Skip to main content

Digital Dialogue

Founder, CEO
Date: 04 September 2026
Follow Us

Your business is not too small to be hacked

“We’re a small business. Why would anyone want to hack our website?”

It is a question we hear far too often.

The uncomfortable answer is that cybercriminals may know nothing about your company. They may not know what you sell, how many people you employ or how much revenue you generate.

They do not need to know.

Automated systems continuously scan websites for outdated software, weak passwords, exposed files and known vulnerabilities. If your website has a weakness, it can be discovered regardless of the size of your business.

Your business does not have to be deliberately targeted. Your website simply has to be found.

Website attacks are increasingly automated

Website attacks were once thought of as highly targeted operations. A criminal would select a company, research its employees and create a plan to gain access.

Targeted attacks still happen, but many website attacks now begin with automated scanning.

Bots can inspect thousands of websites in a short period. They look for common weaknesses such as:

  • Outdated WordPress or Joomla software
  • Vulnerable plugins, themes or extensions
  • Weak administrator passwords
  • Abandoned user accounts
  • Exposed login pages
  • Incorrect file permissions
  • Malware left behind from an earlier attack
  • Unprotected forms and database connections
  • Websites without proper security monitoring

The scanner does not care whether it finds a national retailer or a small family business. It is looking for an opportunity.

Once a weakness is identified, an attacker can use it to install malware, redirect visitors, steal information, create hidden administrator accounts or use your website to attack other systems.

AI is making automated attacks more efficient

Artificial intelligence is helping attackers automate tasks that previously required more time and technical skill.

It can help them analyse software, identify potential weaknesses, create convincing phishing messages and adapt malicious code. This changes the economics of cybercrime.

AI is making automated attacks more efficient

An attacker can now search more websites and test more vulnerabilities with less manual effort.

The question is no longer:

“Why would someone choose our business?”

A better question is:

“What will an automated scanner find when it checks our website?

Being unknown does not make your website invisible

Some small businesses still rely on being relatively unknown as a form of protection.

Unfortunately, obscurity is not a website security strategy.

Your website is publicly accessible. It reveals information about the technology it uses, the services it connects to and, in some cases, the software versions installed.

Your online presence may include:

  • Your website and content management system
  • Website administrator accounts
  • Contact and enquiry forms
  • Customer or member accounts
  • E-commerce and payment integrations
  • Hosting and DNS services
  • Email addresses published on the website
  • Analytics and marketing platforms
  • Third-party plugins and services
  • Agencies, developers and suppliers with access

Every connection creates a potential point of entry if it is not properly managed.

What can happen when a website is compromised?

A compromised website can affect far more than its appearance.

An attacker may:

  • Redirect your visitors to fraudulent or adult websites
  • Insert spam pages and links into Google
  • Steal customer or enquiry information
  • Send spam or phishing emails from your hosting account
  • Add hidden administrator users
  • Install backdoors that allow them to return
  • Replace legitimate website files with malicious code
  • Damage your Google rankings and business reputation
  • Cause your hosting provider to suspend the website
  • Use your website as part of a larger criminal network

Cleaning the visible malware is not always enough. Backdoors, scheduled tasks and malicious database entries can remain hidden and reinfect the website later.

This is why ongoing website management matters.

Website security is not a once-off task

Installing a security plugin does not automatically make a website secure.

Your website changes over time. WordPress, Joomla, plugins, themes, PHP versions and hosting environments all receive updates. New vulnerabilities are discovered, old user accounts remain active and integrations change.

Without regular management, small problems can become serious risks.

Effective website management should include:

  • Regular WordPress or Joomla updates
  • Plugin, theme and extension updates
  • Reliable off-site backups
  • Security scanning and monitoring
  • Administrator account reviews
  • Strong passwords and two-factor authentication
  • Removal of unused software and accounts
  • Protection against common automated attacks
  • Monitoring for unexpected website changes
  • Testing after important updates
  • A clear recovery plan

Updates should also be handled carefully. Applying updates without checking the website can introduce errors, while ignoring updates can leave known security gaps open.

A managed approach balances security, stability and business continuity.

Backups are essential, but they must be reliable

A backup is one of the most important parts of website resilience.

However, simply having a backup plugin installed is not enough.

Backups should be:

  • Created automatically
  • Stored away from the website hosting account
  • Retained for an appropriate period
  • Checked for errors
  • Available when urgently needed
  • Tested to confirm that the website can be restored

If your backups are stored only on the same hosting account as your website, an attacker may be able to damage or delete both.

A reliable off-site backup gives you a safer recovery point when prevention fails.

Build website resilience before you need it

No security system can guarantee that an attack will never happen.

Website resilience is about reducing the risk and being prepared to respond when something goes wrong.

Ask yourself:

  • Would you know if an administrator account was created?
  • Would you notice if files changed unexpectedly?
  • Could you identify how an attacker gained access?
  • Do you have a clean backup stored elsewhere?
  • How quickly could your website be restored?
  • Who would investigate the problem?
  • Could your business continue operating while the website was offline?

These questions matter because the impact of an attack often depends on how quickly it is detected and contained.

Your website needs someone looking after it

Many business websites are launched and then left largely unattended.

The hosting company keeps the server running, but it may not manage your WordPress or Joomla website, check every update, review administrator access or investigate unusual changes.

That responsibility remains with the website owner unless a website management service has been put in place.

A professional webmaster service gives your business ongoing technical oversight. It helps keep the website updated, backed up, monitored and supported, while giving you someone to contact when something goes wrong.

It is not a replacement for wider cybersecurity across your email, staff devices and business systems. It is an important layer of protection for your website and online presence.

Your size is not your security strategy

Being a small business does not make you invisible.

You may never be personally selected by an attacker, but your website can still be discovered by an automated scanner.

If that scanner finds an outdated plugin, weak account or exposed file, the size of your business will not protect you.

Stop asking:

“Why would anyone hack our website?”

Start asking:

“What would happen if they did?”

Cartmell provides website management and webmaster services for South African businesses using WordPress and Joomla. We help keep your website updated, backed up, monitored and supported, so you are better prepared before a problem occurs.

Links: Webmaster Service |  You’re Not Too Small to Be Hacked. That Thinking Is So 2025. |  

Contact Cartmell to discuss professional website management for your business.