SlideShare a Scribd company logo
Google, Cybersecurity
and You: Being
security savvy as an
SEO
Chris Spann | Deepcrawl
@marqueetag
Who Am I?
1
2
3
4
Hi, my name is Chris!
I’ve worked in SEO for nearly 15 years
I have an unhealthy interest in breaking
things and making things do things they
aren’t supposed to
I’m a member of the Professional Services
team at Deepcrawl, working with some of
the biggest websites on earth, finding,
diagnosing and fixing issues from the really
really mundane to the really really weird
1
2
3
4
60% of Small Businesses
close within 6 months of a data breach
Why should I be concerned about security?
😞
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
Why should I be concerned about security?
👤
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
You don’t have to be targeted
to be a victim of malicious activity, just vulnerable
Why should I be concerned about security?
🤷
♂️
Disclaimer:
I am not a security expert!
I’m just an SEO who is either cursed or blessed
with the ability to find these things.
This talk is about preventing issues where
possible, and learning how to find problems to
report to your Secops/Dev teams
Disclaimer:
So what can I do?
SEOs have a unique view of websites
Three Ways You Can Provide Security Benefits
Three Ways You Can Provide Security Benefits
Prevent risks
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Identify Malicious Activity
both successful and attempted
Robots.txt
● Robots.txt is a great way of keeping Google out
of folders and files you don’t want it getting into
● But consider whether you want to announce their
existence to the whole world
Robots.txt
● Instead, consider using the X-Robots-Tag header
to prevent indexation and limit crawling if you don’t
want the urls known - or better yet, block non-
verified visits
● As an aside, if you allow UGC, consider what could
happen if a user is allowed to create a robots.txt slug
Google Alerts
● Set up an alert for ‘site:github.com “[your-website.com]”’
● Catch devs accidentally storing private
keys etc in public github repos
● Catch other nefarious actors who might
be targeting these domains with scripts/code
Google Alerts
● Keep an eye out on what shows up for an image
search for your brand - what can you see in the
background of office photos from news stories?
● This also applies to social media -
has your new starter taken a photo
of their pass?
Crawl Your Site As Google
● This will help you see if your site returns anything
weird or untoward when it thinks you are not a
“normal” user
● Don’t worry too much if the crawl crashes! Your
security team might already be one step ahead
Monitor your SERPs
● Wordpress sites in particular are susceptible to
compromise due to their off the shelf nature
● A famous hack, known as “The Pharma Hack”
(Recently overtaken by “The Japanese Keyword
Hack”) can serve spammy content to Google -
but not to users
Question Things That Look Weird
● Look into outliers - go down rabbitholes,
● and always think laterally about how or why
something has ended up a specific way
● Just because something says it’s Googlebot,
don’t believe it on face value
Question Things That Look Weird
● Look into outliers - go down rabbitholes, and
always think laterally about how or why
something has ended up a specific way
● Just because something says its Googlebot,
don’t believe it on face value
Search Console
● Search Console will straight up tell you if Google
believes your site has been compromised
● Keep an eye on all those subdomains that are no
longer used - a malicious actor can tank an entire
domain’s traffic by 90% via DMCA takedowns
● Make sure the owner inbox is monitored
Summary
● Get to know your site
○ How big is it?
○ What do your SERPs look like?
● Be vigilant of change - especially changes you
haven’t made
● Set up alerts
● Automate crawls
● Spend time in Search Console!
● Anything you really don’t want Google or users
to find should not be in your robots.txt
● Go down rabbitholes, ask questions, investigate
anomalies
Thanks for Coming.
Resources: https://linktr.ee/chrisspann
Chris Spann, Senior Technical SEO at Deepcrawl
@marqueetag

More Related Content

What's hot

How to go viral on a budget using Digital PR.pptx
How to go viral on a budget using Digital PR.pptxHow to go viral on a budget using Digital PR.pptx
How to go viral on a budget using Digital PR.pptx
AlexHickson3
 
How To EAT Links.pptx
How To EAT Links.pptxHow To EAT Links.pptx
How To EAT Links.pptx
Dixon Jones
 
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
Tevfik Mert Azizoglu
 
Why Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody HardWhy Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody Hard
JoshuaHardwickAhrefs
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volume
Liraz Postan
 
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
Kim Dewe
 
SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022
Nitin Manchanda
 
The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker
ReneHarris7
 
BrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
BrightonSEO - Master Crawl Budget Optimization for Enterprise WebsitesBrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
BrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
Manick Bhan
 
Using Search Intent in our Link Building Efforts
Using Search Intent in our Link Building EffortsUsing Search Intent in our Link Building Efforts
Using Search Intent in our Link Building Efforts
Chris Czermak
 
How SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookiesHow SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookies
AccuraCast
 
Kleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdfKleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdf
Kleecks
 
How to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjectsHow to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjects
Kat Nicholls
 
Martin McGarry - SEO strategy c/o England manager Gareth Southgate
Martin McGarry - SEO strategy c/o England manager Gareth SouthgateMartin McGarry - SEO strategy c/o England manager Gareth Southgate
Martin McGarry - SEO strategy c/o England manager Gareth Southgate
Martin McGarry
 
How to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google DiscoverHow to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google Discover
Felipe Bazon
 
brightonSEO - Stress Is Contagious Don't Catch It From Your Clients
brightonSEO - Stress Is Contagious Don't Catch It From Your ClientsbrightonSEO - Stress Is Contagious Don't Catch It From Your Clients
brightonSEO - Stress Is Contagious Don't Catch It From Your Clients
Kathryn Monkcom
 
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
Ian Helms
 
How to come up with content ideas without relying on search volume.pptx
How to come up with content ideas without relying on search volume.pptxHow to come up with content ideas without relying on search volume.pptx
How to come up with content ideas without relying on search volume.pptx
StephNaylor2
 
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptx
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptxSmall Tasks Make Big Changes - Shmulik Dorinbaum.pptx
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptx
Shmulik Dorinbaum
 
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
BethBarnham1
 

What's hot (20)

How to go viral on a budget using Digital PR.pptx
How to go viral on a budget using Digital PR.pptxHow to go viral on a budget using Digital PR.pptx
How to go viral on a budget using Digital PR.pptx
 
How To EAT Links.pptx
How To EAT Links.pptxHow To EAT Links.pptx
How To EAT Links.pptx
 
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
SEO Automation Without Using Hard Code by Tevfik Mert Azizoglu - BrightonSEO ...
 
Why Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody HardWhy Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody Hard
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volume
 
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
KIM DEWE - Transitioning into people management (BrightonSEO April 2022)
 
SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022
 
The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker The Big SEO Migration - Learnings from a first time hiker
The Big SEO Migration - Learnings from a first time hiker
 
BrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
BrightonSEO - Master Crawl Budget Optimization for Enterprise WebsitesBrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
BrightonSEO - Master Crawl Budget Optimization for Enterprise Websites
 
Using Search Intent in our Link Building Efforts
Using Search Intent in our Link Building EffortsUsing Search Intent in our Link Building Efforts
Using Search Intent in our Link Building Efforts
 
How SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookiesHow SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookies
 
Kleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdfKleecks - AI-Martech as a game changer-DEF.pdf
Kleecks - AI-Martech as a game changer-DEF.pdf
 
How to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjectsHow to take care of yourself when researching/writing about tough subjects
How to take care of yourself when researching/writing about tough subjects
 
Martin McGarry - SEO strategy c/o England manager Gareth Southgate
Martin McGarry - SEO strategy c/o England manager Gareth SouthgateMartin McGarry - SEO strategy c/o England manager Gareth Southgate
Martin McGarry - SEO strategy c/o England manager Gareth Southgate
 
How to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google DiscoverHow to Use Search Intent to Dominate Google Discover
How to Use Search Intent to Dominate Google Discover
 
brightonSEO - Stress Is Contagious Don't Catch It From Your Clients
brightonSEO - Stress Is Contagious Don't Catch It From Your ClientsbrightonSEO - Stress Is Contagious Don't Catch It From Your Clients
brightonSEO - Stress Is Contagious Don't Catch It From Your Clients
 
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
Not Just Pride Month: Crafting LGBTQ+-Inclusive Campaigns Year Round - bright...
 
How to come up with content ideas without relying on search volume.pptx
How to come up with content ideas without relying on search volume.pptxHow to come up with content ideas without relying on search volume.pptx
How to come up with content ideas without relying on search volume.pptx
 
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptx
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptxSmall Tasks Make Big Changes - Shmulik Dorinbaum.pptx
Small Tasks Make Big Changes - Shmulik Dorinbaum.pptx
 
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
Accessibility, strategy and schema - do they go hand in hand? Beth Barnham Br...
 

Similar to brighton final.pptx

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
DemandWave
 
Intro to SEO
Intro to SEOIntro to SEO
Intro to SEO
Affiliate Summit
 
Link Audit and Removal
Link Audit and RemovalLink Audit and Removal
Link Audit and Removal
ClickThrough Marketing
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons Learned
Open Source Strategy Forum
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
FINOS
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0
DNN
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
OWASP Delhi
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunity
Warock
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seo
Primary Position
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Melanie Phung
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1
BeyondIndigo
 
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
SEO Master Class - Steve Wiideman,  Wiideman Consulting GroupSEO Master Class - Steve Wiideman,  Wiideman Consulting Group
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found OnlineYou, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Sistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don'tSistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don't
Amazon Associates UK
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022
Ash Nallawalla
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
Authoritas
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
John Crenshaw
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penalty
Woptimo
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir Goldshlager
 

Similar to brighton final.pptx (20)

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
 
Intro to SEO
Intro to SEOIntro to SEO
Intro to SEO
 
Link Audit and Removal
Link Audit and RemovalLink Audit and Removal
Link Audit and Removal
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons Learned
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunity
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seo
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1
 
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
SEO Master Class - Steve Wiideman,  Wiideman Consulting GroupSEO Master Class - Steve Wiideman,  Wiideman Consulting Group
SEO Master Class - Steve Wiideman, Wiideman Consulting Group
 
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found OnlineYou, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
 
Sistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don'tSistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don't
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penalty
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
 

Recently uploaded

Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
Pillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJumpPillar-Based Marketing - Ryan Brock, DemandJump
PickUp_conversational AI_Capex, Inc._20240610
PickUp_conversational AI_Capex, Inc._20240610PickUp_conversational AI_Capex, Inc._20240610
PickUp_conversational AI_Capex, Inc._20240610
Shuntaro Kogame
 
No Cookies, No Problem - Steve Krull, Be Found Online
No Cookies, No Problem - Steve Krull, Be Found OnlineNo Cookies, No Problem - Steve Krull, Be Found Online
No Cookies, No Problem - Steve Krull, Be Found Online
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Mastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando AnguloMastering Your Online Visibility - Fernando Angulo
Global Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
Global Growth Starts With Translation - How To Unlock Global Markets - Tim KirbyGlobal Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
Global Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Pillar-Based Marketing Master Class - Ryan Brock
Pillar-Based Marketing Master Class - Ryan BrockPillar-Based Marketing Master Class - Ryan Brock
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Story Telling Master Class - Jennifer Morilla
Story Telling Master Class - Jennifer MorillaStory Telling Master Class - Jennifer Morilla
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Growth Marketing in 2024 - Randy Rayess, Outgrow
Growth Marketing in 2024 - Randy Rayess,  OutgrowGrowth Marketing in 2024 - Randy Rayess,  Outgrow
Etsy Marketing Guide - Tips For Selling Digital Products
Etsy Marketing Guide - Tips For Selling Digital ProductsEtsy Marketing Guide - Tips For Selling Digital Products
Etsy Marketing Guide - Tips For Selling Digital Products
kcblog21
 
Top digital marketing institutein noida
Top digital marketing institutein noidaTop digital marketing institutein noida
Top digital marketing institutein noida
aditisingh6607
 
Consumer Journey Mapping & Personalization Master Class - Sabrina Killgo
Consumer Journey Mapping & Personalization Master Class - Sabrina KillgoConsumer Journey Mapping & Personalization Master Class - Sabrina Killgo
Consumer Journey Mapping & Personalization Master Class - Sabrina Killgo
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdfLuxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
KiranRai75
 
How American Bath Group Leveraged Kontent
How American Bath Group Leveraged KontentHow American Bath Group Leveraged Kontent
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 

Recently uploaded (20)

Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
 
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis Yu
 
Pillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJumpPillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJump
 
PickUp_conversational AI_Capex, Inc._20240610
PickUp_conversational AI_Capex, Inc._20240610PickUp_conversational AI_Capex, Inc._20240610
PickUp_conversational AI_Capex, Inc._20240610
 
No Cookies, No Problem - Steve Krull, Be Found Online
No Cookies, No Problem - Steve Krull, Be Found OnlineNo Cookies, No Problem - Steve Krull, Be Found Online
No Cookies, No Problem - Steve Krull, Be Found Online
 
Mastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando AnguloMastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando Angulo
 
Global Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
Global Growth Starts With Translation - How To Unlock Global Markets - Tim KirbyGlobal Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
Global Growth Starts With Translation - How To Unlock Global Markets - Tim Kirby
 
Amazing and On Point - Ramon Ray, USA TODAY
Amazing and On Point - Ramon Ray, USA TODAYAmazing and On Point - Ramon Ray, USA TODAY
Amazing and On Point - Ramon Ray, USA TODAY
 
Mastering Email Campaign Automation Strategies and Best Practices - Michelle...
Mastering Email Campaign Automation Strategies and Best Practices  - Michelle...Mastering Email Campaign Automation Strategies and Best Practices  - Michelle...
Mastering Email Campaign Automation Strategies and Best Practices - Michelle...
 
Pillar-Based Marketing Master Class - Ryan Brock
Pillar-Based Marketing Master Class - Ryan BrockPillar-Based Marketing Master Class - Ryan Brock
Pillar-Based Marketing Master Class - Ryan Brock
 
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
Future-Proof Like Beyoncé - Syncing Email and Social Media for Iconic Brand L...
 
Story Telling Master Class - Jennifer Morilla
Story Telling Master Class - Jennifer MorillaStory Telling Master Class - Jennifer Morilla
Story Telling Master Class - Jennifer Morilla
 
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
Marketing in the Age of AI - Shifting CX from Monologue to Dialogue - Susan W...
 
Growth Marketing in 2024 - Randy Rayess, Outgrow
Growth Marketing in 2024 - Randy Rayess,  OutgrowGrowth Marketing in 2024 - Randy Rayess,  Outgrow
Growth Marketing in 2024 - Randy Rayess, Outgrow
 
Etsy Marketing Guide - Tips For Selling Digital Products
Etsy Marketing Guide - Tips For Selling Digital ProductsEtsy Marketing Guide - Tips For Selling Digital Products
Etsy Marketing Guide - Tips For Selling Digital Products
 
Top digital marketing institutein noida
Top digital marketing institutein noidaTop digital marketing institutein noida
Top digital marketing institutein noida
 
Consumer Journey Mapping & Personalization Master Class - Sabrina Killgo
Consumer Journey Mapping & Personalization Master Class - Sabrina KillgoConsumer Journey Mapping & Personalization Master Class - Sabrina Killgo
Consumer Journey Mapping & Personalization Master Class - Sabrina Killgo
 
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdfLuxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
Luxury Hanloom Saree Brand ,Capstone Project_Kiran Bansal.pdf
 
How American Bath Group Leveraged Kontent
How American Bath Group Leveraged KontentHow American Bath Group Leveraged Kontent
How American Bath Group Leveraged Kontent
 
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
How to Use a Free Book Funnel to Drive Highly Qualified Buyers Into Your Busi...
 

brighton final.pptx

  • 1. Google, Cybersecurity and You: Being security savvy as an SEO Chris Spann | Deepcrawl @marqueetag
  • 2. Who Am I? 1 2 3 4 Hi, my name is Chris! I’ve worked in SEO for nearly 15 years I have an unhealthy interest in breaking things and making things do things they aren’t supposed to I’m a member of the Professional Services team at Deepcrawl, working with some of the biggest websites on earth, finding, diagnosing and fixing issues from the really really mundane to the really really weird 1 2 3 4
  • 3. 60% of Small Businesses close within 6 months of a data breach Why should I be concerned about security? 😞
  • 4. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term Why should I be concerned about security? 👤
  • 5. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term You don’t have to be targeted to be a victim of malicious activity, just vulnerable Why should I be concerned about security? 🤷 ♂️
  • 7. I am not a security expert! I’m just an SEO who is either cursed or blessed with the ability to find these things. This talk is about preventing issues where possible, and learning how to find problems to report to your Secops/Dev teams Disclaimer:
  • 8. So what can I do?
  • 9. SEOs have a unique view of websites
  • 10. Three Ways You Can Provide Security Benefits
  • 11. Three Ways You Can Provide Security Benefits Prevent risks
  • 12. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses
  • 13. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses Identify Malicious Activity both successful and attempted
  • 14. Robots.txt ● Robots.txt is a great way of keeping Google out of folders and files you don’t want it getting into ● But consider whether you want to announce their existence to the whole world
  • 15. Robots.txt ● Instead, consider using the X-Robots-Tag header to prevent indexation and limit crawling if you don’t want the urls known - or better yet, block non- verified visits ● As an aside, if you allow UGC, consider what could happen if a user is allowed to create a robots.txt slug
  • 16. Google Alerts ● Set up an alert for ‘site:github.com “[your-website.com]”’ ● Catch devs accidentally storing private keys etc in public github repos ● Catch other nefarious actors who might be targeting these domains with scripts/code
  • 17. Google Alerts ● Keep an eye out on what shows up for an image search for your brand - what can you see in the background of office photos from news stories? ● This also applies to social media - has your new starter taken a photo of their pass?
  • 18. Crawl Your Site As Google ● This will help you see if your site returns anything weird or untoward when it thinks you are not a “normal” user ● Don’t worry too much if the crawl crashes! Your security team might already be one step ahead
  • 19. Monitor your SERPs ● Wordpress sites in particular are susceptible to compromise due to their off the shelf nature ● A famous hack, known as “The Pharma Hack” (Recently overtaken by “The Japanese Keyword Hack”) can serve spammy content to Google - but not to users
  • 20. Question Things That Look Weird ● Look into outliers - go down rabbitholes, ● and always think laterally about how or why something has ended up a specific way ● Just because something says it’s Googlebot, don’t believe it on face value
  • 21. Question Things That Look Weird ● Look into outliers - go down rabbitholes, and always think laterally about how or why something has ended up a specific way ● Just because something says its Googlebot, don’t believe it on face value
  • 22. Search Console ● Search Console will straight up tell you if Google believes your site has been compromised ● Keep an eye on all those subdomains that are no longer used - a malicious actor can tank an entire domain’s traffic by 90% via DMCA takedowns ● Make sure the owner inbox is monitored
  • 23. Summary ● Get to know your site ○ How big is it? ○ What do your SERPs look like? ● Be vigilant of change - especially changes you haven’t made ● Set up alerts ● Automate crawls ● Spend time in Search Console! ● Anything you really don’t want Google or users to find should not be in your robots.txt ● Go down rabbitholes, ask questions, investigate anomalies
  • 24. Thanks for Coming. Resources: https://linktr.ee/chrisspann Chris Spann, Senior Technical SEO at Deepcrawl @marqueetag

Editor's Notes

  1. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  2. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  3. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  4. Change to slide 6 style
  5. Change to slide 6 style
  6. Change to slide 6 style
  7. Animate these We have access to Search Console to see what Google sees We have log files, which is a huge haystack that can be full of needles We have search analytics to show us what users are doing We have backlink tools to show us the websites that link to us We have site crawlers that find weird things we didn’t know were there all the time But most importantly we have search results, which shows us exactly what other people see when they search for our businesses We also often control what parts of a website Search engines (and users) can or can’t find
  8. How to make this slide look nicer?
  9. How to make this slide look nicer?
  10. How to make this slide look nicer?
  11. How to make this slide look nicer?
  12. How to make this slide look nicer?
  13. Worst case scenario: the user could initiate a meta refresh to an externally hosted robots.txt (google will follow redirects) which contains a Disallow: / rule, which stops google crawling ANYTHING
  14. Your website or api endpoint etc
  15. How to make this slide look nicer?
  16. How to make this slide look nicer?
  17. Remember your SERPs are a great example of how Googlebot sees your site
  18. This is a graph showing Googlebot activity on a clients site What has caused that big spike? Googlebot is the most used UA in DDOS attacks, because most sites will just let Googlebot straight in
  19. Googlebot UA hitting possible locations of a file with known weaknesses - except the IP is not a googlebot IP and it is very weird that google would be hyper targeting possible locations of eval-stdin.php? Because if they then find one, they can fire a POST request at that url with custom php in it
  20. Subdomains point to an IP If your ownership of that IP expires, a third party can then buy usage of that IP and host dodgy stuff on there
  21. Mention recent finding that the pirate update can tank a site by 90% - if someone can upload copyrighted material to your site, they can DMCA you Set up a domain level property and look at googlebot activity across ALL subdomains! Pdf hack is very common