Website security
Every site is a door. Someone is always trying it
Not because they know who you are — because it is scripted, and your address is on the list. This is what we do about it: close what can be closed, watch what cannot, and write down what happens if the day ever comes.
What you’re actually up against
Four things worth knowing before you spend anything. The short version is the headline; open one for the rest.
Nobody is targeting you. That is not the same as nobody trying
Almost none of it is personal. It is scripted traffic sweeping every address it can reach, looking for one known flaw in one common piece of software.
- The same sweep arrives at a two-person plumbing company the same week it arrives at a bank.
- So the real question is not whether anyone is trying — they are, today — but whether the thing they are trying still works on your site.
A custom-built site starts several steps ahead
Most site break-ins are not clever. They are a known hole in a plugin nobody updated.
- A typical small-business site runs thirty pieces of third-party code from thirty different authors — thirty doors somebody has to keep locked.
- There are no plugins in what we build, so most of that surface simply does not exist on a Harbor Tree site.
- A head start is not a finished job: the server, the forms, the logins, the keys and the people with access are all still there to get right.
There is no security plan to buy, and that is the point
Security sold separately asks you to make a second decision about a risk you probably don't believe you have — which is why almost nobody buys it, and why the sites that most need it are the ones that don't. So we stopped.
- Every site we build ships secured. That part is never an upgrade.
- Care Plus keeps it true as new flaws are announced: patched on announcement, scanned every week, the firewall and the headers kept current.
- Care Complete adds what only means something over a year: a written runbook, a quarterly access review and a security section in your monthly report.
The cost is never just the site
A defaced or hijacked site is a bad week — but it is rarely the expensive part. The expensive part:
- The warning on your Google listing, and the fortnight the phone does not ring because your top search results say the site may be harmful.
- The customer who filled in a form that was quietly forwarding somewhere else.
- The insurer asking, in writing, what controls you had.
Worth doing if
- You take payments, bookings or customer details through the site
- A customer, insurer or larger client has started asking how it's secured
- The site runs on WordPress and you've lost track of what's installed
- You'd have no idea what to do first if it went down dirty on a Sunday
Before anything else
These plans are for sites we built
There is no security plan to buy, and that is deliberate. Every site we build ships secured, and the plan you are already on is what keeps it that way — which is why the security climbs with the plan rather than sitting beside it on its own price list. If the site you're worried about is one we didn't build, we won't take it on where it stands: we don't put our name on a stack we can't maintain. Start with a Website Audit at $375 and we'll tell you honestly whether it's worth moving.
Why we won’t harden somebody else’s site
Securing a website means taking responsibility for the server it runs on, the code it runs, and every third-party piece somebody else chose. On a site we didn’t build we control none of those, and we can’t promise to defend what we can’t maintain. A shop that tells you otherwise is selling you a report, not a defence.
What to do instead — start with a Website Audit
$375, and you get a short written verdict on what you have: improve it, replace it, or leave it alone. If it’s worth moving we’ll say so and quote the migration; if it’s fine where it is we’ll tell you that too, and you’ll have paid $375 to stop worrying about it.
See what an audit and a migration costHow it climbs
The security comes with the plan
There is no separate security package and there is no one-time hardening fee. Every site ships secured; what each plan adds is how much of it stays proven, and how often.
Every site we build
included, never an upgrade
- Secure the day it ships security headers, encrypted transport and cookie handling set and tested before you go live, and your keys held in managed storage rather than sitting in the code — never sold back to you as a hardening package
Care Plus
$199 a month
- Security patched on announcement, not on a cycle when a flaw is published in something your site runs on, it is fixed that day rather than in the next update round
- File-integrity monitoring if what is deployed stops matching what we deployed, that raises an alarm rather than waiting for somebody to notice
- The firewall in front of your site kept current as attack patterns change
- A vulnerability scan every week against the live site, and anything it finds fixed on the plan
- Your security headers, encryption and cookies held to that floor on every change we ship checked before it goes out, so a change can't quietly undo what the site shipped with
Care Complete
$349 a month
- A security section in that report what got blocked, what got patched, and anything that needs a decision from you
- A written incident runbook who does what, in what order, with the phone numbers already in it — so the worst morning of the year is not also the one you improvise
- A quarterly access review every account that can reach the site, the hosting and the code, re-checked and cut back to who actually needs it, with the leavers found
The first rung is part of every build — you never buy it separately. The other two are not security products: Care Plus and Care Complete are the ordinary care plans, and the security climbs because the plan does.
Prices here are before tax. Maryland charges 3% sales and use tax on web and IT services, and a monthly plan is taxed every month rather than once at signup — so Care Plus at $199 a month reaches your invoice at $204.97. It appears as its own line rather than folded into the price, so you can always see what is our fee and what is tax. If your organisation holds a Maryland sales and use tax exemption certificate, send us the number and we'll apply it.
See the plans in full — what each one costs, what else it does, and the faster response clock any of them can run on.
Being straight with you
What none of this promises
No one can make a website unbreakable, and anyone who says otherwise is selling you a feeling. What these plans buy is a smaller target, a site that is watched, and a written plan for the morning something happens — not a guarantee, and not an insurance policy.
Your laptops, phones and email
We secure the website and the infrastructure it runs on. The most common way a small business actually gets robbed is a compromised email account, and that is your IT provider's ground — we will say so rather than sell you a plan that quietly does not cover it.
Ask what we'd coverA guarantee, or an insurance policy
These plans reduce the odds and shorten the response. They are not a warranty against a breach and they do not pay out if one happens — for that you want cyber liability cover, which is a broker's job and not ours.
Talk it throughCompliance certification
Care Complete produces the written evidence larger customers and insurers ask for, which answers most questionnaires. It is not a PCI, SOC 2 or HIPAA audit, and if you are being asked for one of those by name, you need an assessor.
Tell us what you were askedStart a project
Ready for a site that wins the job?
Tell us what you're working with. You'll get a plain-language reply — and if we're not the right fit, we'll say so and point you somewhere good.
Don't like the first design? Take your money back. What it covers
Want the number first? Build an estimate — a minute, and no email needed.
Not ready? Check your Google listing — free, about ten seconds.
Prefer email? contact@theharbortree.com
Tell us what you need
Three fields. Takes about thirty seconds.