Security
Hosting-level protections
What a host's own firewall and malware scanning actually cover, and the large remaining share of security work that is still entirely yours.
A web hosting provider generally defends the infrastructure a site sits on: the network, the server, the surrounding traffic. This is a real, valuable layer of cyber security protection. It stops a meaningful share of low-level attacks before they ever reach the site’s own software. It is also, on its own, a considerably smaller share of a small-business site’s genuine security exposure than most owners assume, because hosting-level security is only one part of the cyber security picture.
What web hosting’s own security protections typically cover
A network-level firewall, filtering out obviously malicious traffic patterns before they reach any individual customer’s site. Basic malware scanning across the server, looking for known malicious file signatures. Protection against volumetric attacks aimed at overwhelming the server with traffic. These operate at the infrastructure level, generally applied uniformly across every customer on the same hosting platform, and they require no configuration from the site owner to benefit from.
SSL/TLS certificates: the encryption most hosts now include automatically
Most web hosting plans today issue and automatically renew a free SSL certificate, commonly via Let’s Encrypt. The SSL/TLS certificate encrypts traffic between a visitor’s browser and the server, and shows as the padlock in the address bar. This is genuinely a hosting-level protection, not something a site owner has to source separately. It is still worth actively confirming rather than assuming. An SSL certificate that is not renewed automatically can lapse, and an expired SSL certificate presents visitors with a security warning that looks far more alarming than the underlying problem actually is.
What hosting-level website security does not cover
Software-level vulnerabilities in the specific CMS, theme or plugins a site runs are the exact category covered in why small-business websites get compromised. They are largely invisible to a generic, infrastructure-level scan. That is because they are specific to the application layer, not the server itself. A weak admin password, a compromised third-party account, or a plugin with a known, unpatched vulnerability: a host’s own firewall has no visibility into any of these. None of them look like malicious network traffic. Instead, they look like an ordinary, authorised login, or an ordinary application request.
Where a plugin-level or application-level firewall adds a genuinely separate layer
A security plugin or application-level firewall runs inside the CMS itself, rather than at the network edge. That lets it inspect requests with awareness of the specific software it is protecting. It can block a request pattern known to exploit a specific plugin vulnerability, for instance, in a way a generic network firewall cannot. This is a real, additional layer, not a duplicate of what hosting already provides, precisely because it operates with visibility the hosting layer does not have.
What these cyber-security products are sold as stopping, versus what they actually stop
Marketing for cyber security plugins and services frequently implies a comprehensive shield against being hacked at all. What they realistically provide is a further reduction in the same category of opportunistic, automated threats already covered by good hosting and good maintenance. That is an additional, worthwhile security layer. It is not a substitute for applying updates, using strong unique passwords, and maintaining a verified backup. A site with an active cyber security plugin and six-month-old, unpatched software is not meaningfully more secure than one without the plugin at all.
Malware, briefly, and what it actually does once it is in
Sometimes a compromise does succeed despite these layers. The resulting malware typically does one of a small number of things. It might inject spam content or hidden links into pages to manipulate search rankings. It might redirect some visitors to an unrelated scam site. Or it might quietly harvest data submitted through the site’s own forms. Symptoms vary. Sometimes they are highly visible; sometimes they are invisible to the site’s own owner for a long period. That is exactly why detection cannot rely on a business simply noticing something looks wrong.
What to actually ask a web host or supplier
Whether the hosting plan includes network-level firewalling and malware scanning as standard, or whether it is a separate paid add-on. Whether an application-level security layer is already configured for the specific CMS in use, or left entirely to the site owner to add. And, regardless of the answer to either, ask whether updates, strong access controls and tested backups are being actively managed. Those three consistently do more real protective work than either layer covered on this page.
DDoS protection against volumetric attacks, briefly
A distributed denial-of-service attack floods a server with overwhelming traffic, specifically to knock it offline rather than to break into it. That is a different goal from most of the compromises covered elsewhere in this section. Most reputable hosts include at least basic mitigation against smaller-scale versions of this by default. It is still worth asking specifically what protection exists for a site that would be genuinely damaged by extended downtime, such as one running time-sensitive promotions or bookings.
Why layering these protections is more effective than relying on one
Network-level firewalling, application-level security, and the ordinary maintenance discipline covered throughout this section each catch a different category of threat. No single layer catches everything the others do. A site might rely entirely on its host’s infrastructure-level protection, with no attention paid to its own software currency. That leaves the largest gap covered in why small-business websites get compromised completely unaddressed, however strong the underlying infrastructure is.
What a reasonable small-business hosting security setup actually looks like
Four things, combined, are what it takes: competent hosting with standard infrastructure-level protection, a maintained CMS with prompt updates, strong unique passwords with two-factor authentication on key accounts, and verified working backups. Together, this ordinary combination closes the overwhelming majority of realistic risk for a small-business site. None of it is exotic or expensive.
Where to go from here
The causes these layers exist to guard against are set out fully in why small-business websites get compromised. And confirming what a build actually includes at both the hosting and application layer is worth settling explicitly as part of web development services.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- what security does hosting actually provide
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 3 August 2026
- Search results inspected for intent
- No
Source: research/outer-volume-au.json · DataForSEO Google Ads search_volume and Labs bulk_keyword_difficulty, location_code 2036 (Australia), language en · pulled 3 August 2026.
Provenance
Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-03.
Sources
- Outer-cluster demand measurement (this site) —
research/outer-volume-au.json