Repeatable website, DNS & Cloudflare security baselines for client-facing teams
Turn ad-hoc client security into a standard baseline you can run on every site, hand over as client-ready evidence, and repeat on onboarding — without building an enterprise security practice.
Built by Myles Agnew · 18+ years in tech · Cloudflare, AWS, Azure, GCP, WordPress · Sydney, AU
The problem you already know
DNS mistakes take clients down
A bad record change or an un-backed-up zone turns a five-minute edit into an outage — and there's no known-good state to restore to.
Reviews aren't repeatable
Security depends on who did the work and what they remembered. Every engagement starts from scratch instead of a standard baseline.
Clients want proof, not reassurance
"We secured it" doesn't cut it anymore. Clients increasingly expect to see what was checked, what was fixed, and what's monitored.
Onboarding has no security floor
New client sites arrive with unknown DNS, Cloudflare, and WordPress state — and no consistent first-pass to bring them to a safe baseline.
The baseline I run
A practical 25-point review across the five places client sites actually break:
- DNS & domain — registrar MFA, expiry, off-platform record backup, SPF/DKIM/DMARC
- Cloudflare — proxy status, Always Use HTTPS, WAF, rate limiting, stale rules
- Security headers — HSTS, CSP, nosniff, Referrer-Policy, Permissions-Policy
- WordPress — updates, unused plugins, admin accounts, tested backups
- Recovery — off-platform DNS backup, restorable site, documented process
- Client-ready summary — findings, priorities, and evidence they can read
How it works
Request a review
Tell me what you're running — one site or a client portfolio. I confirm scope and fit, no retainer required.
I run the baseline
The full 25-point review against the site(s), with the obvious high-impact fixes flagged and, where quick, remediated.
You get the report
Findings, prioritised fixes, and a client-ready summary you can hand over as evidence — the same structure every time.
Who it's for
A good fit if you…
- Manage websites, DNS, or Cloudflare for clients
- Want a standard security floor for onboarding
- Need evidence clients can actually understand
- Prefer practical fixes over framework theatre
Probably not if you…
- Need formal certification/audit sign-off (ISO, SOC 2)
- Want a full managed SOC or 24/7 monitoring
- Are after enterprise GRC tooling and paperwork
Standardise client security without the overhead
Run the free checklist yourself, or have me turn it into a repeatable, client-ready baseline for your agency or MSP. No retainer, no theatre.