Drupal security is one of the few parts of the open source CMS world where the published process is better than the platform’s reputation. The Drupal Security Team runs a fixed disclosure schedule, scores every advisory on a documented numerical scale, and coordinates fixes across core and tens of thousands of...
Web Security
Articles, guides and tutorials on web security, covering OWASP Top 10 vulnerabilities, secure headers, injection prevention and protecting web applications.
Password storage is one of the few areas in software with a genuine right answer, published, maintained and free. It is also one of the most consistently got wrong, because the wrong answers were correct at some point and nobody revisited them. The failure is rarely exotic. It is a system built in 2016 against advice...
Supply chain security sounds like a problem for organisations with a security function, and the framing is misleading. A small team running a handful of services typically depends on hundreds of packages it has never read, pulled at build time from registries it does not control, executing installation scripts on...
Whether to block AI crawlers is presented as a technical question and it is not one. Blocking them is a few lines of configuration that takes ten minutes. The hard part is deciding whether you want to, and that decision is commercial: you are choosing between protecting content from being trained on and being present...
Most teams treat API security as an authentication problem. They add tokens, check them on every route, and consider the job done. Then a tester changes one number in a URL and reads another customer’s invoice. That gap between “authenticated” and “authorised” is where the majority of real API breaches live, and it is...
If your WordPress site was hacked and is now showing pharmaceutical spam, redirecting visitors to somewhere unpleasant, or has been flagged by Google as deceptive, start here rather than with a plugin. The instinct is to install a security scanner and click clean. That removes the visible symptom and leaves the way in,...
Migrating to Cloudflare Zero Trust is a critical modernisation step for enterprises looking to replace outdated corporate VPNs in 2026. Traditional VPN networks grant users broad access to the entire corporate subnet once they pass the initial login wall, so a single stolen employee credential lets attackers pivot...
Securing Cyber Essentials compliance is a major step for UK businesses looking to protect their server networks in 2026. This government-backed scheme helps companies demonstrate their commitment to data security to public sector buyers and enterprise clients, and maintaining these baselines blocks up to eighty percent...
Determining your website security audit cost is a critical risk-management step for UK enterprises aiming to protect customer databases in 2026. Data breaches expose companies to hefty fines under compliance rules, alongside severe damage to brand reputation. Regular security audits guard your business against...
Calculating the cost of penetration testing in the UK is a vital compliance task for enterprises planning cyber security audits in 2026. With business transactions shifting online, maintaining strict application security is critical to protect sensitive client databases and avoid expensive regulatory penalties....