Security audit: one-off, with a report and a retest
An express audit surfaces open settings and signs of a past breach within a week. Penetration testing goes further: it attempts to get in the way a real attacker would, and backs every finding with evidence rather than a guess.
Why a breach is the last thing anyone hears about
Until something happens, security is taken on the word of the contractor who set it up — not checked by an independent outside look.
Nobody has rechecked the settings
A contractor configured the server and the site years ago, and nobody has reviewed the open ports and permissions since.
“Everything is secure” — on someone’s word
The claim rests on the memory of whoever set it up, not on a dated report listing what was actually checked.
What happens to a finding is unclear
Even when an audit is ordered, it is often unclear whether checking that a vulnerability was actually closed after the fix is part of it.
What the packages include
Four packages, from a quick review of one server up to a test of the internal network.
- Express audit — 1 server and 1 site: settings, vulnerabilities, signs of a past breach, a report with priorities
- Penetration test: external perimeter — up to 10 addresses, a report with evidence, a retest after fixes
- Penetration test: web application — logic, access rights, data, a report, a retest
- Penetration test: internal network — what an employee or contractor could do from the inside
What we do not do
- Ongoing monitoring and a data-leak-prevention subscription are not part of penetration testing — that is a separate, ongoing plan.
What stays with you
A report backed by evidence for every finding — it can be handed to your own team or a contractor to fix.
A retest is part of the penetration-testing package — no need to order it as a separate job.
A priority list: what to close first and what can wait.
Pricing
Audit and penetration testing
Express audit
- ✓1 server and 1 site
- ✓settings
- ✓vulnerabilities
- ✓signs of a past breach
- ✓a report with priorities
Penetration test: external perimeter
- ✓up to 10 addresses
- ✓a report with evidence
- ✓a retest after fixes
Penetration test: web application
- ✓logic
- ✓access rights
- ✓data
- ✓a report
- ✓a retest
Penetration test: internal network
- ✓what an employee or contractor could do from the inside
Terms
- A preliminary assessment from a description is free.
- Payment runs in stages: the next stage starts once the previous one is accepted.
- Our work carries a 3-month warranty after the acceptance certificate is signed.
How it works
We define the scope
What gets tested: one server and site, the external perimeter, a web application or the internal network
We run the test
We look for vulnerabilities and back every one with evidence, not a guess
We hand over a report with priorities
What to close first and what can wait
We retest
After fixes, we confirm the vulnerability is actually closed
FAQ
Tell us the scope to test
One server, a site, a web application or the internal network — we will tell you which package fits and when the report will be ready.
Related reading
We cover this topic in more depth on the blog
Server Security Audit: The Practical Checklist
Updates, access, open ports, exposed configs, malware, logs and backups — exactly what to check on a server, and how to automate it without a security team.
Signs Your Website Has Been Hacked
A hacked site usually looks fine and gives itself away through behaviour: spam from your domain, browser warnings, redirects, new admin accounts. How to spot it.
Hacked Through an Outdated CMS: How It Happens
Outdated CMS and plugin versions are the most common way in — public exploits plus bots scanning at scale. Where the hole usually is and how to close it safely.
Tell us about your task
Describe what you need — we will reply and suggest a suitable plan.