Website Security
The ordinary hygiene behind an accidental publication: folder listings, uploads, logins and who is watching.
Read about website security
An engineering firm's website is a document library with a homepage attached. Capability statements, project sheets, spec pages, sample drawings, registration details. Storing all that is the easy part, so web hosting for engineering firms is really about deciding what is genuinely public, because a server will publish whatever you put in the folder and will not ask you twice.
Look at what an engineering firm actually publishes and it is mostly files. A capability statement. Project sheets with photographs and a short scope. A line card. Sometimes a standard detail, a specification page, a sample calculation, a copy of a certificate of insurance. Marketing pages sit around those files, but the files are what people come for.
That shapes every hosting decision you will make, and it does it in a way that is different from most trades. A landscaper's site is pages. Yours is pages plus a cabinet, and the cabinet needs somebody who decides what goes in it.
Sort every document into one of three piles before it goes anywhere near a server. Not after.
The third pile is the one that matters. Everything else is a preference. That pile is a liability.
We will sit down with your firm's public, gated and never piles and set the site up so the third one has nowhere to land. Since 1999, for Western New York firms. Call 716-771-2536.
Here is how it happens, and it is almost never dramatic. Somebody needs to send a large file to a client and email will not take it. So they upload it to the website, because that is a place they can put a file and get a link. The link works. The client is happy. Nobody deletes the file.
Months later the folder has thirty files in it. A search engine finds one of them through a link in an old email signature, or the folder simply lists its own contents in a browser because nothing was set to stop it. Now a set of drawings with a client's site address on it is indexed and downloadable by anyone who searches the right phrase.
Nobody attacked you. Nobody guessed a password. The file was public the moment it was uploaded, because that is what a web server is for. The only thing that changed later was that somebody found it.
Look in the file manager in your control panel, not in the website's menu. Menus only show pages somebody linked to. The folders usually have names like files, uploads, docs, ftp or a person's initials.
Search a search engine for your domain name restricted to PDF and drawing file extensions. You will find things nobody remembers uploading. Do this before a client does it.
If someone can visit a folder address and see a list of its contents, that setting is on. It should be off on every site. It is one line in the server configuration and any competent host or web company can do it in minutes.
Removing the link to a file does not remove the file. It only removes the signpost. Delete the file itself, and remember that anything indexed will need a removal request as well.
Use business email with proper attachments, or a client file-sharing service, or a genuinely password-protected area. Do not use the public website as a drop box. That habit is the whole problem.
None of this requires a bigger hosting plan. It requires somebody to decide it is their job. If that person does not exist at your firm, that is the thing to fix first, and our website security page covers the ordinary hygiene that goes with it.
Some engineering work carries obligations that follow the document rather than the contract. Defence and aerospace work can be export controlled. A lot of civil and industrial work is covered by a confidentiality clause the client's lawyer wrote. Utility, transit and water projects often involve site information that nobody wants in public for reasons that have nothing to do with competition.
We are not going to tell you which rule applies to which drawing. That is a question for your own counsel and your compliance officer, and the answer changes by client and by contract. What we can tell you is the practical shape of the problem, because it is the same every time.
The safe default for a public marketing site is that no client deliverable goes on it. Show the work in words and in photographs you have cleared. If a client wants to see technical depth, send it to them, and let sending it be a decision somebody makes each time rather than a folder that sits open.
Check with your own adviser before publishing anything you received from a client, and before publishing anything produced under a government contract. Treat that as the rule and treat exceptions as approvals you can point to in writing.
If you chase public work, your website has a second audience that behaves nothing like a normal visitor. Somebody at an agency, or at a prime looking for a subconsultant, is checking whether you are real and whether you have done this before. They spend about a minute.
They want a few specific things and they want them without a phone call. Your legal entity name as registered. Your business classifications, if you hold any. The disciplines you actually practise. A short list of projects with owner, scope, and roughly when. A named contact who answers.
Most firms have one, and most firms have it as a PDF from three years ago sitting on a page nobody links to. Two fixes, and neither is expensive. Put the same content on the page as ordinary web text so it can be found by search, and keep the PDF as the version somebody attaches to an email. Then put a revision date on it, visible, so a reader knows whether to trust it.
Past performance is the part that ages worst. A project sheet from a job that closed in 2019, with a reference contact who has since retired, is worse than no sheet. Set a calendar reminder to review the list once a year. That review is also the moment to check that every project on it is still one you have permission to name.
One more thing that costs nothing. Use email at your own domain on every one of those documents. A capability statement with a free webmail address on it reads as a firm that is between things. Our business email page explains what that involves if you are still on a free address.
Give us the login and we will list what is in the upload folders, what a search engine has already indexed, and what should come down. If nothing is wrong, we will tell you that instead of selling you a bigger plan.
Professional registration is a claim, and claims on a website need to be exact. Buyers check them, competitors check them, and boards do occasionally take an interest in how a firm describes itself.
The practical difficulty is that registration is per state, per discipline, and often per firm as well as per individual. A principal registered in New York and Pennsylvania does not make the firm licensed everywhere it has a project photograph. Some states also regulate what a firm may call itself and how it may advertise engineering services.
The hosting connection here is small but real. A registration list is content you will change several times a year, so it needs to live somewhere you can edit in five minutes without calling anyone. If updating one line on your site currently means emailing a web company and waiting, that is a maintenance problem worth solving, and taking over a website covers what to collect if you are moving that work in-house.
A one-person consulting engineer, and this covers more firms than the industry likes to admit.
If you are a sole practitioner working on referral, your site's job is to prove you exist, say what you do and how you are registered, and give somebody a way to reach you. That is four or five pages. A document library on that site is an empty room you now have to keep clean, and every file in it is a file you have to remember you published.
Where spending more is genuinely justified: you have staff who upload material without a review step, you run a real gated area with client accounts in it, you host an application rather than a set of pages, or your firm has a compliance obligation that requires access records. Those are reasons. Having fifteen employees is not one on its own.
And if you are already paying for a managed plan for a five-page site with no logins on it, you are buying maintenance for machinery you do not run. Say so to whoever sold it and ask what it is protecting.
AldoMedia has built and looked after websites for Western New York businesses since 1999. We are an independent authorised reseller rather than the operator of the underlying platform, which means we set the account up, we help you get the site onto it, and we tell you when the plan you are already paying for is the right one.
For an engineering firm the useful first job is usually an inventory. What is in the upload folders, what is indexed, what should never have gone up, and who at the firm owns the answer from now on. That is an afternoon of work, not a project.
Call 716-771-2536 or tell us what your site runs on. If your current arrangement is fine, that is a perfectly good outcome and we will say so.
Only ones you produced and own outright, with nothing client-identifying on them, and preferably redrawn as an illustration rather than lifted from a deliverable. Anything a client paid for is theirs, and anything under a confidentiality clause stays off. If you want to show technical depth, describe the work in words and send the detail to people who ask.
Yes, and it is the most common one we see at engineering firms. A file in a web folder is public whether or not you linked to it, and those folders are never cleaned out. Use email attachments, a proper file-sharing service, or a genuinely access-controlled area instead, and go and look at what is sitting in those folders today.
Search your own domain restricted to document file types and see what comes back. Then open the folders in your hosting control panel's file manager, because that shows files nothing links to. Turning off directory listing stops a folder from displaying its own contents to anyone who visits the address.
Both, doing different jobs. The web page version can be found by search and read on a phone, which the PDF cannot. The PDF is what somebody attaches to an email or drops into a procurement portal. Keep the two saying the same thing and put a visible revision date on each.
Listing them is normally expected, and buyers check. The risk is not listing them, it is listing them loosely: mixing individual registration with firm authorisation, or leaving a lapsed state up. Keep the list on one page you can edit quickly, and check with your board or your counsel about what your profession allows you to claim in advertising.
Most firms do not. A portal is a login page, a set of accounts and a support obligation, and firms that build one often find clients keep emailing anyway. Build one when clients are actively asking for it and somebody will own the accounts. Until then it is an attack surface you added on purpose.
The ordinary hygiene behind an accidental publication: folder listings, uploads, logins and who is watching.
Read about website securityEmail at your own domain, which is what belongs on a capability statement and on every proposal.
Read about business emailThe plan type most engineering firm sites belong on, and what the higher tiers actually change.
Read about shared hostingEvery trade we cover is listed on hosting by industry.
Hero image: David Adam Kess, CC BY-SA 4.0, via Wikimedia Commons. Cropped.
Tell us what your firm's site runs on and we will look at what is sitting in the upload folders. If the answer is nothing worrying, that is the report you get.
Get Your Web Hosting Plan Get help choosing
Or call 716-771-2536 and tell us what the site has to do. If the plan you are already on is the right one, we will say so.