Protect the control plane

Enable strong multi-factor authentication for registrar, DNS, hosting, source control, and email. Use unique credentials in a password manager and keep recovery codes offline. Restrict administrative interfaces by role and remove unused accounts and tokens.

The domain registrar and primary email account are recovery roots. Protecting the web application while leaving those weak is an incomplete boundary.

Maintain software and secrets

Keep the operating system, runtime, framework, plugins, and dependencies supported and patched. Remove software that is not used. Store secrets outside source code, rotate exposed values, and limit each credential to the systems and actions it needs.

Subscribe to security notices for the components you operate and define who responds.

  • Automate dependency and certificate alerts.
  • Disable directory listing and unused services.
  • Set secure cookie attributes.
  • Use security headers appropriate to the application.

Make recovery routine

Back up data and configuration on a schedule appropriate to the allowed data loss. Encrypt sensitive backups, restrict access, retain copies outside the primary provider, and perform restore tests.

Monitor availability, certificate expiry, unexpected DNS change, authentication failures, and backup completion. An alert needs an owner and a response path.

Verification checkpoint

From a clean destination, restore a backup and configuration, rotate a test credential, and confirm an external alert reaches the responsible person.