
Operationalizing Secure by Design: a CISO’s guide to closing the gap between policy and reality
We’ve been listening to dozens of CISOs. In roundtables, peer forums, customer and prospect calls, on the record, off the record, at event floors and …

Once your business goes live online, you’re vulnerable to mayhem. Detectify’s CEO Rickard Carlsson explains why web security matters and how you can protect your organization on the internet.
The Internet is broken, from a security point of view, and most organizations are vulnerable to attack. You need to figure out how vulnerable your business is, and find the best way to protect your information online. Web security is a long-term commitment that can protect your customers and brand, and keep your website safe from hackers. If you’re running an online business, you need to make security a habit as soon as possible.
To get started, let’s clarify three common misconceptions about web security.
Most hacks are automated and do not target specific organizations. They’re designed to spread malware via your site, send a political or commercial message, carry out an advertising scam, or some other malicious activity. Hackers don’t care about you, specifically. But if they’re successful, the damage will hurt your brand and give you unnecessary clean up work. It is increasingly common for hackers to attack multiple organizations without a specific target in mind, so your website could be at risk even if you think you have nothing of value to steal.
Third party services are vulnerable too and can cause a great deal of damage if they’re hacked. For instance, poor use of JavaScript on a third party service or a plugin could compromise the security of your complete domain. This includes your blog (blog.yourdomain.com) and your general website (support.yourdomain.com).
Unless you asked for a security assessment or safe development, you’re not safe. Even if an agency is taking care of your development, your business can be compromised. What can happen? A potential attacker might try to steal information, or use your site for illegal activities or to spread harmful code. Or the hacker might encrypt all your data, just for fun.
Hackers can replace your site with just about anything, like Viagra ads or changed board member information for new visitors while you still see the original information. Customer data can be obtained and leaked from sites with user login and profiles, and if you are using SaaS service and web-shops, hackers can impersonate a user on your system and trigger actions or complete a purchase.
This might leave you feeling a bit depressed, but don’t give up yet. Here’s what you can do to improve your security through automated tools and professional services dedicated to protecting your business:
Start protecting your systems today and make security a priority. Make sure no stone is left unturned and run security scans on a regular basis.

We’ve been listening to dozens of CISOs. In roundtables, peer forums, customer and prospect calls, on the record, off the record, at event floors and …

For years, development and security practitioners have treated dynamic application security testing as a critical final safety check before code goes live. However, the external …