Welcome to our Nephila Web Newsletter Series — a special edition focusing on security in the Moodle platform. In this edition we highlight the responsibilities of users for ensuring a secure Moodle environment, and how to protect your data from cyberattacks.
Moodle is the world's most widely used open-source Learning Management System — a highly complex web application that stores and processes a massive amount of data. As cybersecurity attacks surge across borders and industries, Moodle is no exception. In the Philippines there have been alarming reports of attacks targeting universities, government bodies and organizations.
At Nephila Web Technology Inc. — a Moodle Premium Partner in the Philippines — security is imperative, non-negotiable, and highly significant in our processes. To explain how we help secure your data, let's start with the Moodle Security Tripartite Responsibility Model we developed in our ecosystem.
The Moodle Security Tripartite Responsibility Model
A collaborative model where every stakeholder identifies each other's responsibilities to secure the Moodle environment against cyberattacks. It rests on the collective shoulders of three roles:
- Moodle sets the foundational security of the application.
- The Moodle Partner bridges the gap.
- The Clients are the final guardians of Moodle security.
Moodle's role — foundational security
- Core security: regular core updates patch vulnerabilities; a new version twice a year ships the full list of security fixes.
- Best practices: guidelines on secure configuration and safe usage through documentation, case studies and community forums.
- Community vigilance: the open-source community identifies and reports potential threats.
- Training & awareness: Moodle equips everyone with knowledge through Moodle Academy.
Nephila Web's role — bridging the gap
- Tailored implementations aligned to your needs and best security practice.
- Infrastructure security: patch management, regular backups, continuous monitoring and access management — as a Select Tier AWS Partner, an Alibaba Cloud Intelligence Channel Partner, and an Akamai Solutions Partner.
- Ongoing support: regular security audits and immediate threat mitigation.
- Training & awareness for clients to use the platform safely.
- Feedback loop to Moodle about potential vulnerabilities.
- Backup & recovery: scheduled backups and a recovery plan.
Clients — the final guardians (your checklist)
- Report security issues to the Moodle Tracker and join the Security & Privacy community forum.
- Serve all pages over HTTPS only — coordinate with your Moodle partner.
- Use strong passwords for admin and teacher roles to resist brute-force cracking.
- Only give teacher accounts to trusted users; avoid public sandboxes on production.
- Enforce strict password policies (length, complexity, character requirements).
- Register your site with Moodle.org to receive security alerts by email.
- Use enrolment keys on courses and disable the enrolment-key hint.
- Respond promptly to the scheduled Moodle upgrades Nephila Web announces.
- Review your site security settings regularly (site-level and HTTP security).
- Follow the principle of least privilege when assigning trusted roles.
Knowledge is our strongest asset against evolving challenges. Thank you for trusting us, and for being our valued clients.