11
Website security hardening
The need for improved security measures has dramatically increased over the last couple of years as there have been high-profile security breaches and consumer demand for greater security and privacy. This has led to the need for A/E/C firms to take a more proactive and deliberate approach to security. This includes converting your website to HTTPS, as well as implementing security hardening measures.
Hypertext Transport Protocol Security (HTTPS) websites use an SSL (Secure Sockets Layer) certificate to protect a site connection through authentication and encryption. While once only found on websites that involved the exchange of sensitive user data (such as banks, e-commerce sites, insurance, etc.), HTTPS is becoming more popular across the board.
Unsurprisingly, Google is leading the charge for making the entire web more secure, even launching an HTTPS everywhere campaign. As part of their ongoing push for improving user experience they have also started including HTTPS as a ranking signal, and now give indexing priority to secure pages over unsecured pages.
To protect your website and ensure optimal performance, it’s now critical to implement a number of website security hardening measures. This starts with hosting your website on a professional-grade server, in order to provide a safer, faster, more reliable environment for your website (as opposed to an inexpensive grid platform that shares the space with many other (likely unsecure) websites.
Nightly, full-site, incremental backups of your website files and database are also critical to ensure that you can fully restore your website at any time and all updates from the previous day will be safe and secure.
Lastly, a robust Website Application Firewall (WAF) and Intrusion Prevention System (IPS) should be implemented to protect your website by intercepting and inspecting all incoming HTTP/HTTPS requests to your website and stripping them of any malicious requests before they arrive safely at the server.
You should also leverage a real-time detection and security monitoring platform that includes automatic virtual patching and hardening engines that offer real-time mitigation of threats. In other words, a simple free plugin is no longer sufficient to protect and monitor your website.