Skip to content
Brendan Tully

Data in motion vs data at rest

From WP Speed Fix Newsletter

I’ve had a few conversations about data privacy and encryption with customers over the last couple of weeks. It was interesting to see first hand how little thought was given to their customer’s data stored in their WordPress sites.

I’m not talking so much about backups or protecting from data loss. Its more in relation to data privacy and the legal obligations companies have, to take reasonable measures to protect customer information and privacy.

I figured I’d send you an email about this, as it will be relevant for a lot of customers and probably something you haven’t thought about in a while if at all.

The core concept I walk to talk about specifically in relation to this is “data at rest vs data in motion” and some action steps you can take to secure and protect the customer data you’re storing.

Data in motion (data being transferred or transmitted)

This phrase broadly relates to the transmission versus the storage of data. Data in motion is data that’s being transmitted or transferred, and data at rest relates to the storage of data.

A lot of attention is given to data in motion. Almost anyone who is running a website is aware of SSL certificates and HTTPS and securing data to and from a website when it’s being transmitted.

99.9% of our customers reading this email will have this box checked as SSL is easy to implement with free SSL certificates provided by all web hosts.

Sidenote, as well as ensuring your site is using HTTPS, make sure HSTS is enabled also. This will help enforce security and may give you some speed and potentially an SEO boost. You can easily enable this using Cloudflare, here’s a blog post and video that walks through setting this up.

HSTS stands for HTTP Strict Transport Security – with this enabled the browser will only connect to the website using an encrypted connection. Click here for a HSTS checker that will tell you whether you have this enabled.


Data at rest (data being stored)

In comparison, I’m guessing you’ve given little to no consideration to the customer data you’re storing in your website. Based on my conversations with customers over the last 10-15 years, it’s probably the case that only 1-2% of our customer base has thought about this in detail.

Broadly speaking, any data apart from logon information and credit card info, is not encrypted when it’s stored in your WordPress site. This includes form data and any attachments that are uploaded as part of forms.

The attachments that are included as part of form submissions present another problem in that typically they’re publicly accessible if you can find the URL for those files. This means that not only are these files not encrypted, they’re not really being protected from being downloaded either.

Years ago we had a security guard company taking online job applications through their website and their WordPress site had THOUSANDS of drivers licenses and passports saved, unencrypted, in their Gravity Forms upload folder. This is a huge risk and if these documents were exposed as part of a hack it would be objectively considered as negligent in a legal context.

Action Items

Here’s a few simple action steps you can take in relation to the customer data you’re storing.

Review the data you’re collecting and storing

As a first step it’s probably wise to determine what customer data you’re actually storing. If you’re storing customer data in your website then you need to give some consideration to the security and privacy of that data.

Some industries like healthcare have very specific guidelines on how customer data is handled and apps and software you’re using to handle data need certification or compliance. For example healthcare software in the US must be HIPAA compliant.

2. Encrypt sensitive form fields

Many of the popular WordPress Forms plugins (we recommend Gravity Forms) have the ability to encrypt form fields – encrypting any sensitive customer data would be a good start here. This ensures that it’s not stored in the WordPress data as plain text.

If you’re using Gravity Forms then there’s a handful of plugins that can do this, one from Plugin Owl and another from Crosspeak

3. Gate uploaded files behind a logon, i.e. don’t allow files to be publicly accessible

If customers have the ability to upload files into your WordPress site via forms then you need to give some consideration to the files. At the very minimum we’d recommend gating these files behind a logon so they’re not publicly available to the internet, i.e. you need to be logged into WordPress in order to be able to download them.

Again, Gravity Forms can do this out of the box – more information here

4. Use Two Factor Authentication (2FA) for WordPress logons

None of the above steps matter if an administrator level password for your website gets compromised. Just last week we had a customer on our WPAlpha hosting platform get “hacked” because their Indian based developer’s logon details were compromised. This technically isn’t a hack if an attacker can simply walk through the front door.

If the customer had 2FA in place this would not have been a problem.

For most customers we recommend using the free version of the Wordfence to provide security at the WordPress site level. Wordfence has a two factor authentication feature that works really well here.

Encrypt files you’re capturing

If the files you’re capturing are sensitive such as the passport and drivers license scans in the example above then ideally you want to be encrypting those files.

Consider offloading file storage to Amazon S3 or some other cloud storage device that can be encrypted. Amazon S3 supports data encryption natively and can be coupled with Gravity Forms to ensure files uploaded with forms are encrypted. The “how to” of this is outside the scope of this email and definitely something you should use a developer for.

Regularly prune and archive data

Most customer data captured through your site has a shelf life. Implementing processes to regularly prune form data and particularly files captured from customers will help reduce the “surface area” of the data that you are storing on behalf of customers.

Thats it for this email, any questions, just hit reply – if you’re stuck with site speed or need help with SEO, email me back with some background on the problem you’re looking to solve and we can send over some recommendations.

First sent to the WP Speed Fix email list on 11 September 2025. Read the original on Bento   Subscribe to the list