Back to Insights

Website Security: The Questions Every Business Owner Should Ask

17 Aug 20263 min read

An orange door bolt is fastened across a plain cream wooden door.

Your website may handle enquiries, applications, customer accounts or simply the information people rely on before contacting you. Keeping it secure means looking after those everyday uses, not only protecting a homepage.

You do not need to understand every technical setting. You do need to know who is responsible for the website, what they maintain and how they would respond to a problem.

Start with these questions.

Who Can Change The Website?

Ask for a current list of people and suppliers with administrative access. Include the CMS, hosting and domain accounts, because they are separate parts of the website’s operation.

Check whether everyone still needs the access they have. Former staff and completed supplier projects should not leave behind unexplained accounts.

Use individual accounts where possible so responsibilities are clear. Avoid passing one shared password between colleagues.

CISA’s guidance on multifactor authentication recommends adding another verification step to supported accounts. Ask your provider to help your team set this up and document an appropriate recovery process, rather than relying on one person’s phone.

Who Keeps The Software Current?

A website can depend on a CMS, extensions, themes and other software. Ask who checks for relevant updates and who is responsible for applying them.

The FTC’s small-business security guidance includes regular software updates among its basic precautions.

For your website, make the responsibility specific. Does the support arrangement cover the whole system or only selected parts? How are important changes tested? Who confirms that forms and other essential functions still work afterwards?

Do not assume that a hosting payment includes every kind of website maintenance.

Could You Recover The Website?

A backup is useful only if the right information was saved and your team knows how to restore it.

Ask what is included: website files, uploaded media, content and any data needed for the site to operate. Find out whether the backup is separated from the system it protects and who can access it.

Then ask when recovery was last tested. A message saying “backup completed” is not the same evidence as successfully restoring a working site.

The NCSC’s small-organisation guidance treats backups as a core part of protecting a business. Your own arrangement should reflect what you could afford to lose and what must be available first.

What Information Are You Collecting?

Review the website’s forms. Does each requested detail serve a clear purpose? Who receives it, where is it stored and when is it no longer needed?

Avoid collecting sensitive documents through a general enquiry form simply because an upload field is available. Agree a suitable process for information that needs greater care.

Ask your provider to explain the boundaries of their responsibility. Protecting the connection to a form, delivering the submission and controlling access to the stored information are different jobs.

Your internal handling matters too. A securely delivered enquiry can still be mishandled after it reaches the business.

How Would You Handle A Suspected Problem?

Keep a short contact and escalation plan somewhere your team can reach if the website is unavailable.

It should name the person who coordinates the response, the provider to contact and who can authorise urgent action. Agree how customer-facing communication will be reviewed.

If you notice unexpected redirects, unfamiliar changes or security warnings, record what you saw and contact the responsible team. Do not circulate credentials or customer data while trying to explain the problem.

Avoid making hurried, uncoordinated changes that could erase evidence or complicate recovery. Let the appropriate technical team investigate.

What Evidence Will You Receive?

“Security included” is too broad to be a useful handover.

Ask for a plain-language record of the work covered, the important exclusions and how your team will know when action is needed. Review it when staff, suppliers or website functions change.

No arrangement can promise that nothing will ever go wrong. Clear ownership and routine care are more useful than that promise.

Talk to us about your website’s ongoing care if you need help clarifying the responsibilities.

Website SecurityWebsite Maintenance

Other Related Articles

View All