Are there any security guides, papers, etc. on how to protect a web wallet (Electrum server)? Search on the forum returns info on general setup, but not specifically on more or less detailed protection tips against bad actors.
Most of security-related tips could be obtained from general guide to protect a server. But if you're looking for Electrum server specific, you could start from reading their guide/documentation. For example, ElectrumX have environment variables related with resource usage[1] which could be modified to reduce damage against DDoS attack.
[1]
https://electrumx-spesmilo.readthedocs.io/en/latest/environment.html#resource-usage-limits