IT Solution.
Audit · Hardening · Backups · Incident

Most sites are not broken by an attack. They are broken by what nobody was watching.

Protection switched off, an update left undone, a backup nobody ever tried to restore. I go through your website, your application and your server, tell you exactly what to fix and in what order — and when it is already too late, I clean it up and find out how they got in.

A compromised site gets dealt with immediately. Call +420 530 330 757 or +420 774 509 038 — do not wait for an e-mail reply.

Four things I deal with.

Most companies need the first two. The third one calls by itself when the first two were skipped.

Security audit

I go through the code, the configuration and what is visible from outside: authentication and permissions, file uploads, APIs, nginx, PHP, TLS, database access, exposed configuration files and backups.

For AWS or Azure, add IAM and roles, MFA and key management, networking, logging and the audit trail.

Website and application from $360 · cloud depending on scope

What is in the output

Hardening and care

Ongoing: system and application updates, firewall, automatic blocking of attacking addresses, TLS, file permission checks, availability monitoring and an alert when something goes down.

It includes a regular report — what happened, what got blocked, what needs a decision from you.

From $32 a month

What gets watched

Incident recovery

A compromised site, spam going out from your domain, fake pages in search results, encrypted data. I cut the attacker off, find and remove the backdoors, restore the site from a clean backup and close the way they came in.

You also get the answer to the question that matters most in the end: whether any data left, and which.

Depending on scope · we start with a phone call, not a form

+420 530 330 757 +420 774 509 038

Backups and restores

Backups off the server and in more than one place, with version history — ransomware will encrypt any backup it can reach. Plus a watchdog that speaks up when a backup does not run.

And above all: a restore that has been tried. Until someone has restored it, you do not have a backup — you have files you believe in.

One-off setup, or part of ongoing care

An audit you get as a document. Not as a scanner dump.

An automated scan will happily list five hundred "findings", four hundred and ninety of which are false. This works differently.

How it runs

  • I read the code, the server configuration, the database schema and what the site actually answers to real requests from outside.
  • Every finding is verified by hand — against the code and against the live response. What fails verification does not go in the report.
  • The audit is non-destructive: nothing deleted, no password brute-forcing, no exploitation of what is found. Your operation never notices it.
  • After the fixes I go through what we fixed once more.

What is in the output

  • A summary for whoever decides — no jargon, one page.
  • Findings ordered by priority: what burns today, what within a month, what is cosmetic.
  • For each one: what it affects, what it risks, how to fix it. Specifically, not "consider adopting security measures".
  • Which of it falls under GDPR and what you would have to report if data leaked.
  • I can do the fixes myself, or you hand the report to your own supplier.

I deliberately do not call this a penetration test. A penetration test actively breaks into the system; that is a different discipline and a different price. This is an audit of code and configuration — on websites and business applications it finds more in practice, and it breaks nothing.

Two cases from practice.

No names — the clients are entitled to that. The numbers and the sequence are exactly as they happened.

A municipal site, two layers of attack

A content management system with a freshly published vulnerability in its core. The attacker got in before the update did and created an administrator account of their own.

Underneath, an older layer surfaced: a backdoor had been sitting on the server since spring, generating fraudulent pages that search engines had crawled hundreds of thousands of times.

Outcome: clean-up, database restored from a pre-attack backup, core and plugins rewritten from verified sources, administration limited to a single address. Documented how much data left and where to. The clean-up itself took fifteen minutes; the whole job including the investigation, five hours.

A gallery: 59 backdoors

The site was behaving oddly and the hosting provider reported spam going out. The system held 59 backdoors in two families — some of them faking their last-modified date to look like original files.

The logs showed the way in was not a plugin flaw but a stolen administrator password: hundreds of login attempts, not one of them successful — and then a single one that went through on the first try.

Outcome: separate quarantine, a clean restore, and above all a documented answer to the client's question — no data had left. Root cause: the security plugin had been switched off for four and a half months, so nobody was watching the site at all.

If this caught your attention because something is happening right now: +420 530 330 757 or +420 774 509 038. Before you write, only take the site offline if someone has told you to — a switched-off server is harder to examine.

Who does the work

On security I work with Jan Jurko. Two layers, two people, one number to call.

Martin Šabata — website and application

Over twenty years of IT infrastructure. Audits of web applications and APIs, PHP, nginx, permissions and access, response to compromised content management systems, backups and restores.

More about me

Jan Jurko — infrastructure and cloud

Twenty-five years in IT. Audits of AWS and Azure environments, IAM and key management, networking, cloud cost optimisation, disaster recovery design including testing it, ongoing care of Linux servers.

jurko.cz

We have no certificate to show you here as a picture. Instead, at the first meeting I will show you an anonymised report from a real audit, so you know exactly what you are getting.

Tell me what you are dealing with.

A few sentences are enough. I will get back to you within one working day and tell you whether it is worth addressing and what it would involve.

Security enquiry

None of this is sold or passed on to anyone.

I will use your contact details only to get back to you — how I handle personal data.