Skip to content
All services

SECURITY

Web & Infrastructure Security Assurance

Understand and improve the security of your websites, web apps, email and infrastructure. Get clear priorities, hands-on fixes and ongoing checks—or help containing and recovering from a compromise.

First steps while you get in touch →

Get a clear picture of your security and practical help improving it. Start with an assessment, bring us findings that need fixing, or choose recurring checks. We work with your existing hosting and email providers.

What we assess

  • Websites and web apps: CMS platforms, custom applications and their dependencies. We review exposed services, configuration, administrative access, updates and available logs.
  • Domains, DNS and TLS: registrar access and recovery, DNS ownership and records, certificates, renewals and relevant transport-security configuration.
  • Email security controls: authorised senders, SPF, DKIM and DMARC alignment and policy, plus account access and recovery. We work with Google Workspace, Microsoft 365 and other mail providers.
  • Hosting and cloud: patching, permissions, exposed services, firewall rules, logging, backups and recovery arrangements within the access and systems you authorise.

Before testing, we agree a written asset list, access, permitted checks and change windows with you. The report records what was checked and where further access or investigation is needed.

What you receive

  • A record of the assets and controls reviewed, the date and any access limitations.
  • Validated findings with supporting evidence, likely impact, priority and practical next actions.
  • A remediation plan identifying who owns each action and what needs a specialist or your existing provider.
  • A discussion of the findings and options for implementation, rechecking and ongoing assurance.

You get a human-reviewed explanation of what matters and what to do next, with evidence you can discuss with your team or provider.

Fix the important findings

We can implement agreed fixes: patch components, tighten privileged access, correct DNS and email controls, improve firewall rules and make recovery more dependable. Work is planned around backups, availability, rollback and permission to make changes. We recheck the controls changed and record anything still open.

Ask us to carry out the work or use the findings with your own team. We confirm the remediation plan and price before making changes.

Keep assurance current

Combine useful automated checks with regular human review: vulnerabilities and updates, access and configuration, domains and certificates, backups and restoration. We prioritise new findings, track open actions and review the controls as your systems change.

Your plan sets out check frequency, reporting and support arrangements. Where we already maintain a website or server, assurance builds on that work.

Active incident response: contain, recover, then improve

If you suspect a compromise, we help establish what is affected, contain further harm and recover the service, then address the weaknesses behind the incident.

Make first contact safely

Use a trusted device and an unaffected contact account if your usual email may be compromised. Tell us the affected public site or application, the symptoms, when you noticed them and what access remains. Do not send credentials, raw logs, customer data or confidential evidence through the public form or chat; we will arrange a suitable transfer route.

Preserve logs and suspicious files rather than wiping the system or deleting evidence. If users are at risk, ask your host to restrict or isolate the affected service while you get help. A maintenance page alone does not remove an attacker's access.

Contain and recover

We agree permission to act, priorities and fees before work begins. Containment may involve restricting access or isolating a service while preserving available files, logs and timestamps. We plan cleanup or rebuilding from trusted sources, check backups before restoring, address the likely entry route and review accounts, sessions and credentials.

We verify important user journeys and check for recurrence before restoring normal access. You receive a technical summary of the findings, actions taken, remaining questions and recommended next steps.

Where an incident calls for specialist forensics, insurance, legal or regulatory advice, we help coordinate with the relevant specialists.

For organisations, agencies and hosts

Work with us directly or bring us in behind your agency or hosting brand. We agree client permissions, reporting and communication with your team. Our hosting and migration experience helps turn recommendations into changes that work in practice.

A clear plan and quote

Start with a free conversation about the systems you use and the concern you want to address. Assessments, remediation and recurring assurance are priced around the assets, complexity and depth of work involved. You receive deliverables and fees in writing before work begins, whether you choose a one-off project or ongoing help.

Cyber Essentials preparation

Working towards an application or renewal? Cyber Essentials Support guides you through the requirements, closes practical gaps and helps you prepare your application.

Talk it through

Let’s talk it through

Tell us what you need help with. We’ll talk through the options and next steps.

  • Deliverables and fees in writing
  • Follow-up and open actions recorded
  • Access and responsibilities agreed
I need help now →

Send an enquiry at any time. We will respond as soon as we can and agree a practical next step with you.