find the ways in, then keep the lights on
penetration testing and hardening, plus the day-to-day IT that never reaches the top of anyone's list: hosting, backups, monitoring, accounts, and access.
penetration testing
we go at your site or app the way an attacker would, on a scope you sign off in writing first. then we show you every way in, ranked by what each one would cost you.
- web application & api testing
- authentication, sessions, and access control
- injection, deserialisation, file handling
- business-logic abuse, the kind scanners never find
- cloud and hosting misconfiguration
- exposed secrets, backups, and admin surfaces
- dependency and supply-chain review
- a free retest once you've fixed things
what the report looks like
two documents: one your board can read, one your developers can act on. neither is a 200-page scanner dump.
the summary
one page. what we found, what it would cost you if someone else found it first, and what to do this week versus this quarter. written for people who don't work in security.
the detail
every finding with the exact steps to reproduce it, the evidence, the severity and why, and a specific fix. nothing in it says "consider implementing input validation".
illustrative sample output, not a real client report
and the day-to-day IT
the work you only notice when it's missing. we own it so your team doesn't have to learn it on a bad afternoon.
- hosting and cloud setup, moves, and cost trimming
- backups we test by restoring them
- uptime monitoring and alerts that reach a human
- domains, dns, tls, and email deliverability (spf, dkim, dmarc)
- google workspace / microsoft 365 accounts and mfa
- joiner and leaver process, so access is granted and revoked on time
- laptop, device, and password-manager setup
- security policies and questionnaire answers for client audits
when something has already gone wrong
site defaced, mailbox compromised, ransomware note, a customer telling you their data is somewhere it shouldn't be. call first, then read this.
contain
cut the access being used, rotate credentials and keys, and preserve the logs before anything overwrites them.
understand
how they got in, what they reached, how long they were there, and whether they're still there.
close and record
fix the way in, restore cleanly, and write the timeline you'll need for customers, insurers, or a regulator.
mid-incident right now? email hello@rebootworks.dev with "incident" in the subject.