Skip to content
NewHost
Menu

Website Security Checklist for Small Businesses in South Africa

A website security checklist for small businesses - passwords, 2FA, SSL, updates, backups, email security and POPIA basics, in plain language you can act on.

By NewHost team · · 5 min read

Most small business websites are not hacked by someone targeting them personally. They are caught by automated tools scanning for weak passwords, outdated plugins and missing security settings. That is good news, because a short list of basics blocks the vast majority of those attacks. This checklist covers what a South African small business owner should check, in plain language, whether you manage the site yourself or pay a developer to do it.

1. Accounts and passwords

Your website is only as secure as the accounts that control it. That includes more than the website login:

  • Hosting control panel - whoever controls this controls everything.
  • Domain registrar - a hijacked domain can redirect your website and email.
  • Website admin (for example WordPress).
  • Email accounts, especially the one used for password resets.

For each one:

  • Use a unique, long password, stored in a password manager.
  • Turn on two-factor authentication (2FA). An authenticator app is stronger than SMS. See two-factor authentication with an authenticator app.
  • Give each person their own login. No shared "admin" password on a sticky note.
  • Remove access for staff, freelancers and former agencies as soon as they leave.
  • Make sure the business, not a developer, owns the domain and hosting accounts.

2. HTTPS everywhere

An SSL certificate encrypts traffic between visitors and your site and shows the padlock in the browser. Browsers now warn visitors on forms that are not secured.

  • Your site loads on https:// and redirects http:// to it.
  • No "not secure" or mixed content warnings on any page.
  • Your certificate renews automatically.

Free Let's Encrypt certificates are fine for almost every small business. Paid certificates mainly add higher validation levels, not stronger encryption.

3. Updates

Outdated software is the most common way in. This is especially true for WordPress plugins and themes.

  • Your content management system (WordPress, Joomla, etc.) is on the latest version.
  • All plugins and themes are updated, and unused ones are deleted (not just deactivated).
  • Plugins come from reputable sources. Never install "nulled" (pirated) premium plugins; they often contain malware.
  • Your hosting runs a supported PHP or Node.js version.
  • Someone is responsible for updates every week or fortnight - write down who.

If you run WordPress, read our WordPress security basics for specifics.

4. Backups you can actually restore

A backup is your undo button for hacks, bad updates and accidental deletions.

  • Automatic backups run at least weekly (daily if content or orders change often).
  • You keep at least one copy outside your hosting account.
  • Backups include both the files and the database.
  • You have tested a restore at least once.
  • You know how long backups are kept, so you can go back to before a problem started.

Our guide to a website backup strategy explains the 3-2-1 rule.

5. Forms, spam and data you collect

Contact forms, quote requests and online shops collect personal information, which brings POPIA obligations.

  • Collect only what you need. A contact form rarely needs an ID number.
  • Add spam protection (a honeypot field or a privacy-friendly challenge).
  • Link to a privacy notice explaining what you collect and why.
  • Don't email sensitive attachments around unprotected; store them securely and delete them when no longer needed.
  • Never store card numbers yourself - use a payment gateway's hosted checkout.

The Protection of Personal Information Act requires "appropriate, reasonable technical and organisational measures" to secure personal information (section 19), and notification of the Information Regulator and affected people after a breach (section 22). For your specific situation, it is worth getting advice from a privacy professional.

6. Email security

Your domain's email is part of your website's security. Criminals love to send invoices "from" small businesses with changed bank details.

  • SPF, DKIM and DMARC records are set up for your domain. See SPF, DKIM and DMARC explained.
  • Staff know to confirm any change of banking details by phone, using a number they already have.
  • Email accounts have strong passwords and 2FA where available.

7. Hosting basics

Your host handles the layers you can't see. Ask your provider, or check their documentation:

  • Are servers patched and monitored by the host?
  • Are sites isolated from each other on shared servers?
  • Is 2FA available on the control panel?
  • Do you get an alert when your account password changes?
  • How are backups taken, how long are they kept, and who does restores?

On NewHost, you can enable two-factor sign-in with an authenticator app and backup codes, you get an email alert when your password changes, SSL is free, and backups run automatically, with the support team handling restores.

8. Monitoring and a simple incident plan

  • An uptime monitor emails you if the site goes down.
  • Google Search Console is set up; it warns you if Google detects malware or hacked content on your site.
  • You have written down who to call if the site is hacked: your developer, your host, and your bank if payments are involved.
  • You know where your latest clean backup is.

What to do if you think you've been hacked

  1. Don't panic, and don't delete everything - you may need evidence.
  2. Change passwords for hosting, website admin and email, from a clean device, and enable 2FA.
  3. Contact your host's support team; they can help identify the problem and restore a clean backup.
  4. Update everything and remove unknown admin users, plugins and files.
  5. If personal information may have been accessed, consider your POPIA notification duties under section 22.

Frequently asked questions

How much does website security cost a small business?

Most items on this checklist are free: strong passwords, 2FA, updates and Let's Encrypt SSL. The main costs are your time, or a developer's time for regular maintenance, and possibly a paid backup or security plugin.

Is a free SSL certificate secure enough?

Yes. A free Let's Encrypt certificate provides the same encryption as a paid domain-validated certificate. Paid certificates mainly differ in validation level, warranties and support.

How often should I update my website?

Check for updates at least every week or two, and apply security updates as soon as they are released. Test major updates on a staging copy first if your site is complex.

Who is responsible for security, me or my web developer?

Legally, your business is responsible for the personal information it collects. Agree in writing what your developer and host look after, and make sure your business owns the accounts.

Want a host that handles SSL, backups and server security for you? Look at our web hosting plans or contact us for help moving your site.

Related guides

Ready to launch on NewHost?

Choose a plan and go live today, or tell us what you need and we'll recommend the right setup.