All Articles
May 06, 2026 · 4 min read

5 Security Basics Every Kenyan Business Website Should Have

Most website security problems are not sophisticated attacks. They are basic protections that were never put in place. Here are five, and how to check whether your site has them.

5 Security Basics Every Kenyan Business Website Should Have

Most website security incidents we get called in to fix were not caused by a sophisticated attacker targeting that specific business. They were caused by basic protections that were never put in place, discovered eventually by automated scanning tools that hackers run against thousands of sites at once, looking for whichever ones are easiest to break into. Being an easy target is usually a choice, even if it was not an intentional one.

Here are five basics every business website should have, and how to check whether yours does.

1. An Active SSL Certificate, Correctly Configured

SSL is what puts the padlock icon in a visitor's browser and turns your address bar green or grey instead of showing a warning. Beyond the visual reassurance, it encrypts the data moving between your visitor and your server, including anything typed into a contact form. Check this by visiting your own site and confirming the address bar shows a locked padlock with no warning. If your site sometimes loads without the padlock, or shows "mixed content" warnings, some of your pages are loading unencrypted resources and need to be fixed.

2. Software and Plugins That Are Actually Up to Date

If your website runs on WordPress or any platform with plugins and themes, every one of those components is a potential entry point if it falls behind on updates. Hackers do not read individual websites looking for weaknesses. They run automated scans across the entire internet looking for sites running specific outdated versions with known vulnerabilities, then exploit them in bulk. Ask whoever manages your site when the core platform and plugins were last updated. If nobody can answer that with a specific date, treat it as overdue.

3. A Real Backup System, Tested at Least Once

A backup that has never been restored is a backup you cannot actually trust. Ask where your backups are stored, how often they run, and when the last successful restore was tested, not just when the last backup file was created. If your site were compromised or your hosting account failed tonight, you want to know with confidence how much work you would lose, measured in hours rather than months.

4. Rate Limiting and Protection on Every Form

Contact forms, newsletter signups, and login pages are common targets for automated bots that submit thousands of fake entries, attempt to guess passwords, or use your form as a relay for spam. A properly protected form limits how many submissions can come from the same source in a short window and includes some form of bot protection. If your inbox has ever been flooded with obvious spam from your own contact form, that is a sign this protection is missing or misconfigured.

5. Restricted Access to Your Admin and Server

Every person with login access to your website's admin panel, hosting account, or server is a potential point of failure, whether through a weak password, a compromised device, or simply someone who no longer works with you but still has access. Review who currently has access to each of these systems, remove anyone who should no longer be there, and confirm that strong, unique passwords are in use rather than anything reused across other accounts.

Checking Your Own Site

You do not need to be technical to get a rough sense of where your site stands on these five basics. Most of it comes down to asking direct questions of whoever built or currently manages your site, and being wary of vague or reassuring-sounding answers that do not actually address what you asked.

For a more thorough check, our free website audit tool will scan your site and flag common issues automatically, and our full website audit service goes deeper, covering security, performance, and SEO together with a prioritised report on what to fix first.

Security is rarely about one dramatic fix. It is about making sure the basic protections are in place and are not quietly lapsing over time, which is also why this overlaps so heavily with ongoing website maintenance rather than being a one-time task you complete and forget.

Ready?

Let's build something great

Let's discuss how we can help you achieve your technology goals.