Cyber Security for a Small Ecommerce Business
An online store never closes, which makes it a permanent target. This article covers the essentials for a small UK ecommerce business: keeping your platform and plugins updated, taking payments without touching card data, protecting customer information under UK GDPR, spotting fraud early, and keeping backups you have actually tested. Practical, plain-English steps you can act on.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
An online store never closes
A shop with a front door is only exposed while it is open. An online store is open every hour of every day, visible to the entire internet, including the automated tools that constantly scan websites looking for a weakness to exploit. That is not a reason to panic, but it is a reason to get the basics right. For a small ecommerce business, a security incident does not just mean downtime, it can mean lost sales, exposed customer data, and a real dent in the trust that took you years to build.
Here are the areas that matter most, in plain English.
Keep your platform and plugins updated
Whether you run on Shopify, WooCommerce, a hosted platform or something custom, the single most common way small stores get compromised is out-of-date software. That includes:
- The shop platform itself
- Your theme or template
- Every plugin, app or extension you have installed
Attackers do not usually target you by name. They scan for known weaknesses in popular plugins and exploit them automatically, at scale. A plugin you installed once for a promotion two years ago and forgot about is a classic way in.
So: turn on automatic updates where you can, apply updates promptly where you can’t, and remove anything you no longer use. Every plugin is a door into your store, and the fewer doors you have, the fewer you have to guard. Stick to well-reviewed, actively maintained plugins from reputable sources, and be wary of “free” versions of paid tools from unofficial sites.
Take payments without touching card data
The safest card data is the data you never hold. Use a reputable payment provider so that when a customer pays, their card details go straight to the provider and are handled on their secure systems, not stored on yours.
- Never store full card numbers in your own database, spreadsheets or emails.
- For repeat or subscription payments, let your provider store the card securely and give you a token to charge against. Your store holds the token, not the card.
- Complete the annual PCI self-assessment your provider supplies.
Handled this way, the bulk of payment security sits with your provider, and your own compliance burden shrinks dramatically.
The safest card data is the data you never hold.
Protect customer data under UK GDPR
Even if you never touch card numbers, you still hold personal data: names, delivery addresses, emails and order history. Under UK GDPR you have a legal duty to look after it. For a small store the practical steps are manageable:
- Only collect what you need. Every extra field you store is extra risk and extra responsibility.
- Have a clear privacy notice explaining what you collect and why.
- Keep it secure. That means updated software, strong admin logins, and encryption in transit (the padlock/HTTPS on your site).
- Don’t keep data forever. Delete or anonymise old records you no longer need.
- Know your breach duty. A serious personal data breach usually must be reported to the ICO within 72 hours, so it pays to know in advance who would handle that.
Good data hygiene is not just compliance, it is good business. Customers increasingly choose shops they trust with their details.
Lock down your admin access
Your store’s admin panel is the keys to the kingdom. If an attacker gets in, they can steal customer data, redirect payments or quietly insert a card-skimming script.
- Use a strong, unique password for the admin account, stored in a password manager such as Proton Pass rather than reused from another site.
- Turn on multi-factor authentication so a stolen password alone is not enough to log in. This is the single most valuable step you can take.
- Give staff their own accounts with only the access they need, and remove those accounts the day someone leaves.
Watch for fraud
Online stores attract two kinds of fraud, and it helps to be alert to both.
- Payment fraud, where stolen cards are used to buy from you. Your payment provider will offer fraud-screening tools; turn them on, and be cautious with unusually large orders, mismatched billing and delivery addresses, or a rush of failed payment attempts.
- Phishing aimed at you and your staff, where a convincing email pretends to be your platform, courier or bank to trick you into handing over your login. Slow down, check the sender, and never log in via a link in an unexpected email. Our guide on how to spot a phishing email covers the tell-tale signs.
Back up your store, and test the restore
If your store were defaced, corrupted by a bad plugin update, or hit by ransomware, could you get it back? A good backup routine means yes.
- Back up your store’s data and configuration regularly, with a copy held somewhere separate from the live site.
- Do not assume your platform does this for you in a way you can actually restore from. Check exactly what is covered.
- Test a restore. A backup you have never restored from is a guess, not a safety net. Our guide to 3-2-1 backups and disaster recovery explains how to do this properly.
A sensible standard to aim for
Most of the steps above map neatly onto the government-backed Cyber Essentials scheme, which is a practical benchmark for any small business and increasingly something larger customers and suppliers expect to see.
You do not have to do all of this alone. As a UK cyber security and managed IT provider, DACROS helps small online retailers get these foundations right and keep them that way. If you would like an honest review of how your store is protected, get in touch and we will talk it through in plain English.
Frequently asked questions
What is the biggest security risk for a small online store?
For most small stores it is out-of-date software: the shop platform itself, its theme and especially its plugins or apps. Attackers scan the web for known weaknesses in popular tools and exploit them automatically. Keeping everything updated, and removing plugins you no longer use, closes off the most common way in.
Do I need to store customers' card details to take repeat payments?
No, and you should not. A reputable payment provider stores card data securely on their systems and gives you a token to charge against for repeat or subscription payments. Your store never holds the actual card number, which keeps you safer and dramatically reduces your PCI and GDPR burden.
What does UK GDPR mean for my online shop?
It means the customer data you hold, names, addresses, emails and order history, must be collected fairly, kept securely, and not held longer than you need it. You should have a clear privacy notice, only ask for data you genuinely need, and be able to respond if a customer asks what you hold. A serious breach must be reported to the ICO, usually within 72 hours.
How do I protect my store's admin login?
Use a strong, unique password stored in a password manager, and turn on multi-factor authentication so a stolen password alone is not enough to get in. Give staff their own accounts with only the access they need, remove accounts when people leave, and never share one admin login across the team.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.