A review that starts outside
What the internet can see about you: certificates, exposed files, mail records, software versions on show. Then the same from the inside, with access to the server.
Services / Cyber Security
Security reviews, hardening and vulnerability checks.
Most small businesses are not targeted by name. They are found by an automated scan looking for an old plugin, an exposed file, a login with no second factor. The work that stops that is unglamorous and mostly invisible, which is exactly why it gets skipped.
What the internet can see about you: certificates, exposed files, mail records, software versions on show. Then the same from the inside, with access to the server.
Turning off what shouldn't be reachable, closing the files that shouldn't be downloadable, and taking the version numbers off the front door.
Filtering the obvious attacks at the edge, before they ever reach your site.
If something is already in there, we find it, remove it, close the way in, and tell you honestly what we think it got.
Old admin accounts removed, shared passwords broken up, multi-factor authentication on the things that matter.
What we found, what we changed, what is left, and what it would take to fix it. No scare tactics and no jargon wall.
Left alone, this is how it goes
None of these are hypothetical. They are the calls that come in, and every one of them is cheaper to prevent than to fix.
No, and we would rather say so than sell you something adjacent and call it that. A penetration test is a specialist engagement with a formal report. We do security reviews, hardening and clean-up, and we can help you get ready for a proper test if you need one.
We can help you prepare: the patching, access control, firewalling and account hygiene the questions are about. We are not a certifying body, so the certificate itself comes from an accredited assessor.
Get in touch and say that plainly. Don't delete anything yet, because the evidence is often the fastest route to finding the way in. We'll tell you what to stop doing immediately, then work through containing it, cleaning it and closing the hole.
No. It filters the obvious traffic. Updates, backups, access control and someone paying attention do the rest. Anyone selling you one box that solves security is selling you something.
Got a technical mess?
Tell us what's going on. You'll hear back from a real person at Purple Imp.