
A bad day stays a small one.
Websites get attacked whether or not anyone is watching. We watch: continuous monitoring, hardening, clean-up when something gets through, backups that have been tested, and the boring access hygiene that prevents most of it.
How we think about it
Most breaches are housekeeping.
Old plugins, shared passwords, a forgotten admin account, a backup nobody has restored. Security work is mostly removing those, then watching. We keep dependencies current, limit who can do what, log what happens, and rehearse the restore so a bad day is measured in hours, not weeks.

What we help with
What we guard.
Continuous monitoring
File changes, suspicious logins, expired certificates and unusual traffic, watched around the clock.
Malware cleanup and hardening
Infected sites cleaned, the entry closed, and the setup hardened so it stays closed.
Backups and restore drills
Backups off-site and restored on a schedule, because an untested backup is a hope.
Access and credential hygiene
Who has access, to what, with two factors, reviewed regularly and removed when people leave.
Updates and dependencies
CMS, plugins and libraries kept current and tested.
Incident response
A plan for the bad day, with a person to call and a checklist we have used before.
How it runs
Assess, harden, watch.
01
Assess
A review of hosting, access, dependencies and backups, written up within one working day.
02
Harden
Fixes in priority order, from the ones that stop most attacks to the ones that limit damage.
03
Watch
Monitoring, updates and drills as a monthly routine, with a report.
Questions
Asked before most projects.
Our site was hacked. Can you help now?
Yes. Start with the contact page, and we take the site to a clean state, find the entry and close it.
Do you do penetration testing?
Not as a formal service. We harden, monitor and respond, and we act on the findings of a penetration test done by a specialised firm.
What about GDPR?
Data minimisation, consent and access control are part of the setup. We build so there is less to protect.
Is this only for sites you built?
No. Any site or app, after a review that tells you what state it is in.
Other things we do
The rest of the studio.
- Web developmentFast, editorial sites on modern stacks, wired to a CMS your team can actually run.Design & build
- DesignWireframes, UI and UX, and the digital concept that holds all of it together.Design & build
- App developmentApps for iOS and Android with a backend that will still make sense in five years.Design & build
- AI-driven solutionsAgents, workflows and content pipelines built around your data, not around a demo.AI, search & systems
- SEO / AEOFound by search engines, and by the AI assistants people now ask instead.AI, search & systems
- IntegrationsBusiness systems, CRM and customer data, joined up through clean APIs.AI, search & systems
- Operations & supportHosting, monitoring, updates and support, with a direct line rather than a ticket queue.Run & protect
