WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers

5 Insights On The Website Security Threat Landscape

Jack Riewe 11.15.2016

At WP Engine, we’ve got your back when it comes to website security. While we’ve covered website security extensively, it remains a hot topic that can’t be talked about enough in the news, tech, and many other industries.

In fact, we have several blog posts and white papers on the importance of SSL security, 10 WordPress security best practices, and 15 tips to harden the security of your WordPress site that offer advice on how to make your WordPress site nearly impenetrable.

However, there’s always more to elaborate on. In a recent webinar, WP Engine invited Tony Perez, CEO of Sucuri to lead a webinar to explore the topic even further.

Here’s what we learned from this insightful session:

Human errors are hacker’s favorite target

Hackers will take advantage of anything they can. Don’t give them a reason to attack your site by having poor management of site configuration, improper configuration tools, lack of active administration or all around bad habits, like weak passwords.

5 Insights On The Website Security Threat Landscape

“This makes their tactics highly effective. Because of these weaknesses, websites get compromised—in mass—through automation. There are targeted attacks, of course. But for the masses, I’d say that approximately 95 percent of the attacks we see every day with website owners are ‘Targets of Opportunity’ or targeted attacks,” said Perez.

Perez also mentioned security is one of the last priorities that website owners neglect to address.

5 Insights On The Website Security Threat Landscape

There are many different kinds of attacks

Types of attacks range from external to internal to reflective.

The types of external attacks hackers use are a “shotgun-like approach,” where they fire a lot of shots and see what works. For example, a “Brute-Force Attack,” is where an attacker sends a barrage of requests to the username and password fields to find the right combination.

screen-shot-2016-11-15-at-1-37-24-pm

Internal attacks can include a hosting misconfiguration and cross-site contamination.

Lastly, reflective attacks are when an attacker compromises your site by not penetrating it. This happens when you trust your site too much and encompass malvertising and third-party integration.

website-security-threats

The order of precedence in a security attack is exploitation of software vulnerabilities, brute-force attempts, users, security misconfiguration, and cross-site contamination.

website-security-threats

Once hackers have entered your site, they have the world at their fingertips

“A lot of the time, it’s not what they will do with your audience as it is what they will do with your resources,” said Perez. “Your website is another connected device that can be added to a larger botnet that can be used to disseminate some traffic or otherwise used to abuse or confuse online visitors.”

website-security-actions

These resources include cross-site examination, your site’s SEO, malware distribution, search engine poisoning, phishing, sending spam email, defacement of the site, and so on.

Search engine poisoning is making use of your online authority and pushing their agenda. Say someone searches your site and clicks on a link, but instead of your site, they will be directed somewhere else. This is the fastest growing number of attacks in cyber security today.

Backdoors are also another issue to worry about. Perez said over 60 percent of infected sites we work on have some backdoor embedded within the system. For those who don’t know, backdoors ensure the attacker is able to still have access to the site, even after the attack has been fixed.

There is no single best solution to cyber security

Perez introduces the idea that he uses at Sucuri, which is “Defense in Depth.”

“It’s the idea that we deploy a series of overlapping, complementary defensive controls across our stack. This is all designed to work in unison with one another,” said Perez. “One is not better than the other. The endpoint security is not better than cloud security. They have to work together.”

Perez advised that to employ an effective “Defense in Depth” strategy, you must focus on the things you can control. You must stay ahead of the unknowns. Security is an ever-going process and not in a static state.

He emphasized that the people, process, and technology circle must all work together to make your site secure. For example, installing a plugin or tool and then forgetting to configure it is a huge security issue. Contrary to the principle of this circle is trying to find one golden thing to rely on to defend your site.

screen-shot-2016-11-15-at-10-22-33-am

WP Engine’s commitment to security

As Perez concluded his presentation, WP Engine Security Engineer, Justin Dailey, took the mic to discuss how we at WP Engine combat malicious attacks.

WordPress core upgrades, disk write protection, active intrusion detection, managed patching and updates, and malware remediation are some of the security features on WP Engine’s platform.

“At WP Engine, security is a shared responsibility between us and our customers. We do as much as we can to take some of the burden off of our customers,” said Dailey.

Conclusion

One of the biggest things to take away from the webinar is that website security is ever-changing. It must be managed by multiple security tools. Hackers will take advantage of any weakness your site has. Yet, there are many simple ways to further harden the security of your site.

You want to trust your hosting provider when it comes to website security. At WP Engine, we promote an open dialogue as well as our many security features.

Check out the entire webinar that includes slides and a Q&A.

More WordPress news from WP Engine

5 Entrepreneurial Tips From Web Summit 2016Live Interview: Shawn Hesketh Spreads WordPress Knowledge

Comments

  1. Val Vesa says

    November 17, 2016 at 1:57 pm

    Did you guys also record a video of the webinar by chance?

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2025 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.