Security audit
A review of your website, servers and access, with a prioritised report and a plan to fix what's found.
We look for the weak points in your systems before anyone else does, then we help you close them.
Strictly defensive work. We only act on systems you own or for which you hold written authorisation. Every engagement is covered by a signed mandate setting out the exact scope, the testing window and the limits. We carry out no action against third parties.
A small business doesn't need a bank's security programme. It needs the obvious doors closed.
All carried out under contract, with your prior authorisation.
A review of your website, servers and access, with a prioritised report and a plan to fix what's found.
Checking your authorised systems for known weaknesses: outdated versions, risky configurations, exposed services.
Patching, configuration hardening, certificates, application firewall and form protection.
Two-factor authentication, password management, and a review of access rights and dormant accounts.
Uptime tracking, alerts when something looks wrong, and regular application of security patches.
Short, practical sessions on phishing, passwords and what to do when something looks suspicious.
A clear framework, from the mandate through to verifying the fixes.
We define in writing what will be tested, when, how, and what is excluded. Nothing starts without your signature.
We examine your authorised systems for risky configurations and known vulnerabilities.
You receive the findings ranked by severity, explained in plain language, with a recommended fix for each.
We apply the fixes or support your team in doing so, then verify the weaknesses are genuinely closed.
We test only the systems you explicitly authorise us to test, under contract. We never act on systems belonging to third parties, and we decline any request in that direction.
The risk is low but not zero. We agree a testing window in advance, confirm a recent backup exists, and stay reachable throughout.
Contact us and say it's urgent. Depending on the situation we'll point you to the first steps to take and, if the incident goes beyond our scope, to the appropriate authorities.
Most attacks aren't aimed at anyone in particular: they sweep the internet automatically looking for vulnerable systems. Being small is not protection.
Thirty minutes is enough to know what's achievable, how long it takes and what it costs.