Skip to content
هذه الصفحة بالإنجليزية. اقرأها بالعربية
UpgradIQ
Insights

Security is a subscription and a habit, not a purchase

Most incidents on ordinary business sites are automated and unglamorous. So are the defences, which is why they are affordable and why they are so often skipped.

6 min readWeb development
The short answer

For a typical business site, the direct costs are modest: a firewall in front, managed updates, backups stored away from the server and tested, and two-factor authentication on every account. What costs real money is not having them on the week you need a restore.

What actually happens to ordinary sites

Almost nothing on a normal business site is a targeted attack. It is automated scanning for known weaknesses in common software, credential stuffing against login pages, and spam injected into forms and content.

That is good news, because defending against automation is a different and much cheaper problem than defending against somebody who has chosen you specifically.

The recurring lines that do the work

These are the ones that prevent the ordinary incidents, and together they are usually smaller than a single month of media budget.

  • Updates applied on a schedule, with somebody accountable
  • Backups stored off the server, with a restore tested at least once
  • A firewall or proxy in front of the site
  • Two-factor authentication on hosting, registrar, and the site's own admin
  • Certificates renewed automatically, with an alert if renewal fails
  • Old accounts removed when people leave

The cost of not having them, stated as a worked example

Suppose the site is compromised and the last usable backup is a month old. The visible cost is the days spent cleaning and rebuilding. The larger cost is a month of content and orders that no longer exist, and the search damage from whatever was injected while nobody noticed.

Set against that, an untested backup is not a backup. It is a file that has never been asked to do the one thing it exists for.

Where spending more stops helping

Beyond the basics, the returns come from process rather than products: fewer accounts with administrative rights, no shared passwords, and a written procedure for what happens when something is wrong.

A monitoring product added to a site with shared logins and no tested restore is money spent on visibility into a problem you cannot yet respond to.

Answers

What to take from this

  • 01Ordinary sites face automation, which is cheap to defend against
  • 02Updates, tested backups, a firewall and two-factor cover most of the risk
  • 03An untested backup has never done the job it exists for
  • 04Beyond the basics, process beats buying another product
Nothing here answers it

Ask the question directly

Is managed hosting enough on its own?
It covers the server and often the platform updates. It does not cover your own accounts, your extensions or your passwords, which is where most ordinary compromises begin.
How often should a restore be tested?
Once when it is set up and once a year afterwards, into a separate environment. The test is whether a working site comes back, not whether a file downloads.
Do we need a penetration test?
If you handle payments or sensitive records, or a client contract requires it, yes. For a brochure site with the basics missing, the basics are a far better use of the same money.
Where it applies

Related answers

Service 02

Web development

New builds, rescues and re-platforms, measured against what the site earns rather than against how it looks. The brand system that carries it is built in the same engagement.

Bring the decision you are stuck on

A call, forty five minutes, no deck. We will tell you if we are the wrong firm.