Service
Alerting and hardening you can restore
MFA where it belongs, logs a human reads, backups restored on a date you pick. WordPress, Drupal, Magento, Shopify, and 365 included — not a PDF in a drawer.
The three proofs
MFA on accounts that can hurt you (host, Cloudflare, Shopify, WP admin, 365 global admin). A log someone opens in Montreal hours. A restore with a date — site, shop, and mailbox.
CMS and shop hardening
File permissions, unused ThemeForest plugins, XML-RPC, dead Magento modules, Shopify staff two-step, PHP version that is not EOL. A compromised plugin is an SEO event: Google will stop trusting the domain.
Read next
Let's write the next step.