Server security

Most attacks never reach your site.

We put the layers in front of your server, keep them up to date, and have a person look when something gets close - on our servers or on yours.

Get a quote

A quiet night, on the record

Every server is attacked every day. What matters is that each attempt is stopped, written down, and seen by someone when it needs to be.

Six layers, outside in

An attacker has to get through every one of them. Each is set up for your server, not copied from a default.

  1. Firewall

    Only the ports your services need are open; everything else is closed at the edge.

  2. Automatic bans

    Repeated failed logins and scanning ban the address on its own, before it gets lucky.

  3. Web application firewall

    Requests carrying injection, file probing and known exploits are dropped before your code sees them.

  4. Hardened access

    Key-only SSH, no root logins, separate users per site and strong TLS settings.

  5. Patching

    Security updates applied on a schedule, and urgent ones the day they are published.

  6. Backups that are tested

    Copies kept off the server and restored on a test machine, so the last line of defence actually works.

And a person behind it

  • An audit first

    We look at the server as it is and give you a written list of what is open, old or weak, before changing anything.

  • Alerts that mean something

    Routine blocks stay in the log. You are told only when something needs a decision.

  • Any server

    Ours, a cloud provider's, or a machine in your office - Linux servers running your sites and applications.

  • A clean-up when it is too late

    Already hacked? We find how they got in, remove what they left, close the door and bring the site back.

Tell us what you are protecting

How many servers, where they run, and what is on them. Every engagement starts with the audit and is quoted after it.

Get a quote