A regional technology centre · Intergovernmental

Five separate websites, one secure CMS platform, built for Intergovernmental security baseline.

WEBSITES - ONE CMS PLATFORMSITE 1SITE 2SITE 3SITE 4SITE 5+SHARED CMS + MYSQLcommon menu · theme · headerXSSOutput encodedSQL INJECTION5 defencesSESSIONSRandom · expiring
The brief, as we understood it
“
Make our project websites work properly on phones and tablets, and bring every one of them up to the organisation's minimum IT security requirements.
- Our reading of the brief handed to Milleniance at the start of the engagement
01 - The challenge

Five websites in different states, and one security baseline to meet.

The centre ran several websites for its programmes. Two were static pages with no content management system, another was not built for mobile or tablet screens, and they did not share a design, menu or platform. Its digital resource centre could only be reached from the office network, and useful capacity-building content sat on a separate portal.

At the same time, the websites had to meet the security requirements set by the United Nations Secretariat. That meant defences against cross-site scripting and SQL injection, controlled access to back-end systems, protected logins, and audit logging - all written down as requirements the finished sites would be tested against.

  • Static sites with no CMS, and no shared design or platform
  • A digital resource centre reachable only from the office network
  • A written security baseline every site had to be tested against
STATICno CMSSTATICno CMSFIXEDlayoutSEPARATEdesignLANonlyNO SHAREDBASELINEFIVE SITES - THREE ISSUES EACH
02 - The approach

Treat the security baseline as the specification, not an afterthought.

The security controls were listed in the requirements up front, so they were built in as acceptance criteria rather than bolted on at the end. Delivery was split into two dated milestones: first, conversion of the static sites to the CMS with responsive layouts and the security controls in place; second, integration of the external content, the resource centre going online and hands-on training for staff.

Every requirement was tested across all the sites before sign-off. Staff who would manage the sites afterwards received training at the centre, along with manuals illustrated with screenshots and diagrams, so day-to-day content work did not depend on a developer.

  • Security requirements written into scope and tested before sign-off
  • Milestone 1 - sites converted, responsive and secured
  • Milestone 2 - content integrated, resource centre online, staff trained
KICK-OFFRequirements set30 DECCONVERT + SECURESites and controls15 JANINTEGRATE + TRAINContent, staff28 JAN
03 - What we built

One platform. Four layers that make five websites dependable.

One platform, five sites
Static sites converted to a MySQL-driven CMS and brought onto a shared platform, with a common menu, theme, colours, banner and header across every site.
Responsive, findable, measurable
A responsive framework optimised for mobile, tablet and desktop, tuned for search engines and slow connections, with Google Analytics inserted automatically into every new page created in the CMS.
Layered application security
Output encoding against cross-site scripting; five SQL-injection defences - parameterised queries, stored procedures, escaping, least privilege and whitelist validation; input validation, upload checks and no error messages that reveal configuration.
Access control and accountability
Passwords stored so they survive a compromise, self-service reset by link, brute-force lockout or CAPTCHA, random session IDs that expire, two-factor or restricted access for elevated accounts, and tamper-protected audit logs.
Built on

A stack chosen for security by default, low-bandwidth reach and easy content management.

MySQL-driven CMS Responsive front-end framework Parameterised queries and stored procedures Google Analytics integration Role-based access control Audit logging
05 - What the engagement covered

A shared platform, a written security baseline and staff able to run it.

5
Websites brought onto one shared platform
5
Layered defences against SQL injection
16wk
Delivery window with two dated milestones
30d
Maximum window to assess security patches

"If your organisation's websites are still a set of separately built pages, a shared CMS and a written security baseline will save more time than another redesign."

Let's see if we're the right fit

Thirty minutes with a senior web platform architect, before either of us commits to anything.

No sales deck, no discovery call with someone who hands you off afterwards. We look at your websites, your security requirements and how your team publishes content today. We respond within one business day.

Talk to a Senior Web Architect →