Service
Cybersecurity
The hole gets found before a malicious user does, not after.
Web app and API penetration testing in a controlled environment based on the OWASP Top 10, hardening Linux servers, Docker and web apps, and encrypted automated backups with a tested restore procedure.
- Pentest report on the OWASP Top 10 with risk ratings
- Server and Docker hardening (firewall, SSH, TLS)
- Encrypted automated backup setup
- Tested restore procedure with documentation
Examples
Typical situations and how I'd handle them
Online shop
A pentest before the attacker
Problem
Nobody has ever checked whether one customer can see another customer's orders.
Solution
A controlled security test against the OWASP Top 10 with a prioritised fix list.
Result
The holes are found before someone else finds them.
Small business
Access, sorted
Problem
Passwords live in a spreadsheet and former employees can still log in.
Solution
An access audit, two-factor authentication, a password manager and an offboarding procedure.
Result
You know exactly who has access to what.
What's included
What I do as part of this service
Penetration testing on the OWASP Top 10
Vulnerabilities found in a controlled environment, in a prioritised report, not an automated scanner printout.
Server hardening in an hour, not a week
Firewalls, SSH and TLS best practice applied without interrupting the service.
Encrypted backups that are actually tested
Automated backups to NAS or cloud, with a regular restore drill: a backup that's never been restored isn't a backup.
A security report you can show the board
Findings, risk level and fixes written in plain language, not jargon.
FAQ
Frequently asked questions
Could a pentest disrupt our production environment?
Testing happens in a controlled environment within an agreed time window to avoid production disruption: critical tests are always coordinated with you.
How often should we run a security audit?
At least once a year, and again after any major system change.
Do you test restoring backups, not just creating them?
Yes, restore testing is part of the process, because an untested backup is a false sense of security.