1. Define the website and data that need protection
Start with a precise inventory of the site rather than a general statement that it should be secure. Identify the production website, databases, media, forms, redirects, DNS records, SSL certificates, analytics configurations and any administrative accounts connected to the public site. A Santa Fe city firm may serve clients across Santa Fe County or elsewhere in New Mexico, but the geographic label does not determine what information the website stores. Confirm whether contact forms contain personal information, whether submissions are retained in the website, and which systems receive them. Bosseo’s public hosting page describes firewall and DDoS protection, SSL, managed security and automatic daily backups. Those capabilities should be matched to your actual data flow and access model, not treated as a substitute for documenting it.
Recommended approach
Ask for a written inventory and responsibility map. It should identify what Bosseo hosts, what remains with another provider, who approves access, where form submissions go and what your firm must retain independently. Do not approve a move until the inventory reflects the current site rather than an assumed standard configuration.
