Security

Before somethinggoes wrong.

Most small businesses are not targeted by name. They are found by a scan looking for an old plugin, an exposed file, or a login with nothing behind it. Here is what we do about that, and a free check you can run on yourself right now.

imp@purpleimp.it: ~
ready. type a domain and press enter.

Free, no sign-up

Check your own domain.

It reads only what is already public: your DNS, your certificate, how your site answers, and the records that decide whether your email can be faked. It takes a few seconds and finishes with the three things we would fix first.

Everything here is what anyone on the internet can already see about your domain:

  • DNS: does the domain resolve to a public address
  • SSL: is the certificate valid, and when does it expire
  • HTTPS: does plain http redirect, is HSTS on
  • Headers: the basic security headers, and version banners
  • Email: MX, SPF, DMARC policy, DKIM at common selectors
  • CAA: who is allowed to issue your certificates

What it can't see: backups, MFA, patching, who still has the admin password. That's the conversation.

What we actually do

Review from outside, then inside

First what the internet can see. Then, with access, the server, the site, the accounts and the backups.

Harden the obvious

Close what should not be reachable, stop backup and config files being downloadable, take version numbers off the front door.

Firewall at the edge

A web application firewall filters the automated attacks before they reach your site at all.

Patch, and keep patching

Operating system, services, CMS and plugins. Most breaches use a hole that had a fix available.

Clean up access

Old accounts closed, shared passwords broken up, multi-factor authentication on anything that can reset something else.

Prove the backups

Security work assumes the worst day happens anyway. A tested restore is the difference between an incident and a catastrophe.

Being straight about it

What we don't do.

Security is a field full of people selling the adjacent thing and calling it the thing. We would rather lose the work than blur this.

  • We are not a penetration testing house. A real test is a specialist engagement with a formal report. We can get you ready for one and help you act on the findings.
  • We do not certify Cyber Essentials. We can prepare you for it: the patching, access control and account hygiene the questions are about. The certificate comes from an accredited assessor.
  • We will not sell you one box that fixes security. It does not exist. The work is updates, backups, access and attention.
  • We will not pretend the free check is an audit. It reads public records. It cannot see your backups, your MFA or who still has the admin password.

If it has already happened

Get in touch and say so plainly. Don't delete anything yet, don't wipe and reinstall in a panic, and don't pay anyone anything. We will tell you what to stop doing immediately, then work through containing it, cleaning it, closing the way in, and telling you honestly what we think was reached.

Rather be dull than newsworthy?

Good. So would we.

Tell us what's going on. You'll hear back from a real person at Purple Imp.