Most small business owners don't think about their website security until something goes wrong. Then, suddenly, they're thinking about very little Stambaugh Designs Bellingham web design else.
A compromised website can mean customer data exposed, your domain blacklisted by Google, your hosting account suspended, and thousands of dollars in cleanup and recovery costs — not counting the reputational damage. For a small business in Bellingham where your reputation is your most valuable asset, that's not a theoretical risk worth ignoring.
The good news is that the most impactful security measures aren't complicated or expensive. They're mostly about doing the basics consistently rather than doing something exotic.
1. Keep Everything Updated — Religiously
If your website runs on WordPress, the single most common path attackers use to compromise small business sites is outdated plugins and themes. Not sophisticated zero-day exploits — just old, unpatched software with known vulnerabilities that automated bots are continuously scanning for.
WordPress alone powers about 43% of websites on the internet, which makes it a constant target. When a vulnerability is discovered in a popular plugin and a patch is released, the race begins: will site owners update before attackers write automated tools to exploit the unpatched version? The attackers are faster than most site owners assume.
What to do:
- Enable automatic updates for WordPress core, plugins, and themes where possible Schedule a 15-minute monthly review to manually update anything that didn't auto-update Remove deactivated plugins entirely — they can still be exploited even when turned off Delete unused themes down to one or two (including the default theme as a backup)
If you're on a platform like Squarespace or Wix, this concern is largely handled for you. The tradeoff is less flexibility; the security benefit is real.
2. Use Strong, Unique Passwords and a Password Manager
"Admin" and "password123" aren't jokes — they're among the most common credentials found on compromised sites. Brute-force attacks and credential-stuffing bots cycle through common username/password combinations continuously.
Strong password hygiene for a business website means:
- A password that's at least 16 characters, mixing upper and lowercase letters, numbers, and symbols A different password for every account (hosting, domain registrar, CMS, FTP, email, etc.) Two-factor authentication (2FA) enabled on every account that supports it
The practical way to do this without memorizing anything: use a password manager. 1Password, Bitwarden, and Dashlane are all solid options. The annual cost is trivial. The alternative — reusing passwords across accounts — means one compromised account can cascade into all of them.
Account Type 2FA Available? Priority Domain registrar (GoDaddy, Namecheap, etc.) Yes Critical Hosting control panel Yes Critical WordPress admin Via plugin (e.g., WP 2FA) High Google Business Profile Yes High Email account Yes Critical Social media accounts Yes MediumDomain registrar access is especially critical. Someone with access to your domain registrar can redirect your entire website and email to a server they control. Losing your domain is a nightmare scenario that 2FA prevents.
3. Install an SSL Certificate (and Make Sure It Stays Current)
If your website address starts with http:// instead of https://, you have a problem. SSL certificates encrypt the connection between your visitors' browsers and your server, which protects any data they submit — contact forms, payment information, login credentials.
Google has marked non-HTTPS sites as "Not Secure" in Chrome for years, and it's a ranking signal. Visitors who see that warning in their browser leave immediately. Most hosting providers include free SSL certificates via Let's Encrypt, so there's no cost excuse.
The catch: SSL certificates expire (typically every 90 days for Let's Encrypt, annually for paid certificates). When one expires, browsers throw a hard security warning that looks alarming and sends your bounce rate into the stratosphere. Set a calendar reminder 30 days before your certificate expiration date, or use a hosting provider that handles auto-renewal.
4. Run Regular Backups — and Test Them
Backups are the safety net that makes everything else less catastrophic. If your site gets compromised, infected with malware, or accidentally broken by an update, a recent backup means the conversation is "how do we restore this?" rather than "did we lose everything?"
The backup strategy that actually works:
- Daily backups of both your website files and your database Offsite storage — backups stored on the same server as your site can be wiped in the same attack 30-day retention minimum, so you can recover from something that went unnoticed for a few weeks Tested restores — a backup you've never tested is a backup you can't trust
Most quality hosting providers (SiteGround, WP Engine, Kinsta, Cloudways) include automated daily backups in their plans. If web design Bellingham WA yours doesn't, a plugin like UpdraftPlus can send backups to Google Drive or Dropbox automatically.
5. Limit Login Attempts and Change Default Login URLs
WordPress sites by default allow unlimited login attempts at the standard /wp-admin URL. Bots know this. They hammer that URL with credential combinations continuously.
Two fixes, both simple:
Limit login attempts. A plugin like Limit Login Attempts Reloaded will lock out an IP address after a configurable number of failed attempts (three to five is typical). This stops brute-force attacks cold.
Change your login URL. Changing /wp-admin to something non-standard (like /site-manager or /your-company-name-login) dramatically reduces automated attack traffic, because bots don't know where to look. This isn't security through obscurity as a primary strategy — it's friction reduction that works well as a secondary layer.
Neither of these requires any technical knowledge. Both take about five minutes to implement.
6. Monitor for Malware and Unexpected Changes
The worst security scenarios are the ones that go undetected for weeks or months. Attackers who compromise a site often don't want to announce themselves — they want to quietly use your domain to send spam emails, serve malicious ads to your visitors, or build SEO links to sketchy websites. You might not notice anything is wrong until Google Search Console sends you a warning or a customer tells you your site is showing casino ads.
Active monitoring catches these situations early:
- Google Search Console is free and will notify you if Google detects malware or unusual activity on your site Wordfence (WordPress plugin) does real-time malware scanning and firewall protection Sucuri SiteCheck is a free tool to scan any site URL for known malware signatures
Set up Google Search Console if you haven't already. It takes 15 minutes and provides ongoing visibility into how Google sees your site — security issues, crawl errors, and ranking data all in one place.
Working With a Professional Helps
If this list feels overwhelming, it doesn't have to all happen at once. Start with SSL, 2FA on your critical accounts, and regular backups. Those three measures alone close the most common attack vectors.
For businesses undergoing a site rebuild or redesign, it's worth raising security configuration with whoever is building your site. Studios like Stambaugh Designs bake these practices into every build rather than treating them as afterthoughts — so you're not inheriting a security debt on a brand-new site.
The goal isn't an impenetrable fortress. It's making your site a harder target than the next one, which is usually enough.
Quick Reference: Security Baseline Checklist
- SSL certificate installed and auto-renewing All CMS software, plugins, and themes updated Unique, strong passwords on all accounts 2FA enabled on domain registrar, hosting, and email Daily automated backups with offsite storage Login attempt limiting enabled Default admin login URL changed (WordPress) Google Search Console connected and verified Malware scanner active (Wordfence or equivalent)
About the Author: [AUTHOR_BIO]
Stambaugh Designs - Bellingham Web Design & Marketing 1505 N State St, Bellingham, WA 98225 (360)383-5662