A hacked website is
worse than no website.

Firewalls, SSL, hardened access, malware removal and continuous monitoring, so your site stays trusted by customers and by Google. And if you’ve already been hit, we clean it up and get you back online.

24/7Monitoring & scanning
<24hCritical patch window
30-dayClean restore points
UKEngineers, in-house

Threat monitoring · what we watch

Running continuously
Brute-force attempts · Login PageRepeated failed logins rate-limited and blocked
firewallBlocked
SQL injection & code attemptsKnown attack patterns dropped at the edge
firewallBlocked
Malware & file-integrity scanFiles compared against a known-good baseline
dailyClean
Disclosed plugin vulnerabilityPatched once released, tested on staging first
CVE feedPatched
Spam & phishing filteringQuarantined at the domain before delivery
mailFiltered
Protected by ACSSSL issued, installed and auto-renewed

Not everyone targets you personally.
Bots target everybody.

Almost every website attack is automated, software scanning the whole internet for a known weakness. Being small isn’t protection; being current is.

What an exposed site costs

  • A browser warning on your brandChrome and Safari flag the site as deceptive, and visitors bounce before they ever see your homepage.
  • Search rankings you spent years earningGoogle de-indexes or blacklists compromised sites, recovery takes weeks after the clean-up is finished.
  • Customer data on the lineEnquiry forms and checkouts hold personal data. A breach is an ICO matter, not just an IT one.
  • Your server used against othersHijacked sites are used to send spam and host phishing pages, which gets your domain and IP blacklisted.
  • No backup, no way backThe most expensive sentence in web security: “the host said backups were included.”

What protection actually looks like

  • Attacks stopped at the edgeA web application firewall filters known attack patterns and rate-limits brute-force attempts before they reach your site.
  • Patched before it's exploitedVulnerability feeds watched daily; critical fixes applied within 24 hours, tested on staging first.
  • Access that's actually controlledLeast-privilege roles, enforced strong passwords, two-factor on admin accounts and old logins removed.
  • Clean, tested restore pointsOff-server backups kept 30 days, so a bad day means a restore in hours rather than a rebuild in weeks.
  • Someone watching who isn't youMonitoring and scanning run around the clock, and the alert comes to our engineers first.

Security services
for websites and the email behind them.

Whether we host you or not, and whether we built the site or inherited it from someone who’s long gone.

Web application firewall

Traffic filtered before it reaches your site - injection attempts, bad bots and known attack signatures dropped at the edge.

Malware & adware removal

Infected files identified and removed, injected code stripped out, and blacklist removal requests submitted to Google and the browsers.

SSL & encryption

Certificates issued, installed and auto-renewed, HTTPS enforced site-wide, and mixed-content warnings cleared.

Access control & 2FA

Least-privilege user roles, enforced password policy, two-factor on admin accounts, and old or shared logins removed.

Brute-force & DoS mitigation

Login rate-limiting, connection delays and automatic IP blacklisting when someone starts knocking repeatedly.

IP & country blocking

Block specific addresses, keyword-filter enquiry forms, or restrict whole regions you don't trade with, your rules.

Spam & phishing filtering

Domain-level mail filtering plus SPF, DKIM and DMARC configured properly, so your mail is trusted and junk stays out.

Vulnerability scanning

Daily scans against CVE feeds for your exact platform, plugin and PHP versions, with patching handled, not just reported.

Handled on a maintenance plan

Backups & rebuild after attack

Clean restore points to roll back to, and where there's no usable backup, we recreate the site from what survives.

No single measure protects a website.
Four layers do.

Anything can be got past on its own. The point is that an attacker has to get past all of them, and that we see it when they try.

Layer 01
The edge
  • Web application firewall
  • Bot & scraper filtering
  • Rate limiting and IP blocks
  • Country-level restrictions
Layer 02
The server
  • Hardened configuration
  • Isolated accounts & permissions
  • Patched OS and PHP versions
  • Off-server nightly backups
Layer 03
The application
  • Core, theme & plugin updates
  • Vulnerability scanning
  • File integrity monitoring
  • Unused plugins removed
Layer 04
The people
  • Two-factor on admin logins
  • Least-privilege user roles
  • Leavers' access revoked
  • Phishing-aware mail filtering

Layer three is ongoing work, not a one-off and it's delivered through a website maintenance plan.

Site defaced, redirecting, or flagged by Google?

Call us. We’ll take the site into a safe state, work out how they got in, clean it properly rather than patching over the symptom, and get the warnings lifted. We do this for sites we’ve never seen before, you don’t need to be a client.

  • Defacement & redirects
  • Malware injection
  • Blacklist removal
  • Spam sent from your domain
  • Locked-out admin accounts
  • No backup available
0121 798 1595Report an incidentMon-Sat 09:00-20:00 · out of hours for support clients

What happens
when you call us.

Four stages. The order matters and cleaning a site without closing the vulnerability, just means doing it twice.

01Stage 1 of 4
Stage 01 · Contain

Stop the bleeding first

The site goes behind a holding page or into maintenance mode, admin sessions and passwords are reset, and a forensic copy is taken before anything is changed, so evidence of the entry point survives.

  • Site isolated
  • Credentials rotated
  • Forensic copy taken
Stage 02 · Investigate

Find out how they got in

Access and error logs, file change timestamps and plugin versions tell the story: an outdated component, a weak password, or a leaked key. Without this step you're cleaning up an infection that comes straight back.

  • Log analysis
  • File integrity comparison
  • Entry point identified
Stage 03 · Clean & restore

Remove it, or rebuild it

Injected code and backdoors are stripped out and the site restored from a clean point where one exists. Where no usable backup exists, we recreate the site from what's intact and put a real backup regime in place.

  • Backdoors removed
  • Clean restore point
  • Rebuild where needed
Stage 04 · Harden & monitor

Close the door behind you

Everything patched, firewall rules tightened, two-factor enforced, blacklist removal submitted to Google and the browsers. Then ongoing monitoring and updates so the same gap doesn't reopen in three months.

  • Patched & hardened
  • Blacklist removal
  • Ongoing monitoring
Keep scrolling

Fix it once,
or keep it from happening.

Most clients start with the first and move to the second – because clean-ups cost more than upkeep, every time.

One-off security work

Quoted per job, after we've looked

  • Malware removal and site clean-up
  • Blacklist and browser-warning removal
  • Rebuild after data loss or defacement
  • Security audit with written findings
  • SSL, firewall and access-control setup
  • Migration to a secure hosting platform
Get it looked atFixed quote before any work starts
Recommended

Ongoing protection

Security delivered through a care plan

  • Everything above, plus continuous cover:
  • Weekly platform, plugin and dependency updates
  • Critical security patches within 24 hours
  • Daily malware and vulnerability scanning
  • Nightly off-server backups, 30-day retention
  • Firewall rules and access reviewed quarterly
  • Monthly report of what was blocked and patched

Already hosted with us? Firewall, SSL and backups are included as standard on every hosting package.

Common questions

Before you get in touch.

Common signs: a browser or Google warning, unexpected redirects, content or links you didn’t add, a sudden traffic drop, mail from your domain being rejected, or admin logins that stop working. If you’re unsure, send us the address and we’ll check for free.

Yes. We work on sites hosted anywhere, provided we can get suitable access. If the current host makes proper clean-up or backups impossible, we’ll say so and can move you to our platform as part of the work.

A straightforward infection with a clean backup is often same-day. A site with no usable backup, or one that needs recreating after data loss, takes longer, we’ll give you a realistic timescale and a fixed quote once we’ve looked.

Not if the entry point is closed. That’s why we investigate before cleaning, and why we recommend ongoing updates afterwards, reinfection almost always happens where a site is cleaned but left unpatched.

Yes. Once the site is verifiably clean we submit review requests to Google Search Console and the relevant blacklists. Removal is usually a matter of days, and we chase it until it’s lifted.

No. SSL encrypts traffic between visitor and server, which matters, but it does nothing about an outdated plugin or a weak admin password. It’s one layer of four.

This page covers the specialist work: audits, firewalling, hardening, clean-up and recovery. Maintenance is the ongoing rhythm that keeps you out of trouble: weekly updates, patching, backups and monitoring. Most clients need a bit of the first and all of the second.

Yes, domain-level spam and phishing filtering, plus SPF, DKIM and DMARC records configured correctly so nobody can convincingly send mail as you, and your legitimate mail lands in inboxes.

Need a quote on Website Security?

Send us your web address for a free security check: SSL and headers, platform and plugin versions against known vulnerabilities, exposed admin paths, mail records and backup status

ACS at work