// OVERVIEW

Security That Doesn't Get In the Way of Business

Most small businesses don't have an in-house security team — and most attackers know it. We do two things, and we do them properly: an audit that finds what is already broken and hardens it, and a penetration test — only ever with written authorisation from the owner of the system — that shows how an attacker would actually walk in. Plus the paperwork to pass Cyber Essentials when procurement asks for it.

// WHAT'S COVERED

Where We Look

// OUR PROCESS

How an Engagement Runs

01

Scope & Authorize

Written authorization, target list, time window. We do not touch anything outside scope.

02

Discover

Recon, fingerprinting, vulnerability scanning — passive first, active with permission.

03

Test & Validate

Manual verification of every finding. No copy-pasted Nessus reports.

04

Report & Fix

Plain-English report with severity, proof, and a prioritized fix list. Re-test included.

// PRICING

One-Shot Engagements

Transparent project pricing, one engagement at a time. No retainer, no monthly lock-in.

Security Audit
£799
one-time
  • OWASP Top 10 web scan
  • SSL / headers grading (A+ target)
  • WordPress / CMS hardening review
  • Written report with fix list
  • Manual exploit verification
  • Re-test after remediation
Book an Audit
Cyber Essentials Prep
£999
one-time
  • Cyber Essentials gap analysis
  • Self-assessment paperwork drafted
  • Technical controls hardening
  • Internal policy templates
  • Pre-submission review
  • Certification body fee (separate)
Get Cert-Ready
// DELIVERABLES

What You Actually Receive

Every engagement ships with the following — readable by both your dev team and your board.

Executive summaryOne page, plain English. The risks, the impact, the priority. For decision-makers.
Technical findings reportEvery finding with CVSS score, reproduction steps, screenshots, and a concrete fix.
Prioritized remediation planWhat to fix first, what can wait. No 200-page PDF of "informational" noise.
Free re-testOnce you ship the fixes, we re-verify and update the report — no extra invoice.
Security headers configCSP, HSTS, X-Frame-Options drop-in — ready for your web server.
Credential exposure checkHIBP + paste-site sweep for leaked staff/customer emails & passwords.
Policy templatesAcceptable-use, incident-response, password policy. Copy, customise, sign.
Written authorization scopeEvery engagement signed off in writing — your legal team will sleep better.
// METHODOLOGY

Built on industry standards

We don't make security up as we go. Every engagement maps to recognised frameworks.

OWASP Top 10 Cyber Essentials NIST CSF CIS Controls PTES ISO 27001-aligned
// FAQ

Common Questions

Will testing take my website down?
No. We use safe, throttled testing methods on production and run intensive checks against a staging copy where one exists. We never run destructive payloads (DoS, mass deletion) without explicit written sign-off.
How long does an audit take?
A standard website audit takes 3–5 working days from authorization to report delivery. Penetration tests run 5–10 working days depending on scope.
Are you Cyber Essentials certified?
We help businesses pass Cyber Essentials certification — we don't sell the certification itself (that comes from an IASME-licensed body). Our prep service gets your technical controls, paperwork and policies ready so the audit is a formality.
What if you find something serious mid-engagement?
We stop and call you the same day. Critical findings (active compromise, exposed credentials, exploitable RCE) are flagged immediately — not held until report delivery.
Do you do offensive work for third parties?
No. Every engagement requires written authorization from the legal owner of the target. We do not test systems you do not own, and we do not develop offensive tooling for sale.
Do you watch our systems 24/7?
No — and we would rather say so than sell you a dashboard nobody is sitting in front of. Round-the-clock detection needs people on shift. What we do instead is make sure your systems raise alarms you actually receive: uptime and error alerting into Slack, Teams, email or a webhook, sensible log retention, and a written incident-response plan so you know who does what at 3 AM.
// READY?

Find out what an attacker would see.

Tell us what you'd like reviewed — we'll come back with a clear scope, timeline and fixed price within one working day.

Request a Security Engagement