about to change, the security work is small and you may not need a monthly plan. Keep two-factor authentication on your logins, know where the repository is, and ask for help when something breaks.

Do not add customer logins, a portal or stored data to look more established. Every login and every stored record has to be protected for as long as the site exists. If a form and a phone number bring the enquiry in, that is the more secure site as well as the cheaper one, and saying no to a feature is a security decision too.

And do not buy a bigger build because the current site feels unsafe. If it runs on code that can still be updated, bringing it current is update work, not a rebuild. A rebuild earns its price when what sits underneath can no longer be updated.

Questions buyers ask

Is an SSL certificate enough to call a site secure?

No. HTTPS encrypts what travels between the visitor and the site, which matters for every form. It does nothing about outdated code, a former employee's login or a script reading your pages. Treat it as the starting point.

Is a coded Next.js site more secure than WordPress?

Neither is secure by default, and neither stays secure without updates. WordPress relies on plugins, and each plugin is code from a separate author that needs its own updates. A coded Next.js site has no plugin marketplace, but it still depends on open-source packages that need updating.

Does a contact form bring GDPR into it?

Yes, because names, email addresses and messages are personal data. Ask only for what you need to reply, know where submissions end up, and cover the form in your privacy statement. What the regulation asks of a small business site is set out in GDPR and your website.

What happens to security if I stop Care?

You own the code, the repository and the database, so the site is yours to hand to another developer. Updates, monitoring and backups stop until someone else takes them on. That matters more on a step 04 build with logins and payments than on a single-page landing.

Tell us what your site runs on and who can log in to it, and we will tell you which side needs attention first: get in touch.

Building something?

JP Studio designs and builds websites, storefronts and product interfaces.

Straight to the person who would do the work. No newsletter, no call centre. Prefer email? support@jp-studio.com