
The premise of ecommerce website security is straightforward: have the trust of your customers in place before any hiccups occur. A properly secured online shop will see off criminals from payment data, stock systems and staff accounts, all the while allowing a customer to make a purchase without being put through the wringer.
Nicholas Fairchild here. After the time I have put in with small businesses one learns that security is viewed much as a dripping tap is, something to be put off until the kitchen is flooded. Fortunately there is no need for a bunker or an odd server room; the bulk of what can be done is within reach and does not break the bank.
Build Trust Before Checkout
An online store visitor forms an opinion in a hurry. If they are met with a clunky checkout, a curious payment screen or some security warning that is not right, they will be gone before delivery options come up. That is why building Sydney ecommerce sites requires a smooth, trustworthy journey.
Ordinary Australians want some assurance as to where their money and information is headed. So security is as much about a transparent, predictable buying experience as it is to keep hackers at bay.
Protect All Customer Touchpoints
You would do well to look after the obvious ones first: the site itself, the help desk, email marketing, the checkout and any delivery integrations. Leave a staff account with an antiquated password and open access and a criminal has no need to trouble your main website.
Have HTTPS on every page, not just for payments. Make sure your domain certificate is set to renew on its own or someone is on the case of it; browsers have a way of making an insecure page look suspect and the customer is entitled to be cautious.
Where you can, go with a payment provider of repute who is configured correctly. There is no reason for your store to be in possession of full card numbers or security codes. The less sensitive data you have on hand, the less there is for a criminal to make off with.
Put Privacy in Plain English
Let your customers know what you are collecting and for how long. A notice written in plain English will serve you better than a wall of legal verbiage that not even the one who put it up will read.
Take only what is needed for the order. An Australian may give you his name, address and so on but that is no licence for your business to hold on to personal information of any kind in perpetuity.
Make certain you are in compliance with the privacy obligations in Australia and what might be required by way of notification in the event of a breach. The person in charge of incident planning should have the Australian Cyber Security Centre’s business guidance to hand.
Get to the Weak Spots
Costly tools do not make for the safest site. What matters is the owner is aware of what he has, who has access and what the plan is if something breaks.
In my line of work I will find the forgotten doors before I suggest putting in new locks. I have seen enough of the usual suspects: old admin accounts, a shared password, an integration that has been left to its own devices.
Make a Map of Your Systems
Put together a map of your operation: host, registrar, CMS, payment and email services, analytics, accounting and inventory software, the devices your staff use to run the store.
Note down who is responsible for each and the means of multi-factor authentication. Put these details in a secure password manager, not some spreadsheet with “Important Passwords Final Final 2” for a title which is hardly reassuring. Do a review of access every quarter or when a contractor or agency departs, and get rid of accounts that are no longer of use. Each person should have a login of his own for proper traceability.
See How the Customer Journey Works
Put yourself in the position of a customer and run a test order from a device of the like. Go through the address bar, the hand-off to payment, the confirmation and password reset. Do it over a mobile connection too, since many will be doing their shopping from a phone whilst they wait for a coffee.
Examine the account pages and emails for any leaks of information. A receipt ought not to be giving away more than is called for and a password reset link should have an expiry date. Try a few wrong passwords and see what the system makes of it; it should put the brakes on repeated attempts but not put a genuine customer out of commission for good. You do not want security to be the cause of a customer-service riot, however you dress it up.
Staff Access and Secure Accounts
A weak password is still the easiest point of entry for an online business. But with good account controls in place, the shop is shielded from the occasional error, a reused password or that dubious email one might be tempted to open after a poor night’s sleep.
Enable multi-factor authentication on all your accounts: payment, hosting, domain, email and administrator. A security key or an authenticator app provides proof of identity that a password by itself cannot.
Least-Privilege Permissions
Restrict users to what is necessary for their role. There is no reason to let the person who puts together product descriptions alter the payment settings, nor should a contractor working on the theme have access to customer exports.
High-privilege administrator accounts ought to be kept apart from those used for day-to-day tasks. In the event a routine login is taken, it curtails the harm and you are less prone to make an inadvertent change.
Sharing of administrator credentials is not advisable. With individual accounts there is accountability; with shared logins you can never be sure who has put their hands on a setting or a customer file, which complicates any investigation without making the office feel like a police station.
Training Staff on What They Will Encounter
Make training about real world scenarios. Put before them a spurious delivery message, an email purporting to be a password reset or an unanticipated login alert and show them how a genuine request is made and the proper way to put in a report.
A once-a-year lecture is forgotten by lunchtime; better to have brief refreshers. And make it simple to come forward without fear of blame. If staff think they will be made an example of they will conceal their errors and give an attacker the run of the place.
Software and Payment Safety
Even when things are running smoothly, a patching regimen is called for for server software, integrations, extensions and the website platform. Old software has its well-publicised vulnerabilities.
Do test important functions after an update and be sure a backup is in hand first. It is a lot more cost effective to do a five-minute checkout test than to find the payment button does not work in the middle of a campaign.
Staging and Patching
If the platform has a staging environment, put it to use. Make a test order, see what the customer emails look like and apply the updates there. Absent that, time it for when trading is slow and have a plan to roll back.
Get rid of any software the store has outgrown. An extension left in place and forgotten can be a security and maintenance headache even if disabled.
When the project is done, ask your developers or service providers what their protocol is for emergency fixes and security updates. For Sydney ecommerce sites you are building, the handover should include ownership of the source code, backups, domains, hosting and administrator accounts.
Limiting Exposure of Payment Data
There is no need to hold on to full card details in case they are of use down the line. Retain only the transaction data you must for legal reasons, refunds, reconciliation and so on.
Where you can, have different accounts for payment administration and refunds. Be on the lookout for oddities in the form of unusual refunds, orders to high-risk locations, a sudden switch in bank details or failed payments and set up alerts for them.
An order with a number of red flags – a new account with a throwaway email, a large value, billing and delivery that do not agree, or multiple failed attempts at payment – warrants a manual review. Keep it consistent and fair, however; fraud prevention is no justification for regarding every customer as a bushranger.
The Value of Backups
In themselves a backup is no security strategy, yet it can mean the difference between a long afternoon and putting the business out of action. The question is can you restore it?
Have several copies in a location of their own and do not leave them open to the kind of credentials an ordinary administrator would have. If one login allows an intruder to wipe the database, the site and the backups, then the whole plan is for show.
What to Restore and at What Cost
Put on record the priority list for restoration, be it the catalogue, the website, domain records or staff email. Also document who has the authority for an emergency change and who is to talk to customers in the event of an outage.
From time to time put the backup through its paces. If it is incomplete or will not open or takes forever to restore, it is not much of a safety net.
| Security Area | Practical Check | Indicative Planning Cost |
|---|---|---|
| Website protection | HTTPS, malware monitoring, restricted admin and updates | $0-300 a year for the basics, setup permitting. |
| Access control | Individual accounts, a password manager and MFA | Service dependent, $0 to $30 per month per user. |
| Backups | Tested and separate | For a small store this will run $10 to $150 monthly. |
| Security review | Independent assessment of configuration and vulnerabilities | For a small business this runs in the region of $500 to $5,000. |
| Incident recovery | Technical investigation, restoration and dealing with customers | Expect to put down a few thousand dollars for that, more for anything complex. |
Consider these numbers as budgeting guides rather than quotes. The ultimate price tag is subject to change depending on your hosting set up, what software you have opted for, the volume of sales and data, and whether there is expertise in house.
Preparation for a Cyber Incident
Phishing, a wayward supplier or unauthorised access can befall even the most circumspect of businesses. Being prepared allows one to remain composed when it is found that no one has the hosting password.
Put together a brief incident plan, with a copy stored offline or otherwise protected. It should have current contact information, spell out who is responsible for what and be written in plain terms.
Keep a simple checklist for response
- Start by ascertaining the facts and putting aside any logs, email, screenshots or records of transactions.
- An account or system under threat should be put in check but do not obliterate evidence in the process.
- Reach out to your security, payment and hosting providers by way of verified channels.
- Any credentials that are exposed must be changed and active sessions, tokens and third-party access revoked.
- See if any personal or payment details have been made off with.
- Be candid with your customers and take professional counsel on your notification obligations.
Under no circumstances should a device be wiped or the site rebuilt before the events are put on record, it is better to leave the evidence. In the event of fraudulent transfers, make prompt contact with the bank and put in a report via the proper Australian channels.
Focus on the Metrics That Count
One should be tracking such things as how many administrator accounts have multi-factor authentication in place, how old the oldest unpatched part is, the time taken to restore a backup and the number of superfluous accounts put to rest.
According to the national reporting from the Australian Cyber Security Centre, a case of cybercrime is put on the books some six minutes apart. Not every scam or attack is reported, but for a small online store it is a matter of normal business hygiene to be ready.
Setting Priorities
The security programme called for by an ecommerce operation is not a one size fits all. A marketplace with years of high value transaction data and customer accounts faces other risks to a small shop with a limited inventory.
Concentrate on controls that mitigate the risks that are both damaging and likely. An assessment of some cost that is not well understood is not worth as much as a good backup and a secure password manager.
When You Have a Day
Multi-factor authentication should be turned on for the primary email, website admin, domain and payment accounts. Do away with any former staff or unused third-party access. Put in a test order to see if HTTPS is working over the whole shop, verify a recent backup is to hand and know who to call in the event the site is down.
Have a look through your inbox for any login alerts or payment changes of which you are not aware. If something does not sit right, put routine changes on hold and get in touch with your provider to find out why.
For Those Requiring Assistance
If you cannot account for where customer data is held, or your store has had an incident, makes use of a lot of integrations or is processing large orders and volumes of personal information, specialist advice is in order.
And for a business without technical people, help with patching and access reviews is advisable. A misstep could mean lost orders or trading being put on hold; it is not an area for beginners and in the end professional support is less expensive than to learn from an actual incident.
What Owners Ask
With each vendor touting its wares as the answer, security guidance can be hard to make sense of. What follows are the decisions of consequence for an Australian online shop. They are a practical way to begin but no replacement for legal or technical advice for a high risk concern.
Is an online store covered by HTTPS?
It is basic protection, nothing more. While it will encrypt the traffic between the site and a customer’s browser it will not stand in the way of poor data handling, an outdated piece of software or a weak password.
Multi-factor authentication for a small store?
You would be well advised to have it for your email, domain, hosting and so forth. There may be fewer eyes on suspicious activity at a small store yet they have valuable payment access and are therefore a target. Multi-factor authentication takes the utility out of a stolen password.
Is there any point in retaining customer data indefinitely?
Not unless there is a sound operational, legal or business reason to do so. Once it is not needed, de-identify or delete it. Otherwise you complicate the management of privacy and give a breach more of an impact.
Will a backup of the website thwart an attack?
No, it is for after the damage is done. Backups need to be used in conjunction with an incident plan, monitoring, patching and strong access control.
How frequently to review security?
At least once a quarter for backups and access. Any time you have a major change to the site, new staff or a payment method is added, the whole setup warrants a look. And if you get an unexpected alert from an account or a supplier is breached, do not delay in investigating.
Trading and Security
In Australia an ecommerce site’s security is not something you install and forget. It is a routine: you patch the software, limit who has access, safeguard payment information and make sure you are in a position to handle the inevitable.
Tackle the systems and accounts that are a risk to your trading or your customers’ information first. Make one improvement here and there and document it so those using it can follow along. A small store in Australia is then a safer place to do business and one from which to recover with less trouble.