{"id":11718,"date":"2022-08-18T12:53:21","date_gmt":"2022-08-18T12:53:21","guid":{"rendered":"https:\/\/nieuw.wpprovider.nl\/is-security-even-a-part-of-your-web-design\/"},"modified":"2022-08-18T12:53:21","modified_gmt":"2022-08-18T12:53:21","slug":"is-security-even-a-part-of-your-web-design","status":"publish","type":"post","link":"https:\/\/nieuw.wpprovider.nl\/en\/is-security-even-a-part-of-your-web-design\/","title":{"rendered":"Is security even a part of your web design?"},"content":{"rendered":"<p class=\"p1\"><b>SMEs are also targeted by cybercriminals.<\/b><\/p>\n<p class=\"p3\">Over the past two years, there have been quite a few reports of companies whose websites were &#8220;taken down&#8221; by cybercriminals.<br \/>\nOnly after paying hefty sums of money was the company in question accessible to its customers again.<br \/>\nRecently a chain of dental practices and in the spring Artis in Amsterdam.<br \/>\nIn both cases, the impact was enormous.<br \/>\nBusiness is completely disrupted at such times.    <\/p>\n<p class=\"p1\"><b>&#8220;My company is too small to make anything&#8221;<\/b><\/p>\n<p class=\"p3\">Many business owners will think this and, as a result, things can actually go wrong.<br \/>\nCybercriminals look for the path of least resistance and only then look for possible gains.<br \/>\nEven if the ransom in the case of ransomeware is not so bad and you are back on the air quickly, you still have to wonder what will be done with the customer information stored in the website&#8217;s database.  <\/p>\n<p class=\"p1\"><b>Security is more important than a low monthly fee for hosting<\/b><\/p>\n<p class=\"p3\">SME entrepreneurs often make a reasonable investment in developing a good Web site.<br \/>\nOnly too often they choose cheap hosting to keep the recurring monthly costs low.<br \/>\nA good example of how cheap turns out to be expensive.  <\/p>\n<p class=\"p1\"><b>What are the key security issues in hosting?<\/b><\/p>\n<p class=\"p3\">When it comes to (WordPress) website security, there are several things that need to be properly taken care of:<\/p>\n<ul class=\"ul1\">\n<li class=\"li3\">Secure updates to templates, plug-ins and WordPress core itself;<\/li>\n<li class=\"li3\">Regular server-level malware scans;<\/li>\n<li class=\"li3\">A software- and hardware-based firewall;<\/li>\n<li class=\"li3\">Additional DDoS protection;<\/li>\n<li class=\"li3\">Use of the latest PHP version (HardenedPHP);<\/li>\n<li class=\"li3\">Regular external backups.<\/li>\n<\/ul>\n<p class=\"p3\">At the bottom of this blog you can read what this point by point means<\/p>\n<p class=\"p1\"><b>But surely every hosting provider offers this?<\/b><\/p>\n<p class=\"p3\">If only that were true.<br \/>\nYou would think it would go without saying that all hosting companies offer this by default.<br \/>\nUnfortunately, this is not so!<br \/>\nThe reason hosting companies don&#8217;t take these actions is:   <\/p>\n<ol class=\"ol1\">\n<li class=\"li3\">It takes more resources (and therefore money) to set up and maintain malware scans, backup servers and routines;<\/li>\n<li class=\"li3\">Additional backups also require additional server space that they prefer to sell to hosting customers.<\/li>\n<li class=\"li3\">Tailoring firewall\/modsecurity specifically to individual websites takes more time<\/li>\n<li class=\"li3\">Not every hosting company specializes in WordPress<\/li>\n<\/ol>\n<p class=\"p3\">In addition, some of the work is offered as an option or left out of the subscription so that hosting can be offered inexpensively.<\/p>\n<p class=\"p1\"><b>Managed WordPress Hosting offers a solution<\/b><\/p>\n<p class=\"p5\">So both end users and Web site developers have a lot on their plate when it comes to security.<br \/>\nFor the former it comes at the expense of doing business and for the designer at the expense of his or her creativity.<br \/>\nFor exactly that reason, in 2015 we started offering <a href=\"https:\/\/wpprovider.nl\/managed-wordpress-hosting\/\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">Managed WordPress hosting<\/span><\/a>.<br \/>\nOffering as a full-service service all the things that we ourselves as developers had been running into since 2009, but wanted to get right for my clients.   <\/p>\n<p><img decoding=\"async\" class=\"alignright\" src=\"https:\/\/media-exp1.licdn.com\/dms\/image\/C5603AQHQxE8PeNPLYA\/profile-displayphoto-shrink_200_200\/0\/1555330761610?e=1666224000&amp;v=beta&amp;t=sgg6GCRN8X4ZqN5Gkw3JqlxPlcdHuBl9oRPNZki2smA\" width=\"175\" height=\"175\"><\/p>\n<p class=\"p1\"> <b><span class=\"Apple-converted-space\"> <\/span>Always personal contact<\/b><span class=\"s3\"><b>!<\/b><\/span><\/p>\n<p class=\"p3\">So WP Provider was born out of personal need for ultimate hosting and personal contact when it matters.<br \/>\nBy and for WordPress enthusiasts.<br \/>\nAnd the latter remains manageable by offering this service only through web designers.<br \/>\nWe focus 100% on the hosting and the designer on the design for his client.<br \/>\nIf you have any questions about this.<br \/>\nFeel free to give us a call to discuss the possibilities.     <\/p>\n<p class=\"p5\">Marco Kroon<\/p>\n<p class=\"p7\"><b>__________________________________________________________<\/b><\/p>\n<p class=\"p1\"><b>For the foodies&#8230;<\/b><\/p>\n<p class=\"p3\">As promised, below is another explanation of the six key points for a secure Web site:<\/p>\n<p class=\"p5\"><span class=\"s4\"><b>Malware Scans<\/b><\/span> Malware stands for &#8220;malicious software&#8221; It is an extended term for malicious code that hackers use to gain unauthorized access or do damage to your WordPress website.<br \/>\nIn most cases, a bot or hacker will exploit a security vulnerability.<br \/>\nIf a plugin is no longer supported by its developers and thus no updates are released for it, it is important to take active action on it.  <\/p>\n<p>  You definitely want to prevent your website from being given an SEO penalty by Google, which is why we perform several scans at the server level including our WP eXploit scanner tool that actively scans files as they are uploaded to the server through FTP or via WordPress directly, for example.<br \/>\nIt can detect suspicious files on the server and prevent most (with the exception of zero-days (the unknown exploits) from being uploaded or executed on the server.   <span class=\"s4\"><b>Software &amp; hardware based firewall<\/b><\/span><b> <\/b>  Through our firewall solution, unused ports are closed, access to certain services is protected and logs are continuously scanned for suspicious activity such as a suspicious number of login attempts to WordPress or the email boxes.<br \/>\nIP addresses and ranges are blacklisted so that the attack is stopped.<br \/>\nIt recognizes many different attacks such as port scans, SYN floods and brute-force attacks.    <\/p>\n<p class=\"p9\"><b>DDoS protection<\/b><\/p>\n<p class=\"p5\">If a Ddos attack is involved, sometimes this is not enough and the Ddos protection shield is enabled.<br \/>\nOur proactive, real-time monitoring capabilities effectively detect and eliminate high-volume attacks.<br \/>\nWhen we encounter a DDoS attack, DDoS Shield separates clean traffic while the attack is redirected to our DDoS scrub center.<br \/>\nWe also have Modsecurity active by default for your account which ensures that suspicious requests are filtered out immediately.   <\/p>\n<p class=\"p9\"><b>Security headers<\/b><\/p>\n<p class=\"p3\">HTTP security headers are, in my opinion, a fundamental part of website security.<br \/>\nBy enabling appropriate headers at the server or application level (WordPress), you can improve the CMS&#8217;s resilience against common attacks, including cross-site scripting (XSS) and clickjacking. <\/p>\n<p class=\"p3\">When a user visits a site through their browser, the server responds with HTTP Response Headers.<br \/>\nThese headers tell the browser how to behave while communicating with the site.<br \/>\nBy applying the right security headers, you are taking a good step toward a more secure Web site.  <span class=\"Apple-converted-space\"> <\/span><\/p>\n<p class=\"p3\"><b><\/b><b>Hardened PHP<\/b><\/p>\n<p class=\"p3\">WordPress recommends that the latest PHP version always be used (and so do we).<br \/>\nOf course, this is not possible in practice because, for example, custom plug-ins are written for an older PHP version or because plug-in developers have not yet rewritten their plug-ins for the latest PHP version.<br \/>\nIf an update of the PHP version is performed, the worst case scenario is that a fatal error occurs and the website can no longer be reached.<br \/>\nFor this reason, we use HardenedPHP, a way to continue using older PHP versions without compromising security.   <\/p>\n<p>  Very popular versions of PHP, used in nearly 85% of all PHP sites, are no longer supported by the <a href=\"http:\/\/php.net\" target=\"_blank\" rel=\"noopener\">PHP.net community<\/a>.<br \/>\nHardenedPHP secures old and unsupported versions of PHP &#8211; 4.4.9, 5.1, 5.2, 5.3, 5.4, 5.5, 5.6, 7.0, 7.1, 7.2.   <\/p>\n<p class=\"p3\">HardenedPHP secures old, and unsupported versions of PHP.<br \/>\nIn those old versions, including the widely used 7.2, 7.1, 7.0 and 5.6, vulnerabilities, even if discovered, are not patched by the <a href=\"http:\/\/php.net\" target=\"_blank\" rel=\"noopener\">PHP.net community<\/a>.<br \/>\nHardenedPHP takes care of all this.  <\/p>\n<p class=\"p3\">PHP represents more than 79.2% of all server-side scripts.<br \/>\nBecause of this wide application usage, PHP is constantly being exploited by hackers, leaving sites vulnerable. <\/p>\n<p>  HardenedPHP keeps your clients and servers safe by patching all PHP versions against known vulnerabilities &#8211; even those versions not supported by the <a href=\"http:\/\/php.net\" target=\"_blank\" rel=\"noopener\">PHP.net community<\/a>.<br \/>\nMore than 100 vulnerabilities, many of which were critical, have been discovered for unsupported versions of PHP.<br \/>\nAll of them have been patched by CloudLinux.    <\/p>\n<p class=\"p2\"><span class=\"Apple-converted-space\"> <img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-4437\" src=\"https:\/\/nieuw.wpprovider.nl\/wp-content\/uploads\/diagram1.1.png\" alt=\"\" width=\"467\" height=\"342\" srcset=\"https:\/\/nieuw.wpprovider.nl\/wp-content\/uploads\/diagram1.1.png 1410w, https:\/\/nieuw.wpprovider.nl\/wp-content\/uploads\/diagram1.1-300x220.png 300w, https:\/\/nieuw.wpprovider.nl\/wp-content\/uploads\/diagram1.1-1024x749.png 1024w, https:\/\/nieuw.wpprovider.nl\/wp-content\/uploads\/diagram1.1-768x562.png 768w\" sizes=\"(max-width: 467px) 100vw, 467px\" \/><\/span><\/p>\n<p class=\"p9\"><b>Backups<\/b><\/p>\n<p class=\"p3\">If something does happen don&#8217;t be alarmed, we can restore a backup for you immediately.<br \/>\nIn addition to total snapshots of all servers on the platform (against ransomware), backups are also made of the WordPress installations.<br \/>\nBecause we advocate backups of backups, these are also additionally backed up off-site in another data center.  <span class=\"Apple-converted-space\"> <\/span><\/p>\n<p class=\"p3\"><span class=\"s4\"><b>What if something does happen?  <\/b><\/span><span class=\"s7\"><br \/>\n<\/span>By default, we make daily backups of your WordPress website.<br \/>\nIn the worst case, we can go back in time to when the website was fully functional.   <span class=\"s7\"><br \/>\n<\/span><span class=\"s4\"><b>What if something happens to the backups?  <\/b><\/span>  We&#8217;ve thought of that, too.<br \/>\nAlways make backups of your backups.<br \/>\nIn addition to full snapshots, we also export our backups off-site to another secure location in another data center.  <\/p>\n<p class=\"p9\"><span class=\"s3\"><br \/>\n<\/span><b>Keep moving<\/b><\/p>\n<p class=\"p3\">&#8220;Securing a Web site is like riding a bicycle. To keep your balance, you have to keep moving.&#8221; This is how Albert Einstein&#8217;s famous bicycle quote would have looked if he had been a cyber security professional. Fortunately (or not) he wasn&#8217;t. But to keep the analogy with the bicycle: you can&#8217;t stop pedaling. The moment you do, the bike slows down and you just end up falling over. And that&#8217;s exactly what we want to avoid. But when it comes to cycling, not all pedal strokes are the same. Some are smooth, some are hard, some make you cover shorter distances, while others take you longer.<span class=\"Apple-converted-space\"> <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SMEs are also targeted by cybercriminals. Over the past two years, there have been quite a few reports of companies whose websites were &#8220;taken down&#8221; by cybercriminals. Only after paying hefty sums of money was the company in question accessible to its customers again. Recently a chain of dental practices and in the spring Artis [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":10823,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[12],"tags":[],"class_list":["post-11718","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-geen-onderdeel-van-een-categorie"],"acf":[],"_links":{"self":[{"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/posts\/11718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/comments?post=11718"}],"version-history":[{"count":0,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/posts\/11718\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/media\/10823"}],"wp:attachment":[{"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/media?parent=11718"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/categories?post=11718"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nieuw.wpprovider.nl\/en\/wp-json\/wp\/v2\/tags?post=11718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}