migration_campaign_2026

Zero Trust Security for Agency-Managed Client Websites

A Cloudways Security Bootcamp panel on how agencies can implement zero trust architecture to secure client websites without sacrificing usability.

🎙️ Speakers
Tessa Kriesel — CEO, Built for Devs
Aurelio Volle — Co-Founder & CEO, WP Umbrella
Host: Moeez — Community Lead, Cloudways

✨ Key Takeaways
✦ Zero trust means never trust, always verify, treating every access as something to double-check.
✦ Reduce the burden for clients by building security in by default, like enforced MFA and limited permissions.
✦ Common agency blind spots include shared passwords, overly permissive access, and unmonitored plugins.
✦ Preserve user experience with adaptive authentication, session monitoring, and granular access rather than constant captchas.
✦ For a compromised account, force logout, revoke access, investigate the logs, then mitigate and monitor continuously.
✦ Update plugins through dev and test environments, keep encrypted off-site backups, and remove unused themes and users.
✦ AI makes convincing fake login pages trivial, so the human layer is the flaw, and zero trust matters more than ever.

Moeez: Now moving on to the next session. This session is about agencies. If there are any agency owners listening to this session, I would suggest that you stick around for this one as well, because this session is about how to make sure that you secure your web agencies. It’s about enforcing zero trust architecture for client websites. I know this might sound a little technical, but we have two amazing panelists who are going to take us through this amazing topic. So first of all I would like to introduce Tessa Kriesel. Tessa, thank you so much for being here today with us. I’m so delighted and honored for you to be here and enlighten us with your knowledge and wisdom about security. For those of you who don’t know who Tessa is, Tessa, if you can give us a short introduction about yourself and enlighten us on what you are up to nowadays.

Tessa Kriesel: Yeah, absolutely. So I am a developer by trade, started in Joomla, so a similar open-source platform to WordPress, shifted into WordPress over time. Throughout my career I have eventually shifted over to what is called developer relations, and that’s working more with companies and products and helping developers find success within those products. Today I am running my own business where I serve a variety of different clients in this space, and actually have two clients that fall into the zero trust sort of world, so pretty excited about chatting about that today.

Moeez: Perfect, and we’re excited to have you with us today, Tessa. And our next guest for this panel discussion is Aurelio Volle. He’s a good friend of mine, I’ve met him a couple of times in different WordCamps, and I’m excited for Aurelio to be here. Aurelio, if you wouldn’t mind, if you can give us a short introduction about yourself and your company WP Umbrella.

Aurelio Volle: Of course. Nice to see you, nice to be with you, Tessa, as well. So I’m Aurelio, I’m the CEO and co-founder of WP Umbrella, which is a WordPress management tool for agencies so they can easily manage many websites, including safe updates, backup, uptime monitoring, security monitoring, from one place. And based on all what they do with WP Umbrella, we automatically send white label care reports to their clients so they can prove the value of WordPress maintenance. And I’m here because I’m not a tech expert, but I’m speaking with agencies every day and I can see so many things that are going wrong on the most basic layer of security.

Moeez: Perfect. So Tessa and Aurelio, I will be taking you through a list of questions around this topic, and I’m sure our audience would love to know your inputs on those topics as well. So I would like to start off with zero trust. Zero trust obviously is a widely used security framework, but many agencies might not fully understand it, and it’s understandable as well because many agency owners are not technical. So how would you define it in a simple, non-technical way? We have a lot of agency owners on the call over here as well, and I’m sure there are a lot of fans of Aurelio who are on this call listening to him at this moment. So how would you define zero trust to these users who are not familiar with this term? Tessa, if you can take us off with this one.

Tessa Kriesel: Yeah, for sure. It was really interesting because when I started getting into the space I was like, zero trust, that makes no sense, why are we saying zero trust, don’t we want like 100% trust? But the idea of zero trust is that we are never trusting anything, and so we are constantly verifying everything. And so that’s how we think about zero trust, it’s this idea of constantly double-checking to make sure that maybe our doors are locked, or maybe it’s a system that we have in our home security, maybe we have Apple Home, and we’re like, hey every 30 minutes just make sure the doors are locked. It’s just a level of never trusting that everything is where it needs to be, and always verifying to make sure that things are working as they should.

Moeez: All right, perfect. Aurelio, do you have an opinion on this one, do you have another definition?

Aurelio Volle: No, I mean very close to what you just said, Tessa. Actually when I was trying to figure out how to explain this to people, I couldn’t help but thinking about climbing. I’m a climber, and when you climb you put your life in the hands of your climbing partner, and the first basic rule of security in climbing is to never trust the person who is belaying you. So you always double check. I have made those knots thousands of times and I can do them with my eyes closed, but I never trust myself and I ask the person with whom I’m climbing to never trust me as well. And that’s what zero trust policy is about, because humans, we make mistakes all the time, and that’s the beauty of what we are, if I can say. And we need to have basic, easy-to-follow policies to make sure that we mitigate the errors that we are doing on a daily basis. And this very complex and frightening term like zero trust policy, it’s just to put in place some very easy mechanisms to make sure that things are under control.

Moeez: All right. It’s hard enough to understand what zero trust is, and I can imagine how hard it must be for agency owners or small businesses to explain or elaborate the importance of having zero trust. So my next question is on the same line. How do you convince your clients, especially small businesses, that implementing zero trust is worth the effort and investment? Aurelio, if you can answer this one.

Aurelio Volle: So the first thing to do is to remove the burden for them of implementing the zero trust policy. I mean, if you force them to activate 2FA on their accounts, if you don’t give them the right, to some extent, to add plugins or to make mistakes, then you have done 80% of the job. And I think nowadays with banking apps for instance, where you have MFA every single time you want to do something, people are more used to these kinds of things. And so the agency needs to, it’s kind of security by design, you have to deliver a project with the zero trust policy by itself as much as possible.

Moeez: All right. Tessa, do you have a similar opinion on this one?

Tessa Kriesel: Well yes, I think that that’s really super important. I think a flip side to think about from this conversation is also showcasing what can happen if they don’t have this in place. And so thinking about that downtime cost, the days of lost revenue, liability risk, getting sued, that type of thing. There’s just all that goes into this where if someone can get into your site, get data, get customer data, get financial data, that’s catastrophic. And so instead I like to think about, not like the fear factor, but a little bit of fear factor, like if you don’t think about it, these are the things that can happen if you don’t actually put these policies in place. And I feel like that’s a strong place to come from, just being able to explain that, and really just talking about, hey how can we eliminate some of those different risks.

Moeez: Yeah, I loved how both of your answers were on how you two operate in normal circumstances. So Aurelio said that he would want to remove the burden of implementing zero trust, because he works in that line where he wants to make it easier for his clients to implement not just zero trust but anything that they want to on their website, so that’s exactly what this tool does. And Tessa, you saying that you have to make sure that you completely translate and communicate the importance of it by telling them what happens if it’s not implemented. So loved how contrasting these two responses were. Aurelio, you were saying something before I started?

Aurelio Volle: Yeah, like, with zero trust policy it’s not just a one-off actually, so you need to design it, in my opinion, by default, and then it’s a constant reminder. Hey, don’t open your laptop, don’t type your password if someone is taking a picture in the background. I was at WordCamp last month and everybody was working, and there were so many photographers, I’m a bit paranoid, but as I should be, and I could see people doing some confidential stuff, or not really confidential but with private data on users, on people. And this is the kind of thing that you cannot design with processes, and I agree with you Tessa, you need to scare people. And I’m not into the fear business to be honest, but you need to remind them, hey this is a basic thing, don’t do this, because even if you don’t have the intention, something bad might happen.

Moeez: Yeah, I think both ways are, if not equally effective, are effective in ways, and it depends on what the client is and how the client actually operates. It also varies from client to client how you communicate these things to them. So moving on to the next question, and it’s more about security blind spots. What are some common security blind spots that agencies have when handling multiple client websites, and how does zero trust help eliminate them? How does zero trust policy help agency owners who have multiple clients remove those blind spots?

Aurelio Volle: In the end it’s all about the value you deliver to your clients and the trust you build along the way. So there is client acquisition of course, but there is also client retention, and the zero trust policy is a good way actually to keep your clients. Because at one point, if the website is hacked, even though you have nothing to do with it as an agency because the flaw was coming from your client, then somehow you are liable, even if it’s not a contract liability, and the client will be, at some point he will leave. So having a strong security by design, zero trust policy implemented, training your clients, it’s the best way actually to keep them.

And on this, as a CPO of WP Umbrella, there is something that always buzzes me. We have 2FA on our application, and we have not made it mandatory, but when people log to WP Umbrella we put a giant red warning, and I’m sure that if there are WP Umbrella users in the room they have seen this warning, and yet so many people don’t activate MFA on their WP Umbrella account. And they are agencies and they know why security matters, they know better than their clients, and this is something we really need to keep training people at, and I should do that with our agencies. And agencies should do that as well with their clients, because security is the core of everything we do. If your website is compromised, like what Tessa said, it’s gone.

Tessa Kriesel: Yeah, just to kind of add to that too. When I was prepping for this and looking through the questions I had a couple of moments where I laughed a little bit, because I spent a great deal of time in agency life building websites, and I remember that we had a shared password across our company, that if you couldn’t get into something try the shared password, that was sort of the common password. And it’s like, I couldn’t even imagine, if I were to come into an agency now I’d be like, oh my gosh are you crazy, why are you doing this. But then, we weren’t in these more advanced days of really realizing and understanding, and obviously you evolve, and maybe there’s still agencies that are doing that, because you’re moving fast, things are shifting fast, and you just need to make sure that everyone has access so they can get work done.

I think another thing that is a really good highlight is like overly permissive access. So bringing in a contractor and just saying, hey you’re a super admin, do what you need to do. Does that person actually need super admin access? Can they work locally with a copy of the database? Do they really need access to the live WordPress instance? Also, thinking about unmonitored third-party plugins. Do you have plugins that are unmonitored? One of the clients that I’m working with is actually in the software signature space, and that’s a future advancement that I’m really looking forward to, starting to see in package managers where open source software actually has this software signing process, so you know exactly where that code came from, who that’s associated to. And I think that’s valuable, obviously we’re not there in the WordPress and all the website world, but I am excited for that world where we’ve got software signing from developers, from people committing code.

And I think thinking about these third-party plugins and whatever code you’re bringing into your website or downloading, how can we automate that, how can we automate the update process, how can we build different types of pipelines using CI/CD, just a variety of other things that can come in. And again, Aurelio, I’m not familiar with your product, but it sounds like your product helps with a lot of this stuff too. So those would be the things that I would immediately check, and then obviously real-time detection, a lot of the things that Umbrella is offering, allowing you to kind of see what’s in your space and understand what’s going on, and just never assume that someone needs that full access, that super admin access, whatever that might be.

Aurelio Volle: Yesterday I was attending a talk made by Oliver from Patchstack I think, and he’s speaking tomorrow, and he was saying to the crowd, hey guys do you realize that when you install a plugin you are just adding 20,000 lines of code to the website and you have no clue about what you are doing. And it was very critical to some extent, I mean it was not critical but you know what I mean. And I think it’s like that with plugins, when you install a plugin you must check who is doing the code, who is behind it, and there is a whole business of hackers buying out non-maintained plugins to exploit hacks. So yeah.

Tessa Kriesel: I mean, I couldn’t agree more.

Moeez: Yeah, absolutely. So before I move on to the next question I just want to take a stroll in the comments section, I want to see what people are talking about, what questions they have. So we do have a question, it’s from Anto, and they asked, what are the biggest challenges businesses face when adopting a zero trust security model? Tessa, would you like to take this one?

Tessa Kriesel: Yeah sure, I can start and obviously can jump in and add to that. I think the things that I talked about, like the shared credentials, weak passwords, overly permissive access, are you not monitoring your code, what’s coming in there. And I think when we talk about those biggest challenges it’s really a matter of shifting your mindset. It isn’t that, oh I’m going to retroactively fix things or go back and adjust this, it’s like you need to change how you operate fundamentally. There needs to be 2FA, all of these zero trust things we’re talking about. And so it is this idea of taking a step back, looking at what you have going on, how many clients do you have from years and years ago.

I remember having so many old client sites from that agency, and I could still get in with that master password, yet I saw employees come through that company and leave again. So that means that essentially the owner is trusting those old employees to never come in and sabotage what’s happening. And that’s just on the admin side, that’s not even talking about the user side, how many bad users have been registered, what access did they have, can they get into the admin to give themselves access.

And so I think really your first step is just take a step back, what is that process for which you have that security, think about zero trust, never having access and constantly having to reverify access. Can you bring in a single sign-on type of architecture where if an employee is cut, their access is cut across the board, so anytime that you’re getting into that admin or that important side of that site, can they even get access? And then code, that’s a whole other way to look at that too, but thinking about where are you putting those code repositories, are they private, who has access to that, who can write. So really just take that step back and think about that mindset shift and what things you need to start to adjust and change inside of your agency.

Moeez: That’s awesome. Aurelio, you want to add anything to this?

Aurelio Volle: I think everything has been said, it’s all about mindset. Because in the end, enforcing MFA, cleaning up admin rights, cleaning up users, having an internal policy paper, enforcing a password management app, it’s not burdensome. In the list of all the time-consuming tasks an agency is performing every day, implementing zero trust policy is actually very easy, and it just requires a bit of discipline in the early days. And for this you might want to scare people, to circle back to what Tessa was telling before. At WP Umbrella we are a very agile company and we are just six, seven people, but in the onboarding I do as a CEO, I spend like 20 minutes reviewing our tiny security policy, just so the new employees realize, okay these people pay attention to security. Because if this is just a one pager that’s left in the back of the room, what’s the value? And you need to make people realize that security should be a major concern in your company. And if you think about it as an agency, how do you look if you don’t speak about security at all, and if you come and say, hey these are our processes and they must be because this is how we should be working, there is value and you can build trust actually with your clients.

Moeez: Awesome, that’s very insightful Aurelio. Now I want to talk about e-commerce and membership based sites. There are completely different dynamics, they are more difficult to manage, they have more security concerns, especially e-commerce sites, because they have people coming in leaving their credit card information and addresses and other personal information over there as well. So I think it’s more crucial for e-commerce and membership based sites to have more solid security. So how can they implement zero trust without negatively impacting the user experience? Because specifically with e-commerce it’s very important to maintain that good user experience to ensure that sales don’t get affected. A lot of e-commerce owners are concerned with making sure that the checkout process is simple, the add to cart process is simple. So how can they add that zero trust policy without negatively impacting the user experience? Tessa, if you can start off with that one.

Tessa Kriesel: Yeah, for sure. Obviously there’s a lot that goes into that. You’re capturing and collecting a lot of private information. Member-based sites can have communities and different private spaces where folks are actually talking and engaging and sharing information, and e-commerce sites have credit card information and financial information, so it’s incredibly important, and I can’t reiterate this, that those sites are taken very seriously, and that you have platforms like Umbrella and others that are coming in and actually helping aid in that process, because they’re so important.

I think when it comes to user experience, zero trust, the grunt of the difficulty there usually should fall on that agency and the builder and the creator and the management side. But when you’re looking at that user experience there’s a few different things that you can think about, and so thinking about adaptive authentication, when do they need to actually reauthenticate versus when they don’t need to reauthenticate. Session monitoring, are they doing something different or strange or outside of their normal types of behavior, can that raise a flag, versus saying, hey you’ve been on here for an hour, we’re just going to make you re-log in. And really diving into what is it at which we are monitoring for that does require that prompt for that authentication or that security layer. Granular access control also, thinking about who has access to what and can you associate that through different user accounts.

There’s obviously a variety of things that can go into this. User experience, we obviously want it to be frictionless, we want them to be able to smoothly get through what they’re getting through, but at the same time, when we can offer things that ensure that that customer also realizes and sees that their information is secure, I think that’s really key. And so thinking about two-factor authentication, or magic passwords, where you just go into your email, you validate and you go back in, and again coming back to single sign-on. It isn’t always necessarily a use case that everyone can use, it tends to have some pretty sticky, expensive price tags behind it when you want to bring in a lot of these higher single sign-on platforms, but there is a variety of different opportunities there. And so when you bring in single sign-on for the user experience side, then you can sort of revoke where you need to, and make sure that you’re covering what needs to be done there, and those usually bring in a layer of security too. Do you have an authenticator app, are you using two-factor authentication. I know that sometimes we can get a little annoyed by those, but how do we bring those together so that it’s a great experience but yet they are being verified when we need to verify, because we are zero trust, we never want to trust but we want to ensure that we know that everything is still in its right place.

I want to share deep examples here, but it is one of those things where you really have to be in the scenario to do it. But I do think I’ve seen a number of e-commerce sites that use like Okta or some of these other authentication platforms, and seen a massive change in what that can do for their platform.

Moeez: Yeah. Aurelio, would you like to add something to this response?

Aurelio Volle: I mean that was very comprehensive. I’m not an expert in WooCommerce or e-commerce website and conversion, but zero trust, showing that your website is safe actually, I think it’s a good thing. It depends of course on the value of your baskets, but it reflects on your brand as well, just like SSL certificates. If you have an expired one it looks bad. And as a user, there is something that’s terrifying me, it’s like on 95% of the websites when I pay, my bank asks for confirmation, and on a few websites it’s not happening because they are not up to date, and when this takes place I’m so scared to go back on this website again to make a purchase. So the zero trust policy shouldn’t be seen as burdensome, it’s a good way to actually build trust.

Moeez: Yep, I agree. Awesome. So I would like to dive into the comments again before moving on to the next question, and we have a question from Danish who asks, enforcing multiple security layers strengthens protection but it can also frustrate users, which is understandable. How can agencies strike the right balance between security and usability for client websites? Aurelio, do you want to take this one?

Aurelio Volle: It’s a matter of balance of course. Do we lose time every morning when we close our door? Yes. Do we still do it? Yes. And I think when it comes to digital agencies, they have a key role to play in education, and it goes way beyond security because it applies also to WordPress smartness for instance. Agencies that don’t take the time, not all of them of course, but they should take the time when they build a website to go way beyond than just building a website, because they’re working for people whose job is not to build websites, and they’re working for people who have not necessarily the knowledge or the will to invest time in this digital knowledge landscape. And it’s their role as an agency to explain to them, and the earlier in the process the better, regardless of the topic, it can be WordPress maintenance, it can be security, it can be the things that will come with the contract as well, renewing domains, how it’s going to work. The sooner in the process they need to educate their users, because once again it’s about the value you add to the people that are paying for your services, and everybody actually likes to be taught.

Moeez: Tessa, anything you want to add to this?

Tessa Kriesel: I don’t think so, I think that was a great answer. When it comes to the usability, I had spoken to that a little bit ago, how can you verify, should they still be in the same situation, can we do some type of monitoring for activity, is there abnormal activity for a user, is it based on a timeline of login, sort of looking at some of those, so that you aren’t bugging people with those constant, really annoying captchas, like oh my gosh the puzzles drive me crazy. Can you instead find ways to authenticate that user and use some different technology to validate on that side.

Moeez: Perfect. So moving on to the next question, and I would like Aurelio to weigh in on that one. So many agencies manage multiple clients from a single dashboard. Your tool is basically used to manage clients for agencies. So how can centralized security platforms like WP Umbrella help enforce zero trust across all sites?

Aurelio Volle: We can allow agencies, we can warn them when they have an outdated plugin, we can allow them to keep all their websites up to date, but once again it means that they are selling care packages to their client, and that they have educated them from the very beginning on the stakes of why do you need to update plugins, and what is WordPress security, and why am I a better person as an agency to do this than you. And it’s way worth the few bucks or dozens of bucks or hundreds of bucks you are having to spend every month to keep your website fast, updated, up and running and safe.

So I think zero trust policy is something so easy to do and it’s very linked to education, to have just a few processes in place. And if your agency doesn’t have processes when it comes to security, to teaching security to your clients, and when I mean processes it can be a five item checklist, did I tell my clients to use a unique password, did I tell my clients to activate MFA, did I install a 2FA admin plugin on the WordPress website. Very basic things, you don’t need to overly complexify the situation. And of course with WP Umbrella you can mitigate and improve the safety and security of the websites, and with WP Umbrella you can update everything in one click and we prevent websites from going down when you have visibility. But I think in this session it’s not necessarily about the right tech tool that can help you add on your security, it’s really about adopting the right mindset and the few items to check when you onboard a client to make sure that zero trust policy is implemented.

Moeez: Perfect, really insightful Aurelio. My next question, Tessa, is for you specifically because it’s a scenario based question. So let’s say an agency suspects a compromised account on a client website. Can you show us what a step-by-step process would look like if they were to respond in a zero trust framework?

Tessa Kriesel: Yeah. Obviously immediately lock down that user. Where did that user account come from, can you identify who that user account was, can you restrict that access, can you do a force log out, that’s really super important. Sometimes people don’t think about that, we can be logged in from our phone or from another device, but we need to actually force them to log out of all devices and then revoke that access. Then we want to investigate that breach, we want to understand what exactly happened, so looking through different log files, both inside of WordPress log files, on your server, any form of logs or any reporting that you might have, to figure out what actually happened in this situation.

From there we obviously want to mitigate and secure. So once we understand what has happened in the breach, what caused that, and how do we go and actually address that and mitigate that. I think in most cases, I was kind of laughing, someone, whoever NK Tally is, had replied back to my comment about I was working in an agency and there was a shared password where it was just constantly shared around, and sharing how scary that is. And so thinking about what are those different things that have happened inside of that to make that happen, and how do we mitigate that. So platforms like Umbrella and otherwise, where you can bring a bunch of sites into a single dashboard, is really key for that, to be able to go through and mitigate and resecure things like that, because it is really super important.

Revoke permissions, does someone have a permission that they shouldn’t have. I would hope that folks will leave this panel and leave the Security Bootcamp being more proactive on these types of things versus reactive, but we’re talking about the scenario here, so in the reactive space, do we have to reset other passwords as we’re looking through that log file, is there some type of situation, if somebody got in and got access to a user account they can likely get in and get access to super admin accounts or other types of accounts, maybe even the database, if they got in enough and they can go get the credentials and figure out how to get into that database, then they have all the data of everything they could ever want. So really just thinking about that, enforcing multi-factor authentication, just like Aurelio was saying with Umbrella, and just really addressing whatever it is that took place, and then securing that.

After that it’s deploying this continuous monitoring process. I had shared earlier about automating your plugin updates, I think that’s really key, especially in WordPress, honestly that is one of the biggest things that you can do to deflect these scenarios, is by actually having these updates constantly being automated. Outside of that it’s like continuous monitoring, can you start to monitor for unusual login, can you monitor for what you actually saw. But the biggest thing about it is really understanding and knowing where to go to get the information. Do you know where those log files are, do you know where those bits of details, of trails, so that you can actually figure out what has happened in the site.

I know that oftentimes in an agency the person who gets that call is like the account manager or the project manager, whoever’s on that actual client account, and so they have to be able to be like, okay let’s have a conversation, let’s calm that person down, let’s figure out what’s going on. And so I think it’s really important to not only have your technical team understand all of this but also have your front of the agency world understand this, what are the things that they can check for, make sure that they understand the security measures, in order to really truly have a zero trust infrastructure inside of your agency. Everyone has to be bought in, everyone has to be on board, and everyone has to realize how serious it is, because it is somewhat annoying to be like, okay let me pick up my phone and get into my authenticator app, but at the end of the day it means that all of your clients are going to have a safer environment. So it is really incredibly important, specifically on that admin side for sure. I think that’s everything. I had a couple little things I wrote down. IP addresses, looking at that, if you’ve never actually tracked down a user to their IP address, that’s another thing too, because you can very frequently say, hey this user is constantly logging in from this location versus, oh wow they’ve actually logged in from a different location, that’s obviously concerning. So anyways, I’ll digress there.

Moeez: Perfect, that was very insightful. So my next question is for both of you. Some common vulnerabilities that agencies should check for right now on their client’s website. I’m sure a lot of agency owners are listening to this right now. What are some of the common vulnerabilities that they should check for right now on their client website, and how can they address them immediately? Aurelio, if you can start us off with this one.

Aurelio Volle: I would start not even on the client side thing but on their own critical stack, just to check with something like haveibeenpwned.com if they have been compromised, and to review internally, do I have a proper unique password policy for the tools I use, and I think they should start with this. This said, when it comes to clients, the first thing to do obviously is to review who has existing access to the wp-admin, review the users, maybe you have former employees, maybe there are people you don’t even know, and like Tessa said, check the logs, where are the visitors coming from, because if you are operating a website in Portugal and you have a very suspicious connection from another continent or another country, this might give you a clue. And also to review your stack of plugins. Very basic things actually that can make everything a bit safer. And I will tackle this later.

Moeez: No worries, you can continue.

Aurelio Volle: It’s somehow unrelated, but also they should review their zero trust policy regarding backups. How do they make backups, where are the backups stored, are the backups encrypted. And by doing so they will, first thing first, realize that many backup plugins in WordPress leave so much trash on their server which is bad for performance, but also that they might have a plugin with vulnerabilities on the backup, they can have so many things that can go wrong about their backup policy. And when it comes to managing your backups you should have the same kind of security policy as when it comes to managing your websites. And I just wanted to add, I think backups can be a critical security flaw, because in the end you have all the data of the website in the backup, and this needs to be thoroughly thought through, and please opt for an encrypted backup solution, first thing first.

Moeez: All right, Tessa, anything that you would like to add to Aurelio’s answer?

Tessa Kriesel: Yeah, he had a great answer. I just have a quick list here so I’ll run through it, so if anyone’s taking notes then they can jot this down. Unused or outdated plugins and themes, take them out. If you’re not using a theme and you shifted over, you built a custom theme, take out the old themes, because something can happen with those old themes, especially if they’re not the WordPress core ones, if they’re owned by a different developer, let’s say they stop supporting the theme and someone hacks into that actual repository and is able to update a theme and then take out all the sites that have that theme on it. So make sure you take out anything that’s outdated, not being used, not activated, it doesn’t need to be in there if it’s not being turned on.

Weak admin passwords, checking for the actual weakness of the admin passwords. If you’ve got sites that are really old, WordPress didn’t have that requirement to change those passwords, you could put in one two three four five and you’re good to go, so looking at what those passwords are. A lack of multi-factor authentication, two-factor authentication depending on how you look at it, on those admin accounts, get that turned on right away. Publicly accessible admin panel, so as we know it’s wp-admin, change that, redirect that, don’t make it the wp-admin URL, so that it is harder to even find where you go and access that admin panel. On the backups, already mentioned there, but I had the same thing, where are those backups going, they should be automated and they should be offsite in a very highly secure location that has zero trust integrated into that.

We talked about shared passwords, so we’re talking about not even just weak passwords, shared passwords, do not use shared passwords, cannot say that enough. And then just constantly checking that access. I had a little note here to mention the contractor thing, and I know I already mentioned it earlier, but it is so important because it’s so easy for you to bring a developer in, or a designer, anyone in, into a project where you’re trying to push forward and give them all the access because you’re in a rush, but then making sure that that person doesn’t have access later. So I think those are some of the very high level key things. Someone did add, yeah, passwords and emails, woof, that’s a rough one. Someone did use like a 1Password or, gosh I can’t remember the other one, LastPass, if you’re going to actually share passwords with clients, utilize some of these password management tools so that you can yet again revoke that through the password management tool or reset it through that tool, and then your company can constantly work within a vault of passwords and revoke access accordingly. So that’s another addition I did add.

And someone in the chat is talking about these out-of-date plugins or not utilizing plugins. Actually I do agree with you on LastPass, they had their own security problems all in themselves, so good call out JW. But long story short, I did share in the chat about how I look at automatic updates, and I do think that they are key, but when you do update things there’s a whole other level of security there too, we can’t just automatically update plugins in your live production site. And so just really thinking about, are you utilizing an environment that has this dev environment, this testing environment, alongside of your live environment. You shouldn’t be messing with things inside of your live environment, you should be updating in your dev environment, publishing to your test environment and allowing that validation process to happen there, making sure your site is what it needs to be when you update, and then push all of that up to your actual live or production servers. And there’s a whole bunch that goes into that, that looks at your servers and your hosting companies, so as you’re looking for different hosting partners, definitely look for those partners that have these security processes in place, that already have this ability to automate the updates of plugins if it’s not necessarily your technical specialty.

Moeez: All right. Moving on to the next question. There is something that obviously is the talk of the town nowadays, which is AI of course. And since there are AI powered threats becoming more sophisticated, they’re becoming more human, because in the previous session we were discussing about bots and how AI bots are behaving more like humans. So apart from bots, there are other threats that AI poses in terms of website security. So how do you see the future of zero trust evolving for digital agencies? Aurelio, if you can answer this one.

Aurelio Volle: That’s the easiest one, it’s going to be more and more important. To give you a quick example, you can replicate the front end of the landing page of WP Umbrella with something like v0 in one prompt, and then you have a fake landing page, and then you start to do some Google ads on our domain, which is something that happened to us, which is why we’ve tried to enforce 2FA, MFA across multiple accounts. And then you can steal credentials from people and you end up having access to many websites. And it happened to Manage WP as well. Everybody can make a super credible fake landing page in one minute with AI, and we have smart bots. And actually, the more complex the technical challenges of security are, the more important the zero trust policy becomes, because in the end the flaw is almost always the human one.

Moeez: All right, Tessa, anything to add?

Tessa Kriesel: I wouldn’t say that there’s anything monumentally insightful to add there. I will say though, I’ve had a lot of different AI types of clients recently, been diving into the AI and ML space, and it is absolutely wild to see what artificial intelligence can do and how it continues to advance every single day. It can build infrastructure for us, complete software solutions in some cases, I’m not saying they’re good, but they can do wild things. And so I think this is really this key time, if you are not thinking about zero trust and you are not having this zero trust mindset inside of your agency, now is absolutely the time, obviously the time was yesterday, but we are in the world that we are in today.

But just really thinking about that, because they can get in and they can change and shift, and they’re computers, they’re going to be able to operate and do things a lot quicker than we can and identify things a lot faster than we can, and so they’ll just have one barrier and then they’ll get past it, and have another and they’ll get right past it. And the thing about thinking of that too is that I know oftentimes in agencies you can start to think, oh well we just have small clients, they’re just marketing websites, they’re just here for information, it doesn’t matter, because if that marketing website goes down and that’s a part of their revenue flow or how they operate or how they exist with their customers, it’s still just as fragile and needs just the same approach as an e-commerce or a membership site or a site that’s for Disney.com. It all matters, and so bringing in zero trust is so incredibly important in today’s world with AI for sure.

Moeez: Perfect, that was awesome Tessa. Aurelio, you were saying something?

Aurelio Volle: It’s easy, don’t make yourself something so big out of it, because it’s so easy to implement, you just need to switch your mindset.

Moeez: Perfect. So folks, final question from both of you on this panel. So if an agency could take just one step today to move towards zero trust security, what should it be? Tessa?

Tessa Kriesel: This is a loaded question because it depends on the scenario they’re in. If you’re still using a shared password that’s probably a good start. I think that there’s a variety of things depending on what level you’re at. I think really it’s that mindset shift, how can you as an entire team sit down and have a conversation about what it would take to reach a zero trust state. So we’ve shared a lot of different things throughout this conversation, but I think the biggest thing is actually getting everybody on board, because if everyone is not on board I could very well see where there’s a UX designer that’s working with the QA tester that’s like, oh hey here’s the password, and it’s like, no no no no no, we just don’t even do that, even though they are on the same team and they are right next to you. What if that QA person gets terminated at the end of the day because of something that happened. There just can’t be this level of sharing and just being kind to each other. And so it really needs to be, we all need to go zero trust and we all need to take these steps to protect ourselves and to protect our clients.

Moeez: Perfect. Aurelio, last thoughts?

Aurelio Volle: I agree very much. I would just say two things. Set up a meeting tomorrow to discuss your security policy, and show your people that it’s not something nice to have, it’s a red line and it shouldn’t be crossed, first thing first. And then it can be actually easy to implement, like force MFA and force the usage of a password management tool so people will have unique passwords, because people are lazy, and if they can just create a unique password in one click then they will do so. It’s just basic things that must be implemented, and that must be implemented thoroughly and strongly, like security is not something nice to have, it’s a must, it’s a necessity.

Moeez: All right, I would just take a look at the comment section, I think we do have a couple of questions before I wrap up this session, I want to take questions from the audience. So Joshua Ezekiel has a question, what about in-browser password managers, are they safe, should we use them? Anyone can take this one.

Tessa Kriesel: I actually started typing an answer. Password managers are absolutely not zero trust, so let me reiterate that. I mentioned password managers because somebody was sharing a password in an email, and I was like, at least utilize a password manager when you’re doing that. But when you think about a password manager, they have vaults, and you can have internal company vaults, and you can have employee vaults, and you can have a team set up, but at the end of the day, unless you are consistently revoking access to things in a zero trust mindset, password managers are not considered zero trust. And so I do think that yes they are more secure, it is an important tactic on a personal side of your own password, if you have access into something or if you need to share something, that is one kind of password, but it is absolutely not a zero trust technique.

And so that’s what I really want to reiterate, is if you’re going for zero trust, a password manager is more of a support. So thinking more on the single sign-on is going to be more along the lines of that zero trust, because if you do that right with a single sign-on, you’re giving, say, one employee access to a variety of different things, maybe a social account, maybe their website, whatever it is that you’re bringing into that single sign-on, and that’s a better process. But at the same time, in agency life we all know that we’re scrappy, we’re moving fast, we have all these different things, and so really what needs to be done is having a conversation around, what is the password manager doing for us, and is this truly zero trust, and the answer is likely it’s not, but what can we do and how can we alleviate this and shift outside of that world. So kind of a deeper, wider conversation there, but that’s my answer.

Moeez: Perfect. Aurelio, do you think on the same lines?

Aurelio Volle: 100%.

Moeez: Perfect. So there is another question on password sharing as well. So Matt has asked about 1Password and LastPass, are they pointless, do we use them to some extent or should we just abandon these password sharing tools?

Tessa Kriesel: I wouldn’t say abandon them, because I use them on my personal level, because I make sure that I am frequently adjusting my passwords. So the nice thing about a password manager is on your individual level, when you’re going into a site, we want to constantly be creating extremely complicated passwords, something that somebody can’t guess, and that’s what those password managers are helpful for. And so I think there’s a difference between managing your own passwords and then sharing passwords. Password managers are amazing for managing your own passwords, when they are secure, when they are trustworthy, when they are used correctly, versus utilizing them as a, oh hey let me just share the super admin password for the website, that’s not what you want to be utilizing them for.

Aurelio Volle: I would water it down a bit. I mean you need unique passwords, and from time to time you need to share a password, and actually this kind of shared vault, they are in the philosophy of zero trust policy, because you need to have access to the dedicated vault, so it must be compartmentalized, if this word exists in English, separated, so not everyone should have access to every password, and you would need the password to access the password. And so in the end it’s way better to have this than nothing, and from time to time you are paying just one license for a tool and you need to share the password, what is important is to make sure that the people that can access this shared password have the right to access this shared password, and that they identify before having access to the vault. That’s what I think, I think we are saying somehow the same thing, but at least there is some kind of verification, and it’s way better than the pizza, I called it the pizza password posted on your office.

Moeez: All right, thank you Tessa and thank you Aurelio. I think this panel discussion was extremely insightful, and I hope that agency owners who are listening to this would have learned a thing or two about managing their security for themselves and for their clients as well. As for you folks, I would like to thank every one of you who have been here throughout this day listening to our sessions and commenting and asking questions. I would again like to thank Tessa and Aurelio for being here today, and with that I would also like to give a shout out to WP Umbrella who have been our partner and supporter throughout this event and making sure that this event takes place successfully. I think this is pretty much it from the panel discussion. Thank you, thank you Tessa, I wish you all the best for your current and future projects, and until then we will see you later.