TechGurus
Strategy Automation Intelligence
Client login ↗Book a Strategy Call
Resources / Guide

How small business websites actually get hacked

Not by somebody choosing you. By automated scanning that tries a list of published weaknesses and moves on. The four ways in, what AI actually changes, and the question of who is responsible for any of it.

7 minute readWritten for owners and operations managers

Most owners picture a break-in as somebody choosing them: a person deciding your business is worth the effort, then going after it. That happens, and it is not what happens to small businesses.

What reaches you is automated and indifferent. A script works through addresses, tries a list of weaknesses that became public knowledge weeks ago, and moves on within seconds if none of them work. Nothing about it is personal, which is the part worth understanding, because it means being uninteresting protects nobody. Being up to date does.

Nobody chose your website. Something found it, tried a list, and moved on when nothing worked.

The four ways in

Almost everything we are called in to look at comes down to one of four things, and they are not exotic.

What it looks likeWhat actually stops it
Software left out of dateA plugin, theme or library with a published vulnerability, still running months after the fix shippedSomebody whose job it is to apply updates, on a schedule, with a staging site to test them on first
Accounts nobody closedLogins for people who left, a password three people share, no second factor on the adminA list of who has access, reviewed whenever somebody leaves, and multi-factor on anything that matters
Things left exposedAn old staging copy, a forgotten subdomain, an admin page open to the world, a backup sitting in a public folderKnowing what you have actually published, and taking down what you no longer use
Anything that accepts inputForms, file uploads, search boxes, and now anything wired to an AI modelChecking what comes in, limiting what each feature is allowed to reach, and testing it with input designed to misbehave

Notice that three of the four are housekeeping rather than engineering. That is genuinely the shape of it. The dramatic version gets written about; the mundane version is what happens.

Where AI changes the picture, and where it does not

Two things are true at once, and they get muddled together in the coverage.

The first is that the tooling for finding weaknesses has become cheaper and faster to run. That does not create new holes in your website. It shortens the time between a weakness becoming public and something turning up to try it, which makes the gap between an update being released and you applying it more expensive than it used to be. The answer is the same answer as before, applied sooner.

The second is genuinely new, and only applies if you have added AI features. Anything that takes text from the public and passes it to a model can be talked into doing something you did not intend, because the instructions and the input arrive through the same channel. And anything that gives a model access to your systems can surface more than you meant in an answer that looks perfectly ordinary. The question to ask of each AI feature is simple: what is it allowed to reach, and what happens when somebody deliberately pushes it?

The question nobody has answered

Ask who is responsible for keeping your website patched and you usually get a pause. Your host patches the server, not the plugins you installed on top of it. The developer who built it moved on when the project finished, and was never engaged to watch it. Your staff use it and reasonably assume somebody else is looking after it.

So the honest answer, in most businesses, is nobody. Not through negligence: it simply never got assigned, because it is the kind of work that produces nothing visible when it is done and is only noticed when it is not.

Fixing that costs less than most people expect. Name a person, agree how often they look, and give them somewhere to test an update before it reaches customers. Whether that person works for you or for somebody else matters far less than whether they exist.

A backup is not a plan until you have restored one

Every host advertises backups and most businesses assume that is the safety net. The questions that decide whether it actually is: can somebody restore one without raising a support ticket, how far back do they reach, and has anybody ever tried it?

An untested backup is a belief. The day you need it is the worst possible moment to discover it has been silently failing, or that it holds the website but not the database behind it. Restore one this quarter, to somewhere harmless, and write down how long it took.

If something does happen

Decide now who gets rung, because the first hour is where the damage is either contained or multiplied. And know that if personal information is involved and the breach is likely to result in serious harm, you have obligations under the Notifiable Data Breaches scheme to notify the people affected and the Commissioner. That is much easier to meet if somebody has thought about it in advance rather than on the day.

What to do this quarter

Five things, none of which need a security specialist to begin. Write down what your website actually runs on, including the plugins. Remove the logins of everyone who has left and turn on multi-factor for the rest. Agree who applies updates and how often. Restore a backup and time it. And write down who gets rung if something looks wrong.

If you get through that list you will have dealt with most of what actually reaches small businesses, which is a better position than most organisations several times your size.

The short version

You are not being singled out, and that is precisely why out-of-date software matters more than obscurity. Most of the risk is housekeeping that was never assigned to anybody: updates, old accounts, forgotten subdomains, and backups nobody has tested. Assign it, and the exotic threats in the headlines become somebody else's problem.

Not sure what you are actually running?

Tell us what the site is built on and who still has access. The security review is fixed-price and read-only, and you get findings ranked by what each would cost you.

Book a Security Review
Keep reading