The fundamentals, outside of any compliance obligation
Separate from what POPIA requires, there's a short list of security basics that prevent the overwhelming majority of small business website breaches. Most are free or near-free to implement and don't require technical expertise beyond following a checklist.
| Control | What it prevents |
|---|---|
| Unique admin passwords + MFA | Credential-stuffing and brute-force account takeover |
| CMS/plugin updates within days of release | Exploitation of known, publicly disclosed vulnerabilities |
| Tested, automated backups | Total data loss from ransomware or accidental deletion |
| Sitewide SSL/TLS | Data interception on unsecured pages |
| Limited admin user accounts | Larger attack surface from unused or shared logins |
The one habit that matters most
Most breaches exploit a known vulnerability that had a patch available for weeks or months before the attack. The single highest-leverage habit is applying CMS and plugin updates promptly rather than waiting for a scheduled maintenance window.
Frequently asked questions
Do I need a security consultant for this?
Not for the basics above - they're configuration changes, not specialist work. A consultant or audit becomes worthwhile once you're handling sensitive data at volume or have specific compliance obligations beyond these fundamentals.