Security

Cybersecurity and compliance

Quick answer

Find the gaps before somebody else does. We run security audits and penetration testing, do the UK GDPR work, and finish with a plain-English list of what to fix and in what order. No 80-page PDF you will never read.

What a security audit covers

  • External surface. What of yours is reachable from the internet, what it exposes, and what is running a version with known problems.
  • Authentication and access. Who can get into what, whether old staff accounts still work, and whether an admin login is one guessable password away.
  • Application logic. The flaws scanners miss: being able to read another customer's record by changing a number in the URL, or skipping a payment step.
  • Data handling. Where personal data actually lives, who can read it, how long it is kept, and what happens to backups.
  • Dependencies. The libraries your software is built on, and which carry published vulnerabilities.

Penetration testing

A test is an attempt to break in under agreed rules, not a scan. We write down the scope and the limits first, in writing, then try to get further than we should. You get what we managed, how, and what stopped us where we were stopped.

Every finding carries a severity, a plain description of what somebody could actually do with it, and the fix. Ranked, because fixing the top three usually removes most of the real risk and the rest can wait for a normal release.

UK GDPR work

Compliance is mostly a set of questions you should be able to answer: what personal data you hold, why, on what lawful basis, who else sees it, how long you keep it, and what you would do in the first 72 hours after a breach. We work through them with you and write the answers down.

For a website that collects enquiries, that is a short exercise. For a care provider or a financial firm it is longer, because the data is more sensitive and procurement will ask.

What you get at the end

A findings document written so a non-technical director can read it, a ranked fix list, and a call to walk through it. If you want us to do the fixes we will quote them separately, and you are free to hand the list to your own developers instead. We would rather you fixed the problems than hired us.

Honest limits

A point-in-time test tells you about the system as it was that week. It is not a guarantee, and anybody offering one is selling something. It also does not replace the unglamorous basics: patching, backups you have actually restored, and multi-factor authentication on anything that matters.

Common questions

How much does a security audit cost?

It depends on how much surface there is to cover. A single marketing website is a small job. A web application with user accounts, payments and an admin area is a larger one. We scope it on a free call and quote a fixed price before starting, so you are not billed by the hour for an open-ended investigation.

Will penetration testing break our live system?

Not if it is scoped properly. We agree in writing what is in and out of scope, and anything genuinely destructive is either excluded or run against a copy. Where a test could affect live users we schedule it out of hours and tell you exactly when.

Do we need this to work with NHS or public sector clients?

Usually yes in some form. Public sector and healthcare procurement almost always asks how you handle personal data, where it is stored, and whether you have tested your systems. Having the answers written down before the question arrives is the difference between a quick approval and a stalled deal.