Who made the website?

Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today.

This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.

Who designed the customer flow?

In TFA there is no single issue of actual things that web developers could be blamed for.

CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.

All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.