/ Web design
How do I keep my website secure?
Update everything monthly, use strong unique passwords with 2FA, keep offsite backups, and remove plugins you don't use.
/ 01
The short version
Small business sites get hacked by bots scanning for known vulnerabilities, not by targeted attackers.
/ 02
What actually matters
- • Patch CMS core, themes and plugins monthly.
- • 2FA on every admin account.
- • Automated offsite backups you've actually tested restoring.
- • Delete unused plugins and old admin accounts.
- • A web application firewall (Cloudflare's free tier is fine) blocks most noise.
/ 03
The bit most people get wrong
Backups nobody has ever restored aren't backups. Test one this quarter.
/ 04
What to do next
Audit your admin users today and remove anyone who's left. Then check when your last successful backup ran.
/ 05
Where RIOT fits in
We're a small Colchester studio helping UK SMBs get website security right without agency waste or freelancer flake. If you've read this far and you want a second opinion on your specific setup, book a 20-minute call and we'll tell you honestly whether it's worth doing anything at all.
We work with clients across Essex, Suffolk, London and the wider UK — and remotely with brands abroad. No lock-in, no monthly retainer minimums, no pretending your problem is bigger than it is.
/ FAQs
Common questions
What if I get hacked?
Restore from clean backup, patch the hole, change all passwords.
Is WordPress more risky?
Only because it's the biggest target and plugins go stale.
/ Related
How long does a website take to build?
Web design
How much should a small business spend on a website?
Web design
Do I need an SSL certificate?
Web design
WordPress vs Webflow vs custom — which should I pick?
Web design
How do I choose the right web designer?
Web design
What is page speed and why does it matter?
Web design
Still not sure?
Book a free 20-minute call — we'll answer your specific version of this question with no sales pitch.
Book a call →