Services · Security audit

A straight answer on how exposed your website is, and what to fix first.

A one-day website security audit covering the site, the server under it, its logs and everything in front of it. Two reports: one in plain English for the owner, one with every finding and fix for your IT team.

Who this is for

Businesses whose website does real work. It takes bookings or payments, holds customer records, or is the first thing a prospect checks before they ring. Nobody has looked at the whole thing, code to server to the traffic arriving at the door, for a long time, and you suspect nobody would tell you if something was wrong.

If your website is a brochure nobody would miss for a week, you probably do not need a day of our time, and we will say so.

If your site is down, defaced or sending spam right now, you need incident response, not an audit. Ring 1300 856 393.

What we examine

Four things, because a website is never just a website.

  • The website. Versions, plugins and themes, how updates are handled, who holds the keys, what is installed but unused, and the signs that someone has already been in.
  • The server. The platform it runs on, who actually owns the account, how it has been kept, and whether it can be reached by going around whatever sits in front of it.
  • The logs. Who has been trying the doors, from where, and for how long. Where logs are missing or too short to be useful, that is a finding in itself.
  • The edge. The layer between the open internet and your server, what it lets through, and whether your real server address is sitting in public records.

What you receive

  • A report for the owner. Your security position in plain language, with a red, amber or green rating and the reasoning behind it. Written so you can hand it to your board or your insurer.
  • A report for your IT team. Every finding in priority order, with the evidence and full remediation steps, for whoever does the fixing: your team, your developer, or us.
  • An hour with the auditor. We walk you through it, in person in Brisbane or by video, including how to explain the findings to other people.
  • Confidential, start to finish. Both reports are yours. We do not share them, and we do not talk about who we work for.

Why a whole day

A scan tells you what a scanner can see. The logs tell you what happened.

Most website security checks look at the website. That is not nothing. But the server, the logs and the edge hold the record of what has actually been going on, and that is where you learn whether the door is merely ajar or someone has already been through it.

Reading that record properly takes a day. It is also the difference between a list of warnings and an answer.

How it works

Step one
Ring, or send the address
We ask what the site does and who looks after it. New to security audits or penetration testing? We start with onboarding: what happens, what we need from you, and what you will get.
Step two
Agree the day
We agree the date and the access we need. One website on one server is one day. Anything larger is quoted before we start.
The day
We do the work
If we find something being actively exploited, you hear about it that day, not when the reports land.
After
The reports and the hour
Then it is your call: fix it in-house, hand the technical report to your developer, or ask us to quote the work.

What it costs

One day, from$1,000inc GST

One website on one server.

Larger or multi-site environments may need more than one day. You will know that before we start, not after.

Private for a reason

What we find stays between us and you. We do not name clients, we do not publish findings, and we do not describe how we work. That is not modesty. A security firm that talks about its clients is a security finding.

If you have never had a security audit or a penetration test, that is normal. Our onboarding walks you through it before anything starts, so nothing on the day is a surprise.

Who does the work

Our nerds are experienced. Fine, old. Some of us remember when a toy whistle from a box of Cap’n Crunch could blow 2600 hertz down a phone line, and when 2600 arrived on paper. We have been watching how people get in ever since.

Luke Elin, who leads Ey3, has spent thirty-five years in databases, web development and cyber security, and works as a red teamer: he is paid to find the way in before someone else does. Most of the ways a site gets compromised are not new. They are the same mistakes, made on newer software, by people who were never told. The reports exist so that you are told, plainly.

Where it fits

Patching applications and operating systems, restricting administrative privileges, multi-factor authentication and regular backups are all part of the Australian Signals Directorate’s Essential Eight. This audit tells you where your website and its server actually stand on them, rather than where you assume you stand.

An audit is accurate on the day it is written. Treating security as a project with a completion date is one of the patterns in The Same Seven Mistakes, which is why an audit pairs naturally with monthly maintenance or managed hosting: they keep the answer true.

Common questions

We already run a security plugin. Is that not enough?
A plugin sees the website from inside the website. It cannot see the server, the traffic arriving at the edge, or what the logs say about who has been trying the doors. Whether it is enough depends on what is behind it, and the audit is how you find out.
We have never had an audit. Where do we start?
With onboarding. We explain what a security audit and a penetration test involve, agree the access we need and why, and nothing on your site or server changes without your say-so.
Is this the same as Privacy Act compliance?
No. The audit is a technical examination of the website and what sits around it. The Privacy Act’s transparency obligations for automated decision-making commence on 10 December 2026, and they are a governance question about how you use personal information in decisions. That work sits under AI consulting.
Will you fix what you find?
If you want us to, we quote the work. The technical report is written so your own IT team or developer can act on it without guessing, and the decision is yours.
Who sees the reports?
You do. Both are confidential to you. We do not contact anyone else about them, and what you share with your own clients, insurer or board is your call.

Next step

Find out where you stand, before someone else does.

Ring and tell us what the site does. If you do not need an audit, we will tell you that too, and you will have spent ten minutes finding out.

Call 1300 856 393Or send the site address