A website is not a one-time purchase. It is a piece of infrastructure that keeps running whether anyone is paying attention or not, and the risk on it compounds the same way. Most owners find out what was wrong only after something breaks: a customer complaint, a compliance letter, a plugin that quietly stopped getting updates three years ago.
The four risks that actually show up
- Accessibility. Web accessibility lawsuits against small and mid-sized businesses have been rising for years, and most target the same handful of issues: no alt text, poor color contrast, forms that do not work with a keyboard. None of these are hard to fix once you know they exist.
- Outdated software. A CMS, plugin, or theme that has not been updated is a known, published list of vulnerabilities that anyone can look up. This is the single most common way small business sites get compromised.
- Privacy and cookie disclosures. If your site sets cookies, tracks visitors, or collects emails, your privacy policy needs to say so accurately. "We do not use cookies" stops being true the day you add an analytics script or an email signup, and an inaccurate policy is worse than none.
- No written record of what is running. If you could not list your site's platform, plugins, and who has admin access right now, from memory, you do not have a security posture. You have a hope.
Why this is a business problem, not a technical one
None of these risks show up as a line item until they do: a lost sale because a form silently failed, a legal letter because a screen reader user could not check out, a Monday morning spent explaining to a customer why their data leaked. The fix is cheap. The unmanaged risk is not.
The starting point is simply knowing what you have. A proper audit checks the platform and hosting, runs an accessibility pass against WCAG 2.1 AA, reviews on-page SEO basics, and tests real-world performance on a phone, then hands you a written, prioritized list. Not a sales pitch. A punch list you can act on with us or without us.