Data in motion vs data at rest: protecting the customer data in your WordPress site

I have had a few conversations about data privacy and encryption with customers recently, and it was interesting to see first hand how little thought is given to the customer data stored in their WordPress sites. I am not talking about backups or protecting against data loss. This is about data privacy and the legal obligation companies have to take reasonable measures to protect customer information.

The core concept I want to cover is “data at rest vs data in motion”, followed by some action steps you can take to secure the customer data you are storing.

Data in motion (data being transferred or transmitted)

Data in motion is data that is being transmitted or transferred. Data at rest is data that is being stored.

A lot of attention is given to data in motion. Almost anyone running a website is aware of SSL certificates and HTTPS and securing data to and from a website while it is being transmitted. 99.9% of our customers will have this box checked, as SSL is easy to implement with the free certificates provided by all web hosts.

As well as ensuring your site is using HTTPS, make sure HSTS is enabled too. HSTS stands for HTTP Strict Transport Security. With it enabled, the browser will only connect to the website using an encrypted connection, which helps enforce security and may give you some speed and potentially an SEO boost. You can enable it easily using Cloudflare; here is a blog post and video that walks through setting it up, and I have gone deeper on it in how HSTS reduces TTFB. This HSTS checker will tell you whether you have it enabled.

Data at rest (data being stored)

In comparison, I am guessing you have given little to no consideration to the customer data you are storing in your website. Based on my conversations with customers over the last 10 to 15 years, probably only 1 to 2% of our customer base has thought about this in any detail.

Broadly speaking, any data apart from logon information and credit card details is not encrypted when it is stored in your WordPress site. This includes form data and any attachments uploaded as part of forms.

The attachments present another problem: typically they are publicly accessible if you can find the URL for the file. So not only are these files not encrypted, they are not really protected from being downloaded either.

Years ago we had a security guard company taking online job applications through their website. Their WordPress site had thousands of drivers licences and passports saved, unencrypted, in their Gravity Forms upload folder. That is a huge risk, and if those documents were exposed as part of a hack it would objectively be considered negligent in a legal context.

Action items

1. Review the data you are collecting and storing

As a first step, work out what customer data you are actually storing. If you are storing customer data in your website then you need to give some consideration to the security and privacy of that data.

Some industries, like healthcare, have very specific guidelines on how customer data is handled, and the apps and software you use to handle that data need certification or compliance. For example, healthcare software in the US must be HIPAA compliant.

2. Encrypt sensitive form fields

Many of the popular WordPress forms plugins (we recommend Gravity Forms) can encrypt form fields. Encrypting any sensitive customer data is a good start, as it ensures the data isn’t stored in the WordPress database as plain text.

If you are using Gravity Forms there are a handful of add-ons that do this, one from Plugin Owl and another from Crosspeak.

3. Gate uploaded files behind a logon

If customers can upload files into your WordPress site via forms, you need to think about those files. At a minimum we’d recommend gating them behind a logon so they are not publicly available to the internet, meaning you need to be logged into WordPress to download them. Gravity Forms can do this out of the box; more information here.

4. Use two factor authentication (2FA) for WordPress logons

None of the above matters if an administrator level password for your website gets compromised. Recently a customer on our WPAlpha hosting platform was “hacked” because their offshore developer’s logon details were compromised. That technically isn’t a hack if an attacker can simply walk through the front door. If the customer had 2FA in place it would not have been a problem.

For most customers we recommend the free version of Wordfence for security at the WordPress site level. Wordfence’s two factor authentication feature works really well here.

5. Encrypt the files you are capturing

If the files you are capturing are sensitive, like the passport and drivers licence scans in the example above, ideally you want to be encrypting them. Consider offloading file storage to Amazon S3 or another cloud storage service that can be encrypted. Amazon S3 supports encryption natively and can be coupled with Gravity Forms so that files uploaded through forms are encrypted. The how-to is outside the scope of this article and is definitely something to use a developer for.

6. Regularly prune and archive data

Most customer data captured through your site has a shelf life. Putting processes in place to regularly prune form data, and particularly files captured from customers, reduces the surface area of the data you are storing on their behalf.

HTTPS is table stakes. The real exposure for most WordPress sites is the data sitting at rest in the database and the uploads folder. Work out what you are storing, encrypt or gate the sensitive bits, lock down your logons with 2FA, and delete what you no longer need.

This article was first sent to the WP Speed Fix email list. If you would like tips like this in your inbox, you can subscribe here.