Security budgets have historically been argued as insurance — a cost you accept to avoid a bad outcome. That framing made sense when the website was a brochure.
It stopped making sense when the website became the acquisition channel. What is being protected now is pipeline.
What actually happens after a compromise
The downtime is the least of it. The sequence that follows costs far more and lasts far longer.
Search engines detect malicious content and de-index or flag the site, often within hours. Browsers begin showing interstitial warnings, which reduce conversion to approximately zero regardless of what the page says. Removal from those lists requires review and takes days after the fix is complete.
Meanwhile every acquisition channel pointing at the site is spending into a wall — paid campaigns, email links, assistant citations and the organic traffic you spent months earning.
The recovery clock does not start when you fix the site. It starts when the review process completes, and that is outside your control.
The AI visibility dimension
There is a newer cost that most security conversations have not caught up with.
AI systems weight corroboration — agreement between independent sources about what your business is and whether it is credible. A site flagged as malicious, or offline for a fortnight, degrades exactly those signals. Third-party sources do not re-verify on your timetable.
So a compromise now damages something that took months to build and rebuilds on a schedule you do not set. That is a materially different risk profile from a day of downtime.
How most compromises actually happen
Not through sophisticated attacks. Through the boring routes, in roughly this order of frequency.
- Unpatched plugins, themes and packages — the largest exposed surface on almost every site.
- Reused or never-rotated admin credentials, frequently belonging to someone who has left.
- Outdated platform versions left because updating risked breaking something.
- Misconfigured file permissions and exposed configuration files.
- Compromised third-party scripts loaded into every page.
A proportionate baseline
For a business whose site is an acquisition channel rather than a bank, this is the proportionate floor.
Proportionate security baseline
Each layer assumes the one outside it has already failed.
SSL and security headers
Correctly configured, with HSTS. The cheapest layer and often wrong.
Patch discipline
Dependencies and platform updated on a schedule, not when convenient.
Access control
Unique credentials, MFA on admin, accounts removed when people leave.
Backup with tested restore
A restore you have actually performed, with a known duration.
Monitoring and alerting
Integrity and uptime checks routed to a named person.
How to argue for the budget
Stop presenting it as risk avoidance and start presenting it as channel protection.
Take your monthly revenue influenced by organic and paid search. Multiply by the realistic recovery window — two to six weeks including review time. That figure is the exposure, and it is usually considerably larger than the security spend being debated.
This is not a scare tactic. It is the same arithmetic you would apply to any other single point of failure in the revenue system.
What we will not claim
No provider can guarantee you will not be compromised, and anyone offering that guarantee is describing something they cannot deliver.
What is achievable is reducing the exposed surface, detecting problems early, and recovering quickly from a restore that has been tested. Those are measurable and they are what a proportionate programme buys.