General information only. Confirm technical and commercial details with the relevant provider and qualified advisers.
Harden access
Use unique administrative accounts, least privilege, strong authentication, key rotation, and a documented break-glass procedure. Restrict management access to approved networks.
Patch and observe
Set patch ownership and maintenance windows. Collect the logs and metrics you need to identify unexpected access, resource changes, and service degradation.
Back up and restore
Keep protected backups separate from the primary environment and test restoration regularly. Define recovery time and recovery point targets appropriate for the application.
Prepare for incidents
Maintain current contacts, escalation steps, evidence-preservation processes, and a clear understanding of which party investigates each type of incident.