We sell website security, so treat this with appropriate scepticism. But we would rather give you an honest framework than a scare story, partly because the scare stories are tiresome and partly because clients who buy something they did not need do not stay.
So: is website security worth paying for? For some businesses clearly yes. For others, genuinely not.
When it probably is not worth it
Let us start here, because this is the part most providers skip.
A monthly service is likely unnecessary if your site is a simple brochure with a handful of pages, brings in little or no business, takes no payments and stores no customer data, could be rebuilt in a weekend, and is already kept updated by someone.
If that is you, good hygiene is probably enough: keep things updated, use two-factor authentication, delete plugins you do not use, and keep a backup. Our hardening checklist covers the free version of this properly.
Security spending should be proportionate to what you would actually lose. For some sites that is genuinely not much.
When it clearly is worth it
The calculation changes when one or more of these is true:
- The site generates real revenue — enquiries or sales you would miss
- You take payments or hold customer data — the downside is legal as well as commercial
- Organic search matters to you — rankings take months to rebuild after a blacklisting
- You have been compromised before — recurrence is common, particularly if the cause was never established
- Nobody would notice for weeks — this is the deciding factor more often than anything else
- You run several sites — the weakest one sets your risk
- Rebuilding would be expensive — a complex or custom site is not a weekend job
That fifth point deserves emphasis. The technical severity of an attack matters far less than how long it runs undetected. Same vulnerability, same attacker: caught in hours it is a minor incident, caught in six weeks it is a blacklisting, a suspension and months of SEO recovery.
Do the arithmetic yourself
Rather than accept anyone's framing, work it out.
What does a day offline cost you? Monthly website revenue divided by trading days. Add the enquiries that go to a competitor instead.
What would a compromise cost? Emergency clean-up, several days of lost traffic while a warning shows, customers who saw a redirect, months of ranking recovery, and your own time spent on none of your actual work.
How likely is it? Higher than most people assume for an unmaintained site, and it rises the longer nothing is updated.
Compare that with twelve months of a monitoring service. For a business doing meaningful revenue online, the comparison is usually not close. For a low-stakes brochure site, it may well be.
What you are actually buying
Worth being precise, because "security" is sold vaguely.
You are not buying immunity. Nothing prevents every attack, and any provider promising that is overselling.
What you are buying is reduced detection time, and prevention of the routine attacks. Instead of finding out in six weeks from a customer, you find out in hours. That single change is where nearly all of the value sits, because it is what determines whether an incident is small or expensive.
You are also buying the removal of a recurring task you will otherwise forget. Not because you are careless, but because running a business means the website is the least urgent thing until it is the most urgent.
Questions worth asking any provider
Including us. These separate a real service from a plugin licence with a markup:
- Who reads the alerts? If the answer is you, it is software, not a service
- Is scanning server-side? Homepage-only scanning misses most modern infections
- Is the database scanned? Files-only scanning is why sites reinfect
- If something is found, is clean-up included or billed separately?
- How fast are security patches applied? Days matter; monthly is too slow
- What is the actual response time when something goes wrong?
Vague answers to these are informative.
The middle options
It is not binary. Several sensible positions exist between doing nothing and a full monthly service.
Do the free things properly. Updates, two-factor, removing unused plugins, backups. This is most of the risk reduction and costs only attention.
Pay for a one-off hardening and audit. Get the site into good shape, then maintain it yourself.
Cover only what matters. If you run six sites and one takes payments, protect that one properly.
Buy the maintenance, not the security. For many sites, reliable updates and backups through a managed plan addresses the actual exposure.
Our honest position
If your website is genuinely part of how your business earns money, something should be watching it. Whether that is us matters less than that it is someone.
If it is a simple site that would be a mild inconvenience to lose, keep it updated, back it up, and spend the money elsewhere. We will tell you that on a call rather than sell you a plan you do not need.
What we would push back on is the middle position we see most often: a site that clearly matters commercially, with nobody watching it, and an assumption that nothing will go wrong because nothing has yet. That is not a decision, it is a deferral — and it usually gets resolved by an incident rather than a choice.
If you want a straight answer about your site
Our security monitoring service covers continuous server-side scanning, file integrity alerts, a managed firewall, prompt patching, and a person who reads the alerts and acts.
But before that, send us your web address. We will look at what you are running and tell you plainly whether you need us — including if the answer is no.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.