Google Begins Campaign Warning Forms Not Using HTTPS Protocol

August 2014, Google released an article sharing their thoughts on how they planned to focus on their “HTTPS everywhere” campaign (originally initiated at their Google I/O event). The premise of the idea was that every website, regardless of what it was doing, should be communicating securely between point A and point B. To help motivate…

Read More

Defense in Depth And Website Security

The concept of Defense in Depth is not new. It’s been leveraged in the InfoSec domain for a long time, and has it’s roots deeply embedded in military strategy and tactics. That however doesn’t mean that even those in the InfoSec domain explain or implement it correctly. To fully appreciate the idea of Defense in…

Read More

How To Protect Your Business Data

It’s impossible to go a week without seeing some reference to a data breach, whether it’s a write up on what happened years ago, or updates on breaches that are still happening. The two breaches I found most interesting where a treasure trove of  business data (not credit card data) was exfiltrated, and subsequently released…

Read More

Impacts of a Website Compromise

The threats of a compromise are real, and are not specific to operating an online store. Attackers find value in a number of things, some of which include your audience and resources. In this webinar I spend some time exploring a number of the impacts we should all be aware of as website owners. I…

Read More

WordCamp US 2015: Navigating Today’s Website Threats!!

Recently I spoke at WordCamp US 2015 on the topic WordPress Security — Navigating Today’s Website Threats!!  WordPress is one of the most recognized website CMS platform available in the market. Dominating over 25% of the websites on the web, and over 50% of the CMS-based websites, it’s no surprise that it’s the preferred technology…

Read More

Security In Open-Source CMS Applications

Open-source CMS applications are no stranger to the battle they face with security. The size of the organizations adopting the platform also has little to do with it – from bloggers to mom and pop shops to Fortune 500 companies; the concern is the same. Can open-source CMS applications be deployed securely within their respective stacks? There are…

Read More