Website Security & IT Support
The site that brings inyour customers should notbe the way you get hacked.
Most small business websites are built once and then left alone. Attackers do not leave them alone. We clean up compromised sites, keep forms and email working, move hosting without losing rankings, and keep the platform patched so it stays that way.
Overview
Marketing sends people to a website. If the site is compromised, the forms are flooded with spam, or the enquiry emails never arrive, the marketing budget is being spent on a broken front door. That is why we treat security and basic IT as part of the same job. This is hands-on work we already do for our own clients, not a reseller package with a dashboard.
What a compromised site actually looks like
Usually nothing, at first. The pages load, the logo is in the right place, and the owner has no idea. Underneath, the footer carries links to pharmacy and gambling domains, extra files sit in folders nobody looks in, and Google has quietly decided the site is untrustworthy. We have cleaned this exact pattern off client sites more than once. The work is the same each time: find every injected file and link, remove it, rotate every password and key that touches the site, close the hole it came through, and then check again a week later, because the first cleanup rarely gets everything.
Forms that reach you, and only you
A contact form with nothing in front of it will be filled in by bots within days. The usual answer is a picture puzzle that punishes real customers. We use a layered approach instead: a hidden field only bots fill in, a timing check that rejects submissions faster than a person could type, Cloudflare Turnstile for a silent bot check, and where it makes sense a geographic filter so a Florida service business is not reading enquiries from three continents. The result is a form your customers do not notice and bots cannot get through.
Email that actually arrives
Form notifications and business email fail for one dull reason more than any other: the domain never told the world who is allowed to send on its behalf. We publish and verify SPF, DKIM and DMARC records, send form mail from the business domain rather than from the visitor, and avoid forwarding chains that break authentication and land mail in junk. Then we test it at Gmail, Yahoo and Outlook, because the records being present is not the same as the mail arriving.
Moving hosting without losing rankings
Changing hosts is where sites lose years of search equity, usually to a missed redirect or a certificate that was never issued. We plan the cutover in order: the new site staged and checked, DNS records changed, the security certificate issued and verified, every previously indexed address confirmed to still answer, and the old host kept in place until nothing depends on it. Search Console and analytics are set up before the move so there is a record of what happened, not a guess.
Keeping WordPress from being the problem
Most compromises come through an old plugin, an old PHP version or an admin door left open. We keep core, PHP and plugins current, block the endpoints nobody legitimately uses, keep configuration secrets out of the public web folder, force HTTPS on one canonical address, and set the security headers browsers expect. Where a business does not need WordPress at all, we will say so and rebuild the site as plain static pages, which removes most of the attack surface in one move.
Larger IT and network work
Some clients bring us problems bigger than a website: networks, infrastructure, security tooling. We assess those first, scope them in writing, and staff them with experienced engineers we bring in for the work. Nothing is quoted blind.
What is included
The workwe actually do.
Compromise cleanup
Injected links and files removed, credentials rotated, the entry point closed, and a follow-up check once the dust settles.
Form spam protection
Honeypot, timing check, Cloudflare Turnstile and optional geographic filtering. No puzzles for your customers.
Email authentication
SPF, DKIM and DMARC published and verified, with form mail sent from your own domain so it lands in the inbox.
Hosting and DNS moves
Staged cutovers with certificates, redirects and every indexed address verified before the old host is switched off.
WordPress maintenance and hardening
Core, PHP and plugin updates, unused endpoints blocked, secrets kept out of the web root, HTTPS enforced.
Backups and checks
Backups taken before every change, and post-change verification of forms, mail and indexed pages.
Common questions
Questions weget asked a lot.
We think our site has been hacked. What should we do first?
Change the hosting and admin passwords, then call us before deleting anything. The injected files tell us how the attacker got in, and that is what has to be closed. Cleaning the visible symptoms without that step usually means doing it again in a month.
Do we have to leave WordPress?
No. A maintained WordPress site is fine for most businesses. We recommend a static rebuild only where the site does not use anything WordPress provides, because then the maintenance burden buys nothing.
Do you handle larger IT and network projects?
Yes, on a scoped basis. Larger network, infrastructure and security engagements are assessed first and staffed with experienced engineers we bring in for the work, with the scope, timeline and price agreed in writing before anything starts.
Is this part of a marketing plan or separate?
Either. For managed marketing clients it is simply part of keeping the site working. For everyone else it is available on its own, most often as a cleanup or a hosting move with a maintenance arrangement afterwards.
Related
Works wellalongside.
Web and conversion
Newer disciplines
Get started
Let’s talk aboutyour website security.
Tell us where your business is stuck and we will show you the fastest way forward. The first conversation is free and useful.
