Website Security
Website security is the part of your attack surface that is exposed to everyone, all the time, and it is the part most companies review least. We harden the site, keep it patched, monitor it for the changes that matter, and lock down the domain so it cannot be used to phish your own customers. Delivered from our Dubai base at Meydan.
Short answer. Website security covers five things: keeping the platform and its plugins patched, hardening the server and the admin accounts, backing the site up somewhere the attacker cannot reach, monitoring for unauthorised change, and authenticating the domain with SPF, DKIM and DMARC so nobody can phish your customers in your name. Krasper Technologies delivers website security for businesses in Dubai and the wider UAE, either as a one-off hardening engagement or as ongoing monitoring.
What Website Security Covers
Five layers. A gap in any one of them undoes the other four.
هل أنت مستعد لتأمين
بنيتك المؤسسية؟
احجز جلسة إحاطة تقنية. بلا عروض بيع، فقط مهندسون وفريقك.
The platform, the plugins, the libraries and the operating system. Most website compromises we clean up used a public vulnerability with a patch already available.
Admin accounts separated and protected with multi-factor authentication, unnecessary services removed, security headers set, upload paths locked down, tested against the OWASP Top 10.
Offline or immutable copies of both files and database, with a restore actually rehearsed, so a defaced or ransomed site is an inconvenience and not an extinction event.
File integrity, unexpected admin logins, certificate expiry and uptime, with alerts routed to a person rather than to a dashboard nobody opens.
SPF, DKIM and DMARC published and moved to enforcement, so your domain cannot be spoofed at your customers. This is the core of how to protect against phishing attacks that impersonate your business.
If the site is already serving content nobody uploaded, we contain, preserve evidence and close the entry route. See the six-step response.
Website security is not a plugin. A security plugin inside a compromised platform is running on the attacker's machine. The controls that hold live outside the site: patching discipline, an isolated backup, an authenticated domain, and monitoring that reaches a human.
How to Protect Against Phishing Attacks: Six Steps
Phishing attacks succeed in two directions: messages sent to your staff, and messages sent to your customers that appear to come from you. Website security work addresses both, because both run through your domain. This is the order we implement it in, and the first three steps are usually complete inside two weeks.
-
Step 1: publish SPF, DKIM and DMARC
Declare which servers may send mail for your domain, sign the mail cryptographically, and publish a policy telling receiving servers what to do with mail that fails. Without these three records anyone can send convincing phishing attacks from your address.
-
Step 2: move DMARC to enforcement
Start at monitoring, read the reports for a few weeks until every legitimate sender is accounted for, then move the policy to quarantine and then to reject. A DMARC record left at monitoring forever protects nobody.
-
Step 3: make a stolen password useless
Phishing-resistant multi-factor authentication on email, admin and anything that can move money. Hardware keys for finance and leadership, because those are the accounts targeted by executive impersonation in the region.
-
Step 4: register the domains that look like yours
Common misspellings and the obvious alternative endings. It is cheap, and it removes the easiest way to run a convincing phishing attack against your own customers and suppliers.
-
Step 5: give staff a one-click report route
A report button that reaches somebody who acts, not a mailbox nobody reads. Reporting has to be faster and less embarrassing than deleting, or people will delete.
-
Step 6: verify money out of band
Every new bank detail and every changed one is confirmed by phone on a number you already had. This single rule defeats the invoice fraud that most successful phishing attacks in the UAE are actually aiming at.
How a Website Security Engagement Runs
Platform, plugin and dependency inventory, exposed surface, admin account review, and the current state of SPF, DKIM and DMARC.
Patching brought current, admin access separated and protected, security headers set, upload and execution paths locked down.
SPF, DKIM and DMARC published, reports read, policy moved toward enforcement once legitimate senders are accounted for.
Integrity monitoring, alerting to a human, and a patch rhythm that does not depend on anyone remembering.
Website security: common questions
How to protect against phishing attacks?
Publish SPF, DKIM and DMARC and move DMARC to enforcement so your domain cannot be spoofed. Put phishing-resistant multi-factor authentication on email, admin and payment accounts so a stolen password is useless. Register the lookalike domains. Give staff a one-click reporting route that reaches somebody who acts. Verify every new or changed bank detail by phone on a number you already had. Training helps at the margin, but the technical layers are what actually stop phishing attacks, because a good enough message will always fool somebody. The full order of work is in the six steps above.
What does website security actually include?
Patching the platform and its plugins, hardening the server and the admin accounts, backups the attacker cannot reach, monitoring for unauthorised change, and authenticating the domain so it cannot be used in phishing attacks against your customers. Application-level testing against the OWASP Top 10 sits on top of that for sites that take payments or hold personal data.
Is a security plugin enough for website security?
No. A plugin runs inside the thing it is protecting, so once the platform is compromised the plugin is running on the attacker's machine. It is a useful extra layer and a poor foundation. The controls that hold sit outside the site: patch discipline, an isolated backup, an authenticated domain, and monitoring that reaches a human.
My website is already hacked, what should I do?
Take the site offline or into maintenance mode rather than deleting anything, preserve the server logs and a copy of the current state, then rotate every credential the site holds, including database, hosting panel, CMS admin and any API keys in configuration files. Restore from a backup made before the first unauthorised change rather than cleaning the live site, then patch the entry route before it goes back online. The full sequence, including the reporting and insurance steps, is in I got hacked, what should I do.
How often should a website be patched?
Security updates within days of release, and automatically wherever the platform allows it. The window between a patch being published and being exploited is now measured in days for popular content platforms, because the patch itself tells attackers where the bug was.
Do you monitor the site after the work is done?
Optionally, and it is the part most worth keeping. File integrity, unexpected admin logins, certificate expiry and uptime, with alerts routed to a person. Monitoring nobody reads is the most common form of website security theatre we find.
Does website security matter if we do not take payments?
Yes. A compromised brochure site is used to host phishing pages, serve malware to your visitors, and send mail from your domain. The attacker wants your reputation and your domain, and both are worth taking even when there is no checkout.
Can you work with our existing web agency?
Yes, and it is usually the right split. We specify and verify, your agency implements what they already maintain. We do not resell hosting or plugins, so there is no commercial reason for us to recommend moving anything.
What clients say about the website security work
Our domain was being used to invoice our own customers. Two weeks after they moved us to DMARC enforcement it stopped completely.
The site had been defaced twice in a year by the same unpatched component. They fixed the patch process rather than the page, and it has not happened since.
What This Page Is Based On
- OWASP Top 10 (2021), Open Worldwide Application Security Project, owasp.org.
- Phishing guidance and Stop Ransomware advisories, Cybersecurity and Infrastructure Security Agency, cisa.gov.
- Multi-factor authentication and password guidance, National Cyber Security Centre, ncsc.gov.uk.
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, u.ae. Summarised on our UAE PDPL reference page.
Continue Reading
Fixed-fee scope for owner-run and mid-sized companies that need a security baseline rather than a governance programme. Small business cyber security consulting in Dubai.
How a phishing-response playbook is wired end to end, branch by branch. SOAR playbook design.
Independent gap assessment and technical control testing, evidenced finding by finding. Information security audit in Dubai.