The Number That Should Make You Uncomfortable
Small and midsize businesses made up roughly 96 percent of ransomware victims in Verizon’s 2026 Data Breach Investigations Report. Not because hackers have a grudge against small businesses but because small businesses are, statistically, the easiest targets. No dedicated IT team. Updates that slip for weeks. Admin passwords that haven’t changed since the site launched.
October is Cybersecurity Awareness Month, and CISA’s official 2026 theme is Securing the Next 250, a call to build digital resilience that lasts. The spirit of that theme applies just as much to the WordPress site you built for your business as it does to national infrastructure.
If you’ve already read our post on what to do after being hacked, this is the companion piece you need the prevention guide that ideally means you never need the other one.
Here’s the checklist. None of it requires a developer. All of it matters.
1. Keep Everything Updated Including the Stuff You Forgot About
Outdated software is the single biggest open door on a WordPress site. In July 2026, hackers actively exploited two critical WordPress core vulnerabilities affecting hundreds of millions of installations and the sites most at risk were simply the ones that hadn’t updated. Verizon’s 2026 DBIR found that exploiting unpatched vulnerabilities now accounts for 31 percent of all breaches, overtaking stolen credentials as the top initial access method.
What to update, and how often:
WordPress core enables automatic minor updates at minimum; check for major releases monthly.
Plugins every plugin is a potential entry point. Update weekly, and delete any plugin you’re not actively using. An inactive plugin sitting in your dashboard is still a liability.
Themes update your active theme monthly. Delete unused themes entirely, including the WordPress defaults.
If you’re on a WebKitty maintenance plan, this is already handled for you. If you’re managing your own site, set a recurring calendar reminder. Seriously, put it in your phone right now.
2. Lock Down Who Can Get In
Brute-force bots hammer WordPress login pages around the clock. They start with the username “admin” because a huge percentage of sites still use it. If yours does, change it today.
Beyond the username, here’s what access control actually looks like:
Multi-factor authentication (MFA). This is the single most effective barrier against credential theft. Even if a password gets phished or cracked, MFA stops the attacker before they’re in. Install an MFA plugin (Wordfence includes it for free) and turn it on for every admin account.
Strong, unique passwords. A password manager generates credentials that AI-powered cracking tools can’t touch. Use one. 1Password, Bitwarden, and others work well pick one and commit to it.
Limit login attempts. By default, WordPress lets anyone try to log in as many times as they want. A login-limiter plugin closes that window quickly.
Review your user list. Any editor, contributor, or admin account that no longer needs access should be removed. Old contractor accounts are a common forgotten risk.
3. Run Backups You’ve Actually Tested
A backup that hasn’t been tested isn’t a backup, it’s a hope. The goal here is simple: if your site gets wiped tomorrow, how long would it take you to restore it, and would the restore actually work?
The minimum standard:
Daily automated backups stored somewhere off your server (a separate cloud storage account, not just a folder on the same host).
Test a restore at least once. Knowing you have backups is not the same as knowing they work.
Keep at least 30 days of history so you can roll back past a compromise that went unnoticed for a few weeks.
Most quality managed WordPress hosts include daily backups. If yours doesn’t, plugins like UpdraftPlus or the BlogVault/MalCare suite handle this reliably.
4. Clean Up Your Plugin List
Here’s a question worth asking right now: how many plugins are installed on your site, and when did you last look at the list?
Plugins are the most common entry point for WordPress hacks. Every plugin is a potential vulnerability, especially popular ones like contact forms, page builders, and WooCommerce extensions. A few things to do today:
Deactivate and delete anything you’re not using. Deactivated plugins still exist in your file system and can still be exploited.
Only install plugins from reputable developers with recent update histories. An abandoned plugin, even a functional one, is a risk.
Don’t stack overlapping security plugins. Running three plugins that all try to manage your firewall, login rules, and file scanning creates conflicts and noise. Pick one solid security plugin and configure it properly. For most small business WordPress sites, Wordfence (free tier) covers the essentials: firewall, malware scanner, login protection, and MFA.
5. Add a Security Plugin and a Web Application Firewall
If you don’t have a security plugin installed, Wordfence is a strong starting point; the free version includes a real firewall, malware scanner, login rate limiter, and two-factor authentication. For sites running WooCommerce or collecting user data, consider adding Patchstack, which provides virtual patching for known vulnerabilities even before a plugin author ships a fix.
A web application firewall (WAF) at the network edge Cloudflare’s free tier works adds another layer before malicious traffic ever reaches your site. Think of it as a bouncer who checks IDs before anyone gets to the door.
6. Make Sure HTTPS Is Actually Working
Your site should load on HTTPS everywhere, with no mixed-content warnings. An SSL certificate encrypts the data passing between your visitors’ browsers and your server login credentials, contact form submissions, payment info. Most hosts provide free SSL via Let’s Encrypt. If your site still shows a browser warning or loads on HTTP, fix this first.
Once HTTPS is in place, check that all internal links, images, and scripts are also loading over HTTPS. Mixed content warnings are a sign that something’s still leaking.
7. Have an Incident Response Plan (Even a Simple One)
CISA’s guidance for small businesses recommends establishing an incident response plan as a basic security measure and it doesn’t have to be elaborate. A one-page document that answers three questions is enough:
1. Who do I call first if my site is compromised? (Your hosting provider, your web developer, your security plugin support.)
2. Where are my backups and how do I restore from one?
3. What do I tell customers if their data may have been exposed?
Writing this down before an incident means you’re not making panicked decisions in the middle of one.

Don’t Forget the Person Behind the Site
Your website’s security is only as strong as the accounts connected to it: your hosting login, your domain registrar, your Google account, your email. A breach of any of those can lead directly to your site.
That’s why, beyond the technical checklist, personal identity protection matters just as much. Verizon’s 2026 DBIR found that 73 percent of ransomware victims had a credential leak or infostealer infection in the year before their attack. Your login credentials are a target independent of your website.
We use IDShield through LegalShield for our own protection. It monitors for your personal information across the web, alerts you to credential exposures, and provides licensed investigators to restore your identity if the worst happens. If you want to see what we actually use to keep our computer and identity protected, [check it out here]().
FAQ
How often should I update WordPress plugins?
Weekly is the practical standard. Security vulnerabilities in plugins are publicly documented once a patch is released, which means unpatched sites become easy targets quickly. Set a recurring time each week to log in and run updates or move to a maintenance plan that handles it automatically.
What is the most important security step for a WordPress site?
If you can only do one thing, enable multi-factor authentication on your admin account. Even if your password is compromised, MFA stops an attacker from completing the login.
Do I need to pay for a security plugin?
Not necessarily. Wordfence’s free tier includes a firewall, malware scanner, login limiter, and MFA features that many paid competitors charge $99 to $149 per year for. The free tier lags Wordfence Premium by 30 days on new threat intelligence, which is an acceptable trade-off for most small business sites.
What should a WordPress backup strategy include?
Daily automated backups, stored off-server (separate cloud storage), at least 30 days of history, and at least one tested restore so you know the backup actually works.
What is Cybersecurity Awareness Month?
Cybersecurity Awareness Month is a national campaign held every October, led jointly by CISA and the National Cybersecurity Alliance. CISA’s official 2026 theme is Securing the Next 250, recognizing the nation’s 250th anniversary and focusing on building a secure digital future. For small business owners, it’s a useful annual checkpoint to audit your security habits before something goes wrong.
Is my identity at risk if my website gets hacked?
Yes. Attackers who gain access to your hosting account or WordPress admin can find credentials, email addresses, and other personally identifiable information stored in your files or database. Protecting your website and protecting your personal identity are two sides of the same problem.
Most small business websites get hacked not through sophisticated attacks but through obvious, preventable weaknesses: an outdated plugin, a reused password, no MFA, and no backup plan. Fix those and you’ve removed the low-hanging fruit that automated bots are constantly scanning for.
This October Cybersecurity Awareness Month is a natural moment to run through this list. It takes an afternoon, not a developer, and the cost of prevention is a fraction of the cost of recovery.
If you want to see what we personally use to protect our computers and identities, take a look here.



