How secure is YOUR website?

secure login

Last night I observed how my e-mail inbox filled up with over 70 messages generated by the firewall component installed on a client’s content management system (CMS). Each one informed me that a single IP address was attempting to log into the administrator panel in the back end and that the username/password combination had been incorrectly entered. For an occasional e-mail to arrive would usually signify an unsuccessful client login and these can normally be safely ignored, but for well over 70 e-mails to arrive in the space of one minute, there had to be a more orchestrated attempt at a brute force attack in progress.

Fortunately, we had taken the precaution of protecting the CMS with a firewall component, which did its job admirably in preventing any hacker attack, saving hours of potential downtime as the client and we went through the process of restoring from a backup. Unscheduled downtime due to attacks can mean hundreds, if not thousands, in lost revenue and sales due to e-commerce systems being affected and this is one of several reasons why it pays not to skimp on website security. Even the most meagre of websites that might be a matter of a simple WordPress blog can be hardened to attack by installing a decent third-party security component. Needless to say, this is a perfect opportunity to re-evaluate your security policy and ensure that you have adequate protection in place and a backup system as well.

Prevention is clearly better than cure and there are numerous ways to stop an attack from happening in the first place. Securing your own website software is foremost; if you are using a CMS, ensure it is running the current release version and that any add-ins are compatible, trusted and up-to-date. It is possible nowadays to take steps to prevent attack from blocks of IP addresses to effectively deny access to the website to certain countries. If you are not particularly concerned about your website being viewable by people in countries from which the vast majority of hacker attacks emanate, it may be well worth investing time in building a blacklist of countries you’d like to block and effect that at the lowest possible level.

Password security is another obvious vulnerability and it always makes good sense to use a strong password. Dealing with IT and Internet security can often represent another chore to be brushed aside by many people struggling with the demands of running a small or medium enterprise, but you can think of it as a sort of insurance against being caught unaware and placed in the awkward position of having to rebuild from scratch. If you find yourself questioning your IT and Internet security, that’s a good thing. If you find yourself questioning how to deal with it because you don’t know or have the time, then contact us for assistance. It may be the best decision you make this year.

Share this post
Posted in

Categories

Archives