What we do
From an automated weekly Security Score to hands-on penetration testing and incident response — sized and priced for businesses that don't have a full-time security team.
Fixed rates on the pricing page · full technical check list on what we check · bespoke quotes via contact
How it works
Book a free scan
Run our automated Security Score against your site. Get a one-page report in 24 hours, no commitment.
Review the findings
We explain every finding in plain English — no jargon, no scare tactics. You decide what to fix first.
We fix it or you do
Ongoing monitoring keeps the score up. Or we can open PRs and fix findings directly in your codebase.
Core Assurance
One-off assessments with written reports, CVSS severity ratings, and a guaranteed retest on critical findings.
Web Application Penetration Testing
Most requestedManual testing of your web app against the OWASP Top 10 and beyond — authentication, session management, injection, business logic, and API security.
- ›Full OWASP Top 10 coverage (SQLi, XSS, CSRF, IDOR, broken auth…)
- ›API endpoint enumeration and security checks
- ›Business logic review (price manipulation, privilege escalation)
- ›Authenticated and unauthenticated test runs
- ›Written report with reproduction steps, severity ratings, and fix snippets
- ›One free retest of critical/high findings within 30 days
⏱ Report delivered within 5–10 business days
CI/CD & DevOps Security Review
A full audit of your build pipeline, secrets management, and software supply chain — covering GitHub Actions, container builds, dependency pinning, and deployment config.
- ›GitHub Actions / GitLab CI workflow audit (secret exposure, injection, trigger abuse)
- ›Secrets management review (are keys in env vars, committed to history, over-scoped?)
- ›Dependency pinning and SBOM analysis (known CVEs, unpinned versions)
- ›Container image security scan (base image age, privilege escalation paths)
- ›Deployment and hosting config review (IAM roles, public bucket access, audit logging)
⏱ Initial findings in 3 business days; full report within 7
Cloud & Hosting Security Review
Thorough review of your cloud setup — from Supabase Row-Level Security to S3/Azure Blob bucket policies, IAM roles, and audit log gaps.
- ›Supabase / PostgreSQL RLS policy review
- ›Storage bucket and CDN permissions audit
- ›IAM / service account over-privilege check
- ›API keys and environment variable exposure audit
- ›Audit logging and alerting configuration
- ›Actionable remediation list with copy-paste policy examples
⏱ Delivered within 5 business days
Internal Network Assessment
Lightweight remote network checks for distributed small businesses; partnered on-site engagement available for deeper internal network work across the Highlands and Islands.
- ›External attack surface mapping (open ports, exposed services, leaked credentials)
- ›VPN and remote-access configuration review
- ›On-site available: internal network scan, Wi-Fi segmentation check, device inventory
- ›Firewall rule review
- ›Findings report with remediation priority list
⏱ Remote checks in 3 days; on-site by arrangement
Continuous & Managed
Ongoing protection that runs in the background — useful for businesses that want monitoring without hiring a security team.
Security Score — Automated Scanning
Available nowWeekly automated scans on Basic, daily on Pro and Agency — TLS health, security headers, DNS authentication, exposed paths, and dependency versions — with an AI-generated one-page executive summary emailed to you.
- ›TLS certificate monitoring and expiry alerts
- ›HTTP security header checks (HSTS, CSP, X-Frame-Options, and more)
- ›SPF, DKIM, and DMARC email authentication audit
- ›Sensitive path exposure scan (.env, .git, config files)
- ›Score out of 100 with trend tracking over time
- ›Plain-English AI summary — no jargon
- ›Slack or Microsoft Teams alerts on score change (Pro/Agency plan)
⏱ First scan runs within 24 hours of sign-up
Dependency & Patch Monitoring
Ongoing tracking of outdated libraries, CMS versions, and known CVEs in your dependencies — with remediation PRs opened automatically in your repository when safe fixes are available.
- ›Real dependency scanning (npm, pip, Composer) via OSV.dev, once you connect a repository (Account → Connect a repository)
- ›CVE matching against your specific declared dependency versions
- ›Findings tagged new/fixed automatically on every re-scan
⏱ Runs as part of your regular scan cadence (weekly on Basic, daily on Pro/Agency) once a repository is connected
Local Business Package
An all-in-one cyber health check and ongoing support package designed for Highland and Islands small businesses with limited IT resource — covers website, email, backups, and GDPR basics.
- ›One-off website and email security audit
- ›SPF/DKIM/DMARC setup and verification
- ›Google Workspace / Microsoft 365 security settings review
- ›Backup strategy review (3-2-1 rule, recovery test)
- ›GDPR basics: what you need to document and display
- ›60-minute staff security awareness session (remote)
- ›Quarterly check-in call
⏱ Initial audit delivered within 2 weeks
Compliance & Governance
Practical documentation and readiness work for businesses navigating GDPR, Cyber Essentials, or procurement requirements.
GDPR Readiness Assessment
Practical gap analysis for small teams — identifies what you need to document, what you can defer, and what would cause a regulator the most concern if they knocked on your door today.
- ›Data asset inventory and mapping (what you hold, why, where, for how long)
- ›Lawful basis review for each data processing activity
- ›Privacy notice and cookie banner audit
- ›Subject access request and breach notification process review
- ›Data Protection Impact Assessment (DPIA) for high-risk activities
- ›Policy templates: retention, acceptable use, breach response
⏱ Assessment report in 5 business days
Cyber Essentials Preparation
Technical and documentation readiness checks aligned to the UK Cyber Essentials scheme — valuable for public sector contracts, grant bids, and supply-chain procurement requirements.
- ›Gap analysis against all five Cyber Essentials control categories
- ›Boundary firewalls and internet gateways review
- ›Secure configuration audit
- ›Access control and administrative privilege review
- ›Patch management and malware protection assessment
- ›Completed self-assessment questionnaire support
⏱ Readiness report within 7 business days; CE+ assessment by arrangement
Security Policy & Incident Response Planning
Practical security policies and IR playbooks sized for a small team — not enterprise boilerplate, but documents your staff will actually be able to follow under pressure.
- ›Tailored information security policy (not generic templates)
- ›Incident response runbook: roles, escalation, communication
- ›Tabletop exercise: walk through a realistic attack scenario with your team
- ›Ransomware response checklist
- ›Supplier and third-party risk review process
- ›Annual review built into contract
⏱ Initial policy drafts in 5 business days; tabletop by arrangement
Incident Response & Remediation
Support when something has gone wrong, and concrete code fixes when you want findings turned into pull requests.
Incident Response Retainer
A defined response window and pre-agreed scope so that if something goes wrong, you're not cold-calling a stranger while the clock is ticking.
- ›Named contact with guaranteed response SLA (8 business hours for retainer customers)
- ›Initial triage call within the SLA window
- ›Containment advice and decision support
- ›Evidence preservation guidance (chain of custody, log collection)
- ›Communication support: what to say to customers, regulators, and staff
- ›Post-incident report and lessons-learned session
⏱ Annual or quarterly retainer; by arrangement
Remediation Pull Requests
Findings from a scan or pentest become concrete GitHub PRs — actual code changes your team can review and merge, not just a list of recommendations.
- ›Scan or pentest findings translated into actionable code changes
- ›PRs opened against your repository with explanation comments
- ›Security headers added directly to your config files
- ›Outdated dependencies updated with test results
- ›Your team retains full review and merge control
- ›Available as a follow-on to any Hebrides Cyber assessment
⏱ PRs opened within 3 business days of assessment delivery
Hebrides Verticals
Sector-specific packages for businesses across the Highlands and Islands where generic advice often doesn't fit.
Tourism & Hospitality
Security for booking systems, point-of-sale, guest Wi-Fi, and GDPR handling across businesses built around seasonal demand and high staff turnover.
- ›Booking system and payment page security review
- ›Guest Wi-Fi segmentation from business network
- ›POS device and card payment security audit
- ›Seasonal staff access management (joiners and leavers)
- ›GDPR: guest data retention and marketing consent
Churches & Charities
Cost-conscious security support for organisations that hold sensitive pastoral and financial data but rarely have a dedicated IT function.
- ›Donation platform and giving page security review
- ›Charity Commission / OSCR data responsibility audit
- ›Volunteer and staff account management (MFA, shared credentials)
- ›Content archive access control (sermons, safeguarding records)
- ›Budget-conscious recommendations with free-tool alternatives where possible
Crofters & Small Agri-Tech
IoT device hardening and data security for small agricultural tech operations using remote sensors, telemetry, or grant-funded digital tools.
- ›IoT device inventory and firmware version audit
- ›Remote access (SSH, VPN, web interfaces) security check
- ›Agricultural data platform review (who can access sensor data)
- ›Grant compliance: data handling requirements for AgriTech funding
Photography & Creative Businesses
Security for client galleries, watermarking workflows, and checkout pages — protecting both creative assets and customer payment data.
- ›Client gallery access control and link expiry review
- ›Checkout and payment security for print/product sales
- ›Cloud storage (Dropbox, Google Drive, OneDrive) sharing audit
- ›Copyright and watermark workflow security
- ›Backup and disaster recovery for image archives
// ready?
Not sure where to start?
Book a free Security Score scan — get a one-page report in 24 hours, no commitment. Or just get in touch and we'll recommend the right starting point.