Maybe you’re about to hire a web agency and you’re not sure what to ask beyond “how much?” and “how long?.” Or maybe you already have a website, and something’s nagging at you about whether it was actually built properly, or just built to be easy on the eye.
If you’re not technical, then security can be the least interesting part of your website build and for this reason is often the easiest element to forget, or not pay attention to as you assume it’s been dealt with. That’s right up until it’s a problem at which point the whole issue is suddenly very much front of mind. To that end here’s how to actually tell the difference between a website which was built with security in mind and one that wasn’t and, crucially for your business, what to ask so you don’t have to find out the hard way.
Why website security matters no matter your sector
You might run a reasonably straightforward website and assume that as it’s not an ecommerce website, or that as you don’t operate in a regulated environment that website security isn’t an issue you need to be particularly aware of. To an extent you might be right, there are degrees of risk. However, a website that isn’t secure isn’t just a technical risk. An insecure website can mean downtime while you’re trying to run your business. It can mean the potential exposure of customer or client data, with the liability that comes with that. It’s the reputational cost of a site that’s been defaced, or is quietly serving malware to your visitors. And increasingly, it’s an SEO problem too, Google actively flags and de-ranks compromised sites, so your security issue can quickly also become a visibility issue.
So while it’s true that you’re unlikely to fall victim to a sophisticated attack that doesn’t necessarily matter any more. Most security risks come from ordinary neglect: software that hasn’t been updated, plugins nobody’s checked in a year, a site built once and never looked at again.
Questions to ask before you hire
A few questions, asked early, can tell you more than any portfolio:
- How do you handle software and plugin updates? “We’ll sort that if it comes up” is a different answer to “updates are part of what we do as standard.” Outdated software is one of the most common ways sites get compromised, it’s rarely more complicated than that.
- Is the site custom-built, or built on a template with a stack of plugins? There’s nothing wrong with using established tools well, the wheel doesn’t always need to be reinvented. The risk comes from sites cobbled together from plugins chosen to cut corners rather than plugins chosen because they’re the right tool for the job. The more moving parts there are and the more of them that aren’t maintained, then the more ways in there are to your website.
- What happens if a vulnerability is found after launch? Is there a plan, or does the relationship end at handover? A website isn’t a one-off delivery; it’s something that needs attention for as long as it’s live.
- What do you offer by way of ongoing maintenance? Depending on the agency you may well find a degree of maintenance is included as standard, understanding what options are available from the start and what costs are involved is much better than trying to agree this later.
Signs your current site wasn’t built securely
If you’re not sure whether your existing site clears this bar, here are a few things worth checking rather than assuming.
We’ve taken over more than one website and found it weak from a plugin perspective. In almost all cases this is not due to one dramatic flaw, but a slow accumulation over time of third-party additions, each reasonable on its own, but never reviewed as a whole. Individually each might be fine but all together, particularly if they’re not being managed holistically they’re opening up your website to risk.
- Whoever is managing your website should be able to give you a complete list of what plugins your site is running, and why. If your website is managed in-house then the same point applies, regularly keep what your website is running under review, it’s very easy for duplication to creep in.
In a similar vein we’ve also provided support to an organisation struggling because of an outdated theme. Old themes stop receiving updates, which means known vulnerabilities in the underlying code stay open indefinitely, and the fix usually isn’t a quick patch; it can mean a rebuild that could have been avoided with proper maintenance undertaken from the start.
The pattern in both instances above is the same: nothing catastrophic on day one, and nothing anyone was paying attention to on day two hundred. That’s usually how these things end up going wrong.
What “done properly” looks like
We build custom so your website is never running anything it doesn’t need, and ongoing technical and security maintenance is treated in the same way. It’s not an afterthought, we have different levels and types of support available so whatever your budget and risk level you’re dealing with we can help. All of these cover updates, backups, code reviews and firewalls.
Both examples above are the Iceberg Effect in practice — a term we use in our pricing guide for the part of a cheap or corner-cut build that’s invisible on delivery day and becomes someone else’s problem months or years later. A site with a plugin sprawl nobody’s reviewed and a site built properly look identical the day they launch. The difference only shows up once you’re below the waterline — which, by then, is usually a more expensive place to be than doing it properly the first time.
That’s not a claim unique to us. It’s what “done properly” is supposed to mean, and it’s a reasonable thing to expect from anyone building your website — which is exactly why it’s worth asking about directly, whoever you’re talking to.
Where to go from here
If you’re about to commission a website, our guide to what that commissioning process should look like covers the wider set of questions worth asking beyond security specifically. If you’re not sure where your current site stands, get in touch, we’re happy to have that conversation without it turning into a sales pitch.
Because the parts nobody checks are usually the parts that matter most.