A hacked website is
worse than no website.
Firewalls, SSL, hardened access, malware removal and continuous monitoring, so your site stays trusted by customers and by Google. And if you’ve already been hit, we clean it up and get you back online.
Threat monitoring · what we watch
Running continuouslyNot everyone targets you personally.
Bots target everybody.
Almost every website attack is automated, software scanning the whole internet for a known weakness. Being small isn’t protection; being current is.
What an exposed site costs
- A browser warning on your brandChrome and Safari flag the site as deceptive, and visitors bounce before they ever see your homepage.
- Search rankings you spent years earningGoogle de-indexes or blacklists compromised sites, recovery takes weeks after the clean-up is finished.
- Customer data on the lineEnquiry forms and checkouts hold personal data. A breach is an ICO matter, not just an IT one.
- Your server used against othersHijacked sites are used to send spam and host phishing pages, which gets your domain and IP blacklisted.
- No backup, no way backThe most expensive sentence in web security: “the host said backups were included.”
What protection actually looks like
- Attacks stopped at the edgeA web application firewall filters known attack patterns and rate-limits brute-force attempts before they reach your site.
- Patched before it's exploitedVulnerability feeds watched daily; critical fixes applied within 24 hours, tested on staging first.
- Access that's actually controlledLeast-privilege roles, enforced strong passwords, two-factor on admin accounts and old logins removed.
- Clean, tested restore pointsOff-server backups kept 30 days, so a bad day means a restore in hours rather than a rebuild in weeks.
- Someone watching who isn't youMonitoring and scanning run around the clock, and the alert comes to our engineers first.
Security services
for websites and the email behind them.
Whether we host you or not, and whether we built the site or inherited it from someone who’s long gone.
Web application firewall
Traffic filtered before it reaches your site - injection attempts, bad bots and known attack signatures dropped at the edge.
Malware & adware removal
Infected files identified and removed, injected code stripped out, and blacklist removal requests submitted to Google and the browsers.
SSL & encryption
Certificates issued, installed and auto-renewed, HTTPS enforced site-wide, and mixed-content warnings cleared.
Access control & 2FA
Least-privilege user roles, enforced password policy, two-factor on admin accounts, and old or shared logins removed.
Brute-force & DoS mitigation
Login rate-limiting, connection delays and automatic IP blacklisting when someone starts knocking repeatedly.
IP & country blocking
Block specific addresses, keyword-filter enquiry forms, or restrict whole regions you don't trade with, your rules.
Spam & phishing filtering
Domain-level mail filtering plus SPF, DKIM and DMARC configured properly, so your mail is trusted and junk stays out.
Vulnerability scanning
Daily scans against CVE feeds for your exact platform, plugin and PHP versions, with patching handled, not just reported.
Handled on a maintenance planBackups & rebuild after attack
Clean restore points to roll back to, and where there's no usable backup, we recreate the site from what survives.
No single measure protects a website.
Four layers do.
Anything can be got past on its own. The point is that an attacker has to get past all of them, and that we see it when they try.
- Web application firewall
- Bot & scraper filtering
- Rate limiting and IP blocks
- Country-level restrictions
- Hardened configuration
- Isolated accounts & permissions
- Patched OS and PHP versions
- Off-server nightly backups
- Core, theme & plugin updates
- Vulnerability scanning
- File integrity monitoring
- Unused plugins removed
- Two-factor on admin logins
- Least-privilege user roles
- Leavers' access revoked
- Phishing-aware mail filtering
Layer three is ongoing work, not a one-off and it's delivered through a website maintenance plan.
Site defaced, redirecting, or flagged by Google?
Call us. We’ll take the site into a safe state, work out how they got in, clean it properly rather than patching over the symptom, and get the warnings lifted. We do this for sites we’ve never seen before, you don’t need to be a client.
- Defacement & redirects
- Malware injection
- Blacklist removal
- Spam sent from your domain
- Locked-out admin accounts
- No backup available
What happens
when you call us.
Four stages. The order matters and cleaning a site without closing the vulnerability, just means doing it twice.
Stop the bleeding first
The site goes behind a holding page or into maintenance mode, admin sessions and passwords are reset, and a forensic copy is taken before anything is changed, so evidence of the entry point survives.
- Site isolated
- Credentials rotated
- Forensic copy taken
Find out how they got in
Access and error logs, file change timestamps and plugin versions tell the story: an outdated component, a weak password, or a leaked key. Without this step you're cleaning up an infection that comes straight back.
- Log analysis
- File integrity comparison
- Entry point identified
Remove it, or rebuild it
Injected code and backdoors are stripped out and the site restored from a clean point where one exists. Where no usable backup exists, we recreate the site from what's intact and put a real backup regime in place.
- Backdoors removed
- Clean restore point
- Rebuild where needed
Close the door behind you
Everything patched, firewall rules tightened, two-factor enforced, blacklist removal submitted to Google and the browsers. Then ongoing monitoring and updates so the same gap doesn't reopen in three months.
- Patched & hardened
- Blacklist removal
- Ongoing monitoring
Fix it once,
or keep it from happening.
Most clients start with the first and move to the second – because clean-ups cost more than upkeep, every time.
One-off security work
Quoted per job, after we've looked
- Malware removal and site clean-up
- Blacklist and browser-warning removal
- Rebuild after data loss or defacement
- Security audit with written findings
- SSL, firewall and access-control setup
- Migration to a secure hosting platform
Ongoing protection
Security delivered through a care plan
- Everything above, plus continuous cover:
- Weekly platform, plugin and dependency updates
- Critical security patches within 24 hours
- Daily malware and vulnerability scanning
- Nightly off-server backups, 30-day retention
- Firewall rules and access reviewed quarterly
- Monthly report of what was blocked and patched
Already hosted with us? Firewall, SSL and backups are included as standard on every hosting package.
Security isn't a product.
It's multiple services doing their job.
A lot of what keeps a site secure sits in maintenance and hosting. Here’s what belongs where, so you’re not paying twice.
Updates, patching and backups
Out-of-date plugins are how most sites get compromised. Care plans cover the monthly update cycle, critical patching within 24 hours, staging tests and daily backups, the ongoing half of everything on this page.
See maintenance plansThe platform underneath
Firewalling, SSL, isolated accounts, hardened server configuration, SPF/DKIM/DMARC and off-server backups all live at the hosting layer, included as standard on our managed hosting rather than sold as an add-on.
See hosting & DNSCommon questions
Before you get in touch.
How do I know if my site has been hacked?
Common signs: a browser or Google warning, unexpected redirects, content or links you didn’t add, a sudden traffic drop, mail from your domain being rejected, or admin logins that stop working. If you’re unsure, send us the address and we’ll check for free.
Can you help if we're not hosted with you?
Yes. We work on sites hosted anywhere, provided we can get suitable access. If the current host makes proper clean-up or backups impossible, we’ll say so and can move you to our platform as part of the work.
How long does a clean-up take?
A straightforward infection with a clean backup is often same-day. A site with no usable backup, or one that needs recreating after data loss, takes longer, we’ll give you a realistic timescale and a fixed quote once we’ve looked.
Will it just get hacked again?
Not if the entry point is closed. That’s why we investigate before cleaning, and why we recommend ongoing updates afterwards, reinfection almost always happens where a site is cleaned but left unpatched.
Do you remove Google's “this site may harm your computer” warning?
Yes. Once the site is verifiably clean we submit review requests to Google Search Console and the relevant blacklists. Removal is usually a matter of days, and we chase it until it’s lifted.
Is an SSL certificate enough on its own?
No. SSL encrypts traffic between visitor and server, which matters, but it does nothing about an outdated plugin or a weak admin password. It’s one layer of four.
What's the difference between this and a maintenance plan?
This page covers the specialist work: audits, firewalling, hardening, clean-up and recovery. Maintenance is the ongoing rhythm that keeps you out of trouble: weekly updates, patching, backups and monitoring. Most clients need a bit of the first and all of the second.
Do you handle email security too?
Yes, domain-level spam and phishing filtering, plus SPF, DKIM and DMARC records configured correctly so nobody can convincingly send mail as you, and your legitimate mail lands in inboxes.
Need a quote on Website Security?
Send us your web address for a free security check: SSL and headers, platform and plugin versions against known vulnerabilities, exposed admin paths, mail records and backup status
