Web application assessment
Scoped to your site and admin panel: input validation, session management, authorisation, security headers and cookie configuration. The natural starting point for teams running e-commerce, membership or customer portals.
Let us act before you are attacked, not after. Your web application, servers and architecture are reviewed under controlled conditions, and every finding arrives with a remediation step. The work is carried out only under written authorisation.
Scope can be narrowed to fit the project. Exactly which headings are included is written out, one by one, in the quote.
XSS, SQL injection, CSRF, authorisation bypass and session management are covered under the OWASP Top 10 framework. Each area appears as its own finding in the report.
Login flow, password policy, session lifetime, multi-factor options and role-based access control are examined. We test whether one user can reach another user’s data.
We assess which layer gives way first under traffic pressure, and produce concrete recommendations for edge protection, rate limiting and caching strategy.
Open ports, unnecessary running services, user and password policy, sudo privileges and missing patches are reviewed. Every item that should be closed is listed with its rationale.
Certificate chain, validity window, supported protocol versions and cipher suites are checked, along with whether renewal automation actually works.
The libraries, packages and images you rely on are checked against known vulnerability records. The version you need to move to is written out item by item.
CSP, HSTS, X-Content-Type-Options, Referrer-Policy and cookie flags (Secure, HttpOnly, SameSite) are reviewed. Missing headers are delivered as ready-to-apply configuration.
Are backups actually running, and do they actually restore — two separate questions. Whether backups are kept off-host and encrypted is part of the scope.
Network segmentation, least privilege, secret management and trust relationships between services are assessed, including how far the impact would spread if one server were compromised.
If an incident happens, is there a record to look back at? We assess whether log collection, retention and alerting rules are enough to catch a real event.
Systems processing personal data are reviewed for appropriate technical measures; gaps are reported mapped to the relevant regulatory headings.
The report is delivered as a prioritised roadmap. Once remediation is applied, the same findings are tested again.
Before any testing begins, the assets in scope, the methods to be used and the working window are agreed and signed in writing.
Terms of engagement: testing is carried out only under written authorisation and a scope agreement. Nothing outside the agreed scope is touched. Anything that could affect production runs in a pre-agreed maintenance window, and potentially destructive steps are never executed without written approval. If gaps appear on the backup and recovery side, they are planned together with the S3 storage and backup scope.
Four questions about where you stand. If the risk looks low, we will say so without dramatising it.
What we hand over is not a scan dump. A few hundred lines produced by a tool tells nobody what to do next. Every finding is written through this five-step flow.
Every finding is labelled critical, high, medium or low. What gets fixed first is never up for debate.
What happens if this weakness is abused, written in business language: which data, which user, which consequence.
A concrete, actionable instruction: which setting, which version, which rule. Not generic advice — written for your system.
How to check that the fix actually worked. Your own team can verify it without us.
Once remediation is applied, the same findings are tested again and closed items are marked off in the report.
The report opens with an executive summary for non-technical decision makers: how urgent each risk is and in what order it should be handled. A cyber security specialist is part of the assessment team, and the report is delivered with a walkthrough — questions get answered live.
Each step has a defined output. You never have to ask where the work stands.
Which assets will be tested, which methods will be used and the working window are all agreed in writing. No testing starts before it is signed.
In-scope domains, servers, services and dependencies are mapped. The inventory is handed to you too — most businesses see their own attack surface here for the first time.
Application, server and configuration testing runs inside the agreed scope. Anything that could affect production moves to the pre-agreed maintenance window.
Findings are ordered by severity; each one is written with a scenario, a remediation step and a verification method. The report is delivered with a walkthrough.
After fixes are applied, the same findings are tested again. Closed items are marked off and a second round is planned for anything still open.
Starting narrow and expanding based on findings is a common choice. Price follows scope, and the quote is a single page. The service runs on a 12-month agreement: the assessment, the post-remediation retest and the follow-up through the year all sit inside the same contract, and the agreed fee does not change during it.
Web application assessment
Scoped to your site and admin panel: input validation, session management, authorisation, security headers and cookie configuration. The natural starting point for teams running e-commerce, membership or customer portals.
Server and infrastructure assessment
Operating system hardening, open port and service inventory, patch status, TLS configuration, backup and recovery resilience. For businesses running their own servers.
Enterprise architecture review
When multiple systems, environments and teams are involved: network segmentation, least privilege, secret management and inter-service trust are assessed as a whole.
An assessment is a snapshot in time; the agreement is annual. At year end, scope and price are reviewed together and signed again — next year's scope is set by this year's findings. If you need patch tracking, monitoring and alert handling in between, it is combined with the outsourced IT support package.
Testing is carried out only under written authorisation and a scope agreement. The agreement states which assets are in scope, which methods will be used and the working window. Nothing outside that scope is touched; if the system is not yours, or there is no authority able to sign the authorisation, the work does not begin.
Anything that could affect production runs in a pre-agreed maintenance window. Potentially destructive steps are never executed without written approval. Most of the review-oriented work completes without any service interruption.
OWASP Top 10 headings form the basis on the web application side. For server and architecture review we work to least privilege, defence in depth and the current hardening guidance published by the vendors. Findings are reported with reference to those frameworks.
The report is not a long scan dump. Every finding is written with four parts: severity rating, exploitation scenario, a concrete remediation step and a verification method. An executive summary is included separately so non-technical decision makers can read the risk.
If you want us to. The report is written clearly enough for your own team to act on it; implementation support is added to the quote as a separate line item. Either way, the post-remediation retest is inside the scope.
At least once a year, and additionally after major releases, infrastructure changes and whenever a new third-party integration goes live. If you need continuous monitoring in between, it can be combined with the outsourced IT support package.
Yes. Scope can be narrowed to web application, server and infrastructure, or enterprise architecture. Starting with a narrow scope and expanding based on findings is a common choice.
Both KVKK and GDPR require appropriate technical and organisational measures for systems processing personal data. A regular security assessment is one of the most concrete ways to evidence that the obligation is being met.
Fill in the form and we will get back to you within 1 business day on the channel you choose. Your details are used only for this conversation.
Most businesses first discuss security after a breach. By then the cost is no longer technical: data loss, downtime, regulatory notification and reputational damage arrive together. A security assessment reverses that order.
Your web application is tested for XSS, SQL injection, CSRF and authorisation bypass; your servers are reviewed for open ports, unnecessary services, weak account policy and missing patches. DDoS resilience and known vulnerabilities in your dependencies are assessed separately.
Each finding is written with a severity rating, a realistic exploitation scenario, a concrete remediation step and a verification method. Once fixes are applied, a retest follows.
Testing is carried out only under written authorisation and an agreed scope. Nothing outside scope is touched, and anything that could affect production runs in a pre-agreed window.