Security · Built in, not bolted on

How we build secure, fast small business websites

Most small business sites that get hacked are hacked the same few ways. We build so those ways mostly don't exist: static pages, served from Cloudflare's network, with updates, backups and monitoring handled for you.

Every SDP siteAll good

  • HostingCloudflare's network
  • ConnectionHTTPS only
  • Public siteStatic: no login, no database
  • UpkeepManaged for $49/month

How we build

Security that comes with every site

None of this is an add-on. It's how every SDP site is built, hosted and looked after.

01 · Static build

Static sites: very little to attack

Your pages are built ahead of time and served as finished files. There's no database, no admin login and no plugins on the public site, which removes the parts attackers usually go after.

02 · Hosting

Hosted on Cloudflare's network

Sites are served from Cloudflare's global edge network, close to your visitors. That keeps pages fast, and Cloudflare sits in front of the site to absorb junk traffic.

03 · Headers

Security headers on every response

Each page tells the browser how to treat it: HTTPS only, no guessing file types, and a Content-Security-Policy rule so only your site and the SDP portal can frame it. These are this site's real headers.

04 · HTTPS

HTTPS everywhere

Every site has an SSL certificate. The http:// address redirects to the secure one, so the padlock always shows.

05 · Forms

Forms protected from bots

Contact and quote forms use Cloudflare Turnstile, which turns away automated spam without puzzles for real visitors.

06 · Upkeep

Updates, backups, monitoring

Software and security updates, backups and monitoring are part of the $49/month. You never log in to patch anything.

07 · Every change

Automated checks before every deploy

Every change runs through automated checks before it can go live: a scan for leaked passwords and keys, static analysis of the code for risky patterns, and an audit of third-party packages for known vulnerabilities. If one fails, the change doesn't ship.

08 · Who builds it

Built by a security-minded team

SDP was founded on a background in information and cybersecurity operations, so security is part of how we design each site, not an afterthought.

About Sims Digital Partners

Why sites get hacked

Why typical small business websites get hacked

It's rarely a targeted attack. Automated tools scan the web around the clock for two things: software that's out of date, and logins with weak or reused passwords. A site gets hit because it's easy, not because it's yours.

A typical CMS site

What a typical CMS site exposes

WordPress and similar systems are good tools. Kept patched, they can be safe. But every part below needs looking after, and on many small business sites the looking after stops.

  • A login page on the public siteAnyone can find it and try passwords against it, all day.
  • Plugins and themes from many authorsEach one is code that needs its own updates, on its own schedule.
  • A database behind every pagePages are built on request from a database the server has to keep reachable.
  • Server software to keep patchedThe CMS itself, its language runtime and the server all need updates.

An SDP static site

What a static site removes

The same website, built ahead of time. Visitors get the finished pages; the parts that need constant patching aren't on the public site at all.

  • No admin login on the siteThe pages are built ahead of time, so there's no login form to guess at.
  • No plugins on the serverFeatures are part of the build, checked before they ship, not bolted on live.
  • No database to break intoVisitors get finished HTML files. There's nothing to query or inject into.
  • No server for you to look afterCloudflare runs the network that serves the files; we handle the site.

Out-of-date plugins are the most common way in. Read whether your WordPress site is actually getting its security updates, and if your site sits behind Cloudflare, check Cloudflare's new AI crawler settings.

Your part

What you still own

We look after the website. A few accounts only you can protect, and they matter as much as the site does. Here's the honest list.

01 · Yours to protect

Your email account

Your inbox resets every other password you have, so it's the account most worth protecting. Use a long, unique password and turn on two-step verification.

02 · Yours to protect

Your domain registrar account

Whoever controls the domain controls where your website and email point. Keep two-step verification on, keep the contact email current, and keep auto-renew on so it never lapses.

03 · Yours to protect

Who has access

When an employee or contractor leaves, remove them from your email, registrar, Google Business Profile and social accounts. Old access is an easy way in.

04 · Yours to protect

Messages asking for logins

Be wary of urgent emails about your domain expiring or your site being suspended. If one looks off, don't click the link. Message us and we'll check it.

Your domain is registered in your name and always stays yours.

Questions

Website security questions, answered

Straight answers to what owners ask us about keeping a site safe.

Is a static website really more secure than WordPress?

It has less to attack. A static site is a set of finished pages served from Cloudflare's network, with no database, admin login or plugins on the public site. A well-maintained WordPress site can be safe too; it simply has more parts that need regular updates, and most hacked sites are the ones where those updates stopped.

Do I need a security plugin?

No. Security plugins exist to protect a CMS's login, database and plugins. A static site doesn't have those on the public site, so there's nothing for a plugin to guard. Your forms are protected by Cloudflare Turnstile instead.

Who keeps my website updated?

We do. Software and security updates, backups, monitoring and the SSL certificate are part of hosting and management at $49/month. You don't log in to update anything.

How are my contact forms protected from spam bots?

Contact and quote forms use Cloudflare Turnstile, a check that tells people from bots without making visitors solve puzzles. Most visitors never notice it, and automated spam is turned away before it reaches your inbox.

Does my website use HTTPS?

Yes. Every site has an SSL certificate and is served over HTTPS only. Anyone who types the http:// address is redirected to the secure one, so the padlock always shows.

Can you guarantee my site will never be hacked?

No one can honestly promise that. What we can do is leave as little as possible to attack, keep everything updated, check every change before it goes live, keep backups and watch the site, and be the person you message if anything looks wrong.

What do I need to do on my end?

Protect the accounts that are yours: your email and your domain registrar. Use unique passwords, turn on two-step verification, and remove old staff from your accounts. If you get an odd message about your website or domain, send it to us before you click anything.

Secure by default · Managed for you

Want a website you don't have to worry about?

Tell us about your business. You'll get a clear scope and a fixed price, from $249, and we'll keep it secure for $49/month.