SECURITY

Security starts on day one of the build.

A site is made safe when it is designed, not patched up afterwards. We learned that in data loss prevention, which is the work of stopping sensitive information from leaking out of an organisation.

Launch checklist kept with your job

  1. Who can see what
  2. Passwords and keys
  3. Forms and sign-ins
  4. Outside components
  5. Backups
  6. A record of what happened
  7. Your customers’ details

IF ONE FAILS The launch waits.

Our security practice comes from work in corporate cyber security across both finance and healthcare, where the information at stake is financial and patient records and a leak cannot be taken back. That is not the usual background for a web studio. It means your customers’ names, bookings and payments get the question we asked there: what could go wrong here, and who would it hurt?

Six things we do on every job.

Most of what keeps a site safe is decided before launch, so that is where most of our work goes. This is our approach, in the order it happens.

  1. In your scope

    We write down what your site will hold, and who can see it.

    Before anything is built, your written scope comes with a plain list of the customer details your site will hold and who is allowed to see them. Who can see what is decided before a single page is written, so it is designed in and not patched on.

    You read it and correct it before you have paid anything.

    From a written scope. An example, for a booking site.

    • Names and phone numbers Seen by you and your front desk
    • Booking dates and times Seen by you and your front desk
    • Messages from the enquiry form Seen by you
  2. In the build

    Nothing real, nothing secret, nothing extra.

    Three rules for the weeks your site is being built.

    • Real customer details on a laptop Made-up data, from day one. We build and test with it. Your customers’ details never go into AI tools either.
    • Passwords and keys in the site’s code Keys locked away on the server. From the first day they sit in a locked settings area, never in the code.
    • Every add-on going As few outside parts as the job needs. We check every one, so there is less that can go out of date.
  3. On every change

    Every change is reviewed before it goes in.

    Automatic checks run on every change, and one of us reviews it before it goes in. We use AI to build, inside rule sets we wrote ourselves that hold it to our engineering and security standards. It does not approve its own work.

    1. A change is written
    2. Automatic checks run
    3. One of us reviews it
    4. It goes in

    Sign-in, payments and anything that touches personal details is reviewed by both of us.

  4. Before launch

    Seven checks, and the launch waits if one fails.

    They are part of every package, not an add-on. A backup is restored as a test, and the completed checklist is kept with your job.

    Launch checklist all seven, every time

    1. Who can see whatCustomer details are visible only to the people who should see them.
    2. Passwords and keysNone are left in the site’s code.
    3. Forms and sign-insProtected against spam, guessing and misuse.
    4. Outside componentsEvery add-on is checked before it goes in, and again at each release.
    5. BackupsRunning from day one, with one restored as a test.
    6. A record of what happenedThe site keeps a log, so if something does go wrong we can see what and when.
    7. Your customers’ detailsThey never go into AI tools. We build and test with made-up data.
  5. At handover

    Every key replaced. Everything in your name.

    On launch day we replace every key used during the build, so nothing from the build still works. Your web address, hosting and code are confirmed in accounts in your name, and you can leave at any time with no exit fee.

    Handover pack launch day

    • Your web addressIn an account in your name.
    • Your hostingIn an account in your name.
    • Your codeIn an account in your name.
    • Every key from the buildReplaced, so nothing used during the build still works.
  6. After launch

    Kept patched, backed up and watched.

    A website is software, and new holes are found in software all the time. Faults are fixed free for 30 days and the first month of care is free. After that a care plan keeps your site looked after, from $150 a month. It is optional and runs month to month.

    See what each care plan covers

    • Patched Security patches on a schedule, to close newly found holes.
    • Backed up A copy saved every day, so a mistake or an attack can be undone.
    • Watched An alert tells us if your site goes down.

We will not tell you your site can never be broken into. Nobody can honestly promise that. What we can show you is that every step here was done.

Why we work this way.

Why security matters, in two topics

Why it matters more now.

AI has made websites quicker to build and quicker to attack. Both sides are moving faster, so how a site is built, and whether anyone keeps it up to date, matters more than it used to. We use AI ourselves, inside our own rules and with one of us reviewing every change.

In Australia

6 minutes between cybercrime reports in 2024–25. The average cost to a small business rose 14% to $56,600.

Australian Signals Directorate, Annual Cyber Threat Report

Lost to scams

$2.18 billion was reported lost to scams by Australians in 2025.

National Anti-Scam Centre, March 2026

How it goes wrong.

Most attacks on small business websites are not personal. They are automatic, and they find whichever sites were left open. These are four ways it usually happens. Pick one to follow it through.

The update nobody did

  1. A hole is found

    A flaw turns up in a popular piece of website software, and the fix is published the same week.

  2. Nobody applies the fix

    Your site looks fine, so nobody touches it. The software underneath is now known to be breakable.

  3. Bots come looking

    Automated programs scan the internet for sites that have not been fixed. They are not looking for you. They are looking for everyone.

  4. The site is taken over

    Spam pages, fake links or a redirect to a scam get added. Often you cannot see them when you look at your own site.

What it costs you

Google can mark the site as unsafe, visitors get a warning, and you usually find out from a customer.

Where we stop it

In the build. We use as few outside components as the job needs and check every one, so there is less that can go out of date.

After launch. Security patches on a schedule, an alert if the site goes down, and a daily backup to roll back to.

The page anyone can open

  1. No lock on the door

    A site is put together fast, often with an AI tool. A page that lists bookings or customer details goes live, and nobody checks whether it asks who is looking.

  2. Someone finds the address

    A bot, a competitor or a curious customer tries the page address and sees every name, phone number and booking.

  3. The list is passed on

    Once the details are copied, they are out. Lists like this are sold and shared between scammers, who put them to work quickly.

  4. Your customers hear from “you”

    A message arrives using their real name and their real booking. It asks them to pay again, confirm a card or use new bank details.

What it costs you

Your customers’ trust, and sometimes their money. Payment redirection scams, where a fake invoice or changed bank details arrive in a real business’s name, cost Australians $166.8 million in 2025.

National Anti-Scam Centre, March 2026

Where we stop it

In the build. Who is allowed to see what is decided before a single page is written, and every page that shows customer details checks the visitor first.

Before launch. We sign in as someone who should not have access and try every page. If we can see it, it does not go live.

The key left in the code

  1. The site needs a key

    To take payments or send email, your site holds a secret key from the payment or email company.

  2. The key is left in plain view

    A rushed build puts that key in the part of the site every visitor’s browser downloads.

  3. It gets collected

    Bots gather keys from websites all day. Yours is now in someone else’s hands.

  4. Your accounts get used

    Spam goes out in your name, or charges run through your account, until the provider shuts it off.

What it costs you

Your email or your payments stop working, and it tends to happen on a busy day.

Where we stop it

In the build. Keys never go in the site’s code. From the first day they sit in a locked settings area on the server, and we check for stray keys before every release.

At handover. We replace every key, so nothing used during the build still works.

The backup that never worked

  1. Something breaks

    A bad update, a staff mistake or a problem at the hosting company takes the site down.

  2. You ask for the backup

    Whoever built the site says there is one.

  3. It does not restore

    The backup is months old, incomplete, or was never tested.

  4. You start again

    The site is rebuilt from memory and screenshots while customers find you offline.

What it costs you

Days or weeks offline, and the price of building the site a second time.

Where we stop it

In the build. Daily backups are switched on before the site goes live, not after the first problem.

Before launch. We restore one to prove it works, and keep testing on a schedule under a care plan.

Fifteen years of the same mistakes.

Ten real cases from the public record, from 2011 to 2026. The names and the sizes change. What went wrong does not: each came down to something ordinary that nobody checked. Big names make the news, but these are the same gaps automatic attacks look for in a small site.

Pick a number to read what happened

The backup that never worked

Distribute.IT

2011 · Australia

An Australian web host was attacked in June 2011. On a Saturday afternoon the attacker wiped four servers and the backups with them. The company told customers that about 4,800 websites could not be rebuilt, and many of those customers had no copy of their own. Within two weeks the business had been sold to a competitor.

4,800 websites lost for good

Where we stop it

Backups. Your site has its own daily backup, switched on before launch, and we restore one to prove it works.

Sources: Delimiter, June 2011 and Public Accountant, November 2025

The backup that never worked

GitLab

2017 · Worldwide

GitLab hosts software projects for developers. In January 2017 an engineer deleted the live database by mistake, on the wrong server. The company had five ways of backing up or copying that data, and none was working reliably. The daily backup had been failing silently, and the warning emails never arrived. The site was down for about 18 hours, and about six hours of customers’ issues, comments and other project records were gone for good. The code itself was not lost.

0 of 5 backup methods working reliably

Where we stop it

Backups. A backup only counts once it has been restored. We restore one before launch, and keep testing on a schedule under a care plan.

Sources: GitLab, incident report, 1 February 2017 and GitLab, postmortem, 10 February 2017

The update nobody did

Equifax

2017 · United States

In March 2017 the credit bureau was warned about a flaw in software it used. Nobody checked that the fix went in, and the system was still unpatched four months later. Attackers used the gap to take names, birth dates and other records of about 147 million people. The settlement that followed was at least US$575 million.

147 million people’s records taken

Where we stop it

Security patches. Under a care plan they go in on a schedule, so a published fix does not sit waiting.

Source: US Federal Trade Commission, July 2019

The key left in the code

Toyota

2022 · Japan

A subcontractor building a Toyota customer website uploaded part of its code to a public code-sharing site, with an access key inside it. The key sat in public view from December 2017 until September 2022. It opened a server holding the email addresses of 296,019 customers, and Toyota said it could not rule out that someone had used it.

296,019 customers behind one stray key

Where we stop it

Passwords and keys. Keys never go in the site’s code, and we check for stray keys before every release.

Source: TechCrunch, October 2022

The page anyone can open

Optus

2022 · Australia

The communications regulator, ACMA, alleges in court that a coding error in 2018 switched off the checks on who could ask an Optus system for customer records, and that the system was later left facing the internet. ACMA says getting in took no special skill, only trial and error. The records of about 9.5 million people were reached. Optus is defending the case.

9.5 million people’s records reached

Where we stop it

Who can see what. Every page that shows customer details checks the visitor first.

Sources: CSO Online, on ACMA’s court filing, June 2024 and ABC News, August 2025

The password someone guessed

KNP

2023 · United Kingdom

KNP was a 158-year-old British transport company running about 500 lorries. In 2023 attackers got in through what is believed to be one guessed staff password, then locked the company’s data and held it to ransom. KNP had cyber insurance and said it met industry standards. It did not recover, and about 700 people lost their jobs.

700 jobs gone

Where we stop it

Forms and sign-ins. Sign-in pages are protected against guessing before the site goes live.

Source: Container News, on reporting by the BBC

The update nobody did

WordPress sites

2023 · Worldwide

WordPress is the most widely used website software in the world. By 2023 Sucuri, a security firm, had tracked one campaign that it estimates infected more than a million WordPress sites from 2017 onwards, using known holes in themes and plugins. Waves of attacks sometimes began within hours of a new hole being announced. Visitors to an infected site were sent on to fake tech support and fake prize pages.

1 million+ websites infected, by Sucuri’s estimate

Where we stop it

Outside components. We use as few as the job needs and check every one, so there is less that can go out of date.

Sources: Sucuri, April 2023 and W3Techs, usage of WordPress

The part someone else wrote

Polyfill

2024 · Worldwide

Polyfill was a free helper script that more than 100,000 websites loaded from someone else’s server. In February 2024 the web address behind it was sold. By June the script had been changed so that some phone visitors to those sites were sent to scam pages, such as fake betting sites. The site owners had not changed a thing.

100,000+ websites affected by one change

Where we stop it

Outside components. Every add-on is checked before it goes in, and again at each release.

Source: BleepingComputer, June 2024

The page anyone can open

Tea

2025 · United States

Tea is an app where women share reviews of men they have dated or are dating, and it asked early members for a selfie and photo ID to join. In July 2025 its image storage was found open, with no sign-in needed. About 72,000 images were exposed, 13,000 of them selfies and photo IDs. A second database held 1.1 million private messages.

72,000 images left open

Where we stop it

Who can see what. Before launch we sign in as someone who should not have access and try every page. If we can see it, it does not go live.

Source: BleepingComputer, July 2025

The key left in the code

Moltbook

2026 · Worldwide

Moltbook is a social network for AI agents. Its founder said he had not written a single line of its code, and that AI had built it. Researchers at Wiz found the key to its database in the code every visitor’s browser downloads, with nothing limiting what that key could open: 1.5 million access tokens, 35,000 email addresses and private messages. It was fixed within hours of being reported.

1.5 million access tokens exposed

Where we stop it

Passwords and keys. Keys sit in a locked settings area on the server, not in code a browser downloads, and one of us reviews every change before it goes live.

Source: Wiz, February 2026

Tell us what you need, in your own words.

The first call is free and takes 30 minutes. You get a written scope and a fixed quote within three business days, and if we are not the right fit we will tell you.

Book a free call
Top