Category · 35 guides
Maintenance & Security
Keeping websites and apps safe, fast and online: updates, backups, email security, incident response and what a maintenance plan should actually include.
Bots, spam and DDoS: protecting a small site
Most traffic hitting a small website is not human. A few sensible layers, a CDN, a web application firewall, form protection and login limits, stop most of the harm without enterprise tools.
DNS explained: why changing it breaks email
Your domain's DNS points the website to one place and your email to another. Move the website carelessly and the email goes with it. Here is how the records work and how to change them safely.
Losing your domain: how renewals go wrong
When a domain expires, the website and every email address stop working at once. Here is how it happens, how to lock your domain down for good and what to do if it has already lapsed.
Maintain your website yourself or outsource it?
Simple sites can be self-maintained with a routine. Shops and custom code rarely should be. Here is the split by site type, the cost of your own time, and a hybrid that works for most small companies.
Maintenance retainer or pay-as-you-go?
A retainer buys attention before things break. Hourly support buys help after they do. Here is how to compare them for your own site.
A monthly routine for keeping your site current
Outdated prices and staff who left a year ago cost more trust than a slow page. Thirty minutes a month, with a named owner, keeps your site honest.
NIS2 and the Cybersecurity Act: does it affect you?
Most small Swedish companies are outside NIS2 on paper and inside it in practice, because their customers are covered and pass the requirements down the supply chain. Here is how to tell which side you are on.
Outdated PHP: why your host keeps warning you
The warning email from your host is not upselling. An end-of-life PHP version stops receiving security fixes. Here is how to upgrade without breaking the site.
Password managers for small companies
The spreadsheet of passwords is one of the most common security risks in small companies. A business password manager fixes it in an afternoon.
What does a security test cost for a small site?
A scan and a penetration test are very different products at very different prices. Here is which one a small business needs, and what you should get for the money.
Personal data breach: the 72-hour rule in practice
The clock starts when you become aware, not when you understand. This guide walks a small company through assessing, documenting and reporting a breach to IMY, and deciding whether to tell the people affected.
Phishing protection for a small team
A small company is not too small to target; it is small enough that one click reaches the bank account. Here is a defence built from filtering, two-factor, a reporting habit and a plan for the click.
Cutting your cloud and hosting bill
Cloud bills grow quietly: a test server nobody turned off, a database sized for a launch that never came, backups kept forever. Here is how to find the waste safely.
The invisible risks of an old website
Old websites rarely break loudly. They drift out of support, out of compliance and out of search results quietly, and the bill arrives all at once. Here is what to check.
Security headers in plain language
Six short lines in your server configuration close a whole class of browser attacks. Here is what each security header does, and how to add them safely.
SPF, DKIM and DMARC: stop your emails landing in spam
Gmail and Microsoft now expect every sending domain to prove who may send in its name. Here is what SPF, DKIM and DMARC each do, and a rollout order that does not break your invoices.
SSL certificates and HTTPS: what can go wrong
The padlock is simple until it breaks. Here is what the certificate actually does, why sites suddenly show 'not secure', and how to make renewals boring.
Staging environments: test before it goes live
A staging site is a private copy of your website where changes are tested before customers see them. Here is how it works, and how to stop it leaking into Google.
Turning on two-factor authentication everywhere
A stolen password should not be enough to empty your ad account or hijack your domain. Here is the order to protect accounts in, which second factor to choose, and how to avoid locking yourself out.
Updating plugins without breaking your site
Updates are not optional, but breaking the site is. A short routine with a backup, a staging copy and a rollback plan makes update day uneventful.
Uptime monitoring: know before your customers do
Most small businesses learn their site is down from a customer. A monitor costs almost nothing and tells you first, but only if it checks the right things and alerts the right person.
Your web agency disappeared — get control back
The agency stopped answering and you have no logins. The order to recover domain, hosting, accounts and code, and how to prove it is yours.
Website backups and the restore test
A backup is a promise; a restore is proof. What to copy, how often, where to keep it, and the quarterly test that tells you whether the promise holds.
What does website downtime cost you?
Generic downtime statistics tell you nothing about your business. Here is a worksheet that prices an hour of outage from your own numbers, so the prevention decision is a calculation rather than a guess.
Not sure which package fits?
Book a free 15-minute call and we will match your needs to the right package — or tell you honestly if none of them fit.
Free · ~15 minutes · No obligation