Back to all answers

/ Web design

How do I keep my website secure?

Update everything monthly, use strong unique passwords with 2FA, keep offsite backups, and remove plugins you don't use.

/ 01

The short version

Small business sites get hacked by bots scanning for known vulnerabilities, not by targeted attackers.

/ 02

What actually matters

  • Patch CMS core, themes and plugins monthly.
  • 2FA on every admin account.
  • Automated offsite backups you've actually tested restoring.
  • Delete unused plugins and old admin accounts.
  • A web application firewall (Cloudflare's free tier is fine) blocks most noise.

/ 03

The bit most people get wrong

Backups nobody has ever restored aren't backups. Test one this quarter.

/ 04

What to do next

Audit your admin users today and remove anyone who's left. Then check when your last successful backup ran.

/ 05

Where RIOT fits in

We're a small Colchester studio helping UK SMBs get website security right without agency waste or freelancer flake. If you've read this far and you want a second opinion on your specific setup, book a 20-minute call and we'll tell you honestly whether it's worth doing anything at all.

We work with clients across Essex, Suffolk, London and the wider UK — and remotely with brands abroad. No lock-in, no monthly retainer minimums, no pretending your problem is bigger than it is.

/ FAQs

Common questions

What if I get hacked?

Restore from clean backup, patch the hole, change all passwords.

Is WordPress more risky?

Only because it's the biggest target and plugins go stale.

Still not sure?

Book a free 20-minute call — we'll answer your specific version of this question with no sales pitch.

Book a call
Ashley Scott
Studio Lead
speak to Ashley