I am not sure whether this is the right place to ask this question as there is no right and wrong answer.

I have a MVC5 application with WCF service and it will be used internally. However it requires some security as it involves finance stuffs and cannot ignore even though it is internal.

So how can I ensure that the application is secure?? Do I need to use hashing algorithms > SHA1

