Women In Security Magazine Issue 3

Page 74

KAREN STEPHENS Karen is CEO and co-founder of BCyber, an agile innovative group who works with SMEs to protect and grow their business by addressing their cybersecurity and governance risk gaps by demystifying the technical.

Ten top tips to secure your website In May this year Domain.com.au advised that a cyber-

3. Implement least-privilege access. Limit people’s

attack had resulted in an unauthorised third party

access to the lowest level they need to do their

gaining access to users’ personal information and

job. Not everyone needs full admin access. And

deposit details. Yet, when you mention cybersecurity

limit external parties’ access and timeframes.

most people automatically think of antivirus, the

There is no need to have umpteen administrators.

Deep and Dark Web, Ransomware as a Service, and

People with unnecessary access can result in

possibly the need for a cyber awareness program or

unwanted website security incidents and when

endpoint protection. Few people, if any, have website

a staff member leaves, check that their website

security top of mind.

accesses are removed.

Website attack is very popular with the

4. Deploy a secure sockets layer (SSL) certificate.

cybercriminals. Some estimates put attack

Buy an SSL certificate. With that little lock

numbers as high as 50,000 websites per day. The

showing in the top left corner of your website

cybercriminals tend to adopt a “spray and pray”

you boost your SEO rankings and ensure any

approach, using programs that detect websites with

data your visitors send to your site is using an

accessible vulnerabilities, only a small minority target

encrypted channel, so cybercriminals cannot

specific sites. Cybercriminals do not necessarily

see it while it’s in transit. You may even wish

want your data. They may want to use your server as

to consider upgrading to TLS (Transport Layer

an email relay for spam or set up a temporary web

Security) a more recent version of SSL.

server for nefarious purposes, plant malware, redirect traffic to another site to name but a few objectives.

5. Update early, update often, update everything. Websites use tools to run effectively: content

You can implement a few small, but powerful

management systems, plugins, WordPress, Java

measures to protect your website.

scripts and the like. Updates not only fix “bugs

1. Review your site security. Have a formalised scanning and review program covering access levels, patching, updating protocols and the like. 2. Take ownership of security. Do not leave the security of the site in the hands of the wrong people, for example marketing or web designers. They may be great at what they do, but would you let your interior decorator recommend, implement, and monitor your back-to-base alarm?

and glitches”, but they also often provide security enhancements. Updating immediately means you are closing a vulnerability and remaining one step ahead of the cybercriminals. 6. Have a website backup strategy. A regular backup program will help you recover more quickly from a site hack (or human error or an update problem). Ideally you should have the backup stored on a server other than the one hosting your website. You do not want to lose your website only to find your backup has been infected as well, because that would mean a full site rebuild.

74

WOMEN IN SECURITY MAGAZINE


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

Surviving a crisis - a view from the trenches

6min
pages 120-123

Are you doing enough to protect your organisation’s IT security?

2min
pages 118-119

Take me to cuba

6min
pages 111-113

Whose afraid of Zero Day

6min
pages 114-117

How to embrace the coming technology revolution

4min
pages 108-110

Linking data privacy to security

3min
pages 106-107

transforms cybersecurity

8min
pages 102-105

Back to basics

6min
pages 99-101

AusCERT plenary panel

6min
pages 96-98

Hackers are not who you think they are

2min
pages 91-95

Celebrating information security excellence in 2021

9min
pages 86-89

Factors threatening effective partnerships in crisis situations

2min
page 90

AWSN returning to in-person events around Australia

3min
pages 84-85

Building relationships in the security and risk suite and why it matters

4min
pages 80-81

fighting for women in STEM

8min
pages 76-79

Ten top tips to secure your website

3min
pages 74-75

How SiteMinder’s product and technology teams stayed motivated and innovative during the pandemic, while servicing the traditional hotel industry

5min
pages 72-73

Top 5 digital parenting tips for parents with teens

2min
pages 64-65

Lisa Jiggetts

5min
pages 54-57

Could inclusivity expand the cybersecurity talent pool in australia?

3min
pages 60-61

A Tuesday in the life of a Regional Technical Support Manager

5min
pages 62-63

How to make a midcareer move into cybersecurity

3min
pages 58-59

Gergana Winzer

7min
pages 46-49

Noushin Shabab

4min
pages 52-53

Christina Keing

4min
pages 50-51

Dr Lesley Seebeck

6min
pages 40-41

Anna Liebel

4min
pages 32-33

Jo Stewart-Rattray

5min
pages 34-36

Daniella Traino

6min
pages 30-31

Giulia Traverso

3min
page 37

Shelly Mills

5min
pages 38-39

How to create a culture of belonging and why it matters

8min
pages 18-21

Beware of ransomware

2min
pages 16-17

more diverse workforces

4min
pages 12-15
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.