Skip to main content

What a Security Expert Wants Organizations To Know About Securing Their Websites

A Q&A with Steve Sharer, CEO of RipRap Security, on the most important ways to protect your site

by mangrove team
published on August 28, 2026
Two closed padlocks against a vibrant orange and yellow background

Strong website security is the result of common sense decisions about structure, hosting, and maintenance made over time. And the basics really do matter most. Things like keeping your site updated regularly and knowing who’s responsible for changes and updates, do more to protect your organization than almost anything.

Because website security matters to Mangrove and our clients, we sat down with Steve Sharer of RipRap Security to talk about this important issue and what organizations should consider prioritizing first.

Steve Sharer is the CEO of RipRap Security, a Certified B Corp specializing in nonprofit cyber security with a human-first approach. Before keeping nonprofits and their communities secure at RipRap, he protected public sector institutions and technology companies against attackers. Read more of Steve’s bio below. 

What’s the first thing organizations should consider when thinking about website security?

The most critical thing is making sure that you have a strong web development partner who cares about security and who knows they have to care about it. A lot of client organizations discover too late that the team they hired to build their website never thought about security, never validated to make sure that their site was secure, and never had a plan for keeping it that way. That’s a hard place to start from in launching a new website. Having a good development partner is key.

How can organizations tell the difference between a partner who takes security seriously and one who’s just saying the right things?

Most purpose-driven organizations we work with are targeted by attackers who want to disrupt the trust they’ve built with their communities. A good technology partner leads with security, and they should be able to give you specific answers when you ask questions about it. If a partner gives you a wishy-washy answer that they can’t back up, that’s a strong sign that they don’t have the expertise, or don’t fully understand the specific risks and harms that nonprofits and B Corps face to commit to it. Security is a real differentiator among web agencies. Only a small number of lead with it.

Some smaller, purpose-driven organizations may assume they’re too small to be a target. Is that true?

This is really common. We call it security hubris, the idea that we’ve got all our ducks in a row and could never fall victim to an attack. But a lot of these attackers are financially motivated, and they don’t care about your mission or how much money you have. They can use techniques like issuing fake invoices, impersonating your executive team to request that staff urgently buy gift cards, and directly hacking financial systems to process payments to their accounts.

It’s not only about money. We’re seeing more ideologically or politically motivated attacks, which can lead to things like web defacement. One of the more concerning patterns we’re finding is attackers breaching an organization’s website through software vulnerabilities or guessing passwords in order to attack its visitors. That’s not just bad content showing up on a page. That’s turning a legitimate, trusted website into a tool to harm the very people it’s meant to serve.

How have big innovations and changes in the technology landscape, like AI, affected how we all need to think about website security?

Attackers have used automation at scale for a while, but AI has changed the variety of ways in which they can creatively strike an organization. It’s not just the scale of the attack, it’s the complexity. AI can now do things that used to require a person to carry out by hand. Just as AI may be driving productivity gains in offices, it’s driving productivity gains for the attacker. It now takes less human effort to make an attack succeed.

A lot of our clients run their websites on WordPress. Where does risk on WordPress usually come from?

We think about this in a few layers. The first is wherever WordPress is hosted, whether that’s WP Engine (a Mangrove Business Partner), Pantheon, or somewhere else, organizations need to make sure that platform is configured securely. We often find organizations paying for security features they haven’t even turned on.

The next layer is WordPress itself: multi-factor authentication on every account, and using the security features WordPress already offers. A lot of that goes unused, either because people don’t know it exists or they’re worried about what might break if they turn it on.

Then there’s ongoing care, updating plugins and WordPress itself. It’s not glamorous, but organizations that keep things updated are far less likely to get hit. When attackers scan websites, they’re looking for outdated WordPress installations and plugins because those are often the easiest way in.

So, how often should organizations check their website updates?

At least once a month. Quarterly is too infrequent, and honestly a month is longer than I’d personally like. But realistically, once a month is a workable cadence. It only takes a few seconds, but someone needs to own it. It’s important to make sure this is something somebody has on their radar.

Automatic updates help too, though they carry some risk: an update could break something on your site without you knowing right away. That’s why many organizations maintain a staging site to test plugins (e.g. tools for calendars, repositories or other site functionality) before pushing them live.

If an organization only has the capacity to handle a few basics this year, what should be on that list?

Updates. Updates. Updates. I can’t say it enough. The second thing is multi-factor authentication that the organization makes mandatory. Most WordPress and hosting platforms let you require it, so no one can log in without it set up. It’s free, and it doesn’t make life harder. Updates and 2FA are table stakes.

The third is backups. If your site gets hacked, having backups with a tested restoration process makes everything easier. Organizations without regular and automatic backups later regret it deeply, having to revert to an ancient version saved in a folder. Most good hosting platforms offer some number of days of backups, but you may have to turn that feature on.

Is there a security measure people often overlook?

Often overlooked is figuring out whose job it is to maintain the website. We’ve walked into situations where a new partner’s website just got hacked, and when we ask who’s been maintaining it, we hear “our vendor.” When we ask to be introduced we find no maintenance contract, and no support plan. The organization thought their site was being taken care of. It was not.

Your website is the digital front door to your organization. It’s worth having that sometimes-awkward conversation with your vendor upfront: are they still supporting you, are you paying for it, and how will you know they’re actually doing it?

Security matters to us

Security optimization has always been important to the way we develop sites. We’ve built and managed WordPress sites for years and know how much it matters for that platform in particular. We make it a priority to ensure security is in place at launch and can help our clients make decisions about maintaining their site health over time.

As the technology we use keeps changing, we’re looking out for the factors that affect security so we can think through what it means for the way we build. If a client’s security needs call for more, we bring in trusted partners like RipRap.

If you’d like to talk through our approach to security in more detail, we’re always happy to connect.

Steve Sharer is passionate about helping progressive organizations safeguard their staff, data, donors, board members, and the communities they serve without overwhelming limited resources or disrupting their mission-focused work. He holds a Bachelor’s in Security and Risk Analysis from Penn State University and a Master’s in Cyber Security from National Intelligence University. 

A Certified B Corp, Mangrove is a woman-owned website design and development company with a diverse, talented team distributed around the globe. We’ve been building websites since 2009 that amplify the work of change-making organizations and increase the competitive power of businesses owned by historically underrepresented people.

If you found this post helpful, subscribe to our monthly newsletter for notice of future posts and other news from us.

Thinking about a project?