Sound familiar?
- You have not logged in to update the site for months
- Your security plugin keeps emailing you about failed logins
- Google Search Console has sent a security issues warning
- Strange admin users or unknown files have appeared
- Your host has warned you about malware or suspended the account
- Visitors are being redirected to spam or scam sites
Key facts
- Out-of-date plugins and themes are the most common way small business sites are compromised
- We apply and check updates, then test the site still works
- Login hardening: two-factor authentication, limited login attempts, no "admin" usernames
- Server hardening: correct file permissions, PHP execution blocked in uploads, XML-RPC disabled where not needed
- Security headers such as HSTS, X-Content-Type-Options and a sensible Content-Security-Policy
- Daily off-site backups so a clean restore is always possible
- Essential plan £25 a month + VAT includes updates, backups, uptime and security monitoring
How small business websites actually get hacked
Most attacks on small business sites are automated, not personal. Bots scan millions of sites for a known vulnerability in a particular plugin version, or try thousands of password guesses against wp-login.php. If your site is running an old version of a popular form, slider or page builder plugin, it will be found.
The other common routes are weak or reused passwords, abandoned plugins that no longer get security fixes, nulled (pirated) themes with backdoors built in, and old FTP or hosting control panel accounts that nobody remembers setting up.
If your site is already showing signs of a hack, go straight to hacked website repair or malware removal. This page is about stopping it happening.
What dijitul support does to secure your site
- Updates applied and checked. Core, plugins and themes updated, with a backup taken first and the site checked afterwards.
- Abandoned code removed. We flag plugins that have been closed or not updated for a long time and suggest maintained alternatives.
- Login protection. Two-factor authentication for admins, rate-limited login attempts, unique usernames, and removal of old user accounts.
- Hardening. File editing disabled in the dashboard (DISALLOW_FILE_EDIT), PHP execution blocked in the uploads folder, correct file and folder permissions, XML-RPC switched off if nothing uses it.
- HTTPS and headers. SSL working everywhere with no mixed content, HSTS, and sensible security headers.
- Monitoring. File change and malware scanning, uptime checks, and alerts if something looks wrong.
- Backups. Daily, off-site, and tested so we know they restore.
Beyond the website itself
A secure site also depends on the accounts around it. We check who has access to your hosting control panel, domain registrar and DNS, and make sure two-factor authentication is on where the provider supports it. A hijacked domain account is just as damaging as a hacked website. For DNS and domain questions see domain and DNS support, and for the wider business see cyber security support.
Quick checks you can do today
Before you talk to anyone, five minutes in your dashboard will tell you a lot:
- Count the pending updates. More than a handful, or anything months old, is a warning sign.
- Look at the user list. Remove anyone who no longer works with you, and check nobody is called "admin".
- Look for plugins that are installed but deactivated. They can still be exploited, so delete them.
- Check your site loads on https:// with a padlock and no warnings. If not, see SSL certificate support.
- Ask yourself where the last backup is and when it was tested. If you do not know, see website backups.
If any of these answers worry you, that is exactly what a monthly plan takes off your plate.
Your responsibilities under UK GDPR
If your website collects names, emails or enquiries, you are processing personal data, and UK GDPR expects you to keep it secure with appropriate technical measures. A site left unpatched for years is hard to defend as appropriate if it leaks form submissions or customer accounts. Keeping software updated, restricting admin access and holding backups are the basic, sensible steps. For the wider picture, see GDPR IT compliance.
Plans and pricing
Website security is not a one-off job, because new vulnerabilities are published every week. Our support plans are built around that:
| Plan | Price | Security cover |
|---|---|---|
| Essential | £25 a month + VAT | Updates applied and checked, daily backups, uptime and security monitoring |
| Business | £50 a month + VAT | Everything in Essential, plus 1 hour of fixes each month and priority support |
| Complete | £99 a month + VAT | Everything in Business, with 3 hours a month plus IT and Microsoft 365 helpdesk |
A one-off security review and hardening pass, with no plan, is £45 an hour + VAT. Get in touch to start.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
How much does website security cost?
dijitul support includes updates, daily backups, uptime monitoring and security monitoring in the Essential plan at £25 a month + VAT. A one-off security review and hardening with no plan is charged at £45 an hour + VAT, with a 30-minute minimum.
Is a security plugin enough to protect WordPress?
No. A plugin such as Wordfence or Solid Security helps, but it cannot protect you from an out-of-date plugin with a known hole, a weak hosting password or a missing backup. Security comes from keeping everything updated, limiting access and having a restore point you trust.
Why do I need updates if my site is working fine?
Many updates are security fixes for flaws that have been published. Once a flaw is public, automated bots start scanning for sites that have not patched it. A site can look perfectly normal while running vulnerable code, right up until it is compromised.
Do you add two-factor authentication to my website login?
Yes. dijitul support sets up two-factor authentication for administrator accounts, limits repeated login attempts and removes old or unused accounts. We also check two-factor is on for your hosting and domain registrar where those providers support it.
What happens if my site gets hacked while on a plan?
Because you have daily off-site backups and monitoring, we can usually find the change quickly and restore a clean copy, then close the hole that let the attacker in. Larger clean-ups beyond your plan's included time are charged at £45 an hour + VAT, and we tell you before starting.
Related
Hand it over and stop worrying
Updates, backups, monitoring and fixes from £25 a month + VAT. Real UK people on the phone.