It is the most common thing a small business owner says about website security, and it sounds completely reasonable. You are a plumber, a dentist, a two-person consultancy. Who would bother?
The answer is nobody. Nobody is bothering. That is exactly the problem.
Attacks are not aimed, they are swept
Picture someone walking down a street pulling on every car door handle. They are not evaluating the cars. They do not care whether it is a new BMW or a fifteen-year-old hatchback. They are checking which handles open.
That is what happens to your website, except the street is the entire internet and the walking is done by software that never sleeps. A bot requests a URL, reads what version of WordPress and which plugins are running, checks that against a list of published vulnerabilities, and either moves on or gets in.
Your revenue, your industry and your visitor count are not inputs to that decision. The only input is whether you match a known weakness.
Small sites are worth something specific
Attackers do not want your site because of what your business does. They want it for what a working website with a clean reputation can do for them:
- Sending spam. Your server has a mail capability and your domain has a decent reputation, at least until it does not.
- Hosting phishing pages. A fake bank login on a real small-business domain lasts far longer than one on a suspicious new domain.
- SEO spam. Hidden pages and injected links use your domain's standing in Google to rank someone else's content.
- Redirecting your traffic. Even a few hundred visitors a month is a few hundred people to send to a scam.
- Bulk resources. Your hosting becomes a small node in a much larger operation.
None of that requires you to be big. In several of those cases, being small and unwatched is the feature. A site nobody monitors is a site that stays infected for months.
The cost lands harder on a small business
Here is the part that gets missed. A large company has an incident response process, a security budget and a communications team. A small business has you.
When a small site gets hit, the bill is not really the cleanup. It is the four days you spend on it instead of working. It is the leads that hit a browser warning and went to a competitor instead. It is the search rankings you built over three years, gone, and the six months of climbing back. It is the email deliverability problem that quietly kills your invoices.
Proportionally, a compromise hurts a ten-person business far more than a ten-thousand-person one.
"But nothing has ever happened"
Two possibilities. Either your login page has genuinely never been probed, which is not plausible for any site that has been online more than a few days, or nothing has happened yet.
There is a third and less comfortable option: something has happened and you do not know. Most modern WordPress malware is built to stay hidden. Silence is not evidence of safety, it is just silence.
The fix: stop reasoning from the absence of bad news and go look. Log out, search your own site on Google, check your admin user list, and run an actual malware scan. That takes twenty minutes and gives you a real answer instead of an assumption.
What actually reduces your exposure
The good news in all of this: because the attacks are generic, so are the defences. You are not trying to outsmart a determined adversary. You are trying to not be the unlocked door.
- Keep WordPress core, plugins and themes updated, and delete what you do not use.
- Unique strong passwords, plus two-factor on anything that can log in.
- Remove old administrator accounts from developers and agencies you no longer work with.
- Run a firewall that blocks the known bad requests before they reach your site.
- Keep off-site backups you have actually tested, so a bad day is a restore and not a rebuild.
That list closes the overwhelming majority of automated attacks. It is not glamorous and it is not clever. It just works, if someone does it consistently.
Consistently is the hard part
You will do all of this the week after you read about it. The question is whether it is still happening eight months from now, in a busy quarter, when a plugin patch ships on a Friday afternoon.
That is the gap Up Speed fills. Malware scanning, 24/7 uptime monitoring, tested updates and scheduled off-site backups run on every plan, including Starter. If you want the hardening layer, the Wordfence firewall, iThemes configuration and two-factor login sit on the Professional plan.
Nobody can make a website impossible to attack, and we will not pretend otherwise. What we will do is close the doors the bots are actually trying, and fix what breaks when something gets through, rather than sending you an alert and calling it a service.