SlideShare ist ein Scribd-Unternehmen logo
1 von 24
Google, Cybersecurity
and You: Being
security savvy as an
SEO
Chris Spann | Deepcrawl
@marqueetag
Who Am I?
1
2
3
4
Hi, my name is Chris!
I’ve worked in SEO for nearly 15 years
I have an unhealthy interest in breaking
things and making things do things they
aren’t supposed to
I’m a member of the Professional Services
team at Deepcrawl, working with some of
the biggest websites on earth, finding,
diagnosing and fixing issues from the really
really mundane to the really really weird
1
2
3
4
60% of Small Businesses
close within 6 months of a data breach
Why should I be concerned about security?
😞
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
Why should I be concerned about security?
👤
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
You don’t have to be targeted
to be a victim of malicious activity, just vulnerable
Why should I be concerned about security?
🤷
♂️
Disclaimer:
I am not a security expert!
I’m just an SEO who is either cursed or blessed
with the ability to find these things.
This talk is about preventing issues where
possible, and learning how to find problems to
report to your Secops/Dev teams
Disclaimer:
So what can I do?
SEOs have a unique view of websites
Three Ways You Can Provide Security Benefits
Three Ways You Can Provide Security Benefits
Prevent risks
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Identify Malicious Activity
both successful and attempted
Robots.txt
● Robots.txt is a great way of keeping Google out
of folders and files you don’t want it getting into
● But consider whether you want to announce their
existence to the whole world
Robots.txt
● Instead, consider using the X-Robots-Tag header
to prevent indexation and limit crawling if you don’t
want the urls known - or better yet, block non-
verified visits
● As an aside, if you allow UGC, consider what could
happen if a user is allowed to create a robots.txt slug
Google Alerts
● Set up an alert for ‘site:github.com “[your-website.com]”’
● Catch devs accidentally storing private
keys etc in public github repos
● Catch other nefarious actors who might
be targeting these domains with scripts/code
Google Alerts
● Keep an eye out on what shows up for an image
search for your brand - what can you see in the
background of office photos from news stories?
● This also applies to social media -
has your new starter taken a photo
of their pass?
Crawl Your Site As Google
● This will help you see if your site returns anything
weird or untoward when it thinks you are not a
“normal” user
● Don’t worry too much if the crawl crashes! Your
security team might already be one step ahead
Monitor your SERPs
● Wordpress sites in particular are susceptible to
compromise due to their off the shelf nature
● A famous hack, known as “The Pharma Hack”
(Recently overtaken by “The Japanese Keyword
Hack”) can serve spammy content to Google -
but not to users
Question Things That Look Weird
● Look into outliers - go down rabbitholes,
● and always think laterally about how or why
something has ended up a specific way
● Just because something says it’s Googlebot,
don’t believe it on face value
Question Things That Look Weird
● Look into outliers - go down rabbitholes, and
always think laterally about how or why
something has ended up a specific way
● Just because something says its Googlebot,
don’t believe it on face value
Search Console
● Search Console will straight up tell you if Google
believes your site has been compromised
● Keep an eye on all those subdomains that are no
longer used - a malicious actor can tank an entire
domain’s traffic by 90% via DMCA takedowns
● Make sure the owner inbox is monitored
Summary
● Get to know your site
○ How big is it?
○ What do your SERPs look like?
● Be vigilant of change - especially changes you
haven’t made
● Set up alerts
● Automate crawls
● Spend time in Search Console!
● Anything you really don’t want Google or users
to find should not be in your robots.txt
● Go down rabbitholes, ask questions, investigate
anomalies
Thanks for Coming.
Resources: https://linktr.ee/chrisspann
Chris Spann, Senior Technical SEO at Deepcrawl
@marqueetag

Weitere ähnliche Inhalte

Was ist angesagt?

How To EAT Links.pptx
How To EAT Links.pptxHow To EAT Links.pptx
How To EAT Links.pptxDixon Jones
 
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing PagesAreej AbuAli
 
Kleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdfKleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdfKleecks
 
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...Tevfik Mert Azizoglu
 
How to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjectsHow to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjectsKat Nicholls
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volumeLiraz Postan
 
The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker ReneHarris7
 
Data Driven Approach to Scale SEO at BrightonSEO 2023
Data Driven Approach to Scale SEO at BrightonSEO 2023Data Driven Approach to Scale SEO at BrightonSEO 2023
Data Driven Approach to Scale SEO at BrightonSEO 2023Nitin Manchanda
 
Brighton SEO Talk HS FINAL.pptx
Brighton SEO Talk HS FINAL.pptxBrighton SEO Talk HS FINAL.pptx
Brighton SEO Talk HS FINAL.pptxHarry Sumner
 
Google Sheets For SEO - Tom Pool - London SEO Meetup XL
Google Sheets For SEO - Tom Pool - London SEO Meetup XLGoogle Sheets For SEO - Tom Pool - London SEO Meetup XL
Google Sheets For SEO - Tom Pool - London SEO Meetup XLTom Pool
 
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successBrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successDylan Fuler
 
How to get more traffic with less content - BrightonSEO
How to get more traffic with less content - BrightonSEOHow to get more traffic with less content - BrightonSEO
How to get more traffic with less content - BrightonSEOAnna Gregory-Hall
 
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika Höller
 
How to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google DiscoverHow to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google DiscoverFelipe Bazon
 
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDX
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDXThe most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDX
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDXAleyda Solís
 
Product, service and category page links (and how to get them) - Rebecca Moss...
Product, service and category page links (and how to get them) - Rebecca Moss...Product, service and category page links (and how to get them) - Rebecca Moss...
Product, service and category page links (and how to get them) - Rebecca Moss...Rebecca Moss
 
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...LazarinaStoyanova
 
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdf
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdfBrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdf
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdfSteven van Vessum
 

Was ist angesagt? (20)

How To EAT Links.pptx
How To EAT Links.pptxHow To EAT Links.pptx
How To EAT Links.pptx
 
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages
[BrightonSEO 2022] Unlocking the Hidden Potential of Product Listing Pages
 
Kleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdfKleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdf
 
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
 
How to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjectsHow to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjects
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volume
 
The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker
 
Data Driven Approach to Scale SEO at BrightonSEO 2023
Data Driven Approach to Scale SEO at BrightonSEO 2023Data Driven Approach to Scale SEO at BrightonSEO 2023
Data Driven Approach to Scale SEO at BrightonSEO 2023
 
Brighton SEO Talk HS FINAL.pptx
Brighton SEO Talk HS FINAL.pptxBrighton SEO Talk HS FINAL.pptx
Brighton SEO Talk HS FINAL.pptx
 
Don't be a cannibal
Don't be a cannibalDon't be a cannibal
Don't be a cannibal
 
Google Sheets For SEO - Tom Pool - London SEO Meetup XL
Google Sheets For SEO - Tom Pool - London SEO Meetup XLGoogle Sheets For SEO - Tom Pool - London SEO Meetup XL
Google Sheets For SEO - Tom Pool - London SEO Meetup XL
 
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successBrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
 
How to get more traffic with less content - BrightonSEO
How to get more traffic with less content - BrightonSEOHow to get more traffic with less content - BrightonSEO
How to get more traffic with less content - BrightonSEO
 
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
 
How to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google DiscoverHow to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google Discover
 
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDX
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDXThe most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDX
The most Damaging SEO Mistakes & Issues in 2021 and How to Avoid Them #EngagePDX
 
Product, service and category page links (and how to get them) - Rebecca Moss...
Product, service and category page links (and how to get them) - Rebecca Moss...Product, service and category page links (and how to get them) - Rebecca Moss...
Product, service and category page links (and how to get them) - Rebecca Moss...
 
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
 
How to control googlebot
How to control googlebotHow to control googlebot
How to control googlebot
 
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdf
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdfBrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdf
BrightonSEO October 2022 - Log File Analysis - Steven van Vessum.pdf
 

Ähnlich wie brighton final.pptx

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides DemandWave
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)FINOS
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Strategy Forum
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0DNN
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamOWASP Delhi
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunityWarock
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seoPrimary Position
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!Rawnet
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Melanie Phung
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1BeyondIndigo
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022Ash Nallawalla
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksAuthoritas
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesJohn Crenshaw
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penaltyWoptimo
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir Goldshlager
 
Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Dan Jaffe
 

Ähnlich wie brighton final.pptx (20)

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
 
Intro to SEO
Intro to SEOIntro to SEO
Intro to SEO
 
Link Audit and Removal
Link Audit and RemovalLink Audit and Removal
Link Audit and Removal
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons Learned
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunity
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seo
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1
 
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found OnlineYou, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
 
Sistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don'tSistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don't
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penalty
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
 
Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?
 

Kürzlich hochgeladen

BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
Kraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentationKraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentationtbatkhuu1
 
Unraveling the Mystery of The Circleville Letters.pptx
Unraveling the Mystery of The Circleville Letters.pptxUnraveling the Mystery of The Circleville Letters.pptx
Unraveling the Mystery of The Circleville Letters.pptxelizabethella096
 
Major SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain DigitalMajor SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain DigitalBanyanbrain
 
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...ChesterYang6
 
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024Moving beyond multi-touch attribution - DigiMarCon CanWest 2024
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024Richard Ingilby
 
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptx
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptxDigital-Marketing-Into-by-Zoraiz-Ahmad.pptx
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptxZACGaming
 
The Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdfThe Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdfVWO
 
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15SearchNorwich
 
Labour Day Celebrating Workers and Their Contributions.pptx
Labour Day Celebrating Workers and Their Contributions.pptxLabour Day Celebrating Workers and Their Contributions.pptx
Labour Day Celebrating Workers and Their Contributions.pptxelizabethella096
 
Aryabhata I, II of mathematics of both.pptx
Aryabhata I, II of mathematics of both.pptxAryabhata I, II of mathematics of both.pptx
Aryabhata I, II of mathematics of both.pptxtegevi9289
 
How to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail SuccessHow to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail SuccessAggregage
 

Kürzlich hochgeladen (20)

BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
 
Kraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentationKraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentation
 
Unraveling the Mystery of The Circleville Letters.pptx
Unraveling the Mystery of The Circleville Letters.pptxUnraveling the Mystery of The Circleville Letters.pptx
Unraveling the Mystery of The Circleville Letters.pptx
 
Creator Influencer Strategy Master Class - Corinne Rose Guirgis
Creator Influencer Strategy Master Class - Corinne Rose GuirgisCreator Influencer Strategy Master Class - Corinne Rose Guirgis
Creator Influencer Strategy Master Class - Corinne Rose Guirgis
 
Major SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain DigitalMajor SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain Digital
 
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
 
Digital Strategy Master Class - Andrew Rupert
Digital Strategy Master Class - Andrew RupertDigital Strategy Master Class - Andrew Rupert
Digital Strategy Master Class - Andrew Rupert
 
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...
Netflix Ads The Game Changer in Video Ads – Who Needs YouTube.pptx (Chester Y...
 
Brand Strategy Master Class - Juntae DeLane
Brand Strategy Master Class - Juntae DeLaneBrand Strategy Master Class - Juntae DeLane
Brand Strategy Master Class - Juntae DeLane
 
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024Moving beyond multi-touch attribution - DigiMarCon CanWest 2024
Moving beyond multi-touch attribution - DigiMarCon CanWest 2024
 
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptx
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptxDigital-Marketing-Into-by-Zoraiz-Ahmad.pptx
Digital-Marketing-Into-by-Zoraiz-Ahmad.pptx
 
The Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdfThe Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdf
 
BUY GMAIL ACCOUNTS PVA USA IP INDIAN IP GMAIL
BUY GMAIL ACCOUNTS PVA USA IP INDIAN IP GMAILBUY GMAIL ACCOUNTS PVA USA IP INDIAN IP GMAIL
BUY GMAIL ACCOUNTS PVA USA IP INDIAN IP GMAIL
 
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
 
No Cookies No Problem - Steve Krull, Be Found Online
No Cookies No Problem - Steve Krull, Be Found OnlineNo Cookies No Problem - Steve Krull, Be Found Online
No Cookies No Problem - Steve Krull, Be Found Online
 
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
 
Labour Day Celebrating Workers and Their Contributions.pptx
Labour Day Celebrating Workers and Their Contributions.pptxLabour Day Celebrating Workers and Their Contributions.pptx
Labour Day Celebrating Workers and Their Contributions.pptx
 
Aryabhata I, II of mathematics of both.pptx
Aryabhata I, II of mathematics of both.pptxAryabhata I, II of mathematics of both.pptx
Aryabhata I, II of mathematics of both.pptx
 
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
SEO Master Class - Steve Wiideman, Wiideman Consulting GroupSEO Master Class - Steve Wiideman, Wiideman Consulting Group
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
 
How to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail SuccessHow to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail Success
 

brighton final.pptx

  • 1. Google, Cybersecurity and You: Being security savvy as an SEO Chris Spann | Deepcrawl @marqueetag
  • 2. Who Am I? 1 2 3 4 Hi, my name is Chris! I’ve worked in SEO for nearly 15 years I have an unhealthy interest in breaking things and making things do things they aren’t supposed to I’m a member of the Professional Services team at Deepcrawl, working with some of the biggest websites on earth, finding, diagnosing and fixing issues from the really really mundane to the really really weird 1 2 3 4
  • 3. 60% of Small Businesses close within 6 months of a data breach Why should I be concerned about security? 😞
  • 4. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term Why should I be concerned about security? 👤
  • 5. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term You don’t have to be targeted to be a victim of malicious activity, just vulnerable Why should I be concerned about security? 🤷 ♂️
  • 7. I am not a security expert! I’m just an SEO who is either cursed or blessed with the ability to find these things. This talk is about preventing issues where possible, and learning how to find problems to report to your Secops/Dev teams Disclaimer:
  • 8. So what can I do?
  • 9. SEOs have a unique view of websites
  • 10. Three Ways You Can Provide Security Benefits
  • 11. Three Ways You Can Provide Security Benefits Prevent risks
  • 12. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses
  • 13. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses Identify Malicious Activity both successful and attempted
  • 14. Robots.txt ● Robots.txt is a great way of keeping Google out of folders and files you don’t want it getting into ● But consider whether you want to announce their existence to the whole world
  • 15. Robots.txt ● Instead, consider using the X-Robots-Tag header to prevent indexation and limit crawling if you don’t want the urls known - or better yet, block non- verified visits ● As an aside, if you allow UGC, consider what could happen if a user is allowed to create a robots.txt slug
  • 16. Google Alerts ● Set up an alert for ‘site:github.com “[your-website.com]”’ ● Catch devs accidentally storing private keys etc in public github repos ● Catch other nefarious actors who might be targeting these domains with scripts/code
  • 17. Google Alerts ● Keep an eye out on what shows up for an image search for your brand - what can you see in the background of office photos from news stories? ● This also applies to social media - has your new starter taken a photo of their pass?
  • 18. Crawl Your Site As Google ● This will help you see if your site returns anything weird or untoward when it thinks you are not a “normal” user ● Don’t worry too much if the crawl crashes! Your security team might already be one step ahead
  • 19. Monitor your SERPs ● Wordpress sites in particular are susceptible to compromise due to their off the shelf nature ● A famous hack, known as “The Pharma Hack” (Recently overtaken by “The Japanese Keyword Hack”) can serve spammy content to Google - but not to users
  • 20. Question Things That Look Weird ● Look into outliers - go down rabbitholes, ● and always think laterally about how or why something has ended up a specific way ● Just because something says it’s Googlebot, don’t believe it on face value
  • 21. Question Things That Look Weird ● Look into outliers - go down rabbitholes, and always think laterally about how or why something has ended up a specific way ● Just because something says its Googlebot, don’t believe it on face value
  • 22. Search Console ● Search Console will straight up tell you if Google believes your site has been compromised ● Keep an eye on all those subdomains that are no longer used - a malicious actor can tank an entire domain’s traffic by 90% via DMCA takedowns ● Make sure the owner inbox is monitored
  • 23. Summary ● Get to know your site ○ How big is it? ○ What do your SERPs look like? ● Be vigilant of change - especially changes you haven’t made ● Set up alerts ● Automate crawls ● Spend time in Search Console! ● Anything you really don’t want Google or users to find should not be in your robots.txt ● Go down rabbitholes, ask questions, investigate anomalies
  • 24. Thanks for Coming. Resources: https://linktr.ee/chrisspann Chris Spann, Senior Technical SEO at Deepcrawl @marqueetag

Hinweis der Redaktion

  1. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  2. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  3. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  4. Change to slide 6 style
  5. Change to slide 6 style
  6. Change to slide 6 style
  7. Animate these We have access to Search Console to see what Google sees We have log files, which is a huge haystack that can be full of needles We have search analytics to show us what users are doing We have backlink tools to show us the websites that link to us We have site crawlers that find weird things we didn’t know were there all the time But most importantly we have search results, which shows us exactly what other people see when they search for our businesses We also often control what parts of a website Search engines (and users) can or can’t find
  8. How to make this slide look nicer?
  9. How to make this slide look nicer?
  10. How to make this slide look nicer?
  11. How to make this slide look nicer?
  12. How to make this slide look nicer?
  13. Worst case scenario: the user could initiate a meta refresh to an externally hosted robots.txt (google will follow redirects) which contains a Disallow: / rule, which stops google crawling ANYTHING
  14. Your website or api endpoint etc
  15. How to make this slide look nicer?
  16. How to make this slide look nicer?
  17. Remember your SERPs are a great example of how Googlebot sees your site
  18. This is a graph showing Googlebot activity on a clients site What has caused that big spike? Googlebot is the most used UA in DDOS attacks, because most sites will just let Googlebot straight in
  19. Googlebot UA hitting possible locations of a file with known weaknesses - except the IP is not a googlebot IP and it is very weird that google would be hyper targeting possible locations of eval-stdin.php? Because if they then find one, they can fire a POST request at that url with custom php in it
  20. Subdomains point to an IP If your ownership of that IP expires, a third party can then buy usage of that IP and host dodgy stuff on there
  21. Mention recent finding that the pirate update can tank a site by 90% - if someone can upload copyrighted material to your site, they can DMCA you Set up a domain level property and look at googlebot activity across ALL subdomains! Pdf hack is very common