Contact

Digital 360 - Christophe Margaine EI, MSc

Cybersecurity & GDPR, from the project side

Let's get to the point! I make sure your web projects ship protected, measurable and compliant, without breaking search visibility.

Cybersecurity and GDPR: CDN, WAF, WAAP, SSO, consent

What I take on

WAAP, WAF, CDN and anti-DDoS

Akamai, Cloudflare, Google Cloud Armor (WAF/WAAP): cache and session rules, filtering of malicious bots, including those exploiting application-level flaws, volumetric protection.

Detect and reduce the attack surface

Editing back office off the public internet, static public site behind a load balancer, WAAP and CDN. Less exposed code, fewer incidents.

Identity and access

SSO and identity federation, MFA, access reviews. Admin access goes through strong authentication, not an IP allow list.

GDPR in practice

Consent before any tracker, consent proof, retention periods and automated purging. Written in the code, not only in a policy.

Security and SEO

A misconfigured WAF also blocks Google and AI search crawlers. I reconcile both, with the security team.

Security by design

HTTP headers, secret management, CMS hardening, protection against injection and XSS, review before go-live.

Frequently asked questions

Do you run penetration tests?

Yes, within an authorized scope: reconnaissance, configuration review, code review, vulnerability explanation (OWASP Top 10), recognized tools, interpretation of results and remediation. What makes a penetration test legal is neither the tool nor AI: it is the authorization.

Where should we start?

With what is exposed: the public site, admin access, trackers. Start with what the internet can reach.

Is a WAF enough?

No. A WAF must never hide an application defect. It protects while the cause is fixed.

And GDPR compliance?

It plays out in technical details: which tag fires before consent, how long data is kept, who can export it.

Need to secure a project or bring it into compliance?

Get in touch