Coverage
Key security areas
HTTPS and transport security
Secure connections, certificate management and mixed-content avoidance help protect traffic between visitors and the site.
Administrative protection
Strong passwords, multi-factor authentication and careful privilege management are important controls for administrator access.
Application separation
Marketing content remains on the public website while CRM, learner and wellness records belong in their dedicated authenticated platforms.
Form and spam controls
Public enquiry forms should use validation, anti-spam measures and privacy-conscious routing to reduce abuse and protect submissions.
Security headers and hardening
Headers, file protections, patching and configuration reviews help strengthen the public web environment when properly tested.
Backup and recovery readiness
Regular backups and tested restore procedures are essential for resilience, rollback and incident response planning.
