Drupal security
Drupal has a strong security posture when it is patched, configured, and monitored. We do all three. Monthly patching, config audit, incident response, and the boring operational work that keeps a site out of the news.
How we approach it
Patch on the release schedule
Security advisories are applied the same day for critical, within a week for the rest. Documented in your monthly change log.
Least-privilege by default
User roles, permissions, and file uploads all scoped tight. Editors get what they need. Nothing more.
WAF and rate-limiting matter
A managed WAF (Pantheon, Cloudflare, or Sucuri) blocks the noisy stuff before it reaches PHP.
Incident response is documented
When something happens, the runbook is on the shelf. Escalation paths, rollback procedures, and post-mortem template ready to go.
What's included
- Core and contrib security patching
- Drupal permissions and role audit
- File upload restrictions
- WAF configuration (Pantheon Advanced Global CDN, Cloudflare, or Sucuri)
- Two-factor authentication for editors and admins
- SSL and security header configuration
- Backup and disaster recovery review
- Incident response runbook
- Post-incident review if anything happens
Who it's for
Organizations under compliance requirements
HIPAA, FERPA, PCI, state privacy laws. We map Drupal configuration to the standard.
Sites handling member or donor data
Nonprofits with donor records, associations with member data, healthcare with patient portals.
Post-incident cleanup
Sites recovering from a breach, defaced content, or credential leak. We stabilize, patch, and document.
What it costs
Security-only engagements start at $10K for an audit + hardening pass. Ongoing security work is included in monthly support retainers.
Common questions
What's the fastest attack path against a Drupal site?
Unpatched core or contrib with a public CVE, followed by weak admin passwords, followed by outdated PHP. Patching and 2FA close 90 percent of it.
Do you handle incident response?
Yes. If you are actively compromised, we can respond within business hours, with on-call for retainer clients. We stabilize, patch, and document.
Can we get a security report we can share with our board?
Yes. Deliverables include a plain-language executive summary alongside the technical audit.
Ready to talk through it?
Book a free discovery call. We'll talk through what you need, what we'd recommend, and whether we're the right fit.