Services / Cyber Security

Boring is the goal.Boring means nothing got in.

Security reviews, hardening and vulnerability checks.

Most small businesses are not targeted by name. They are found by an automated scan looking for an old plugin, an exposed file, a login with no second factor. The work that stops that is unglamorous and mostly invisible, which is exactly why it gets skipped.

What you get

A review that starts outside

What the internet can see about you: certificates, exposed files, mail records, software versions on show. Then the same from the inside, with access to the server.

Hardening

Turning off what shouldn't be reachable, closing the files that shouldn't be downloadable, and taking the version numbers off the front door.

A web application firewall

Filtering the obvious attacks at the edge, before they ever reach your site.

Malware found and cleaned

If something is already in there, we find it, remove it, close the way in, and tell you honestly what we think it got.

Access tidied up

Old admin accounts removed, shared passwords broken up, multi-factor authentication on the things that matter.

A plain-English write-up

What we found, what we changed, what is left, and what it would take to fix it. No scare tactics and no jargon wall.

How it works

  1. Check what's publicStart with the free check on this site. It takes a few seconds and tells you what anyone else could already see.
  2. Look properlyWith access, we go through the server, the site, the accounts and the backups.
  3. Fix the cheap wins firstMost risk is removed by a short list of unexciting changes. We do those before anything expensive gets discussed.
  4. Write it downYou get a document you can hand to an insurer, a client or a board, in words they will understand.
  5. Keep checkingSecurity is a state you keep, not a job you finish. Patching and monitoring carry on.

Left alone, this is how it goes

What we get called about

None of these are hypothetical. They are the calls that come in, and every one of them is cheaper to prevent than to fix.

  • An old plugin gets exploited by a scan that was never aimed at you in particular.
  • Your site quietly starts serving other people's spam, and your search rankings go with it.
  • A backup file sitting in a web folder hands over your source code and database credentials.
  • A former member of staff still has an admin login nobody thought to remove.
  • A customer asks how you protect their data, and nobody can answer.

Questions we get asked

Do you do penetration testing?

No, and we would rather say so than sell you something adjacent and call it that. A penetration test is a specialist engagement with a formal report. We do security reviews, hardening and clean-up, and we can help you get ready for a proper test if you need one.

Can you help with Cyber Essentials?

We can help you prepare: the patching, access control, firewalling and account hygiene the questions are about. We are not a certifying body, so the certificate itself comes from an accredited assessor.

We think we've been hacked. What now?

Get in touch and say that plainly. Don't delete anything yet, because the evidence is often the fastest route to finding the way in. We'll tell you what to stop doing immediately, then work through containing it, cleaning it and closing the hole.

Is a firewall enough on its own?

No. It filters the obvious traffic. Updates, backups, access control and someone paying attention do the rest. Anyone selling you one box that solves security is selling you something.

Got a technical mess?

Excellent. We like those.

Tell us what's going on. You'll hear back from a real person at Purple Imp.