All services

Cyber Security

Protect what you have built — hardening, malware cleanup, access control and a recovery plan you can actually rely on.

Cyber Security — an illustration of the tools and systems involved

What we deliver

9 services in this discipline. Each one says what it includes and how we approach it — no jargon, no vague promises.

    01

    Website Security

    Close the common holes: injection, XSS, exposed admin paths and outdated plugins.

    We check for the issues that are genuinely exploited in the wild — injection, cross-site scripting, insecure uploads, exposed admin paths, outdated components — and fix what we find. Security headers, cookie flags and CSRF protection are included, since these are commonly skipped. You get a report of what was found and what was changed.

    02

    Server Security

    Hardened configuration, least-privilege access and services kept patched.

    Least-privilege accounts, key-based access, patched services, no unnecessary daemons and audited sudo rules. Hardening is documented so it survives staff changes and server rebuilds. Where something must stay open for business reasons, the compensating controls are explicit.

    03

    SSL Configuration

    Strong ciphers, correct certificate chains and no mixed-content warnings.

    Modern protocol versions, strong cipher suites, correct certificate chains, HSTS where appropriate, and no mixed content anywhere on the site. Verified with external testing rather than assumed to be working from the config file. Renewal is automated and monitored so it stays correct.

    04

    Security Hardening

    A systematic pass over the whole stack against a written, repeatable checklist.

    A systematic pass over application, server, network and access layers against a written checklist, with each change recorded. Because it's a checklist rather than intuition, it's repeatable — new servers start hardened instead of being fixed later. You keep the checklist, so your own team can apply it.

    05

    Malware Cleanup

    Find the backdoor, remove the payload, and close the route it came in through.

    We find the injected files and backdoors, remove them, then identify how the attacker got in and close that route so it doesn't recur. Cleanup without root-cause analysis just means being reinfected next month. Afterwards we take a clean backup and monitor for signs of reinfection.

    06

    Firewall Setup

    Network and application-level rules matched to how your systems are genuinely used.

    Network and application-level rules built from what your services genuinely need, including egress restrictions that limit damage if something is compromised. Rules are tested against real traffic before enforcement, so nothing legitimate is blocked at go-live. Documentation explains each rule's purpose for future changes.

    07

    Access Management

    Who can reach what — with keys, roles and revocation that work when you need them.

    A clear inventory of who can reach what, using keys and roles instead of shared passwords, with revocation that actually works when someone leaves. Multi-factor authentication is enabled wherever the system supports it. Access is reviewed periodically rather than only at onboarding.

    08

    Security Monitoring

    Alerts on suspicious logins, unexpected file changes and unusual traffic.

    Alerts on unexpected logins, privilege changes, file integrity violations and unusual traffic patterns, tuned so that alerts remain meaningful. Logs are retained long enough to investigate properly after the fact. Alert routing makes sure the right person is notified rather than a shared inbox.

    09

    Backup & Disaster Recovery

    A recovery plan that has been tested under real conditions, not just written down.

    Backups that are automated, off-site, encrypted and — critically — restore-tested on a schedule rather than assumed to work. You get a written recovery procedure with realistic time estimates for each scenario. We also identify what cannot be recovered, so expectations are honest.

Let's talk

Need cyber security?

Tell us what you are trying to do. If we are not the right people for it, we will say so.