Cyber security

Do security headers matter for a small business website?

They matter, but less than the red crosses on a scanner make it look. They protect the people visiting your site, they cost nothing, and most take a few minutes to add. They will not fix a hacked website or a weak admin password.

Security headers are short instructions your website sends with every page, telling the visitor’s browser what that page is and is not allowed to do. Visitors never see them. Scanners do, and a scanner that finds them missing paints your site red, which is how most business owners first hear the term.

They are worth doing. They are also not the most important thing about your website’s security, and it helps to know the difference.

What do they actually protect against?

Mostly against tricks played on your visitors rather than attacks on your server. Each header closes off one:

  • Strict-Transport-Security tells browsers to only ever use the encrypted version of your site, so somebody on hostile wifi cannot serve them an unencrypted copy instead.
  • Content-Security-Policy lists where scripts, styles and images are allowed to come from. If somebody manages to inject a script into your page, this is what stops it running. It is the most powerful and the hardest to get right.
  • X-Frame-Options stops another site loading yours invisibly inside a frame and tricking people into clicking buttons they cannot see.
  • X-Content-Type-Options stops browsers second guessing a file’s type and running something that was uploaded as a picture.
  • Referrer-Policy limits how much of your page address is passed on when somebody clicks a link to another site.
  • Permissions-Policy switches off browser features your site never uses, such as the camera and microphone.

How do you check yours?

Put your address into our security headers checker. It tells you which of the six are in place, explains each one in plain English, and gives you the one line fix for anything missing. securityheaders.com does the same job and gives you a letter grade, if you want a second opinion.

How hard are they to fix?

That depends almost entirely on where your website is hosted, not on how good your developer is.

  • If your site sits behind Cloudflare, it has a ready made “Add security headers” setting that switches on X-Content-Type-Options, X-Frame-Options and Referrer-Policy. The rest can be added with a rule.
  • On WordPress, your host may let you add them, or a security plugin can. Ask your host first, because another plugin is another thing to keep updated.
  • On your own server, they are a few lines in the Apache, Nginx or IIS configuration.
  • On a hosted website builder, you may not be able to set them at all. That is a limitation of the platform, and it is worth knowing before you spend time looking for the setting.

Five of the six are usually safe to add in one go. Content-Security-Policy needs testing, because a policy that is too strict stops parts of your site working. Send it in report only mode first, see what it would have blocked, and tighten it once the reports are clean.

What happened when we checked our own site?

We left one of the six off our own website on purpose. When the site launched in September 2026 it already scored an A, and Strict-Transport-Security was the only gap, so we decided it could wait.

Then we built our own headers checker, pointed it at our own site, and it marked us Missing in red, which is exactly what any visitor trying the tool would have seen. So we turned it on, and the site went from an A to an A+.

There is a point in that beyond the grade. Headers are one of the few parts of your security that anybody can see from the outside without asking, so they say something about whether anybody has looked.

What will security headers not protect you from?

A perfect score says nothing about the server behind the site, the admin passwords, the plugins that have not been updated, or the backups. A WordPress site with every header in place can still be taken over through an old plugin or a reused password. Old plugins and reused passwords are far more common ways in than a missing header.

So fix the headers, because it is cheap and it protects the people visiting you. Then spend the bigger share of your attention on who can log into the site, how it is updated and whether you could restore it. The 15 minute security check covers the parts of your business that matter more than any header, and if you want somebody to look at the website properly, get in touch.

Questions

The questions people ask us about this

Will adding security headers break my website?

Most of them will not. Content-Security-Policy is the exception: set it too tightly and scripts, fonts or embedded videos stop loading. Send it in report only mode first, which logs what it would have blocked without blocking anything, and tighten it from there.

Do security headers help with Google rankings?

Not directly. Google has used HTTPS as a ranking signal since 2014, and Strict-Transport-Security helps make sure visitors always get the HTTPS version, but the headers themselves are not a ranking factor. Do them for your visitors, not for your position.

Does Cyber Essentials ask about them?

Not specifically. Cyber Essentials is about the devices, accounts and network inside your business. Security headers are about the website your customers visit, which is usually hosted somewhere else entirely.

Read next

Cyber security

What is Friday afternoon fraud, and how do you stop it?

It is payment diversion fraud, timed for late on a Friday when a property completion is due and everyone wants to be out the door. The attacker has usually been reading the email thread for weeks. The control that stops it is a verbal check against a phone number you already held, never one taken from the email.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.