The first sign of trouble is rarely dramatic, and by the time malware recovery lands on your desk a customer has usually spotted it first: a screenshot arrives at 8pm showing a red warning screen where your homepage used to be. This is a practical guide for UK local business owners who wake up to exactly that. By the time you finish reading, you'll know what to change on Monday morning, and in what order.
What to do in the first 24 hours after a hack
Speed decides how much this costs you. Every hour an infected page stays live is another hour Google shows a warning to your customers, and another hour it counts against your rankings. So before you try to work out how it happened, contain it. Take the site into maintenance mode, tell your host you suspect a compromise, and stop taking any orders through it until it is clean. The forensics can wait; the bleeding cannot.
None of this is a reason to panic. Most UK SMB sites are hit by automated bots probing for a known weakness, not by someone targeting your business by name. That is oddly reassuring, because a generic attack usually has a generic fix. The wider security and backups pillar sets out how the pieces fit together once the fire is out.
The malware recovery steps, in order
There is a long way and a short way, and the short way clears roughly 80% of small-business infections. Work through it in sequence rather than jumping to the step that feels urgent.
- Put the site into maintenance mode so visitors and search engines stop landing on the infected pages.
- Change every password at once: hosting, CMS admin, database, FTP and email. Treat all of them as compromised, because you cannot yet prove they are not.
- Restore from a known-clean backup taken before the infection date, which is where a proper 3-2-1 backup routine earns its keep.
- Scan every file and the database for injected code, then close the entry point: an outdated plugin, a weak login or an unpatched core.
- Once you are certain the site is clean, request a review in Google Search Console to lift any "this site may be hacked" flag.
Where malware recovery usually goes wrong
Three mistakes turn a bad day into a bad month. The first is restoring a backup without finding the hole, so the same bot walks straight back in a week later. The second is cleaning the visible pages but missing injected code buried in the database or a theme file. The third is assuming one scan is enough; a scheduled vulnerability scan catches the reinfection that a single manual check misses. If you want to see the standard of sites we keep patched and monitored, our recent work shows what a well-kept UK business site looks like.
Prevention beats recovery every time
Recovery is the expensive way to learn a cheap lesson. A short, boring routine stops almost all of this: strong logins, current software, daily backups and someone actually watching the alerts. Run through our website security checklist and you will close most of the doors attackers rely on. If the breach exposed customer data, treat it as a reportable event and follow the UK GDPR compliance steps rather than hoping nobody noticed.
The evidence for staying current is not hard to find. Google Search Central Docs and the Google Business Profile docs both publish UK-applicable guidance confirming that hacked sites lose visibility fast and recover slowly. Skim the linked pages if you want the raw detail. Businesses that harden the site early rank faster, convert better, and spend less on paid ads patching over a leaky funnel.
Want us to handle the malware recovery for you
You do not have to do any of this alone. Read the website hosting and support guide for the full picture, where malware recovery sits alongside the other subtopics that protect a site together. Or hand it over: our hosting and support plans include the scanning, backups and monitoring that keep the next attack from ever reaching your customers.
Related cluster posts
From the same pillar, these dig into the adjacent subtopics:

