BRITAIN FOR CHRIST CYBERSECURITY & RECOVERY STANDARD Version 27 · 25 August 2026 PURPOSE Britain for Christ treats cybersecurity as a continuing responsibility. No public website can be guaranteed to be immune from attack. The objective is layered protection, minimum exposure, early detection, controlled change and reliable recovery. 1. MINIMISE THE ATTACK SURFACE The public site should remain static where practical. Do not add visitor accounts, unrestricted uploads, payment-card collection, exposed databases or public admin interfaces without a separate security design and review. 2. CONTENT SECURITY POLICY Executable scripts and styles should come only from the Britain for Christ origin unless a reviewed exception is required. Inline executable JavaScript, inline event handlers, frames and plug-in objects should be blocked. 3. BROWSER SECURITY HEADERS Deploy anti-clickjacking, MIME-sniffing protection, referrer controls, permissions restrictions and appropriate cross-origin isolation headers through Cloudflare static-asset response headers. 4. HTTPS All public traffic should use HTTPS. Enable Cloudflare Always Use HTTPS after confirming the edge certificate is active. HSTS should be enabled only after its requirements and recovery consequences are understood. 5. CLOUDFLARE ACCOUNT SECURITY Use a unique high-entropy password and two-factor authentication. Prefer a phishing-resistant security key where available; retain recovery codes securely offline. 6. DNSSEC Enable and confirm DNSSEC so DNS responses can be authenticated and spoofing risk is reduced. 7. WAF AND BOT PROTECTION Use Cloudflare managed WAF protections and appropriate bot protection. Review security events after unexpected traffic, availability problems or suspicious behaviour. 8. SECRETS Never publish passwords, API tokens, private keys, account recovery codes or credentials in HTML, JavaScript, downloadable ZIP files, screenshots, source code or public documentation. Use least-privilege API tokens where integrations are later required. 9. EXTERNAL LINKS External resources open with protections against reverse-tabnabbing. Website code must not treat an external resource as trusted executable code merely because it is linked from a Britain for Christ page. 10. FORMS AND PERSONAL DATA Current public forms use the visitor's own email application rather than a Britain for Christ server-side database. Future server-side forms must include validation, bot controls such as Turnstile where appropriate, rate limiting, data-minimisation and a privacy review. 11. SOCIAL ACCOUNT INTEGRITY Do not publish social-media links as official until exact account ownership has been confirmed. Treat unexpected changes to official social links as a potential security incident. 12. RELEASE INTEGRITY Every production release should be generated from a known-good source folder, validated, checksummed and packaged cleanly. Do not merge or skip conflicting deployment files. 13. RECOVERY If compromise is suspected: preserve evidence; change/rotate affected credentials; check Cloudflare account access and DNS; restore from a known-good package; validate security headers and public pages; then monitor for recurrence. 14. RESPONSIBLE DISCLOSURE Security concerns should be reported privately to the published security contact. Do not publish exploitable details, credentials or personal data while an issue is unresolved. 15. SECURITY IS CONTINUOUS Security controls, dependencies, Cloudflare settings and recovery procedures should be reviewed after major releases and when threat conditions or platform capabilities change. © 2026 Sukhdip Parvez. Britain for Christ.