Protect your business – 7 Steps to Improve Your Website Security

Jan 10, 2018 | Security, Website Basics

If you read the news in January 2018 you might have noted the articles about Intel, and the fact that more than 90% of computers worldwide – and many other devices – were exposed to security flaws which left them vulnerable to attacks by hackers. Initially I raised my eyebrows at the scare-mongering headlines, as the media does like to make technology seem terrifying to those already suspicious of it. 

But then I remembered that actually it’s important the headlines are scary. If you look at the cost of the ransomware attack on the NHS earlier in 2017, you can see that the cost of ignoring security advice can be too high. The warnings were there, but the failure lay with the humans who didn’t follow instruction to protect their system.

When it comes to protecting your data you need to take notice, be suspicious, and TAKE ACTION.  

DON’T IGNORE UPDATES!

Every day there are hundreds of bugs and exploits doing the rounds on the internet that never make the headlines, and it’s in your interests to protect yourself. Digital security is vital if you’re running a business online – any vulnerability might take down a fundamental part of your business.

It’s not just about sales revenue you lose from the time your site is down, as website security guru Alison Monday from tiny blue orange explains here, there are many other costs you need to consider. Just like when you prang your car, you don’t just lose the ability to drive for a while as it’s in for repair, you have to pay for fixing, insurance premiums, and maybe even have to buy a new car. So let’s protect your digital vehicle shall we?

Why would they bother with little old me?

You might wonder “why would a hacker bother with my website?”, and you’re right, generally they’re not trying to destroy your website and ruin your life (unless you’ve made some enemies, I’m not judging…). It’s not you specifically, it’s just all data.  Firstly the “hacker” is rarely one guy in a hoody sitting in the dark as much as Hollywood would like you to believe it, it’s usually bots: programs crawling the internet looking for exploits. If a site is hijacked, they can send spam emails from your server, insert malware into your site, create SEO spam, mine for personal data and yes, deface your site. A little of what this can mean for you:

  • damaging your reputation
  • damaging site performance
  • email blacklisting
  • search engine blacklisting
  • data breach

…And more, it’s not pretty.

There are some key steps you should take to protect your online business. However do note these measures don’t guarantee protection, because a 100% secure website doesn’t exist (unless it’s offline and unavailable to the outside world). But following these basic best practices should protect you against the majority of attacks.

1. INSURE YOURSELF

Protect the engine of your business with these steps, but make sure you insure the whole car: take backups of your website and database regularly, and always before updating. Also take backups of your local machine so you are covered if you lose your hard drive.

2. UPDATE YOUR SOFTWARE

As I said at the start, make sure you update your computers and devices, those notifications aren’t there for fun.

3. UPDATE YOUR WEBSITE PLATFORM

Whether you’re using WordPress or another platform for your website CMS, keep your core files and plugins updated. Just like fixing a broken window, developers are always fixing insecure holes in software. If you don’t update and fix that window, hackers can get in. And don’t forget that as updates become common knowledge, hackers will know exactly what to look for in sites running older versions to exploit that vulnerability.

Also, let’s not forget that often updates contain exciting new functionality which might make your life easier, so UPDATE!

DON’T FORGET – make sure you remove any plugins or extensions you are not using. Even if they are not activated, they are files on your server, and as you’re not updating them, they will remain vulnerable. There’s no need to keep inactive plugins on your website.

4. USE SECURE PASSWORDS

Are you still using your kids birthday as your hotmail password? No matter what website you’re signing in to, always make sure that your password uses the following guidelines:

  • At least one capital letter,
  • At least one number
  • Preferably a special symbol such as # or %
  • Should be at least 8 characters long.
  • Don’t use whole words or personal details such as a date of birth or anniversary.
  • Don’t reuse passwords across different websites.
  • Change them often.

Hackers run checks on thousands of passwords at a time, so complexity is vital. 

Bad password: harrypotter87

Good password: H*678sTT3^^mn

Yes it’s hard to remember, but get used to it, or even better use a password tool like Dashlane, Keeper or Lastpass. I do, and I use 2 step authentication wherever possible (and not with SMS).

5. CHANGE YOUR USERNAME

Anything but admin! Changing your website username from the default ‘admin’ to almost anything else will automatically avoid a significant number of hack attempts. It doesn’t need to be as difficult as your password, it just needs to not be admin!

6. DON’T SHARE YOUR DETAILS

Never share account information or passwords, especially on email, text, or messenger services. They aren’t secure, and the data you send through them may be stolen and used against you. Just like your bank pin, don’t write down passwords on paper or keep them in a document on your computer. Yes they are less likely to be stolen, but they are now available to anyone who sees the paper or to a hacker who accesses your personal computer through malware or viruses.

7. BACK UP

It’s worth saying again: Whether you pay your host to do it, or manage backups yourself, it’s the most important step to getting yourself back up and running should the worst happen.

Back. It. UP!

TL;DR

Digital security is vital to your business: get into a regular routine of checking, updating, securing and backing up your machine and your website. Keeping your site secure isn’t the only reason to maintain your website – out of date software and plugins can SLOW YOUR SITE DOWN – and you know how Google hates a slow website, not to mention providing a negative experience for your users.

Problems usually occur from human error i.e. not following sensible protocol, rather than in the technology itself. Don’t be that human.

QUICK STEPS:

  1. Backup Backup Backup
  2. Run software updates on devices when available
  3. Update your website platform and plugins (Remove any unused plugins)
  4. Use secure passwords (and change them often)
  5. Don’t use admin for your username
  6. Don’t share information
  7. BACK. IT. UP.

Need help?

I provide my clients with hosting, maintenance and security for their websites, so they can get on with their jobs, safe in the knowledge their website is being kept up to date in line with best practices, and backed up should the worst happen. I also include content updates if you worry about having to log in and deal with your WP dashboard.

If you’d like to find out more about my maintenance contracts, drop me a line…

 

Pin me and share the love…

7 Steps to Improve Your Website Security

Related Posts

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Pin It on Pinterest