We look at the system the way an attacker does: permissions left wide open, outdated libraries, secrets written into the code, and entry points nobody remembers leaving open. Then we harden the servers and close what can be closed.
And if the breach has already happened, we start with containment: stop the bleeding first, clean up, close the route they came in through, then write down exactly what happened and how.
Technologies
- Hardening
- Audit
- Incident response
- WAF
- TLS
- Secrets management
- Backups
What the work includes
- A documented security review
- Server and service hardening
- Library and dependency updates
- Secrets moved out of the code
- A permissions and access review
- Web application firewall rules
- Malware scanning and cleanup
- A risk report ordered by severity
How we work
Define the scope
What is reviewed, and what is out of scope.
Review
The code, the server and the permissions.
Remediate
Fixes and hardening, by severity.
Verify
A re-scan and a final report.
Pricing
Priced once the scope is set. Emergency breach response is quoted separately.