際際滷

際際滷Share a Scribd company logo
Secure Your WordPress Site 
AND Your Business
Stacy M. Clements
WordCamp Minneapolis 2019
https://www.linkedin.com/in/stacyclements
@StacyClements
Secure Your WordPress Site - And Your Business
Secure Your WordPress Site - And Your Business
Secure Your WordPress Site - And Your Business
Secure Your WordPress Site
 And Your Business
Why you should care
Ways youre vulnerable
Cybersecurity Framework
Three cybersecurity fundamentals
 Small business owner
 Air Force veteran
 Technology & security enthusiast
Stacy M. Clements
Fixer  Problem Solver  Pitbull
Why should you care?
 Computing power
 Server resources
 Personal information
 Connections / access
What Do You Have?
 Phishing
 Ransomware
 Cryptojacking
 Denial of service
 Insider attack
What Can Happen To It?
 Technical problems and
changes
 Security misconfiguration
 Uneducated or inattentive
users
How Can They Get It?
VULNERABILITY
THREATASSET
RISK
VULNERABILITY
THREATASSET
RISK
Risk
Why isnt a plugin enough?
Secure Your WordPress Site - And Your Business
Application
 WordPress core
 Themes/plugins
 cPanel
Network
 Server
 Computer/mobile device
 Router
 Tubes
Human
 Site administrators
 Contributors/users
ATTACK
SURFACE
Secure Your WordPress Site - And Your Business
Secure Your WordPress Site - And Your Business
NIST Cybersecurity Framework
 Collaborative effort
 Built using best
practice guidelines for
organizations to better
manage and reduce
cybersecurity risk
 Designed to be flexible
Framework Core Elements
Functions organize basic cybersecurity activities at
the highest level
Framework Core Elements
Categories break down Functions into groups of
cybersecurity outcomes
Framework Core Elements
Subcategories get more specific  describing specific outcomes
of technical and/or management activities
Framework Core Elements
Informative References are common standards, guidelines,
and practices used to achieve these outcomes
Once Upon A 意庄馨艶
BOB
Source: Sucuri Website Hack
Trend Report 2018
Secure Your WordPress Site - And Your Business
IDENTIFY Asset Management
Identify
WordPress
site
Cloud
storage
Plugins
Database
Users
Files
Payments
Server
 What are your assets?
 Who can access  and how?
SALLY
Identify
IDENTIFY Asset Management
Risk Assessment
 What are the threats and vulnerabilities?
 How do you get your cyber threat intelligence?
PROTECT Access Control
Protect
 Enforce strong passwords and use 2FA
 Change default credentials!
Protect
PROTECT Access Control
Information Protection Procedures
Protect
 Secure  Update  Backup  TEST!
 Develop and exercise response and recovery plans
PROTECT Access Control
Information Protection Procedures
Protective Technology
Protect
 Plugin is protective technology  if configured
 Logs / removable media / no kitchen sink servers
Detect
DETECT Security Continuous Monitoring
 Awareness  have a baseline and know
when something looks suspicious
Detect
 Who is getting and assessing alerts?
 Who is taking action?
DETECT Security Continuous Monitoring
Detection Processes
Respond
RESPOND Execute Response Plan
 What immediate actions do you need to take?
 Make required notifications
Respond
RESPOND Execute Response Plan
Analysis & Mitigation
 Restore from the backup you created and tested
(You did do that, right?)
 Communicate with your customers
Recover
RECOVER Execute Recovery Plan
Recover
 Recovery is not just returning to the pre-incident
state
 Hotwash / Lessons Learned?
RECOVER Execute Recovery Plan
Improvements
Secure Your WordPress Site - And Your Business
Secure Access
 Password management
 Multi-factor authentication
Update
 Inventory
 Regular update schedule
 Periodic review
Backup
 Backup
 Backup
 Backup
 TEST!
Takeaways
Security is managing risk
Protect your entire attack surface
Cybersecurity Framework
3 fundamentals to do now
S-U-B set  Secure Access, Update, Backup (and test)
Secure Your WordPress Site 
AND Your Business
Stacy M. Clements
WordCamp Minneapolis 2019
https://www.linkedin.com/in/stacyclements
@StacyClements

More Related Content

Secure Your WordPress Site - And Your Business