Security
Today, website security is something all website administrators must take seriously and monitor routinely.
If a bad actor hacks a website, bad things will likely happen.
We believe MSHS’ vulnerability to a brute force attack is low. Our hosting service, Siteground, has strong firewalls and other defenses. We also have installed their Security plugin and have configured it to minimize threats.
In fact, for too many websites, it’s the habits and behavior of the site’s own admins and editors that are problematic. Bad habits can lead to plugins not updated in a timely manner and passwords compromised through careless behavior.
The key to WordPress Security is good habits and cautious behavior for both admins and editor users.
What do hackers want?
Different bad actors want different things. Some want to:
- Steal Sensitive data.
- Email addresses and passwords
- Donor info
- A link to the Society PayPal account
- Install Ransomware. Bad guy software that locks the site down until a ransom paid.
- Vandalize the site:
- Delete or modify or replace the content.
- Crash the website entirely
- Install Malware. Hackers could use the website to distribute malware to infect visitors’ computers to steal their data, and more
Site Admin Security Tips & Procedures
- Pay Attention to Passwords
- Use strong passwords and change them a few times per year
- Share with your admin team only – keep a list of those with access
- Don’t get tricked by email or other phishing schemes, etc.
- Never send passwords by email
- Sending by text is safer (especially between iPhones)
- If sharing by text, send password and user name in separate messages
- Best: use Dropbox (or similar secure sharing) to exchange user names & passwords
- Make sure the Siteground Site Tools Email Redirects forwards alerts to the correct admin email
- Do routine security checks for plugins and other updates, ideally weekly or biweekly
- Tip for MSHS admins & officers who receive Form submissions: configure your email to highlight incoming Form alerts, so you don’t miss them
- Do not deactivate the security plugin
- Backup every time you add new content or update plugins
- Limit admin access to trusted individuals —no casual password sharing!
- Review these security procedures with every new admin/editing volunteer
- Add new tips as necessary