Static sites: very little to attack
Your pages are built ahead of time and served as finished files. There's no database, no admin login and no plugins on the public site, which removes the parts attackers usually go after.
Security · Built in, not bolted on
Most small business sites that get hacked are hacked the same few ways. We build so those ways mostly don't exist: static pages, served from Cloudflare's network, with updates, backups and monitoring handled for you.
Every SDP siteAll good
How we build
None of this is an add-on. It's how every SDP site is built, hosted and looked after.
Your pages are built ahead of time and served as finished files. There's no database, no admin login and no plugins on the public site, which removes the parts attackers usually go after.
Sites are served from Cloudflare's global edge network, close to your visitors. That keeps pages fast, and Cloudflare sits in front of the site to absorb junk traffic.
Each page tells the browser how to treat it: HTTPS only, no guessing file types, and a Content-Security-Policy rule so only your site and the SDP portal can frame it. These are this site's real headers.
Every site has an SSL certificate. The http:// address redirects to the secure one, so the padlock always shows.
Contact and quote forms use Cloudflare Turnstile, which turns away automated spam without puzzles for real visitors.
Software and security updates, backups and monitoring are part of the $49/month. You never log in to patch anything.
Every change runs through automated checks before it can go live: a scan for leaked passwords and keys, static analysis of the code for risky patterns, and an audit of third-party packages for known vulnerabilities. If one fails, the change doesn't ship.
SDP was founded on a background in information and cybersecurity operations, so security is part of how we design each site, not an afterthought.
About Sims Digital PartnersWhy sites get hacked
It's rarely a targeted attack. Automated tools scan the web around the clock for two things: software that's out of date, and logins with weak or reused passwords. A site gets hit because it's easy, not because it's yours.
A typical CMS site
WordPress and similar systems are good tools. Kept patched, they can be safe. But every part below needs looking after, and on many small business sites the looking after stops.
An SDP static site
The same website, built ahead of time. Visitors get the finished pages; the parts that need constant patching aren't on the public site at all.
Out-of-date plugins are the most common way in. Read whether your WordPress site is actually getting its security updates, and if your site sits behind Cloudflare, check Cloudflare's new AI crawler settings.
Your part
We look after the website. A few accounts only you can protect, and they matter as much as the site does. Here's the honest list.
01 · Yours to protect
Your inbox resets every other password you have, so it's the account most worth protecting. Use a long, unique password and turn on two-step verification.
02 · Yours to protect
Whoever controls the domain controls where your website and email point. Keep two-step verification on, keep the contact email current, and keep auto-renew on so it never lapses.
03 · Yours to protect
When an employee or contractor leaves, remove them from your email, registrar, Google Business Profile and social accounts. Old access is an easy way in.
04 · Yours to protect
Be wary of urgent emails about your domain expiring or your site being suspended. If one looks off, don't click the link. Message us and we'll check it.
Your domain is registered in your name and always stays yours.
From the blog
· 6 min read
· 6 min readQuestions
Straight answers to what owners ask us about keeping a site safe.
It has less to attack. A static site is a set of finished pages served from Cloudflare's network, with no database, admin login or plugins on the public site. A well-maintained WordPress site can be safe too; it simply has more parts that need regular updates, and most hacked sites are the ones where those updates stopped.
No. Security plugins exist to protect a CMS's login, database and plugins. A static site doesn't have those on the public site, so there's nothing for a plugin to guard. Your forms are protected by Cloudflare Turnstile instead.
We do. Software and security updates, backups, monitoring and the SSL certificate are part of hosting and management at $49/month. You don't log in to update anything.
Contact and quote forms use Cloudflare Turnstile, a check that tells people from bots without making visitors solve puzzles. Most visitors never notice it, and automated spam is turned away before it reaches your inbox.
Yes. Every site has an SSL certificate and is served over HTTPS only. Anyone who types the http:// address is redirected to the secure one, so the padlock always shows.
No one can honestly promise that. What we can do is leave as little as possible to attack, keep everything updated, check every change before it goes live, keep backups and watch the site, and be the person you message if anything looks wrong.
Protect the accounts that are yours: your email and your domain registrar. Use unique passwords, turn on two-step verification, and remove old staff from your accounts. If you get an odd message about your website or domain, send it to us before you click anything.
Secure by default · Managed for you
Tell us about your business. You'll get a clear scope and a fixed price, from $249, and we'll keep it secure for $49/month.
Start a project
Leave an email or a phone number and we’ll be in touch.
Message sent
Thanks for reaching out. We’ve got your message and we’ll be in touch soon.