Here's a story I hear more often than you'd think. A local business, say a clinic, a café or a trade, has had the same website for a few years. It's worked fine. Then one day something's off. Their pages are full of dodgy links to things they've never sold. The booking form stops working. Or worse, Google slaps a big red "this site may be harmful" warning in front of anyone who searches for them.
They didn't do anything wrong. They got hacked. And the frustrating part is that it was almost certainly preventable, because for most small business sites, getting hacked isn't bad luck. It's the technology they were built on.
The large majority of small business websites in Australia run on WordPress, often with a pile of plugins, little add-on programs that bolt on extra features like a booking system, a photo gallery, a contact form, an SEO helper.
Plugins are the reason WordPress is so popular. They're also the reason so many sites get hacked.
Every plugin is a separate piece of software, written by a different developer, that needs to be kept up to date. The moment one falls behind, it can become an unlocked door. Hackers don't sit there guessing your password. They run automated bots across the whole internet looking for sites with a known, out-of-date plugin, and walk straight in through the gap. You don't need to be a target. You just need to be running the wrong plugin on the wrong day.
On top of that, a WordPress site has:
None of that is exotic or unusual. It's just a lot of doors, and every door is something that has to be locked, watched and maintained forever.
It's rarely dramatic. Most small-business hacks are quiet on purpose. The attacker isn't trying to deface your site. They're trying to use it. Usually one of two things:
By the time you notice, the cleanup bill (someone to find the breach, scrub the site, and beg Google to trust you again) often costs more than the site did.
Here's the thing that surprises people. You don't need to fight this battle at all. You can just build a website that doesn't have the doors in the first place.
The sites I build for clients are what's called static sites. In plain English, that means the website is a set of fast, finished pages served straight to your customer, with:
There's simply nothing there for the usual automated attacks to grab hold of. On top of that, every site is served from an enterprise-grade network (the same kind of infrastructure that runs some of the biggest sites on the internet), with a security certificate (SSL), modern security headers, and spam protection on the contact form, all as standard, on every plan.
It's a bit like the difference between a house with twelve doors and windows to lock every night, and a solid brick wall. The wall isn't "better secured". There's just far less to secure.
Fair question, because that booking system is often exactly where the old site got into trouble. The answer is to use a proper, dedicated provider for it (a purpose-built booking or payment platform whose entire job is to keep that data safe and working), and connect it neatly to your site, rather than bolting a cheap plugin onto your homepage and hoping. You get the feature, without inheriting the risk.
No one who's straight with you will promise a website can never be touched. Security is about removing risk, not pretending it's zero. But the specific thing that catches out most small businesses, an out-of-date plugin on a WordPress site quietly opening the door to spam, is a risk you can design out completely. That's the whole idea.
If your current site has ever been hacked, filled with spam, or you've just got a nagging feeling it's held together with duct tape, it's worth a chat. Rebuilding it properly usually costs less than you'd expect, and it means never having to think about this again.
12 Bar Digital, Largs North, Adelaide, South Australia. (08) 7077 0985. hello@12bardigital.com.au