Website Security Basics: What to Do if Your Site Gets Hacked

Website Maintenance

Your website is the front door to your business, and weak website security can cost you customers, revenue and trust in a single afternoon. Most small business owners assume hackers go after the big names. They don’t. Hackers also target small sites because it’s easier. We just don’t hear about them as much.

What Is Website Security?

Website security is the set of measures used to protect your site, your data and your users from cyberattacks. It works by combining the right hosting setup, strong access controls, regular software updates and active monitoring so threats are blocked, spotted early, or contained when they get through.

For a small business, good website security covers four things. Your people, devices, and network. And the server that hosts your site. A weakness in any one of these can put the whole business at risk.

Why Do Hackers Target Small Business Websites?

Hackers don’t always pick targets based on size. They pick based on opportunity. A small business site running an outdated plugin is a much softer target than a large company with a dedicated security team, and the payoff can still be worth their time.

There are four common motivations.

  • Money. Stealing credit card details, banking logins or personal information. Bad actors use this data directly or sell it.
  • Ransom. Locking you out of your own site and demanding payment to restore access.
  • Hacktivism. Defacing a site to make a political, social or religious point.
  • Personal grudge or bragging rights. Sometimes there’s no commercial logic at all.

The result is the same in every case. Your site is down, your data is exposed, and your business has a problem.

How Bad Is the Threat in Australia Right Now?

According to the Office of the Australian Information Commissioner, 532 data breaches were reported in Australia between January and June 2025, with malicious or criminal attacks responsible for 59% of them. Breach numbers have been sitting at elevated levels for several years now, and the trend isn’t easing.

Two things to take from this. First, the threat is not slowing down. Second, it is no longer a problem only big companies worry about. The OAIC’s data shows breaches across every sector, from health and finance to government and small private operators.

And the cost is real. IBM’s 2025 Cost of a Data Breach Report puts the global average cost of a breach at USD 4.44 million. That’s a 9% decrease on the previous year, which IBM attributes to faster identification and containment of breaches. Small businesses won’t see figures that big, but the proportional hit can be worse, because most don’t have the cash reserves to ride out extended downtime.

What’s Actually at Stake?

When people picture a hack, they picture stolen data. That’s part of it, but it’s not the whole picture. Here’s what you’re really protecting.

Customer trust is the first thing to go, and once it’s gone it’s hard to get back. People remember which businesses leaked their details. Revenue is next. Every hour your site is offline is an hour you’re not taking orders or generating leads. Then there’s your data itself. Without a current backup, recovery can take weeks. Sometimes it’s not possible at all.

There’s also legal exposure to think about. If customer data is compromised and you didn’t take reasonable steps to protect it, you may be liable under the Privacy Act. And finally, reputation. Negative press from a breach can outlast the technical fix by years.

Prevention is significantly cheaper than recovery. Always.

How to Improve Your Website Security in 7 Steps

Most small business sites get hacked through predictable weak spots. Outdated software. Weak passwords. No backups. The seven steps below cover those weak spots, in order of impact.

1. Train Your Team to Spot Scams

Most breaches start with a person, not a machine. Someone clicks a link in a fake email. Someone hands over a password on a dodgy phone call. Your team is your first line of defence, and they need to know what to watch for.

Cover these four scam types.

  • Phishing. Fake emails that look like they’re from a bank, supplier or colleague, usually with an urgent tone and a link to a fake login page.
  • Smishing. Same idea, delivered by SMS. Common impersonations include Australia Post, the ATO and major banks.
  • Vishing. Phone calls from scammers pretending to be tech support, your bank, or a government agency.
  • Quishing. A newer one. A QR code in an email or printed material that leads to a malicious site.

The rule for every staff member is simple. If a request feels off, verify it through a different channel before acting. Pick up the phone. Walk to the desk next door. Never trust the original message to confirm itself.

2. Build Strong Password Habits

Passwords are still where most attacks start. Make sure your team is using long passphrases, never reusing them across sites, and storing them in a password manager rather than a notebook or a browser autofill.

Multi-factor authentication is no longer optional. Turn it on for every system that supports it. Email, your website admin, your hosting account, your social channels, your accounting software. Everything.

3. Keep Every Device Patched and Protected

A hacked laptop can become the doorway into your website. Three rules.

Run automatic software updates on every computer. Use reputable security software. Enable full-disk encryption so a stolen device doesn’t hand over your business in one go.

4. Lock Down Your Network

Your office network is part of your security perimeter, even if you’re a small team.

  • Change the default password on your router. Most people never do.
  • Turn on the router firewall.
  • Use WPA3 or WPA2 encryption for your wifi.
  • Set up a separate guest network so visitors aren’t on the same connection as your business devices.

5. Choose a Reliable Web Host

A good host does a lot of the heavy lifting for you. They keep server software patched, run their own firewalls, block known malicious traffic and back up your site automatically. A cheap, unmanaged host does none of this, and the savings are rarely worth it.

If you’re not sure whether your host is doing the work, ask them three questions. What software updates do you apply automatically? How often is my site backed up, and where are the backups stored? What’s your response time if my site is compromised?

If the answers are vague, change hosts.

6. Harden Your CMS

If your site runs on WordPress, Joomla or another open-source content management system, the platform itself isn’t the problem. Out-of-date versions and dodgy plugins are.

Practical steps.

  • Update your CMS, themes and plugins as soon as updates are released.
  • Only install plugins from reputable sources, and uninstall anything you’re not actively using.
  • Change the default admin username. Never use “admin”.
  • Enforce strong passwords and two-factor authentication for every user with access.
  • Apply the principle of least privilege. Give people the minimum access they need to do their job. A staff member who updates blog posts does not need full admin rights.
  • Limit failed login attempts to block brute-force attacks.
  • Install a reputable security plugin to monitor file changes and login activity.

7. Add a Layer of Third-Party Protection

For sites that handle payments or customer data, third-party security services are worth the investment. Common options include Cloudflare or Sucuri for web application firewalls and DDoS protection, and dedicated backup services like UpdraftPlus or BlogVault for off-server backups.

Off-server backups matter. If your host is compromised, an on-server backup may be compromised with it.

What Should I Do if My Website Gets Hacked?

If you suspect your site has been hacked, act in the first hour. Speed matters. Here is the response plan.

  1. Don’t panic, don’t delete anything. Evidence helps with recovery and root cause analysis.
  2. Tell your team and key stakeholders. A phone call first, then follow up in writing. Let them know passwords are being reset.
  3. Contact your web host immediately. They’ve seen this before, and they have tools you don’t. Most reputable hosts have an incident response team.
  4. Reset all passwords. Site admin, hosting, FTP/SFTP, database, email accounts linked to the business. Assume any password the attacker may have seen is now compromised.
  5. Take the site offline or restrict access to a single admin login while you investigate. A maintenance page is better than leaving a compromised site live.
  6. Scan the site for malware using a tool like Sucuri or MalCare. If your host offers a clean-up service, use it.
  7. Restore from a clean backup if available, ideally from before the breach occurred. Check the backup date carefully. Restoring from after the attack reintroduces the problem.
  8. Update everything. CMS, plugins, themes, PHP version. Patch anything out of date.
  9. Document the incident. When it was discovered, who found it, what you did, what you changed. This becomes your record for any reporting obligations and your reference for next time.
  10. Check your notification obligations under the Notifiable Data Breaches scheme. If customer personal information was exposed and serious harm is likely, you may need to notify affected individuals and the OAIC.
  11. Review what got through. Once the site is clean, work out how the attacker got in. Then fix that specific weakness before you go live again.

If you don’t have the internal capacity to do this, get help quickly. The cost of a security professional for a day is small compared to the cost of getting it wrong.

Comparison table showing six security layers: managed hosting, multi-factor authentication, WordPress security plugin, web application firewall, off-server backups, and DDoS protection. Each row li...

Comparing Common Security Layers

Not every business needs every layer. Here’s a quick way to think about what fits.

LayerWhat it doesBest for
Managed hostingServer patching, automatic backups, basic firewallingEvery business
Multi-factor authenticationBlocks logins even if a password is stolenEvery business
Security plugin (WordPress)Monitors file changes, blocks brute-force attemptsWordPress sites
Web application firewallFilters malicious traffic before it reaches your siteSites with logins, payments or forms
Off-server backupsIndependent copy of your site if hosting is compromisedAny business that can’t afford to lose data
DDoS protectionKeeps your site up under traffic-flood attacksHigher-traffic or public-profile sites

Start with the top of the list. Work down based on risk and budget.

Start With the Basics

Most breaches start with something small. A weak password. An out-of-date plugin. A backup nobody checked. A staff member clicking the wrong link. The cost of fixing those before they’re a problem is a fraction of the cost of fixing them after. Get the basics covered. We can help if you want.

Let’s talk website maintenance.

Frequently Asked Questions

How do I know if my website has been hacked?
The common signs are sudden traffic drops, new files in your CMS you don’t recognise, redirects to unknown sites, browser warnings when visitors arrive, or Google flagging your site in search results. If you see any of these, treat the site as compromised until you can prove otherwise.
How long does it take to recover a hacked website?
A straightforward clean-up with a recent backup can be done in a few hours. A site with no clean backup, custom code or an unclear point of entry can take days or weeks. Recovery time is the single biggest argument for getting prevention right.
Do I have to notify customers if my website is hacked?
Possibly. Under Australia’s Notifiable Data Breaches scheme, you must notify affected individuals and the OAIC if personal information has been accessed without authorisation and serious harm is likely. The OAIC has guidance on what counts. When in doubt, ask a lawyer.
Is WordPress less secure than other platforms?
No. WordPress runs around 40% of the web, which makes it a popular target, but the platform itself is well-maintained. Most WordPress hacks come from outdated plugins, weak passwords or poor hosting, not from the core software.
How much should a small business spend on website security?
There’s no fixed number, but a sensible baseline is good managed hosting, MFA everywhere, an off-server backup service and a security plugin if you’re on WordPress. For most small businesses, that’s a few hundred dollars a year.

Related Articles