Website security · UAE

Website security for the data you hold.

Cleaning the malware is the fast part. Webzenia closes the entry point and establishes what was actually reached, because a licensed UAE entity has to be able to say.

Get a security assessment

What website security covers

What website security covers.

Website security is the work of keeping attackers out of a marketing site, and of knowing what they reached if they get in. A compromise costs three separate things.

Site firewallProtectedFirewallAttacks blocked today1,827100% blocked · 0 reached the site23:41SQL injection103.21.44.xBlocked23:39Brute force45.83.12.xBlocked23:38Bad bot191.96.7.xBlocked23:36XSS attempt88.214.5.xBlockedSecurity gradeA+HARDENEDSSL/TLS validFirewall activeMalware cleanHardened, monitored, and recovered if it ever matters · 24/7

The site itself.

The malware comes off, the injected pages go, and the host and the browsers clear you again. This is the fast part, and it is the only part most quotes in this market are written for.

The trust signals.

A browser warning or a search result marked unsafe is seen by every buyer who looks you up that week, including the ones already mid-decision. A reputation recovers slower than the files do.

Your notification duty.

If personal data was reachable, the entity holding it is licensed here and answerable here. You cannot report what you have not established, which is why the first hour goes on scope rather than on a restore.

What a compromise costs

What a compromise costs.

Cleanup is the line everyone quotes for. The three columns below are the postures a UAE site is usually in when the bill arrives, and the last row is the one nobody prices.

A plugin, installed onceSwitched on, then never opened againA cleanup, bought onceThe symptom removed, the way in left openA defended siteWatched, hardened, and answered for
The cleanupQuoted in the emergency, at the price an emergency supports.Paid once, and paid again the next time.Inside the plan, so nothing is negotiated during the incident.
Time offlineHowever long it takes to find someone willing to look at it.Hours to days, then normal service until the next one.Rebuilt from a copy taken before the intrusion, not cleaned in place.
The Google warningFound when a customer sends you a screenshot of it.Removed on request, once somebody remembers to ask.Caught by monitoring, cleared, and the review filed the same day.
Whether it repeatsThe entry point was never looked for, so it is still there.The files were replaced. The way in was not closed.The entry point is found, named in writing, and shut.
What you can reportNothing. There is no record of what was reachable.A cleaned site, and a guess about everything else.What was reached, when, and from where, written down.
Which one your site is on.

Most sites here are on the first, and the second usually follows it. What separates the third is the last row: a cleanup can be bought from anywhere, and a record of what was reachable can only be produced by whoever was watching. Where the question is the standing schedule rather than the incident, that is website maintenance. Where the build itself is the entry point, that is website design and development. The people who would be on the call are named.

From the field · UAE

The day after a breach.

Webzenia has worked with Gulf clients since 2018. Four things separate a compromise here from the same compromise anywhere else, and only one of them is technical.

  1. 01of 04
    The duty starts on the dayPDPL · Federal Decree-Law 45 of 2021

    A breach starts a notification duty.

    Under the UAE personal data protection law a controller must notify the federal data protection regulator as soon as it knows of a breach that could harm the data, and describe its nature, cause and scope. What you file is a matter for your counsel. Establishing the scope is the part we do.

    Our methodEvery incident produces a written record of what was reachable, when it changed and from where, in the form a controller needs before it can answer the question at all.
  2. 02of 04
    Two regimes, one licenceDIFC and ADGM run their own

    Your licence decides who you tell.

    A Business Bay brokerage on a DET mainland licence and a DIFC-registered fund sit under different data-protection regimes, and ADGM runs a third. The obligation is not the same one, and it is not something a cleanup service in another country can know about you.

    Our methodThe first call asks where the entity is registered, because it changes who an incident has to be reported to and on what basis, and that is a fact worth having before anything happens.
  3. 03of 04
    A different industry answersWhat the local market is built to sell

    This market sells network appliances.

    Dubai has a real security stack, from the Dubai Electronic Security Center to the federal information assurance standards, written for government entities and critical infrastructure. A Deira trading house on a DET mainland licence with an enquiry form is a different problem with a different owner. Neither regime is aimed at it.

    Our methodWe say plainly which purchase you are making, and where a network security supplier is genuinely the right call instead of us we say that too.
  4. 04of 04
    A repeat is a diagnosisNot bad luck, and not a coincidence

    Reinfection means the way in stayed open.

    Reinfection is the most diagnostic thing that happens in this category. It says the files were replaced and the way in was left where it was: an outdated plugin, a password reused somewhere that has since leaked, an upload path that accepts what it should not. Cleaning it twice changes nothing.

    Our methodA cleanup is not signed off until the entry point is identified and named in the report, and where it genuinely cannot be identified we write that down instead.

The scope

The security work itself.

Six pieces of work. The last two are what a compromise actually needs, and they are the two nobody on page one is selling.

Firewall1,204 blockedSQL injectionBrute forceBad botsYour siteattacks stopped at the door, before they reach your site

A firewall in front.

A web application firewall that stops injection attempts, brute-force logins and bad bots at the edge rather than at your server

Output

the background attack traffic every live site attracts never reaches it, and what it tried is logged

WAFBot filtering
Malware scancleanScanneddaily4,182Threats2Removedauto2Recent scanwp-content/uploadscleantheme injected scriptremovedthreats caught early, with full cleanup included

Malware removed and cleared.

Scheduled scans that catch injected files, spam pages and changes nobody made, with removal included and the blocklist review filed with Google and the host

Output

a clean site, and the warning taken off it

ScansCleanup included
Hardeningsurface reducedCore & plugins updatedTwo-factor on loginsFile permissions lockedAdmin URL hiddenXML-RPC disabledSecurity headers setthe holes attackers actually use, closed off

The way in, closed.

Core and plugins patched, two-factor on every admin account, file permissions locked, the admin path moved and the security headers set

Output

the specific way in is named in writing and shut, which is the only thing that prevents a second visit

HardeningTwo-factorHeaders
Incident recordwritten same dayReachableWhenFromAdmin login03:12 · 4 Mar185.220.x.xCustomer records03:18 · 4 Marsame sessionOrder exportsnot reachablen/aCertificateTLS 1.3 · HTTPS forcedwhat was reachable, when it changed, and from where

A certificate that covers everything.

TLS configured properly, HTTPS forced on every route and the mixed content cleared, so nothing on the page loads outside the encrypted connection

Output

the transport section of a client security questionnaire answered without a phone call

TLSQuestionnaire
Monitoring1 incidentWatched · 30 daysFile change · 3:12amanswered in 3 minround-the-clock, with a human who responds, not an email

Monitoring for unexpected file changes.

File integrity, admin logins and traffic watched continuously, so an unexplained change at three in the morning raises a person rather than an email nobody opens

Output

the incident is found by us, and the hour it started is on the record

File integrityAlerts
Backupsoff-site dailyDaily off-site backupsMonTueWedThuFriSatSunrestore pointTested restoreknown-clean copyrebuilt from a clean copy, not cleaned in place

A clean copy to restore from.

Daily copies held off-site, away from the host, with a restore that has actually been run

Output

a compromised site is rebuilt from a known-clean copy rather than cleaned in place, which is the difference between a fix and a hope

Off-siteKnown-clean copy

Our stack

The tools we defend with.

Five tools, chosen for a marketing site rather than a corporate network. Select one to see why it earns its place, and what we do with it that most do not.

Cloudflare
Why Cloudflare

Cloudflare sits in front of the site as a firewall, a bot filter and a DDoS absorber, so most attack traffic is answered at the edge and never touches the server it was aimed at.

How we excel

We write the rules against your own traffic rather than from a template, because a ruleset copied off a default is how a site ends up blocking its own buyers alongside the bots.

Edge firewallBot filteringStopped where
CloudflareAt the edge
AWS WAFAt the edge
A plugin firewallOn the server
Nothing in frontNowhere

How the engagement runs

Find it, close it, then report it.

Week one is a scan and a lock-down. What changes when something has already happened is the order: scope first, restore second.

01Week 1Audited

Scan, clean, close the way in.

We scan the site and the server for malware and for the weaknesses that let it in, remove anything already there, take a full copy and put a firewall in front. The entry point is then identified and closed, and you get it in writing. If the site was already compromised when you called, the order changes: we establish what was reachable and when it changed before anything is restored, because a restore overwrites the evidence that question is answered from.

  • ScannedThe site and the server, from outside and from within
  • ClosedThe entry point, identified and named in writing
  • RecordedWhat was reachable, and when it changed
02OngoingRunning

Block, watch, keep it small.

The firewall answers the routine traffic, scans run on a schedule, and file integrity, admin logins and traffic are watched continuously so a change nobody made raises a person. Patching and hardening keep the attack surface small as plugins and themes move underneath. The standing update routine, the monthly report and the response window belong to website maintenance, and the two plans are usually held together.

  • BlockedThe routine attack traffic, at the edge
  • WatchedFiles, admin logins and traffic, continuously
  • HardenedThe surface kept small as the software moves
03If it happensHeld

Establish scope, rebuild, report.

An incident starts with scope rather than with a restore: what was reachable, when it changed, and from where. The site is then rebuilt from a copy taken before the intrusion instead of cleaned in place, the entry point is closed, and the blocklist review is filed. You end up with a written record of what happened, which is what a controller needs when the personal data protection law asks for the nature, cause and scope of a breach. The notification itself is yours to make, with your counsel. Our job is that you have something true to put in it.

  • EstablishedWhat was reached, when, and from where
  • RebuiltFrom a copy taken before the intrusion
  • ReportedA written record, while it is still fresh

Every incident leaves a written record of what was reachable and when, so the notification is made from evidence rather than from a guess.

The record, in writing
Entry point namedScope recordedCleanup included

Our commitment

Our promises on an incident.

Security is the easiest service to sell on fear and the hardest to prove afterwards. These four are the parts we put in writing before anything is signed.

  • Cleanup is inside the plan.

    If malware gets through while we hold the site, removal and rebuild are part of what you already pay for. Nobody negotiates a price with you on the day the site is down, which is the day every incentive points the wrong way.

  • You are told how they got in.

    A cleanup is not finished until the entry point is identified and named in the report. Where we genuinely cannot identify it, we write that down rather than imply the job is closed, because an unnamed entry point is what produces a repeat.

  • The incident record is yours.

    What was reachable, when it changed and from where, written up while it is still fresh rather than reconstructed at the end of the month. It is your record, and you keep it whether or not the engagement continues.

  • We say when to call someone else.

    This is website work, not a network firewall procurement and not a security operations centre. Where the problem is genuinely one of those, or where the question is legal rather than technical, we say so and name who should be holding it.

Common questions

Website security in the UAE, answered

Next step

See what your site is exposed to.

Send us the site and what you have noticed. We will scan it, tell you what is reachable from outside, and show you the fix before you commit to anything.

Tell us what you need.

+971
Chat on WhatsApp