Cyber Security
Complete protection for your IT infrastructure. Audits, penetration testing, hardening and incident response to keep the business safe.
Security across the whole estate
Security is not a product but a continuous process. I find the vulnerabilities, put the defences in place and train your people, building a security culture that protects the business from real threats.
From infrastructure analysis to continuous monitoring, I offer complete cyber security services for companies of every size, aligned with GDPR and international best practice.
Proactive Protection
Vulnerabilities closed before attackers find them
Vulnerability Assessment
Identifying the weak points in your systems
GDPR Compliance
Regulatory compliance assured
Incident Response
Fast response when an attack lands
Why choose me for cyber security
What makes my approach to protecting your IT infrastructure different.
Experience of Real Attacks
I've run incident response for companies under ransomware attack, through data breaches and system compromises. I know attackers' tactics because I've seen them at work. That field experience means the defences I put in place work in practice, not just on paper.
A Business-Led Approach
Security shouldn't get in the way of the business. I find the balance between protection and usability, with controls proportionate to the real risk. No needless paranoia, just measures that protect without making life difficult for your staff.
Compliance Built In
Every piece of security work is designed to satisfy GDPR, ISO 27001 and sector regulations, with full documentation for audits and certification. One supplier for both technical security and compliance: fewer vendors, lower cost, greater consistency.
Cyber security services
Complete protection for your IT infrastructure and your company data.
Security Audits
A full analysis of your IT infrastructure to identify vulnerabilities and security risks.
Penetration Testing
Controlled intrusion testing to gauge how your systems hold up against real attacks.
Server Hardening
Tightening server configuration to reduce the attack surface and close vulnerabilities.
Incident Response
Rapid response and incident handling, with forensic analysis and remediation.
Security Training
Staff training on phishing, social engineering and security best practice.
GDPR Compliance
Bringing you into line with privacy law and personal data protection under the GDPR.
Every Cyber Security Service
A detailed guide to working out which security service suits your company.
Vulnerability Assessment
Find the vulnerabilities before attackers do
A vulnerability assessment is a systematic scan of your IT infrastructure to identify known weaknesses in systems, applications and configuration. Unlike a penetration test it doesn't try to exploit them, but catalogues them by risk priority.
What the service includes:
- Automated scanning with enterprise tools (Nessus, OpenVAS)
- Analysis of server and network device configuration
- Checks for missing patches and obsolete software
- Assessment of credentials and password policy
- A report with vulnerabilities ranked by CVSS score
- A prioritised remediation plan
Ideal for:
- Smaller companies wanting a first security review
- Companies with compliance requirements
- Regular assessments (quarterly is recommended)
- Pre-audit work for ISO 27001 certification
Indicative price:
From 800 euro (small business) to 3,000 euro+ (enterprise)
Penetration Testing
A controlled simulation of a real attack
Penetration testing (or ethical hacking) simulates a real attack to test your defences. Unlike a vulnerability assessment, the tester actively tries to exploit weaknesses to show the concrete impact of a breach.
What the service includes:
- Reconnaissance and information gathering (OSINT)
- Scanning and service enumeration
- Manual exploitation of the vulnerabilities found
- Privilege escalation and lateral movement
- An executive report with evidence of each attack
- A debriefing session with your IT team
Ideal for:
- Companies holding sensitive or critical data
- PCI-DSS, ISO 27001 or GDPR requirements
- Pre-launch testing of new applications
- Verifying that existing defences actually work
Indicative price:
From 2,500 euro (web app) to 10,000 euro+ (full infrastructure)
Web Application Security
Protecting websites and online applications
Web application security covers protecting sites, online shops, portals and APIs from attacks such as SQL injection, XSS, CSRF and the rest of the OWASP Top 10. It includes both testing and hardening.
What the service includes:
- OWASP Top 10 testing (injection, XSS, CSRF and so on)
- Analysis of authentication and session handling
- REST/GraphQL API vulnerability testing
- SSL/TLS configuration and security header checks
- Security code review (optional)
- WAF (web application firewall) configuration
Ideal for:
- Online shops and sites taking payments
- Portals holding sensitive user data
- SaaS applications
- Public or B2B APIs
Indicative price:
From 1,500 euro (basic site) to 5,000 euro+ (complex web app)
Network Security
Protecting your network infrastructure
Network security protects your infrastructure from unauthorised access, attack and data leakage. It covers secure firewall configuration, network segmentation, VPNs and traffic monitoring to spot anomalies.
What the service includes:
- Firewall and ACL configuration audit
- Network segmentation (VLAN, DMZ)
- Site-to-site and remote access VPN configuration
- IDS/IPS implementation
- Network monitoring and alerting
- Wireless security assessment
Ideal for:
- Companies with on-premise networks
- Offices with staff working remotely
- Multi-site organisations with site-to-site links
- Environments with IoT and OT devices
Indicative price:
From 1,200 euro (audit) to 5,000 euro+ (implementation)
Cloud Security
Security for AWS, Azure and Google Cloud
Cloud security protects resources hosted on public cloud platforms. The shared responsibility model demands specific expertise to configure IAM, encryption, networking and compliance correctly.
What the service includes:
- Cloud Security Posture Management (CSPM)
- IAM and access policy audit
- Encryption at rest and in transit
- Network security groups and VPC configuration
- Logging, monitoring and SIEM integration
- Compliance checks (CIS Benchmarks, SOC 2)
Ideal for:
- Companies running on AWS, Azure or GCP
- Cloud-native startups
- Migrations from on-premise to cloud
- Multi-cloud environments
Indicative price:
From 2,000 euro (audit) to 8,000 euro+ (implementation)
Incident Response
Rapid response to an attack in progress
Incident response is the emergency service for attacks already under way: ransomware, data breaches, compromised systems. It covers immediate containment, forensic analysis, eradication of the threat and a safe restore.
What the service includes:
- Initial triage and containment (within 4 hours)
- Forensic analysis to identify the attack vector
- Eradication of malware and backdoors
- Recovery and a secure system restore
- A forensic report for insurers and the authorities
- Lessons learned and post-incident hardening
Ideal for:
- Companies under ransomware attack
- A suspected data breach or compromise
- Ransom demands already received
- Anomalous behaviour in your systems
Indicative price:
From 3,000 euro (minor incident) to 15,000 euro+ (ransomware)
Security Hardening
Locking down servers and systems
Security hardening reduces the attack surface by configuring servers, operating systems and applications to security best practice: removing unnecessary services, tightening permissions and adding security controls.
What the service includes:
- OS hardening (Windows Server, Linux)
- Secure service configuration (Apache, Nginx, MySQL)
- CIS Benchmarks implementation
- Patch management and automatic updates
- Logging and audit trail configuration
- Secure backup and disaster recovery
Ideal for:
- Internet-facing servers
- New server builds
- Post-incident work to prevent a repeat
- Compliance requirements
Indicative price:
From 500 euro/server (basic) to 1,500 euro/server (enterprise)
Ransomware Protection
Defence against digital extortion
Ransomware is the number one threat to business. This service puts defence in depth in place: prevention (email security, endpoint protection), detection (EDR, monitoring) and recovery (immutable backups, disaster recovery).
What the service includes:
- Assessment of your current ransomware exposure
- Email security with advanced anti-phishing
- Endpoint Detection and Response (EDR)
- Immutable backups (the 3-2-1 rule)
- Network segmentation to limit spread
- A recovery plan, tested regularly
Ideal for:
- Every company (ransomware doesn't discriminate)
- Critical sectors (healthcare, manufacturing)
- Companies hit before
- Anyone who cannot afford downtime
Indicative price:
From 2,500 euro (small business) to 10,000 euro+ (enterprise)
Security Awareness Training
Train your people against the threats
Ninety per cent of attacks start with human error: a click on a malicious link, an infected attachment, a shared password. Security awareness training turns staff from the weakest link into the first line of defence, through practical training and simulations.
What the service includes:
- An initial assessment of awareness levels
- Training on phishing, social engineering and passwords
- Regular phishing simulations
- Security policies that are clear and workable
- Tailored training materials
- Progress reports and metrics
Ideal for:
- Companies with a large headcount
- Sectors handling sensitive data
- GDPR requirements (training is mandatory)
- After an incident caused by human error
Indicative price:
From 50 euro per employee per year (platform) plus training
GDPR and Compliance
Regulatory compliance and data protection
GDPR compliance is not only a legal obligation but a security best practice. This service covers the whole exercise: from mapping your processing activities to the technical measures, from documentation to staff training.
What the service includes:
- GDPR audit and gap analysis
- Record of processing activities
- DPIA (Data Protection Impact Assessment)
- Privacy policy and cookie policy
- Technical measures (encryption, pseudonymisation)
- DPO support and data breach handling
Ideal for:
- Companies processing personal data
- Online shops and sites with contact forms
- Companies with EU customers
- Regulated sectors (healthcare, finance)
Indicative price:
From 1,500 euro (small business) to 8,000 euro+ (enterprise)
Which Security Service Should You Choose?
A summary table to help you pick the right service for your company.
| Service | Main objective | Price from | Priority | Ideal for |
|---|---|---|---|---|
| Vulnerability Assessment | Finding vulnerabilities | 800 euro | High | Small business, compliance, regular reviews |
| Penetration Testing | Testing the defences | 2,500 euro | Critical | Sensitive data, PCI-DSS, ISO 27001 |
| Web App Security | Protecting sites and APIs | 1,500 euro | Critical | E-commerce, SaaS, portals |
| Network Security | Protecting the network | 1,200 euro | High | Offices, multi-site, IoT |
| Cloud Security | Protecting the cloud | 2,000 euro | High | AWS, Azure, GCP |
| Incident Response | Handling attacks | 3,000 euro | Critical | Emergencies, ransomware, breaches |
| Security Hardening | Locking systems down | 500 euro/server | Medium | Exposed servers, new builds |
| Ransomware Protection | Preventing extortion | 2,500 euro | Critical | Everyone (a universal threat) |
| Security Awareness | Training staff | 50 euro/user | High | Any company with employees |
| GDPR Compliance | Regulatory compliance | 1,500 euro | Mandatory | Anyone processing personal data |
The security assessment process
A methodical approach to finding and reducing security risk.
Reconnaissance
Gathering information on the infrastructure and mapping the assets to protect.
Scanning
Vulnerability scanning, configuration analysis and identification of weak points.
Testing
Verifying the findings with controlled, documented penetration tests.
Remediation
A detailed report and implementation of the countermeasures.
Tools and methodologies
The best technologies and frameworks for professional security assessment.
What people say
What people who chose to work with me have to say.
Is your company really protected?
Request a free security assessment. Within 48 hours you'll get a report covering your critical vulnerabilities, your ransomware exposure, any GDPR compliance gaps and a prioritised set of recommendations.
Request a Security AssessmentFree for companies with at least 5 employees. Emergency in progress? Contact me straight away.