Cover your assets: five things to protect in twenty minutes

Your website matters. So do these five, and almost nobody checks them.

 approx 5 minute read

Two huge companies, one very simple trick

Between 2013 and 2015, Google and Facebook paid out $122 million to one man sending invoices from a company he had invented.

Nobody went near either website.

That is the whole point of this article. Two of the best defended companies on earth, and the way in was an email address that looked close enough.

Your website is one door into your business. It matters, and we have written plenty about keeping everything up to date.

But it is one door.

Your business has several others, and most of them have never had so much as a glance. They are not exciting. There is no industry selling you fear about them. Which is exactly why they get missed.

So here they are. Five assets that sit outside your website, what actually goes wrong with each one, and a check you can run today.

Most take about two minutes. Twenty for the lot.

Book of domains icon

#1 Your domain name

Your domain is the only thing on this list you genuinely cannot replace.

Everything else can be rebuilt. If your domain lapses and somebody else registers it, your website, your email and years of built-up search visibility all leave together.

It happens far more often than you would think, and never for dramatic reasons. Usually it is a card that expired. Or auto-renew switched off years ago by someone who has since left. Or renewal reminders going to an email address nobody reads anymore.

There is a grace period after expiry. After that, the domain goes to auction. And there is a whole industry of people watching for expiring domains that already have traffic.

Check this today:
Log in to wherever your domain is registered. Confirm the expiry date. Confirm auto-renew is switched on. Confirm the card on file has not expired. Add a backup. Then check which email address the renewal reminders go to. If it belongs to someone who left in 2021, fix that first.

Email icon

#2 Business email

This is the one UK businesses genuinely get caught by.
The government’s Cyber Security Breaches Survey for 2025/26 found that 43% of UK businesses reported a breach or attack in the previous twelve months. Phishing was the most common type by a distance, affecting 38% of businesses. Of those hit by anything at all, 69% said phishing was the most disruptive thing that happened to them.

Scaled up, that is around 612,000 UK businesses. Not exotic attacks. Emails.

Invoice fraud runs in two directions, and they need different answers.

Someone pretending to be you:
They email your customer, apologise for the confusion, and supply new bank details. Your customer pays. You never see the money, and you have a difficult phone call ahead of you.

This one is technical, and it is fixable. There are three settings on your domain that make you much harder to impersonate. They are called SPF, DKIM and DMARC. You do not need to understand how they work. You just need to know whether you have them, because a domain without them is far easier to spoof. Most small businesses have none of the three and have never been told they exist.

Someone pretending to be your supplier:
This is the more common one, and it catches out businesses of every size. An invoice arrives from a company you genuinely buy from, and the bank details have changed.

No setting on your domain stops this. Look again at what happened to Google and Facebook. Nothing was hacked and nothing was spoofed. A real company was registered under a plausible name, and it sent real invoices from real email addresses. There is no technical control that catches that.

What catches it is a rule. Bank details never change on the say-so of an email. If a supplier’s details change, you ring them on the number you already had, not the one printed on the invoice.

Check this today:
Two things. First, find a free DMARC checker online (MXToolbox is a common one), type in your domain and see what comes back. Thirty seconds. If it reports nothing configured, that is worth a conversation with whoever looks after your email. Second, agree the rule with whoever pays your invoices. Changed bank details get verified by phone. Every time.

Goggle logo

#3 Your Google Business profile

For a local business, this can sometimes be worth more than the website.

It is what appears in Maps and in local search results, carrying your opening hours, your phone number, your photos and your reviews.

It is also a target. Competitors and scammers can attempt to claim ownership of a profile. Google emails the registered owner when that happens, and that email very often goes to an address nobody monitors.

The reviews are the part that really stings. Years of them, gone.

Check this today:
Firstly, make sure you have claimed your own listing. Then sign in to your Google Business Profile and look at who has access. Check both owners and managers. If there is an old agency, an ex-employee or an account you do not recognise, remove them. While you are in there, check the opening hours are still correct.

Account and gear icon

#4 The account that controls everything

Somewhere there is an email address that can reset the password to almost everything else you own. Your domain. Your hosting. Your website login. Your Google account. Possibly your bank.

That address is the master key.

For a lot of small businesses, it is a personal Gmail account with a password chosen in 2016, which has also been used on nine other websites, at least two of which have since been breached.

The most secure website in the world does not help if someone can log into the email account that controls it.

Check this today:
Two things. First, put two factor authentication on that email account if it is not already there. Second, go to haveibeenpwned.com, type the address in, and see which breaches it has appeared in. It is free, it is legitimate, and the results are usually sobering.

Social icon

#5 Your social accounts

The problems here are boring ones. One person has access and they left last year. There is no two factor authentication. The Facebook page is tied to somebody’s personal profile rather than a business account. Nobody can remember the login for the account you set up in 2019 and then abandoned. Business profiles on Meta platforms are notoriously difficult to reclaim.

Plus, abandoned accounts matter more than people expect. If somebody gets into a dormant profile with your name on it, they are posting as you.

It’s more likely that phishing scams are set up in the name of Meta, pretending there is a problem with your page. But this is often just a ploy to get you to enter your login credentials.

Check this today:
List every social account your business has, including the ones you never use. For each one, work out who has access and whether two factor is switched on. Close anything you have genuinely abandoned. Be careful when prompted to enter login details.

5 keys checklist

Now the honest bit

We sell website care plans. We look after WordPress sites, keep them updated, monitor them, back them up.

A care plan does not do any of the above.

It will not renew a forgotten domain. It will not stop someone spoofing your email address. It will not protect your Google Business Profile, or your social accounts, or the personal Gmail that unlocks the lot.

A locked front door is not much use if the window is open.

The five checks on this page are free, and between them they take about twenty minutes. Do them this week and you will have covered ground most business owners never look at once.

One last thing

If you work through that list and something looks off, or you are not even sure where your domain is registered, just ask. We deal with this daily and we are happy to point you in the right direction, customer or not.

And if you would like to read more about the website side of things, start here.