Reduce the privilege surface
Use individual accounts, phishing-resistant multi-factor authentication where available, and the smallest role each operator needs. Do not share the registrar, DNS, hosting, and application passwords. A compromise should not hand over every recovery channel at once.
Review active sessions, API tokens, SSH keys, and delegated users on a schedule and immediately after team changes.
Create a change trail
Record the reason, owner, time, affected service, expected result, and rollback for DNS, runtime, certificate, database, and file changes. Export configuration before editing it. Screenshots help, but machine-readable exports are better when the platform provides them.
Avoid editing production code through a panel. Deploy versioned artifacts from source control so a rollback reproduces a known state.
- Take a targeted backup before destructive changes.
- Change one layer at a time.
- Verify from outside the provider network.
- Close temporary access when work is complete.
Know what the provider does not back up
A dashboard labeled backup may exclude mailboxes, DNS zones, external databases, large objects, or recent snapshots. Read the scope and retention policy, then test a restore to a separate location.
Keep at least one recoverable copy outside the failure and billing boundary of the hosting account.
Review accounts and tokens, export current configuration, and restore a selected file plus a database into a disposable destination without modifying production.