A handful of response headers close entire attack classes for zero runtime cost: HSTS forces HTTPS forever after the first visit, X-Frame-Options stops the page being embedded in a hostile site, X-Content-Type-Options stops the browser second-guessing file types, Referrer-Policy controls what leaks in links.
The big one is the content security policy — a whitelist of where scripts, styles and connections may come from, which makes most XSS dead on arrival. It takes real work on a legacy site because it enumerates every legitimate source; on a new build it should ship on day one.
Related terms
Content Security Policy
A header that whitelists where a page's scripts, styles, images and connections may come from — the second wall that stops XSS even when injection happens.
TLS
Transport Layer Security — the encryption layer behind HTTPS that keeps traffic private and proves the site you reached is the site you meant.
Cross-site scripting (XSS)
An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
