Request a demo →
← All case studies Government & Public Sector · WordPress Security, SAML SSO & MFA

Two Years Without a Website Compromise

A regional planning commission broke a cycle of repeat WordPress compromises after restores and password resets had repeatedly failed.

24 months without a website compromise
0 incidents after cleanup and federated MFA
Hundreds of attempts blocked and logged
THE CHALLENGE

Why a stronger solution was needed

The public website was being compromised repeatedly. Its design partner restored clean backups and changed passwords after every incident, but the problem returned. Malicious plugins and injected code persisted while the original credential path remained open. Because the site published public financial figures, integrity and availability mattered as much as confidentiality.

RAINBOW SECURE APPROACH

How the engagement was structured

Rainbow Secure addressed both halves of the problem: remove the malicious persistence already inside the site and close the credential path attackers were using to return. WordPress was then configured as a SAML service provider, Rainbow Secure became the identity provider, and rSecureKey MFA protected admin and editor access. Local WordPress password authentication was disabled.

WHAT WE DID

From problem to governed access

01

Remove what was inside

Identified and removed malicious plugins and injected code from the live site.

02

Close the way back in

Federated WordPress login over SAML and protected admin and editor access with rSecureKey MFA.

03

Disable the bypass

Turned off local password authentication so the governed path became the only route to the dashboard.

04

Keep evidence

Logged and refused attempted compromise before the WordPress dashboard was reached.

FEATURES IN PRACTICE

What was used, where and why

Rainbow Secure capability Where it was used How it helped
Malware cleanup Live WordPress installation Removed malicious plugins and injected code that had survived repeated backup restores.
SAML federation WordPress administrator and editor login Moved credential validation away from the website and into Rainbow Secure.
rSecureKey MFA Publishing and administrative access Made a stolen password insufficient by requiring multidimensional human interaction.
Audit activity Blocked login attempts Recorded attempted compromise before access reached the WordPress dashboard.
WHAT WAS BEING PROTECTED

The business impact behind the technology

Published financial data

Altered figures would damage public trust and the integrity of a government record.

Public availability

A public record that cannot be reached cannot serve its purpose.

Publishing access

Only verified administrators and editors should be able to change public information.

THREATS REDUCED

Risk connected to control

Threat or weakness Control that addressed it
Malicious plugins and injected code Identified and removed during live-site cleanup
Persistence surviving backup restore Removed from the live environment instead of repeating the same restore
Password spraying and credential stuffing Blocked by multidimensional MFA and federated login
Local-login bypass Closed by disabling local password authentication
Unauthorized content changes Restricted publishing access to verified identities
BUSINESS OUTCOME

What changed

The previously repeat-compromised website operated for 24 months with zero further compromises as of the source case study. Hundreds of login-compromise attempts were blocked and recorded, the reinfection cycle ended, and the design partner no longer had to absorb repeated emergency recovery work.

Verified engagement metrics from the supplied Regional Planning Commission case study. Results are specific to this environment and are not a projection.
YOUR ENVIRONMENT WILL BE DIFFERENT

Start with one customer problem and build the right identity-security path.

We can map the users, applications, access risks and evidence requirements involved in your first use case.

Discuss your use case →