Why securing your non-critical websites is still essential

Every now and again, we get asked, "Why should I secure my website? It is not critical, and we are not hosting it on our network." The below article is meant to answer this question.
Attacks on a business website may cause a claim (subject to policy wording). Even if the website is purely for reputational purposes, it may still be used by attackers to gain access to actual funds of the business, cause 3rd party liability claims, and gain access to critical information and business data as a platform for a larger attack.
How a simple website change can lead to fraud
Here's an explanation of how just changing phone numbers and business addresses on a website can potentially lead to financial fraud: In a scenario where an attacker gains unauthorized access to a legitimate business website — either through exploiting vulnerabilities, using open ports, or stealing credentials — once inside, the attacker changes the phone number and business address on the website to their own contact information.
- Redirecting Sensitive Communications: By changing the phone number listed on the website to their own, the attacker can intercept incoming calls from customers, suppliers, or partners trying to contact the legitimate business. The attacker may pose as a representative of the business, potentially deceiving callers into providing sensitive information, such as payment details or login credentials.
- Fraudulent Transactions: With control over the website's contact information, the attacker can manipulate incoming inquiries or sales leads to redirect them to their own channels — intercepting email, soliciting payments for non-existent products or services, or redirecting legitimate transactions to their own accounts.
- Impersonation and Social Engineering: By changing the business address on the website, the attacker can create a false sense of legitimacy and authority to convince individuals to disclose sensitive information or make payments.
- Reputation Damage and Loss of Trust: Unauthorized changes to a business website's contact information can damage the organization's reputation and erode trust among customers, suppliers, and partners.
Even isolated websites are entry points
Even if a website is hosted on a separate server and seemingly isolated from core business systems, attackers can use it as a pivot point. A compromised website can host malware that infects visitors (including your own employees), serve as a phishing platform, or be used to harvest credentials via fake login pages. The website's domain itself — even without hosting sensitive data — can be weaponized for business email compromise (BEC) through email spoofing if DMARC, DKIM, and SPF records are not properly configured.
What insurers need to know
From an underwriting perspective, Cyberwrite's external scanning infrastructure captures website security posture as part of every risk assessment — including configuration hygiene, certificate validity, exposed services, and email security settings. A seemingly non-critical website with poor security hygiene will lower a company's Cyberwrite risk score, because attackers don't distinguish between critical and non-critical entry points. Organizations should implement robust security measures to protect all web properties from unauthorized access, regularly monitor for suspicious changes, and educate employees about safeguarding website credentials.