Virgola
← All posts

3 August 2026

Basic website security checklist for small NZ businesses

Most website security problems aren't sophisticated attacks — they're weak passwords, missing HTTPS, and old logins nobody's cleaned up. A practical checklist.

Most small business owners picture website security as something out of a heist film — a sophisticated hacker specifically targeting them. In practice, almost none of it looks like that. It’s automated bots scanning thousands of sites for the same handful of easy openings: weak passwords, out-of-date software, forms with no spam protection. None of the fixes below need technical skill — they’re mostly about closing obvious doors, not building a fortress.

Passwords and who has access

The single biggest security hole on most small business sites is login access nobody’s audited in years. Worth doing right now:

HTTPS isn’t optional anymore

If your site doesn’t show a padlock in the address bar, browsers actively warn visitors it’s not secure — which kills trust instantly and is genuinely embarrassing for a live business site in 2026. Most modern hosts (including the one we build on, Cloudflare Pages) issue this automatically for free, so if you’re seeing this warning, it’s almost always a DNS or hosting misconfiguration worth raising with whoever manages your site, not something to live with.

Forms are a common, overlooked opening

A contact or quote form with no spam protection doesn’t just fill your inbox with junk — it’s a common vector bots use to attempt more serious attacks, and a flood of spam submissions can quietly bury the one genuine enquiry you actually wanted. A basic spam filter (like Cloudflare Turnstile, which we use on our own contact form) blocks the vast majority of it without adding friction for a real customer filling it out.

Keep software current — or avoid needing to

If your site runs on WordPress or a similar CMS, out-of-date plugins and themes are the most common way small business sites actually get hacked — an old, unpatched plugin is a known, published vulnerability that automated bots actively scan for. Staying current matters enough that it’s usually worth a proper maintenance plan rather than hoping someone remembers; we’ve written a full checklist for what a maintenance plan should include. A static site with no database and no plugins avoids most of this category of risk entirely, which is one of the quieter advantages of that kind of build.

Watch for phishing aimed at your business, not just your site

A lot of “website security” incidents don’t start with the website at all — they start with a fake invoice, a spoofed email pretending to be your hosting provider, or a text claiming your domain’s about to expire. Slow down before clicking a link in an unexpected billing email, and go directly to the provider’s actual site to check rather than trusting the email’s link.

If something does go wrong

The honest answer

Website security for a small NZ business isn’t really about defending against a targeted, sophisticated attack — it’s about not being the easiest target in an automated scan. Old logins, weak passwords, missing HTTPS, and unpatched plugins are the openings that actually get used. Close those, and you’ve dealt with the overwhelming majority of real risk.

Ready to talk?

We build fast, considered websites for small businesses across Nelson and the Top of the South.

Get in touch