Adobe Commerce certified developers · Nearshore teams available within 2 weeks

Defence you can evidence

Most breaches are not sophisticated. They are unattended.

An unpatched appliance, a password reused from a personal account, an ex-supplier whose access nobody revoked, a backup that turned out not to restore. We work on the unglamorous side of security — the controls that fail quietly — and we run them as a standing process with named owners and evidence, because that is both what stops incidents and what an auditor, an insurer or an enterprise client will ask you to produce.

Technologies

CIS BenchmarksOWASP ASVSISO 27001 controlsNIS2 · DORA readinessSSO · MFA · SCIMSecrets managementVulnerability scanningLog aggregation & alertingEDR · WAFPhishing simulation

01Capabilities

01

Identity first, because that is the way in

Single sign-on, enforced MFA, least-privilege roles, joiner-mover-leaver automation and quarterly access review. Credential abuse is the entry point in the large majority of incidents, and it is the cheapest one to close.

02

Patching as a schedule, not a reaction

Inventory, severity-based windows, staged rollout and a record of what was applied when. Most exploited vulnerabilities had a patch available for months.

03

Detection with a defined response

Centralised logs, alerts routed to a person, and a written runbook per alert class with an agreed response window. We are explicit that this is business-hours managed detection, not a 24/7 analyst floor — and we say which of the two your risk actually justifies.

04

Recovery proven, not assumed

Off-site, encrypted, versioned backups with immutability where the platform supports it, restored on a schedule into a scratch environment. A backup nobody has restored is a hope with a filename.

02Scope

What is included

  • Security baseline and hardening for Linux servers, containers and cloud accounts
  • Identity: SSO, MFA enforcement, role design, joiner-mover-leaver process
  • Secrets management and removal of credentials from repositories and configs
  • Vulnerability scanning, dependency and supply-chain monitoring
  • Patch management with severity-based windows and an audit trail
  • Log aggregation, alerting and runbook-driven response
  • Endpoint protection and device policy for laptops and mobiles
  • Network segmentation, firewall review, WAF and rate limiting
  • Backup immutability, retention design and scheduled restore testing
  • Incident response plan, tabletop exercises and post-incident reports
  • Phishing simulation and security awareness for the whole team
  • Supplier and third-party risk assessment
  • NIS2 and DORA readiness assessment for in-scope organisations
  • Evidence packs for ISO 27001 audits, insurers and enterprise questionnaires

03The layers

Where the work actually happens

Security is not one product. These are the six places we work, roughly in the order they pay off.

01

Identity and access

SSO, MFA everywhere it can be enforced, least-privilege roles, and access that is removed the day someone leaves rather than at the next review.

  • Quarterly access recertification
  • Privileged access separated
  • Service accounts inventoried
  • Shared credentials eliminated
02

Systems and patching

A real inventory, hardened baselines against CIS, and patch windows sized by severity so a critical fix does not wait for the next maintenance slot.

  • Asset inventory kept current
  • CIS-benchmarked baselines
  • Automated OS and dependency updates
  • Change record for every window
03

Applications

Secure defaults in the codebase, dependency and container scanning in CI, and review gates on the paths that touch money, authentication or personal data.

  • SCA and secret scanning in CI
  • Review required on sensitive paths
  • Security tests in the pipeline
  • See also our web security review
04

Detection

Logs centralised, alerts that reach a person, and a runbook for each class so the first ten minutes are not improvised.

  • Central log retention
  • Alert routing and escalation
  • Runbook per alert class
  • Agreed response windows
05

Recovery

Immutable, off-site backups and a restore that is actually performed on a schedule, into an environment where a failure costs nothing.

  • Immutability where supported
  • Documented RPO and RTO
  • Scheduled restore rehearsals
  • Recovery runbook maintained
06

People and suppliers

Phishing simulation with training that follows a click rather than punishing it, and a risk assessment before a new supplier gets access.

  • Recurring phishing simulation
  • Onboarding security briefing
  • Supplier assessment before access
  • Contractual security terms

04Being straight about it

What we are, and what we are not

We are not a 24/7 security operations centre. Staffing analysts around the clock is a different business with a different cost base, and a supplier who implies otherwise while running a business-hours rota is selling you a feeling. What we provide is managed detection with defined response windows, an on-call rotation for critical alerts, and a runbook so the first response does not depend on who happens to answer. Where your risk profile genuinely requires round-the-clock eyes, we will say so and help you procure it.

We are not a certified penetration testing house. We do adversarial review with the source code and infrastructure in hand, which finds a different and often larger class of problem for less money. But when a certification, a client contract or a regulator requires a formal test by an accredited third party, that is what you need, and we will scope it with you and remediate what it finds.

We do not do forensic investigation for legal proceedings. We contain, preserve evidence, restore service and write the incident up. If the matter is heading to court or an insurance claim, a licensed forensic examiner needs to take custody early — and calling them late is what usually destroys the evidence.

Everything else on this page we do, run and can show you evidence of.

05Engagement

How it starts and how it continues

012–3 weeks

Assessment

A posture review against CIS and ISO 27001 controls, producing a gap list with severity, effort and cost. Often this is the IT audit, scoped to security.

024–8 weeks

Remediation sprint

The critical gaps closed in a defined block of work: identity, patching, secrets, backups. This is where most of the risk reduction happens.

03monthly

Operate

Monitoring, patch windows, access recertification, restore rehearsals and phishing simulation on a calendar, with a monthly report that says what was done and what changed.

04quarterly

Exercise

A tabletop incident twice a year, and a real restore test quarterly. Plans that have never been rehearsed fail in the same three places every time.

05Questions

Frequently asked questions

We are a small company. Is this not overkill?

The controls scale down; the attacks do not discriminate. For a small team the work is mostly identity, patching, backups and phishing awareness — a defined block of remediation and then a modest monthly retainer. Skipping it is what turns a routine incident into an existential one, because a small company has no spare capacity to absorb two weeks of downtime.

Does NIS2 apply to us?

It applies to essential and important entities in scope sectors above certain size thresholds, and — this is the part people miss — it reaches their suppliers through contractual security requirements. Many companies encounter it not as a regulator but as a clause in a customer contract. We run a readiness assessment that tells you which category you are in and what the gap is, without guessing on your behalf.

What happens if we are breached while you are engaged?

The incident response plan runs: contain, preserve evidence, identify the entry point, restore from verified backups, then a written report with a timeline suitable for an insurer or a regulator. Notification clocks — seventy-two hours under GDPR, shorter under NIS2 for in-scope entities — are tracked from the moment of awareness, and the contract states who does what rather than leaving it to be negotiated during the incident.

Can you work alongside our existing IT provider?

Frequently, and it is often the right structure: they keep operations, we bring the security discipline and the independent view. It has to be agreed openly — security work done around an incumbent rather than with them tends to produce two half-owned systems and a gap between them.

How is this different from your web security page?

That page is the application layer and the regulatory paperwork: reviewing a Magento or WordPress codebase, cleaning up after a hacked site, GDPR data mapping, PCI DSS scope. This page is the organisation — identity, endpoints, network, monitoring, recovery, people and suppliers. Most clients need both, and we scope them together.

What we do

Cyber Security

Hardening, identity, patching, monitoring, backup verification and incident response — run as an ongoing discipline against ISO 27001 and NIS2, not as a product you switch on.