29th September 2026
If you run a small business website, you might assume that nobody is interested in hacking it.
After all, why would a criminal spend time attacking a small business in Caithness, Wick or Thurso when there are much bigger organisations to go after?.
There is some truth in that thinking.
But there is also an important catch.
The attacker may not care who you are.
Increasingly, computer systems can scan huge numbers of websites looking for particular weaknesses. If your website happens to be running vulnerable software, you can become a target simply because your website has presented an opportunity.
And artificial intelligence could make that process faster.
It may be your website, but they could be looking beyond it
Imagine somebody walking down a street trying the doors of hundreds of houses.
They are not necessarily interested in who lives in each house.
They are looking for one with an unlocked door.
Internet attacks can work in a similar way.
A criminal can scan websites and servers looking for outdated software, badly configured services, weak passwords or other known weaknesses.
If something is found, the website itself may not even be the ultimate prize.
The attacker may be interested in what lies behind it.
That could include the hosting account, other systems connected to the same network, customer information, administrator credentials or simply the opportunity to use the compromised website for another criminal purpose.
Whether that is possible depends heavily on how the website and hosting environment have been designed.
The National Cyber Security Centre warns that attackers can use compromised internet-facing systems as a starting point for further activity. It also stresses that administrative accounts and credentials are particularly attractive targets.
AI changes the economics
This is where the recent stories about ChatGPT, DeepSeek and other AI systems become relevant.
OpenAI has disclosed cases where people involved in cyber operations used ChatGPT for tasks including researching vulnerabilities, developing and modifying malicious software, reconnaissance and phishing.
OpenAI said the attackers were mainly using AI to make existing techniques faster and more efficient rather than obtaining completely new hacking capabilities.
That distinction is important.
AI did not invent hacking.
But if it can help someone automate parts of the process, an attacker may be able to examine many more potential targets.
That means a small website does not necessarily have to be important to become interesting.
It simply has to be vulnerable.
So what should a small website owner do?
The good news is that the answer isn't to become a cybersecurity expert.
The first step is to know what actually runs your website.
Is it WordPress?
Which plugins are installed?
Who provides the hosting?
Who has administrator access?
Are there old accounts that nobody uses any more?
When was the software last updated?
Those are surprisingly important questions.
Keep everything updated
Website software, plugins and themes should be kept up to date.
One of the easiest opportunities for an attacker is software with a publicly known vulnerability for which an update already exists.
An old plugin that nobody remembers installing can potentially be more important than the website's visible pages.
Protect the administrator account
The website administrator's login is effectively the front door.
Use a strong, unique password.
Don't use the same password for the website that you use for email, banking or other services.
Where available, turn on two-step verification or multi-factor authentication.
The NCSC specifically recommends strong, separate passwords and two-step verification for important online accounts.
Know who has access
Small businesses sometimes accumulate administrator accounts over the years.
A web designer gets access.
An employee gets access.
Someone else helps with the website.
Eventually nobody is quite sure who can still log in.
That is worth checking.
Remove accounts that are no longer required and make sure former employees or contractors cannot continue accessing the site.
Back up the website
This is one of the most important precautions.
If something goes wrong, the question becomes:
Can I rebuild my website?
A good backup can turn a major disaster into a major inconvenience.
The NCSC recommends regular backups and, particularly against ransomware, keeping copies separate from the systems being backed up. It also recommends regularly testing that backups can actually be restored.
A backup that has never been tested is rather like a spare tyre that has never been checked.
It might be fine.
Until you need it.
Ask your hosting company some questions
This is probably particularly important for small website owners who do not manage their own servers.
Ask the hosting company:
Are my website and database isolated from other customers?
Do you monitor for vulnerabilities?
Are backups maintained separately?
Do you provide two-factor authentication for the hosting account?
What happens if my website is compromised?
A good hosting company should be able to answer these questions.
And if the answer to several of them is "I don't know", it may be time to find out.
Don't panic about AI
There is no reason for a small business owner to hear these stories about AI hacking and immediately assume their website is under attack.
Most website owners will never know whether their site has been automatically scanned.
The important point is that scanning is increasingly cheap and automated.
The sensible response is therefore not fear.
It is preparation.
The UK's National Cyber Security Centre now has a free Cyber Action Toolkit specifically designed for small businesses and sole traders, with practical steps that can be worked through without specialist technical knowledge.
The smallest businesses can be surprisingly exposed
There is a temptation to think that hackers only want banks, governments and large corporations.
But criminals don't necessarily think in those terms.
They may simply be looking for weaknesses.
A small business website with no customer database and no valuable financial information might still be useful as a stepping stone, a source of credentials, a platform for distributing malicious material or simply another compromised computer system.
That doesn't mean every small website is about to be hacked.
It means that being small is not a security system.
The good news is that many of the things that make a website harder to attack are remarkably ordinary.
Update the software.
Protect the administrator account.
Use two-factor authentication.
Remove unnecessary users.
Back up the site.
Keep the hosting account secure.
And know who is responsible for looking after the technical side.
AI may be changing the economics of cybercrime.
But the basic defence remains surprisingly old-fashioned.
Don't make your website the easiest door on the street.