October, the month of pumpkin spice latte and spooky tricks, has another significant aspect to it – it’s officially Cyber Security Month. This year, at SiteGround we are excited to bring you something that underscores the vital importance of website security in a truly hair-raising way.
We’re thrilled (get it?) to announce our Website Horror Stories campaign, where we’ve gathered real-life stories of digital nightmares caused by neglecting website security, but, thankfully, fearlessly busted by SiteGround. From defaced websites, malicious file uploads, email frauds, bot traffic and vengeful former employees to long-forgotten applications that became hacker gateways – we’ve seen them all, and they all carry a crucial message: Each story is a stark reminder of the potential threats lurking in the digital shadows, ready to exploit any security oversight. Let those cautionary tales remind you of the importance of website security and using all tools and services you have to protect your website at SiteGround.
Celebrate #CyberSecurityMonth, share the Website Horror Stories campaign to spread our message about the importance of website security, and keep your site safe with SiteGround’s multilevel website security tools and services.
Since more businesses are going online, customers’ personal data becomes even more important for hackers who leverage it on the dark web. With Black Friday, Cyber Monday and the holidays ahead of you, as a business owner, you can expect increased website traffic and with it – higher risk of data breaches.
Protecting customer data during these peak shopping seasons is crucial for your business in terms of brand reputation and trust, customer loyalty and protection, laws compliance and cyber attacks prevention.
Increased Cybersecurity Threats
Customer data leakage has indeed become one of the biggest security threats of our time. According to Statista, as of 2023, the global average cost per single data breach amounted to $4.45 million, where the average cost varies across sectors. The highest average cost is in the healthcare industry, with each leak costing the affected party $10.1 million.
In 2022, the most common cause of a cyber attack in the USA was email phishing, according to data by Statista. Some other common threats faced by retailers and consumers include website malware and ransomware, data breaches, identity theft, and others.
The Implications of Data Breaches
All of the above-mentioned cyber attacks can have a huge negative impact on your business. Let’s explore a few ways why is data security important:
Impact on customer trust and brand reputation
To operate with customers’ information means that customers have trusted you with their personal data. If you suffer any data breach, even not your direct fault, your customers will lose their trust in your business. In turn, this will result in you losing customers and profits. Brand reputation damage and negative PR are the other long-term damages.
Legal and regulatory consequences
A data breach will cost your business not only your customers, profits and reputation, but big financial losses. On one hand, you can be held liable for failing to comply with privacy regulations, which in turn can result in a lawsuit with financial consequences, i.e. regulatory fines.
For example, if you collect personal information of EU residents, the applicable law for your business will be GDPR (General Data Protection Regulation), or if you collect consumer data of residents of California, USA, you’ll be subject to the California Consumer Privacy Act (CCPA), and so on. Such regulations and laws will apply if your customers are residents of these countries, even if your business is not located there.
Essential Measures for Client Data Protection: Securing Data Systems
To avoid a data system breach, implement these essential measures to secure data systems:
Keep data systems up-to-date and patched
One of the most common reasons why data systems get hacked are security vulnerabilities in softwares which get exploited by cyber criminals. It’s important to keep an eye on patch releases for the softwares you use and implement them in due time. These will not only bring your software up-to-date, but also keep your data safe.
When you’re using a lot of different softwares, this could be tedious work on its own. SiteGround clients that use WordPress, take advantage of our WordPress auto-update feature. It automatically updates all WordPress installations, hosted with us, and ensures that our customers’ WordPress sites are secure and up-to-date.
Implement robust access controls and encryption techniques
Your access point is another common source of a security vulnerability. To increase security and reduce the risk of data breach, implement the usage of a password management tool which will create, encrypt and store smart passwords for you and your employees for all the tools you access with a password. A tool like this will take care of static data, but now let’s take a look at what happens to data that’s in transit.
A lot of traffic may go through your website, including sensitive information like login credentials and credit card details of your customers. To keep all these protected, you need to encrypt them. An SSL certificate can easily encrypt all this data and it is essential for your website security. SiteGround clients, for instance, leverage free SSL certificates on every web hosting plan we offer.
Enhanced Security Measures and Increased Vigilance during Peak Shopping Seasons
Even though the above-mentioned steps are crucial to begin with, there are some enhanced security measures to follow in order to manage data security protection:
Implementing intrusion detection and prevention systems
You need to have your website scanned regularly for potential threats. Start by implementing an anti-virus and anti-malware software or prevention system. Make sure the tool you choose is reviewed and approved by your security team and the team is in control of it at all times. This will allow you and your employees to stay up-to-date with the latest security measures and updates.
SiteGround clients have the opportunity to leverage our Site Scanner service that helps protect their websites from malware. Our Site Scanner constantly crawls web pages to detect the latest threats that might affect a website, warns clients about such potential threats at an early stage and in a timely manner and gives them tools for reaction, in case their sites are under attack.
For WordPress users, we have an all-in-one security solution – our free Security Optimizer plugin. It’s available to all WordPress users (no matter where they’re hosted) and provides them with all the security measures they need to keep sites safe. The plugin protects sites on application level (hides WordPress version; disables themes & plugins editor, etc.), provides advanced protection, such as locking and protecting system folders, enabling advanced XSS protection, hardens login security, and many other features.
Conducting regular security audits and monitoring network traffic
Even if you implement all these security measures, you still need to monitor your website security status regularly. You need to keep an eye on your site’s security status at least once a month, yet this could take some time, effort and money. As a business owner, you probably have lots on your plate, so you might consider outsourcing this activity.
SiteGround clients receive free monthly security reports, delivered straight into their inboxes. We automatically monitor our clients’ websites and send them detailed summary results, along with actionable tips on what they can improve to reduce the security threats, in case we detect any weak areas on their websites.
Collaboration with Logistics Partners
With all the enhanced security measures in force, you then need to think about your collaboration with logistics partners, i.e. the participants which provide the cloud computing services, such as Google Cloud, AWS (Amazon Web Services), or Microsoft Azure, for instance. Effective communication and collaboration are key for ensuring secure handling of customer information throughout the supply chain. Companies working together is also important for reducing costs, improving service quality and flexibility.
To achieve all these, they need to communicate openly, share common goals and have trust in the partnership. Should they succeed in their collaboration, this will result in different advantages, such as improved customer satisfaction, better risk management and even cost savings.
For example, companies like Amazon or Apple handle sensitive customer data. If they don’t follow strict client data protection standards, there’s always a chance for potential vulnerabilities in the data protection chains. Back in 2019, Amazon Web Services faced a data breach, affecting CapitalOne bank’s 100 million customers’ names, social security numbers, credit scores, and credit card data. An ex-employee was found guilty in misconfiguration of cloud storage servers to access and steal the data.
When businesses collaborate closely with logistics partners, they can ensure the implementation of crucial security measures (e.g. encryption, 2-factor authentication and others). Effective communication and strong relationships with logistics partners are essential factors for a successful overall performance and data security protection.
Employee Awareness and Training
Now that you’ve secured your website on all levels, it’s important to make sure that your employees are also up-to-date with the latest security measures in order to prevent weak points. Start by educating your employees about security best practices. To mitigate human errors, conduct regular security awareness training and checks. Educate employees about the most common security threats, such as phishing, in order to prevent hackers from stealing their credentials and personal details.
Our website can be a good starting point with tons of useful security resources. Visit the security category on the SiteGround blog to get more information on website security topics.
Transparent Communication with Customers
An essential next step is to have transparent communication with your customers about your privacy policy and how you handle their data.
You need to have clear, written Privacy Policy and Data Handling Practices. Important points to cover in it include who can access your customers’ data and in what ways, as well as how their data will be used and how it should not be handled.
Publish the Privacy Policy on your business website and communicate it to your customers, informing them how you collect, store, use and protect data privacy. Keep them in the loop about the latest changes and updates to your privacy policy.
Educating Customers on Secure Online Shopping
Being a customer during peak shopping seasons has its security threats as well. To protect personal information, be cautious of phishing emails, use strong passwords and update your devices and software regularly.
In the unfortunate event of a security breach happening, it’s a good idea to have an incident response plan, developed in advance. Draft thorough steps on how you would contain a data breach or security incident. These should include timely notification of affected customers and/or employees and open cooperation with the relevant cybersecurity authorities. When it comes to a security incident, communication is key. Make sure your employees can report suspicious activities to your data protection security team (or data protection officer), as well as ensure that your customers are informed at all times of any suspicious behavior. Beware what you share with your customers and provide them only with the essential information they need.
With the peak shopping season just ahead of all of us, we can not stress enough on how important protecting customer data is. Ensuring security data protection is key for your business, as it will keep your customers’ trust, brand reputation and your success levels high. Implement the data protection security measures you learned from this article for a successful and secure shopping season. Add a comment below to share with us other security measures that have worked well for your business data privacy or tell us more about your general data protection strategy.
Like your home, your website also accumulates dust and clutter over time that can slow it down and make it vulnerable to security threats. So cleaning your website is just as important as spring cleaning your home, and with our help, it can be much easier and faster.
Get started with our actionable tips on how to declutter your site for even stronger security and faster speed.
Clean up your WordPress website
For all of you, using WordPress, we’ve identified some crucial, yet easy-to-follow tips that will help you take special security and speed care of your WordPress website.
Quick website security tips
Keep your WordPress version and plugins up-to-date
It’s important to keep your WordPress version and plugins updated to the latest version, because hackers use every opportunity and backdoor to attack your website and get access to your files or valuable information. Keep an eye on the latest WordPress versions and plugins and install them in a timely manner. Luckily, SiteGround clients don’t have to worry about this, as we do it automatically for them – we autoupdate all WordPress installations, hosted with us.
Clean up your user roles and permissions
Make sure you review and remove inactive users or limit access for certain users only to the resources they require. For instance, give administrator access to your site only when strictly necessary and only to users that actually need it. The same applies to the login details for your hosting account.
Enforce strong and secure passwords
Weak passwords are one of the most common reasons sites get hacked. Always use secure credentials for accessing your account. On top of this, remember to store your passwords only in password vaults – no plain text, no writing them down, no sharing. As a complementary step, you’d also need to implement 2-factor authentication for login access. It will require an additional step of verification upon each log-in for an extra layer of security.
Clean up unused plugins and themes
Outdated plugins and themes can open up the backdoor for hackers to gain access to your website. That’s true even for deactivated plugins and themes. For this reason, delete any plugins and themes that you’re not using to lower the risk of security breaches on your site.
These are just some of the steps to follow in order to spring clean and secure your WordPress website. The good news is that you don’t have to do them on your own and one by one. Some of them and many more you can find as one-click features in the free SiteGround Security plugin, available for all WordPress users. Download it now and enable many powerful security options in just a few clicks. For SiteGround clients, it’s already been installed and working out-of-the-box.
Easy-to-follow website speed advice
Clean up your WordPress database
Your WordPress database can significantly affect the speed of your website, which, in turn, affects its overall health and search engine rankings. To ensure optimal performance, it is important to keep the database clean. Cleaning up your WordPress database is a vital part of refreshing your website and optimizing its functionality.
Compress large images
Large images can significantly slow down your WordPress website. Use image compression to speed up your site. You can compress them as much as you like, without compromising on their quality. For this purpose, make sure to always take advantage of the latest image formats, such as WebP format.
Minify CSS and JavaScript files
Minify your CSS and JavaScript files which will basically remove all unnecessary characters from them. Minification of CSS & JS files will speed up your website by reducing your site’s code weight.
Preload your fonts
Your website’s fonts are yet another thing that the browser needs to load in order for the users to see it. To keep them from slowing down your website and allow the browser to render faster, you need to preload your fonts. Keep in mind to preload only the font files that you use most oftenly, not all of them; otherwise, you might end up slowing down your site further.
To help you get access and enable most of the above options and many more with just a few clicks, we have an in-house developed SiteGround Optimizer plugin that’s free and available for all WordPress users. It also offers powerful caching features, frontend optimizations, as well as media and environmental optimizations.
Scan your website thoroughly
Continue with performing a complete and regular scan of your website, checking it for potential malware-infection and other security threats over time. There are different types of site scanning services available out there. At SiteGround, we have our in-house developed Site Scanner security service. The Site Scanner checks your entire website for malware and the latest threats, notifies you about any potential security issues in a timely manner, giving you enough time and tools to react in case of any suspicious activity.
Apply powerful website performance optimizations
Level up your website speed by implementing these powerful optimization tips:
Make sure your PHP is fast
Ensure that your website is running on the latest and fastest PHP version and that your web server handles that in the best way possible. SiteGround clients have the opportunity to take advantage of our ultrafast PHP setup that cuts the TTFB (time to first byte) and makes web pages load 30% faster in comparison to standard PHP setups.
Leverage caching
Caching is one of the most powerful techniques to make your website load even faster. You can apply caching at different levels, such as browser caching and server-side caching. SiteGround clients take advantage of our powerful caching technology out-of-the-box that’s built in-house on three levels – Nginx Direct Delivery for static content, Dynamic caching for dynamic content, and Memcached (object caching). All three can speed up website performance up to 5 times.
Use CDN
Speed up your website even further by enabling a content delivery network (CDN). A CDN keeps copies of your website on servers that are geographically closer to your end users. Then, when they request to see a web page, it gets served faster from a location that’s close to them. SiteGround clients take advantage of our free in-house built SiteGround CDN which now comes in version 2.0 that is even faster and more efficient.
Check your website security and speed status regularly
Once you’ve done all of the above, it’s good to keep an eye on your website security and speed status regularly. Make sure you’re aware of any potential backdoors on your website that might still be open for the hackers, or any performance issues that might slow down your website.
At SiteGround, we know how much time and effort this might cost you. That’s why our clients receive monthly security and performance reports, delivered straight into their inboxes, at no extra cost.
In the monthly security reports, we provide them with digestive summary results from automated security checks that we perform for their websites. Our clients get their site security status in a user-friendly and understandable format, along with actionable tips on how to reduce the risk of malicious attacks, in case we’ve identified areas that need their attention. With the free monthly security reports, we help our clients stay in control of their website security in the long run.
Similarly, the monthly performance reports provide our clients with easy access to information about their website speed status. We check a number of performance categories for our clients’ websites (e.g. cache ratio, CDN usage, WordPress optimization, and more), and give them an overall performance score in a user-friendly structure, plus actionable recommendations, if some areas need improvement.
As you can see, website security and speed are an ongoing process that needs your attention throughout the whole year, not just in the spring. Yet, now is the best time to start taking care of your site speed and safety in order to avoid any potential issues in the future.
The results from our traditional annual client survey are here! Looking back at 2022, we’ve been working hard to introduce new and improve existing tools and services that make your websites even faster and safer. But at the end of the day, what really matters is the impact of these improvements and the positive effect they brought for our users. Here is what you had to say and how you rated our efforts and your experience with our hosting services throughout the past year.
An Outstanding 98.8% Satisfaction with Site Security
Securing your websites has always been a top priority for us during the years. 2022 was not an exception and our efforts didn’t go unnoticed – our Website Security was rated high by an overwhelming 98.8% of all respondents! Here’s what we did to achieve that:
We improved our already great-performing Site Scanner with features improving early malware detection and introduced a new plan with proactive reaction tools in case of a website attack. During our #CyberSecurityMonth campaign last October, we went even further. We not only ran an intense email awareness campaign about website security, but we also introduced new security features, such as an on-demand IP and Geo traffic blocking tool. We also improved our AI-driven brute-force prevention system and its state-of-art self-learning mechanism, which now blocks over 95% more bad traffic before it even reaches our servers. Here’s a recap of all essential website security features for your website, in case you’ve missed it.
Last but not least, towards the end of 2022, we launched our new monthly security reports, included for free with all our plans. You can now sign up and receive directly in your inbox a personalized security overview of your website(s) every month, with highlights of what security measures we’ve applied and suggestions of what you can improve.
A Supreme 97.7% Satisfaction with Website Loading Speed
Website loading speed is important for your conversion rates, SEO rankings, and users’ experience. That’s why boosting website performance is of utmost importance to us and we’re constantly working on making your websites as fast as possible.
As early as February 2022, we introduced a newer version of our SiteGround Optimizer plugin for WordPress, making it available and free to all WordPress users, regardless of where they host their websites and included new advanced speed features, such as file-based caching. The plugin now has over 1 Million active installations and was voted Silver in the top 3 best WordPress optimization plugins in the annual WordPress community awards.
One of our biggest speed-boosting achievements in 2022 was the launch of our in-house built SiteGround CDN which not only makes websites load blazingly fast around the world, but it’s super simple to configure in a few clicks and included free in all our plans. We didn’t stop there and kept on growing our CDN and data center networks with a new location in Madrid and a few new locations in the USA.
Top Marks for Easy Website Migration and Setup
We’re happy to welcome those of you who have recently joined SiteGround as clients.
48.6% of our new clients say that the number one factor that led to the decision to get on board was a recommendation for SiteGround by someone they trust. 44.4% of you point out positive reviews about SiteGround were what influenced your decision to choose our hosting services, which is the greatest mark for the level of quality we provide, and the recognition and loyalty of our clients.
Your feedback about how easy our onboarding process is was also extremely valuable. A total of 78.3% of you, who created a new website with us, have noted that setting up a website on SiteGround wasa hassle-free process. 76.9% of you, who switched over from another host, pointed out in the survey that transferring your websites to us was a seamless process.
Now it’s even easier to migrate and manage all elements of your website presence to SiteGround with our newly launched Email Migrator tool. It helps you transfer emails to SiteGround servers easily, securely, and automatically.
We’re looking forward to making your future experience with us even better and contributing to your websites’ success.
A Steady 98% Overall Satisfaction In the Last Few Years
We completed 2022 with an overall client satisfaction rating of 98.1% which solidifies our top-rank customer happiness rate in the last couple of years. The overall satisfaction rate is based on your reviews for the following services we provide:
The breakdown of the satisfaction rate of each aspect of our services is based on the evaluation of both long-term and new clients. The overall ratio of all respondents is 90.40% long-term clients and 9.6% clients who have joined in the past 12 months. The fact that the majority of respondents have been with us for a couple of years now, and continue to express their satisfaction with our services with top marks is the greatest recognition a company can have.
You Helped the Environment by Completing Our Client Survey
Just like everything else we do, we also tried to maximize the impact of our client survey this year. In return for completing it, we committed to donate funds for planting a SiteGround forest. Thanks to you, we’ve already planted more than 11,000 trees worldwide – in the USA, Spain, Portugal, France, Indonesia, Madagascar.
We’d like to thank you for your trust, for your feedback, and for helping the environment! Stay tuned for all the upcoming services improvements and new tools launches that will aim to make your websites even more secure, better-performing and successful in 2023.
Do you know how secure your site is and if its security level is changing over time? Have you ever wondered how many actual attacks toward your site are being mitigated? Do you want to know if you have missed doing something easy that may protect your site from incidents?
Now with SiteGround’s Monthly Security Reports, you can get all that information and more – straight to your inbox. Just sign up and start receiving an actionable monthly report covering what SiteGround is doing to safeguard your site and highlighting security measures that you may have overlooked.
What’s in the Monthly Security Reports?
Each month we will perform automated security checks for your website covering malware protection, SSL certificates, software exploits, brute force attacks, and other security areas. Based on our checks, you’ll receive a digestible summary of the results – including a total site security score, breakdown score for each security check, and actionable tips if some area needs your attention. The monthly security reports will be your go-to place to get an overview of your website security status.
The benefits of the Monthly Security Reports
Site security information in one place
Performing website security checks manually can be an investment of valuable time, effort, and money that most website owners can’t commit. With the monthly security reports, SiteGround will handle the heavy lifting for you, performing all necessary security checks and delivering user-friendly reports straight into your inbox. So you get to know everything with no effort required on your side.
Easy to understand format
With our user-friendly design, you can quickly scan the report and easily identify areas that need your attention, if any. All you have to do is follow our straightforward color codes: green when everything is good; yellow: needs improvement; red: definitely needs attention. You also receive an overall score for the month and information how it has changed in comparison with the previous month.
Actionable advice when needed
If we have identified an area of your site security that may be improved, the report will include easy-to-follow instructions on what can be done. For example, if we detect that you don’t have an SSL certificate installed on your site, it will provide you with a link to the information on how to set it up.
Confidence that your website is protected
By signing up for our monthly security reports, you may easily monitor what we do on a regular basis to keep your website safe. Each month you will see information like: how many software vulnerability attacks have been prevented; how many malicious IPs were stopped from reaching your site; how many backups you may count on, etc. Making sure your site is secure is an enormous part of our job as a host, and with the reports you can keep an eye on this process.
How to get the Monthly Security Reports?
Starting from next year we will gradually begin to proactively send the reports to all our clients. However, you may hurry up and sign in yourself today and be among the first to receive their report in early January 2023.
The reports are sent out at the beginning of each month for sites that have been active for more than 30 days and have their domains pointed to SiteGround. You can see detailed information on subscription, content and score calculation in our Security Reports Explained article.
Sign up today and sleep soundly, knowing that all relevant site security information is right at your fingertips.
When you’re busy processing tons of emails each day, and we all are, the last thing you need is a bunch of spam messages sneaking into your inbox. Spam protection has always been an important part of our email service and in our strive to constantly improve it we are now introducing a new in-house built solution. It is designed to efficiently minimize the amount of SPAM emails delivered to your inbox, while constantly learning from your email reading behavior. It is also built specifically for our clients and works seamlessly as part of our hosting environment.
Efficient and easy to use for our clients
Less SPAM messages delivered to your inbox
Based on our multiple years of managing email services, we have created a system that decides with a high amount of accuracy which messages are legitimate and should reach your inbox, which are suspicious and should be delivered in your Junk folder, and which are outright dangerous and should not reach your email at all and will bounce instead.
Your email reading behavior trains the system
Your natural actions, while working with your mailbox will train the system. Whenever you move a message to or from your Junk folder you will improve its accuracy. Based on your action the system will add your personal perception of what is SPAM on top of its own underlying rules. Thus your feedback is taken into account seamlessly, without a need for you to use an additional SPAM management interface.
Easy interface to allow and block senders
And also, if you would like to tell the Spam protection system directly how to treat a certain sender, you can still use our easy interface to block or allow specific senders. By adding an email address or an entire domain to the Block or Allow List you indicate how you want this sender to be treated by the system. Check the following tutorial on how to use the Spam Protection service in Site Tools.
Better control and easier scalability for us
We may address our clients’ needs
By using an in-house solution we can more easily address our clients’ specific needs and introduce new features and improvements faster. For example, we have noticed that the current setup makes it difficult for our users to find out when a legitimate email is not delivered to them and is marked as spam by the system. This happens because the message is placed in a quarantine folder in a separate tool that is not part of the user’s natural email management. With the new solution we were able to address this issue by using the much more visible Junk folder instead.
We may handle email usage spike better
When we manage the spam protection system as part of our own infrastructure, we can easily scale it. Even if there is a steep global increase in the email traffic we can seamlessly add the resources needed for the evaluation of the excessive messages. Thus the email delivery will not be delayed for our clients, regardless of the unexpected usage spike.
How to use SiteGround Spam Protection?
All SiteGround clients have our state-of-the-art Spam Protection features enabled by default.
The infrastructure that runs the Internet’s email hasn’t changed a whole lot in the past 30 years. Yes, we’ve layered a few things on top of it like Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) but at its heart, the protocol remains the same. That’s the problem. Email was designed in a simpler time. A time when the Internet was a trusted resource and nobody gave a second thought to the fact that it’s easy to say fudge the headers on an email so that it looks like your boss is getting an email from the President of the United States commending you for all your excellent work. I’m not saying that has happened or that I was a part of it…but hypothetically, it is possible.
So, if email can’t be trusted, what can we do? Well first, these days email is a lot more trustworthy. It is much easier to detect emails sent from someone, but say they are from the President, thanks to things like Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM).
Even with these new technologies though, email scams are still rampant. As we charge headlong into the holiday season, let’s stop for a moment and look at a few things you can do to make sure you don’t fall for the latest scam. (Which is not sending emails to unsuspecting bosses…)
Email Scams You Need to Be Aware Of
Let’s take a look at a few of the many ways that bad people try to do bad things to you via email. This first group of scams all fall into the category of Phishing scams. A Phishing scam is basically an email designed to fool you into thinking it is from someone it is not and convince you to click on a link embedded in the email.
The Fake ‘’Account verification’’ Requests
These can seem to come from your bank, Netflix, Twitter, or one of those sites that you don’t admit to having an account on. It doesn’t matter where they are coming from, they all have the same basic message.
“Your account has been locked for a REASON. To unlock your account before we delete it totally, click on this link.
Here’s a hint, no trusted system out there sends these emails out randomly. If you get one and you are not currently interacting with this organization, then it is almost assuredly a phishing scam.
When in doubt, pull out the paperwork you have for this organization, find a phone number and call them. Ask if there is a problem with your account. When they say no, thank them, wish them a great day, hang up, mark the email as spam, and move on with your life.
The unexpected ‘’Billing error’’ notifications
Did you know that it is possible for bad people to figure things out about you without you telling them? It is relatively simple to find out where a website is hosted. When bad people find out information like this, they like to use it for their gain and your loss. Such is the “Billing Error” notice.
For instance, if you are a SiteGround customer and you get an email from SiteGround notifying you that there has been a billing error and you now owe $XXXXX more, stop. Don’t click any links in the email. Instead, go to the SiteGround support page and start a chat session with one of their great support people. They can tell you if there’s an issue with your account or not.
Here’s an example of a phishing email that requests from a SiteGround customer to update their billing details in order to be able to renew their domain:
Scam email example
Notice that this fake email does not contain the name of the recipient, and SiteGround original emails should include the name you’ve used for registering your account.
Next, notice that this email has grammar and spelling mistakes. These are red flags for a scam email along with the poor formatting.
Finally, the signature is not the one used by the SiteGround team.
When you confirm that there is not actually a billing error, thank the nice support person, wish them a wonderful day, disconnect, mark the email as spam, and move on with your life.
The ‘’Order confirmation’’ requests
An oldie but a goodie – and one that pops up a lot these days because ecommerce has exploded – is the “Order Confirmation” email. These are most effective when they are from companies that you’ve never dealt with. They usually involve large sums of money as well. The idea here is to alarm you so much that you will obviously click the link to “Unconfirm” the order.
If the email looks like it is from a company you don’t do business with, ignore it. Mark it as spam, and move on with your life.
If it looks like it is from a company you do or have done business with, contact them directly outside of the email. Talk with the sales or accounting department and see if someone has placed an order on your behalf… When you find that the answer is no…well, you know the drill by now.
The ‘’Click and collect’’ scam
Thanks to the recent pandemic, “Click and Collect” has become a common way to shop. You buy something online from a nearby retailer. You drive to their store and let them know you are there, they bring the item out to your car. Sometimes, they even put it in your trunk so you don’t have to even meet them face to face.
Nowhere in the Click and Collect workflow is there an email that says “Click here if you didn’t order this.” Treat these the same as Order Confirmation requests. If you don’t deal with the company, it’s a scam. If you deal with the company but haven’t placed an order, it’s a scam. If you are in doubt, contact the company directly, not by replying to the questionable email.
Sometimes, scammers are really REALLY good. They send you an email that looks exactly right.
Real Life Phishing Emails (Well, Screenshots)
What do good phishing emails look like? Here are a few examples of actual phishing scam emails sent to SiteGround customers.
Scam emails examples
Apart from all the red flags already covered above, the ‘from’ email address of these emails is not a valid SiteGround email. What is more, a proper SiteGround email would never mention the payment method used by you to pay for the service in question.
If you’re a SiteGround customer who comes to report such emails, SiteGround would ask you to send the whole email as an attachment, as they use it to train their own systems to block such emails (in case your email is hosted with SiteGround), so that they do not reach your inbox. In case your email is not hosted with SiteGround, you can mark it as spam in your email provider.
To learn more about how to stay safe from phishing email attacks, check out the blog post on this topic.
How Do You Stay Safe from Email Scams During the Holidays?
So how would you tell if this was a scam email? Well the easy answer is to “practice safe email”. Here are a few of the things I do before I click a link on an email, any email.
Check the ‘from’ address. We’ve already done this but so very many phishing emails come from implausible email addresses. Most scammers don’t bother to try and hide it because so few people pay attention. A recent phishing attempt sent to me purported to come from NetFlix. However, the email address was XXX@yahoo.jp. Yes, Yahoo has a Japan domain but they don’t send email for NetFlix from it! Not even to Japanese customers.
A good rule of thumb is if you were not expecting an email from someone, even a family member or friend, treat it as suspicious until you know it was actually from them. If you don’t recognize the person it came from, then automatically assume it is malicious until you can prove otherwise.
Check all links before clicking. Most email clients these days will let you hover over a link that says “Click Here” (or wherever) and see what the actual URL is. Read it VERY CAREFULLY. Pay attention to the domain name. https://goog.le is not the same as https://google.com. Read it carefully. If it looks suspicious, do not click it.
Some email programs will show you the link in a popup when you click it and ask for verification before it actually opens a browser to that link. If your email program will do this, by all means turn this feature on. Yes, it adds an extra step before you can see that precious baby picture your friend sent you, but it allows you to make sure that you are actually going to see a baby picture and not install malware on your computer.
Do not automatically download attachments Your email program should be set to not automatically download attachments. This means that if you download something from an email, you will have to do it on purpose. If the email doesn’t seem right or fails any of the checks we’ve discussed here, don’t download anything. Even things like Microsoft Word documents which seem innocuous (click here to see the invoice for the service you didn’t order) can do malicious things if you open them. If you weren’t expecting someone to send you an email attachment, don’t open it!
Read The Headers Ok, this is for the hardcore email nerds out there but those of us who have been doing this a while can discover a lot by reading the headers that come with every email. These days email programs hide the headers from you but they are there if you want to read them.
Listen to your gut My wife, The lovely and talented Kathy, got an email from our worship pastor one day with the subject line “I love you”. She was good friends with this man and while the subject line confused her, it also piqued her interest. She opened it only to find that there was a malicious script attached to the email. It deleted about ½ of the images we had stored on our home server before I could stop it. Thankfully, I had a backup so there was no loss, other than the hours it took to clean up the mess. Had she simply called him, opened a new email and written him at the address she had in her contacts list, or contacted him in any of a half-dozen other ways, she could have found out that it was not from him but was a scam. Instead of trusting her gut, she opened the email.
Other Black Friday Scams To Be Aware Of
Email is by far the easiest way for bad actors to get unsuspecting people to do bad things. However, there are a couple of other ways.
Links to malicious ‘’Copycat websites’’
If you get an email with a link to goog.le, it’s easy enough to spot. However, if you are doing your shopping at https://reallyLongDomainName.com and you misspell it or “fat finger” it (typo), then you might end up at a site that looks exactly like the one you were aiming for.
Bad actors look for common misspellings for profitable domains. They buy them up and put copycat sites up. These are sites that look just like the one you were looking for. They probably even have products and a shopping cart. However, make no mistake, they are scams. When you put in your personal information and credit card number, you are not going to get those purple widgets you ordered that your sister will just love. You won’t get anything but a nasty surprise when your credit card statement arrives.
This is really easy to thwart, if you pay attention.
First, after you arrive at a site, look at the address bar. Is there a little lock next to the domain name?
The little lock means that the domain you are using has a secure certificate and that it is valid. If you don’t have a little lock, or if there is a line through it, that means that either the certificate does not exist, or that it is invalid for that domain. Both of those are really big red flags that you don’t want to do any business on this site or put in any of your personal information.
A SSL certificate isn’t always enough to prove that you are on the right website. Scammers can register sitegroound.com, for example, and install a certificate on it. The certificate just provides encryption in most cases. It’s always a good idea to also double check the URL address, especially when you make payments, create accounts, fill out forms, etc.
Sites impersonating landing or login pages
The final type of website scam we’ll talk about are fake login pages. These might be part of a very good looking fake, or you might arrive at a site only to find that before you can get to the good stuff, you have to enter your login credentials. If this is an ecommerce vendor you normally do business with, or an institution you bank with, stop. Don’t do anything else. Sites like that don’t just put up a login page without letting everyone know well in advance. These are nothing more than “password collectors”.
If you do enter your credentials into the site, they won’t work…because they are fake. But humans are stubborn. You will assume that you mis-typed something…especially if you are using a long and very secure password. So you’ll try again.
If you are like most of us, when it doesn’t work the second time, you will assume that you’ve used the wrong password and you’ll try another password, and another, and maybe even a 4th one before starting to think that something may be wrong.
Every set of credentials you entered have gone into a database and bad people will start using them to try and sign in to any site they think you may have an account on. Since you were giving them real login credentials, you’ve given away the keys to the kingdom.
Be watchful, be alert, be suspicious bordering on paranoid. Make sure before you put any information into a website, you are absolutely sure you are at the right website. Looks can be deceiving.
How to Practice Safe Internetting This Holiday Season
Always be suspicious of unknown or unexpected emails. If you don’t know the person, or even if you do know them but aren’t expecting to hear from them, be suspicious. Yes, your long lost aunt may be contacting you via email with a hotmail.com email address to tell you that she’s leaving you her entire fortune when she dies and she needs you to sign the will, but chances are really good that it might NOT be her. Verify before you take any action.
Don’t click a link in an email until you are absolutely sure you know where it is going and what is going to happen.
Don’t provide your personal information to any site unless you are positive and you know that it is the site you think it is. If you don’t think you are on the right site, close the browser immediately.
Whenever possible, use a Virtual Private Network (VPN) from a reputable provider. I won’t name my Internet provider but I will say that I do not trust them. They have been known to make it easy for bad people to watch the traffic going across their network and pull out information as they see it. These days almost all websites use encryption to make sure that’s not easily done, but it is still possible for people with enough time, money, and determination. So whenever possible, I use a VPN to encrypt my traffic even further.
VPN software isn’t expensive these days, as a matter of fact, if you are a “computer person” you can download, configure, and run your own. I don’t recommend that as it’s easy to get it wrong, but I’ll admit to having done that in the past. These days, I use a commercial VPN that comes with my virus protection. Now, my neighbor can’t see any of my traffic because I’ve got an encrypted tunnel between my network and a server in Miami, FL, USA. (I can choose from about 50)
Don’t use the same password on any 2 websites Look, I know how hard this is. It’s difficult to come up with one secure password that you can remember, let alone the 20-30 you need to make sure every site is different. I suggest using a password manager from a reputable software company. There are a few of them out there. The one I use works on Windows, Mac, iOS, iPadOS, and Android. So, no matter where I am at, my passwords are with me. All my passwords on all major sites are long, random, and unique. If you know one of them, you can’t get into anything but that one service I use it for.
Wrap-up
Stay safe out there this holiday season. Have fun, enjoy the company of family, and if you get an email from me saying that Bill Gates is giving 1 Bitcoin to each person that forwards this email…well, you get the idea.
Last week, we helped you get your website ready for the Black Friday traffic spikes. Now that you’re all set to handle the upcoming traffic, do you know how much of it is real and how much – non-human? According to Statista, in 2022 more than 40% of Internet traffic is from bots, and a significant portion of that is bad bot traffic. This kind of bot traffic hurts your online business and can lead to both financial and conversion losses. Let’s dig deeper into what bot traffic is, why most of it is so harmful, and how to avoid it during the busiest time of the year.
What is bot traffic and why it should be cut down to a minimum
Bot traffic is any non-human traffic that comes to a website or app. Some of it is good, when it originates from SEO crawlers (such as Google crawl bot), commercial, site-monitoring, or feed bots. Needless to say, all of these cause no harm to your site. On the other hand, bad bots come with malicious intent. These can leave spam comments, irrelevant backlinks, weird advertisements, collect private information, reuse your content, perform DDoS attacks, and other malicious activities.
How bad bot traffic affects your website
Bad bot traffic may have different consequences on your website and business, causing multiple damages:
Website security and availability damage
Bad bot traffic hurts your website security and availability. For instance, these massive amounts of traffic to your site are a way for hackers to cause a DDoS attack. During such an attack, the traffic is so massive that the server where your site is hosted cannot handle it. This can make your website slow, unreliable or even unavailable for your users.
Bad bots are also the main force of a brute-force attack – a way to guess your password/login details by trying numerous combinations of letters, numbers and symbols. If such an attack is successful, malicious hackers gain access to your account and/or private information.
Website speed issues
Even if it doesn’t cause massive hacker attacks, bad bots activity can make your website much slower or even unavailable for your real visitors, affecting their overall user experience. To have your visitors stay longer on your site and turn them into clients, you’d want them to have an excellent user experience. A huge part of that is your website loading speed being as fast as possible.
Analytics metrics and SEO rankings chaos
Bad bot traffic can also hurt your analytics metrics and SEO rankings. For example, too much bad bot traffic can bring your site down and cause 503 errors (“site is temporarily unavailable”). This directly negatively impacts your SEO rankings. What is more, bad bots can affect your analytics metrics, causing abnormally high pageviews and bounce rates, sudden drop/increase in session durations, and fake conversions. All these factors may confuse you as a site owner and you may not be able to make sense of your analytics data.
How we decrease bad bot traffic at SiteGround
At SiteGround we take multiple measures at different levels to reduce bad bot activity by default for the websites hosted on our servers, so you can have peace of mind.
Improved and advanced AI anti-bot system
Our AI anti-bot system has successfully been blocking millions of brute-force attempts per day. Recently, we improved it even further, resulting in 95% less bad traffic. Its core features are still there – analyzing and recognizing traffic patterns to eventually stop brute-force attempts. With each new brute-force attempt, the system’s knowledge expands and it gets better at preventing future attacks. As of recently, we’ve upgraded the system with a traffic validation feature that stops even more malicious non-human bots by minimizing the number of brute-force attacks. Currently, the system blocks a huge percentage of bad bots traffic towards our servers, allowing more capacity for your websites for legitimate traffic.
Combined with our enterprise-grade security system, these server-level security optimizations block the majority of all bad bot traffic and ensure website protection on a global scale. Let the numbers speak for themselves – 99,99% of bad traffic is blocked before it even reaches your website.
Smart, server-level WAF
Hacker attacks usually increase during the Black Friday season. A single outdated WordPress plugin, theme, or vulnerability can easily be used for massive damages during this busiest time of the year. That’s where our smart Web Application Firewall comes to the rescue. Our security experts closely monitor security bulletins and server activity 24/7, and in case of reported exploits, immediately add custom WAF rules (patches) into our server firewall to protect your site from current hacks and breaches due to outdated plugins, and other vulnerabilities. Our proactive security approach allows us to react much faster, often before the original plugin, theme or app developers have had the chance to release an official update. The most recent example of this was just last month, with two previous major ones not so far behind – a plugin vulnerability patched on day 0, and a Linux Kernel vulnerability patched within hours of detection.
DDoS protection
To address potential DDoS attacks from bad bots, we have a system of hardware and software mechanisms to protect your sites:
A hardware firewall that filters flooding traffic;
A local software firewall with more complex functions and traffic monitoring;
А limit to the number of connections a remote host can establish;
A check for a high number of failed login attempts from hosts and filtering them, if any.
24/7 server monitoring system
Again, in addition to all monitoring and prevention systems and checks in place, our expert system administrators team are monitoring our servers 24/7 for any system issues and in case of any, can react quickly to save the day.
How to identify that you have bad bot traffic coming to your site
Now, you probably wonder what are some signs and symptoms of bad bot traffic that will help you identify whether your site is in danger. Here are some of the red flags and ways to prevent them:
Check your site traffic stats
You also need to check your traffic statistics, especially the IP addresses and the sources of traffic. For example, regular and high number of visits from the same IP address or increase in traffic from other regions or countries, from which you didn’t have (much) traffic before, could be an indication of bad bot traffic. As a SiteGround customer, you can easily check your traffic statistics in Site Tools > Statistics > Traffic.
Keep an eye for unusual users’ behavior
Remember to monitor your users’ behavior regularly. In case there are increased spam comments under your posts, strange user registrations, and/or increased blocked login attempts, these are all red flags that you might be getting bad bot traffic to your site. WordPress users, who have the free SiteGround Security plugin installed, can monitor their site and login page for unauthorized visits and brute-force attempts from their Activity Log menu. What is more, they can easily block suspicious IPs and visitors.
Make regular speed tests
You probably already do that, but if you don’t, it’s a good idea to start making regular website speed tests. For this purpose, you can use a number of different tools to measure your site speed, such as Google PageSpeed Insights, Pingdom, GTMetrix, and others that generate results in all the major speed metrics.
In case you have the free SiteGround Optimizer plugin installed on your WordPress website, you can run a speed test within the plugin in its Speed test functionality. The check uses Google PageSpeed, provides information on the level of optimization in over 20 different areas, and gives you optimization suggestions.
If you identify that your site is experiencing page loading speed issues, dig deeper into the problem to find out the causes. These might not necessarily be bad bot traffic issues, but that’s one of the main potential reasons behind the slow speed results.
How to filter bad bot traffic yourself on SiteGround
Some of the traffic that reaches your websites may seem legitimate, even if it’s not. Thankfully, there are a number of ways and free services we offer to let you filter good from bad website traffic all by yourself:
Both options allow you to easily block suspicious or malicious traffic to your website. If you want to block a specific IP address from accessing your site, because, for example, you see it’s using too much bandwidth, you simply go to Site Tools > Security > Block Traffic, choose the domain for which you want to block access, then add the IP address (or a whole range in IP/IP Range), and finally click ‘Block’.
Similarly, if you notice that you get suspicious abnormal activity from a country you don’t usually operate in or have clients from, you can easily block traffic from it in a few clicks. You need to go to Site Tools > Security > Block Traffic > Block Country. There, you choose the domain for which you want to block access, pick the desired country to block in the Country dropdown, and finally click ‘Block’.
These two options will help you not only block bad bot traffic coming to your site, but they can also significantly improve your site performance by reducing the unwanted traffic and giving your site more capacity to handle real human traffic.
Improving your site capacity to handle more requests
In case you’ve identified that your site still gets some bad bot traffic which cannot be easily filtered or removed, you can decrease its negative impact by improving your website speed and performance, which will allow more capacity to handle any type of traffic altogether. Here’s how to do that:
We’ve developed a powerful caching system to help you cache as much content on your website as possible. Cached content is served much faster to visitors and thus improves your site capacity to handle traffic. Our system is comprised of three caching options that are all available in your Site Tools > Speed > Caching: NGINX Direct Delivery for caching static content, such as images and CSS files; Dynamic Caching for dynamic content to be stored in the server RAM, and Memcached for storing data and objects in memory (best for database-driven websites).
Use our other optimization services
We do a lot to improve website performance and you can make use of our premium solutions. Here are three of the main ones that can speed up your website and make room for more visitors’ requests.
Our in-house developed SiteGround CDN requires no configuration, it’s easy-to-manage with just a few clicks, and above all, makes your site load blazingly-fast for visitors around the world. Its Basic version comes completely free of charge and provides your site with all the essential features to handle international traffic from various international locations.
Another in-house developed speed tool is the free SiteGround Optimizer plugin for WordPress websites. It provides you with many different optimization options (media, frontend, environment) that can all be enabled in a few clicks.
Last, but not least, our unique ultrafast PHP setup makes your pages load up to 30% faster and allows the server to process your website’s visits quicker.
Wrap-up
While most people are busy selling and buying goods and services during the Black Friday period, bad bots are also more active than ever, “visiting” websites and causing all kinds of potential issues. If not addressed on time and in the proper manner, they can ruin a big chunk of your holiday conversions during that time of the year, when you worked hard to get the highest number of sales.
Building and maintaining a strong website security is a constant process that often gets neglected by website owners due to its complexity, time consumption and cost. As a hosting provider, we know better. Over 18 years of experience in hosting, maintaining and securing millions of websites has taught us that website security is absolutely critical for every online business. We have seen the devastating consequences a hack can have on a website and ultimately on a business, and we have dedicated serious efforts to preventing and minimizing the effects of hack attempts.
Over the years, we have optimized the security of our platform by developing sophisticated security systems, introducing a variety of security tools, plugins and features, and constantly analyzing and monitoring traffic and patterns to recognize potential threats. While all of this has made us one of the most secure and trusted web hosting providers in the world, we know that platform security on its own, is not enough. The involvement of webmasters and site owners is just as important for properly securing a website. That is why we have compiled a list of the most essential security features you can enable that can make the difference between a hacked website and peace of mind.
Use SSL
Today an SSL is absolutely essential for every website. An SSL certificate encrypts the connection between your visitors’ browsers and your website’s server so that the data transmitted between the two, such as personal information, credit card data, login credentials or else, cannot be hijacked by hackers.
SiteGround clients get free Standard and Wildcard SSL certificates with all hosting plans, regardless of the number of sites. Make sure you have your SSL installed and traffic properly redirected via HTTPS from Site Tools > Security > SSL to ensure the encryption of the connection.
If you have a business website or you’re processing online payments, you may consider our premium Wildcard certificates that come with $10,000 underwritten warranty and a dynamic site seal to create credibility and trust among your visitors.
Protect your login
Your login credentials are a gateway to your account and personal information (and when talking about websites, to your domain, site and emails, too). There are several things you can do to ensure that your login credentials are safe and secure, and that only you or the people you have authorized have access to your website:
Harden Your Passwords
Despite all the awareness created nowadays about weak passwords and the importance of never sharing login credentials with anyone, one of the most common credentials hacking is through guessing or brute-forcing easy-to-crack passwords. Having a long password, consisting of multiple characters and a combination of words, letters, numbers and symbols is an easy and super effective way to keep your accounts secure. Remember to use different passwords for different sites and apps, and never share your passwords with anyone, nor write them on publicly accessible places like post-it notes on your computer! Read more on the topic here.
Use 2-factor authentication
Regardless of how hard your password is, there’s still a possibility for a hacker to get to it through a brute-force attack, virus, malware or other. With 2-factor authentication enabled, a secondary step needs to be passed by anyone attempting to access your data. 2FA adds another layer of authentication, usually through a temporary dynamically generated code (accessible only from your phone or email, depending on the settings), which cannot be guessed or hacked and makes your login defense bulletproof!
For SiteGround Client Area, which is the gateway to your domains and sites, you can easily enable 2FA from Client Area > Login & Profile.
For your WordPress application login, you can install and activate the SiteGround Security plugin and enable the 2FA feature. Download the plugin here, or install it directly through your WordPress admin area.
Monitor your website
Scan for malware regularly
There are numerous ways a website may get infected with malware – through compromised login credentials, infected or fake plugins and themes, corrupted software and more. Malware can have a serious impact on your site and online business. The best prevention for it is a secure web hosting platform and constant monitoring. If you’re a SiteGround customer, you can activate Site Scanner – a service that crawls your website on a daily basis and notifies you of potential malware and other threats. Just recently, Site Scanner helped save thousands of WordPress sites from particularly nasty malware.
Block suspicious traffic
There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.
Back up your site regularly
While backups don’t protect you from hackers directly, they keep you safe from other unexpected events – a site update that may have gone wrong, an infected site that has to be reverted to a clean version, and any other situation where a copy of your website is all you need to bring it back online. We know how often backups can save an otherwise dire situation, so we do automated daily backups of all sites hosted with us and keep them for up to 30 days. You can easily restore your website, files, or databases for free in just a few clicks from Site Tools > Security > Backups.
Take special care of your WordPress
Being the most popular CMS in the world, WordPress is also one of the most popular targets for hackers. While all of the advice above applies to WordPress, there are a few additional things you can do to ensure that your WordPress site is well protected from bad actors and malicious software.
Keep your WordPress up-to-date
Keeping your WordPress up-to-date is essential for your website security. If your site is hosted with SiteGround, we’ve got this covered for you. All WordPress sites hosted with us get automatically updated to the latest stable WordPress version (only after we have thoroughly tested it). Free plugins are also auto-updated, depending on the user settings.
Add an extra safety layer with a trusted security plugin
There are WordPress-specific exploits and vulnerabilities that are best handled within WordPress itself. Some of our best WordPress engineers have developed the (free for all) SiteGround Security plugin that consists of a number of tools and features designed to keep your WordPress safe and secure. It helps site owners to disable XML-RPC if you don’t need it, add XSS protection, protect system folders from being injected with malicious files with just 1 click, and many more.
Avoid common usernames like “Admin”
Your login consists of two pieces – a username and a password. On many occasions, the username is something automatically generated by the platform where you register and you have no control over it, but on others, such as your WordPress application, you are in full control of what your usernames should be. Except, all WP installations come with the user “Admin” by default. And hackers know that, which means they are one step closer to accessing your site! That is why we suggest you disable all Admin users on your sites and create users with different usernames and equal to the Admin rights. You can disable the use of Admin and other common usernames with the free SiteGround Security plugin.
Limit login attempts
A standard behavior of unauthorized users is to try and guess your password (or username and password) on the login form by making multiple consecutive attempts for that. You can easily cut them off by limiting the number of consecutive unsuccessful login attempts they can make. After they reach the set amount, the IP from which they log in gets blocked for 1 hour. Use the free SiteGround Security plugin to activate this feature for WordPress sites.
Use a trusted web hosting provider with a security-first approach
As we mentioned in the beginning, protecting your website is a team effort and on our platform your website’s security is our number one priority. Here we want to recap some of the things we do and in case you are not a SiteGround client, you may want to consider these security essentials for any hosting provider you work with:
Server-level Web Application Firewall
The web application firewall monitors the traffic and blocks the opportunity for hackers to exploit many common application security holes. Although there are many solutions such as WordPress plugins, or third-party services to address that need, a server-level WAF is of utmost importance since it works with big data and real-time. That is why our dedicated Security Team constantly monitors various security bulletins for exploits and vulnerabilities, and immediately creates custom security rules, which they add to our smart and in-house managed Web Application Firewall. It protects all sites hosted with us out-of-the-box.
Brute-force prevention
Siteground has a sophisticated AI-driven bruteforce prevention system that for years has been stopping millions of bruteforce attempts per day (even hour)! And while this on its own is impressive, we recently made it even better. After the recent system upgrade, we have managed to reduce the amount of malicious traffic reaching your site by 95% and thus significantly minimizing the actual bruteforce attempts! No action is required on our clients’ end, they’re already using it. 🙂
DDOS protection
DDOS attacks are frequently used by hackers to bring down sites for different reasons – ransom demands, economical or business competition, political motives or simple vandalism. We have a system of software and hardware mechanisms that divert DDOS attacks, mitigate their impact, and eventually stop them. And the best thing is that you don’t have to do anything – we protect all sites hosted on our platform!
Managed PHP
Keeping PHP up-to-date is essential for keeping your website safe. Older PHP versions are often a gateway for vulnerabilities and malware, and a lot of web hosting providers tend to overlook this in order to make PHP management easier. We have developed a secure managed PHP solution that helps our customers keep their PHP updated to the latest stable PHP version.
On-demand traffic blocking (IP and Geo-Blocking)
There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.
Smart Client Area & Site Tools Login
All SiteGround accounts are protected behind a smart login we have developed to recognize suspicious behavior and enforce additional client verification when an irregular pattern is detected. Our login system learns from your behavior – like the devices you’re usually using or the locations you often log from, for example – and knows whether a login attempt is coming from you or an impostor. In the latter case, a challenge is introduced – one that is easy to pass for the real account owner and very hard for anyone else.
Monthly Security Reports
There’s one more thing that often gets overlooked, but it’s important to include it in your website security strategy. You need to make sure that you keep an eye on your site’s security status regularly, yet this can take you much time, effort, and money. SiteGround clients receive free monthly security reports straight into their inboxes.
We perform automated security checks of our clients’ websites and then provide them with summary results in a user-friendly format, along with actionable tips on reducing the risk of malicious attacks, if we identify any weak areas.
These are the features that are essential for your website security. If you have all of them enabled, we’re confident that your website is well protected and you can have peace of mind that you have done everything in your power to secure your online business. We’d love to hear which of these features you’re already using and which are the ones you just found out about.
How to secure your WordPress website? (Video tutorial)
There is a saying amongst tech companies that if you can’t afford to pay for security, you can’t afford a security breach. The consequences of a breach can be quite expensive in terms of data loss, human involvement, costs for business recovery, reputation damages, and many more. That is why big companies spend millions of dollars to protect their data and spend significant time in implementing and maintaining data safety procedures and security strategies. Naturally, small businesses cannot afford any of that and usually have a limited budget dedicated to security. That’s when and where using the services of a secure web hosting provider becomes critical.
Although web hosts cannot be solely responsible for your website security, the good ones can do a lot to help you stay safe and prevent the worst from happening. Here at SiteGround, we have developed a centralized, enterprise-grade security system to protect our clients’ sites, applications and data. Its complexity has grown over time and describing it in whole can be quite overwhelming, but in this post we’ll give you a glimpse on how we analyze and filter web traffic coming to your sites and how we prevent on a daily basis hundreds of millions attacks to the sites we host.
Effective security-building blocks
All our servers have essential security software installed on them and systems set to work locally per server – a network traffic firewall, Web Application Firewall, IDS/IPS (intrusion-detection/prevention-systems such as brute-force prevention), deep HTTP analysis of meta data, DDOS protection and more. These are classic and very effective means of filtering bad traffic and preventing brute-force attacks, malware injections, denial of service, and more, which we heavily rely on. Under the competent management of our DevOps engineers and System Administrators, these systems are constantly improved and all of them together filter roughly 1 TB of bad traffic and more than 300 million bad requests across our servers daily!
But if those systems operate stand-alone, on a server-level only, the following issues appear: in case a hacker threatens server A, even if the server’s individual security systems can keep the server safe, they can’t stop the hacker from attempting the same attack on servers B, C, etc. To ensure that all of our servers are protected at all times, we have built our Central Security System that constantly gathers and analyzes data from all individual server security systems, and distributes smart security rules that are applied to and protect all machines.
Centralized big data analysis
Our Central Security system relies on the big data it receives from all the other server-level systems and analyzes the various attack sources, detects bigger patterns, and blocks many more attacks globally on the whole platform.
Web Application Firewall Data Feed
As mentioned above, every server has a WAF, whose main responsibility is to protect web applications like WordPress, Magento, Joomla, Drupal and others from a variety of attacks such as cross-site scripting (XSS), SQL injection, and more. The moment we become aware of a security threat (software vulnerability), our security engineers write a new rule to patch it and add that rule to our local WAFs.
Every request that is not dropped at network level, is filtered by the server WAF. If the request is hitting the parameters of a WAF rule, the WAF sends information about it to the Central Security System. The Central System logs and analyzes all requests hitting WAF rules across all our servers (for example their IP and other metadata). If it detects a pattern, like multiple requests across many servers coming from the same IP address, the Central System will block that IP and distribute a rule to all the machines in our infrastructure. Depending on the specific case and the rule, the system may limit the suspicious IP requests to be challenged by captcha or entirely limit the traffic from it to any of our servers for a specific period (hours, days, weeks or even permanently).
Brute-force Prevention Traffic Patterns
As part of our brute-force prevention strategy, we have deployed local monitoring systems on all our servers. They monitor the login attempts to all applications hosted with us and report every failed one to the Central Security System. The system is notified of the attempt along with all important security information related to it, like an IP address, number of requests, IP history and more. Every 60 seconds the Central Security System reviews the aggregated data and analyzes the volume and frequency of repetitive metadata looking for patterns. When patterns are clearly identified, the system creates blocking rules that are distributed to all servers.
An example of this would be multiple failed login attempts on one or more servers, coming from the same IP address within a short period of time (different time thresholds are set for higher precision and effectiveness). In a case like this, our system would flagg the IP and the future requests coming from it towards any of our servers would be challenged with captcha.
Many more systems send data to our Central Security System
There are many more ways we feed our Central Security System with data – like monitoring login attempts to a server-level services like FTP, EXIM, Dovecot, etc; reviewing XML-RPC traffic of WordPress sites; inputting different traffic patterns from third-party systems, and more.
The more relevant data sources we input, the bigger the pool of data becomes, which significantly improves the analytical power and accuracy of the Central Security System. Over time the System’s capability of effectively preventing attacks grows bigger and bigger.
Enterprise-grade Protection on a Global Scale
And to wrap it up, here are some numbers that can help you understand the scale and effect of what the Central Security System does. On a daily basis over 260 million requests are challenged with captcha and less than40,000 actually pass the challenge. We have more than 50,000 IPs currently flagged as bad or suspicious and nearly half of them are completely blocked from reaching our servers. The number is changing daily, as new IPs are flagged and challenged due to suspicious activity, while previously flagged ones get cleared after successful verification or ban expiration.
All of these numbers and the comprehensive work involved in maintaining an effective Central Security System lead to the number that matters most – 99,99%of bad traffic blocked before it reaches your website.