Bola Rotibi, member of the (ISC)2 Application Security Advisory Board; and Research Director at Creative Intellect Consulting Ltd
As a web developer you get used to being the first point of contact when something goes awry with a website that you’ve worked on. It is understandable that people see something is wrong and then need to call someone to get it addressed as quickly as possible. What is often lost on clients is the importance of their website hosting and the interdependence between developers and those responsible for that hosting.
Increasingly websites and web applications are coming under attack from a variety of threats such as script injections and denial of service. We’ve all seen high profile examples of this type of event. Developers have a role to play in making sure that the websites that they build are secure but so does the companies on whose infrastructure that site resides.
The key therefore is to balance those responsibilities. No web developer today should have their site fall victim to a SQL injection attack as the threat is so well known that there can be no excuse for not addressing it. Another scenario is malicious script being injected into website pages. It is the hosting company that is best placed to prevent this. Working together both parties help to protect the client’s customers, reputation, data and IP.
What this highlights is the increasingly unique skillset and experience that those who work in website hosting have developed over many years. A number of times in my career, clients decided to do website hosting themselves, within their own IT function. This appears to be a straight forward task as the server technology makes it easy. For sure, modern servers have made this quick and easy to do. However, the ability to easily set-up website hosting hides the challenges in supporting it. Most clients who took this route experience significantly more failures and successful attacks than those using professional hosting providers.
This is because dealing with the challenges of hosting whether they be basic technical issues or the growing security ones requires skills and experience specific to this role. This should not be underestimated and those who do this every day should be recognised for it.
This topic becomes more pertinent with the growth of Cloud. An interesting aside to Cloud is how many people have failed to see the connection with traditional outsourced hosting. Most hosting companies are now offering Cloud solutions as they are a natural extension of their traditional business. At the same time many organisations are being encouraged to set-up their own Clouds.
The focus is usually on the core technology such as the server software and management tools that enable the flexibility and elasticity that Cloud provides. What’s often lost is that Cloud will have many of the same challenges, especially with respect to security, as traditional web hosting. It is important therefore that the skills developed within the hosting industry are recognised by those now adopting Cloud. The ability to easily provision Cloud should not over shadow the many challenges that running and supporting Cloud will pose.
Only by recognising this will Cloud be the safe and secure environment that organisations and individuals require and expect. The security of applications in the Cloud, just like old-style web, is not purely the preserve of the developer.