Mostly maintenance, done consistently

Website security is a maintenance job. The great majority of what actually protects a small business website is unexciting and repetitive: keep the software patched, keep the certificates valid, keep backups that have been tested, and notice quickly when something changes.


None of that is difficult. It fails because it is nobody’s specific job, and because a site that is quietly out of date looks exactly like one that is fine, right up until it does not.


  • SSL certificates issued, installed and renewed before they expire
  • Software and platform patching, kept current rather than caught up
  • Backups of sites, applications and mailboxes
  • Uptime monitoring, so we know before your customers tell you
  • Email protection: filtering in, authentication out
  • Support for businesses working towards Cyber Essentials
2008

Trusted since

Website design, email hosting, and more

1

Supplier

Domain, DNS and mail

0

Third-party plugins

Our own CMS, maintained here

100%

UK-based team

Nationwide clients

Where website security actually goes wrong

Small business sites are rarely targeted individually. They are found by automated scanning that looks for known weaknesses in common software, and the weakness is almost always something with a fix already published, sometimes months earlier. The break-in is not clever. The site was simply out of date.

This is one of the reasons we build on our own content management system rather than on a platform with a plugin ecosystem. A conventional site can depend on a dozen third-party components, any of which can stop being maintained without anybody noticing, and each of which is a way in. We maintain what we wrote, so there is no chain of other people’s code to keep track of.

The other common failure is expiry. Certificates and domain registrations lapse, and a browser warning on your own site does more immediate commercial damage than most actual breaches. Visitors simply leave. It is entirely preventable by someone tracking dates.

Backups only count if they restore

An untested backup is a belief, not a safeguard. The common ways they disappoint are all mundane: the backup covered the files but not the database, it ran but had been failing silently for months, or the only copy sat on the same infrastructure as the thing it was protecting.

We back up sites, web applications and mailboxes. See email hosting for what that covers on the mail side. We care about whether a restore actually works, because that is the only property of a backup that matters.

Everything covered under Security

The maintenance that keeps a site, an application and its email out of trouble.

Certificates and Encryption

SSL certificates issued, installed and renewed on schedule, so nobody meets a browser warning on your address.

Patching and Updates

Platform and software kept current rather than caught up later, on a system we maintain ourselves with no third-party plugin chain behind it.

Backup and Recovery

Backups of sites, applications and mailboxes, held so that a restore is a real option rather than a hopeful one.

Monitoring

Uptime and certificate monitoring running continuously, with alerts reviewed during support hours so problems are caught before customers report them.

Security questions

Why would anyone attack our website? We are small.

Almost nobody chooses you specifically. Automated scanning looks for known weaknesses across the whole web and takes whatever it finds. Being small is not protection but being up to date is.

Is monitoring the same as support cover?

No, and it is worth being clear. Monitoring runs continuously, so a problem is detected whenever it happens. Alerts are reviewed during support hours, Monday to Friday 9:00am to 5:30pm. It is not a round-the-clock response service.

Our site was built by someone else. Can you secure it?

Sometimes. It depends what it runs on and what access we can get. We will look and tell you honestly whether it can be maintained safely as it stands, or whether the sensible money is on replacing it, and those answers do not always come out the way you would expect.

A client is asking us security questions we cannot answer.

That is an increasingly common reason people call, particularly around insurance renewals and tenders. Send us the questionnaire. A good part of it will be about things we already manage for you.

Not sure how exposed you are?

Whether it is a certificate about to lapse, a site nobody has updated in years, or a questionnaire you have been sent, tell us what has prompted it.