A working origin-protection checklist has to survive rotation. The following list is what we validate on every Cloudflare-fronted engagement.
Certificate transparency audit for prior origin IPs. Locked-down origin firewall (allow only current edge IPs). Signed CDN header verified end-to-end. Historical DNS records reviewed for exposure. No staging environments listening on public interfaces. No CI runners on production-adjacent IPs.
None of these are novel. The consistent finding is that they need to be automated. A manual checklist done at launch does not survive the first infrastructure change.