Nobody Targeted You. That Is the Point.
The first thing owners say after a hack is “why would anyone attack us, we are a small business”. Almost nobody did, in the sense they mean.
The overwhelming majority of WordPress compromises are automated. Software crawls the web looking for sites running a plugin version with a publicly known vulnerability, finds one, and exploits it without a human ever deciding you were interesting. Your size is irrelevant. Being reachable and out of date is the entire qualification.
This is why the defence is unglamorous and why it works: keeping things updated stops far more attacks than any product you can buy. A firewall plugin helps. An outdated plugin with a known hole undoes it.
Prevention and Cleanup Are Not the Same Job
Prevention is hardening, sensible logins, current software, and backups you have actually tested restoring. It is cheap, boring, and best done before anything happens.
Cleanup is what happens after: finding the malware, removing it, and — the part people skip — working out how it got in. A cleanup that removes the symptom without closing the entry point buys you a few weeks. If the site was reinfected shortly after somebody “fixed” it, that is what happened. Our guide on fixing a hacked WordPress website sets out what a real cleanup involves.
When You Already Have This
Monthly security monitoring is included in our maintenance plans, so if you are already on one you do not need to buy it separately — website support and maintenance covers updates, backups and monitoring together, and that combination is worth more than any single security purchase.
If you are not on a plan and want to know where you stand before spending anything, the practical steps are written up in WordPress security for a small business, and most of them cost nothing but an afternoon.