Security

Your site’s security is our priority….

How do we ensure security and why is it important?

Hackers scour the internet to exploit known website security issues known in software. Lack of knowledge and skill regarding the web security could give hackers the opportunity to compromise a website.

Effective website security requires design effort across the whole of the website: in your web application, the configuration of the web server, your policies for creating and renewing passwords, and the client-side code.

Security breaches not only mess up the website but runs the risk of user data being stolen and allowing the server to be compromised and used for illegal purposes.

How do we secure our websites:

01
We Keep Software & plugins up to Date

The code & scripts running on our websites are thoroughly screened and vetted before writing them.

We perform routine checks to ensure all software is up-to-date and check whether security patches are complete.

We update plugins on a timely manner, to mitigate risk from known software vulnerabilities.

02
By adding SSL certifcates

We choose the SSL certificate that is best for your site.

This is very important because without this the site is now labeled as insecure.

03
By using the best security tools

These include protection against DDOS Attacks, Malware, Spam, other Hack Tools, Conditional redirects and E-commerce Malware.

We have the right firewalls in place.

We have the whole data backed up on a regular basis and this does not come with an extra charge.

04
Configuring our server by using the best industry practices

The code & scripts running on our websites are thoroughly screened and vetted before writing them.

Check our hosting page for more information.

FAQ

What is a DDOS Attack?

DDOS stands for Distributed denial-of-service. These are cyber-attacks that target servers,  websites, online services and networks, by flooding them with so much internet traffic that they are rendered inoperable. The idea is to overwhelm the server with more traffic than it can accommodate. This traffic is generated form different compromised devices.

Any web server has a limit to the number of requests it can accommodate simultaneously. Similarly the medium that connects the server and the internet also has a definable bandwidth. Hence, when the  number of requests exceed the capacity of this infrastructure, it is bound to fail by either being unresponsive to the users or the service being slower than normal.

What is the purpose of these attacks?

Just like any other cyber attack, the purpose behind DDOS could be anything depending on the mindset and motivation of the attackers.

The attack could be by bored teenagers doing it for an adrenaline rush; it could be with an intent of extortion; it could by businesses in order to cut the competition or simply because someone decides they do not like the content on your site and do not agree with your ideology.

How to protect your site against DDOS attacks?

  1. By using anti-DDOS services: These help is identifying spikes on the traffic and DDOS attacks.
  2. By analysing and monitoring the abnormalities in traffic. Keeping an eye for abnormal traffic surges, suspicious IP’s and locations.
  3. Configuring Firewalls and routers: Keeping the routers and firewalls up to date with the latest security tools is critical. These can be configured to reject suspicious traffic.

We put in place on all our servers DDOS protection, through traffic filtering systems and firewalls, again another way we relieve the stress for you.

 

What is Malware?

Malware, as the name suggests is malicious software; developed with an intent of doing malicious activities on a website. These take advantage of the poor security and known vulnerabilities of software.

The purpose of malware injections could vary from the intent of gaining bragging rights to stealing information or money. In addition to these threats, your site could end up being removed from Google’s search results.

Some common types of website malware are:

SEO SPAM: This involves injecting SEO keywords, spam links, ads on a competitors site, with the purpose of bringing down the SEO ranking of the compromised website, and thus of increasing their own website’s rank.

Ransomware attack: In this, the hackers encrypt your website files, rendering them inaccessible, and then demand payment to restore access. Unfortunately, there’s no assurance that your files will be recovered, and even if they are, they’ll most likely be irreparably damaged. Regular site backups can aid in the recovery of files in the event of a ransomware attack.

Viruses : A computer virus is a harmful code or programme that disrupts the operation of a computer or website. It can quickly spread to other computers, including those of your website’s visitors, once it has been executed.
Viruses can affect you in a variety of ways, including monitoring your keystrokes, stealing sensitive data, and damaging computer files.

Phishing: These attacks are done by tricking users to give out personal or sensitive information. This happens when an attacker is disguised to be someone else to gain information. They successfully replicate webpages like login, landing pages or webmail portals and thus extract information.

Conditional redirects: This involves adding malicious code to a website that redirects certain users to another website. This is done with a purpose to redirect a user to a malicious domain that could be setup for phising.

How to protect yourself from Malware?

To defend a site from these distinct types of malware, website owners should make it a practice to adopt proactive cybersecurity solutions, such as daily malware scanning and a web application firewall (WAF) to protect the site.

What is a Web Application Firewall?

Web Application Firewall (WAF), filters and monitors HTTP traffic between a web application and the Internet. It helps by protecting it against vulnerabilities in the application by filtering out malicious traffic. It usually defends online applications against threats including cross-site forgery, cross-site scripting (XSS), file inclusion, and SQL injection.

It  acts as a barrier between a web application and the Internet when it is deployed in between them.

It is a type of reverse-proxy that protects the server from exposure by having clients pass through the it before reaching the server.

What is an SSL?

A Secure Sockets Layer certificate (SSL certificate) encrypts data sent from your website to a server, such as emails and credit card numbers. This is a simple website security technique, but it’s so critical that most browsers and search engines now identify sites without SSL as “insecure,” making users skeptical to use your site.It’s used to verify the identity of a server sending the request, which helps avoid on-path attacks, domain spoofing, and other techniques of impersonating a website and deceiving users.

What are the different types of SSL certificates?

There are mainly five types of SSL certificates, namely:

  1. Extended Validation Certificates (EV SSL) : Extended Validation involves a thorough investigation of the organization’s history. The CA (certificate authority) will verify that the organisation exists and is lawfully registered as a business, that the address listed is accurate, and so on.
    This is the most secure type of SSL certificate when it comes to validation level. These take the take the longest to validate and cost the most. Thus are usually employed by high-profile websites that require a lot of personal information from their visitors or routinely collect online payments.
  2. Organisation Validated Certificates (OV SSL): Organization Validation is a manual vetting process in which the CA contacts the organisation obtaining the SSL certificate and conducts additional research.
    Organization Validation SSL certificates include the name and address of the organisation, making them more trustworthy for users than Domain Validation certificates.
  3. Domain Validated Certificates (DV SSL) : Domain Validated SSL certificates show that a domain is registered and that the given URL is being managed by the site’s administrator.  The Certificate Authority can validate this by email, DNS, or HTTP. This is the cheapest level of validation.
    It’s a good option for blogs, portfolio sites, or small businesses that just want to get HTTPS up and running quickly, especially if they don’t sell items online.
  4.  Single-name and wildcard SSL Certificates: Single-name certificates can be a great choice if you need to add a certificate to single subdomain/hostname. Wildcard SSL allows you to secure an unlimited number of subdomains for a single domain.
  5. Multi-Domain SSL Certificate (MDC) : By utilising the SAN extension, multi-domain SSL certificates enable security for multiple domains with just one certificate.  You can combine multiple hostnames with multi-domain SSL certificates, regardless of whether they are from the same domain or not.

Again to remove the stress and hassle so that you don’t need to worry, all of our sites are protected through Let’s Encrypt using DV SSL.

Which type of email should I choose - free or paid?

The type of email you are going to use becomes a very important choice when it comes to your business and its reputation. An email address that ends in a customised domain name can be free or paid.  So if you can have a free email address with your customised domain, why pay?

Nothing is truly free. We provide a choice between free and paid. Though the free email accounts have no support and no potential for backing up emails, they also lack the security of the paid solution.

While an email address which is a @gmail.com, @outlook.com, @yahoo.com, etc. is a free email address, these email addresses do have security because of who provides them. They lack the professional edge of a customised domain.

While with platforms like gmail.com you don’t pay a penny for email which is great, but google gets to study your behaviour through your emails and target you for their ads. While the free storage space is usually enough for individual; for business it may not be the best choice.

Some other cons of free email are:

  1. The security is not as good as you get with paid email hosting provider, depending on who the provider is.
  2. It fails to have the impact a professional email address will have on your customers, that builds brand awareness and trust.
  3. You always run a risk of losing all your contacts and mails in case of security mishap. With a paid email you can always have the necessary backups in place and restore them anytime.