CMS security for web agencies: managing the security of multiple client sites
By Kike Gandia · Co-Founder & CEO, OSCP
Web agencies managing multiple client sites on WordPress, Drupal, Magento or PrestaShop face a particular risk surface: a compromise on a shared server or a poorly managed update process can affect dozens of clients at the same time. Managing security in this context calls for a systematic approach.
The specific risk facing agencies with multiple CMS sites
Agencies that host several clients on the same server or under the same hosting account are exposed to lateral movement: a compromise on one client's site can grant access to the shared server and from there to other clients' sites. It's the web equivalent of lateral movement across a corporate network.
Agencies also tend to use the same stack of plugins or extensions across multiple clients. A vulnerability in a plugin used on 30 sites becomes a vulnerability affecting 30 clients simultaneously unless a systematic update process is in place.
What liability does an agency take on for its clients' security
Legal liability depends on the maintenance contract: which services are included, what SLAs apply and what responsibility is assumed in the event of an incident. Many web maintenance contracts include no explicit security commitments, which leads to disputes when a compromise occurs.
Beyond the contract, there is a reputational liability: an agency managing 50 sites of which 10 are compromised in the same attack campaign has a business problem regardless of what the contract says.
How to outsource CMS security auditing for agencies
Agencies that want to offer CMS security as a service without an in-house team can outsource the technical analysis to a specialist provider. The usual models:
Periodic audit of the whole portfolio: Analysis of every site in the portfolio once a year, prioritised by client criticality.
On-demand audit per project: Specific pentesting when a new site is launched, when critical features are added or when the client requests it for a compliance process.
Continuous vulnerability monitoring: Monitoring installed plugins against newly published vulnerabilities, with alerts when a client is running an affected plugin.
The specialist security provider brings the offensive technical capability the agency lacks internally, while the agency brings knowledge of the client and the environment.
FAQ
Can we offer CMS security as a service to our clients if we outsource the pentesting?
Yes. It's the usual model for many agencies that want to add security to their portfolio without hiring an in-house offensive security team. The agency manages the client relationship and project coordination; the security provider runs the analysis and delivers the report.
What information does the security provider need to audit my clients' sites?
For the initial analysis: the site URL, the CMS and version if known, the scope agreed with the client and access credentials if an authenticated assessment is performed. The agency acts as the intermediary to obtain the client's consent and coordinate availability of the environment.
Related service
Related content
- CMS pentesting
- CMS security vs web maintenance
- Common CMS vulnerabilities
- How to choose a CMS security provider