Skip to main content

Cyber Risk and Your Company Website

Focused female IT technician using digital tablet in server room.

Servers that host the data and other content available to your customers on your company website are often the most targeted and attacked components of a company’s network. This is because they are directly accessible from the Internet and can be subject to automated scanning and probing by an attacker.

Web content management systems

Some companies may contract with third-party service providers to provide a web content management system (WCMS). These software systems provide website authoring, collaboration and administration tools that are designed to allow users with little knowledge of web programming languages to create and manage website content. And, unfortunately, they may also be arranged to allow administrator access privileges to employees that have not been properly educated on your company cyber security policies and controls.

In addition, because the service providers are not aware of each company's security needs, default hardware and software configurations that are set by manufacturers to emphasize features, functions and ease of use at the expense of security may have to be reconfigured to reflect your company security requirements.

Examples of security exposures that websites are subject to include, but are not limited to:

  • Structured Query Language (SQL) injection, which allows an attacker to inject a software command into the web server application to steal, compromise or delete sensitive data stored in the back-end database.
  • Vandalism that defaces the website and/or installs malware, which can be transmitted to customers who visit the website.
  • Distributed Denial of Service (DDoS) attacks, which can overwhelm the server with connection attempts. Mitigating DDoS attacks can be challenging because it requires accurately distinguishing and segregating good traffic from bad traffic to preserve business continuity.
  • Unencrypted sensitive information which is transmitted between the web server and the browser can be intercepted.
  • Weak passwords and password management practices can allow hackers to breach company network security and steal sensitive information.  

The level of protection is dependent on the sensitivity of the data it contains, as well as the types of services it provides.

Informational websites and security

Informational websites can contain exclusively public content and/or require security authentication to access protected areas available to only some users. Each requires different security considerations.

A public information website presents the lowest level of risk. Public information websites generally are repositories of information available to all users. It can be used to let people know about your business, products and services. Unlike e-commerce sites, these websites are not transactional.

An informational website that provides customers/subscribers access to proprietary information as a value-add or access to account information, such as looking up a medical claim status or banking or investment statement will require a higher level of security because inadequate controls could allow the release of proprietary or confidential information to unauthorized or unintended persons.

Transactional websites and security

A transactional website presents the highest level of risk. Strong information security controls should be in place. Accepting payment for goods or services over the Internet raises several security and legal issues, including, but not limited to, theft (internal or external), liability for unauthorized payments, tax issues, liability for failure to safeguard confidential information, etc.

Chief Information Security Officer (CISO) responsibilities

The network security design should anticipate the frequency, sophistication and variety of web server attacks that may be anticipated. Security controls include, but are not limited to:

  • Confirm your network infrastructure, e.g., network firewall, web application firewall, router, etc., that support the web server are properly arranged. In most configurations, the network infrastructure will be the first line of defense between a public web server and the Internet.
  • If you accept payment by credit or debit cards, have security steps in place to help keep customer information safe. At a minimum, your program controls should comply with state and federal regulations, the Payment Card Industry (PCI) Security Standards Council and the contractual security agreements of companies that transact the payment cards you accept.
  • Use secure connections for payment card transactions. HTTPS utilizes Transport Layer Security (TLS) and Security Sockets Layer (SSL), which are industry certification standards for cryptography protocols to achieve communication security over the Internet. If you provide transactions via your company’s website, consult with your service provider about available options for incorporating HTTPS for your site.
  • Consider purchasing DDoS protection services.
  • Contracts with third parties should be in in accordance to your company “third-party management” policies and procedures and should specify their responsibilities for keeping your information secure and for promptly providing software security patches.
  • Establish a regular schedule to confirm the web content management system has been properly updated with all software patches.
  • Review and approve any employees and the scope of their administrator access privileges. Confirm they are knowledgeable and in compliance with the administrator privilege controls.
  • Require the use of strong passwords. Consider adding security measures that will block access after too many failed attempts. This security measure prevents brute-force attacks, which use automated software to generate a large number of consecutive guesses until a password is generated correctly.  

Webmaster responsibilities

To help ensure that only appropriate content is published on your website, establish a web publishing process or policy that determines what type of information to publish openly or should not be published. All information to be placed on the website must be reviewed and approved by the webmaster.

Regularly back up the web content management system and its underlying database in accordance with your company business continuity plan.  

Copyright, trademark and licensing compliance

All pictures, video, audio and other media displayed on your website must comply with licensing requirements. The unauthorized use, downloading, installation, copying or distributing of copyrighted, trademarked or patented material should be prohibited. A procedure should be established to have all website changes reviewed by legal counsel prior to incorporating onto the website.

Website privacy statement

A privacy statement should be provided on your website.  Consider updating annually thereafter. The disclosure format will include a description of the information that you collect, who has access to this information, how the information is used and how you protect the information.

It also is important to share your privacy policies, rules and expectations with all partners who may come into contact with your company’s nonpublic information.

Related resources

Avoiding Liability on Your Website

Learn topics to consider and tips for identifying and avoiding potential website liability.

Related resources

Malicious Software and Malware Protection

This bulletin discusses the importance of malicious software and malware protection as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Network Logging and Monitoring

Company networks should be protected against employee accidental or intentional actions, as well as cyber threats originating outside the company.