Simple, non-tech steps to keep your website and business safe
Why Your Cyber Security Matters
Every October, Cyber Security Awareness Month reminds us to give our websites and online accounts a quick health check. At Cash Cow Marketing, we’re an SEO and web design team — but we’re often the first port of call when something goes wrong: a hacked WordPress site, a social media account taken over, or a shopping cart flagged as unsafe.
By the time it happens, it’s stressful, it scares people, and often, results are catastrophic. The truth is, cyber attacks don’t just hit big brands.
This year, the headlines have done the awareness job for us. A cyber attack forced Jaguar Land Rover to halt production for weeks; they’re only now carefully restarting parts of their operations after a month-plus standstill, with losses reported well into nine figures. It’s a stark reminder that attacks don’t just target banks and tech giants — manufacturers, retailers and their suppliers are all in scope.
Retail has had a rough run too. Marks & Spencer confirmed a cyber incident in spring that disrupted operations and involved some customer data, and the Co-op warned of a nine-figure profit impact from a sophisticated attack earlier in the year. Even when the supermarket itself isn’t directly hit, the supply chain can be — Sainsbury’s, for example, was affected when a key chilled-goods distributor suffered a ransomware attack, causing knock-on disruption.
But smaller businesses get caught up too, sometimes directly, sometimes because a supplier or plugin is the weak link. The good news? A few simple habits will prevent most common problems.
How cyber security affects marketing and sales
- Trust and sales: If a browser shows a warning or your site looks broken, people click away.
- Google and SEO: Search engines avoid sending people to risky sites.
- Time and money: Fixing a mess costs more than preventing it.
So here’s a straightforward, no-jargon checklist you can use today.
A friendly cyber security checklist for busy website owners
Think of this like locking your shop at night: simple habits, done regularly.
1) Keep your website and plugins up to date
Your website is built from parts (your CMS, theme, and plugins). Updates fix holes that attackers look for.
What to do:
- Turn on automatic updates where possible.
- Remove plugins you don’t use.
- Avoid plugins that haven’t been updated in ages.
2) Use strong passwords and MFA
MFA (Multi-Factor Authentication) means using two locks instead of one. After typing your password, you confirm it’s really you — usually with a code from your phone or an app.
What to do:
- Use a password manager (it remembers long, unique passwords for you).
- Turn on MFA for your website login, hosting, domain name account, email (Gmail/Microsoft 365), and social media.
- Never share a single “master” login with the whole team; create separate logins.
3) Make sure your site is fully on HTTPS
HTTPS is the little padlock sign in your browser. It means data sent between your site and visitors is encrypted.
What to do:
- Check you have a valid SSL certificate (your host can help).
- Make sure all pages load with the padlock (no “mixed content” warnings).
- Ask your developer/host to “force HTTPS” so every visitor sees the secure version.
4) Add basic protection to your site
A website firewall (often built into a security plugin or your host) filters out common cyber security attacks automatically.
What to do:
- Install a reputable security plugin or ask your host about their firewall.
- Limit login attempts (so attackers can’t guess your password forever).
- Change the default admin URL if your platform allows.
5) Back up your website (and know how to restore it)
A backup is a copy you can roll back to if something breaks. It’s your cyber security safety net. If in doubt, your hosting provider should be able to help with this — and it could already be included in your plan.
What to do:
- Set daily automatic backups of both files and database.
- Store at least one backup “Off-Page” (not just with your host).
- Test a restore every so often, so you know it works before you need it.
6) Tidy up who has access
Only the right people should be able to change your website or accounts.
What to do:
- Remove access for ex-employees or old agencies.
- Give people the lowest level of access they need (e.g., “editor” instead of “administrator”).
- Review access every quarter.
7) Protect your social media
If your Facebook or Instagram gets taken over, attackers can post spam or run ads with your money.
What to do:
- Turn on MFA for every social platform.
- Check who’s an admin. Remove anyone who no longer needs it.
- Review connected apps and remove anything you don’t recognise.
8) Train your team to spot phishing
Phishing is when someone tries to trick you into clicking a bad link or entering your password on a fake page.
What to do:
- Be suspicious of “urgent” messages about invoices, deliveries or password resets.
- Double-check unusual requests by phoning the person on a known number.
- If you’re unsure — don’t click. Ask someone to take a look first.
9) Have a one-page “break glass” plan
When something does go wrong, a calm checklist beats panic.
What to include:
- Who to call (host, domain registrar, payment provider).
- Steps to take (change passwords, turn on MFA, restore from backup).
- A short customer update you can reuse (“We spotted an issue, we’ve fixed it, here’s what we recommend you do…”).
10) Consider Cyber Essentials
Cyber Essentials is a UK badge that says you’re doing the basics well. It’s not mandatory for everyone, but it’s a helpful framework and can win trust with bigger customers.
When people call us “after the bang”
If you ever do get caught out, here’s how we usually help: we pause changes, save a copy of what we need for evidence, reset passwords, remove the bad code, update everything, and restore from a clean backup. Once the site is tidy, we help you ask Google to review it so warnings disappear. We then leave you with a short, simple plan to avoid repeat problems.
If you prefer not to think about this stuff at all, we can bundle the basics into your website care: updates, backups, access checks and simple monitoring. Quietly done in the background.
The Cyber Security questions UK businesses ask us most
As a web design agency, lots of people come to us in an emergency, asking for help. Here are some of the questions we’re asked most frequently about cyber security.
FAQs
What’s the single best thing I can do to improve my cyber security?
Turn on MFA for your most important accounts (website, email, hosting, domain name). It shuts the door on many common attacks. Learn more about the simple steps you can take now to avoid cyber attack here.
I’m on WordPress — how often should I update?
Check weekly. Turn on automatic updates for minor fixes, and remove plugins you don’t use. Big updates are best tested on a staging copy first.
Do I really need a password manager?
Yes. It creates and remembers strong passwords for you, so you can have a different one for every site without writing them down.
How do I know if my website has been hacked?
Common signs include strange pop-ups, new users you didn’t add, sudden slowdowns, or customers seeing warnings. Security plugins and your host can scan for problems.
What should I do if my browser says my website is “not secure”?
Ask your host to install/renew your SSL certificate and force HTTPS. Fixing this is usually quick and improves trust.
Are website firewalls worth it?
Yes. They block many automated attacks and bad bots. Think of it as a bouncer on the door — most trouble never gets inside.
My Facebook/Instagram was taken over — what now?
Recover access through the platform’s help centre, remove unknown admins, change your password, turn on MFA, and check for any connected apps or active ads you don’t recognise.
What is phishing and how do I avoid it?
It’s a fake message that tries to trick you into clicking or paying. Slow down, check the sender, and confirm unusual requests by phone. If in doubt — don’t click.
Do website security issues affect SEO?
Yes. Warnings scare visitors and search engines avoid risky sites. Fix the issue, request a review in Google Search Console, and your visibility can recover.
What’s the difference between HTTPS and HTTP?
HTTPS encrypts the connection (the padlock icon), protecting data between your site and your visitors. It builds trust and avoids warnings.
Need a hand?
If you’d like a quick, plain-English cyber security audit of your website and accounts, we’ll map out the risks, fix the basics, and put easy routines in place so you can get back to running your business.




