Hi Team,
As part of our ongoing commitment to protecting customer data and maintaining compliance, the Security Team has reviewed our current loan application processing workflow. We recommend the following actions to strengthen our security posture:
- Verify all form submissions and uploads use secure HTTPS.
- Minimize data exposure by disabling entry storage in Gravity Forms.
- Enforce Multi-Factor Authentication (MFA), Single Sign-On (SSO), and strong passwords for all accounts accessing WordPress, Salesforce, and PowerBI.
- Enable Web Application Firewall (WAF), login rate limiting, file integrity monitoring, and activity logging in CloudFlare and implement some sort of web scanning.
- Lock down access to the WordPress backend, including hiding the login page from the public default path.
- Secure database access by using least-privilege accounts, secrets management, encrypted backups, and performing regular restore tests.
- Harden Salesforce by implementing strong authentication, field-level security, encryption, and malware scanning for uploaded files.
- Automate deletion of old data to ensure we meet our 1-month retention policy.
Implementing these recommendations will help us reduce risk, protect sensitive information, and support our compliance obligations.
If you have any questions or need assistance with these actions, please reach out to the Security Team.
Thank you,
Security