Explanatory publication Four textsNo scanning, no auditsNothing for sale

WebOps DeskSite security, plainly
Frequent questions

Questions that keep coming up

About what this publication covers and, more importantly, what it cannot do.

List of questions

Do you scan sites or sell security software?

No. We do not scan, test or audit websites, we do not sell or operate software and we take on no client work. This site publishes freely readable explanations of how these mechanisms work and where they fail.

Do you recommend particular tools or providers?

No. We name no products and compare no vendors. What fits depends on your stack, your traffic and who maintains the site. We describe what a tool has to do and which questions to ask before relying on one.

My site has been hacked. Can you help?

No, and please do not send us details. We cannot assist with an active incident. Contact whoever hosts or maintains the site immediately; if personal data may be involved, there are notification duties with short deadlines and you should get qualified advice straight away.

Is any of this a substitute for a security review?

No. These texts explain concepts and common failure modes. A real review looks at a specific system, with access to it, by someone qualified to do so. Nothing here replaces that, and nothing here should be read as certifying that a site is secure.

Why are there no scan frequencies or severity thresholds here?

Because the right answer depends on what the site does, how often it changes and what it holds. A schedule that suits a shop processing payments is wrong for a brochure site that changes twice a year. We explain what determines the answer instead of printing one.

Where to go

Each situation to its own place

  • An active incident: whoever hosts or maintains the system, immediately.
  • Possible exposure of personal data: the Dutch Data Protection Authority publishes the notification duties and deadlines; get qualified advice the same day.
  • Practical security guidance: the National Cyber Security Centre, which publishes material for organisations.
  • A security review of your system: a qualified assessor with access to it.
  • Certificate or hosting configuration: your hosting provider, in writing.