{"id":17510,"date":"2024-02-02T14:34:48","date_gmt":"2024-02-02T19:34:48","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=17510"},"modified":"2024-02-28T12:55:58","modified_gmt":"2024-02-28T17:55:58","slug":"how-do-i-make-my-website-secure","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/how-do-i-make-my-website-secure\/","title":{"rendered":"How Do I Make My Website Secure? The Essential Guide"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-knowing-how-to-make-your-website-secure-can-be-the-difference-between-sharing-positive-news-with-website-users-and-having-to-inform-them-that-their-data-has-been-breached\">Knowing how to make your website secure can be the difference between sharing positive news with website users and having to inform them that their data has been breached. &nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are certain things every website owner should know, and a very important one is how to make your website secure (or, at least, as secure as possible). We\u2019re here to provide guidance that may serve as a quick refresher for some and an educaitonal guide for others to explore.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-make-your-website-secure-17-ways\">How to Make Your Website Secure (17 Ways)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s dive right into answering the question you want to know: \u201chow do I make my website secure?\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-use-public-key-cryptography-to-your-advantage\">Use Public Key Cryptography to Your Advantage<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-1-install-an-ssl-tls-certificate-that-secures-your-main-domain-and-any-subdomains\">1. Install an SSL\/TLS Certificate That Secures Your Main Domain (and Any Subdomains)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Considering we\u2019re The SSL Store, it shouldn\u2019t come as a surprise that the top item on our list would be a website security certificate. However, our reason for doing so isn\u2019t purely biased; using a valid SSL\/TLS certificate on your website:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is an industry best practice for securing data in transit using public key encryption.<\/li>\n\n\n\n<li><a href=\"https:\/\/developers.google.com\/search\/blog\/2014\/08\/https-as-ranking-signal\">Improves your site\u2019s Google search engine ranking<\/a>.<\/li>\n\n\n\n<li>Aids compliance with industry data security and privacy laws and regulations.<\/li>\n\n\n\n<li>Supports your brand\u2019s reputation and standing with customers through digital trust.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When data is transmitted in plaintext, it\u2019s vulnerable to <a href=\"https:\/\/www.thesslstore.com\/blog\/man-in-the-middle-attack\/\">man-in-the-middle (MitM) attacks<\/a>. This means that bad guys can see and steal sensitive data (credit cards, bank account info, usernames and passwords, etc.) they can use to commit crimes. They can also inject malicious content and create a host of other issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This next item on the list of how to make your website secure goes hand-in-hand with the first\u2026. &nbsp;&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-2-carefully-manage-your-pki-digital-assets-using-automation-to-avoid-downtime\">2. Carefully Manage Your PKI Digital Assets Using Automation to Avoid Downtime<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Having an expired, revoked, or otherwise invalid SSL\/TLS certificate on your website or web app means you (and your company\u2019s customer support team) are in for a bad day. When a certificate isn\u2019t valid, your site, app, and customers will experience downtime or service outages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, here\u2019s the type of message your customers may see if your site is using an invalid SSL\/TLS certificate:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"509\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example-1024x509.jpg\" alt=\"How do I make my website secure graphic: invalid SSL certificate warning\" class=\"wp-image-17514\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example-1024x509.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example-300x149.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example-768x382.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example-1536x764.jpg 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/invalid-ssl-certificate-example.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of a website displaying an \u201cInvalid SSL certificate\u201d warning message.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is what it may look like (in Google Chrome) if your site uses an expired website security certificate:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"532\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/your-connection-is-not-private-example-1024x532.png\" alt=\"How do I make my website secure graphic: &quot;Your connection is not private&quot; Chrome warning\" class=\"wp-image-17515\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/your-connection-is-not-private-example-1024x532.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/your-connection-is-not-private-example-300x156.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/your-connection-is-not-private-example-768x399.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/your-connection-is-not-private-example.png 1268w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot we captured on BadSSL.com of the example expired certificate.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Downtime like this leaves customers with a bad impression of your company, damaging relationships and resulting in lost sales and revenue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check out our other related articles to learn more about expired certificates:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\">This Is What Happens When Your SSL Certificate Expires<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/your-security-certificate-has-expired-how-to-fix-it\/\">Your Security Certificate Has Expired: Here\u2019s How to Fix It (3 Steps)<\/a><\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-use-automation-to-simplify-your-certificate-management-tasks\">Use Automation to Simplify Your Certificate Management Tasks<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to make these tasks easier on yourself, consider using a certificate management automation tool. These tools are designed to make certificate management easier by giving you complete visibility of your network and the cryptographic assets that are spread throughout it.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Want to know what certificates you have and where they\u2019re located? Done.<\/li>\n\n\n\n<li>How about when they were issued or will expire? No trouble at all.<\/li>\n\n\n\n<li>What about knowing who is responsible for managing them? Easy as pie.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-central-palette-1-color has-central-palette-19-background-color has-text-color has-background has-link-color wp-elements-df71ca0f6981c387e221e229e1883794\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1.png\" alt=\"\" class=\"wp-image-17524 size-full\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1-300x151.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1-768x387.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-central-palette-7-color has-text-color has-link-color wp-elements-eec278cd911a009bda9c639e68f22e55\" id=\"h-digicert-trust-lifecycle-manager-simplifies-pki-digital-certificate-management\">DigiCert Trust Lifecycle Manager Simplifies PKI &amp; Digital Certificate Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DigiCert Trust Lifecycle Manager is an all-in-one PKI &amp; certificate lifecycle management (CLM) solution. Explore how this tool can help you keep a close eye on your PKI and avoid certificate outages.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-7-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/www.thesslstore.com\/solutions\/digicert-trust-lifecycle-manager.aspx\" style=\"color:#ffffff\">Learn More<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-3-regularly-scan-your-website-using-a-trusted-security-scanning-tool\">3. Regularly Scan Your Website Using a Trusted Security Scanning Tool<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Ideally, you should use a daily website scanner to identify vulnerabilities and other exploit opportunities that must be addressed. Using a website scanning tool is something that can help you find and identify vulnerabilities and malware that may exist on your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SiteLock is a monitoring tool that enhances the security of your website by automatically scanning , detecting, and blocking cyber threats.<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-central-palette-19-background-color has-background\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"801\" height=\"913\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/sitelock-smart-scan-example.png\" alt=\"SiteLock Smart Scan Results example screenshot\" class=\"wp-image-17548 size-full\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/sitelock-smart-scan-example.png 801w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/sitelock-smart-scan-example-263x300.png 263w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/sitelock-smart-scan-example-768x875.png 768w\" sizes=\"auto, (max-width: 801px) 100vw, 801px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<h2 class=\"wp-block-heading has-central-palette-7-color has-text-color has-link-color wp-elements-ef4275149bc0c74c62aaae3cb57d97bb\" id=\"h-don-t-like-malware-or-other-vulnerabilities-on-your-site\">Don&#8217;t Like Malware or Other Vulnerabilities on Your Site? <\/h2>\n\n\n\n<h2 class=\"wp-block-heading has-central-palette-1-color has-text-color has-link-color wp-elements-f18427d36dc5351b153dae340d3ea4e1\" id=\"h-we-don-t-either\">We Don&#8217;t, Either.<\/h2>\n\n\n\n<p class=\"has-central-palette-1-color has-text-color has-link-color wp-elements-5361b456d7560860e776bec6ca9f54e3 wp-block-paragraph\">Stay one step ahead of hackers by using SiteLock, a security solution that uses automation to scan and identify vulnerabilities to prevent future cyber attacks. Plans start as low as $9.37per month. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-7-background-color has-background wp-element-button\" href=\"https:\/\/www.thesslstore.com\/sitelock.aspx\">Shop Now<\/a><\/div>\n<\/div>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. Use a Web Application Firewall (WAF)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A web application firewall is often considered an industry go-to for helping organizations protect their web apps against malicious actors and cyber attacks. Its job is to help you filter and monitor HTTP\/HTTPS traffic to identify any unusual activity to or from your website\/web apps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A WAF can help you:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify traffic surges and drops,<\/li>\n\n\n\n<li>Watch where traffic is coming from, and<\/li>\n\n\n\n<li>Help you stop bad bot traffic in its tracks.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This can be useful in helping you identify and mitigate distributed denial of service (DDoS) attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But don\u2019t think using a WAF alone is enough; using this tool should be part of a much larger cybersecurity strategy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not sure whether your site or web apps need a WAF? Ask yourself a few quick questions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do you collect customer\u2019s personal data through your web app?<\/li>\n\n\n\n<li>Does your organization engage in ecommerce activities?<\/li>\n\n\n\n<li>Do you want greater visibility of your traffic?<\/li>\n\n\n\n<li>Do you want to be able to help identify and stop DDoS attacks?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the answer to any of these questions is \u201cyes,\u201d then you should be using a web application firewall.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">5. Monitor Your Website Logs (Automated Tools Can Help)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Website and web app monitoring is vital for every website\u2019s security. But we get it; monitoring logs for your digital properties is about as appealing as trimming your toenails. It\u2019s a task you don\u2019t really <em>want<\/em> to do, but, well, <em>somebody\u2019s got to do it<\/em>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Likewise, website logs provide a wealth of information relating to access requests, changes, errors, and security events and incidents. But the reality is that they generate an overwhelming amount of data that makes it virtually impossible to slog through manually. (Who has the time?)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you can imagine, there\u2019s an ungodly amount of \u201cnoise\u201d generated by these tools. Thankfully, there are automated log analysis tools that can help you collect and make sense of all types of data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Maintain Up-to-Date Website Security Tools and Plugins (Mainly For WordPress Site Admins)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Are you using WordPress for your site? If you\u2019re like the <a href=\"https:\/\/w3techs.com\/technologies\/details\/cm-wordpress\">43% of websites estimated by W3Techs<\/a>, then your answer is yes. If so, the following section\u2019s talking points will mainly apply to you.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">6. Ensure You\u2019re Using Your Host Client\u2019s Latest Software Version<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of which hosting management software you use (e.g., cPanel for shared hosting, Plesk, DirectAdmin), ensure that your server is running the latest version. If you\u2019re not, then you\u2019ll want to <a href=\"https:\/\/docs.cpanel.net\/knowledge-base\/general-systems-administration\/how-to-update-your-system\/\">upgrade to the latest version<\/a> of your interface.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Applying system patches and updates enables a software developer to fix any vulnerabilities or issues that would cause you problems now and\/or down the road. So, as with any software, ensure you keep your software version as current as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re a cPanel user, for example, you can find out which version of the software you\u2019re using by scrolling down to the bottom of your dashboard once logged in:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"703\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/where-to-find-certpanel-version-1024x703.png\" alt=\"How do I make my website secure graphic: A screenshot of CertPanel's version number, which displays at the bottom of its dashboard\" class=\"wp-image-17516\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/where-to-find-certpanel-version-1024x703.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/where-to-find-certpanel-version-300x206.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/where-to-find-certpanel-version-768x527.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/where-to-find-certpanel-version.png 1219w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: This is a screenshot we captured on a test site\u2019s cPanel dashboard, which showcases the cPanel software version number.<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">7. Install Plugins From Trusted (Reputable) Developers and Publishers<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re a WordPress site admin, you\u2019re likely well acquainted with WordPress plugins, themes, and other add-ons. Plugins can meet and simplify a wide assortment of needs and tasks, providing flexibility and customization opportunities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, the drawback is that installing these tools can increase your attack surface if they\u2019re not carefully managed and updated on the developer\u2019s side. (More on that in a moment.) Using poorly guarded and outdated website plugins creates vulnerabilities within your website\u2019s defenses that might not otherwise exist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s for these reasons (and others) that, if you decide to use third-party plugins and themes, you should only choose ones from reputable developers\/publishers who update their products regularly. Be sure to read the reviews and do your research via other sources as well before making a decision about which plugin(s) to use.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">8. Keep All of Your Themes and Plugins Up to Date<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/wpscan.com\/statistics\/\">WPScan reports<\/a> that 94% of the vulnerabilities in their database are plugins. Cross-site scripting (XSS) attackers have been known to use <a href=\"https:\/\/grahamcluley.com\/wordpress-plugin-vulnerability-puts-two-million-websites-at-risk\/\">vulnerable plugins to inject malicious code<\/a> into WordPress sites. Depending on the severity, this type of attack can <a href=\"https:\/\/portswigger.net\/daily-swig\/xss-vulnerability-in-popular-wordpress-plugin-seopress-could-enable-complete-site-takeover\">enable bad guys to take over your website completely<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For these reasons (and the ones we mentioned in the last two sections), you must keep your themes and plugins up to date. Doing so is both an industry best practice and a way to prevent threat actors from exploiting vulnerabilities on your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is really simple to do in WordPress. In the left-hand navigation bar on your WordPress dashboard, click on <strong>Plugins<\/strong> and it\u2019ll bring up a page listing all of your installed plugins (both active and deactivated). Here, you can manually update, activate, and deactivate your plugins, or enable auto-updates. <strong>&nbsp;NOTE:<\/strong> If a plugin has a vulnerability but no update yet, you won\u2019t see it here. This is another reason why it\u2019s crucial to do regular (daily) vulnerability scanning, too.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"559\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-plugin-updates-1024x559.png\" alt=\"How do I make my website secure graphic: A screenshot of redacted plugins that show some what up-to-date and out-of-date plugins look likein WordPress\" class=\"wp-image-17517\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-plugin-updates-1024x559.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-plugin-updates-300x164.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-plugin-updates-768x419.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-plugin-updates.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot from the WordPress admin dashboard that shows what it looks like when some plugins require updates and others don\u2019t.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For Themes, just look under the <strong>Updates<\/strong> option in the left-hand navigation bar and scroll down. If any themes need updating, it\u2019ll tell you there and will give you the option to update them in just two clicks.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"262\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/themes-up-to-date-1024x262.png\" alt=\"A screensht demonstrating the message you'll see when your Themes are curent in WordPress\" class=\"wp-image-17518\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/themes-up-to-date-1024x262.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/themes-up-to-date-300x77.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/themes-up-to-date-768x196.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/themes-up-to-date.png 1210w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot from the WordPress admin dashboard that shows what it looks like when your installed themes don\u2019t require any updates.<\/em><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Secure Access to Your Admin Dashboard and Other Sensitive Resources<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">9. Keep Tight Reins on Assigned Administrative Privileges and Access<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Alright, we\u2019re over halfway through the list of ways to answer the question: \u201chow do I make my website secure?\u201d Now, please repeat after me: <em>Not everyone who wants access needs access.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just because an employee wants admin access to your website, database, or other related resources should have it. Access should only be granted at the most minimal level. This is the idea behind the principle of least privilege (PoLP, or what\u2019s also known as the least privilege model).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, access to your website\u2019s Admin dashboard should be restricted to only those individuals who need it in their roles. Access privileges should be granted based on individual employees\u2019 job responsibilities and the tasks they\u2019re expected to complete. That\u2019s it. Just give them the absolute minimum permissions they need to do their jobs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that a marketing specialist whose job is to write and publish blog posts likely doesn\u2019t need the same level of access as a web dev who needs to mess around with the website\u2019s root directory. The same idea applies to access to your server and other sensitive resources. Take great care to ensure you only assign admin rights to those whose roles require them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick example of what it looks like when a user is assigned access privileges by role in a WordPress blog:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"440\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress-1024x440.png\" alt=\"How do I make my website secure graphic: A redacted list of WordPress users that shows only their role settings in WodPress\" class=\"wp-image-17519\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress-1024x440.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress-300x129.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress-768x330.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress-1536x660.png 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/user-roles-access-wordpress.png 1570w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of the Users menu in a WordPress admin dashboard.<\/em><\/figcaption><\/figure>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-advice has-icon\" data-type=\"advice\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 9V5a3 3 0 0 0-3-3l-4 9v11h11.28a2 2 0 0 0 2-1.7l1.38-9a2 2 0 0 0-2-2.3zM7 22H4a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h3\"><\/path><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Authentication and Authorization Go Hand-in-Hand<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">Check out our related article to learn more about <a href=\"https:\/\/www.thesslstore.com\/blog\/the-role-of-access-control-in-information-security\/\">The Role of Access Control in Information Security<\/a>.<\/p><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">10. Require Use of Secure, Unique Passwords (and a Password Manager)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">While it may seem basic, practicing strong password security is one of the most essential points you can drive home to your employees. This is because your employees\u2019 accounts (and everything they touch) are only as secure as the credentials they use to access them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If their passwords are recycled from other accounts, or if they\u2019re common passwords that can be found on virtually any breach list, then they\u2019re useless as far as your site\u2019s security is concerned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We saw an ugly example of this when the genetic testing company <a href=\"https:\/\/www.businessinsider.com\/23andme-data-breach-victims-responsibility-not-updating-passwords-2024-1\">23andMe pointed fingers at customers after a data breach<\/a>, saying they were reusing login credentials that were compromised in other third-party data breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s vital to set password requirements and check inputs against known databases of leaked\/breached passwords and common passwords. This way, if Sam on your Sales team tries to change his password to something that\u2019s already identified as compromised, you can make it so that he\u2019ll have to change his input to something else. (<strong>NOTE:<\/strong> Don\u2019t tell the user that the password is already in use \u2014 that gives away too much information. Rather, inform the user that their password choice is invalid and make them re-enter a new password. We\u2019ll speak more on that later.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, take the time to educate users on password security best practices for all accounts, including their website login credentials. This topic should include a conversation about securely storing passwords (i.e., saving them in a password management tool rather than <a href=\"https:\/\/www.thesslstore.com\/blog\/a-600000-reminder-to-not-save-your-passwords-on-post-it-notes\/\">storing them on Post-It notes<\/a>).<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-advice has-icon\" data-type=\"advice\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 9V5a3 3 0 0 0-3-3l-4 9v11h11.28a2 2 0 0 0 2-1.7l1.38-9a2 2 0 0 0-2-2.3zM7 22H4a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h3\"><\/path><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Go Beyond the Basics of Password Security<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">Check out the article <a href=\"https:\/\/www.thesslstore.com\/blog\/password-security-what-your-organization-needs-to-know\/\">Password Security: What Your Organization Needs to Know<\/a> to learn how to make passwords more secure.<\/p><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">11. Implement Zero-Trust Processes and Procedures<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The idea behind zero trust is that you never trust anything or anyone automatically and must always verify everything. (It\u2019s all about continuous authentication.) Virtually every company should aim for this approach in terms of securing their networks and overall IT infrastructure. But how does this apply to your website?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to securing administrative access to your website, lean on digital identity verification and authentication methods that go beyond traditional username-password combinations alone. So, what are some ways to help you verify someone\u2019s digital identity when trying to log in as an admin on your site?<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-advice has-icon\" data-type=\"advice\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 9V5a3 3 0 0 0-3-3l-4 9v11h11.28a2 2 0 0 0 2-1.7l1.38-9a2 2 0 0 0-2-2.3zM7 22H4a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h3\"><\/path><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Want to Learn More About Zero Trust?<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">Our article, <a href=\"https:\/\/www.thesslstore.com\/blog\/the-rise-of-zero-trust-threats-are-no-longer-perimeter-only-concerns\/\">The Rise of Zero Trust: Threats Are No Longer Perimeter-Only Concerns<\/a>, explores what zero trust is and how it\u2019s a necessary component of strong network cybersecurity.<\/p><\/div>\n\n\n\n<h5 class=\"wp-block-heading\">Implement Human-Verification Security Measures (MFA, CAPTCHA, etc.)<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">A good first step to cutting out bad bot traffic and brute force attackers is to implement multi-factor authentication (MFA), <a href=\"http:\/\/www.captcha.net\/\">captcha<\/a>\/<a href=\"https:\/\/www.google.com\/recaptcha\/about\/\">reCAPTCHA<\/a>, or an equivalent replacement such as <a href=\"https:\/\/www.cloudflare.com\/products\/turnstile\/\">Cloudflare Turnstile<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s quickly review what each of these tools do:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Multi-factor authentication<\/strong> \u2014 These tools add another layer of security to the authentication process by requiring users to prove their identities via more intricate methods. For example, you have to know a password and have a phone that receives a push notification from an authentication app such as Google Authenticator or Okta.<\/li>\n\n\n\n<li><strong>CAPTCHA or reCAPTCHA<\/strong> \u2014 These automated security mechanisms require you to do something to prove you\u2019re a real human and not a bot in order to authenticate. For example, you may have to pick out pictures, click a bot, answer a math question, sole a puzzle, or engage in some other way.<\/li>\n\n\n\n<li><strong>Cloudflare Turnstile<\/strong> \u2014 This <a href=\"https:\/\/developers.cloudflare.com\/turnstile\/\">alternative to CAPTCHA technologies<\/a> runs JavaScript challenges that detect human behaviors and involve secret keys and tokens in the background. This mechanism doesn\u2019t require users to solve any puzzles or engage in similar ways.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s what it looks like when you have a Cloudflare Turnstile or math CAPTCHA enabled on WordPress and someone tries to log in with the wrong password:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"932\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-security-captcha-turnstile-1024x932.jpg\" alt=\"Two examples of WordPress security mechanisms -- a Cloudflare turnstile on the left and a traditional mathematical CAPTCHA on the right\" class=\"wp-image-17520\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-security-captcha-turnstile-1024x932.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-security-captcha-turnstile-300x273.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-security-captcha-turnstile-768x699.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/wordpress-security-captcha-turnstile.jpg 1126w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: Side-by-side comparison screenshots that show how it looks when you use Cloudflare\u2019s turnstile or an alternative like a built-in math captcha.<\/em><\/figcaption><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Require Admin to Use Secure Connections<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">A little CYA is always helpful for businesses \u2014 particularly in our increasingly litigious world. As an organization, one of the things you can do is establish internal company policies covering set behaviors and standards that every employee is expected to abide by.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, when employees sign into their work device, you can have an acknowledgment screen that communicates set behaviors and standards that they must acknowledge to access the device. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In your documented procedures, be sure to specify that when accessing secure digital assets and systems (including your website\u2019s admin dash), authorized users must always use secure, encrypted connections. Here are two such ways to accomplish this:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Require in-office employees to connect via your company\u2019s secure ethernet network, or<\/li>\n\n\n\n<li>Require users working remotely to use a secure VPN connection based on PKI <a href=\"https:\/\/www.thesslstore.com\/products\/email-document-signing-certificates.aspx\">client authentication certificates<\/a>.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">You also can make this one of your policies that employees must read, acknowledge, and agree to adhere to as part of the hiring and employment process.<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-advice has-icon\" data-type=\"advice\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 9V5a3 3 0 0 0-3-3l-4 9v11h11.28a2 2 0 0 0 2-1.7l1.38-9a2 2 0 0 0-2-2.3zM7 22H4a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h3\"><\/path><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">We Can&#8217;t Cover Everything Regarding Client Authentication Here&#8230;<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">If you want to learn more about secure client authentication, check out our article <a href=\"https:\/\/www.thesslstore.com\/blog\/client-authentication-certificate-101-how-to-simplify-access-using-pki-authentication\/\">Client Authentication Certificate 101: How to Simplify Access Using PKI Authentication<\/a>.<\/p><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">12. Limit Invalid Login Attempts<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This is a biggie regarding knowing how to secure a website. If you don\u2019t want people trying to brute force their way in, a good security measure to prevent them from doing so is to set account lockout thresholds. For example, you can set it so that any user can attempt to enter their password no more than three times. After that, the account will be locked for a specified period (10 minutes, 3 hours, 24 hours, etc.).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"697\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/limit-login-attempts-wordpress-1024x697.png\" alt=\"A screenshot that shows the Limit Login Attempts Settings options that are available in WordPress\" class=\"wp-image-17521\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/limit-login-attempts-wordpress-1024x697.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/limit-login-attempts-wordpress-300x204.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/limit-login-attempts-wordpress-768x523.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/limit-login-attempts-wordpress.png 1212w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of the Limit Login Attempts setting in WordPress.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This approach helps prevent attackers from unleashing scripts with guessed username-password combinations from brute forcing their way into your site. This is also beneficial for credential stuffing and other similar attacks for the same reason.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">13. Use Allowlists and Blocklists to Restrict Access to Your Admin Controls<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.blackfog.com\/cybersecurity-101\/allowlist\/\">Allowlists<\/a> (formerly called <a href=\"https:\/\/www.blackfog.com\/cybersecurity-101\/whitelist-allowlist\/\">whitelists<\/a>) and <a href=\"https:\/\/www.imperva.com\/learn\/application-security\/ip-blacklist\/\">blocklists<\/a> (formerly blacklists) are tools that give website admins granular control of access to their digital properties. They can be used in multiple scenarios, including whitelists of websites and email accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For websites, allowlists typically rely on user\u2019s IP addresses. For example, you can use an allowlist to restrict access to specific parts of your website, such as the login page, to <a href=\"https:\/\/wordpress.org\/support\/topic\/login-lockdown-ip-whitelist-locks-everyone-except-admin\/\">only one or more specified users<\/a> by including their IP address on an allowlist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Likewise, you can use a blocklist to preclude specific users from accessing parts of your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine a scenario where you\u2019ve bought a beautiful house in a restricted, gated community.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If you want only certain people to have access to the house, you can provide the community\u2019s security team with a list of authorized users (allowlist) to permit entry.<\/li>\n\n\n\n<li>If there\u2019s someone you wouldn\u2019t want to access your new digs, you can provide that person\u2019s info to the guards at the gate. That individual would be barred from accessing the property (blocklist).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When you use an allowlist, you can set default access settings to deny, thereby precluding anyone whose IP address isn\u2019t explicitly noted. But how can you use this to permit connections from only specified IP addresses?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Install plugins that enable allowlist\/blocklist capabilities (for WordPress users).<\/li>\n\n\n\n<li>Update your site\u2019s <em>.htaccess<\/em> file to list specific IP addresses. (NOTE: This should only be done by experienced site admins.)<\/li>\n\n\n\n<li>Set firewall rules to enforce your allowlist.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">14. Use Salting to Increase the Security of Stored Password Hash Values<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If your website allows users to log in by creating usernames and passwords, this section is for you. Password salting is an important practice in database security for securing stored password-related details. You never want to store plaintext passwords in your database because they\u2019ll be vulnerable to compromise via hash table and <a href=\"https:\/\/www.thesslstore.com\/blog\/rainbow-tables-a-path-to-password-gold-for-cybercriminals\/\">rainbow table attacks<\/a>. Instead, what you should store is the salted password hash values.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This process involves taking an input (i.e., a plaintext password) and adding a salt (a random, unique string of data) to it before applying a cryptographic hash function. This generates a unique password hash value that you can use instead of a plaintext password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s imagine this using the password <em>Password123<\/em> and the salt value <em>+Oa8kFpYobjX<\/em>:&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Password123<\/strong> + <em><strong>+Oa8kFpYobjX<\/strong><\/em><em> = <\/em><em><strong>e72fd887c202a4367b8a96d42d1a1e10<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Even if two users use the same password, when a unique salt value is added to it before applying the hash function, the resulting hash value for each user\u2019s password will be completely different.<\/em><\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-advice has-icon\" data-type=\"advice\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 9V5a3 3 0 0 0-3-3l-4 9v11h11.28a2 2 0 0 0 2-1.7l1.38-9a2 2 0 0 0-2-2.3zM7 22H4a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h3\"><\/path><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Want to Learn More About Salting?<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">Check out our related article <a href=\"https:\/\/www.thesslstore.com\/blog\/password-salting-a-savory-way-to-secure-your-secrets\/\">Password Salting: A Savory Way to Secure Your Secrets<\/a> to explore more in depth why salting is essential to password security.<\/p><\/div>\n\n\n\n<h5 class=\"wp-block-heading\">Don\u2019t Give Away Too Much Information<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Securing your account-related information is akin to playing poker: you need to keep your cards close to the vest and not have any tells that alert other players to your plans. Likewise, when it comes to account security, you don\u2019t want to give away too much information in error response messages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a user tries to log in to a website using the wrong password, for example, it\u2019s not uncommon to see a message kick back, stating that they\u2019ve entered the wrong password. While on the surface this seems like a standard response, this approach can decrease your website\u2019s security because it provides cybercriminals with useful information they can use for credential stuffing attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, if you specify that the <em>password<\/em> specifically was incorrect, then it lets them know that the username is correct. They can then use that username and try different password combinations with it until they hit gold.&nbsp; &nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Implement Database Hardening Techniques<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">15. Secure Access (Physical and Remote) to Your Database<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Your website and database are separate but intricately related digital assets that must be secured. Websites use databases as backend storage and management systems for all sorts of content (think website copy, graphics, video media, etc.). They rely on databases to store data that they can retrieve and display to users without having everything hardcoded directly on the site.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strong database security enables authorized access to data while still maintaining the confidentiality, integrity, and availability (CIA) of the database itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are physical security measures you can use \u2014 keeping your database server(s) locked up, implementing secure access using ID cards, installing cameras, etc. But what if your database isn\u2019t on prem? Then, at the very least, use separate databases for internal and external uses. Require authorized users to connect to your database using client authentication-based secure connections via a VPN. And remember: only give access permissions to people whose roles require it!&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">16. Secure Your Web Apps and Forms Against Common Database Attacks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Remember how we mentioned that bad guys are always looking for the easiest point of entry? One such method is searching for SQL injection flaws in your site\u2019s web apps that they can exploit. Some ways to make your database more secure against SQL attack techniques include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using parameterized database queries<\/li>\n\n\n\n<li>Sanitizing web app inputs<\/li>\n\n\n\n<li>Keeping your backend components (libraries, frameworks, database software, etc.) current<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Check out our other resource to learn more about <a href=\"https:\/\/www.thesslstore.com\/blog\/sql-injection-attack-what-it-is-how-to-protect-your-business\/\">how to secure your web apps and database(s) against SQL injections<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">17. Use Custom Ports to Help Reduce Log Clutter and Limit Automated Attacks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s no secret that cybercriminals love to target \u201clow-hanging fruit\u201d \u2014 i.e., websites and databases with outdated, crappy or non-existent cybersecurity mechanisms in place. Why? Because they\u2019re easy pickings. It\u2019s the equivalent of a shark targeting an injured seal rather than a healthy, able-bodied seal that can fight back.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using default port numbers represents one of these easy-picking opportunities for bad guys. Ports allow information to flow between a website and the browser connecting to it. For example, a port commonly used for secure shell (SSH) protocol is port 22. For example, <a href=\"https:\/\/www.ionos.com\/help\/server-cloud-infrastructure\/getting-started\/important-security-information-for-your-server\/changing-the-default-ssh-port\/\">IONOS<\/a> recommends changing it to a port between the \u201c1024 and 65536\u201d range. According to the <a href=\"https:\/\/www.ietf.org\/archive\/id\/draft-cotton-tsvwg-iana-ports-00.html\">IANA Allocation Guidelines for TCP and UDP Port Numbers<\/a>, \u201cThe Well Known Ports Are Assigned by IANA and over the range 0-1023,\u201d so it\u2019s best to avoid using them for deployments or product releases.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"668\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/iana-port-numbers-1024x668.png\" alt=\"A snippet from IANA's assigned service names and port numbers, which shows port 22 as the default option for SSH\" class=\"wp-image-17522\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/iana-port-numbers-1024x668.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/iana-port-numbers-300x196.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/iana-port-numbers-768x501.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/iana-port-numbers.png 1356w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A list showing that port 22 is commonly associated with SSH connections. The screenshot was captured on IANA.org.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Simply put, changing from default to custom port numbers is a way to create a layer of security through obscurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s important to note, however, that port scanning isn\u2019t technically a threat on its own; it\u2019s a method of reconnaissance that provides attackers with information they can use against you. While changing port numbers doesn\u2019t stop bad guys who are determined to figure out what ports you\u2019re using, it eliminates the guys, gals, and bots who mass-scan default ports. So, why not close that window and not give attackers a potential \u201cin\u201d to your site or web services?&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To figure out what port numbers to use, check out the <a href=\"https:\/\/www.iana.org\/assignments\/service-names-port-numbers\/service-names-port-numbers.xhtml\">Internet Assigned Numbers Authority\u2019s (IANA\u2019s) Service Name and Transport Protocol Port Number Registry<\/a> to see which numbers aren\u2019t used for other services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Takeaways on How to Make Your Website Secure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It used to be that prospective customers could look up your ads and listings in the Yellow Pages or follow the recommendations of family members and friends. While word-of-mouth still plays a critical role, your website often provides your company\u2019s first impression to customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why having a website that\u2019s informative, useful, performs well, and is secure matters. No one (myself included) likes receiving notices that the companies whose websites or services they\u2019ve been using have been compromised. If you take steps now to make your website, web apps, and other digital assets as secure as possible now, you can avoid the pitfalls and security issues that lead to breaches down the road.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We hope you\u2019ve found this article informative and useful. Have other insights and recommendations for how to secure a website? Share them in the comments below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Knowing how to make your website secure can be the difference between sharing positive news with website users and having to inform them that their data has been breached. &nbsp;&#8230;<\/p>\n","protected":false},"author":17,"featured_media":17564,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[13266],"class_list":["post-17510","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-website-security","post-with-tags"],"views":12971,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/how-do-i-make-my-website-secure-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17510","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=17510"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17510\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/17564"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=17510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=17510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=17510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}