migration_campaign_2026

Why Hackers Target Small Business Websites (and How to Stop Them)

A Cloudways Security Bootcamp session on why hackers target small business websites even when they seem insignificant, and how to protect your site with a proactive, empowered mindset.

🎙️ Speakers
Kathy Zant — CEO, Zantastic LLC
Host: Moeez — Community Lead, Cloudways

✨ Key Takeaways
✦ Hackers target small sites for profit: your server resources and clean domain reputation are the real prizes.
✦ Most break-ins come down to poor authentication or software vulnerabilities, with stolen session cookies on the rise.
✦ Proactive security correlates with better business outcomes, and security is everyone’s responsibility.
✦ Plan incident response before you’re hacked, faster detection and response means far less damage.
✦ Audit regularly, remove unused plugins, keep off-server backups, and test that restores actually work.
✦ Strengthen access with unique passwords, a password manager, 2FA, and the principle of least privilege.
✦ Never cram many client sites into one cPanel, functional isolation stops one breach from spreading.

Moeez: Hey Kathy, what’s up?

Kathy Zant: Hi, so glad to be here, thanks for inviting me.

Moeez: Yeah, it’s a pleasure having you Kathy. Obviously it’s not the first time that we have done an event together, but every time you’re here it’s an absolute pleasure to have you with us. So Kathy, I’m sure people over here know who you are and what you have been up to, but I would like to take a few seconds to introduce you to our audience. So Kathy is a seasoned security consultant, she’s a mindset hacker, an expert in marketing and personal branding with a background in web development. She’s passionate about helping web developers, which is why she’s here, solopreneurs and online businesses overcome challenges and achieve success. So everything that we want from a guest speaker for this event, I think Kathy has it. So Kathy, I wouldn’t want the audience to wait more for your session, so I would just give you the stage and you can take it over.

Kathy Zant: Awesome. Well thank you so much for that warm introduction. I’m always happy to be here at Cloudways Security Bootcamp and any events that you guys do. You do a great job just bringing the community together. And I’ll give you a little bit more background on how I got here, all of the pain I went through cleaning hacked sites and hacked servers and all of that fun stuff as well. But before I get started I just want to talk a little bit about my mindset about security and why I do this work.

There was, at WordCamp US 2019, I was working for a security company at that time, I was a speaker at WordCamp US, and one of my co-workers was walking from the event back to his hotel and he came across somebody who really needed help in the street, just lying in the street and needed help. And he noted that everybody was walking by, nobody was stopping to help this person, and my co-worker stopped and helped. And in that conversation I realized that when people are in fear, when people are afraid of their site getting hacked, when people are afraid of being out of control, or that something else has power over them, they aren’t living their best life, they aren’t putting their brand out there to the world, they’re not being of service, they’re not bringing their full selves. And so by helping you understand the power that you have in protecting your site, my goal is that you find empowerment to bring your voice, your business, your brand, everything that you’ve got, to the world. So it’s a little unusual for security, but that is my underlying motivation, is to give you the tools, the power and the knowledge to know that you can protect yourself.

So with all of that, I can then talk about how I got into this space. The company I was working for put out a call for people who could clean hacked sites, and I had done enough of that. I had taken a security class back in the 1990s where they taught me how to spoof emails, back when that really could be done, and I was playing practical jokes on my co-workers. I learned a lot about security, but I learned about security because I inherited a server that had gotten hacked. I had assumed that it was set up right because all of the technical people had set it up, and I figured they had set it up right. I made an assumption that everything was okay, and everything was not okay. So I learned all about security because I was a victim of a hack.

I want you to learn about security through the stories and the experiences that I and others have had, so that you can feel empowered, so you don’t have to go through that experience of discovering your site’s been hacked, or that your server’s been hacked, and having to go through incident response. Since that time I’ve helped a number of Fortune 500 companies with incident response, I’ve cleaned thousands of hacked sites, I’ve been to DEF CON, so I have all of these security experiences and my goal is to bring them all to you. If you want to learn more about me, I am at z.com, I also have some courses at kathy.com, so those are all linked up there on the screen.

But let’s get talking about you. A lot of people with small business websites, they ask me, it’s just my plumbing business, it’s just my blog, why is my cat blog being hacked by these hackers, I don’t have any audience really, I don’t have anything of value. It’s important to realize why hackers target small businesses. We’re going to talk about what their motive is so that we can better understand their mindset, because if you understand the psychology of a hacker you can understand what they’re doing and why your site is at risk, even if you think it is insignificant.

Hackers want your site for a number of reasons, and it’s all going to boil down to one thing, it’s the profit motive. They don’t necessarily even really want your audience, they don’t want the content you have on the site necessarily, unless you’re storing credit card numbers, but if you’re using WordPress and WooCommerce you’re probably not. But they’re after a couple of main things. They’re after your server resources so that they can install their malicious scripts. They’re after your squeaky clean domain reputation, the fact that you have some kind of presence in the search engine result pages, the fact that your domain isn’t being blacklisted. They are looking for those things. Your server and your domain are assets whether you think about them that way or not, they are valuable, and they’re valuable to you, they’re also valuable to hackers.

They will take things like spam mailers, spam links, and put those on a squeaky clean site and ruin your reputation. They will use your site to install phishing kits, so they’ll send out malicious mailings, and if somebody clicks on a link it could be going to a hidden page that is on your compromised site, and that collects information like credit card numbers, passwords and other information from a victim of a phishing attack. They will install malware that will redirect any site visitors to a bad part of the internet, and maybe install malware on someone’s computer who visits a malicious site with a vulnerable browser. And they’re also looking to install backdoors, because once they get in they know you’re probably going to notice something’s wrong, and they want to hide a backdoor so that they can get back in later. All of this leads to one thing, hackers profit.

And now it’s not just a guy who’s sitting in the basement targeting your cat blog or your plumbing site, they are targeting tons of sites, and they use malicious scripts and command and control centers of other hacked sites to attack all sites that they can get within their systems. Now why are they targeting WordPress websites? Well WordPress is the most prevalent content management system on the internet, it’s powering over 40% of the major sites on the internet. So because it is so prevalent, because it’s so easy to use, because so many people use it, they understand the economy of scale. They know that if they concentrate their attacks looking for vulnerabilities and looking for ways in with WordPress, the number of opportunities they have in order to get into a vulnerable site are much larger.

Now according to Patchstack, in their report that they released last week, over half a million sites were compromised in 2024. That’s a lot of sites, and it’s not all big business sites, it’s a lot of small business sites, it’s a lot of blogs, it’s a lot of content sites, it’s brand sites for speakers and coaches. All of these sites are a target for hackers, and hackers know that they can get into these sites.

Now how do they get in? Well, you can basically boil it down into two camps. First of all there is poor authentication. Either you’re reusing passwords and one of your passwords has been in a breach, and so your password has been exposed to malicious attackers. They can brute force a bad password, if you’re using your pet’s name and a couple of numbers they can put that into a database and basically cycle through that and do numerous requests to your site to see if they can brute force their way in.

Another way that they get in is through stolen authentication cookies. So if you have a vulnerable computer and you are logged into your WordPress site, these hackers are getting into your devices, your cell phone, your computer, your desktop computer or your laptop, and if you have not patched your devices they can get in with what they call an info stealer. And these info stealers steal whatever they can. If you have an authentication cookie, a live cookie in your browser, they can take that cookie and then use it to basically become you and log into your WordPress site. And Thomas Raphael at wewatchyourwebsite has been studying this for a couple of years and has seen the prevalence of it. I don’t even know the number now, I think it’s like 9 million sites, it’s probably more than that now, but he does incident response, and he started seeing cases where in log files you would just have this session that was continued at a different IP address. It was a stolen session cookie, and it is more prevalent than you think.

Think about how you log into your bank now, and you go to make a cup of coffee and you come back and you’re logged out already. Large businesses are realizing that this is a problem, and so in order to protect you and to protect your assets they are making session cookies shorter and shorter in duration of how long they stay live and useful. So this is another way that hackers are getting in. They also get in through software vulnerabilities, and that would be the plugins on your site, a theme that might have a vulnerability, or even WordPress core. Now according to Patchstack, 96% of the vulnerabilities they saw in 2024 came from plugins rather than themes and WordPress core, so interesting data that they’re finding there.

Moeez: All right, so we just had a session before, Oliver, telling us that 99.9% of the vulnerabilities came from plugins, so that’s a good point that you share as well.

Kathy Zant: Yeah, it’s a great report, you can find it on the Patchstack site if you want to look at more statistics about what’s happening with WordPress security. So we know that hackers are targeting WordPress, but what’s the risk to you as a small business? Well, according to, the source is down on the slide, and if you want my slides there’s going to be a link at the end, I can’t remember who the source is on that particular one, but it’s up there, 60% of small companies that are the victim of a breach go out of business within six months.

So if you are the victim of a breach it has a number of ramifications. If you are doing commerce online, your credit card company doesn’t like it when the site on which you are collecting orders has a breach. You have to notify all of your customers that their personally identifiable information has been exposed to malicious attackers. There are a lot of different jurisdictions that have different rules, but there’s a lot of risk for your site becoming breached, and you see it in this number of 60% of small businesses going out of business within six months. Your credit card companies might shut down your credit card processing capabilities, and of course all of those breach notifications that you have to do. So there are a lot of risks to small businesses.

So what is a small business to do? There’s hackers and there’s all of this risk. Do you just install a plugin and block every IP address from every other country except the country you’re doing business in? There’s some ramifications to doing something like that. What if you are a public speaker and you want to do speaking in the UK, you want to block all of that too? Or travel the world? You want to have your site available to as many people as possible. Shutting down and limiting access to your site is not the answer.

Here’s the thing. According to AT&T, there are many rewards to being proactive about security. Now they did some research, and of course they’re selling larger scale security solutions, but they had some research that I think points to something that’s important. They found that companies that had proactive security had better business outcomes, meaning they’re making more money. So if they have proactive security policies, they had 24% sales growth over three years and 20% profit margins. Sounds pretty good. I’ll tell you my theory in a second. The contrast, no active security policies, they actually had much lower sales growth and much smaller profit margins.

It’s interesting to me. I think that those of us that have proactive policies, that think about security in a way where we take control, where we know what we can do in order to protect ourselves, where we have incident response plans in place so if something does go wrong we know exactly what to do, that we make sure we have security protecting our sites and protecting our computers and our devices, that we think about security in this way, my thinking is, if you’re thinking about security in this way you’re also thinking about your business in that way. You’re thinking about your business and your business assets in a way that protects them and grows them. So if you are doing that you are set for growth. So when your CEO says, oh well we don’t need security, our site’s fine, you can point to these statistics and you can let them know that this has much more ramifications than just protecting the site, it has ramifications for how people think about the business and the assets within that business in a much different way.

We want new results, right? We don’t want to get hacked. So what do we do? Who’s responsible for security? Is it your hosting company, oh they just handle everything? Or is it maybe your web developer, maybe they’re responsible? My philosophy is, in this day and age, security is everybody’s responsibility. Even your kids are walking around with cell phones, and if they’re not patching those cell phones they could be a vulnerability that comes to your home network. Your wife or your husband who has a computer that’s on your network at home, and you’re working from home, if that’s not protected that could be an intrusion vector. Security is everyone’s responsibility from the CEO down to customer support. Everyone needs to think about security, and if anyone has access to your WordPress site they must consider security and the decisions that they make and how it has ramifications for the assets of your business.

So the first thing we need to do is be prepared and also to protect our site. So incident response planning is not necessarily something people think about. They think about, oh well I’ll just have somebody else clean it up if something happens. But when you go through the process of planning for what happens when, not if, your site gets hacked, what will happen, who needs to know about it, what rules will you put in place that say okay we need to shut the site down and get it cleaned up, or it can stay up and we’re going to take a copy of it, clean it up and then swap it out. You need to know what you’re going to do, because if you know what you’re going to do and you know what it looks like when an intrusion is actually happening, here’s what happens, you take action, you take action faster. You have monitoring in place that lets you know that there has been an intrusion, and the faster you take action the faster you lock the hacker out, the less damage they can do to your domain reputation, to your site, to your server, the less of a job the cleanup is.

Now I’ve cleaned hacked sites that were actually hacked like six months prior, and the person who owned the site didn’t have any indications whatsoever that the site was hacked, and it affected their results in the search engine result pages, it affected their customers, it affected their business, and then the cleanup was so much harder. And when it happens like that, finding out what went wrong and when is so much harder, because typically hosting providers are only keeping 30 days of log files. So if something happened six months ago, those log files are gone. It’s just our best guess of what software vulnerabilities are there, or maybe if it looks like it was an intrusion because of a bad password, it’s really hard to tell, and when it’s hard to tell you don’t get to learn from that experience. So having an incident response plan, even if you don’t think you’re ever going to get hacked, thinking through the process of what you do when you get hacked is going to help you and your business prepare. It’s going to help you identify the importance of the asset of your website, it’s going to help you think through things in a way that’s going to change how everyone in your business thinks about security.

Security auditing is also incredibly important. How often do you audit your site security? I recommend people do it quarterly at least. Some people do it once a year. It’s going to depend based on the importance of the asset. If the site goes down because of a hack and you are taking in money, if it’s supporting people and paying salaries and the site is down, you have to figure out what is our opportunity cost if we’re not able to take in orders. If that’s the case, maybe you want to audit monthly. Now I have a security auditing checklist that I can give you at the end of the presentation, I will have a link where you can go get that. But you want to make sure that you’re doing security auditing on a fairly regular basis, and that checklist is going to walk you through everything to look at.

It will have you walk through evaluating each and every plugin. Plenty of people just leave plugins on the site, oh well I might use that duplicator plugin even though you’re not using it today. Does it really need to be there? Can’t you install it when you need it? And how often are you duplicating things? Some sites do do that, but each site is different. So auditing a site is not something where I can say okay here’s the rules, because the asset value is different. You’re going to have to do the risk assessment to see what exactly is at stake, what exactly needs to be there in order to do the job, in order to present the site in the right way, and you’re going to have to evaluate everything on a case-by-case basis. The first security audit is always the hardest because you’re thinking through these things, but once you establish a baseline, subsequent security audits are always much easier.

Backing up. Tons of people keep their backups on the same server, and here’s the thing, once the site gets hacked you have to assume that everything that’s there has been exposed to the malicious attacker. So you have to assume that all of those backups are possibly affected as well. So I highly recommend that you get your backups off server, you store them someplace else, and I also recommend that people keep one year of backups. So if your hosting provider is only keeping 30 days, it might be good to just backup some of those backups, or backing up even log files, because I’ve seen cases where a hacker will get in, maybe it’s a zero day vulnerability that nobody else knows about, and they want to cover their tracks and they will wipe out log files. So log files, another thing you want to back up off of your server.

You want to uncover any kind of vulnerabilities. If there is a vulnerability in a plugin, you want to make sure that you patch before hackers find things. Now Patchstack is doing great work with this because they work with so many different web developers. When I was working at another company they worked with us to do the managed vulnerability reporting, because there’s so many hackers that will go and say, oh well we found this vulnerability in your plugin, pay me, and so there’s a lot of noise, and Patchstack does really great work in weeding out that noise, validating whether there’s a vulnerability or not, and of course they protect customers as well. So before anyone knows, before the patch is even done, Patchstack is protecting. I think it’s just such an important service that they do for WordPress users and for plugin and theme developers, so I would highly recommend looking into their service, because you want to patch your site before hackers know that there is a vulnerability.

Now sometimes there are zero day vulnerabilities, that means that a hacker knows that there’s a vulnerability and no one else knows, the developer doesn’t know, Patchstack, the security companies, nobody knows, but the hackers got this juicy little vulnerability. These types of things do happen. Firewalls can help with things like that. But it’s important to consider the fact that your website just isn’t what you get in a browser. There’s so much stuff that is happening behind the scenes. There are many different ways to get into your web presence. You have file transfer protocol, there’s FTP access that gives you access directly to the files. There is SSH where you can just on the command line get into files and even your database. There’s your hosting panel. How many of you, when you think about WordPress security, think about how important it is to secure the hosting panel and everything that can happen there? There’s of course the wp-admin. There’s also XML-RPC which is a programmatic way to send information from one site to another. There’s the REST API. And then there’s something called phpMyAdmin, which is basically a collection of PHP files that give you access into the database. The database isn’t just your posts and pages, it’s also all of your users, it is salted passwords, but they’re in there, and at this point it’s pretty easy to unsalt those passwords and figure them out.

So it’s incredibly important that all of these things are considered when you are looking at the security of your site, because a sophisticated hacker, it’s kind of like somebody who wants to break into a house. They go around and they jiggle door handles, right? But if they come to a house and they’re like, no I really want in to this one, I think they’ve got the goods, they’re going to break a window, throw a brick through a window, they’re going to do all sorts of things, it doesn’t matter if you have a security system, they’re going to get in, they’re going to find a way if they think it is valuable enough. So based on how important your asset is, you’re going to secure it in a different way. The shed in the backyard with the lawn mower in it, are you that concerned about that? You get a new lawnmower. But your precious metals, your jewelry, all of the stuff that you have in your house that is incredibly important and so valuable to you, you’re going to protect that in a much different way. Websites are very much the same way, that’s why that risk assessment with incident response is so important.

And I’m just showing what they call the OSI model. This is just showing you all of the different layers that go into any application really, but a web presence, there’s the application layer, there is the presentation layer, and I’m not going to go through all of this, I just want to show you that there’s a lot that goes into all of this. And hackers know this stuff, and hackers use this stuff when they are targeting sites. So it’s not just like install a plugin and you’re fine, you have to consider every aspect of how your site operates.

So let’s talk a little bit about protecting authentication, your passwords. I was sitting at a WordCamp once and I was helping a woman with something, she didn’t understand something with WordPress, and she’s like, oh well here’s my password, it’s my password for everything. The security person in me had to stifle the scream, the existential scream of like, oh no please don’t do this. I mean I did explain it to her, but oh my gosh, people still do that. Maybe not so much now, maybe all of these breaches are starting to teach people not to reuse passwords. If you’re reusing a password everywhere, that password is at risk. You can go to a website called Have I Been Pwned, instead of owned it’s P-W-N-E-D, put in your email address and it’ll tell you how many times your email address has been in a breach. You can even put in one of your passwords and see if that password has been breached to one of these databases that hackers use when they’re brute forcing. You want to make sure that you are using a strong and unique password, a different password for everything that you log into.

Now my test sites, ah I’ll just wipe those out, they’re not an important asset, my risk assessment for them is I will just wipe it out and rebuild it, it doesn’t matter, so maybe I might reuse a password there. There’s something else called the blind password strategy, for those people who are not yet using a password manager because you are afraid of putting all of your passwords in one place and you’re afraid you’re not going to have that master password secured enough. You can do something that’s called the blind password strategy. That means the password that you store in the password manager isn’t the actual password that you’re logging in with. So what you do is you have a password in the password manager, and it’s a nice long 12 to 16 character thing that you’ll never remember, but there’s a four-digit number or set of letters that you always remember, you don’t write it down anywhere, it’s not in your password manager. And so what you’ll do is you’ll copy that password out of the password manager, paste it into the site you’re logging into, and then type in your four-digit pin number or whatever that’s only in your head.

And that way, if you are scared of using password managers, and I do meet people who are afraid to use a password manager because there has been a breach. LastPass had a breach that affected all of their users, and that happened a few years ago. So there’s a reason, for some people for very important things. So again, you’re doing a risk assessment with all of your passwords. So for your bank account that has the most money in it, maybe you want to use a blind password strategy because you just want to lower that risk. You’re never going to reduce it to zero. My first security teacher taught me that the most secure computer is encased in cement and buried six feet underground in your backyard. It’s completely unusable. So there’s a continuum of security where you make decisions. So some things you’re going to secure them, maybe not bury them in the ground encased in cement, but you’re going to secure them close to that, but that’s going to affect usability. Test sites, I type in glass and I’m in, because it doesn’t matter and I want to make it easy. So consider that when you’re addressing a password strategy.

All right, two-factor authentication. Not something that comes with WordPress core, but many security plugins offer it. There’s even standalone security plugins. If for example one of your passwords for one of your users is exposed in a breach somewhere and you just don’t know it yet, two-factor authentication is a code that you’ll type in after you type in your username and password. It is a second level of protection, not just for you, if you have multiple people logging into your WordPress site you need to make some decisions in order to protect your asset of your site by doing that.

Passkeys. Solid Security has passkeys, which is a relatively new technology. I do have a video on my YouTube channel if you want to go learn about passkeys. It’s just another method of authentication, it is passwordless, it just uses biometric to log in. It’s really cool, I’m hoping to see more of it in the wild, but Solid Security brings that to WordPress. Sorry about that, it’s dry here, we’re having like a windstorm in Texas and so the air is like super dry, it’s affecting me a little.

I want to talk a little bit about the principle of least privilege. The principle of least privilege is a security principle that says you only give access to people for enough that they need in order to do their job. So everybody that logs into your WordPress site doesn’t necessarily need to be an admin, and you definitely shouldn’t be giving everyone the same username and password to log into WordPress. Everybody should have their own login, and if somebody is only publishing blog posts they don’t need access to plugins, so you want to give them editor access. If someone is just a contributor, just give them contributor access. So always and for everything, this isn’t just for WordPress, this goes for your accounting system, this goes for your business systems, all stuff. If they don’t need access to do their job, they don’t get access. It’s really important as a small business that you establish some kind of policies and procedures and keep track of what you give access to for every of the individuals that works for you, so that when you offboard them you know what to shut down. Incredibly important. I have seen people who are like, oh well they didn’t have the Twitter account did they, ah we won’t change it, and then their Twitter account gets an angry former employee post. It happens.

Protecting software. This isn’t just for WordPress, it means that all of your software, if there’s an update, update. Apple just put out a security update I think within the last seven days because of a zero day vulnerability that was being exploited in WebKit. So update your phone, update your computer. When Chrome says relaunch to update, relaunch to update, because Chrome has had a number of vulnerabilities as well. Your system OS, everything, all of your applications. And if you’re not using software, both software in your computer, your phone, but also your WordPress dashboard, there’s a plugin that you’re just using like the file manager plugin, super useful, you’re in the admin, let me just go see if that file is there, but if that code is not being used regularly don’t leave it on the site. Don’t deactivate, delete. If it’s just a utility, don’t just leave it there because it’s convenient, you want to make sure you delete it as well as deactivate it.

All right, protecting your software. I have seen so many people who put like four WordPress sites in one hosting account because cPanel lets them do it. The worst one I had was 30 sites in one cPanel. It was an agency, and the agency gave all of his clients admin access to their sites, 30 of them, one cPanel. One breached password on one of those sites, where his client had a breached password, they logged in and they appended malicious code to every single JavaScript file in the entire hosting account, and so all 30 of those sites were maliciously redirecting to malware. So all of the people who are visiting any of those sites, we had to shut down all 30 sites in order to get it cleaned. The clean was pretty easy, but the effects were wide ranging.

You want to functionally isolate each individual site into its own server-based user. If you’re using a cPanel type of account, remember that each cPanel has its server-based user, and just because you do add-on domains doesn’t mean you should. One site for each function. If you have a learning management site and a commerce site, maybe think about the risks of having all of that on one site. Again, making sure your backups are off server, and just because you’re backing up doesn’t mean it’s really a backup if it doesn’t work trying to restore it. So test restoration. You have your backup, and you set up a staging server and test a restoration of your backup just to make sure that everything’s being backed up. What if certain image files aren’t being backed up and you do a restore and there’s huge chunks of your site that just aren’t working? So test your backups and do that regularly, I would do that when you’re doing your security auditing.

Protecting access, very important. I’m a huge fan of Cloudflare. It’s not just for performance, of course they have a CDN, but they also have a firewall that filters out a lot of the malicious traffic, sort of the background noise of the internet. They also have Turnstile, which is like a captcha, so you can use things like that to help protect against carding attacks and form spam submissions. A carding attack is when hackers have a list of credit card numbers and they’re trying to see which ones are valid, which ones are going to go through, so they’ll pick out a small business site without any protection and you’ll just get like a hundred fake orders just to see if those cards will work. It is a huge nuisance for site owners. So Turnstile is sort of in the background and tests to see if something is a real person or not, and firewalls can filter out some of that traffic too.

And like I said, fast detection, fast response is going to limit the impact on your asset. So you want to do things like scanning for file changes and scanning for malware. Many hosting providers do this for you. There are some plugins that do this, but if you ever do get hacked you cannot trust that the plugin is going to find the malware, because what hackers will do, they have access to the PHP that’s doing all of that, so they can change those plugins. So you have to consider plugin-based malware scanning to be vulnerable, and Kelvin Ellen from Snicco did some research on this and found numerous instances of this happening, so you can’t trust those. But you want to monitor what is happening with your site, you want to set up any kind of intrusion detection, if you see logins that shouldn’t be happening those types of things you want to investigate those immediately. Monitoring your network also incredibly important.

These are a lot of things that hosting providers are really stepping up, and I’m really liking that, because I don’t think, the job of WordPress is to deliver site content to the users and also help you manage content and things like that, but I’m really loving to see so many hosting providers like Cloudways doing security types of things, taking the load off of WordPress, so that security is being handled at different levels of that OSI model. They’re handling it at the network level, they’re handling it in many other places, so you don’t have to worry about that. So when you’re evaluating a hosting provider, some of the questions you can ask are about the security options that they have available in order to not only protect your site but protect their network as well. They don’t want your site hacked either, really, because it’s a huge drain on server resources and they don’t want that either. So I love that hosting providers are stepping up for this. And again I’ll just mention Patchstack, they’re doing a great job with virtual patching, and like I said they work with the plugins, they get those plugin vulnerability reports faster than anyone else, so they can write the rules to patch your site, it’s like having the inside track. So I love the team at Patchstack, so I’m just going to shout them out again.

All right, so let’s talk about me for a minute. If you want that audit checklist you can get it by filling out a little form and subscribing to my newsletter, just go to z.com/cloudways and that is there. I don’t write that much about security anymore, I am much more moving into consulting with businesses on a much more private scale, but I’m also still speaking and stuff like that. I do have some security courses available. There’s a WordPress mini course, I call it a mini course because it’s really everything that you should know, but I just moved it and it is like 20 modules, I’m like, maybe it’s not so mini, there’s a lot of information there. I go in much deeper with all of that. But I do highly recommend getting this checklist. Maybe not everything on the checklist is going to apply to you, but it’s a starting point. It is the checklist that I developed so that a major security company could have an auditing process, and it’s probably the same checklist that they’re using as well. And I give you in that checklist the rules that I use for evaluating each of those items. So it’s not just like, go check to make sure that SSH is turned off, maybe you need SSH but if you don’t, turn it off. So I’m teaching you all of those rules, I’m teaching my mindset.

Now, if there’s any agencies watching us, Nathan Ingram and I put together a course that is for agencies. Agencies, you love building sites for clients, and the worst thing in the world is you give access to a client, they reuse a password, and the site is messed up and you have to help them. So it is a very user-friendly course that anyone can go through, it’s only 30 minutes, and it just teaches someone who doesn’t want to know what FTP is, they just want to know, please help me not make bad decisions with site security. So it’s at monstersecure.com, and agencies can buy it, and it’s a free course, anybody can use it. But if an agency wants to use a process to track their clients and make sure that they are adhering to your contract, that they will make good security decisions, Nathan’s got all of that stuff set up. I’m just the one teaching the course, but he’s got all of the rules that help agencies manage security for the clients. So that’s at monstersecure, Nathan’s got his whole monster brand, so we did that together, so I just wanted to mention that in case any agencies are on here. So that’s it. I’m happy to answer any questions, any comments.

Moeez: Thank you Kathy, I think that was extremely insightful. I can see a lot of comments in the section and people are finding it insightful, enlightening. We do have questions in the comments, so let’s take this one first, from Kevin. So, I’m not yet familiar with Turnstile, can you tell me more about that? Is it a replacement for captcha, or does it work for forms, WooCommerce and logins?

Kathy Zant: Yes. There is a plugin, I can’t remember the name of it, a British bloke, can I say that because I’m not British, but I think British, British guy, I can’t remember his name even, but if you just go into plugins and search for Turnstile there you’ll need a Cloudflare account. But it goes behind the scenes, you know there’s no like go find all the fire hydrants so that we can train our overlord drivers. It’s behind the scenes and it just detects whether or not someone is human, and you can tune that, and you can use it for all of your forms. There’s a WordPress plugin that makes it super easy to use. That’s as far as I know, it is free. So yes, you can use Turnstile, it is highly effective. And if you’re dealing with any of those carding attacks, I have seen a lot of chatter about CleanTalk being very effective against carding attacks, so I’m just going to throw that out there, do your own research, I’ve just seen chatter.

Moeez: All right, so next up it’s more of a comment. So Carlos says that he never thought about the risks of having many WordPress installations in the same cPanel, but I think it’s very evident that it’s definitely a risky move if you have so many installations on a single cPanel.

Kathy Zant: It is, it’s such a painful experience. I mean here’s the thing, I’ve done so many security talks and I’ve been in a room at a WordPress Meetup and I felt like it was me against the world, because there were all these agency guys and women in there, and they’re like all standing up like, well we do that all the time, and I’m like, okay well everyone that you put in there, every single one, the risk assessment goes up and up and up. Because if it’s just one site it’s isolated, right, you clean it up, you fix it, one client affected, whatever, you got 30 in there, now you have a huge, your whole agency, all of your clients are now affected. So this is why security is a mindset. I’m trying to teach people to think about their site as an asset, each site is an asset, and do a risk assessment for all of the decisions that you’re making around that particular site.

Moeez: All right, so the last question in the comments was around, you mentioned about having backups off server, so they asked, what’s the best way to do that, to have these backups off server?

Kathy Zant: Yeah, I’m not sure how Cloudways handles backups. I know that there are some, like I was using SpinupWP and they had a different option for, you can put it in an S3 bucket or you can put it into a Google Drive or something like that. There’s different tools that will do that for you. If there’s an option to take something off server you want to do that. If there’s no option to take it off server, then I might create a script or a manual process even to just get those backups backed up off server. There’s numerous, each hosting environment is so different, I can’t tell you exactly how each one would do that, but it’s something you want to consider. And not just backing up the site but also backing up log files, and then rotating them too. And if you can write a script, we used to do like Perl scripts and Python scripts to do it all for us, I haven’t had to do that in a long time, I am a coder, I just don’t like doing it anymore.

Moeez: All right, so I think the last question in the comment section is, how do you see cyber threats and security measures evolving over time? I think that would require a lengthier answer, but if you can just briefly describe how have these cyber threats and security measures changed over the period of the last maybe five, 10 years?

Kathy Zant: Yeah, the thing I love about security is it’s always changing, a cat and mouse game. Sometimes the hackers have the upper hand and things are crazy, and most of the time the people, you call them red team, blue team, the blue team, the people who are doing the protecting, those are the people who most of the time have the upper hand. But when I started in security you could spoof emails, there wasn’t protection on emails, it was super easy to do, it was so much fun to play games on my co-workers and send them a fake email from the boss to tell them to do something, and we’d sit in our cube and start laughing because there was no authentication at all, there were no protections, it was so easy. That shows how old I am, because now it’s really hard to do that. Now they hack into somebody’s LMS account and use that account to send out spam, it’s much harder to do that.

So it just evolves. The hackers get an upper hand, a vulnerability happens, and hackers get an upper hand for a little bit. I don’t know that it’s getting harder, but I think the risks are higher because there’s so many more people who are online. Like code signing, something that WordPress doesn’t yet have, is a way to say that the plugin that you’re downloading into your wp-admin is actually code signed, that there’s actually some kind of check to make sure it did come from the plugin developer. So these kinds of supply chain attacks, where they breach something within a system and then it affects so many other people, those types of more complex attacks happen. I think they don’t happen as frequently but they cause more damage.

So the risks, when I first got into it the risks were pretty low, who’s on the internet, it’s a bunch of dumb kids like us, right, and so the risks were lower. But the risks are so much higher now because everyone’s online, so much of our economy is based on the internet, so the risks are so much higher, which means that security is everyone’s responsibility. Because just because Jane in the front office doesn’t know how to do anything in WordPress, but she has a login to go update something because she has to, she’s closest to the activity and you want to make sure something gets updated on the site, she’s still a security risk, because if they chain together vulnerabilities and she has just like a contributor account or something much lower, that can be escalated with the right kind of vulnerabilities.

Moeez: All right. Thank you Kathy. I think this is it from the comments, I don’t think we have any more questions, and I think this is it from the session as well. I would like to thank you Kathy for being here today. We all know that you’re very busy nowadays with multiple projects and you still made time to be here with this presentation, and we could see how hard you worked on this presentation and you made sure that you cover each and every point in detail. So thank you so much Kathy for being here today, it was a pleasure having you as a speaker, and I’m sure people listening to this learned a few things to make sure that they protect their online businesses starting today. So thank you Kathy, any last words, any last thoughts on this Security Bootcamp or anything that you would like to say to our audience?

Kathy Zant: I just want to thank everybody for being here, thank you so much for thinking about security, thanks to Cloudways for organizing this and inviting me, because I think it’s important, just to remember it’s not about the tools, it’s about you, it’s about protecting yourself and protecting your site.

Moeez: All right, thank you Kathy, this was amazing.