Attacks are automated and indiscriminate. Software scans every reachable site for known weaknesses, so size is irrelevant and only your configuration matters.

Nobody chose you

The assumption behind why would anybody bother with us is that somebody decided to attack your business.

Almost nothing works that way. Software scans enormous ranges of addresses continuously, tries a list of known weaknesses against everything it finds, and records what worked.

No person looked at your site, considered your size, and decided you were worth the effort.

Which means being small offers no protection at all, because size was never an input.

What the software is looking for

Each of those is checked automatically, in seconds, against every site found. The list is published, shared, and updated whenever a new weakness is disclosed.

What they want it for

Not your customer records, usually, which is the other half of the misunderstanding.

A compromised small business site is useful as infrastructure: somewhere to send spam from, somewhere to host a page pretending to be a bank, or somewhere to hide links to other sites.

It can be used to attack visitors, or added to a network of machines used against somebody else.

All of those work better on a site nobody is watching closely, which describes a small business site precisely.

So being small is not merely no protection, it is mildly attractive for these purposes.

Your data may be taken as well, and it is frequently not the point.

The disclosure window

The mechanism that explains why updates matter so much and so urgently.

When a weakness in a widely used plugin is published, along with a fix, the publication tells everybody what to look for.

Automated scanning for that specific weakness begins within days and sometimes hours.

Which means a site running the outdated version is not at some vague long-term risk. It is being tested for that specific thing this week.

That is why updating promptly matters more than any other single measure, and why a site left unattended for months is at genuinely elevated risk rather than theoretically so.

A worked example

A business with a small brochure site and no customer data found their hosting suspended without warning.

The host had detected outbound spam originating from the account.

An outdated plugin, unused for two years and still installed, had a published weakness that had been fixed eight months earlier.

The site had been compromised and used to send mail, which nobody had noticed because the site itself looked normal.

Cleaning it, restoring from a backup, and getting the domain removed from blocklists took most of a week, during which their email was also affected.

Nobody had targeted them and the cost was the same as if somebody had.

The hosting account is a separate target

Worth separating, since attention goes to the site and the account underneath it is frequently weaker.

The hosting control panel, the domain registrar, and the email accounts all have their own logins, and compromising any of them is worse than compromising the site.

Somebody with the registrar account can move the domain entirely, which is considerably harder to recover from than a defaced page.

Those accounts are also the ones set up years ago, with an old password, by whoever built the site, and never revisited.

Check that you control the registrar account yourself, that its password is strong and distinct, and that two-step verification is on.

What actually reduces the risk

A short list, and it is unexciting.

Keep the platform, plugins, and theme updated, promptly rather than eventually.

Remove anything you do not use, since an inactive plugin still sits on the server.

Use distinct strong passwords and two-step verification on every account that has access.

Take backups that are stored away from the server and have been restored at least once.

Limit who has administrative access and remove people who have left.

That list covers the overwhelming majority of what automated attacks exploit, and none of it requires expertise.

Your visitors carry some of the cost

A consequence worth understanding, since it changes who this is about.

A compromised site can serve something harmful to the people visiting it, or collect what they type into a form.

Search engines and browsers detect that and display a warning in front of your site, which is seen by everybody arriving and is remembered.

Removing the warning requires cleaning the site and then requesting a review, which takes days rather than hours.

So the exposure is not only your own data and your own downtime, it is the customers who trusted the link, which is the part that damages a local business most.

Nobody will tell you

The reason this persists, and it is worth stating plainly.

A compromised site usually looks completely normal to its owner.

The spam goes out invisibly, the hidden pages are served only to search engines, and the injected links are visible only in the source.

Businesses typically find out when the host suspends the account, when their email stops being delivered, or when a warning appears in search results.

All of those arrive weeks after the fact, which is why checking rather than waiting to notice is the only approach that works.

Set up whatever monitoring your platform offers, and check the search console for security notices, which is free and takes a minute.

The counter-case

The risk should not be overstated either.

A simple site on a maintained platform, updated regularly, with good passwords, is at low risk, and the measures above are sufficient rather than a starting point.

Security services sold to small businesses are frequently expensive relative to the exposure, and a great deal of what they offer duplicates what the platform does.

There is also a version of this that produces paralysis, where somebody stops updating anything for fear of breaking it, which increases the risk considerably.

Update promptly, remove what you do not use, secure the accounts, keep tested backups, and do not buy anxiety.

What to do

  1. Update the platform and everything on it.
  2. Remove unused plugins and themes entirely.
  3. Set strong distinct passwords.
  4. Turn on two-step verification.
  5. Remove access for anybody who has left.
  6. Take backups stored off the server.
  7. Check for security notices monthly.

Step two is the one people skip, since a deactivated plugin feels harmless and is still a file on the server that can be reached.

What happens when it goes wrong is covered in a site that got hacked and what happened next.


Frequently asked questions

Why would anybody target a small business?

Nobody did. Software scans enormous ranges of addresses continuously, tries known weaknesses against everything it finds, and records what worked. Size was never an input.

What are they looking for?

Login pages at predictable addresses, common usernames with weak passwords, known holes in outdated plugins and themes, old platform versions, and exposed files.

What do they want it for?

Usually infrastructure: somewhere to send spam from, host a fake bank page, or hide links. All of those work better on a site nobody is watching closely.

Why do updates matter so urgently?

Because publishing a fix also publishes what to look for. Scanning for that specific weakness begins within days, so an outdated site is being tested for it this week.

How would I know I was compromised?

Usually you would not. The site looks normal, spam goes out invisibly, and hidden pages are served only to search engines. Most owners find out when the host suspends them.

What actually reduces the risk?

Prompt updates, removing unused plugins, strong distinct passwords, two-step verification, tested off-server backups, and limiting who has access.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Plugin you stopped using two years ago?

Delete it rather than deactivating it. A deactivated plugin is still a file on the server that can be reached.

Start a Conversation