
Before someone else finds the gap
Find the gap before it is found for you.
Most breaches we are called into were not sophisticated. An unpatched plugin, an exposed admin panel, a credential in a repository, a backup nobody encrypted. We audit against that reality, fix what is exposed, and leave you with a process that keeps it closed.
Technologies
01Capabilities
Application security audit
Authentication, authorisation, injection, file handling, session management and dependency risk, reviewed against OWASP ASVS and reported with severity and reproduction steps.
Infrastructure review
Exposed services, patch levels, TLS configuration, secrets handling, backup integrity and access control across servers and cloud accounts.
Incident response
Hacked site cleanup, root-cause analysis, closing the entry point, restoring clean state and a written report suitable for insurers or a regulator.
Compliance that fits reality
GDPR records, data flow maps, retention rules, DPIAs and cookie handling that actually match what your systems do — not a copied policy page.
02Scope
What is included
- Application and infrastructure security audits
- Penetration-test style review with prioritised remediation plan
- Security hardening for Magento, WordPress and servers
- Hacked site cleanup and incident response
- Dependency and supply-chain vulnerability management
- SSO, MFA and access control implementation
- GDPR: data mapping, retention, DSAR handling and DPIA support
- Cookie consent and tracking compliance
- PCI DSS scope reduction and SAQ support
- NIS2 readiness assessment for in-scope organisations
- Security monitoring, audit logging and alerting
05Questions
Frequently asked questions
How is an audit different from a penetration test?
A formal penetration test is an adversarial exercise, usually required for certification. Our audit is a review with the source code and infrastructure in hand, which finds a different and often larger class of issues for less money. We will tell you when you genuinely need a certified pen test instead.
Our site was hacked. What happens first?
Containment: take the attacker out, preserve evidence, and get a clean version serving. Then root-cause analysis to find the actual entry point, because restoring a backup without that just resets the clock. You get a written report with a timeline and the remediation steps taken.
Is GDPR compliance really a development task?
Partly, and that is the part usually missing. A policy page does not delete data on request, log a lawful basis, honour a consent choice before a tracking script fires, or expire records on schedule. Those are code and configuration, and they are what an actual investigation examines.
06Nearby
Related services
IT Audit
An independent review of your infrastructure, applications, security posture, costs and delivery process — delivered as a written report with severities, owners and a costed plan.
Infrastructure & DevOpsCyber Security
Hardening, identity, patching, monitoring, backup verification and incident response — run as an ongoing discipline against ISO 27001 and NIS2, not as a product you switch on.
Infrastructure & DevOpsDevOps, Linux Servers & Managed Hosting
Linux server configuration, hardening, Docker deployments, CI/CD pipelines, monitoring and managed hosting — the infrastructure work most agencies quietly outsource.
What we do
Web Security & Compliance
Security audits, hardening, incident recovery and the practical side of GDPR, PCI DSS and NIS2 — for teams that would rather not learn this during a breach.
