Last post, we talked about why that flood of notifications isn’t a viral moment — it’s a bot, and it’s either trying to crash your site or find a way in. So now the real question: what do you actually do about it?
Good news — you don’t need a computer sience degree. You need a few smart habits and to know when to call in backup.
1. Turn on comment moderation.
If your website platform lets comments post live without approval, turn that off. Most platforms (WordPress, Squarespace, etc.) let you require comments to be manually approved before they show up. This won’t stop the bots from hitting your site, but it stops them from actually publishing anything on it.

2. Add a CAPTCHA or spam filter.
Tools like Akismet, Google reCAPTCHA, or built-in spam filters are designed specifically to catch bot traffic before it hits your comment section or contact forms. This is one of the simplest, lowest-effort fixes with the biggest payoff.
3. Keep your website software updated.
If you’re on WordPress or a similar platform, outdated plugins and themes are one of the most common ways bots actually get in — not just spam, but real access. Set a recurring reminder to check for updates, or better yet, automate them where you can.

4. Watch for patterns, not just one-off pings.
One weird comment? Probably nothing. A sudden burst of comments, form submissions, or login attempts in a short window? That’s worth a closer look. You don’t have to become a security analyst — you just have to notice when something feels off and take five minutes to check your site’s activity or comment log.
5. Have a backup.
If the worst happens and someone does get in, a recent backup is the difference between a bad afternoon and a business crisis. Most hosting platforms offer automatic backups — make sure yours is actually turned on, not just available.
6. Use Two-Factor Authentication
Using Two-Factor Authentication on your Admin Accounts helps keep your admin accounts safe from the hackers trying to add malicious code easily. This is good advice in general but we want to ensure that we are using good password policies on our website.
7. Know when to call in a professional.
Here’s the founder trap: you can DIY the basics, but you can’t always see what you can’t see. If you’ve never had someone actually look at your website’s security — not just “is it password protected” but “what could someone actually exploit” — that’s worth getting eyes on before it becomes a problem instead of after.
We also want to ensure if we have had unusual website activity that they haven’t put any “backdoor” code into our website. Many times malicious actors will put code in and leave it dormant for a period of time which reduces your suspicions before deploying it. This is why it is good to have the professionals take a look periodically.
How can we help?
This is exactly the kind of thing we dig into with small business owners at PDRM. You built your business to serve your customers, not to become a part-time IT security analyst. But a few smart habits, plus knowing when to bring in help, means that ping in your inbox can go back to being something you’re excited about — not something you’re dreading.
If a website audit, has been on your radar we can do it as part of our Critical Services Security Assessment or standalone. For more information, please take a look here.






