HebridesCyber

What we do

From an automated weekly Security Score to hands-on penetration testing and incident response — sized and priced for businesses that don't have a full-time security team.

Fixed rates on the pricing page · full technical check list on what we check · bespoke quotes via contact

How it works

Book a free scan

Run our automated Security Score against your site. Get a one-page report in 24 hours, no commitment.

Review the findings

We explain every finding in plain English — no jargon, no scare tactics. You decide what to fix first.

We fix it or you do

Ongoing monitoring keeps the score up. Or we can open PRs and fix findings directly in your codebase.

Core Assurance

One-off assessments with written reports, CVSS severity ratings, and a guaranteed retest on critical findings.

🔓

Web Application Penetration Testing

Most requested

Manual testing of your web app against the OWASP Top 10 and beyond — authentication, session management, injection, business logic, and API security.

  • Full OWASP Top 10 coverage (SQLi, XSS, CSRF, IDOR, broken auth…)
  • API endpoint enumeration and security checks
  • Business logic review (price manipulation, privilege escalation)
  • Authenticated and unauthenticated test runs
  • Written report with reproduction steps, severity ratings, and fix snippets
  • One free retest of critical/high findings within 30 days

Report delivered within 5–10 business days

⚙️

CI/CD & DevOps Security Review

A full audit of your build pipeline, secrets management, and software supply chain — covering GitHub Actions, container builds, dependency pinning, and deployment config.

  • GitHub Actions / GitLab CI workflow audit (secret exposure, injection, trigger abuse)
  • Secrets management review (are keys in env vars, committed to history, over-scoped?)
  • Dependency pinning and SBOM analysis (known CVEs, unpinned versions)
  • Container image security scan (base image age, privilege escalation paths)
  • Deployment and hosting config review (IAM roles, public bucket access, audit logging)

Initial findings in 3 business days; full report within 7

☁️

Cloud & Hosting Security Review

Thorough review of your cloud setup — from Supabase Row-Level Security to S3/Azure Blob bucket policies, IAM roles, and audit log gaps.

  • Supabase / PostgreSQL RLS policy review
  • Storage bucket and CDN permissions audit
  • IAM / service account over-privilege check
  • API keys and environment variable exposure audit
  • Audit logging and alerting configuration
  • Actionable remediation list with copy-paste policy examples

Delivered within 5 business days

🌐

Internal Network Assessment

Lightweight remote network checks for distributed small businesses; partnered on-site engagement available for deeper internal network work across the Highlands and Islands.

  • External attack surface mapping (open ports, exposed services, leaked credentials)
  • VPN and remote-access configuration review
  • On-site available: internal network scan, Wi-Fi segmentation check, device inventory
  • Firewall rule review
  • Findings report with remediation priority list

Remote checks in 3 days; on-site by arrangement

Continuous & Managed

Ongoing protection that runs in the background — useful for businesses that want monitoring without hiring a security team.

📊

Security Score — Automated Scanning

Available now

Weekly automated scans on Basic, daily on Pro and Agency — TLS health, security headers, DNS authentication, exposed paths, and dependency versions — with an AI-generated one-page executive summary emailed to you.

  • TLS certificate monitoring and expiry alerts
  • HTTP security header checks (HSTS, CSP, X-Frame-Options, and more)
  • SPF, DKIM, and DMARC email authentication audit
  • Sensitive path exposure scan (.env, .git, config files)
  • Score out of 100 with trend tracking over time
  • Plain-English AI summary — no jargon
  • Slack or Microsoft Teams alerts on score change (Pro/Agency plan)

First scan runs within 24 hours of sign-up

🔍

Dependency & Patch Monitoring

Ongoing tracking of outdated libraries, CMS versions, and known CVEs in your dependencies — with remediation PRs opened automatically in your repository when safe fixes are available.

  • Real dependency scanning (npm, pip, Composer) via OSV.dev, once you connect a repository (Account → Connect a repository)
  • CVE matching against your specific declared dependency versions
  • Findings tagged new/fixed automatically on every re-scan

Runs as part of your regular scan cadence (weekly on Basic, daily on Pro/Agency) once a repository is connected

🏪

Local Business Package

An all-in-one cyber health check and ongoing support package designed for Highland and Islands small businesses with limited IT resource — covers website, email, backups, and GDPR basics.

  • One-off website and email security audit
  • SPF/DKIM/DMARC setup and verification
  • Google Workspace / Microsoft 365 security settings review
  • Backup strategy review (3-2-1 rule, recovery test)
  • GDPR basics: what you need to document and display
  • 60-minute staff security awareness session (remote)
  • Quarterly check-in call

Initial audit delivered within 2 weeks

Compliance & Governance

Practical documentation and readiness work for businesses navigating GDPR, Cyber Essentials, or procurement requirements.

📋

GDPR Readiness Assessment

Practical gap analysis for small teams — identifies what you need to document, what you can defer, and what would cause a regulator the most concern if they knocked on your door today.

  • Data asset inventory and mapping (what you hold, why, where, for how long)
  • Lawful basis review for each data processing activity
  • Privacy notice and cookie banner audit
  • Subject access request and breach notification process review
  • Data Protection Impact Assessment (DPIA) for high-risk activities
  • Policy templates: retention, acceptable use, breach response

Assessment report in 5 business days

🛡️

Cyber Essentials Preparation

Technical and documentation readiness checks aligned to the UK Cyber Essentials scheme — valuable for public sector contracts, grant bids, and supply-chain procurement requirements.

  • Gap analysis against all five Cyber Essentials control categories
  • Boundary firewalls and internet gateways review
  • Secure configuration audit
  • Access control and administrative privilege review
  • Patch management and malware protection assessment
  • Completed self-assessment questionnaire support

Readiness report within 7 business days; CE+ assessment by arrangement

📝

Security Policy & Incident Response Planning

Practical security policies and IR playbooks sized for a small team — not enterprise boilerplate, but documents your staff will actually be able to follow under pressure.

  • Tailored information security policy (not generic templates)
  • Incident response runbook: roles, escalation, communication
  • Tabletop exercise: walk through a realistic attack scenario with your team
  • Ransomware response checklist
  • Supplier and third-party risk review process
  • Annual review built into contract

Initial policy drafts in 5 business days; tabletop by arrangement

Incident Response & Remediation

Support when something has gone wrong, and concrete code fixes when you want findings turned into pull requests.

🚨

Incident Response Retainer

A defined response window and pre-agreed scope so that if something goes wrong, you're not cold-calling a stranger while the clock is ticking.

  • Named contact with guaranteed response SLA (8 business hours for retainer customers)
  • Initial triage call within the SLA window
  • Containment advice and decision support
  • Evidence preservation guidance (chain of custody, log collection)
  • Communication support: what to say to customers, regulators, and staff
  • Post-incident report and lessons-learned session

Annual or quarterly retainer; by arrangement

🔧

Remediation Pull Requests

Findings from a scan or pentest become concrete GitHub PRs — actual code changes your team can review and merge, not just a list of recommendations.

  • Scan or pentest findings translated into actionable code changes
  • PRs opened against your repository with explanation comments
  • Security headers added directly to your config files
  • Outdated dependencies updated with test results
  • Your team retains full review and merge control
  • Available as a follow-on to any Hebrides Cyber assessment

PRs opened within 3 business days of assessment delivery

Hebrides Verticals

Sector-specific packages for businesses across the Highlands and Islands where generic advice often doesn't fit.

🏨

Tourism & Hospitality

Security for booking systems, point-of-sale, guest Wi-Fi, and GDPR handling across businesses built around seasonal demand and high staff turnover.

  • Booking system and payment page security review
  • Guest Wi-Fi segmentation from business network
  • POS device and card payment security audit
  • Seasonal staff access management (joiners and leavers)
  • GDPR: guest data retention and marketing consent

Churches & Charities

Cost-conscious security support for organisations that hold sensitive pastoral and financial data but rarely have a dedicated IT function.

  • Donation platform and giving page security review
  • Charity Commission / OSCR data responsibility audit
  • Volunteer and staff account management (MFA, shared credentials)
  • Content archive access control (sermons, safeguarding records)
  • Budget-conscious recommendations with free-tool alternatives where possible
🌾

Crofters & Small Agri-Tech

IoT device hardening and data security for small agricultural tech operations using remote sensors, telemetry, or grant-funded digital tools.

  • IoT device inventory and firmware version audit
  • Remote access (SSH, VPN, web interfaces) security check
  • Agricultural data platform review (who can access sensor data)
  • Grant compliance: data handling requirements for AgriTech funding
📷

Photography & Creative Businesses

Security for client galleries, watermarking workflows, and checkout pages — protecting both creative assets and customer payment data.

  • Client gallery access control and link expiry review
  • Checkout and payment security for print/product sales
  • Cloud storage (Dropbox, Google Drive, OneDrive) sharing audit
  • Copyright and watermark workflow security
  • Backup and disaster recovery for image archives

// ready?

Not sure where to start?

Book a free Security Score scan — get a one-page report in 24 hours, no commitment. Or just get in touch and we'll recommend the right starting point.