Cyber Security

Complete protection for your IT infrastructure. Audits, penetration testing, hardening and incident response to keep the business safe.

Security across the whole estate

Security is not a product but a continuous process. I find the vulnerabilities, put the defences in place and train your people, building a security culture that protects the business from real threats.

From infrastructure analysis to continuous monitoring, I offer complete cyber security services for companies of every size, aligned with GDPR and international best practice.

Proactive Protection

Vulnerabilities closed before attackers find them

Vulnerability Assessment

Identifying the weak points in your systems

GDPR Compliance

Regulatory compliance assured

Incident Response

Fast response when an attack lands

Why choose me for cyber security

What makes my approach to protecting your IT infrastructure different.

Experience of Real Attacks

I've run incident response for companies under ransomware attack, through data breaches and system compromises. I know attackers' tactics because I've seen them at work. That field experience means the defences I put in place work in practice, not just on paper.

A Business-Led Approach

Security shouldn't get in the way of the business. I find the balance between protection and usability, with controls proportionate to the real risk. No needless paranoia, just measures that protect without making life difficult for your staff.

Compliance Built In

Every piece of security work is designed to satisfy GDPR, ISO 27001 and sector regulations, with full documentation for audits and certification. One supplier for both technical security and compliance: fewer vendors, lower cost, greater consistency.

Cyber security services

Complete protection for your IT infrastructure and your company data.

Security Audits

A full analysis of your IT infrastructure to identify vulnerabilities and security risks.

Penetration Testing

Controlled intrusion testing to gauge how your systems hold up against real attacks.

Server Hardening

Tightening server configuration to reduce the attack surface and close vulnerabilities.

Incident Response

Rapid response and incident handling, with forensic analysis and remediation.

Security Training

Staff training on phishing, social engineering and security best practice.

GDPR Compliance

Bringing you into line with privacy law and personal data protection under the GDPR.

Every Cyber Security Service

A detailed guide to working out which security service suits your company.

Vulnerability Assessment

Find the vulnerabilities before attackers do

A vulnerability assessment is a systematic scan of your IT infrastructure to identify known weaknesses in systems, applications and configuration. Unlike a penetration test it doesn't try to exploit them, but catalogues them by risk priority.

What the service includes:

  • Automated scanning with enterprise tools (Nessus, OpenVAS)
  • Analysis of server and network device configuration
  • Checks for missing patches and obsolete software
  • Assessment of credentials and password policy
  • A report with vulnerabilities ranked by CVSS score
  • A prioritised remediation plan

Ideal for:

  • Smaller companies wanting a first security review
  • Companies with compliance requirements
  • Regular assessments (quarterly is recommended)
  • Pre-audit work for ISO 27001 certification

Indicative price:

From 800 euro (small business) to 3,000 euro+ (enterprise)

Penetration Testing

A controlled simulation of a real attack

Penetration testing (or ethical hacking) simulates a real attack to test your defences. Unlike a vulnerability assessment, the tester actively tries to exploit weaknesses to show the concrete impact of a breach.

What the service includes:

  • Reconnaissance and information gathering (OSINT)
  • Scanning and service enumeration
  • Manual exploitation of the vulnerabilities found
  • Privilege escalation and lateral movement
  • An executive report with evidence of each attack
  • A debriefing session with your IT team

Ideal for:

  • Companies holding sensitive or critical data
  • PCI-DSS, ISO 27001 or GDPR requirements
  • Pre-launch testing of new applications
  • Verifying that existing defences actually work

Indicative price:

From 2,500 euro (web app) to 10,000 euro+ (full infrastructure)

Web Application Security

Protecting websites and online applications

Web application security covers protecting sites, online shops, portals and APIs from attacks such as SQL injection, XSS, CSRF and the rest of the OWASP Top 10. It includes both testing and hardening.

What the service includes:

  • OWASP Top 10 testing (injection, XSS, CSRF and so on)
  • Analysis of authentication and session handling
  • REST/GraphQL API vulnerability testing
  • SSL/TLS configuration and security header checks
  • Security code review (optional)
  • WAF (web application firewall) configuration

Ideal for:

  • Online shops and sites taking payments
  • Portals holding sensitive user data
  • SaaS applications
  • Public or B2B APIs

Indicative price:

From 1,500 euro (basic site) to 5,000 euro+ (complex web app)

Network Security

Protecting your network infrastructure

Network security protects your infrastructure from unauthorised access, attack and data leakage. It covers secure firewall configuration, network segmentation, VPNs and traffic monitoring to spot anomalies.

What the service includes:

  • Firewall and ACL configuration audit
  • Network segmentation (VLAN, DMZ)
  • Site-to-site and remote access VPN configuration
  • IDS/IPS implementation
  • Network monitoring and alerting
  • Wireless security assessment

Ideal for:

  • Companies with on-premise networks
  • Offices with staff working remotely
  • Multi-site organisations with site-to-site links
  • Environments with IoT and OT devices

Indicative price:

From 1,200 euro (audit) to 5,000 euro+ (implementation)

Cloud Security

Security for AWS, Azure and Google Cloud

Cloud security protects resources hosted on public cloud platforms. The shared responsibility model demands specific expertise to configure IAM, encryption, networking and compliance correctly.

What the service includes:

  • Cloud Security Posture Management (CSPM)
  • IAM and access policy audit
  • Encryption at rest and in transit
  • Network security groups and VPC configuration
  • Logging, monitoring and SIEM integration
  • Compliance checks (CIS Benchmarks, SOC 2)

Ideal for:

  • Companies running on AWS, Azure or GCP
  • Cloud-native startups
  • Migrations from on-premise to cloud
  • Multi-cloud environments

Indicative price:

From 2,000 euro (audit) to 8,000 euro+ (implementation)

Incident Response

Rapid response to an attack in progress

Incident response is the emergency service for attacks already under way: ransomware, data breaches, compromised systems. It covers immediate containment, forensic analysis, eradication of the threat and a safe restore.

What the service includes:

  • Initial triage and containment (within 4 hours)
  • Forensic analysis to identify the attack vector
  • Eradication of malware and backdoors
  • Recovery and a secure system restore
  • A forensic report for insurers and the authorities
  • Lessons learned and post-incident hardening

Ideal for:

  • Companies under ransomware attack
  • A suspected data breach or compromise
  • Ransom demands already received
  • Anomalous behaviour in your systems

Indicative price:

From 3,000 euro (minor incident) to 15,000 euro+ (ransomware)

Emergency in progress? Contact me immediately. Every minute counts in limiting the damage. Available 24/7 for emergencies.

Security Hardening

Locking down servers and systems

Security hardening reduces the attack surface by configuring servers, operating systems and applications to security best practice: removing unnecessary services, tightening permissions and adding security controls.

What the service includes:

  • OS hardening (Windows Server, Linux)
  • Secure service configuration (Apache, Nginx, MySQL)
  • CIS Benchmarks implementation
  • Patch management and automatic updates
  • Logging and audit trail configuration
  • Secure backup and disaster recovery

Ideal for:

  • Internet-facing servers
  • New server builds
  • Post-incident work to prevent a repeat
  • Compliance requirements

Indicative price:

From 500 euro/server (basic) to 1,500 euro/server (enterprise)

Ransomware Protection

Defence against digital extortion

Ransomware is the number one threat to business. This service puts defence in depth in place: prevention (email security, endpoint protection), detection (EDR, monitoring) and recovery (immutable backups, disaster recovery).

What the service includes:

  • Assessment of your current ransomware exposure
  • Email security with advanced anti-phishing
  • Endpoint Detection and Response (EDR)
  • Immutable backups (the 3-2-1 rule)
  • Network segmentation to limit spread
  • A recovery plan, tested regularly

Ideal for:

  • Every company (ransomware doesn't discriminate)
  • Critical sectors (healthcare, manufacturing)
  • Companies hit before
  • Anyone who cannot afford downtime

Indicative price:

From 2,500 euro (small business) to 10,000 euro+ (enterprise)

Security Awareness Training

Train your people against the threats

Ninety per cent of attacks start with human error: a click on a malicious link, an infected attachment, a shared password. Security awareness training turns staff from the weakest link into the first line of defence, through practical training and simulations.

What the service includes:

  • An initial assessment of awareness levels
  • Training on phishing, social engineering and passwords
  • Regular phishing simulations
  • Security policies that are clear and workable
  • Tailored training materials
  • Progress reports and metrics

Ideal for:

  • Companies with a large headcount
  • Sectors handling sensitive data
  • GDPR requirements (training is mandatory)
  • After an incident caused by human error

Indicative price:

From 50 euro per employee per year (platform) plus training

GDPR and Compliance

Regulatory compliance and data protection

GDPR compliance is not only a legal obligation but a security best practice. This service covers the whole exercise: from mapping your processing activities to the technical measures, from documentation to staff training.

What the service includes:

  • GDPR audit and gap analysis
  • Record of processing activities
  • DPIA (Data Protection Impact Assessment)
  • Privacy policy and cookie policy
  • Technical measures (encryption, pseudonymisation)
  • DPO support and data breach handling

Ideal for:

  • Companies processing personal data
  • Online shops and sites with contact forms
  • Companies with EU customers
  • Regulated sectors (healthcare, finance)

Indicative price:

From 1,500 euro (small business) to 8,000 euro+ (enterprise)

Which Security Service Should You Choose?

A summary table to help you pick the right service for your company.

Service Main objective Price from Priority Ideal for
Vulnerability Assessment Finding vulnerabilities 800 euro High Small business, compliance, regular reviews
Penetration Testing Testing the defences 2,500 euro Critical Sensitive data, PCI-DSS, ISO 27001
Web App Security Protecting sites and APIs 1,500 euro Critical E-commerce, SaaS, portals
Network Security Protecting the network 1,200 euro High Offices, multi-site, IoT
Cloud Security Protecting the cloud 2,000 euro High AWS, Azure, GCP
Incident Response Handling attacks 3,000 euro Critical Emergencies, ransomware, breaches
Security Hardening Locking systems down 500 euro/server Medium Exposed servers, new builds
Ransomware Protection Preventing extortion 2,500 euro Critical Everyone (a universal threat)
Security Awareness Training staff 50 euro/user High Any company with employees
GDPR Compliance Regulatory compliance 1,500 euro Mandatory Anyone processing personal data

The security assessment process

A methodical approach to finding and reducing security risk.

1

Reconnaissance

Gathering information on the infrastructure and mapping the assets to protect.

2

Scanning

Vulnerability scanning, configuration analysis and identification of weak points.

3

Testing

Verifying the findings with controlled, documented penetration tests.

4

Remediation

A detailed report and implementation of the countermeasures.

Tools and methodologies

The best technologies and frameworks for professional security assessment.

Nmap
Burp Suite
Metasploit
Wireshark
OWASP
Nessus

What people say

What people who chose to work with me have to say.

Is your company really protected?

Request a free security assessment. Within 48 hours you'll get a report covering your critical vulnerabilities, your ransomware exposure, any GDPR compliance gaps and a prioritised set of recommendations.

Request a Security Assessment

Free for companies with at least 5 employees. Emergency in progress? Contact me straight away.