Security advisorywp2shell: WordPress core vulnerability. Updated August 7, 2026.

Read the advisory

Steps to secure your business online

A practical sequence for small online businesses: risk priorities, updates, network basics, staff training, access control, and shadow IT without the brochure voice.

Topics Hardening & checklists Beginner guides

Lars Koudal

Updated Published

Running a business online means email, cloud apps, and usually a website people can reach from anywhere. Attackers automate the easy wins: stolen passwords, unpatched software, and staff who click a convincing invoice.

You do not need a hundred-tool stack. You need a short sequence you will actually maintain. For WordPress-heavy shops, pair this with the WordPress security checklist and security guide.

1. Know what matters and what you can lose

Planning priorities

List the systems that would hurt if they failed or leaked: domain registrar, email, hosting, payment tools, CRM, accounting, and the website. Rank by impact, not by what is trendy to buy.

Write down who owns updates and who gets the 2 a.m. call. A one-page risk list beats a binder nobody opens. More context: WordPress website risk management.

2. Keep systems updated

Malware and patching

Unpatched software is still how many incidents start. WannaCry hurt organizations that skipped available Windows updates; WordPress shops see the same pattern with abandoned plugins.

  • Turn on automatic updates where you trust them (OS, browsers)
  • Schedule WordPress core, plugin, and theme updates; test checkout on staging when you sell online
  • Retire devices and apps that no longer receive patches

Depth on plugin risk: WordPress plugin security risks and the vulnerabilities hub.

3. Secure the network you actually use

Password and network hygiene

  • Unique Wi-Fi passwords; separate guest Wi-Fi from the office LAN when you can
  • VPN for staff on public networks who touch admin or customer data
  • Segment when the business is large enough that “everything on one flat LAN” is reckless
  • Firewall defaults that deny junk; do not expose RDP or database ports to the world

Home-office and travel habits matter as much as the office router. See security issues at public events and keeping data safe when working remotely.

4. Train people on phishing and passwords

Employee training

One rushed click can install malware or hand over email MFA codes. Short, regular training beats annual theater.

Cover password managers, phishing tells, and how your real vendors contact you. Require two-factor authentication on email, banking, hosting, and WordPress admins. Login depth: WordPress login security guide.

5. Control access on purpose

Access control

Least privilege means people see what their job needs, not the whole company drive.

  • Separate WordPress roles instead of everyone as Administrator (user roles)
  • Remove accounts the day someone leaves
  • Vendors get time-boxed access, not permanent admin
  • Review sharing links in Google Drive, Dropbox, and similar tools quarterly

6. Reduce shadow IT

Shadow IT risk

Shadow IT is the unpaid SaaS and browser extensions staff adopt because official tools feel slow. Data then lives in places you do not back up or control.

  • Ask teams which tools they already use before you ban everything
  • Approve a short list; block the dangerous unknowns at DNS or SSO when you can
  • Prefer SSO and centralized billing so accounts leave with the employee

Defense in depth, not one product

Defense in depth means updates, MFA, backups, least privilege, and monitoring work together. A single security plugin or antivirus license is not a program.

Customer data specifics: protecting customer data. Testing when you are ready: penetration testing for small business.

Short business security checklist

  • Asset and owner list for critical systems
  • Patch cadence for OS, apps, and WordPress
  • MFA on email, money, domain, hosting, and admins
  • Least privilege and offboarding that happens same day
  • Backups tested; phishing awareness ongoing
  • Approved tool list; fewer random SaaS logins

Secure the business the way you secure a shop floor: clear owners, boring routines, and no shared keys under the mat.

Found this useful? Share it.