Buildgin / Resources / Writing
Security · 15 September 2026 · 8 min read
Website security, for a business that does not have an IT department
Nobody targeted you. A script scanned the internet, found a plugin three years out of date, and walked in.

When an SME website gets compromised in India, it’s almost never a targeted attack. It’s automated. A script scans millions of sites looking for a specific known weakness, finds yours, and gets in.
Which is good news, because automated attacks are prevented by unexciting maintenance.
What actually happens when a site is compromised
Usually not a defacement. More often something quiet. Spam pages get injected, invisible to you and visible to Google. Or visitors get redirected to a scam site, but only visitors arriving from search, so you never see it yourself.
The first sign is often a Google warning label on your search listing, or a customer asking why your site tried to install something. By then the damage to your search position has been done.
The short list
- HTTPS on every page. Free through Let’s Encrypt. Browsers mark sites without it as Not secure, which is the first thing a cautious buyer sees.
- Update everything, monthly. If you run WordPress, this is the whole ballgame, and the update process is documented. Core, plugins, themes. An unpatched plugin is how most break ins happen.
- Delete what you don’t use. Every unused plugin is an open door with nobody watching it. Deactivating isn’t deleting.
- Strong passwords and two factor on the admin login. Not admin and your company name with 123 after it.
- Backups you have actually restored once. An untested backup is a belief with a filename.
- Limit who has admin access. The intern from 2019 probably still has an account.
Why static sites sidestep most of this
A site built as plain files has no database to inject into, no admin login to brute force, and no plugins to go out of date. There’s very little to attack.
That’s a genuine security argument for static builds on catalogue and brochure sites, and it’s why we default to them. It isn’t right for every project. It removes an entire category of risk when it fits.
The forms question
If your site has an enquiry form, it needs spam protection, and it needs to actually deliver. We find dead forms in most audits. Sometimes they’ve been silently failing for years, and the business assumed enquiries had simply dried up.
Test yours now. Fill it in from your phone, on mobile data rather than office wifi, and see whether anything arrives. Check the spam folder too.
What this costs
For a static site, close to nothing beyond hosting. For WordPress, budget an hour a month for patching, or a small retainer with whoever maintains it.
Either way it’s cheaper than recovering a site that’s been flagged by Google, which takes weeks and costs you rankings you spent years earning.
Written by Sameer Gaikwad, founder of Buildgin. Thirty three years in electrical power systems across global MNCs, now applying the same condition monitoring habit to websites.
BUILDGIN