{"id":8742,"date":"2021-04-29T13:09:52","date_gmt":"2021-04-29T11:09:52","guid":{"rendered":"https:\/\/ditech.media\/?p=8742"},"modified":"2021-04-29T15:24:12","modified_gmt":"2021-04-29T13:24:12","slug":"from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals","status":"publish","type":"post","link":"https:\/\/ditech.media\/news\/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals\/","title":{"rendered":"From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Sophisticated security software is no longer reserved for <\/span><i><span style=\"font-weight: 400;\">just<\/span><\/i><span style=\"font-weight: 400;\"> large enterprises. Today\u2019s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Business leaders often understand the impact the right security measures have on consumer trust and brand health but are often uncertain about where to begin. Here are three fundamental web security tips all businesses should put in place to safeguard their websites this year.<\/span><\/p>\n<p><b>Nailing the basics<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The most common web security question this year is: \u2018What\u2019s my likelihood of getting breached?\u2019 Websites are hacked typically when they\u2019re running vulnerable plugins that aren\u2019t patched.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Despite the all-too-common myth of<\/span><a href=\"https:\/\/make.wordpress.org\/core\/\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">WordPress Core<\/span><\/a><span style=\"font-weight: 400;\"> as a point of vulnerability, it\u2019s the third-party plugin vulnerabilities that represent<\/span><a href=\"https:\/\/www.wordfence.com\/blog\/2016\/03\/attackers-gain-access-wordpress-sites\/\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">55.9%<\/span><\/a><span style=\"font-weight: 400;\"> of the known entry points for attacks. However, this only represents half of the equation \u2013 the other half is proper management of WordPress accounts, especially through using a Multi-Factor Authentication (MFA) plugin.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The solution is simple: avoid running any more plugins than you need to and ensure the ones you do use have a good history of updates after published vulnerabilities. To tackle the burden of keeping plugins up to date and the risk of mission-critical sites breaking, machine learning and visual testing tools can now even automate plugin updates on a nightly or weekly basis without causing unintended consequences that could result in downtime or lost traffic. Make sure to limit admin access to \u201cmust-have\u201d users and make sure they are using MFA.<\/span><\/p>\n<p><b>Bringing the right skills onboard<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The shortage of cybersecurity skills is a global issue and Australia is no exception.<\/span><a href=\"https:\/\/www.austcyber.com\/educate\" target=\"_blank\" rel=\"noopener\"> <i><span style=\"font-weight: 400;\">AustCyber<\/span><\/i><\/a><span style=\"font-weight: 400;\"> predicts by 2026, the nation will face a skills shortage of 18,000 security experts, which means organizations will not only struggle to hire internal security leaders but also to source external help.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To ensure organizations have the right team in place, leaders should start mapping out the risk profile unique to their business. Identify employees who are experts in WordPress and eCommerce and consider how your industry poses particular challenges, such as websites in the healthcare sector, which have undoubtedly experienced different kinds of traffic surges this past year. For those weighing between hiring and training more in-house staff or bringing on a vendor, revisit the basics of vendor management and how you\u2019re drawing the lines of responsibility, depending on who fits where in your security puzzle. If you\u2019re working with a partner, they will be required to make those investments into skills and technology on your behalf.<\/span><\/p>\n<p><b>Prepping for peaks<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Seasonal shopping periods like Valentine\u2019s Day, Christmas, Black Friday, and end of season sales pose a tricky challenge for retailers and eCommerce platforms. Website managers often scramble to meet a high volume of revenue-driving activity on their site while at the same time facing increasing numbers of cyberattacks such as distributed-denial-of-service (DDOS) attacks, which<\/span><a href=\"https:\/\/blog.cloudflare.com\/network-layer-ddos-attack-trends-for-q3-2020\/\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">doubled every quarter<\/span><\/a><span style=\"font-weight: 400;\"> in 2020. During these lucrative periods for cybercriminals, the<\/span><a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/guidance\/stay-safe-when-shopping-online-holiday-time\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">Australian Cyber Security Centre<\/span><\/a><span style=\"font-weight: 400;\"> regularly updates its guidance for online shoppers<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Load testing, which is performance testing that simulates real-world loads on software, applications, or websites, can help answer the question of \u2018how many people can visit my site at once?\u2019. Proper load testing can help site managers assess things like scaling capabilities, lifecycle hooks, and <\/span><span style=\"font-weight: 400;\">susceptibility to DDOS attacks due to high load<\/span><span style=\"font-weight: 400;\">, automatic code deployment, health checks, and target tracking. Without proper planning and action, <\/span><span style=\"font-weight: 400;\">retailers are at an increased risk of successful DDOS attacks that lead to a significant revenue loss.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This year, it\u2019s critical that the desire to cash in on the shopping season doesn\u2019t come at the cost of security. Companies need to have basic web security measures in place so that while WordPress Core may be secure, they\u2019re giving the right attention to the plugins they use and are securely managing their WordPress users. They also need to strike the right balance between people, process, es and technology to ensure they have the right skills and staff in place. Finally, they need to plan ahead for key consumer moments and seasonal periods, looking not just for visitor traffic spikes but for different kinds of cyberattacks. The road to recovery in 2021 won\u2019t be easy, but with these steps it\u2019ll be a much smoother ride.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophisticated security software is no longer reserved for just large enterprises. Today\u2019s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims. Business leaders often understand the impact the right security measures have on consumer trust and brand health but are &hellip;<\/p>\n","protected":false},"author":13644,"featured_media":8744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,157,162],"tags":[259,235],"_links":{"self":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/8742"}],"collection":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/users\/13644"}],"replies":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/comments?post=8742"}],"version-history":[{"count":3,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/8742\/revisions"}],"predecessor-version":[{"id":8747,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/8742\/revisions\/8747"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media\/8744"}],"wp:attachment":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media?parent=8742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/categories?post=8742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/tags?post=8742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}