Some key audiences can be really difficult to reach. Those of us who focus on helping website owners keep their sites safe from hackers know this well - those who we think we could help the most are often the least tuned-in. Through the years that Google has been chipping away at the challenge of teaching all webmasters how to be security-conscious, we’ve learned some lessons we like to share - the challenges, techniques that have worked, approaches we tried and haven’t been quite as effective, and how this ties to our own philosophy of focusing on content that is relevant, targeted and focused on solving the user need.
How Do You Teach 10 Million Hard-to-Reach Website Owners the Essentials of Website Security?





























Auto-generated transcript - may contain errors. Tap a timestamp to jump the video.
My father runs a small online newspaper in his hometown. He lives in a small town in Northwestern Columbia called Tamesi, Santokia. This town is so high up in the Andes, it's literally above the clouds. And his online newspaper is something he painstakingly puts together using nineteen nineties desktop publishing tools, he creates a PDF and then proceeds to email it to all of his readers.
You might call it a zine if it were in the nineties, and there's, you know, something about about it that is rich because he's talking about poetry and the and the and the culture of the town and revitalizing sort of a sense of place that they've lost a little bit through through conflict in time.
And the main issue though that I have a little bit is that his paper isn't crawlable, searchable, indexed, and found on search results, which is a little bit ironic given the work that I do. My name is Juan Felipe Rincon and I lead the search outreach team for Google's trust and safety team, and our job is to teach webmasters how to make good content and make it accessible universally and useful and usable.
And in fact it's so ironic because as we're going around trying to help build tools and resources to help people websites, we're doing things around the world. A a team of people in five different countries around the world with global footprint. Just last couple of weeks we ran a conference in India for webmasters who are publishing newspapers in Hindi, and they're traditionally publishing newspapers that they're putting out on PDF and then putting up on search, and it's not crawlable and indexable, and we're going on and helping them figure out how to make it
discoverable for their users to make sure that there's actually a really good voice for Hindi content creators in India. And that's the beautiful irony of this, is that I'm leading a team of people who are teaching newspaper creators how to make a content editor and my own dad has a website that isn't online yet.
I mean they've been publishing this, they're on issue three hundred now, they publish it every two weeks. The fact is there's a little bit of me that that sort of tension, that desire to have his newspaper be online because it's it's pretty neat, is balanced out with deep dread.
And that dread is, it's not just about sort of what happens when I decide that I'm gonna set him up with a beautiful CMS, something like what Jane Austen was discussing yesterday, that would be perfect for him. But just the deep dread, not that I'm going become the tech support side, but that his website is going to be hacked, it's going to be compromised, it is somehow going to become vulnerable, and that that's going to harm him, it's going to harm his information, it's going to harm his readers.
And that's pretty intense, because the reality is hacked websites today are used for large number of very bad things. At the very least, it's just irritating. Right? You end up with a phone that starts vibrating out of your hand with some ad for a supermarket that didn't even actually put it in there, it's somebody else pretending to be there.
But in the worst case, you actually get more horrible things, things that are trying to take money, are trying to install software, that are to steal data, that are trying to sort of pull people into horrible scams and are taking advantage of good content creators, good website owners, who are just trying to set their story out and now all of a sudden are paying for somebody else to distribute nonsense.
And this problem is in the rise, and that's the thing that gives me concern. Earlier this year in May, we published a report on our hack recovery efforts around the world and we discovered that in twenty sixteen we had seen thirty two percent more hacked websites than we had seen in the previous years.
And our detection improved, but not so much that accounted for volume increase. We just saw way more websites being hacked by bad players. And there's no inclination that this is actually drastically decreasing. But there's a greater issue as well, which is that sixty one percent of the website owners, we had no way of reaching them.
We had no way of telling them your website's compromised, your website's vulnerable. And it's not because we haven't been trying for years to do so. We certainly have a team that encourages people to get on Search Console or other teams that encourage them to get on Google Analytics or use some kind of security monitoring tool.
The challenge is that these are really difficult people to reach sometimes because they're not connected to that space. There's some part that gives me hope though, which is that you know when somebody actually gets notified and when they actually get involved and get connected, eighty four percent of webmasters who recognize they have a problem and start fixing it are able to do so.
And they're able to do so and they're able to do so successfully, and actually in in in an amount of time that would seem less less onerous than you'd think for somebody starting from scratch. And so the thing we know though is that there's that challenge that we have of trying to actually educate people ahead of the game.
How do we get people to build their websites in a way that's secure and protected from this kind of behavior? And and how do we go about incorporating the technical know how to prevent themselves, a set aside the technical know how from how to actually fix the problem.
And we do this by encouraging non technical website owners, are small business owners, these are folks who have not spent the time, haven't had to spend the time, and probably shouldn't have to spend the time developing the technical expertise that we used to assume from CS experts or security experts.
And we encourage them to adopt five best practices. They're simple, straightforward things to implement to a certain extent. The first one is the value of notifications. Get yourself on something that will let you know there's a problem. We talk about Search Console a lot because we know, at the very least, if we detect it, can tell them through that, and it's a very direct channel for us to communicate to a website owner.
There are other tools as well. There are search engines, Bing has great ones, Yandex has great ones. Will notify people of this. There are security alert notification systems and we just encourage get something on there so that you know that there's a problem, so that you know before your clients call you and there's a problem.
Second practice we encourage is use HTTPS on your website across the board because that takes away a huge number of risk factors. That just eliminates a whole bunch of ways in which somebody can take over your site. Not only that, you're protecting your users data, you're protecting the transactions they're having, you're not unnecessarily exposing the conversation they're having with you to third party players in the middle.
Third practice we encourage is backups. Backup all of your data, backup all of your software, have a regular synchronized system to keep a replica of everything you have on your system because if your system does get compromised, having something of having a backup that is very recent, as recent as possible is going to make recovering all that that much more quick.
The fourth practice is what we call update patch and validate. Always keep your software updated, always patch everything that you install and always check on something you're going to install. And for a small business owner this can be onerous because you're saying how do I know to update and we encourage them, hey turn on the auto updates on software that has it, actually do so.
If you're hiring a software developer who's telling you, oh I can't do this because we're making changes to it and it's going to make the patches break, get them to do it so that it doesn't work that way. That's not an acceptable coding practice, just break a common platform that's being updated for security practice and make it difficult.
Make it happen, make it a priority. And the last thing we encourage small business owners, small site owners is have good passwords and use two step verification. A good password doesn't have to be some complicated set of symbols with numbers and digits and things that you don't free that you so easily forget that then you write it down on a poster in front of your computer.
It can be just something long and memorable that has enough combination of spaces and commas and other things in there for you to remember it. And so we have these five practices, we know if we can simplify these and we get people to adopt these, we actually protect them.
We know how much that helps reduce the likelihood that a website gets gets compromised in easy ways. The challenge is that, as I mentioned before, there are more than sixty percent of these folks we can't even reach, we haven't been able to get the message to them already.
And that's the challenge, the big challenge that we're trying to solve. It's such a big challenge that in fact I call it, I make it an interview question for anybody who's joining my team. How do you teach ten million website owners who are hard to reach the essentials of website security?
And I asked that question for two reasons, the first one the obvious one which is it tests for the knowledge. And it tests for good ideas because great ideas in this space are valuable, extremely valuable, and if any of you have any great ideas please let me know.
The other thing though is that every time I ask this question, it reminds me of the fact that to fix this problem, we have to go back to the very very basics of our discipline in terms of developer outreach, developer relations or technical communications.
And I think it's such a big challenge and also that reminder is so strong that I think it's very valuable for me to share some of the lessons we've learned with you about it. Because it'll also help us perhaps figure out what we're missing in the process.
But to just start, in text marketing, in tech marketing, in product marketing, in sales, we often talk about the adoption of innovation curve. Right, and we see it as the nested curve and you've all seen it before. You've seen this in plenty of startup pitches and plenty of startup discussions, and we talk about the people who've already joined in and over time how they accumulate.
After a certain volume of adoption, you reach an inflection point, and there's a moment when traffic takes off, and then that's when you start hearing phrases like hockey sticks and viral spread. In fact, Andy Young had a whole great presentation about how hockey sticks don't just magically happen, and this conversation usually talks about the roles of early adopters.
Early adopters in sort of influencing change and driving viral growth and viral spread, But going about this takes me back in order to sort of tell you where I'm going, need to go a little bit back about how this connects to my dad.
And to connect with how this goes to my dad, have to talk a little bit about potatoes. So bear with me. During my childhood, my dad worked at a research institution in Peru called the International Potato Center. This is a fantastic research institution that's been in existence for decades.
They run great projects where they have plant pathologists and plant geneticists and agronomists who study basically ways of creating better practices for farming potatoes to eventually help farmers protect their potato crops. And they run programs like, they had a program in Bangladesh in India that that improved food security for a hundred thousand families.
They doubled potato potato production in sub Saharan Africa since nineteen ninety four through some of the programs they supported. It's a fantastic program. And the main thing about it is that the process that my dad leading the communications unit, that basically would take the scientific work from the potato security researchers, if you will, and try to take it to the people who are running potato farms isn't all that different from the work that I do from taking the material from security researchers and taking it to website owners.
In fact, not to put too fine a point on it, but the work that I'm doing almost seems like the twenty first century version of the work that my dad was doing, which is also a little bit interesting given the following facts. The overall name for this discipline, this process called agricultural extension, and agricultural extension started in Dublin in eighteen forty five.
Again, ironies in this presentation is a coincidence as I live in Ireland right now. And this process started as a result of the potato blight in Ireland in eighteen forty five. Right? And the seminal or key textbook in this discipline is called diffusion of innovations by Roger by Everett Rogers.
How many of you are familiar with this textbook? I see a handful of hands. Now I think you all really need to become familiar with this textbook because the phrase early adopters was first put in this book. Right? And this is Rogers who was the son of a farmer in Iowa in the United States whose father failed to adopt some drought resistant corn and therefore their family suffered greatly for years, and he got into this as a passion.
And he got his master's degree at Iowa State University in sociology and statistics, that's where my dad got his master's degree in communications, but that's a different story. And there's an interesting curve in this book along with the s shaped curve, comes from this book as well, which is the innovation adoption curve.
And you see if you instead of taking cumulative adoption, take incremental adoption. You start seeing how it tapers down over time. You'd be familiar with this and if you're looking at the churn of your of the adoption of your product, sort of know that it does decline over time.
But the fact is that if we start seeing this as the people who are adopting this, and then we start seeing it over time, we could eventually look this as a way of actually segment the audience, segment these people, who are these people?
And Rogers does this in this book, it would cause the first group of people, first two percent to adopt any new practice, whether it's new potato farming techniques or new antivirus software or Twitter. The innovators and these folks tend to be, that tended to have in his books, larger farms, they were wealthier, they were super super risk tolerant, they could basically take all sorts of risk and stuff and try new stuff because if it failed, it's not a big deal to them.
They're also a little bit off on the social network, they weren't connected broadly, they weren't generally broadly respected, except by a small group of people, these were the early adopters, who tend to be younger, more educated, tend to be community leaders, or also tend to be people who are really really really really in tough spots, and who can afford to take a risk because they basically have nothing else to lose.
The early adopters generally are willing to take the risk, listen to what the innovators are looking at, they connect those, they connect that community, but it's the early adopters and the early adopters that basically stimulate the early majority who are more conservative, but are open to new ideas and therefore will tend to follow along.
But when we go back to talk about website security practices and the people that we're trying to target, it's none of these folks. It's the folks on the other end, the folks we don't often talk about in the marketing discipline, And Rogers has names for them, he calls them the late majority and the laggards.
Now the laggards word has given him a lot of critique because it seems loaded, but in fact they're just lagging behind in adoption. And when we think about our process of teaching website owners who haven't been on the early adoption of website security or technology, they basically join the game later, it's a different audience and we need to look at them and their dynamics a little bit differently.
So our focus is on improving our reach for this late majority, improving our messaging for that and really talking about late majority and laggards rather than sort of trying to drive the new adopters and so on, which forced us to do some major reassessments of both how we do our communications work to website owners and how we actually adjust and engage.
First thing is we had to reassess the audience and as you saw, know, in security communications for website owners, basically the language tended to be about SQL injections and about day zero attacks and about particular vulnerabilities. If I started reciting those, many of you would look at me and sort of of know where I'm going.
A few of you would know exactly what I'm talking about. Most of you would sort of be just right on that other side of the comfort fence in the terminology. You wouldn't feel comfortable explaining it to that. And think about the business here, and you're in digital marketing, you wouldn't probably feel comfortable explaining Now a small coffee shop owner whose website has been hacked isn't anywhere close to that usually.
So we had to adjust our language. First of all had to stop talking to sys admins and webmasters. You know that image of you know somebody sitting in a somebody sitting in a data center that has root access and that can basically sort of magically fix everything with a in a in a VI terminal and instead talk to small site owners, Talk to small business owners in their language, their terms, in terminology.
That's a shift for people who've been talking a lot about sort of robots. Txt and sitemaps and link practices and the like. The other reassessment we had to do was we had to reassess our language. As I said, we had to shift from talking about SQL injections zero day exploits to recovery guides and practices.
How do you know your website's hacked? How do you fix it? Here are the different ways in which your site might have been hacked. These are the three steps you need to take. Which for us was a change in conversation because we had to get a lot more didactic.
And how did we do this? We also had to do we also had to change how we talk to them instead of sort of we had to reassess our data as well to understand what folks were experiencing. We had to look through patterns in our website forms in a different way.
Look at search console communications in a different way, we had to interview website owners to really go and understand their journey very deeply and that way we had to augment the way we spoke about it. We would still have security researchers talking about security problems that were discovered and sort of really advancing the field, but we had to talk to people to fix and we had to educate and train and teach.
Popularize the practice. The other reassessment we had to do is we had to reassess our notion of reach. Because we had been talking about reach in terms of broadcast, and broadcast is fantastic for our information dissemination, but it's not necessarily a great way to ensure that you're driving practice and you're driving change in practice.
And so we had to essentially get out from behind the desk and in front of the camera. Right? We don't have a team of cooperative extension agents going around and talking to individual SMBs one by one to sort of teach them these five practices, but we can at the very least be a lot more open there, lot more visible, a lot more readily, regularly available to people to help them out and also start engaging much more with the community who are pushing these practices to help reinforce their efforts in some way.
And then we also needed to know when we would start pulling back because at some point these efforts do get momentum of their own, you do start getting an adoption curve with that set of people that's a little bit different. So the reassessments we made in terms of our, the way we think about reach, way we think about our language, the way we think about our audience also led to some changes in how we operate it.
First of all, we had to recommit to strengthening our own free feedback loop. We had been for many many years engaging constantly with the SEO space and listening to issues that were coming around. We had a whole team that we're talking to our ranking engineers and our crawling engineers to make sure that we were fixing problems, but we had to go back to talk to website owners.
Early on in my Google days, I've been at Google three and a half years, my team that was thinking about this started proposing, you know what, what we should do is just have direct one on one consults with webmasters who are going through a really difficult hack reconsideration.
I was a bit trepidatious of that. Those early days of Google, still early in the discussions of sort of how do we talk about search and search ranking for me. Certainly we've always known that having conversations about sort of what does Google want or don't want can be difficult conversations for us to have because it's not like we want anybody to do anything particular.
Just give the website, we'll try to figure it out and serve it to users. But I'm glad that my team pushed through and convinced me to make this happen and to do this because they learned an intense amount. The biggest thing about it was that it reminded them, it gave them back that empathy that they had never lost, but it's really sometimes difficult to look when you've been in spam fighting mode with some hack recovery to think about hack recovery that's a result of spam.
That's a shift in mindset. And that empathy to the problem that a small business owner having when you send them a message saying your website's been injected, we detected some kind of sneaky cloaking redirect, and then going, my funnel's dead, I'm not getting any more clients into my cart because people aren't coming through it, because there's some awful content on my page and I don't know what to do.
And then those conversations also gave us more insight as to the nature of the problems they were having. We sort of were able to categorize them into two. One was, I just really have no idea what you're talking about, Which clearly communicated to us we had to change how we did things in terms of the way we wrote our recover guides, way we sent our notifications to webmasters.
We're still working on it, still iterating on this and we always want to hear what on this is helping or not helping. The other thing we found out is that for companies that maybe are a little bit more resourced than organizational resource, they still have problems in terms of getting buy in for doing the fixes, which seemed odd to us.
We just thought it was obvious that a security fix needed to be done, you just needed to patch things. Just you know if you've been in the computing space often and long you kind of just believe that. But people would keep on talking about the fact that well I'm being asked for the ROI on doing the security patch.
Right? Or you know I have to get approval, I can't get approval and focus on the updates because we have this development pipeline that's on the round and every time we want to do a patch it sort of puts a halt on development because operations needs to sort of keep everything stable for a while and that just means that we can't move on and the CMO won't agree and the CTO and the CMO are loggerheads on it.
That helped us also recognize that aside from giving resources, we also have to help create allies for the security practitioners that are pushing for this. And if we go back to Everett Rogers, Everett Rogers has this phenomenal list of generalizations that he has in his book that come from doing vast literature reviews of people who have been in cooperative extension, innovation adoption technology, a variety of different disciplines.
Generalization nine point two from Edward Rogers is that change agent success is positively related to a client orientation rather than a change agency orientation. I listen to your customers give them what they need. Right? But it's good that there's theory that's been going around for two hundred years that confirms that what we all believe to be true is actually very empirically supported.
Second change we had to do is we had to revisit the value we were offering and how communicating it. We were always encouraging people to get on Search Console because that's how we that's how you know when we have an issue crawling your website, and if you have questions as to how you show up on organic search results, this is how you find out the data that makes makes you be better on that.
And we realized that for small business owners that actually was a is a very important thing to them if they're thinking about their organic search presence at all. When we were talking about website security and said why don't you implement these practices, we realized if we connect one and the other and we sort of drive, and oh by the way you get this notification thing for your security website that will help protect you, it drove the adoption of this practice that we really think is very important for the health of the ecosystem while
addressing that individual need of a business owner, that pressing market, how do I get an audience viewpoint, how do I get them to know where I'm located. Again, Everett Rogers has a beautiful generalization for this. Change agent success is positively related to the degree to which the diffusion program is compatible with clients needs, I.
E. Gave the users what they need. Change number three is to really focus on the barriers that webmasters were encountered, website owners were encountered, then remove them altogether. So we did things like search console, it's straightforward to get search console connected to a website, but we also realize that we think it's very straightforward if you have command line access, or if you have access to your domain registry, or if you're able to put a file on your server, but for some folks that actually is takes a few steps of learning.
And we realized there's something we can do here. So we started collaborating with CMS providers and hosting providers and so on to sort of say, hey, there's an API you can use to integrate on this. It's open and it's available. If you facilitate this registration, we can also send you as a hosting provider notification when your websites are compromised and you can send them to your website owners and they'll know about it and all of a sudden everybody is healthier as a result of this.
And we continue to work with other players in the ecosystem as well like CMS providers and plug in developers to sort of help them understand where there may be vulnerabilities and get those to go away altogether. We'll continue to work on that. You shouldn't have to use any specific product to have a secure website to the extent that we can help people through whatever tools we're promoting, we want to do that.
Complexity of innovation is negatively related to its rate of adoption. Make it easier it'll get adopted more readily. Right? And then the fourth change which is what brings me today is to recruit allies. Right, we particularly on what we call is a decentralized system of diffusion, which is what we're in.
We're not the only players talking about website security, there are many other players, everybody believes this is important. The fact is the more these folks get connected and engage with each other, the more likely we are to actually address this problem because it's a significant challenge.
And that's why that's why I'm here is because I think that there's a role that you can play here. In particular as you're promoting marketing strategies and branding strategies, this is important for your efforts. Certainly no amount of investment in brand, or in conversion funneling, or in client delight is going to be worth much if it's done on infrastructure that get that becomes vulnerable all of a sudden, puts all of that at risk.
Right? Or if it actually happens and becomes compromised, of that investment is lost. And the easiest way of avoiding that is to just think about it ahead of the game. So best best request to you and why I'm here to you is ask you to become the ally of the most security minded person in the organization you work with.
And if you're not that person, think about it. You don't have to become an expert about it. You just have to ask the question at the beginning, what's the security plan on this? Because there will be somebody in the organization that thought about it, sometimes that person is seen as the gadfly that's always just saying, hey, did we think about security?
Do we think about security plan? And then people just moan and sort of of clutch at their heads, but oftentimes that person just needs somebody else to validate that what they're saying is important and it will be accounted for. And then they'll move on and just make sure that the right things are in place.
That is probably the biggest the biggest piece to incorporate is make sure that as you're going through creating campaigns for your clients, as you're going through developing your own products, as you're going through talking to your own customers about about their own online presence, throw in that that bit of security.
Know that you can actually talk about it just a little bit and drive awareness of it because even that little bit of awareness makes implementing the remaining five practices notifications, https, update, validate, and patch, secure passwords, two step verification all the more easy to implement.
And that you might ask now sort of at the end like, well what about your dad's website? Have you fixed it yet? To be honest, I haven't yet. As I was going through this, part of me is like, oh I need to go here, I need to go to Turingfest and say, yeah, here's the happy epilogue, like I went and set up my dad's website, now it's online, here's the wonderful glowing CMS on it.
Frankly, I'm still I'm still in that battle of like, that's a project. But but I'm more committed to do it now than I was before, if only because I want to make this consistent. Right? I want to make my my language consistent with my actions.
But in any event, it's still working. I think it's still very important for him to do so and I'm hoping that he will. With that, thank you to photographers who've kindly, kindly generously given to this sort of common wealth of knowledge and information and content that we all share, that we're all trying to protect.
And thank you all for your attention and time. Appreciate it.