Services · Security audit
A straight answer on how exposed your website is, and what to fix first.
A one-day website security audit covering the site, the server under it, its logs and everything in front of it. Two reports: one in plain English for the owner, one with every finding and fix for your IT team.
Who this is for
Businesses whose website does real work. It takes bookings or payments, holds customer records, or is the first thing a prospect checks before they ring. Nobody has looked at the whole thing, code to server to the traffic arriving at the door, for a long time, and you suspect nobody would tell you if something was wrong.
If your website is a brochure nobody would miss for a week, you probably do not need a day of our time, and we will say so.
If your site is down, defaced or sending spam right now, you need incident response, not an audit. Ring 1300 856 393.
What we examine
Four things, because a website is never just a website.
- The website. Versions, plugins and themes, how updates are handled, who holds the keys, what is installed but unused, and the signs that someone has already been in.
- The server. The platform it runs on, who actually owns the account, how it has been kept, and whether it can be reached by going around whatever sits in front of it.
- The logs. Who has been trying the doors, from where, and for how long. Where logs are missing or too short to be useful, that is a finding in itself.
- The edge. The layer between the open internet and your server, what it lets through, and whether your real server address is sitting in public records.
What you receive
- A report for the owner. Your security position in plain language, with a red, amber or green rating and the reasoning behind it. Written so you can hand it to your board or your insurer.
- A report for your IT team. Every finding in priority order, with the evidence and full remediation steps, for whoever does the fixing: your team, your developer, or us.
- An hour with the auditor. We walk you through it, in person in Brisbane or by video, including how to explain the findings to other people.
- Confidential, start to finish. Both reports are yours. We do not share them, and we do not talk about who we work for.
Why a whole day
A scan tells you what a scanner can see. The logs tell you what happened.
Most website security checks look at the website. That is not nothing. But the server, the logs and the edge hold the record of what has actually been going on, and that is where you learn whether the door is merely ajar or someone has already been through it.
Reading that record properly takes a day. It is also the difference between a list of warnings and an answer.
How it works
What it costs
One day, from$1,000inc GST
One website on one server.
Larger or multi-site environments may need more than one day. You will know that before we start, not after.
Private for a reason
What we find stays between us and you. We do not name clients, we do not publish findings, and we do not describe how we work. That is not modesty. A security firm that talks about its clients is a security finding.
If you have never had a security audit or a penetration test, that is normal. Our onboarding walks you through it before anything starts, so nothing on the day is a surprise.
Who does the work
Our nerds are experienced. Fine, old. Some of us remember when a toy whistle from a box of Cap’n Crunch could blow 2600 hertz down a phone line, and when 2600 arrived on paper. We have been watching how people get in ever since.
Luke Elin, who leads Ey3, has spent thirty-five years in databases, web development and cyber security, and works as a red teamer: he is paid to find the way in before someone else does. Most of the ways a site gets compromised are not new. They are the same mistakes, made on newer software, by people who were never told. The reports exist so that you are told, plainly.
Where it fits
Patching applications and operating systems, restricting administrative privileges, multi-factor authentication and regular backups are all part of the Australian Signals Directorate’s Essential Eight. This audit tells you where your website and its server actually stand on them, rather than where you assume you stand.
An audit is accurate on the day it is written. Treating security as a project with a completion date is one of the patterns in The Same Seven Mistakes, which is why an audit pairs naturally with monthly maintenance or managed hosting: they keep the answer true.
Common questions
We already run a security plugin. Is that not enough?
We have never had an audit. Where do we start?
Is this the same as Privacy Act compliance?
Will you fix what you find?
Who sees the reports?
Next step
Find out where you stand, before someone else does.
Ring and tell us what the site does. If you do not need an audit, we will tell you that too, and you will have spent ten minutes finding out.