Service

Cybersecurity

The hole gets found before a malicious user does, not after.

Web app and API penetration testing in a controlled environment based on the OWASP Top 10, hardening Linux servers, Docker and web apps, and encrypted automated backups with a tested restore procedure.

  • Pentest report on the OWASP Top 10 with risk ratings
  • Server and Docker hardening (firewall, SSH, TLS)
  • Encrypted automated backup setup
  • Tested restore procedure with documentation

Examples

Typical situations and how I'd handle them

Online shop

A pentest before the attacker

Problem

Nobody has ever checked whether one customer can see another customer's orders.

Solution

A controlled security test against the OWASP Top 10 with a prioritised fix list.

Result

The holes are found before someone else finds them.

Small business

Access, sorted

Problem

Passwords live in a spreadsheet and former employees can still log in.

Solution

An access audit, two-factor authentication, a password manager and an offboarding procedure.

Result

You know exactly who has access to what.

What's included

What I do as part of this service

Penetration testing on the OWASP Top 10

Vulnerabilities found in a controlled environment, in a prioritised report, not an automated scanner printout.

Server hardening in an hour, not a week

Firewalls, SSH and TLS best practice applied without interrupting the service.

Encrypted backups that are actually tested

Automated backups to NAS or cloud, with a regular restore drill: a backup that's never been restored isn't a backup.

A security report you can show the board

Findings, risk level and fixes written in plain language, not jargon.

  • OWASP ZAP
  • Linux
  • Docker
  • Let's Encrypt

FAQ

Frequently asked questions

Could a pentest disrupt our production environment?

Testing happens in a controlled environment within an agreed time window to avoid production disruption: critical tests are always coordinated with you.

How often should we run a security audit?

At least once a year, and again after any major system change.

Do you test restoring backups, not just creating them?

Yes, restore testing is part of the process, because an untested backup is a false sense of security.

All frequently asked questions

Get started

Do you know how secure your system is?

Tell me what needs protecting. I'll find the holes before someone else does.