Select Page

Are Your Suppliers Costing You Money or Adding Value to Your Business?

Today I want you to have a think about your organisation and its suppliers in general, digital or otherwise. And ask yourself the question; are your suppliers costing you money or adding value to your business?

Naturally with speaking with a lot of businesses we hear a lot of information and comments about costs, investments, pricing information and a lot of other information that enables us to get a good feel for how a business perceives different items within their business and supply chain. There is an excellent book titled The Slight Edge by Jeff Olson, which if you haven’t read I’d urge you to go out and buy a copy now. The book can really be summarised by the image below;

 

Slight Edge Graph

 

Source: http://slightedgecommunity.com/blogs/12726/3614/beyond-the-12-steps-the-slight

And summarised further by a quote from Yoda in Star Wars;

 

“No. Try not. Do… or do not. There is no try.” – Yoda

 

The same is true in business. You either make the right decision, or the wrong decision, there is no middle ground. Many businesses often make the wrong decisions when it comes to their digital assets, but we’ve already talked about that quite a bit recently. Here I want you to take a bit of time and think about your business in a slightly different way than you do currently. Think critically about where you are now, where you want to get to and if the decisions that are being made are working towards these goals or away from them. As Yoda said, there is no try, you are either making strategic decisions daily which are working towards your goals or you are naturally moving away from your goals either by doing nothing or making the wrong decisions.

 

Are Your Suppliers Costing You Money or Adding Value to Your Business

 

Markets are changing at a faster pace than ever before and as a business it is essential that you keep up to date with these changes to compete. There is an enormous cost of doing nothing within business as competitors are continually improving and markets are ever shifting. We’re not talking about significant innovation within your business, although this is absolutely essential and a topic for a future blog post, no, where talking about incremental improvements based on making strategic decisions that are going to move your business forward.

To put this into perspective, below are a few graphs showing the cost of doing nothing compared to the results of making the right decisions. The top graphs show a 5% decline year on year based on an ever more competitive market place, which you have failed to keep up with, and the bottom graph showing a 5% increase year on year based on making the right strategic decisions. The data is clear;

 

The Cost of Doing Nothing in Business

(click for larger graphs)

 

Remember, you are either actively improving your business in all aspects or you are falling behind. There is no middle ground of staying steady. Take some time and have a think about your business in a critical way for every aspect. And remember, we always have time for a coffee if you want to bounce a few ideas off us, we’re a friendly bunch and will always give you honest feedback and comments about your digital and technology choices whether this is what you want to hear or not. We like to work with businesses and help them along their journey to their goals and ambitions.

If Your Website is Seen as a Cost You Have Already Lost

Why is it that so many businesses still see a website as a cost rather than an investment to generate a return? We live in a digital world so why isn’t your online presence at the forefront of your business strategy to increase revenue? Well, after speaking with thousands of businesses ranging from startups all the way up to companies with offices around the globe, I’ve noticed a few common comments and it’s time to debunk some of the common reasons we hear and get serious about your investments in digital channels.

The Current Situation

So many established businesses will happily spend money on traditional activities because that is what they have always done. The world has changed, it’s time to keep up or give up. Traditional ways that money is spent includes sponsoring awards, radio advertising, printed materials such as flyers and handouts, promotional products such as pads, pens and mugs, trade fairs, direct mail, advertisements in magazines and newspapers, printed banners, popup stands and many more methods. Money is spent in these areas without batting an eyelid. Because apparently this is what we need to run a business, right? Have you ever attempted to calculate the return you generated as a direct result of your spend on these activities? I imagine that if you have, you have also struggled to attribute any of these activities individually to a direct increase in revenue.

Let’s be clear here though, I’m not saying don’t do any of these. I’m a huge believer of testing everything and tracking the results. And yes, these activities certainly support your overall marketing strategy. But you have to ask yourself the question, if we live in a digital world, why aren’t you investing more seriously in digital channels? What are you afraid of?

 

 

If you see your website as a cost, you’ve already lost. A website should support your business goals, sales and marketing strategy and more. Your website should be a key touchpoint during the sales process or should be directly generating revenue for your business through ecommerce sales or generating enquiries.

 

Digital Doesn’t Work for Our Industry

Seriously? Did I just hear you correctly? I kid you not, this is something we have heard on multiple occasions.

** Takes a deep breath **

You think that digital doesn’t work in your industry? I ask you to prove to me that digital doesn’t work in your industry. I want to see all of the following that you have invested in previously and generated zero results if you truly believe that digital doesn’t work in your industry;

  • Show me your Google Analytics data, how many visits are you getting per month from different traffic sources, what are these website visitors doing when they get to your website (Are they bouncing away straight away? It’s probably because you have a horrible website or you are getting low quality traffic), how many enquiries or sales are you generating through your website? (You aren’t tracking this you say?), is your website traffic increasing or decreasing every month? (You are tracking this on a regular basis aren’t you?)
  • Show me how visible you are on Google when customers are searching for your key products and services? (You are tracking this data aren’t you?)
  • Show me how your pay per click advertising campaigns are performing on Google AdWords (You have tested this haven’t you?)
  • Show me how your social media campaigns are feeding into your digital marketing strategy to connect with key influencers and boost your brand online (You are active on social media on a regular basis aren’t you?)
  • Show me how well your email marketing campaigns are performing, I want to see open rates, click through rates, popular content, active customers
  • Show me your average order values and customer lifetime values per traffic source, I want to see how your individual digital marketing campaigns are performing against your traditional marketing activities. Show me the return on your investments for all of your activities.

During our initial analysis when speaking with businesses, we ask some very probing questions about the businesses we may choose to work with in the future. We want to make sure that you are ready to invest in digital seriously. We want to make sure that you are truly open to increasing your revenue through digital marketing, or whether you are simply looking at digital to dip your toe in and seeing everything as a cost and a tick box exercise.

 

Facepalm Star Treck

 

Generally speaking, when we hear comments such as “Digital doesn’t work for our industry” there isn’t a great deal we can do to help at this stage. Let’s chat again in a couple of years when you’re ready to talk things through seriously and are more aware about how the world has changed. For those who can answer some of the basic questions outlined above, then this is where we come in to get you on the right track and get your digital marketing campaigns performing well.

 

We Had SEO Done Once

Search Engine Optimisation is never done. It is part of an ongoing process designed to increase organic traffic to your website over time and ultimately sales / enquiries / revenue depending on the sector you are working in. We’ve seen businesses who thought they “had SEO done” previously and decided to go no further, against our best efforts to convince them otherwise. Avoid making the same mistakes as we have seen to many other businesses make, invest in your digital channels to build long term results, rather than seeing SEO as “done”;

 

Weve Had SEO Done Once

 

Would you ever see your physical shop or office space as being “done”? Or would you empty the bins daily, clean the carpets, tidy the desks, bring in new customers, promote your shop as being open, walk your shop floor daily, add new products to your inventory, run special offers and promotions to generate new customers and more? It is no different when looking online. The only difference comes down to choice. Each individual business either choses to invest in digital, or they don’t. Living in a digital world, you yourself will naturally research many of the products you have around you right now online in the first instance.

 

We Already Have a Website, Why Do We Need Another?

Is your website performing? No? Is your website mobile friendly? No? Does your website look like it was built in 1996? Yes? Your customers online are looking for a website that sells a specific product or service, is extremely easy to use, is branded very well and fits with their personal beliefs. If you website was built by your friends neighbour’s son who was taking a Dreamweaver course 10 years ago then it probably isn’t going to be relevant for your customers.

A bad website is like turning up trying to sell to potential customers unwashed, unshaven, wearing unfitted clothes with holes in and smelling like a wet dog. If you turned up in person to sell to potential customers like this, how do you think they would react? And how is this different online?

Your website is your digital shop front, make it count and engage with your audience. Website visitors want to see that you care, that you are there to help them accomplish their goal, that you are only a phone call away from being able to answer their queries and that you actually want new customers. A bad website simply pushes people away.

 

Google1998

 

A good website builds loyal customers over time. Your website may not look as bad as Google’s did back in 1998 (although we have seen some that do come close!). Do you think Google would be as popular today if they didn’t invest in their website seriously over the past several years?

 

We Spent 10’s of Thousands on Our Website about 5 years

5 year is a lifetime in the digital world. Traditional civil engineering projects are often designed to last 100 years. You’re lucky if your website lasts 100 months without any input. Unfortunately spending money on digital projects does not guarantee quality. We’ve seen so many instances where companies have spent a lot of money on websites which simply haven’t delivered. Only recently have we seen a brand new website launched that is effectively telling Google to go away.

This is an unfortunate reality for many businesses, which is why we launched our Digital Lifeline packages so you can call on someone to give you solid advice about your digital activities and website technologies. Having bought a website years ago and wondering why this isn’t performing now is a little mad when you compare this to the real world. Imagine if you bought an old car from a sleazy second hand car sales man, you can picture the type, and then you decided not to get an MOT done at all, no services, any repairs were done with your own hammer, screwdriver, car manual and a bit of duck-tape where needed. How do you think your car would be performing today? Probably not very well.

Again, the same is true for your website. If you see your website as a cost, then you have already lost. If you see your website as a vehicle to increase ecommerce sales, enquiries from around the globe and ultimately revenue then you are on the right track. Imagine living out in the sticks, with only a post office and a corner shop in the village. Not a great deal of job opportunities (i.e. personal revenue). In this instance, buying a car isn’t a cost, buying a car gives you freedom to break into new markets such as cities and increase your personal revenue by getting a higher paid job. Your website is no different – when you invest in your website seriously.

 

We bought a website once

 

Your Website Should Generate a Return on Your Investment

Have a think about this;

  • If I asked you to give me a £1 coin right now, how many of you would pop one in the post to us? No-one? Why? We’re a great bunch of folk 🙂
  • As a comparison, if I asked you to give me a £1 coin right now, and I would give you £2 back, how many £1 coins would you send us in the post? I’m guessing that you’d empty your bank account, right? Because you would double your money overnight.

The logic of investing in digital marketing channels is no different. The difference being between traditional marketing channels and digital marketing channels is that you can track every single detail in one of these channels, whereas you can track very little results in the other channel.

Looking at the famous quote;

 

“Half the money I spend on advertising is wasted; the trouble is I don’t know which half.”

 

I’d like to expand on this quote and be a tad facetious;

 

“Half the money I spend on advertising is wasted; It’s the offline half!”

 

Being able to track and understand how all of your marketing channels are performing will allow you to make strategic decisions to grow your business. Simply spending money aimlessly on activities that you’ve always done in business probably isn’t the best approach going forward, unless you are confident that this is already working for you.

 

Next Steps

We work with businesses of all shapes and sizes, some who are well versed in digital technologies and are needing support along their fast paced journey, and also companies who require a good amount of support as they are still at the start of digital journey. We will work with any business who requires our help and is ready.

The familiar quotes couldn’t be truer;

 

“You can lead a horse to water, but you can’t make it drink” – Quote

“When the student is ready, the teacher will appear” – Chinese proverb

“A journey of 1000 miles begins with a single step” – Chinese proverb

 

We’re ready to work with you and your company as soon as you are. All of the contents of this blog post are choices which people and businesses can make. People either choose to do something about their underperforming website and talk to us, or they choose to do what they have always done.

The more companies I personally speak with, the more I realise that success in the digital world is not down to our amazing work alone (although this does help!) but it is often down to the choices made by the individuals within either ambitious or struggling businesses.

Remember, all you need to do is ask we we’ll be there to help.

Blue Pill Red Pill

The Importance of Using Progressive Enhancement Website Development Techniques

We’ve spotted a trend recently with many website developers utilising technologies that make it difficult for search engines to crawl and index the website. Meaning that when search engines find it difficult to understand the content of your website, that you are in a position whereby Google may either penalise your website for spammy behaviours or simply losing a significant portion of the traffic to your website and ultimately revenue too. Clearly for websites that are generating a lot of visits from search engines, if this suddenly dropped off, how much revenue would you lose out on?

The trend we have spotted is around using JavaScript technologies which are inhibiting search engines from crawling websites. So while a new website may look flashy and all-singing-all-dancing, but if the new website cannot be easily crawled by search engines then quite simply you are going to be losing a lot of organic traffic to your website and ultimately sales / enquiries. Don’t make the same mistake that so many website developers do and use the latest technology without thinking through the consequences of what this means for your overall digital marketing strategy.

 

Common Problems

The common problems we are seeing more frequently at the minute are with developers using JavaScript technology which often looks nice for users. From a search engines perspective, JavaScript technology is difficult to crawl which can confuse the search engines and would always be recommended to avoid.

As a prime example, a local business recently re-launched their ecommerce website which certainly looked pretty but when viewing the website with JavaScript turned off (as Google would see it), then there is no content to display at all;

 

Website Using Too Much JavaScript Technology

 

A website that looks good but can’t be indexed to Google is the equivalent of having a beautiful shop on the high street and keeping your doors locked at all times – you aren’t going to be generating any sales. For this business specifically, they have been notified of the issue and are working to fix the problem. Let’s be clear though, this is the exact reason why it is important that you are working with the right digital agency who understands how each piece of the digital marketing jigsaw fits together. A good looking website is often not the same as a good performing website. Good performing websites think about usability, functionality, SEO, PPC, Email Marketing, Conversion Rate Optimisation and more.

 

Why this is a problem for search engines

Developers love to use new technology, but this isn’t always the right decision to make. As a nice comparison, if a new website removed the traditional login username and password and instead replaced this with fingerprint scanning technology to access the website, which is possible. Sounds like a fun and exciting thing to play around with, right? But when you dig a little deeper, this means that only those with the latest Samsung Galaxy phones and certain specialist laptops would be able to use this technology, forcing everyone else away.

There is always a place for new technology and we would always encourage people to experiment with new technology to lead the way in their industry. That being said, you cannot do this at the expense of forcing people to use this technology if they don’t have the means to do so.

The same is true for Google. Search engines cannot easily index content that is powered by JavaScript. Which means that all pages on your website need to be accessible when JavaScript is turned off. Google recently updated their official guidelines on the topic which states that websites should be developed using Progressive Enhancement. So while some of your JavaScript based content may be being found by Google, it would always be recommended to follow Google’s guidelines on the topic to improve the chances of benefitting the website in terms of SEO;

 

What is Progressive Enhancement?

So what exactly is progressive enhancement? Well it comes down to creating a website (or mobile app) that can be run on all devices easily with basic functionality. Then if a certain device has a specific piece of functionality or technology, then you can enhance the usability of the website based on this technology. Most importantly, don’t assume that everyone accessing your website has all of the technology available that you think they do.

For example, how many times have you been prompted when accessing a website from your laptop which asks if it is OK if this website uses your location?

 

Website Wants to Use Your Location in Browser

 

While this technology can certainly work on website, it is often rather inaccurate due to the way your location is essentially guessed based on several factors. Compared with the GPS signal from your mobile phone which is accurate to within a few feet of your location. This is a prime example of when progressive enhancement would be used, with a baseline set of website features not using the Geolocation and only asking the user if you can use their location when they are accessing from a mobile device. People accessing services through their mobile device are used to giving websites their location in return for some form of added features or functionality. As an obvious example, Google Maps clearly needs your location to help you get from A to B.

From a search engines perspective, it is important to use progressive enhancement at all times to ensure that they can easily crawl and index your website and content. Far too often are JavaScript based websites (and Flash websites back in the day!) are built without thinking about how Google is going to be able to crawl them. When using progressive enhancement, this ensures that the baseline website is still accessible to Google when JavaScript is turned off.

Progressive enhancement is not only recommended by Google, but it is also recommended by the wider community opposed to the older approach of graceful degradation. The reason behind this is because it provides a much better user experience when people are accessing a website from a variety of devices with multiple technologies.

As a simple summary of the above, all modern smartphones come built with GPS, accelerometers, gyroscopes, compasses, barometers and more. Whereas most laptops and desktop computers don’t have any of these technologies built in by default. Any website that depends on technology for key features or functionality that not everyone has is doomed to fail.

 

How to Test

To check your own website is displaying correctly for Google, turn JavaScript off in your web browser and navigate around your website. If you can’t easily access all parts of your website with JavaScript turned off, then the chances are that search engines are also having difficulty. While it is true that Google does attempt to index JavaScript based content, they do still find it difficult which is why they recommend progressive enhancement their self.

Removing any ambiguity from your website means that Google will be able to crawl and index your website with ease. It is easy for Google to assume that you are showing one version of content to the user and another version of content to search engines – for which websites can be penalised for this behaviour. Always use progressive enhancement as a way to develop websites effectively.

If you need any tips, advice or pointers related to the technology your website is using then get in touch. We have a range of services to support your individual needs, from starter Digital Lifeline support packages to our high end consultancy packages designed to be tailored to your every need.

Is it Ok that Google is Tracking Your Every Move?

Did you know that Google is tracking your every single move? No? Most people don’t, yet they are;

 

Google Tracking Your Every Move

 

The above is where I have personally been recently while out and about on the road visiting businesses which is naturally a large part of the work that I do. This isn’t some feature that I have personally set up. No, this is something which Google has enabled by default and means that they are tracking my every move, and yours too. I’m sure there will be some small print in the terms of use somewhere but this isn’t the point.

Google is not alone in this activity. Back in 2012, Apple were found out to be tracking users without permission. With the rise of smart technology such as phones and tablets, which have many sensing devices built in, there needs to be a much easier way for users to understand what data is being tracked and how this is being used.

 

Check what Google knows about where you have been recently

 

To see what Google knows about where you have been recently, click the above link and sign into the (or one of the..) Google Accounts that you are signed into on your mobile phone. You’ll be surprised at what you can see!

 

Clear Permissions and User Control

Currently it is not clear for users what data is being tracked by the majority of software and apps that you are using on your mobile devices. The industry as a whole needs to take more responsibility for privacy and security related issues. Google has recently launched Google My Account which is designed to take this a step closer to where we need to be, although I’m not sure this going far enough;

 

Google My Account

 

If you are concerned about what information Google is tracking about you, it would be recommended to check through the settings for all of your Google Accounts within the My Account feature that has recently launched. Specifically where you can turn off the feature for how Google is tracking your every move if you feel this is a little too invasive into your life. Simply navigate to the Personal Info & Privacy page, then scroll down to the Places You Go section to turn this off;

 

Turn off Google Location Tracking

 

Privacy

The amount of data that is being collected about everyone on a daily basis is enormous. Data that can ultimately be used for advertising purposes, sold to other companies or even stolen by cyber criminals. There are already rules in place around data security including the Data Protection Act which states that any information stored must be;

  • used fairly and lawfully
  • used for limited, specifically stated purposes
  • used in a way that is adequate, relevant and not excessive
  • accurate
  • kept for no longer than is absolutely necessary
  • handled according to people’s data protection rights
  • kept safe and secure
  • not transferred outside the UK without adequate protection

There is stronger legal protection for more sensitive information, such as:

  • ethnic background
  • political opinions
  • religious beliefs
  • health
  • sexual health
  • criminal records

What is interesting when comparing the above with what is actually happening in the world, it takes no legal expert to raise a few eyebrows at the disparity between the rules and reality. What is clear though is that there needs to be a much more thorough and clear process in place for all data stored about people by large organisations. When comparing this to a real world context, if you were being followed around all day, every day, by a private investigator how would you feel?

Experimenting with the New Top Level Domains

A while ago we talked about what the new top level domains mean for businesses. Since writing that blog post over 12 months ago, a lot has happened. Since the initial announcement of new top level domains coming to the market, we thought it would be worth looking at what has actually changed and what you can actually do with the new domains.

 

New Generic Top Level Domains

Back in February 2014, there was a total of 362 top level domains that had been registered. Today, there are 988, a figure that is almost triple. Again, have a good browse through the top level domains that have been registered over the past year to get a feel for how things are changing.

An interesting point to note that while we have seen an almost tripling of top level domains that have been registered, we’ve yet to see any significant rollout of these domain names from businesses and brands online. The .google top level domain has been registered, yet we are all still using google.com or google.co.uk when searching. Likewise, .barclays has been registered but we are also still using barclays.com or barclays.co.uk. So why is this?

Well, honestly, things haven’t really changed that much over the past year when it comes to how customers perceive top level domains. If anything, people have become more wary of websites that don’t appear genuine, with cyber fraud and phishing attacks becoming part of everyday life. You only need to look back and read some of the topics we’ve covered on cyber security recently to see the scale of the problem; Cyber Security Conference 2015; Online Fraud and Cybercrime is a Serious Threat in 2015; Creative Entrepreneur 2014; A Short Story About… A Poorly Designed Website Allowing Anyone to Register as an Administrator Without Validation or Authorisation.

What this has ultimately led to is a situation whereby it appears that brands aren’t willing to experiment with the new top level domains just yet. So we thought we would experiment a little to see what kind of things we could do. It would be extremely unlikely for us to switch over to our new top level domain for the main website, since people are still very unsure about the new top level domains and still associate websites with the traditional .com and .co.uk. Hence why this is a nice little experiment to see how people can interact with websites and brands in a more user friendly and effective way with a little thought and planning.

 

Introducing contrado.digital

That’s right, we’ve just purchased a trendy domain that fits well with our brand, http://contrado.digital. Yes this is the full domain. The .digital top level domain became available quite recently, so we thought it would be worth securing this to protect the brand. Going beyond this, we’ve set up some additional functionality that allows you to interact with us a little easier.

 

http://search.contrado.digital

To search the Contrado Digital website, you could use search functionality that is built into WordPress, www.contradodigital.com/?s=searchQuery, although you may not know that exists. We’ve kept the search functionality hidden on purpose for the time being to avoid cluttering the main navigation as we found that it wasn’t being used a great deal by the majority of website visitors. But what if you still want to search the website without having to remember what the specific search URL is?

That’s why we created search.contrado.digital. Simple type this into your web browser, followed by your search query and you will automatically be shown a search results specifically for your query. For example, here are a few you can try;

So there’s a nice easy way to find exactly what you need on the Contrado Digital website.

 

Search Engine Optimisation

 

http://email.contrado.digital

To email us at Contrado Digital, again, simply type the following into your web browser, email.contrado.digital and you will be presented with a simple way to drop us an email without any effort at all. Go on, give it a go;

Yes, you could just go to the homepage, scroll down to the bottom and click on the link there. But why waste your time looking for an email address when you could just setup a nice piece of functionality that automates this whole process for you.

 

Small Business Email Addresses

 

Social Media Channels

How about if you want to go straight to our social media channels to find out the latest trends happening in the digital world? Sure, you could again go to the website, hunt for the social media icons or go to the social media website and search for us there. But why waste your time doing that when you could just go straight to the relevant channel with ease;

Nice little bit of functionality!

 

Social Media Sharing

 

Summary

While the new top level domains are certainly still in their infancy, is there any way that you could be using these to help your audience connect with your brand easier? I’m sure there are many different and unique pieces of functionality that can enhance the user experience of your website by using this technology. What ways can you think of that would help by using a similar setup?

A Short Story About… A Poorly Designed Website Allowing Anyone to Register as an Administrator Without Validation or Authorisation

A Short Story About… series, sharing stories about epic fails related to digital marketing, web design, technology choices and more. All designed to make you aware of what can happen when you work with the wrong people and an inexperienced digital agency. Remember the importance of working with the right digital agency.

Sharing these real life stories with you allows you to review your own setup to make sure you aren’t making the same rookie mistakes. Sharing is caring and it also makes our life easier when you speak with us about increasing your revenue through digital marketing and technology.

 

Look at our new shiny website!

The story starts here…. We received an email from a business owner who mentioned that they had passed on our details to another business owner related to some work that they needed support with. Nothing too strange here, we get this all the time.

Naturally, when we receive requests such as this, we have a quick nosey around to get a feel for the website, digital marketing channels, technologies in use and more. Based on this quick analysis we soon get a feel for where the business is at when it comes to how digitally advanced they are, or aren’t, as the case may be.

Having already heard of the business that had been referred to us, we already knew that the website was in development with another agency (sorry, we’re not going to name and shame here, but we shall say that they are local to us…). Based on this, we had a quick look around the new website;

 

Poorly Designed Website X

Website X

 

Initial Investigations

One of the key areas we investigate is to see what technology the website has been built with and ultimately decide if we even want to get involved with helping the business. Depending on the technology used and other factors, we often turn down work that is just too far gone to help and there is no budget for a complete rebuild. Often bad decisions in the past can lead to costly solutions in the future, often which businesses don’t have budgets for re-doing something. Thankfully though, there is generally something we can help with in one way shape or form.

We always recommend the right solutions for businesses, it’s unfortunate that this ethos isn’t the same for all agencies, with many often using poorly configured technology, custom built technology and everything in between. Hence, why businesses come to us when things have gone wrong elsewhere and they are looking for a good solution that is truly suitable for their long term needs. As a caveat, there are a lot of good agencies around alongside ourselves and we can quite happily point you to them. It is also true, as many businesses are painfully aware, that there are a lot of charlatans around too.

So, while investigating what technology was powering the website, we soon noticed a login button on the website;

 

Login Button Website X

 

So we had a quick look at the login page to see if this resembled any of the common content management systems around;

 

Login Page Website X

 

And what do we see here, a nice “Register” button, so we investigated a little further;

 

Register Page Website X

 

Ooohh, that looks like a nice easy registration form, so we tested a little further…;

  • Username: test
  • Password: test123
  • Confirm password: test123

Surely any content management system or website worth it’s weight in salt would handle guest registrations in a graceful and secure way? Well, no, and this is where we were really shocked to see how bad this system has actually been built in terms of security. After registering a user using the form available on the website for anyone to see, we went back to the login page from earlier and tested these details;

 

Manage Pages Website X

 

And here we are, straight into the administration area where we can edit the content of the website as we choose. Adding content, deleting content, uploading images in the gallery, addling links to websites of our choosing and more. To test that we do indeed have the right privileges, we added (and then immediately removed) a piece of content to the website which was visible once we updated this;

 

Edited Website Content Website X

(Click for larger view)

 

The above isn’t the actual content that was added to the website for obvious reasons. It was simply a number “1” which was added to one of the sentences then removed immediately. The above image is purely for illustrative purposes and to emphasise the point.

It is extremely worrying that a website can be built with no security in place at all. This process took no more than 5 minutes to investigate, test and access the admin area. Imagine what we could do in 10 minutes…

Now if someone came along who had an axe to grind or was looking to infect websites with malware and other code, this would be extremely easy thing to do. Not only could this result in the website being blacklisted from Google, your own website visitors and customers could be infected with viruses or your website could be (unknowing to you) part of a bot net that is hacking many websites around the world.

This blog post is not designed to show how good we are when it comes to identifying security issues related to websites (although we aren’t too bad at that…), this blog post is designed to highlight how easy security issues can occur when you are using either the wrong technology, incorrectly configured technology, sloppy web developers or an agency who clearly has no idea what they are doing.

For any website or web application, security should be embedded from the start of the project and clear testing throughout to ensure that only those who have access to the administration area do have access to it. Security is not an added extra, this is your own business and website that we are talking about. An area that you have clearly worked hard on and one that will no doubt have been a reasonable investment. Don’t get caught out with rookie mistakes.

Imaging if the administration area contained a list of all of your customers who had registered with your website? Or if this contained personal sensitive information in unencrypted form, names, email addresses, phone numbers or heavens forbid credit card details? Such a simple mistake can turn into an enormous problem. All preventable when you are working with the right people who have the skills, knowledge and experience to do the job properly.

 

Technology

For reference, the technology behind the website in this case study was running the following;

  • IIS 8 Web Server
  • Net / ASP.Net MVC Framework (this is where the problem and solution lie, allowing anyone to view the user registration page and allowing the default user to be created as an Administrator)
  • Google Hosted Libraries
  • jQuery
  • Fancybox

Incorrectly configuring technology is one of the most common pitfalls related to website security. It is so important that you are working with a well-respected company who have staff with a wealth of experience and capable of preventing issues like this occurring.

 

The Solution

Throughout this blog post, the company has remained masked and is not identifiable in any way for obvious reasons. The company has also been notified and their agency is working on a solution as a priority. We believe in responsible disclosure, which is why we have published these findings, to avoid others falling into the same trap.

For reference for the developers working on this solution, if any pointers are needed, a quick Google search for the solution came up which may be quite useful;

Please also have some form of robust security processes in place within your business to prevent this happening again in the future. Please also check all of your other clients who you have built websites for in this same fashion, as this could also need fixing on their website too. Again, it is extremely simply to gather a list of websites built by the same agency where this problem could also exist;

 

All Other Websites Possibly Open to Attack

 

For anyone looking to do harm, this could turn into a reputational nightmare for the agency involved along with causing all of the businesses involved an awful lot of lost revenue if this was exploited fully by a hacker before a solution was implemented. Staff training, for both technical and non-technical users is key in this area to ensure that problems are identified before other people find them and exploit them.

 

Summary

As mentioned at the start, it is essential that you are working with the right digital agency who is capable of delivering projects in a secure fashion. Simply working with the cheapest company, the company who can talk the best talk or the company who manages to convince you that their solution is the best one over all of the others just isn’t going to cut it. As a business owner or decision maker, it is ultimately your responsibility that you are working with well-respected agencies who know what they are doing.

If you are concerned by the contents of this blog post, if you are questioning your current supplier or are generally concerned about the security of your digital assets, then get in touch. Cyber security is a hot topic for a reason, it is hugely important to protect the future of your online presence and more.

The learning point: Ensure your website registration process doesn’t allow new users to access parts of the website they shouldn’t. In this example, using a well-respected content management system would have prevented this issue altogether. Many website builds do not require any fancy custom built content management system solution, popular platforms such as WordPress or Magento are often perfect for the job.