Online Security is something that all business owners who have a website, or who store data online or on their computer or laptop, should consider to be a priority.
Unfortunately, most don’t, and with website hacking on the rise, we wanted to share some experiences and advice.
The UK Government are continually evaluating the UK cyber security risks and below is a chart showing a worrying trend in website breaches, hacks, malware insertions.

What is even more concerning is that we ourselves have seen in particular malware injections happening to websites that we come into contact with. There is no commonality, and no rhyme nor reason.
Again the UK Government have tried to break this down. They have seen that of the 39% of UK businesses who identified an attack, the most common threat was phishing attempts (83%). Of the 39%, around one in four (21%) identified a more sophisticated attack type such as a denial of service known as DDOS, malware injection, or ransomware attack.
What we should elaborate on is that not everyone knows they have been attacked, and not everyone reports it. The 39% of UK business who identified an attack are likely to be a very small number of those who actually knew about it, or who reported it.
After all, a small local business will just sort it with their hosting company or web maintenance company and then try to take preventative measures.
Also bear in mind that hackers are always one step ahead. For example, a WordPress plugin is only updated for security when they have found a security hole, which is often discovered by an attack of some kind. By then, it may be too late.
There are things that we can do to protect ourselves. For example, you can add a Firewall, which masks the IP address of your website, making it harder to find an access point.
Let us share an experience of a website that moved from one server which will remain unnamed, to our UK based servers.
We copied both the site files and the database, after checking that the site looked fine (which it did). We then copied the same site files and database onto our servers and ran a standard malware scan. Something the other server did not have the facility to do.
39 malicious malware files and injected code were found.
We deleted the files, but the code is more specialist, after all, changing code can have a detrimental affect to any website. We recommended a solution to fix the problem, which was not expensive, in fact you could spend more on buying coffee at your local cafe if you liked a cup twice a day. The client decided it really wasn’t worth it anymore, and simply shut down his website.
His site had been hacked before, and he was a small, one-man-band and this was just one more thing that simply pushed him to that very final decision.
We think if there had not been Covid and then the cost of increased energy bills and lifestyle bills in the mix, he may have had the energy, the will and the desire to keep it running. But this is what hackers do, they look for weaknesses and exploit them.
When we consider our home security, we will have a lock on the front door, maybe on the windows, and possibly have CCTV as well. You may have a very thorny bush and a gravel path or driveway too, to help deter any intruder.
We know that if you are more protected than your neighbour, unfortunately it will be your neighbour who is the prime target over your more secure property or vehicle. It is no different with your website security.
Having a well built website and keeping up to date with plugins is one thing, having a paid for Firewall service and top quality hosting is another. These are an investment, but are never a guarantee you will not get hacked, but you will be that person in the street with the better protection, therefore the intruders are less likely to pick you.
if you are looking to move hosting company to a more secure server, like the one we use for our clients, then you need to consider the following process steps:
1) you need to make sure your emails are backed up
2) you will need to take a copy of your website files
3) you will need to take a copy of your database
4) you will need to be prepared with your new email settings, if you are not using Microsoft 365 or Google Business Workspace
5) you will need to expect a small amount of time without your SSL being in place, as this will have to be reordered and implemented
But the effort will be worthwhile.
If you need extra help or support, or just want to chat about the options, please feel free to contact us.





