Website Security Maintenance for Kenyan Businesses
Website security is a continuing management practice. Updates, access control, backups and monitoring reduce avoidable exposure, but no checklist or provider can make a website hack-proof.
The right goal is to lower risk, detect unusual conditions, recover more confidently and keep ownership clear. Security work should match the website’s technology, data, integrations and importance to the business.
1. Keep software supported and updated
Apply security updates to the CMS, plugins, themes, server software and custom dependencies after appropriate testing. Remove unused components rather than leaving abandoned plugins or accounts available. CISA’s Secure Our World guidance recommends installing software updates promptly because updates can fix security risks.
2. Reduce and protect administrative access
- Give each administrator a separate account.
- Grant only the permissions needed for the role.
- Use strong, unique passwords and multi-factor authentication where available.
- Remove access promptly when staff or suppliers leave.
- Keep domain, hosting and analytics ownership in accounts controlled by the business.
3. Maintain recoverable backups
A backup is useful only if it contains the required files and data, is protected from the same incident and can be restored. Define the backup frequency from how much data the business can afford to lose. Retain more than one recovery point, protect access and test restoration periodically. CISA guidance repeatedly recommends maintaining and testing backups as part of cyber resilience.
4. Review the public attack surface
Check exposed administration pages, unnecessary services, security headers, certificate configuration and public files. For email-related domains, review SPF, DKIM and DMARC with a provider who understands the organisation’s sending systems; an incorrect change can interrupt legitimate email.
5. Monitor meaningful changes
External monitoring can identify availability problems, certificate changes, suspicious page modifications and some known configuration issues. Application logs, hosting alerts and third-party security services can add context where access is available. Monitoring does not prove that a site is safe; it helps surface conditions that deserve investigation.
6. Protect forms and customer data
Collect only the information the business genuinely needs. Use HTTPS, validate input on the server, limit form abuse, protect stored submissions and document who can access them. Do not email sensitive information simply because a form makes it convenient. Privacy, retention and breach duties should be reviewed with qualified advisers for the organisation’s specific situation.
7. Prepare a simple incident plan
- Identify who decides whether to take the site offline.
- Keep current contacts for hosting, domain, development and business leadership.
- Preserve evidence before changing systems where possible.
- Use a known-good recovery process rather than improvising under pressure.
- Record what happened, what changed and what will prevent recurrence.
What to ask a website care provider
Ask how updates are tested, where backups are stored, whether restoration is tested, who receives alerts, what access the provider needs and how critical incidents are escalated. Require clear boundaries around security monitoring and avoid absolute promises.
Build routine security care into every month
Website Care includes agreed security monitoring, backups and updates where applicable, with scope confirmed after a website review.
See Website Care plansSources: CISA: update software promptly and CISA guidance that includes tested backups and patching.