HomeLearnWebsite Security Checklist for Businesses
Security checklist · Updated August 2026

Website Security Checklist for Businesses

Website security is an operating practice, not a plugin or a launch task. This checklist helps a business identify who owns each account, reduce avoidable access, maintain supported software, protect customer interactions, test recovery, and prepare for incidents.

1. Establish ownership and an inventory

Many website incidents become business crises because no one can reach the registrar, hosting account, backups, or deployment system. Ownership is a security control.

2. Protect administrative access

Unique identities

Give each administrator an individual account. Shared credentials remove accountability and make offboarding unreliable.

MFA

Require multi-factor authentication for registrar, DNS, hosting, content management, repository, deployment, email, analytics, and support systems.

Least privilege

Grant only the access required for the role and task. Separate content editing from site administration and infrastructure control.

Recovery

Protect recovery email, phone, codes, and backup administrators. Test recovery before an emergency and after staff or vendor changes.

3. Maintain the technology

Use supported operating systems, runtimes, content systems, themes, plugins, libraries, and integrations. Subscribe to security notices for critical components. Test and apply updates through a defined process, with backups and rollback for changes that could affect production.

Remove unused software rather than leaving it disabled indefinitely. Minimize third-party scripts because each one adds code, data flow, availability, and supply-chain risk. Restrict deployment permissions and protect the main branch or production release process from casual changes.

Configuration matters as much as versions. Review file permissions, secret storage, database access, administrative paths, directory listing, error output, development tools, default accounts, sample content, and exposed backups.

4. Protect customer interactions and data

Control areaChecklist
HTTPSRedirect all public traffic to HTTPS, monitor certificate expiry, and remove mixed content.
FormsValidate input, limit data collection, control uploads, prevent abuse, secure delivery, and define retention.
SessionsUse secure cookies, appropriate timeouts, protection against request forgery, and careful error messages.
PaymentsUse reputable payment services and avoid collecting or storing payment data the business does not need.
SecretsKeep API keys, passwords, and tokens out of public code, browser scripts, logs, and downloadable backups.
PrivacyKnow which data each form and third party receives, why it is needed, where it goes, and who can access it.

5. Back up for recovery, not reassurance

Back up the website files, databases, content, configuration, DNS, redirect rules, and other components required to rebuild service. Keep copies separate from the production account so one compromised or failed system cannot destroy both the site and its backup.

Define recovery point and recovery time expectations based on business impact. Protect backups from unauthorized access, record retention, and test restoration. A successful backup notification does not prove the website can be recovered.

6. Monitor and prepare for incidents

North Star provides website maintenance, hosting and care, and broader cybersecurity services for Canadian businesses.

Frequently asked questions

Website Security Checklist for Businesses FAQ

What is the most important website security control?

There is no single control, but business ownership of critical accounts, MFA, supported software, tested backups, and a named response owner prevent many common failures from becoming prolonged outages or permanent losses.

How often should website software be updated?

Review security notices and available updates continuously through a defined maintenance process. The appropriate installation timing depends on severity, exposure, compatibility, testing, and rollback readiness rather than an arbitrary calendar alone.

Does HTTPS make a website secure?

No. HTTPS protects data in transit between the visitor and the website. It does not replace secure software, access control, input validation, backups, monitoring, safe configuration, incident response, or protection of administrative accounts.

Should a website backup be stored on the same hosting account?

Not as the only copy. Keep recoverable backups separate from the production environment and protect them with access control and retention. Test restoration so the business knows the backup contains everything required.

Who should own a business website domain?

The business should control the registrar account, administrative contacts, renewal, MFA, and recovery process. A trusted provider may manage the domain, but ownership and the ability to transfer or recover it should remain with the business.

Turn the plan into a website that sells

North Star designs, rebuilds, hosts, and supports business websites remotely across Canada. Bring the checklist or brief to a scope call and we will translate it into a clear proposal.

Request a Website ScopeExplore Web Design