In Poland 97% of recorded incidents are fraud and only 0.3% break-ins. So this section starts with the list of accounts, not the firewall.

A conversation about cyber security for a small business usually starts with the firewall and the plugins. The data says to start somewhere else.
The EU's cybersecurity agency, ENISA, analysed 4,875 incidents across the Union for its Threat Landscape 2025, covering July 2024 to June 2025. Phishing — by email, by phone, through malicious ads — accounts for about 60% of the ways attackers got in. Exploiting a flaw in software accounts for 21.3%. In other words, somebody getting hold of a login is roughly three times as common as somebody breaking through the code. The Polish national figures point the same way, only more sharply: in 2025 CERT Polska, the national incident response team, registered 260,783 incidents. Break-ins were 750 of them — three tenths of a per cent. Computer fraud was 97%, and the theft of logins and passwords alone 30% of everything. Nobody is likely to break in the way you imagine. Somebody will simply get a password.
That is why this section is built around access, not tools — and why it starts with a list of accounts, not with a purchase. Below are six situations, one per article. I do not teach any of them from the beginning here; that is what the articles I point to are for.
How to use this section. If you are going to do one thing, start with the section just below and come back in a week. If you want to know in what order to do the rest, go to the section on order: the three most effective items are free and fit into one afternoon. And if you are looking for a specific subject, the six entry points further down lead straight to it.
Open the list of users in your website's dashboard and, for each account, answer three questions: who is this, do they still use it, and do they need these permissions?
What usually turns up is the account of a contractor from two agencies ago, the "admin" account from the installation, and three people with administrator rights of whom one actually edits. On top of that come three kinds of access the dashboard does not show and that give more than an administrator account: the hosting, the database and the domain account.
A quarter of an hour, no cost, and it closes the route by which the large majority of incidents arrive. How to do it and what comes next: [how to secure a website](posts:69241af55f2464f7c72d876b).
If you have five minutes left after that quarter of an hour, spend them on one thing: check which email address receives the dashboard's password reset. It is sometimes a former employee's mailbox or an alias nobody reads — and whoever holds that mailbox holds the dashboard, without breaking anything.
"Somebody could break in — what should I actually do?"
Access control, dashboard accounts, plugins as an attack surface, and six signs that something has already happened — split into the ones you will notice yourself and the ones a customer sees first. This is also where the EU figures are laid out in full, together with the free checks almost nobody uses.
"The browser warns people about my site" or "do I have to pay for a certificate?"
What a certificate is, when a free one is enough, when you need a wildcard, and what changes on dates none of you set — including shrinking certificate lifetimes and browsers moving towards HTTPS by default.
"I have a dozen update notifications and I am afraid to click"
Where the vulnerabilities really sit — 91% in plugins, 9% in themes, six in the core — what to switch to automatic, what not to touch without your contractor, and what to do when an update takes the site down.
"The hosting has backups — is that enough?"
The four layers a working site is made of, the three places a copy can live and what each protects against. And the part that changes the category of the problem: under the GDPR, losing access to personal data is a breach in its own right, with a 72-hour clock for notifying the Personal Data Protection Office (UODO).
"Is our privacy notice in order?"
What the GDPR requires your site to tell people, what ends up in these texts by copying someone else's template, and cookie consent — with the rule on storing things in the visitor's browser that most sites read wrongly in one direction or the other.
→ GDPR and your privacy notice
"Do we even have anything to work with — who can check?"
If none of the sentences above sounds like your situation and you simply want to know what state the site is in, start with the quarter of an hour with the account list described above, then check your domain for free in Google Search Console, in Google's Safe Browsing lookup and with moje.cert.pl, the free domain check run by CERT Polska. You can do all three yourself, and all three will tell you more than any offer you receive without a check.
"An employee clicked a link"
The company layer: the mailbox, the phones, accounts in other people's systems. One reflex worth teaching the team instead of a course in spotting phishing, four moves after the click, and the protection you already use without knowing it.
Three paths, depending on what brought you here.
Nothing has happened and you simply want to get it in order. Start with the section above, then the section on order and backups. Three steps, one afternoon, and what is cheapest to close is closed.
Something has already happened. Go straight to how to secure a website, the section on what to do after a break-in — and if it is about a clicked link or a taken-over mailbox, to company data security. If what became unavailable or leaked included data about people, a deadline counted in hours comes on top: the GDPR and your privacy notice.
You are preparing for a conversation with your contractor. Read updates and backups: each of them produces specific questions you can ask in the meeting, and each ends with a list of what the answer should contain.
The order in which to do it
Digital Vantage — our assessment from audits, not a measurement
The order on this figure does not follow what is most interesting, but how much risk each item closes against the effort it takes. The first three are free and fit into one afternoon.
Notice where monitoring and the security plugin are: at the bottom. Not because they are useless, but because installed before the account list they create the feeling of having done something without closing the route people actually use. It is the most common mistake of order we see, and the most expensive one, because it costs a subscription and a false sense of calm at the same time.
One remark about the figure itself: these two measures are our assessment from audits, not a measurement. The caption says so too. The numbers that are measurements — the split of intrusion vectors and the split of incidents in Poland — are in the introduction and come from ENISA and CERT Polska.
A caveat on that number as well, because it belongs to the honesty of the argument: ENISA works mainly from open sources and from information shared by member states, and says itself that this is not a complete picture. Its dataset leans towards large, visible organisations — public administration is the most frequently hit sector in it — rather than towards a small company with a brochure site. For your decision that changes little: mass phishing campaigns do not check who they are writing to, and the proportion points the same way.
It is worth saying plainly, because the security services market sells the opposite impression.
For nothing: the account list and removing unneeded access, a second login factor, unique passwords, removing unused plugins, checking where the password reset goes, reporting suspicious messages, checking your own domain in Google's tools.
For very little: a copy kept outside the hosting account. It is the only expense we recommend to practically everyone. In our maintenance cost calculator, a weekly backup is PLN 30 a month and a daily one PLN 60. Those are our prices, not a market average: we have not surveyed what others charge for this item alone.
Reasonably worth paying for when the site earns money: monitoring that alerts a named person, and technical maintenance with an agreed response time. The difference between "I find out within the hour" and "I find out from a customer a week later" can then be put into numbers — and that is the only way to justify the expense with a figure rather than a hunch.
There is also an in-between category that is rarely mentioned: the time of somebody who goes through all this for you once a quarter. Not monitoring, not a subscription — just an hour of work with the account list, the plugins and the backup. In a company where nobody opens the dashboard except to add a post, it is the best-spent hour in the whole section.
What is not worth buying: "premium security" packages bolted onto the hosting when nobody knows what they cover. There is one control question, and it settles the matter in a sentence — will this service alert a named person, or will it generate a report in a panel nobody opens?
What is in this section, and what sits next to it
Digital Vantage
"We are too small for anyone to be interested in us." Phishing campaigns do not choose targets — they replay credentials from other people's breaches and test well-known account names on everything that answers. Nobody checks the size of a company before trying to log in.
"The hosting takes care of that" or "our IT person does." They take care of their layer, and usually do it well. They are not responsible for the accounts in your dashboard, for abandoned plugins, or for whom you gave access three years ago. The GDPR puts it in its own terms: as the controller, it is you who must use only processors that provide sufficient guarantees (Article 28), and it is you whom the processor must notify of a breach (Article 33) — not the other way round.
"We will do it at the next redesign." The most expensive of the three, because the list in this section has nothing to do with a redesign — these are settings, not a project. Putting them off until the next big job usually means two years of open access in exchange for nothing.
What they have in common: each of these sentences shifts responsibility onto something external — the size of the company, the supplier, the calendar. The list that actually works is entirely internal, and that is why it is often the hardest to start.
There is a fourth sentence, rarer but worth noting because it sounds more reasonable than the others: "we will do it when we have the budget." For this list, budget is not the bottleneck — the three most effective items cost nothing, and the only one we recommend to practically everyone costs PLN 30 a month with us. The bottleneck is the decision about who in the company opens the dashboard and removes access from a person you enjoyed working with. That is uncomfortable, and that is why it slides through the calendar under another name.
Finally, three things you will not find in these six articles, because we choose not to write them.
No frightening numbers without an origin. Every number in this section has a named, dated source, and where the source is a vendor with an interest in the result, we say so next to the number. From earlier versions of these texts we removed every statistic that could not be traced to anything.
No selling of tools. We do not compare plugins or providers: they change faster than an article can be kept current, and the right choice depends on what you already use.
No pretending to give legal advice. Where the law comes in, we cite the basis directly — with the article number and a link to the text — so that you can check it or show it to a lawyer. Doubtful cases belong to them.
With the list of accounts in the dashboard, and with the three kinds of access the dashboard does not show: the hosting, the database and the domain. A quarter of an hour, no cost. Then a second login factor and unique passwords. Monitoring and security plugins come at the end of this order, not at the beginning.
Rarely a target, often a catch. In 2025 CERT Polska registered 260,783 incidents, of which computer fraud was 97% and break-ins 0.3%; in ENISA's Threat Landscape 2025, phishing accounts for about 60% of observed intrusion vectors across the EU and the exploitation of software flaws for 21.3%. These campaigns are mass campaigns and do not check the size of the company — you defend against them by removing the easy ways in, not with sophistication.
The most effective part is free: the account list, a second factor, unique passwords, removing unused plugins. The only expense we recommend to almost everyone is a backup kept outside the hosting account — with us, PLN 30 a month for a weekly copy. The rest makes sense once the site earns money.
Installed before the accounts are in order, it creates the feeling of having done something without closing the route people actually use. Here the order matters more than the choice of tool — and it is the most common mistake we see in audits.
For their own layer, yes, and they usually handle it well. They are not responsible for the accounts in your dashboard or for access granted years ago. Under the GDPR it is the controller — you — who must use only processors that provide sufficient guarantees (Article 28), and it is you whom the processor notifies of a breach (Article 33), after which you have 72 hours to notify the Personal Data Protection Office (UODO).
A second factor on the dashboard and on the mailbox, then a unique password for the dashboard, then a backup kept outside the hosting account and restored at least once. Four steps, three of them free; the whole thing fits into one afternoon.
In an audit we check who has access to the dashboard, the hosting and the domain — including contractors from years ago. It is the part no scanner will do for you.
In Poland 97% of recorded incidents are fraud and only 0.3% break-ins. So this section starts with the list of accounts, not the firewall.
91% of WordPress vulnerabilities sit in plugins; six were found in the core. And 46% had no fix on disclosure day, which changes what a routine is for.
Phishing is 30% of incidents registered in Poland, break-ins through code 0.3% (CERT Polska 2025). Securing a website is access control, not plugins.
On a website, the GDPR duty to inform is the privacy policy. What must be in it, what is padding, and why cookies sit on a separate legal basis.
A free certificate is enough almost every time. When you need a wildcard, why the EV bar disappeared, and what Chrome changes in October 2026.
A WordPress backup nobody has restored is a feeling, not a safeguard. Four layers, three storage locations, and why losing access is a GDPR breach.
Company data rarely leaks through the website. It leaves through the mailbox, the phone and an account in someone else's system. What to do first.
Table of Contents · 8 sections · 8 minutes read
Rate this article
Back to the guide: Websites — a guide to the whole section

An ecommerce SEO audit runs mostly on free Google reports: indexing, Core Web Vitals, rich results, duplicates and Merchant Center data.

Google Merchant Center: site verification, product data, shipping and landing page rules, disapprovals, and Shopify, WooCommerce and IdoSell integrations.

API explained with NBP, KSeF and VIES as examples: REST API, webhooks, OpenAPI, API keys and integration security for business.

Multi-tenant SaaS: single tenant vs multi-tenant, the silo/pool/bridge models, Row Level Security, GDPR and choosing a model for an MVP.

Cloud computing by the NIST definition: five traits, IaaS, PaaS and SaaS, public, private and hybrid cloud, and how Polish businesses actually use the cloud.

When a free booking calendar is enough, what an online booking system must handle and when a custom module pays off. Vendor prices and our estimate.

WordPress themes are not chosen on looks: three fields in the directory tell you what a theme will cost you in a year, and what disappears when you switch.

Three layers in the order that matters, the list of checks, and the price stated outright. With three findings an owner will never spot on their own.

A free site is a real option with a precise limit. Three routes, what each one gives you, what it withholds, and what it costs once a year has passed.