About Mike Ferguson

Mike Ferguson has been tinkering with websites full time since 1999 after leaving a perfectly good, well paying civil servants job with benefits. He can't help himself.

The Only 3 Security Things Small Businesses Actually Need

Most small businesses don't need enterprise-level security - they need three things done consistently: strong passwords with a password manager and multi-factor authentication, regular automated backups stored off-server and tested quarterly, and keeping all software updated through a staging site. These three practices address the vast majority of security risks facing small business websites. Everything else is secondary noise that quality hosting providers typically handle automatically. The Only 3 Security Things Small Businesses Actually Need The internet is full of overwhelming security advice. Firewalls, penetration testing, intrusion detection systems, security audits - it's enough to make you want to unplug your website and go back to the Yellow Pages. Here's the truth: Most small businesses don't need enterprise-level security. You need three things done consistently. That's it. I've been hosting and maintaining websites since 1999, and I can tell you that nearly every security problem I've seen came down to one of these three issues. Fix these, and you're ahead of 80% of small businesses out there. 1. Strong Passwords (And Stop Reusing Them) This sounds basic because it is basic. It's also the #1 way websites get compromised. "Password123" doesn't cut it. Neither does your business name plus the current year. And please, for the love of all that's holy, stop using the same password for your website, email, bank account, and Netflix. What Actually Works Use a password manager. I don't care which one - 1Password, LastPass, Bitwarden - just pick one and use it. Let it generate random passwords for everything. You only need to remember one master password. For your WordPress admin account, think 16+ characters minimum. Mix uppercase, lowercase, numbers, and symbols. Let the password manager handle it. Multi-factor authentication adds another layer. Even if someone steals your password, they [...]