Goal:
To protect the client's website from potential threats (hacking, DDoS, data leaks, website destruction, etc.) through an audit and implementation of necessary security measures.
Current situation:
- The website is based on a template solution (CMS to be specified)
- There is a Cloudflare account
- Control over hosting and domain is available
- Security is not configured systematically
Tasks:
1. Conduct a security audit of the website
2. Identify areas for improvement (CMS, plugins, access controls, hosting, SSL)
3. Provide a specific list of recommended actions
4. Implement protection:
- Configure Cloudflare (Firewall, Bot Protection, etc.)
- Install WAF / antivirus software (if needed)
- Set up backups and recovery points
- Monitoring and incident alert system
5. Configure access restrictions and basic security policies (passwords, 2FA)
6. If necessary — migrate to a secure hosting (discussed separately)
Expectations:
- Clear work plan
- Understanding of priorities and risks
- Price proposal with breakdown by stages
- Examples of successful cases
- Conditions for further support / guarantees