Most small products are breached through ordinary gaps, not clever attacks. This list covers the ordinary gaps.
Accounts
- Turn on two-factor authentication for your email, domain registrar, hosting, code host and payment provider.
- Use a password manager and a unique password everywhere.
- Remove access for anyone who no longer works with you.
Secrets 4. Keep keys out of the code repository. Search the history too. 5. Use separate keys for development and production. 6. Know how to replace every key, and replace any that have been shared in chat.
The application 7. Keep dependencies updated and turn on automated alerts for known vulnerabilities. 8. Check on the server that a user can only read their own data. Try changing an id in the address bar. 9. Rate-limit login, signup and password reset. 10. Use the framework's built-in protections. Do not write your own authentication if you can avoid it.
Recovery 11. Take automatic backups, keep a copy somewhere else, and restore one to prove it works. 12. Write down what you would do if the site went down or data leaked, including who you would have to tell.
Which of these did you put off longest? And what would you add?