Most breaches at small and mid-sized companies are not sophisticated. They come from an unpatched server, a password reused across services, an old admin account nobody closed, or a backup that turned out never to have been tested. Fixing those is unglamorous and it is most of the value.
What we do
- Vulnerability assessment — scanning and manually reviewing your applications and servers, then reporting findings ranked by real risk rather than by scanner severity.
- Secure code review — reading the application code for injection, broken access control, weak authentication and exposed secrets.
- Infrastructure hardening — patching, firewall and port review, TLS configuration, removing dormant accounts and excess privileges.
- Access control — sensible roles, multi-factor authentication and a joiner-mover-leaver process so access ends when employment does.
- Backup and recovery — verifying that backups exist, are isolated from the systems they protect, and can actually be restored. We test the restore, not just the backup job.
- Incident preparation — a written plan for who does what, in what order, when something goes wrong.
How we work
Testing is done only against systems you own, with written authorisation and an agreed scope and window. You get a report that names the specific issue, how we found it, what an attacker could do with it, and what to change — written so your developers can act on it, with a plain-language summary for management.
We prioritise by what is actually exposed and exploitable in your environment. A critical-rated finding on a service unreachable from the internet may matter less than a medium-rated one on your login page.
What we are not
We are a development company that secures the kind of systems we build: web applications, business software and the infrastructure they run on. We are not a 24/7 managed security operations centre, and we do not currently hold formal security certifications. If your requirement is a certified audit for compliance purposes, tell us and we will say honestly whether we are the right fit or point you elsewhere.
Frequently asked questions
- Will testing disrupt our live systems?
- We agree the scope and timing with you first, and default to non-disruptive techniques on production. Anything with a risk of impact is either run against a staging copy or scheduled for a window you choose.
- What do we receive at the end?
- A written report: an executive summary, each finding with evidence and reproduction steps, a risk rating with our reasoning, and specific remediation advice. We will walk your team through it and re-test fixes.
- Do you hold security certifications?
- Not at present. Our security work rests on twenty years of building and running the kinds of systems we are asked to review. We would rather tell you that up front than imply credentials we do not have.
- Can you fix what you find?
- Yes. We can hand the report to your team, or carry out the remediation ourselves since we do development in-house. Where we have written the code being reviewed, we will make that conflict of interest clear.

