Skip to main content
Fugen Services logo

Cloud & Infrastructure

Find the vulnerabilities that are actually exploitable, then fix them

An automated scan produces forty findings, most of which do not matter. What you need to know is which of them a real attacker could chain together to reach your data — and that requires someone actually trying. This is a manual audit that ends with the problems fixed, not a PDF of scanner output.

Indicative

From £3,500

Fixed price agreed in writing before any build starts.

Get a quote+44 7488 265083

The problem this solves

Two things make security reports useless. Volume without prioritisation, where a genuine authentication flaw sits in a list beside a missing header on a static asset. And findings without proof, which get argued about internally for months instead of fixed.

What you get

Authenticated application testing

Tested as each user role, because the interesting bugs are in authorisation — one customer reading another’s invoices, an editor reaching an admin endpoint. Unauthenticated scanning never finds these.

Proof of concept per finding

A reproducible sequence showing the impact. It removes the argument about whether something is real, which is usually what delays the fix.

Findings ranked by exploitability

Ordered by what an attacker could actually achieve, not by scanner severity. A theoretical medium behind three other controls sits below a trivially reachable low.

Server and configuration review

Exposed services, TLS configuration, security headers, file permissions, secrets in version control, and database accounts with more privilege than they need.

Dependency and supply chain check

Known CVEs in your dependencies, cross-referenced against whether the vulnerable code path is one you actually call — which is what separates 200 alerts from the four that matter.

Fix, then retest

We fix what you ask us to fix, then retest to confirm it and to check the fix did not open something else. An audit that stops at the report has done half the job.

How we work

  1. Scope and authorisation

    Exactly what is in scope, on what environment, in what window — agreed in writing before anything starts. Testing without written authorisation is not something we do.

  2. Reconnaissance

    Map the surface: endpoints, roles, integrations, third-party components.

  3. Manual testing

    Authentication, authorisation, injection, file handling, business logic and rate limiting, tested by hand with tooling as support rather than as the method.

  4. Report

    Each finding with reproduction steps, impact in plain terms, and a specific remediation. Plus a short summary a non-technical director can act on.

  5. Remediation

    We fix, or your team fixes with us reviewing.

  6. Retest

    Verify every fix and confirm nothing new was introduced.

What you should expect

  • Every finding proven, so none of them get debated instead of fixed
  • A fix order based on real exploitability rather than scanner severity
  • Fixes verified by retest, not assumed
  • A written record of the work for customers and insurers who ask

Built with

  • OWASP ASVS
  • OWASP Top 10
  • Burp Suite
  • nmap
  • sqlmap
  • npm audit
  • Composer audit
  • Snyk
  • Cloudflare WAF
  • fail2ban
  • Imunify360

Mainstream, well-supported technology — chosen so you can hire for it and so another team could take the project over.

Security Audits & Hardening — your questions

Including the ones about cost, which most agencies leave off the page.

A focused audit of one web application starts around £3,500 and typically runs £3,500 to £9,000 depending on the number of user roles and integrations. Remediation is quoted separately once we know what is actually there, because pricing fixes before finding the problems is meaningless.

Both, weighted to what will find more for your situation. Where we can read the source, reviewing it finds classes of bug that black-box testing misses — and it is faster. We are not a CREST-accredited testing house, and if your compliance requires that certification we will say so and point you at one.

We test against staging wherever one exists. Where production testing is unavoidable it is scoped explicitly, run in an agreed window, and destructive tests are excluded unless you specifically authorise them in writing.

WordPress core is reasonably solid. The problems are almost always abandoned plugins, weak admin passwords with no rate limiting, and old PHP. The typical WordPress compromise we clean up came in through a plugin last updated three years ago — not through WordPress itself.

We tell you immediately, before finishing the audit, and switch to containment. We preserve evidence rather than cleaning first, because knowing how they got in is what stops it happening again — and note that a personal-data breach carries a 72-hour ICO reporting obligation you will need advice on.

Yes. Alongside the technical report you get a summary suitable for sharing — scope, methodology, findings by severity, and confirmation of remediation — which is normally what an enterprise procurement questionnaire or an insurer is asking for.

Talk to someone who has built this before

A short call is usually enough to tell you whether this is the right service for your situation — including when it is not.