Security & IntelligenceCybersecurity
Cybersecurity for your websites and servers, hardened and watched
For companies in the US and Italy that run websites, servers and business apps. We set up firewalls and DDoS protection, harden your systems, scan for vulnerabilities on a schedule and help you respond when something goes wrong. Clear reports, in English or Italian.
- Scans on a schedule
- findings ranked, each with a fix
- Clear firewall rules
- reviewed and documented
- Help when it happens
- contain, recover, learn
Traffic and threats this weekWebsite, firewall and weekly scan
Thursday: a traffic flood, filtered at the edge
- INFOScan started, 3 hosts
- OKweb-01: all clear
- WARNapp-01: TLS 1.0 on
- OKFix booked: Sat 22:00
Example · not a real system
01When to call us
Signs your security needs a closer look
Most problems are not exotic. They are default settings, old software and firewall rules nobody remembers writing.
The site slows down or goes offline
A flood of traffic, aggressive bots or a server at its limit. You need to know which one, and stop it.
Firewall rules nobody understands
Years of exceptions, ports opened “just for a test” and no documentation.
Old software on public servers
Unpatched operating systems, CMS and plugins are the most common way in.
Too many people with admin access
Shared passwords, former staff still active and admin panels open to the internet.
02What we do
Fewer ways in, faster answers when it matters
We start with what your company exposes to the internet, then work inward. Every change is written down, tested where possible and applied in a window you approve.
- DDoS protection and traffic filtering
- Firewall setup and rule review
- Scheduled vulnerability scans
- Server and website hardening
- Access control and 2FA for admins
- Monitoring with useful alerts
- Help with incident response
- Reports in plain language
Every finding, with a fix and a dateSecurity review · web-01, app-01
- Admin panel exposed onlineapp-01 · move behind VPN Now
- TLS 1.0 still enabledapp-01 · disable old protocols This week
- SSH allows passwordsweb-01 · keys only This week
- Security headers missingwebsite · add CSP and HSTS Planned
- Firewall rules documentededge · 14 rules, all justified Done
03What is included
The work, item by item
Pick what you need. Many companies start with a review and the fixes that come out of it, then keep scans and monitoring running.
DDoS protection
Keep your website and services reachable when traffic spikes or someone floods them.
- Filtering and rate limits at the edge
- CDN and caching set up properly
- A plan for what to do during an attack
Firewall configuration
Rules that allow what your business needs and block the rest.
- Review of existing rules and open ports
- Separate zones for office, servers and guests
- Documentation you can actually read
Vulnerability scans
Regular checks of your servers, websites and exposed services.
- Scans on a schedule you choose
- Findings ranked by real risk
- A re-check after every fix
Hardening
Secure settings for servers, websites and applications.
- Operating system and web server settings
- Patch plan for OS, CMS and plugins
- Security headers and modern TLS
Access control
The right people with the right access, and nobody else.
- Admin accounts reviewed and cleaned up
- Two-factor authentication for admins
- SSH keys, VPN and remote access
Incident response
Hands-on help when something has already gone wrong.
- Contain the problem and keep the logs
- Restore from clean backups
- A short report on causes and fixes
04How we work
From the first scan to systems that stay healthy
Clear steps, agreed in writing. You always know what we are checking, what we change and why.
-
Look from the outside
We map what anyone can see from the internet: domains, servers, open ports and login pages.
With your written OK -
Review the inside
With your team, we check configurations, accounts, patches and backups.
Read-only first -
Fix in order
The riskiest items first, in agreed windows, with a way back for every change.
Windows you approve -
Keep watch
Scans on a schedule, alerts that mean something and a short report after each round.
Reports in EN or IT
05Questions
Questions we hear before we start
Something else on your mind? Write to us. A real person reads every message and replies by email.
Only with your authorization. We scan and test systems that belong to you, or that you are allowed to have tested, after you approve the scope in writing.
Do you work with our existing IT team or provider?
Yes. We often work alongside an internal team or an outside provider. We share what we find, agree who fixes what and stay out of the way of daily operations.
Will a vulnerability scan slow down or break our systems?
Scans are planned with you, run in agreed time windows and tuned to be gentle on production. Anything more intrusive is discussed first and done only with your written approval.
Can you help if we are under attack right now?
Write to us with “urgent” in the subject. We will tell you honestly whether we can step in right away, and what you can do in the meantime, such as isolating the affected systems and keeping the logs.
Do you only protect websites?
No. We work on websites, servers, firewalls, remote access and the cloud services around them. Databases and the wider infrastructure are handled by the same team.
What do we get at the end?
A plain-language report: what we found, what we fixed, what is left and in what order to tackle it. Technical details go in an appendix for your IT team.
Want to know what an attacker would see first?
Tell us which websites and servers matter most. We reply by email with a proposal for a first review, in English or Italian.