{"id":795,"date":"2020-03-31T19:52:29","date_gmt":"2020-03-31T19:52:29","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=795"},"modified":"2025-04-28T12:05:20","modified_gmt":"2025-04-28T12:05:20","slug":"how-to-secure-a-website-website-security-tips-for-businesses","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/","title":{"rendered":"How to Secure a Website: 21 Website Security Tips for Businesses"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"17-website-it-and-cybersecurity-professionals-weigh-in-on-how-to-make-a-website-secure-and-things-you-should-avoid-doing-with-their-expert-tips\">17 website, IT and cybersecurity professionals weigh in on how to make a website secure (and things you should avoid doing) with their expert tips<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re not sure \u201chow to secure a website\u201d most effectively, then you\u2019re not alone. As of the time of writing this article, there were literally <em>more than 2.6 billion<\/em> search results for that particular topic on Google alone!  This is where our list of website security tips come in handy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, we have our own thoughts and opinions about the\nbest ways to approach website security:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Using secure passwords <\/li><li>Patching and updating your software, firmware,\nand server <\/li><li>Using SSL\/TLS certificates<\/li><li>Maintaining current website backups<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But we all know there\u2019s more to strong website security than\njust that, which is why I called in the cavalry to help answer your question. I\u2019ve\ngathered 21 website security tips from 17 website pros, IT admins, and\ncybersecurity experts from around the U.S. and abroad. You\u2019re welcome.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, I know that you\u2019re chomping at the bit to get to those expert website security tips. But if you want to know more about who each expert, be sure to check out our list of experts by clicking on the &#8220;Meet the Website Security Tips Experts&#8221; link (#4) in the table of contents below.<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">Website Security Tips Table of Contents<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewbox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#17-website-it-and-cybersecurity-professionals-weigh-in-on-how-to-make-a-website-secure-and-things-you-should-avoid-doing-with-their-expert-tips\">17 website, IT and cybersecurity professionals weigh in on how to make a website secure (and things you should avoid doing) with their expert tips<\/a><ol><\/ol><\/li><li><a href=\"#14-website-security-tips-on-how-to-make-your-website-secure\">14 Website Security Tips on How to Make Your Website Secure<\/a><ol><li><a href=\"#1-implement-strong-password-requirements-and-follow-password-management-best-practices\">1. Implement Strong Password Requirements and Follow Password Management\nBest Practices<\/a><ol><\/ol><\/li><li><a href=\"#2-implement-strong-authentication-methods-and-limit-access\">2. Implement Strong Authentication Methods and Limit Access <\/a><ol><\/ol><\/li><li><a href=\"#3-don\u2019t-allow-unvalidated-file-uploads-to-your-website\">3. Don\u2019t Allow Unvalidated File Uploads to Your Website<\/a><ol><\/ol><\/li><li><a href=\"#4-use-encryption-and-secure-protocols-to-serve-your-website-via-https\">4. Use Encryption and Secure Protocols to Serve Your Website via HTTPS<\/a><ol><\/ol><\/li><li><a href=\"#5-use-dns-filtering-to-restrict-access-to-specific-sites\">5. Use DNS Filtering to Restrict Access to Specific Sites<\/a><ol><\/ol><\/li><li><a href=\"#6-have-visibility-within-your-servers-databases-networks-and-general-infrastructure\">6. Have Visibility Within Your Servers, Databases, Networks, and General\nInfrastructure<\/a><ol><\/ol><\/li><li><a href=\"#7-keep-software-firmware-up-to-date-and-patched\">7. Keep Software, Firmware Up to Date and Patched<\/a><ol><\/ol><\/li><li><a href=\"#8-check-your-configurations-to-ensure-they\u2019re-set-properly\">8. Check Your Configurations to Ensure They\u2019re Set Properly<\/a><ol><\/ol><\/li><li><a href=\"#9-use-reverse-proxies-for-large-websites\">9. Use Reverse Proxies for Large Websites<\/a><ol><\/ol><\/li><li><a href=\"#10-reconsider-hosting-multiple-websites-on-one-server\">10. Reconsider Hosting Multiple Websites on One Server<\/a><ol><\/ol><\/li><li><a href=\"#11-keep-multiple-current-website-files-and-database-backups\">11. Keep Multiple, Current Website Files and Database Backups <\/a><ol><\/ol><\/li><li><a href=\"#12-keep-your-database-separate-from-your-file-server\">12. Keep Your Database Separate from Your File Server<\/a><ol><\/ol><\/li><li><a href=\"#13-use-the-right-website-security-tools-and-features\">13. Use the Right Website Security Tools and Features<\/a><ol><li><a href=\"#sqlmap\">SQLMap<\/a><ol><\/ol><\/li><li><a href=\"#threatrunner\">ThreatRunner<\/a><ol><\/ol><\/li><li><a href=\"#zed-attack-proxy-zap\">Zed Attack Proxy (ZAP)<\/a><ol><\/ol><\/li><li><a href=\"#multiple-solution-recommendations\">Multiple Solution Recommendations<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#14-review-your-web-server-security-policies-regularly\">14. Review Your Web Server Security Policies Regularly<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#website-security-tips-7-website-security-mistakes-to-avoid\">Website Security Tips: 7 Website Security Mistakes to Avoid <\/a><ol><li><a href=\"#believing-cyber-security-is-\u201call-or-nothing\u201d\">Believing Cyber Security Is \u201cAll or Nothing\u201d<\/a><ol><\/ol><\/li><li><a href=\"#being-negligent-and-ignoring-the-obvious\">Being Negligent and Ignoring the Obvious<\/a><ol><\/ol><\/li><li><a href=\"#having-poor-password-selection-management-and-policies\">Having Poor Password Selection, Management, and Policies<\/a><ol><\/ol><\/li><li><a href=\"#using-default-credentials-site-addresses-and-database-prefixes\">Using Default Credentials, Site Addresses, and Database Prefixes<\/a><ol><\/ol><\/li><li><a href=\"#including-session-ids-in-urls\">Including Session IDs in URLS<\/a><ol><\/ol><\/li><li><a href=\"#lacking-regular-website-testing\">Lacking Regular Website Testing<\/a><ol><\/ol><\/li><li><a href=\"#trusting-their-security-to-one-product-or-solution\">Trusting Their Security to One Product or Solution<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#meet-the-website-security-tips-experts-listed-in-alphabetical-order-by-surname\">Meet the Website Security Tips Experts (Listed in Alphabetical Order by\nSurname)<\/a><ol><\/ol><\/li><li><a href=\"#final-thoughts-on-these-website-security-tips-and-how-to-secure-your-website\">Final Thoughts on These Website Security Tips and How to Secure Your Website<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"14-website-security-tips-on-how-to-make-your-website-secure\">14 Website Security Tips on How to Make Your Website Secure<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"606\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2019\/03\/secure-wordpress-website-1024x606.jpg\" alt=\"Secure WordPress website using website security tips\" class=\"wp-image-103\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2019\/03\/secure-wordpress-website-1024x606.jpg 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2019\/03\/secure-wordpress-website-300x178.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2019\/03\/secure-wordpress-website-560x332.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2019\/03\/secure-wordpress-website.jpg 1456w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"1-implement-strong-password-requirements-and-follow-password-management-best-practices\">1. Implement Strong Password Requirements and Follow Password Management\nBest Practices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Account security is often only as good as the passwords and\nmanagement strategies that are used to manage them. If you\u2019re using insecure\npasswords, or if you aren\u2019t regularly updating them or managing them, then\nyou\u2019re quickly going to find yourself on a trip up a stinky brown creek. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To start off our list of website security tips, the experts also had a lot to say on the topic:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One of the most common website security threats is the usage of weak passwords. When passwords are not set using the correct procedures, they can be easily hacked by external actors which will allow them to infiltrate your website. The risk of weak passwords can easily be fixed by educating employees about the importance of strong passwords. By implementing a password manager tool or multi-factor authentication it can offer an additional layer of security against possible website attacks.&#8221;<\/em><\/p><cite> <strong>\u2014<\/strong> <strong>Sivan Tehila, director of solution architecture of&nbsp;Perimeter 81<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">But what exactly constitutes \u201cweak\u201d passwords? <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>You need to setup a secure password that isn\u2019t associated with your or your lifestyle, hobbies, etc. You can use an on-line password generator. Be careful as there was a site that generated the same password for all users. This was a trap by hackers, who would then try this password for numerous accounts.<br> <br>You can use a combination of dates, names and locations; merging them will make them a lot more secure than single terms. Use upper and lower case, alphanumeric characters, numbers and non-real life words.<br> &nbsp; &nbsp; &nbsp; &nbsp; <br> Ideally you should change your passwords. monthly, but if not, quarterly is reasonably safe, and don\u2019t use the same passwords for multiple sites as you can be a victim of multiple hacks. Your email or user name can be tracked among multiple sites. If hackers gain access to one of your accounts then they will try the same password across all other sites. This is normal protocol for them.\u201d<\/em> <\/p><cite>  <strong>\u2014<\/strong> <strong> Dustin Vann, owner &amp; website manager at Trusy Social<\/strong> <strong>(Trusy.co)<\/strong><\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, there are other considerations as well when it\ncomes to website password security. In addition to the complexity of the\npasswords and how frequently you change them, another consideration is how to\nmanage those passwords and keep them secure.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One big tip we have is ensuring you have multi-factor enabled, especially if you are using a CMS system like WordPress. It is so easy for someone to break your password through a phishing attack or WordPress vulnerability. They can use your credentials to mangle your website, install malware, and destroy your brand.\u201d<\/em> <\/p><cite> <strong>\u2014 Nick Santora, co-founder and CEO at Curricula<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>When possible, it&#8217;s best to protect passwords with 2FA, or 2-Factor authentication. A Yubikey is ideal, but authenticator apps are useful as well. Doing so will provide an additional layer of protection in the off chance your password is compromised or your phone is SIM-swapped. <\/em><\/p><p><em>People are storing more and more value online and virtual items and assets like cryptocurrencies are becoming more mainstream, which has led to a huge surge in 2FA support across a variety of platforms, be it Twitter, Facebook, Coinbase, Amazon, iCloud and more. Every day there\u2019s less of an excuse to not have Google Authenticator downloaded on your iOS or Android.\u201d<\/em> <\/p><cite> <strong>\u2014 Corey Petty, senior security engineer at Status<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"2-implement-strong-authentication-methods-and-limit-access\">2. Implement Strong Authentication Methods and Limit Access <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to web <a href=\"https:\/\/sectigostore.com\/blog\/the-difference-between-authentication-and-authorization-explained-in-detail-by-a-security-expert\/\">authentication<\/a>, you definitely have a lot of options. You\u2019ve got the traditional <a href=\"https:\/\/sectigostore.com\/blog\/what-is-multi-factor-authentication-and-how-does-it-differ-from-2fa-sfa\/\">two-factor and multi factor authentication<\/a> mechanisms. But there also are hardware tokens and other types of measures available as well as using digital signatures. Make sure that you choose whatever authentication method works best for your organization and hardens your defenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, regardless of what Pam in accounting says, <em>not\neveryone needs access to everything<\/em>. This is why limiting access to what\nusers actually need is crucial to website security. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Enable secure access to your admin area via IP whitelisting or Two-Factor Authentication. Practice regular account auditing for admin accounts as well as API users and remove any that are unnecessary or adjust access to only necessary areas.\u201d<\/em> <\/p><cite> <strong>\u2014 Brian Taylor, co-founder of Forix<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Websites owner make a mistake in giving credentials to partners, Instead, if partners need to pull user data from your site, provide them with an OAuth based API. This is also known as <\/em><em>the Password Anti-Pattern<\/em><em>.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>User and admin list should be reviewed and cleaned up if such people are no longer part of that project\/entity\/company\/etc.\u201d <\/em><\/p><cite> <strong>\u2014 Ross Thomas, IT administrator at SectigoStore.com<\/strong> <\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Login functionality and session management are also\nimportant considerations in website security: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Check the session management, after login does not perform any user action for 15 mins, Let say your session timeout is 15 min, After 15 mins if you perform any user action, It should automatically be logged out from the website.\u201d<\/em><\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Avoid staying logged in to inactive sessions. Not only could data be being collected on you in the background, but it increases the chance of someone maliciously accessing your account. Additionally, if you\u2019re using a centralized identity service like Google, Twitter, or Facebook as your login, if someone hacks one of those accounts, they\u2019ll immediately gain access to your connected accounts too. Don\u2019t reuse passwords, especially on valuable services like email, online banking, identity services. Use a password manager to help you.&#8221;<\/em> <\/p><cite> <strong>\u2014 Corey Petty, a&nbsp;Senior Security Engineer at Status<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"3-don\u2019t-allow-unvalidated-file-uploads-to-your-website\">3. Don\u2019t Allow Unvalidated File Uploads to Your Website<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Even though the Open Web Application Security Project (OWASP) itself warns against allowing \u201cjust anyone\u201d to upload files and other content to websites, it never fails to amaze me how many websites simply ignore those guidelines and do it anyway. The <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/File_Upload_Cheat_Sheet.html\" target=\"_blank\">OWASP File Upload Cheat Sheet<\/a> outlines some great principles to follow for secure file upload implementation (which we won\u2019t go into listing them all here but thought it was worth mentioning in an article about website security tips). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But why\nis this such a critical move for website security? Let\u2019s ask one of the pros:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Here is one way that a lot of <a href=\"https:\/\/sectigostore.com\/blog\/what-to-do-if-your-website-is-hacked\/\">websites get hacked<\/a>. A lot of websites will allow unvetted file uploads to their website. The grave mistake website owners make is that they only check the file extension and determining if it&#8217;s safe based of that. This is a huge error since the extensions can easily be faked and .exe files aren&#8217;t the only thing that can cause damage. For example, images can have dangerous PHP code in the comments.&nbsp;There are some workarounds that website owners can do. One is to simply not allow the users to execute any files that they upload. This means that the files will be stored in the database, outside of the server where your website is stored. Make sure that the files uploaded are using a secure mode of transportation with SFTP and <a href=\"https:\/\/sectigostore.com\/blog\/ssh-vs-ssl-exploring-the-similarities-and-differences\/\">SSH<\/a> ports. The second one is to do a quick check to verify that the file extension is the correct one by simply changing the extension name.\u201d<\/em> <\/p><cite> <strong>\u2014 Mark Soto, owner of Cybericus<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"4-use-encryption-and-secure-protocols-to-serve-your-website-via-https\">4. Use Encryption and Secure Protocols to Serve Your Website via HTTPS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Oh, yeah. You knew this would make our expert website security tips list somehow. Using <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/sectigostore.com\/ssl-types\" target=\"_blank\">SSL\/TLS certificates<\/a> for your website and server to facilitate a secure, encrypted connection between two parties (i.e. your site visitors\u2019 clients and your web browser) is essential. We don\u2019t only say that because we happen to sell such certificates, but because serving websites via HTTPS is actually required by Google and the other major browsers to avoid being slapped with a tacky \u201cNot Secure\u201d label.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thankfully, we\u2019re not alone \u2014 David Alexander, Alexander M. Kehoe, Dave Hatter, Ross Thomas, and Greg Rogozinski also agree. In their website security tips, they emphasize the importance of SSL\/TLS protecting users\u2019 sensitive information. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Probably the two who put it best, though, are Luka Arezina and Sivan Tehila: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One good tip for any website owner, especially <a href=\"https:\/\/sectigostore.com\/blog\/21-powerful-ecommerce-statistics-that-every-entrepreneur-must-know\/\">eCommerce websites<\/a>, is to set up SSL security on the domain. Having an SSL-secured domain lets your future customers know that they are visiting a website where the data is coming from a secure source.&nbsp;This is visually displayed as a &#8220;green padlock&#8221; icon on the website address field, in the top-left corner of your browser.&nbsp;<\/em><\/p><p><em>A secure domain also lets visitors on your website know right from the landing page that your company takes cybersecurity seriously. It also prevents &#8220;content warning&#8221; and &#8220;unsecured connection&#8221; messages from spooking away your potential customers. Additionally, it adds another layer of data protection to transactions on the website, which is critical for doing business online.\u201d<\/em><\/p><cite> \u2014 <strong>Luka Arezina, editor-in-chief at DataProt<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>When it comes to best website security tips, the first one that comes to mind is making sure your website has an SSL connection. An SSL connection is an encryption method that is used when a visitor makes a connection to your web host server. This is one of the easiest ways to ensure your customer\u2019s information is secure. Additionally, Google warns visitors when they\u2019re entering a site without SSL.&#8221;<\/em> <\/p><cite> <strong>\u2014 Sivan Tehila, Director of Solution Architecture of&nbsp;Perimeter 81<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"5-use-dns-filtering-to-restrict-access-to-specific-sites\">5. Use DNS Filtering to Restrict Access to Specific Sites<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If only there was a way to protect your employees from\naccidentally downloading web-borne threats\u2026 Oh, wait, there is! It\u2019s called\nusing a DNS filter. The domain name system (DNS), which (in a roundabout sort\nof way) is used as an intermediary between browsers and servers to convert\n\u201cgoogle.com\u201d or \u201capple.com\u201d into an IP address that the server can retrieve,\nalso has some handy filtering capabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, why is it such a great option for cybersecurity? Sivan\nTehila is, again, quick with an answer:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One of the best website security tools I recommend to implement is a DNS filtering feature. DNS filtering offers businesses the option to restrict employee access to certain URLs, by defining which are either permitted or blocked sites. One of the key reasons why every business should adopt DNS filtering is to prevent employees from gaining access to websites that don\u2019t help them with their jobs, or sites that can create major security risks for the organization. By limiting access to certain URLs, it helps employees be more productive and helps to fight off potential security risks such as data loss, malware, or even legal issues.&#8221;<\/em> <\/p><cite> <strong>\u2014 Sivan Tehila, Director of Solution Architecture of&nbsp;Perimeter 81<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"6-have-visibility-within-your-servers-databases-networks-and-general-infrastructure\">6. Have Visibility Within Your Servers, Databases, Networks, and General\nInfrastructure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Website and IT admins worldwide\nface a very real and frustrating conundrum every day: They\u2019re expected to keep\nnetworks, computer systems, and websites safe from the reach of hackers and\ncybercriminals. Heck, you\u2019re probably one of them. But how can you protect what\nyou don\u2019t know you have? This is where having strong visibility is key:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>In short, know what is being deployed in your infrastructure. If you can\u2019t tell when a new device is added anywhere on your network, there\u2019s an issue. Organizations are compromised everyday via third-party systems or shadow IT that they didn\u2019t know was on the network.\u201d<\/em> <\/p><cite> <strong>\u2014 Brad Pierce, director of network security at HORNE Cyber<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Whether it\u2019s a mobile device, an SSL\/TLS certificate, or an <a href=\"https:\/\/sectigostore.com\/blog\/10-iot-security-tips-you-can-use-to-secure-your-iot-devices\/\">IoT device<\/a> like a smart printer, you need to know what\u2019s connected to your systems at all times to prevent <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/sectigostore.com\/blog\/data-leak-8-data-leakage-prevention-tips-for-your-organization\/\" target=\"_blank\">data leaks<\/a> and to improve your website security efforts (and general cybersecurity) as a whole. Shadow IT and unknown digital certificates for websites not only leave your business at risk, but it can cost you time and money as well in terms of downtime and noncompliance penalties. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For obvious reasons, this is one of the most important website security tips we could include in this list. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"7-keep-software-firmware-up-to-date-and-patched\">7. Keep Software, Firmware Up to Date and Patched<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This next point nicely follows the last in our list of website security tips. While it\u2019s not only important to have full visibility of your network, IT infrastructure, and tech components, it\u2019s also essential that you make sure everything is current. I\u2019m talking about updates and patches here. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At one point or another any software or server is going to\nrequire updates and\/or patching. Keeping everything up to date not only enables\nyou to operate using the newest everything, but it also helps you to patch any\ngaps in your cybersecurity defenses that manufacturers fixed with those updates.\nYou can do this manually, or you can rely on automatic updates.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One of the first tips I start with is making sure your server isn&#8217;t using an old version of PHP like the 5.x generation. I see this issue on a regular basis when PHP 5.x has been retired and not receiving&nbsp;security and bug fixes since&nbsp;1 January 2019.\u201d<\/em> <\/p><cite> \u2014<strong> David Alexander, designer, developer and digital marketer at MazePress<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"8-check-your-configurations-to-ensure-they\u2019re-set-properly\">8. Check Your Configurations to Ensure They\u2019re Set Properly<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Taking the time to periodically check your site configurations is simple and is a best practice. For one, this expert tip helps you to ensure that not changes were made to your existing configurations. Secondly, it also gives you a chance to review what your current configurations are in case you do need to make some changes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what do they experts have to say about it?<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One of the biggest gaps that I see is the lack of security around website configurations (database credentials, API tokens, etc.). Most websites store their configurations either un-encrypted on their servers, or even worse, directly in code. And developers typically share the configs through unsecure channels like Slack or Email. <\/em><\/p><p><em>A solution to this would be to encrypt configurations, however managing how to decrypt and inject that configuration securely is a huge challenge. I run a startup that is building a product called &#8220;Courier&#8221; (CourierConfig.com) that helps users secure their application configuration for deployment and securely share their configuration. This was really born out of the difficulty of managing websites&#8217; configuration.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Yoseph Radding, software engineer and Cofounder of Shuttl LLC<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"9-use-reverse-proxies-for-large-websites\">9. Use Reverse Proxies for Large Websites<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Although not everyone thinks it\u2019s necessary to go to the\ntrouble of implementing them, using reverse proxies is a practice that\u2019s been\nknown to secure multiple web servers from web application vulnerabilities. These\nproxies are typically used to not only increase security, but they also\nincrease performance and general reliability because they often have greater\nresources at their disposal. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>While I would agree it is easier said than done, reverse proxies are a great security-related solution for larger websites or clusters of websites. A reverse proxy is a server that handles requests (typically the public facing 443 and 80 requests) to webserver(s) that the proxy sits in front of. When it is time to handle requests to the public, the reverse proxy will get the information (typically cached) from the webservers and then serve it to the requestors. So, a user would not be requesting directly from the webserver, but it would be requesting from the reverse proxy. <\/em><\/p><p><em>This adds another layer of security between and the requests made from reverse proxy to webserver can be way more secure without worry of breaking access or adding tons of overhead during high-traffic times.\u201d<\/em> <\/p><cite> <strong>\u2014 Ross Thomas, IT administrator at SectigoStore.com<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"10-reconsider-hosting-multiple-websites-on-one-server\">10. Reconsider Hosting Multiple Websites on One Server<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-1024x640.jpg\" alt=\"Image of a server room, which would be impacted by SSL offloading\" class=\"wp-image-741\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-1024x640.jpg 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-300x188.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-560x350.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-1536x960.jpg 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-940x588.jpg 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading-480x300.jpg 480w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/ssl_offloading.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">While there is not necessarily anything inherently \u201cbad\u201d\nabout hosting multiple websites simultaneously on a server, there is security\nconcern that the sites might have some limited level of access to each other. Basically,\nthe issue here is the risk of cross-site contamination in shared hosting\nenvironments. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.sucuri.net\/2020\/01\/what-is-cross-site-contamination.html\">Cross-site\ncontamination<\/a> results when websites in a shared server environment aren\u2019t\nproperly isolated. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>You should avoid running multiple websites on one server and I&#8217;ve seen this mistake done numerous times. Secondly, you should create a separate database for each site instead of using prefixes. This will help you keep your websites isolated.\u201d<\/em> <\/p><cite> <strong>\u2014 Mihai Corbuleac, information security consultant at StratusPointIT<\/strong>  <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"11-keep-multiple-current-website-files-and-database-backups\">11. Keep Multiple, Current Website Files and Database Backups <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The importance of regularly creating and maintaining up-to-date <a href=\"https:\/\/sectigostore.com\/codeguard\/backup\">website and database backups<\/a> should go without saying. Basically, if crap hits the proverbial fan and you don\u2019t have your files, content, plugins, and anything else related to your website backed up, then you\u2019re really going to regret it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our web and IT experts are in agreement with their website security tips on the topic: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>They say prevention is better than the cure, but having a fallback plan is also a good idea. You should back up your website regularly in the unlikely event that it gets compromised. Luckily for you, some hosting providers do it for you automatically. However, this is no excuse to not do it yourself, since this is your website after all. Having an <a href=\"https:\/\/sectigostore.com\/blog\/what-is-an-incremental-backup\/\">off-site backup<\/a> somewhere might just be the magic cure that resurrects your website from the dead.\u201d&nbsp;<\/em><\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Also, is crucial to back up your website regularly. Of course, some hosting providers do it for you, automatically, but for improved security it&#8217;s best to keep off-site backups.\u201d<\/em> <\/p><cite> <strong>\u2014 Mihai Corbuleac, information security consultant at StratusPointIT<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"12-keep-your-database-separate-from-your-file-server\">12. Keep Your Database Separate from Your File Server<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are different reasons why someone would choose to host\ntheir files on the same server as their database. One of the most common is\nconvenience or to save on cost. However, there are some regulations that may\nrequire a separation of duties (SoD). The Payment Card Industry Data Security\nStandard (PCI DSS) is one of them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pcisecuritystandards.org\/pdfs\/pci_dss_validation_requirements_for_qualified_security_assessors_QSAs_v1-1.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">PCI DSS Rule 2.2.1<\/a> of the most recent Requirements and Security Assessment Procedures doc (version 3.2.1) specifies that PCI DSS compliance businesses must \u201cimplement only one primary function per server to prevent functions that require difference security levels from co-existing on the same server.\u201d So, this means that any database containing sensitive financial data, such as credit card details, must be separate and can\u2019t communicate directly with the internet. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, if you don\u2019t need to be compliant with PCI DSS for some\nreason, what other reason could you have for wanting to separate your web or\napplication servers from your database? Some experts argue that running a\nmulti-server environment can actually be beneficial because it increases the\nnumber of resources and connections you can support, and that it also can make\nmonitoring more effective. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>I highly recommend that you separate the database from the file server. It might be costly at first, but doing this will ensure that no attacker will have access to sensitive data found in your database. You might have a compromised website but at least information like bank accounts, credit cards, and personal information.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Depending on what your site is doing, user data is always a big point of contention and can lead to the dreadful lawsuits\/PR embarrassment. Do right by your customers\/clients and protect their data. <\/em><\/p><p><em>One thing that should always be practiced, no matter how small the site, is to offload any database related to the website onto a different server. The amount of code added to makes calls\/queries to the database server is often minimal, but moreso than making calls to the local machine. And, as long as you have your database being accessed through a local network, as in no public facing network interfaces, that immediately complicated any hackers\u2019 attempts to gaining access to that data. Though, it is certainly not impossible. <\/em><\/p><p><em>Things like tokenization or encryption can help protect the data itself. Consider using these if you are holding sensitive user information, such as addresses or payment information. Encryption makes a lot of sense when the database is only be accessed by a few things.\u201d<\/em><\/p><cite> <strong>\u2014 Ross Thomas, IT administrator at SectigoStore.com<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"13-use-the-right-website-security-tools-and-features\">13. Use the Right Website Security Tools and Features<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every website owner or administrator should be using secure\narchitectural design and coding practices. Furthermore, it\u2019s crucial that they\nalso use standard defense and threat detection mechanisms as well, including\nvulnerability scanning tools and web application firewalls. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what other software, plugins, extensions, etc. would be useful? We posed this question to the experts as well for our list of website security tips. Here\u2019s what they had to say:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"sqlmap\">SQLMap<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>SQL injections have become really trendy lately, and I believe that most hackers are prone to using this especially with the rise of cloud-based systems like Microsoft Azure. If you didn\u2019t know SQL injection is effective for cloud-based systems which is why a lot of security experts are finding ways to stop this vulnerability. <\/em><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"http:\/\/sqlmap.org\/\" target=\"_blank\"><em>SQLMap<\/em><\/a><em> is an open-source testing tool that can detect SQL flaws in the system allowing you to fix potential areas that are targets for SQL injection. I highly recommend that anyone with a website get this.\u201d<\/em><\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"threatrunner\">ThreatRunner<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Being proactive and taking an offensive approach to ensuring online security is the better option, as compared to waiting to see if an attack comes.&nbsp;<\/em><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/threatrunner.com\/\" target=\"_blank\"><em>Threat Runner<\/em><\/a><em>&nbsp;is a penetration tool that is designed to safely simulate a malware infection on an organization&#8217;s network. Through reverse engineering and the de-weaponization of authentic malware samples, it mitigates the risk of damage of an attack through knowledge and context of vulnerabilities within the network, strengthening security posture.\u201d<\/em> <\/p><cite> <strong>\u2014 Brad Pierce, director of network security at HORNE Cyber<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"zed-attack-proxy-zap\">Zed Attack Proxy (ZAP)<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>ZAP is also a web security application that every website owner should get. It\u2019s open-source software that simulates an attack allowing the program to find vulnerabilities in your systems such as missing anti-CSRF tokens, private IP disclosure, SQL injections, and&nbsp;XSS injections. ZAP is also very intuitive, making it usable for both beginners and pros alike.<\/em>\u201d&nbsp;<\/p><cite> &nbsp;<strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"multiple-solution-recommendations\">Multiple Solution Recommendations<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">And some experts believe there is never just one solution\nthat should be put to work: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>I don&#8217;t think the professionals&nbsp;limit their selves with one or two tools, so it is not possible to have favorite ones. It is all about to clarify what do want to do and what is your goal, because every tool has its own specificity.\u201d<\/em> <\/p><cite> \u2014 <strong>Ben Hartwig, chief security officer and head software engineer at InfoTracer<\/strong> <\/cite><\/blockquote>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Duo Two-Factor Authentication is a great service that allows you to securely log in without being restricted by location or IP address. On the fraud prevention front both Kount and Signifyd provide great services for verifying identity and protecting businesses from fraudulent credit card use, which is rampant in this day and age.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Brian Taylor, co-founder of Forix<\/strong> <\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"14-review-your-web-server-security-policies-regularly\">14. Review Your Web Server Security Policies Regularly<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While this should be part of your regular responsibilities\nrelating to website security, it\u2019s surprising how many people try to put it off\nfor another day (that, ultimately, may never come). Reviewing your security\npolicies is something that should be done on a regular basis \u2014 quarterly,\nideally. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Security policies can encompass a lot of things, but the main points are who has access to what and how do they do it. Of course, the \u2018why\u2019 is the reason why we even do all of this\u2026.<\/em><\/p><p><em>Reviewing the access policy (basically like a lower level firewall) for your webserver is a good way to close the roads of the unwanted requests. Typically, you\u2019d want your public-facing traffic going through port 443 (HTTPS) or port 80 (I guess) but specifying admin access (typically using something like SSH) to certain IP addresses will really limit access to the backend and parts outside of the website.<\/em><\/p><p><em>Review patches for critical software that are (likely) improvements in the software\u2019s security. Unless the flaw is critical and propagating quickly, I would also wait on patches and review feedback so efforts to secure a problem are not doubled.\u201d<\/em> <\/p><cite> <strong>\u2014 Ross Thomas, IT administrator at SectigoStore.com<\/strong><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><em>But, wait, there\u2019s only 14 website security tips listed here!<\/em> Yes, I know. That\u2019s because the experts also had some suggestions about things you should avoid doing to improve your website security (and general cyber security as a whole) as well that I\u2019d like to share. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"website-security-tips-7-website-security-mistakes-to-avoid\">Website Security Tips: 7 Website Security Mistakes to Avoid <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now that we\u2019ve covered some of the website security best\npractices that should be implementing or following, I thought it would be fun\nto also ask these experts what sort of website security mistakes that people\nshould avoid. Of course, there are the usual things \u2014 don\u2019t ignore your\nsecurity, make your budget match your security efforts, etc. But, surely, there\nare other recommendations, right? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Needless to say, I wasn\u2019t disappointed. Here are some of the\ninsights from these website and cybersecurity experts about what you should not\ndo when it comes to website security:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"believing-cyber-security-is-\u201call-or-nothing\u201d\">Believing Cyber Security Is \u201cAll or Nothing\u201d<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>The biggest mistake we see in cyber security is the mindset that it is all or nothing. You don&#8217;t need to budget a million dollars a year to have a full time cyber-security consulting firm watching your every move. For most businesses, especially small businesses, all they really need is some very minor protection from firewall software, an SSL certificate, and 2-factor authentication&nbsp;of their passwords. You can absolutely find free and cheap tools to protect your website from 90% of attacks without bankrupting&nbsp;your company. <\/em><\/p><p><em>Once you can afford a more robust security apparatus, then you can buy one. Don&#8217;t be afraid to take a few&nbsp;minor&nbsp;steps, because those may be enough to save your business from the majority of attacks.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong>&nbsp;<strong>Alexander M. Kehoe, Co-founder and Operations Director at Caveni<\/strong>  <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"being-negligent-and-ignoring-the-obvious\">Being Negligent and Ignoring the Obvious<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>It&#8217;s usually a matter of not bothering with the obvious things. Not making sure you&#8217;re up to date on PCI vulnerability scans, not limiting access to your admin area due to inconvenience, and not investing in staying up to date with the software versions are the most common reasons we&#8217;ve seen for breaches.\u201d<\/em> <\/p><cite> <strong>\u2014 Brian Taylor, co-founder of Forix<\/strong> <\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">IT security consultant Dave Hatter says that some of the most important things to consider when securing web applications can be found on <a href=\"https:\/\/sectigostore.com\/blog\/what-is-owasp-what-are-the-owasp-top-10-vulnerabilities\/\">OWASP\u2019s Top 10<\/a> and <a href=\"https:\/\/cwe.mitre.org\/top25\/archive\/2019\/2019_cwe_top25.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">CWE\u2019s Top 25<\/a> lists.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Of these lists, the things that seem to be most often overlooked and most easily corrected are:<\/em><\/p><p><em>&#8211; Injection attacks (SQL, Command): Validating ALL input against a whitelist and disallowing dynamic queries (requiring parameterized queries or stored procedures)<\/em><\/p><p><em>&#8211; Broken authentication: Ensuring that all secured pages require a unique token along with complete mediation, ensuring that each and every access to a secured object is checked for authorization can solve this issue<\/em><\/p><p><em>&#8211; Sensitive data exposure: Encryption, least privilege and least common mechanism can solve this issue<\/em><\/p><p><em>&#8211; Hardened systems: CIS Benchmarks can help admins harden and secure on-premises systems, and Cloud based platforms like Azure, when configured correctly can provide additional security for web apps.&#8221;<\/em><\/p><cite> <strong>\u2014 Dave Hatter, IT security consultant at Intrust IT<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"having-poor-password-selection-management-and-policies\">Having Poor Password Selection, Management, and Policies<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Common mistakes people make with passwords that make them easily hackable is people using notable people, pets and dates personal to them, which of course these words will be the first passwords that a hacker will attempt!\u201d<\/em> <\/p><cite> <strong>\u2014 Dustin Vann, Owner &amp; Website Manager at Trusy Social<\/strong> <strong>(Trusy.co)<\/strong>  <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"using-default-credentials-site-addresses-and-database-prefixes\">Using Default Credentials, Site Addresses, and Database Prefixes<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>My tips to help protect websites from one of the most popular security problems that is breaking into the admin system using brute-force. Oftentimes, when e.g. bots try to guess the admin password and you have a standard &#8220;wp-admin&#8221; panel address and a default \u201cadmin\u201d username, it is easy for them to break into your system. The following tips will help prevent it.<\/em><\/p><p><em>What I recommend is to, first of all, change the default login admin panel address to one made by yourself, e.g. \u201c\/wp-admin\u201d to \u201c\/my-own-secure-cms-panel\u201d. The next step is changing the default administrator name, e.g. from \u201cadmin\u201d to \u201cmylogin2746\u201d. If you are using an open-source CMS, change the default database prefixes e.g. \u201cwp\u201d to \u201chj34\u201d. WordPress&#8217; users should additionally install a security plugin, such as Wordfence or iThemes Security. Another good practice is to introduce two-step verification of users when logging into the admin panel.\u201d<\/em> <\/p><cite> <strong>\u2014 Greg Rogozinski, co-founder and CEO of Cut2Code<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"including-session-ids-in-urls\">Including Session IDs in URLS<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Session-Id should not be passed to URL. It may allow an attacker to login to the system and perform unauthorized operations.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"lacking-regular-website-testing\">Lacking Regular Website Testing<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>One of the most common mistakes that I see a lot of website owners make is that they don\u2019t test their website regularly. Scanning can help detect problems, but testing the website itself will reveal problems with the code itself. You\u2019ll be able to see which parts are vulnerable to attack and which areas to improve. Testing your website regularly after a new update is a must to ensure that no one will take advantage of poorly written code.\u201d<\/em> <\/p><cite> <strong>\u2014<\/strong> <strong>Kenny Trinh, CEO of GeekWithLaptop and founder and CEO of Netbooknews<\/strong> <\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"trusting-their-security-to-one-product-or-solution\">Trusting Their Security to One Product or Solution<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Be wary of security products and solutions that are marketed to completely protect your organization. I\u2019m not talking about the traditional requirements of firewalls, intrusion detection\/prevention, but rather the \u201cautomagic\u201d and \u201csilver bullet\u201d cybersecurity solutions of the world. There\u2019s no easy button &#8212; cybersecurity is complicated and cyber threats are constantly evolving and so should your security tools.\u201d<\/em><strong> <\/strong><\/p><cite> <strong>\u2014 Brad Pierce, director of network security at HORNE Cyber<\/strong>  <\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now that you\u2019ve had a chance to hear from all of these incredible\nindustry experts, you may be wondering: <em>Who the heck are they and why should\nI listen to them?<\/em> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wonder no more! Let\u2019s introduce our experts for this website security tips list. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"meet-the-website-security-tips-experts-listed-in-alphabetical-order-by-surname\">Meet the Website Security Tips Experts (Listed in Alphabetical Order by\nSurname)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>David Alexander, designer, developer and digital marketer at <\/strong><a href=\"https:\/\/mazepress.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>MazePress<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a web\ndeveloper and WordPress expert with 14 years of experience, Alexander has had\nto deal with his fair share of hacked websites and offers a malware removal\nservice.&nbsp;He works with clients globally across a variety of markets. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Luka Arezina, editor-in-chief at <\/strong><a href=\"https:\/\/dataprot.net\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>DataProt<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DataProt is an online publication that\u2019s dedicated to teaching\nusers how to stay safe online and teaches the ins and outs of cyber hygiene.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mihai Corbuleac, information security consultant at <\/strong><a href=\"https:\/\/www.computersupport.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>StratusPointIT<\/strong><\/a><strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">StratusPointIT is an IT support company providing\nprofessional IT support, cloud and information security services to small and\nmedium businesses across the United States since 2006.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ben Hartwig, chief security officer and head software engineer at <\/strong><a href=\"https:\/\/infotracer.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>InfoTracer<\/strong><\/a><strong>.<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hartwig is both the IT guru and the self-proclaimed digital\noverlord at InfoTracer. He authors guides on marketing and cyber security\nposture \u2014 he also loves sharing best practices to enhance website security. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Dave Hatter, an IT cybersecurity consultant at <\/strong><a href=\"https:\/\/www.intrust-it.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Intrust IT<\/strong><\/a><strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hatter is a software engineer and educator with more than 25 years\nin IT. Throughout his career, he\u2019s focused on software development and\ncybersecurity. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Alexander M. Kehoe, Co-founder and Operations Director at <\/strong><a href=\"https:\/\/caveni.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Caveni<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kehoe is both the co-founder and operation director at\nCaveni Digital Solutions, a leading digital marketing agency in Philadelphia.\nHe\u2019s also a co-author of the book \u201cNavigate the Digital Realm\u201d and frequently\nspeaks and consults in the fields of digital marketing, web design, artificial\nintelligence, and other areas of expertise. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Corey Petty, a&nbsp;Senior Security Engineer at <\/strong><a href=\"https:\/\/status.im\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Status<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Petty is a technology enthusiast as well as a privacy and\nsecurity evangelist who co-founded The Bitcoin Podcast Network. He previously\nserved as a senior blockchain scientist, SME at Booz Allen Hamilton and has a Ph.D.\nin chemical physics. Status is an encrypted messenger application that also\nfunction as a crypto wallet and Web3 browser. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Brad Pierce, director of network security at <\/strong><a href=\"https:\/\/www.hornecyber.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>HORNE Cyber<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.hornecyber.com\/our-team\/brad-pierce\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Pierce<\/a>&nbsp;has 15 years of IT and cybersecurity experience. He manages the cybersecurity operations center where he, along with a team of cyber analysts, monitors live network traffic for clients in search of active threats. He also creates information security awareness programs for organizations to help guide them on how to best address cyber risks and remediate organization-specific vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Yoseph Radding, software engineer and Cofounder of <a rel=\"noreferrer noopener\" aria-label=\"Shuttl LLC (opens in a new tab)\" href=\"https:\/\/www.shuttl.io\/\" target=\"_blank\">Shuttl<\/a><a href=\"https:\/\/www.shuttl.io\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Shuttl LLC (opens in a new tab)\">,<\/a><a rel=\"noreferrer noopener\" aria-label=\"Shuttl LLC (opens in a new tab)\" href=\"https:\/\/www.shuttl.io\/\" target=\"_blank\"> LLC<\/a><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Radding is a professional programmer, hobbyist hacker, and\nweb developer. He also is the co-founder of Shuttl, LLC and developer of the\nmobile app LykeMe. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Greg Rogozinski, co-founder and CEO of <\/strong><a href=\"https:\/\/cut2code.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Cut2Code<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rogozinski is the CEO of Cut2Code, a company that specializes in web development based on CMS platforms. He is a specialist with <a href=\"https:\/\/sectigostore.com\/blog\/wordpress-stats-eye-opening-wordpress-statistics\/\">8 years of experience in digital business, and an expert in Magento and WordPress<\/a>. He has worked with such agencies as Global4Net, Lemon Sky and JWT Poland.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Nick Santora, CEO and co-founder of <\/strong><a href=\"https:\/\/www.getcurricula.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Curricula<\/strong><\/a><strong>, a cyber security education company. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Santora previously spent seven years as a cybersecurity\nadvisor for the North American Electric Reliability Corporation (NERC), the\nenforcement agency that\u2019s responsible for regulating the U.S.\u2019s power grid. He\nalso is a cybersecurity expert who speaks regularly at conferences across the\nU.S. on the topic of the psychology of influencing employees via security\nawareness programs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Brian Taylor, co-founder of <\/strong><a href=\"https:\/\/www.forixcommerce.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Forix<\/strong><\/a><strong>, <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Taylor is vice president and head of business development at\nForix, a Portland-based digital agency that focuses on ongoing eCommerce\nwebsite support and conversion rate optimization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sivan Tehila, Director of Solution Architecture of&nbsp;<\/strong><a href=\"https:\/\/www.perimeter81.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Perimeter 81<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tehila is a cyber and information security expert with 13\nyears of experience in cyber management, defense industries, and critical\ninfrastructures. She is dedicated to promoting women in cybersecurity, having\nfounded the Leading Cyber Ladies community in NYC and Cyber19w in Israel.\nPerimeter 81 is a Zero Trust Network as a Service provider designed to secure\nnetwork access for the modern and distributed workforce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ross Thomas, IT administrator at SectigoStore.com<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thomas started his IT career in high school, completed a bachelor\u2019s\ndegree in management information systems at Florida State University, then a master\u2019s\ndegree in IT security from the University of Liverpool. He has more than 20 years\nof experience working across many facets of the IT world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mark Soto, founder of <\/strong><a href=\"https:\/\/cybericus.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Cybericus<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Soto is the founder of Cybericus, a small cybersecurity\ncompany in Wisconsin. He holds a degree in computer science and worked as a\nsecurity analyst in the banking industry for 8 years where he saw the rise of\nransomware. Sensing an opportunity, he left the corporate world and started his\nbusiness, which focuses on ransomware data recovery. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Kenny Trinh, CEO of <\/strong><a href=\"https:\/\/www.geekwithlaptop.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>GeekWithLaptop<\/strong><\/a><strong> and founder and CEO of <\/strong><a href=\"https:\/\/www.netbooknews.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"><strong>Netbooknews<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the head of GeekWithLaptop, an online review publication\nwith 100% remote workers, Trinh understands the complexities of working\nremotely and values the importance of having strong cybersecurity mechanisms in\nplace. He is the managing editor of both tech-focused publications, which review\ntech and gadgets and aim to help users gain knowledge about everything tech. As\na tech enthusiast, Trinh\u2019s been building computers and coding since he was a\nchild. He also has a bachelor\u2019s degree in it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Dustin Vann, Owner &amp; Website Manager at <\/strong><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/trusy.co\/\" target=\"_blank\"><strong>Trusy Social<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Vann is a social media and branding genius who serves as\npresident of digital &amp; ecommerce ventures at Comer Companies. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts-on-these-website-security-tips-and-how-to-secure-your-website\">Final Thoughts on These Website Security Tips and How to Secure Your Website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The bottom line here is that having\nan ecommerce website is a golden opportunity for many businesses. It\u2019s also a\ngreat way for other organizations to get their name out there and to promote\ntheir missions. But without the proper protections in place, websites are\ninherently insecure, which leaves your data \u2014 and that of your site users who\nprovide their information via transactions and forms \u2014 at risk to the world of cyber\nthreats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why it\u2019s crucial for\norganizations, regardless of size, to do everything within their power to\nsecure their websites. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After reading these website\nsecurity tips from many industry experts, I\u2019m sure that you have some\nadditional recommendations of your own. Be sure to share them in the comments\nbelow to add them to the list!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>17 website, IT and cybersecurity professionals weigh in on how to make a website secure (and things you should avoid doing) with their expert tips If you\u2019re not sure \u201chow&#8230;<\/p>\n","protected":false},"author":8,"featured_media":802,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13],"tags":[44,52],"class_list":["post-795","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-tips","tag-website-security","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"Wondering how to secure a website? We&#039;ve got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"Wondering how to secure a website? We&#039;ve got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-31T19:52:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-28T12:05:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Casey Crane\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Casey Crane\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/\"},\"author\":{\"name\":\"Casey Crane\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\"},\"headline\":\"How to Secure a Website: 21 Website Security Tips for Businesses\",\"datePublished\":\"2020-03-31T19:52:29+00:00\",\"dateModified\":\"2025-04-28T12:05:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/\"},\"wordCount\":6552,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/website-security-tips.jpg\",\"keywords\":[\"Tips\",\"website security\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/\",\"name\":\"How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/website-security-tips.jpg\",\"datePublished\":\"2020-03-31T19:52:29+00:00\",\"dateModified\":\"2025-04-28T12:05:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\"},\"description\":\"Wondering how to secure a website? We've got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/website-security-tips.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/website-security-tips.jpg\",\"width\":1600,\"height\":1000,\"caption\":\"Website security tips graphic of a hand typing on a computer displaying HTML info\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/how-to-secure-a-website-website-security-tips-for-businesses\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Secure a Website: 21 Website Security Tips for Businesses\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\",\"name\":\"Casey Crane\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"caption\":\"Casey Crane\"},\"description\":\"Casey is a writer and editor with a background in journalism, marketing, PR and communications. She has written about cyber security and information technology for several industry publications, including InfoSec Insights, Hashed Out, Experfy, HackerNoon, and Cybercrime Magazine.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights","description":"Wondering how to secure a website? We've got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/","og_locale":"en_US","og_type":"article","og_title":"How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights","og_description":"Wondering how to secure a website? We've got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.","og_url":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/","og_site_name":"InfoSec Insights","article_published_time":"2020-03-31T19:52:29+00:00","article_modified_time":"2025-04-28T12:05:20+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg","type":"image\/jpeg"}],"author":"Casey Crane","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Casey Crane","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/"},"author":{"name":"Casey Crane","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c"},"headline":"How to Secure a Website: 21 Website Security Tips for Businesses","datePublished":"2020-03-31T19:52:29+00:00","dateModified":"2025-04-28T12:05:20+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/"},"wordCount":6552,"image":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg","keywords":["Tips","website security"],"articleSection":["Cyber Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/","url":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/","name":"How to Secure a Website: 21 Website Security Tips for Businesses - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg","datePublished":"2020-03-31T19:52:29+00:00","dateModified":"2025-04-28T12:05:20+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c"},"description":"Wondering how to secure a website? We've got 21 useful website security tips for your organization from 17 website, IT, and cyber security industry experts.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/website-security-tips.jpg","width":1600,"height":1000,"caption":"Website security tips graphic of a hand typing on a computer displaying HTML info"},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/how-to-secure-a-website-website-security-tips-for-businesses\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"How to Secure a Website: 21 Website Security Tips for Businesses"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c","name":"Casey Crane","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","caption":"Casey Crane"},"description":"Casey is a writer and editor with a background in journalism, marketing, PR and communications. She has written about cyber security and information technology for several industry publications, including InfoSec Insights, Hashed Out, Experfy, HackerNoon, and Cybercrime Magazine."}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=795"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/795\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/802"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}