Don’t know if your customers’ data is secure? Are you panicking that your website could be defaced, leading to reputation damage? We all worry about the risks that we face as website ‘owners’. That said, most attacks and incidents are well known and can be easily protected against.
Perhaps you are new to the field of website or application development, or perhaps your new role has the nondescript ‘manage website’ bullet in the job description. Before you go screaming to the InfoSec team or looking for a new job, I wanted to provide a quick way to assess the situation so you know
Much like any other risk management exercise, we want to weigh our risks versus needed website security. The first question to ask is “Does my website store any confidential information?” Here are some examples of confidential information:
When I say store, I mean: is the information saved on your website? Many plugins and services will store data on your web server. Some examples are WPForms or Gravity Forms for WordPress or Webform for Drupal.
If the answer is yes, we will want to be extra diligent with the next steps. Data privacy is becoming much more important and many states and countries now have laws requiring companies to protect their customers’ data. For a fuller picture of the data privacy landscape, read our blog post on the Data Privacy Landscape or check out our webinar on Data Privacy.
If you answer “no” to any of the below questions, you should take immediate action:
If you answer “no” to any of the questions below, but you do not house any customer data, add these tasks to your backlog and start roadmapping now. If you answer “no” to any of the below and you are housing customer data, take immediate action.
To sum it up, if you aren’t doing everything under the “Low Hanging Fruit” category, get that going tomorrow! We’ve done our best to provide actions you can take right away. If none of them fit, feel free to Contact Us or talk to your tech team.
If you are housing customer data and you are not doing everything under “More Advanced”, start making a plan now. You may also want to consider speaking with your dev team about a secure SDLC.
Now go forth website owner, and own Security as well!