Notes

How to keep your Norfolk business website secure in 2026 without the jargon.

Security isn't optional anymore. Here's what Norwich small businesses need to do to protect their websites, customers and reputation.

Atanas Kyurkchiev
13 Sept 2026 · 4 min read

Photo by Pixabay on Pexels

Most Norfolk small businesses we talk to treat website security as something that happens in the background, a box ticked during the build and then forgotten. Until something goes wrong.

A compromised website doesn't just mean downtime. It means customer data at risk, your Google ranking tanking, and your reputation taking a hit that's hard to recover from. In 2026, with AI-powered attacks getting smarter and cheaper to deploy, security has moved from nice-to-have to essential.

Here's what you actually need to do, without the technical noise.

Start with HTTPS and keep your certificates current

If your website still runs on HTTP (no padlock in the browser bar), you're actively telling customers their data isn't safe. HTTPS encrypts the connection between your site and your visitors. It's been table stakes since around 2018, but we still see Norfolk businesses running unencrypted sites.

SSL certificates need renewing, usually annually. Let them lapse and browsers will throw up a scary warning before anyone reaches your homepage. Most modern hosting platforms automate this with free Let's Encrypt certificates. If yours doesn't, that's a red flag about your hosting quality.

Set a calendar reminder three weeks before your SSL expires. If you don't know when that is, ask your developer or host today.

Keep your website software up to date

Every plugin, theme and core platform (WordPress, Shopify, whatever you're running) gets security patches. Attackers scan for sites running outdated software with known vulnerabilities, then exploit them at scale.

If you're on a care retainer, your developer should handle updates as part of the service. If you're managing it yourself, you need a monthly routine:

  • Log in to your CMS dashboard
  • Check for available updates
  • Run them on a staging site first if you have one, otherwise back up before updating live
  • Test key pages and forms afterwards

Putting this off for six months turns a small maintenance job into a risky overhaul.

Back up your site properly (and test the backups)

Backups are your undo button. If your site gets hacked, corrupted or accidentally broken, a recent backup means you're back online in hours instead of weeks.

What counts as a proper backup:

  • Automated and frequent: daily for e-commerce or booking sites, weekly minimum for brochure sites
  • Stored off-site: not just on the same server as your website
  • Tested: a backup you've never restored is a backup you can't trust
A backup you've never restored is a backup you can't trust.

Many hosts include basic backups, but read the small print. Some only keep them for seven days, others charge to restore them. If your site handles customer orders or bookings, you need a backup strategy you've actually verified works.

Use strong passwords and two-factor authentication

Weak admin passwords are still one of the easiest ways into a website. "Password123" or your business name with a couple of numbers won't cut it.

Use a password manager (1Password, Bitwarden, anything reputable) to generate and store complex passwords. Then turn on two-factor authentication (2FA) for every login that offers it: your CMS, your hosting account, your domain registrar.

2FA means even if someone gets your password, they still can't get in without the second factor (usually a code from your phone). It's a small friction that stops most attacks cold.

Limit who has admin access

Every extra person with full admin rights to your website is another potential weak link. A former employee's login still active six months after they left, a contractor who never deleted their account, a family member who helped set something up in 2019.

Audit your user accounts quarterly. Remove anyone who doesn't need access anymore, and downgrade people to the minimum permission level they actually require. Your receptionist booking blog posts doesn't need the same access as your developer pushing code.

If you've lost track of who has access to your site, that's a security problem. Start with a full audit this week.

Monitor for problems before customers notice

Uptime monitoring tools (many are free for basic use) ping your website every few minutes and alert you if it goes down. Security plugins can scan for malware, suspicious file changes and login attempts from dodgy IP addresses.

Catching a compromise early, before Google blacklists you or customer data leaks, makes the difference between a quick fix and a full crisis.

What this looks like in practice

For most Norfolk small businesses, good security isn't about building Fort Knox. It's about consistent, boring habits:

Key takeaways

  • Keep software and certificates up to date every month
  • Back up daily or weekly, store off-site, and test you can restore
  • Use strong passwords, turn on 2FA, and audit who has access
  • Monitor uptime and scan for threats before they escalate

If you're on a care retainer with a developer, most of this should already be handled. If you're doing it yourself, block out an hour a month to run through the checklist. And if you're not sure what's in place right now, that's the first thing to fix.

Your website is too important to your business to leave security to chance.

More notes