Cyber Security
Tailored security for websites, apps and infrastructure
We run advanced security tests and continuous monitoring to find vulnerabilities and protect your systems, in line with the GDPR and international best practice.
- eCommerce with customer accounts, orders, checkout and integrations.
- WordPress, WooCommerce or PrestaShop sites with critical plugins and modules.
- Companies with servers, APIs, CRM or ERP systems exposed to the web.
- Before a migration or go-live.
- After Search Console warnings, spam or odd redirects.
- When plugins, modules or servers haven't been updated in a long time.
- Full scan of sites, servers, applications and networks
- Identification of known vulnerabilities (CVE)
- Detailed report with priorities and impact
- Continuous or periodic assessment
- Manual and automated attack simulations
- Black-box, white-box or grey-box testing
- Focus on web applications, APIs and corporate networks
- Technical report and recommended remediation
- Source code and software configuration review
- Access control, input validation and session checks
- OWASP checks defined in the scope and documented in the report
- Direct support to developers for targeted fixes
- Audits of firewalls, servers, VPNs and LAN/WAN networks
- Linux/Windows system hardening
- Analysis of ports, services and critical configurations
- Monitoring and alerting with response times and channels set by the service
Frequently asked questions
A vulnerability assessment combines tooling and technical checks to find known vulnerabilities and risky configurations. A pen test goes deeper into an agreed scope with manual, controlled attempts, to verify how exploitable an issue really is and what its impact would be.
It depends on the sector, the contracts, the risks and the applicable rules. The GDPR requires technical and organisational measures appropriate to the risk, but does not impose the same test on every organisation: the testing programme should be agreed with your technical and, for compliance, legal contacts.
Yes. We analyse plugins, configurations, versions and access, and report the risks with a priority order for fixing them.
Yes. Every test includes a clear document covering the vulnerabilities found, the risk level, the impact and the recommended fixes.
Yes. We can install IDS/IPS systems and monitoring dashboards for brute-force attacks, malware, scans or suspicious logins.