Security for businesses that run their own servers
We set up monitoring so you see attacks as they happen, harden the systems attackers go for first, and handle response and recovery when something gets through. Run by EC-Council certified analysts.
What is included
Security monitoring with Wazuh SIEM
We deploy and manage Wazuh across your servers and endpoints.
Included
Manager and agent deployment
Log collection
Custom detection rules
Alert routing
Dashboards
Tuning to reduce false positives
Ongoing rule updates
ForBusinesses running their own servers that want to see attacks as they happen.
Threat detection and response
Alert triage, investigation and containment when something fires.
Review of servers, cloud accounts and applications: access control, exposed services, storage permissions, stale credentials, patch state, backup integrity.
Included
Ranked findings with evidence
Remediation plan
Optional implementation
ForBusinesses that have been operating for years without an outside review.
Server and cloud hardening
Linux hardening: SSH key-only access, firewalling, intrusion prevention, automatic updates, kernel and service lockdown. Cloud hardening: IAM least privilege, storage exposure, network rules, audit logging to tamper-proof storage.
Included
Baseline review
Changes applied with rollback
Written record of every change
ForAnyone about to go to production, or who never hardened after they did.
Incident response and recovery
Containment, cleanup and rebuild after a compromise.
Included
Containment in the correct order
Persistence hunting
Clean rebuild on new infrastructure
Restore from backup
Post-incident report and hardening
ForCompromised websites, hosting suspensions, ransomware on servers.
Web and email security
Security headers, Content Security Policy, WAF and login protection for your site, plus SPF, DKIM and DMARC enforcement so nobody can send as you.
Included
Header and CSP deployment tested against your site
WAF rules
Login rate limits
DNS records for every sending platform
DMARC moved to enforcement in stages
Before-and-after verification
ForAgencies and businesses with a public site, and any business whose domain can be impersonated.
01
Read-only review first
We look before we change anything and write down what we find.
02
You approve every change
Nothing significant goes live without your sign-off.
03
Backup and rollback before cutover
Every migration and every fix has a way back before it starts.
04
Handover documentation
You can run it without us, or hand it to the next person.
Contact
Tell us what you are running.
A few lines is enough. What you have, what is not working, and what you want to
happen. We reply within one business day with what we would look at first.