Security operations
Security that’s looked after every month, not once
New vulnerabilities in WordPress plugins are published every week. A SecOps retainer keeps your site patched, watched and tested by the people who know it, with a report that shows exactly what we did.
What’s included
Done properly, start to finish
Patching
Security updates applied quickly and carefully, with a backup first and a check after.
Vulnerability tracking
Every plugin, theme and library you run, watched against new disclosures.
Access reviews
Old accounts removed, roles kept tight, two-factor sign-in enforced.
Log reviews
Sign-ins, failed attempts and changes reviewed, so odd behavior gets noticed.
Incident response
If something does get through, the team that knows your site is already on it.
Reporting
A one-page monthly report: what we patched, what we checked, what we recommend.
The routine
What happens, and when
Written down, so you can see it’s being done.
Every month
- Updates applied after a backup, then checked
- Plugins and themes checked against new vulnerability disclosures
- Users and access reviewed
- Sign-in and audit logs reviewed for anything unusual
- Security headers, certificates and DNS checked
- A one-page report
Every quarter
- A test restore from backup
- An external vulnerability scan
- A review of who can reach what
When it matters
- Urgent patches as soon as a fix is out
- Incident response if anything gets through
- A full penetration test, yearly or before a big launch
The steps
From first message to closed
- 01
Baseline
An audit and hardening, so we start clean.
- 02
Monthly
Patching, reviews and a report.
- 03
Quarterly
Restore test and external scan.
- 04
Yearly
A penetration test, if you want one.
Start here
Request a security assessment
Tell us what you run and what worries you. We’ll reply with a scope, dates and a fixed price in writing, and you decide from there.
- A reply from the people who’ll do the work
- Scope, dates and a fixed price before anything starts
- An NDA before we start, if you want one
- Nothing is tested without written authorization
Urgent? Message us on WhatsApp ↗
How is this different from a care plan?
A care plan covers website updates, SEO, fixes and content. SecOps is security only and goes deeper: vulnerability tracking, log and access reviews, regular testing and incident response. Many clients have both.
Do you watch the site around the clock?
Automated checks run all the time and alert us when something looks wrong. We respond during business hours, with urgent issues handled first. If you need a guaranteed 24/7 response, tell us and we’ll scope it honestly.
Can you look after a site you didn’t build?
Yes, after an initial audit and hardening, so we start from a known, clean state.
What does it cost?
A fixed monthly price, set after the first audit, based on how many sites you have and how complex they are.
More security services
The rest of the loop
Manual testing of your website, web app or API, following the OWASP testing guide, with every finding re-tested after it’s fixed.
Read more → WordPress securityAudits, hardening and fixes for WordPress: plugins, users, logins, configuration and the server underneath.
Read more → Vulnerability remediationBring us a pentest report, scan results or a host warning. We fix every finding and re-test it.
Read more → Hack recoveryMalware removed, the entry point found and closed, passwords rotated and search warnings cleared.
Read more →