Consequences of Data Breach

Turtle54

Free Member
Jul 14, 2015
3
0
Hi there,

I've considered launching an online service based on WordPress. I have a considerable amount of knowledge in this field, and plan to take steps to prevent unauthorised access to sensitive areas of the site (such as databases).

However, it seems that we can't go a few days lately without hearing about large firms having data breaches. As a small, not-for-profit organisation, this leaves me feeling rather vulnerable as I obviously don't stand a chance against hackers if the 'big guys' can't even thwart them.

So then I got to thinking... What if this happened to me? What would happen? Would I be liable for my site getting hacked? Speaking hypothetically of course.

I don't plan on storing overly sensitive information, just email, username, password (hashed) and possibly country. Other than using UK-based PCI compliant servers with CloudLinux, numerous firewalls & fancy HTACCESS rules, CloudFlare, site-wide forced SSL, and encouraging good password etiquette... I don't think there's much more I can do to prevent intrusions. It's just something that's worried me and hindered me from creating this site.
 

ryedale

Contributor
Free Member
Dec 17, 2013
1,554
369
50
Malton
What you have to take into account is the hackers who do the big companies are the very best hackers in the business with a vast amount of tools and knowledge and the rewards of getting in make it worthwhile

So long as you keep your Wordpress and plugins up to date, then the average script kiddie in his bedroom isn't going to to go extra effort to get into your site, he'll just go to a softer target - it's like a burglar choosing the house with the open window ahead of the one with windows locks
 
  • Like
Reactions: Turtle54
Upvote 0

Sam@UTS

Free Member
May 7, 2014
24
8
Plymouth, Devon
Ryedale is right, its important to view any security precautions you take in the context of the threat level that you are likely to be exposed to, which in the case of a normal WordPress site is somebody looking for known vulnerabilities.

Make sure your site and plugins are patched and that you use SSL where necessary, non-default usernames and complex passwords and you should be fine!
 
Upvote 0

Latest Articles