Cloud & Infrastructure
Find the vulnerabilities that are actually exploitable, then fix them
An automated scan produces forty findings, most of which do not matter. What you need to know is which of them a real attacker could chain together to reach your data — and that requires someone actually trying. This is a manual audit that ends with the problems fixed, not a PDF of scanner output.
Indicative
From £3,500
Fixed price agreed in writing before any build starts.
Get a quote+44 7488 265083The problem this solves
Two things make security reports useless. Volume without prioritisation, where a genuine authentication flaw sits in a list beside a missing header on a static asset. And findings without proof, which get argued about internally for months instead of fixed.
What you get
Authenticated application testing
Tested as each user role, because the interesting bugs are in authorisation — one customer reading another’s invoices, an editor reaching an admin endpoint. Unauthenticated scanning never finds these.
Proof of concept per finding
A reproducible sequence showing the impact. It removes the argument about whether something is real, which is usually what delays the fix.
Findings ranked by exploitability
Ordered by what an attacker could actually achieve, not by scanner severity. A theoretical medium behind three other controls sits below a trivially reachable low.
Server and configuration review
Exposed services, TLS configuration, security headers, file permissions, secrets in version control, and database accounts with more privilege than they need.
Dependency and supply chain check
Known CVEs in your dependencies, cross-referenced against whether the vulnerable code path is one you actually call — which is what separates 200 alerts from the four that matter.
Fix, then retest
We fix what you ask us to fix, then retest to confirm it and to check the fix did not open something else. An audit that stops at the report has done half the job.
How we work
Scope and authorisation
Exactly what is in scope, on what environment, in what window — agreed in writing before anything starts. Testing without written authorisation is not something we do.
Reconnaissance
Map the surface: endpoints, roles, integrations, third-party components.
Manual testing
Authentication, authorisation, injection, file handling, business logic and rate limiting, tested by hand with tooling as support rather than as the method.
Report
Each finding with reproduction steps, impact in plain terms, and a specific remediation. Plus a short summary a non-technical director can act on.
Remediation
We fix, or your team fixes with us reviewing.
Retest
Verify every fix and confirm nothing new was introduced.
What you should expect
- Every finding proven, so none of them get debated instead of fixed
- A fix order based on real exploitability rather than scanner severity
- Fixes verified by retest, not assumed
- A written record of the work for customers and insurers who ask
Built with
- OWASP ASVS
- OWASP Top 10
- Burp Suite
- nmap
- sqlmap
- npm audit
- Composer audit
- Snyk
- Cloudflare WAF
- fail2ban
- Imunify360
Mainstream, well-supported technology — chosen so you can hire for it and so another team could take the project over.
Security Audits & Hardening — your questions
Including the ones about cost, which most agencies leave off the page.
A focused audit of one web application starts around £3,500 and typically runs £3,500 to £9,000 depending on the number of user roles and integrations. Remediation is quoted separately once we know what is actually there, because pricing fixes before finding the problems is meaningless.
Both, weighted to what will find more for your situation. Where we can read the source, reviewing it finds classes of bug that black-box testing misses — and it is faster. We are not a CREST-accredited testing house, and if your compliance requires that certification we will say so and point you at one.
We test against staging wherever one exists. Where production testing is unavoidable it is scoped explicitly, run in an agreed window, and destructive tests are excluded unless you specifically authorise them in writing.
WordPress core is reasonably solid. The problems are almost always abandoned plugins, weak admin passwords with no rate limiting, and old PHP. The typical WordPress compromise we clean up came in through a plugin last updated three years ago — not through WordPress itself.
We tell you immediately, before finishing the audit, and switch to containment. We preserve evidence rather than cleaning first, because knowing how they got in is what stops it happening again — and note that a personal-data breach carries a 72-hour ICO reporting obligation you will need advice on.
Yes. Alongside the technical report you get a summary suitable for sharing — scope, methodology, findings by severity, and confirmation of remediation — which is normally what an enterprise procurement questionnaire or an insurer is asking for.
Related services
Most projects touch more than one of these.
Server Management
Patching, monitoring, backups that are actually tested, and a named person to call when something is wrong.
Read moreDevOps & Cloud Engineering
Automated pipelines, infrastructure defined in code, and monitoring that tells you about a problem before a customer does.
Read moreCloud Migration
A phased migration with a rehearsed cutover and a rollback that has been tested, not just written down.
Read moreQA & Software Testing
Automated tests on the journeys that actually matter, running in CI, with flakiness treated as a defect.
Read moreWordPress Development
Custom themes, plugin surgery, and performance and security work — plus a straight answer about whether to stay on WordPress.
Read moreTalk to someone who has built this before
A short call is usually enough to tell you whether this is the right service for your situation — including when it is not.

