Skip to content
Back to the blog

Security

Online store security: a checklist for business owners

· 8 min read · LEXATEK

An online store handles the most sensitive part of your business: money and your customers’ data. A security problem doesn’t just cost sales; it costs trust, and that’s much harder to win back. You don’t need to be an expert to protect your store, but you do need to know what to ask. This checklist covers the minimum every store should meet.

1. Payments: your store should never touch card data

  • Take payments through a well-known payment gateway (for example Stripe, PayPal, Square or Mercado Pago). They comply with the card industry’s security standard (PCI DSS) and process the data for you.
  • Your store must not store card numbers or security codes. Ever. Not in the database, not in emails.
  • Turn on your gateway’s anti-fraud tools and bank authentication (3-D Secure) when available.
  • Look closely at unusual orders: very large amounts, several cards in a short time or addresses that don’t match.

2. A secure connection across the whole site

  • HTTPS on every page, not just at checkout. The padlock in the browser is the first thing a wary customer looks for.
  • The certificate should renew automatically. An expired certificate shows a warning that scares anyone away.
  • Always redirect the insecure version (http) to the secure one (https).

3. Access: passwords and permissions

  • Two-step verification on the store dashboard, hosting, domain, email and payment gateway.
  • One account per person, with only the permissions they need. No sharing the “admin” user.
  • When someone stops working with you, remove their access the same day.
  • Use a password manager: long passwords, different for every service.

Beware of fake emails. Many attacks start with an email that looks like it’s from your bank, your payment gateway or your hosting provider asking you to “verify your account”. Always type the address yourself; never use the link in the email.

4. Updates

Most automated attacks exploit known flaws in outdated software. If your store runs on a platform with plugins or extensions:

  • Update the platform, the theme and every extension as soon as security patches are released.
  • Delete (don’t just deactivate) plugins you don’t use.
  • Test updates on a copy before applying them to the live store, so you don’t break checkout.

5. Backups that actually work

  • Automatic daily backups of the database (orders, customers, products) and the files.
  • Keep at least one copy off the store’s server.
  • Test a restore every now and then. A backup that has never been tested is just a hope.

6. Protection against bots and abuse

  • Protect login, sign-up and forms with an anti-bot system (such as Cloudflare Turnstile or reCAPTCHA) and attempt limits.
  • A web application firewall (WAF) blocks many common attacks before they reach your store.
  • Watch for unusual spikes in traffic or new accounts: they’re often bots testing stolen cards.

7. Personal data and legal notices

If you collect personal data (name, email, address, phone), privacy laws apply, and which ones depends on where you and your customers are: for example, Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (new version published on March 20, 2025), the European Union’s GDPR or US state laws such as California’s CCPA.

  • Have a visible, up-to-date privacy notice and a cookie policy that tells the truth about the cookies you use.
  • Ask only for the data you really need to ship and invoice.
  • If you use analytics or advertising tools, turn them on only after the visitor accepts cookies.
  • Make your terms and conditions clear: shipping, returns, warranties and payment methods.

8. Have a plan for when something goes wrong

  • Know who to call: who manages the hosting, the domain and the store.
  • Keep the recovery details for your main accounts at hand.
  • If there’s a data breach, act fast: shut off access, change passwords, check what was exposed and notify those affected.

Quick checklist

  1. Payments through a well-known gateway; zero card data stored.
  2. HTTPS across the whole site, with automatic renewal.
  3. Two-step verification and one account per person.
  4. Platform and extensions up to date; nothing installed that isn’t used.
  5. Daily backups, off the server and tested.
  6. Anti-bot checks and attempt limits on forms and logins.
  7. Privacy notice, cookie policy and terms up to date.
  8. A clear plan in case something goes wrong.

In short

Store security doesn’t depend on a single tool, but on many simple practices applied consistently. If you don’t have time to keep an eye on updates, backups and access, it makes sense for someone to do it for you. At LEXATEK we build online stores with secure payments and offer maintenance and managed hosting plans so your store stays protected every day.

← See all articles