SlideShare a Scribd company logo
1 of 24
Google, Cybersecurity
and You: Being
security savvy as an
SEO
Chris Spann | Deepcrawl
@marqueetag
Who Am I?
1
2
3
4
Hi, my name is Chris!
I’ve worked in SEO for nearly 15 years
I have an unhealthy interest in breaking
things and making things do things they
aren’t supposed to
I’m a member of the Professional Services
team at Deepcrawl, working with some of
the biggest websites on earth, finding,
diagnosing and fixing issues from the really
really mundane to the really really weird
1
2
3
4
60% of Small Businesses
close within 6 months of a data breach
Why should I be concerned about security?
😞
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
Why should I be concerned about security?
👤
60% of Small Businesses
close within 6 months of a data breach
As well as direct financial damage,
damage to reputation and customer confidence can be long term
You don’t have to be targeted
to be a victim of malicious activity, just vulnerable
Why should I be concerned about security?
🤷
♂️
Disclaimer:
I am not a security expert!
I’m just an SEO who is either cursed or blessed
with the ability to find these things.
This talk is about preventing issues where
possible, and learning how to find problems to
report to your Secops/Dev teams
Disclaimer:
So what can I do?
SEOs have a unique view of websites
Three Ways You Can Provide Security Benefits
Three Ways You Can Provide Security Benefits
Prevent risks
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Three Ways You Can Provide Security Benefits
Prevent risks
Identify weaknesses
Identify Malicious Activity
both successful and attempted
Robots.txt
● Robots.txt is a great way of keeping Google out
of folders and files you don’t want it getting into
● But consider whether you want to announce their
existence to the whole world
Robots.txt
● Instead, consider using the X-Robots-Tag header
to prevent indexation and limit crawling if you don’t
want the urls known - or better yet, block non-
verified visits
● As an aside, if you allow UGC, consider what could
happen if a user is allowed to create a robots.txt slug
Google Alerts
● Set up an alert for ‘site:github.com “[your-website.com]”’
● Catch devs accidentally storing private
keys etc in public github repos
● Catch other nefarious actors who might
be targeting these domains with scripts/code
Google Alerts
● Keep an eye out on what shows up for an image
search for your brand - what can you see in the
background of office photos from news stories?
● This also applies to social media -
has your new starter taken a photo
of their pass?
Crawl Your Site As Google
● This will help you see if your site returns anything
weird or untoward when it thinks you are not a
“normal” user
● Don’t worry too much if the crawl crashes! Your
security team might already be one step ahead
Monitor your SERPs
● Wordpress sites in particular are susceptible to
compromise due to their off the shelf nature
● A famous hack, known as “The Pharma Hack”
(Recently overtaken by “The Japanese Keyword
Hack”) can serve spammy content to Google -
but not to users
Question Things That Look Weird
● Look into outliers - go down rabbitholes,
● and always think laterally about how or why
something has ended up a specific way
● Just because something says it’s Googlebot,
don’t believe it on face value
Question Things That Look Weird
● Look into outliers - go down rabbitholes, and
always think laterally about how or why
something has ended up a specific way
● Just because something says its Googlebot,
don’t believe it on face value
Search Console
● Search Console will straight up tell you if Google
believes your site has been compromised
● Keep an eye on all those subdomains that are no
longer used - a malicious actor can tank an entire
domain’s traffic by 90% via DMCA takedowns
● Make sure the owner inbox is monitored
Summary
● Get to know your site
○ How big is it?
○ What do your SERPs look like?
● Be vigilant of change - especially changes you
haven’t made
● Set up alerts
● Automate crawls
● Spend time in Search Console!
● Anything you really don’t want Google or users
to find should not be in your robots.txt
● Go down rabbitholes, ask questions, investigate
anomalies
Thanks for Coming.
Resources: https://linktr.ee/chrisspann
Chris Spann, Senior Technical SEO at Deepcrawl
@marqueetag

More Related Content

What's hot

Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...
Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...
Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...Ahrefs
 
Why Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody HardWhy Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody HardJoshuaHardwickAhrefs
 
How to create content that generates leads -- not just traffic.pptx
How to create content that generates leads -- not just traffic.pptxHow to create content that generates leads -- not just traffic.pptx
How to create content that generates leads -- not just traffic.pptxAramintaRobertson
 
Can you trust AI with your content?
Can you trust AI with your content?Can you trust AI with your content?
Can you trust AI with your content?Mat Bennett
 
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)Gianna Brachetti-Truskawa 🐙
 
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successBrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successDylan Fuler
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volumeLiraz Postan
 
Improving Crawling and Indexing using Real-Time Log File Insights
Improving Crawling and Indexing using Real-Time Log File InsightsImproving Crawling and Indexing using Real-Time Log File Insights
Improving Crawling and Indexing using Real-Time Log File InsightsSteven van Vessum
 
SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022Nitin Manchanda
 
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]Chloe Smith
 
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...LazarinaStoyanova
 
EAT: Have We Been Looking At It Backwards
EAT: Have We Been Looking At It BackwardsEAT: Have We Been Looking At It Backwards
EAT: Have We Been Looking At It BackwardsEdwardZiubrzynski1
 
Jasmine Granton - Brighton SEO 2022.pptx (1).pdf
Jasmine Granton - Brighton SEO 2022.pptx (1).pdfJasmine Granton - Brighton SEO 2022.pptx (1).pdf
Jasmine Granton - Brighton SEO 2022.pptx (1).pdfJasmine Granton
 
Probabilistic Thinking in SEO - BrightonSEO October 2022
Probabilistic Thinking in SEO - BrightonSEO October 2022Probabilistic Thinking in SEO - BrightonSEO October 2022
Probabilistic Thinking in SEO - BrightonSEO October 2022Andrew Charlton
 
How SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookiesHow SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookiesAccuraCast
 
How to improve Core Web Vitals on a WordPress website
How to improve Core Web Vitals on a WordPress websiteHow to improve Core Web Vitals on a WordPress website
How to improve Core Web Vitals on a WordPress websiteIndigo Tree Digital
 
The Full Scoop on Google's Title Rewrites
The Full Scoop on Google's Title RewritesThe Full Scoop on Google's Title Rewrites
The Full Scoop on Google's Title RewritesMordy Oberstein
 
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika Höller
 
Shining a light on the dark funnel
Shining a light on the dark funnelShining a light on the dark funnel
Shining a light on the dark funnelRiaz Kanani
 
BrightonSEO - Apr 2022 - No excuses for doing UX
BrightonSEO - Apr 2022 - No excuses for doing UXBrightonSEO - Apr 2022 - No excuses for doing UX
BrightonSEO - Apr 2022 - No excuses for doing UXOban International
 

What's hot (20)

Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...
Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...
Machine Learning use cases for Technical SEO Automation Brighton SEO Patrick ...
 
Why Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody HardWhy Scaling (Great) Content Is So Bloody Hard
Why Scaling (Great) Content Is So Bloody Hard
 
How to create content that generates leads -- not just traffic.pptx
How to create content that generates leads -- not just traffic.pptxHow to create content that generates leads -- not just traffic.pptx
How to create content that generates leads -- not just traffic.pptx
 
Can you trust AI with your content?
Can you trust AI with your content?Can you trust AI with your content?
Can you trust AI with your content?
 
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)
TECHNICAL SEO QA - SHINING A LIGHT ON INVISIBLE WORK (BrightonSEO April 2022)
 
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO successBrightonSEO April 2023 Similar AI: Automation recipes for SEO success
BrightonSEO April 2023 Similar AI: Automation recipes for SEO success
 
The Hidden Gems of Low search volume
The Hidden Gems of Low search volumeThe Hidden Gems of Low search volume
The Hidden Gems of Low search volume
 
Improving Crawling and Indexing using Real-Time Log File Insights
Improving Crawling and Indexing using Real-Time Log File InsightsImproving Crawling and Indexing using Real-Time Log File Insights
Improving Crawling and Indexing using Real-Time Log File Insights
 
SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022SEO at Scale - BrightonSEO April 2022
SEO at Scale - BrightonSEO April 2022
 
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]
Content Design & its Role in SEO and Accessibility [BrightonSEO Spring 2023]
 
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
How to Incorporate ML in your SERP Analysis, Lazarina Stoy -BrightonSEO Oct, ...
 
EAT: Have We Been Looking At It Backwards
EAT: Have We Been Looking At It BackwardsEAT: Have We Been Looking At It Backwards
EAT: Have We Been Looking At It Backwards
 
Jasmine Granton - Brighton SEO 2022.pptx (1).pdf
Jasmine Granton - Brighton SEO 2022.pptx (1).pdfJasmine Granton - Brighton SEO 2022.pptx (1).pdf
Jasmine Granton - Brighton SEO 2022.pptx (1).pdf
 
Probabilistic Thinking in SEO - BrightonSEO October 2022
Probabilistic Thinking in SEO - BrightonSEO October 2022Probabilistic Thinking in SEO - BrightonSEO October 2022
Probabilistic Thinking in SEO - BrightonSEO October 2022
 
How SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookiesHow SEO changes, as we say bye bye to cookies
How SEO changes, as we say bye bye to cookies
 
How to improve Core Web Vitals on a WordPress website
How to improve Core Web Vitals on a WordPress websiteHow to improve Core Web Vitals on a WordPress website
How to improve Core Web Vitals on a WordPress website
 
The Full Scoop on Google's Title Rewrites
The Full Scoop on Google's Title RewritesThe Full Scoop on Google's Title Rewrites
The Full Scoop on Google's Title Rewrites
 
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptxVeronika bSEO-Googles-MUM-Speaker-Slides.pptx
Veronika bSEO-Googles-MUM-Speaker-Slides.pptx
 
Shining a light on the dark funnel
Shining a light on the dark funnelShining a light on the dark funnel
Shining a light on the dark funnel
 
BrightonSEO - Apr 2022 - No excuses for doing UX
BrightonSEO - Apr 2022 - No excuses for doing UXBrightonSEO - Apr 2022 - No excuses for doing UX
BrightonSEO - Apr 2022 - No excuses for doing UX
 

Similar to brighton final.pptx

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides DemandWave
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Strategy Forum
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)FINOS
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0DNN
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamOWASP Delhi
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunityWarock
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seoPrimary Position
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!Rawnet
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Melanie Phung
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1BeyondIndigo
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022Ash Nallawalla
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksAuthoritas
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesJohn Crenshaw
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penaltyWoptimo
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir Goldshlager
 
Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Dan Jaffe
 

Similar to brighton final.pptx (20)

Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
Post-Penguin SEO Strategies for Google Success - 8-27-13 slides
 
Intro to SEO
Intro to SEOIntro to SEO
Intro to SEO
 
Link Audit and Removal
Link Audit and RemovalLink Audit and Removal
Link Audit and Removal
 
Open Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons LearnedOpen Source Horror Stories and Lessons Learned
Open Source Horror Stories and Lessons Learned
 
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
OPEN SOURCE HORROR STORIES (AND LESSONS LEARNED)
 
What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0What You Need to Know About Google Penguin 2.0
What You Need to Know About Google Penguin 2.0
 
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security TeamSecrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
Secrets of Google VRP by: Krzysztof Kotowicz, Google Security Team
 
Se algorithm immunity
Se algorithm immunitySe algorithm immunity
Se algorithm immunity
 
The easy guide to dealing with bad seo
The easy guide to dealing with bad seoThe easy guide to dealing with bad seo
The easy guide to dealing with bad seo
 
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
Rawnet Lightning Talk -  Negative SEO - A Dirty Business!Rawnet Lightning Talk -  Negative SEO - A Dirty Business!
Rawnet Lightning Talk - Negative SEO - A Dirty Business!
 
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018) Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
Common SEO Mistakes During Site Relaunches, Redesigns, Migrations (2018)
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1
 
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found OnlineYou, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
You, AI & the Future of Organic Search (aka SEO) - Steve Krull, Be Found Online
 
Sistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don'tSistrix - SEO Do's and Don't
Sistrix - SEO Do's and Don't
 
Introduction to SEO in 2022
Introduction to SEO in 2022Introduction to SEO in 2022
Introduction to SEO in 2022
 
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live TalksSEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
SEO Friendly Migrations - Tea-Time SEO' Series of Daily SEO Live Talks
 
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank WebsitesGoogle is Watching You: How Google Spies on Search Behavior to Rank Websites
Google is Watching You: How Google Spies on Search Behavior to Rank Websites
 
How to escape from a Google penalty
How to escape from a Google penaltyHow to escape from a Google penalty
How to escape from a Google penalty
 
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
Nir goldshlager Killing a bug bounty program - twice Hack In The Box 2012
 
Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?Can my underperforming law firm website be saved?
Can my underperforming law firm website be saved?
 

Recently uploaded

Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresLisa M. Masiello
 
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDemandbase
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfEastern Online-iSURVEY
 
marketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfmarketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfarsathsahil
 
Exploring The World Of Adult Ad Networks.pdf
Exploring The World Of Adult Ad Networks.pdfExploring The World Of Adult Ad Networks.pdf
Exploring The World Of Adult Ad Networks.pdfadult marketing
 
pptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxpptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxarsathsahil
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guidekiva6
 
Talent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulTalent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulAtifaArbar
 
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garside
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon GarsideInbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garside
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garsiderobwhite630290
 
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024CIO Business World
 
2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)Jomer Gregorio
 
McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)DEVARAJV16
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setupssuser4571da
 
Fiverr's Product Marketing Interview Assignment
Fiverr's Product Marketing Interview AssignmentFiverr's Product Marketing Interview Assignment
Fiverr's Product Marketing Interview AssignmentFarrel Brest
 
TAM AdEx 2023 Cross Media Advertising Recap - Auto Sector
TAM AdEx 2023 Cross Media Advertising Recap - Auto SectorTAM AdEx 2023 Cross Media Advertising Recap - Auto Sector
TAM AdEx 2023 Cross Media Advertising Recap - Auto SectorSocial Samosa
 
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRCall Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRlizamodels9
 
The Pitfalls of Keyword Stuffing in SEO Copywriting
The Pitfalls of Keyword Stuffing in SEO CopywritingThe Pitfalls of Keyword Stuffing in SEO Copywriting
The Pitfalls of Keyword Stuffing in SEO CopywritingJuan Pineda
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...Hugues Rey
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies bruguardarib
 
Michael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisMichael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisjunaid794917
 

Recently uploaded (20)

Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample Genres
 
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
 
marketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfmarketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdf
 
Exploring The World Of Adult Ad Networks.pdf
Exploring The World Of Adult Ad Networks.pdfExploring The World Of Adult Ad Networks.pdf
Exploring The World Of Adult Ad Networks.pdf
 
pptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxpptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptx
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guide
 
Talent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulTalent Management for mba 3rd sem useful
Talent Management for mba 3rd sem useful
 
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garside
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon GarsideInbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garside
Inbound Marekting 2.0 - The Paradigm Shift in Marketing | Axon Garside
 
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
 
2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)
 
McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setup
 
Fiverr's Product Marketing Interview Assignment
Fiverr's Product Marketing Interview AssignmentFiverr's Product Marketing Interview Assignment
Fiverr's Product Marketing Interview Assignment
 
TAM AdEx 2023 Cross Media Advertising Recap - Auto Sector
TAM AdEx 2023 Cross Media Advertising Recap - Auto SectorTAM AdEx 2023 Cross Media Advertising Recap - Auto Sector
TAM AdEx 2023 Cross Media Advertising Recap - Auto Sector
 
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRCall Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
 
The Pitfalls of Keyword Stuffing in SEO Copywriting
The Pitfalls of Keyword Stuffing in SEO CopywritingThe Pitfalls of Keyword Stuffing in SEO Copywriting
The Pitfalls of Keyword Stuffing in SEO Copywriting
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies
 
Michael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisMichael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysis
 

brighton final.pptx

  • 1. Google, Cybersecurity and You: Being security savvy as an SEO Chris Spann | Deepcrawl @marqueetag
  • 2. Who Am I? 1 2 3 4 Hi, my name is Chris! I’ve worked in SEO for nearly 15 years I have an unhealthy interest in breaking things and making things do things they aren’t supposed to I’m a member of the Professional Services team at Deepcrawl, working with some of the biggest websites on earth, finding, diagnosing and fixing issues from the really really mundane to the really really weird 1 2 3 4
  • 3. 60% of Small Businesses close within 6 months of a data breach Why should I be concerned about security? 😞
  • 4. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term Why should I be concerned about security? 👤
  • 5. 60% of Small Businesses close within 6 months of a data breach As well as direct financial damage, damage to reputation and customer confidence can be long term You don’t have to be targeted to be a victim of malicious activity, just vulnerable Why should I be concerned about security? 🤷 ♂️
  • 7. I am not a security expert! I’m just an SEO who is either cursed or blessed with the ability to find these things. This talk is about preventing issues where possible, and learning how to find problems to report to your Secops/Dev teams Disclaimer:
  • 8. So what can I do?
  • 9. SEOs have a unique view of websites
  • 10. Three Ways You Can Provide Security Benefits
  • 11. Three Ways You Can Provide Security Benefits Prevent risks
  • 12. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses
  • 13. Three Ways You Can Provide Security Benefits Prevent risks Identify weaknesses Identify Malicious Activity both successful and attempted
  • 14. Robots.txt ● Robots.txt is a great way of keeping Google out of folders and files you don’t want it getting into ● But consider whether you want to announce their existence to the whole world
  • 15. Robots.txt ● Instead, consider using the X-Robots-Tag header to prevent indexation and limit crawling if you don’t want the urls known - or better yet, block non- verified visits ● As an aside, if you allow UGC, consider what could happen if a user is allowed to create a robots.txt slug
  • 16. Google Alerts ● Set up an alert for ‘site:github.com “[your-website.com]”’ ● Catch devs accidentally storing private keys etc in public github repos ● Catch other nefarious actors who might be targeting these domains with scripts/code
  • 17. Google Alerts ● Keep an eye out on what shows up for an image search for your brand - what can you see in the background of office photos from news stories? ● This also applies to social media - has your new starter taken a photo of their pass?
  • 18. Crawl Your Site As Google ● This will help you see if your site returns anything weird or untoward when it thinks you are not a “normal” user ● Don’t worry too much if the crawl crashes! Your security team might already be one step ahead
  • 19. Monitor your SERPs ● Wordpress sites in particular are susceptible to compromise due to their off the shelf nature ● A famous hack, known as “The Pharma Hack” (Recently overtaken by “The Japanese Keyword Hack”) can serve spammy content to Google - but not to users
  • 20. Question Things That Look Weird ● Look into outliers - go down rabbitholes, ● and always think laterally about how or why something has ended up a specific way ● Just because something says it’s Googlebot, don’t believe it on face value
  • 21. Question Things That Look Weird ● Look into outliers - go down rabbitholes, and always think laterally about how or why something has ended up a specific way ● Just because something says its Googlebot, don’t believe it on face value
  • 22. Search Console ● Search Console will straight up tell you if Google believes your site has been compromised ● Keep an eye on all those subdomains that are no longer used - a malicious actor can tank an entire domain’s traffic by 90% via DMCA takedowns ● Make sure the owner inbox is monitored
  • 23. Summary ● Get to know your site ○ How big is it? ○ What do your SERPs look like? ● Be vigilant of change - especially changes you haven’t made ● Set up alerts ● Automate crawls ● Spend time in Search Console! ● Anything you really don’t want Google or users to find should not be in your robots.txt ● Go down rabbitholes, ask questions, investigate anomalies
  • 24. Thanks for Coming. Resources: https://linktr.ee/chrisspann Chris Spann, Senior Technical SEO at Deepcrawl @marqueetag

Editor's Notes

  1. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  2. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  3. In our survey, we asked them. Understanding the importance of your website and the real business impact it can provide is only half the battle. When it came time to execute, we found that many marketing leaders were struggling. Here’s why: People: 40% said that they did not have the right people (or enough people) on their teams who could carry out the work necessary to succeed in website health and organic search. Delays in implementing website changes: 39% said there were significant delays when it came to implementing changes on their sites that would benefit SEO. Poor collaboration across teams: 23% said that there wasn’t the necessary level of collaboration happening across teams — and 23% also said that their tech/IT/development teams did not prioritize organic search — likely leading to the delays in implementation mentioned earlier! A lack of inclusion in strategy: 29%, meanwhile, said that improving their websites’ health was not seen as part of their organizations’ strategic priorities — despite the fact they themselves understood the impact that website performance and organic search could have on larger goals such as revenue and awareness-building. A lack of leadership buy-in: 23% also called out leadership specifically as creating blockers when it came to getting the resources they needed to implement website health
  4. Change to slide 6 style
  5. Change to slide 6 style
  6. Change to slide 6 style
  7. Animate these We have access to Search Console to see what Google sees We have log files, which is a huge haystack that can be full of needles We have search analytics to show us what users are doing We have backlink tools to show us the websites that link to us We have site crawlers that find weird things we didn’t know were there all the time But most importantly we have search results, which shows us exactly what other people see when they search for our businesses We also often control what parts of a website Search engines (and users) can or can’t find
  8. How to make this slide look nicer?
  9. How to make this slide look nicer?
  10. How to make this slide look nicer?
  11. How to make this slide look nicer?
  12. How to make this slide look nicer?
  13. Worst case scenario: the user could initiate a meta refresh to an externally hosted robots.txt (google will follow redirects) which contains a Disallow: / rule, which stops google crawling ANYTHING
  14. Your website or api endpoint etc
  15. How to make this slide look nicer?
  16. How to make this slide look nicer?
  17. Remember your SERPs are a great example of how Googlebot sees your site
  18. This is a graph showing Googlebot activity on a clients site What has caused that big spike? Googlebot is the most used UA in DDOS attacks, because most sites will just let Googlebot straight in
  19. Googlebot UA hitting possible locations of a file with known weaknesses - except the IP is not a googlebot IP and it is very weird that google would be hyper targeting possible locations of eval-stdin.php? Because if they then find one, they can fire a POST request at that url with custom php in it
  20. Subdomains point to an IP If your ownership of that IP expires, a third party can then buy usage of that IP and host dodgy stuff on there
  21. Mention recent finding that the pirate update can tank a site by 90% - if someone can upload copyrighted material to your site, they can DMCA you Set up a domain level property and look at googlebot activity across ALL subdomains! Pdf hack is very common