- Plugin and theme audit with risk-based cleanup
- Admin hardening: two-factor, roles, brute-force protection
- File permission and server configuration lockdown
- Firewall and malware scanning configured and tuned
- Off-site backup setup with a verified restore test
- Incident runbook your team can follow under pressure
Already infected? Cleanup is scoped separately, then hardening follows so it doesn’t repeat.
