Mitigations: rate limiting, MFA, secure cookie flags, Content Security Policy (CSP), least-privilege storage, encryption at rest, rotate secrets, and regular security reviews.