Service

Websites do not get hacked, they get neglected

Almost nothing that takes a small business site down is targeted. It is automated, opportunistic, and aimed at a known hole somebody left open.

01

What actually happens, against what people picture

The mental image is someone choosing your business. The reality is a script working through every site on the internet looking for one specific unpatched version — which is good news, because the defence is unglamorous and mostly mechanical.

What people picture

  • Someone deciding to target this business
  • A sophisticated, novel attack
  • A problem you would notice immediately
  • Something a one-off security audit prevents

What actually happens

  • A bot scanning every site for one known hole
  • An abandoned plugin nobody updated in two years
  • Spam pages quietly added, found weeks later by Google
  • A login reused from a breach on another service
02

What is actually done about it

None of this is exotic. It is a short list of things that have to happen continuously rather than once, which is exactly why they lapse when nobody owns them.

  1. 01

    Reduce what can be attacked

    A custom build ships the code it uses and nothing else, so there is simply less surface than a site carrying a dozen plugins it half-uses.

  2. 02

    Patch on a schedule

    Dependencies and platform updates applied continuously, not when something breaks. Most incidents exploit a hole that had a fix available for months.

  3. 03

    Watch it

    Uptime and certificate monitoring, plus checks for the quiet failure modes — injected pages, unexpected redirects, a form that silently stopped delivering.

  4. 04

    Be able to go back

    Off-site backups, verified by actually restoring them. An untested backup is a belief, not a safeguard.

  5. 05

    Have a plan for the bad day

    Who is called, what gets taken offline, how the clean version goes back up, and what customers are told. Deciding that during an incident is how a small problem becomes a long one.

03

What this is, and what it is not

This is website security: the site, its hosting, its dependencies, its backups and its monitoring. It is the layer this studio builds and runs, and it is where the overwhelming majority of small-business incidents actually happen.

It is not a certification, an audit against a formal standard, or cover for your wider network, devices and internal systems. Those are a different discipline with different qualifications, and a website studio claiming them would be overreaching. If that is what you need, it is worth saying so plainly rather than being sold a monitoring plan.

Measured on this page, in your browser

What this page is actually doing

 
 
 
 
 
 
 
 

These are read from your browser as you look at this, not typed in by us. Open devtools and check them — that is rather the point.