Security has always been an important area for every website and same was discussed at DrupalCon Barcelona. The session started with an intro of the speakers and then about the Drupal Security issues. Here are some of the tips that were shared initially:
Great session on drupal security by @scorlosquet and @_klausi_. Thanks @drupalsecurity team for keeping us secure. pic.twitter.com/uqd2kxOAfE
— Mauricio Dinarte (@dinarcon) September 23, 2015
You can also secure your site by using Drupal hosting providers/companies products. They provide tuned Drupal security and performance (code, db, config, uploaded files) and manage security updates as well.
Security can also be enforced by using contrib modules like secure login, paranoia, security review, and many more.
Coordinating with the Drupal Security team
Educating the community on security best practices
Copying the security advisory for every security release
XSS
Access bypass