TechGurus
Strategy Automation Intelligence
Client login ↗Book a Strategy Call
Services / Security Audit
Service

Security Audit

An independent, read-only look at your hosting, your systems, your website and your code, and a plain statement of where you actually stand.

Security ReviewHosting & AccessDependency ReviewAI Integration RiskBackup TestingFix List
How it runs
Scope and access
We agree what is in scope and what is not, get read-only access to the right places, and put in writing what we will not touch. Nothing starts before that is settled.
The review
Hosting and the accounts that control it, the environment and what it exposes, the website and what it runs on, the code and its dependencies, and anything connected to an AI model.
Report and fix list
Ranked findings, an ordered fix list with owners, and the scope statement. Anything genuinely serious reaches you the day we find it, not a fortnight later in a document.
Fix and retest
On your sign-off we fix what we found, or work alongside whoever will, then retest and confirm in writing what has actually changed.
Problems it addresses

If any of this sounds familiar, it is worth a conversation.

The site was built a few years ago and nobody has looked at what has gone out of date since.

Staff and contractors have come and gone, and nobody is certain who still has access to the hosting, the domain or the admin.

You have added AI features or integrations, and nobody has asked what they could be talked into doing.

You have backups, and nobody has ever restored one to find out whether they work.

What we deliver

A working outcome, not a slide deck.

All four come out of one fixed-scope review. The report is yours, and it is written so another provider could act on it if you would rather they did.

01

Fixed-Price Security Review

A read-only review across hosting, environment, website and code. We look, we record, and we change nothing. Nothing is exploited and nothing is taken offline to produce the findings.

02

Ranked Findings Report

Written for a decision-maker rather than an engineer, and ordered by what each finding would cost your business if it happened, which is rarely the same order a scanner would give you.

03

Prioritised Fix List

What to do this month, what can wait, and who owns each item: you, us, your host or your software vendor. The order matters as much as the list, and we explain why each one sits where it does.

04

Scope Statement

What we examined and, just as plainly, what we did not. An audit that implies more coverage than it has is worse than no audit, because you will make decisions on the strength of it.

The engagement

What's involved

A fixed-scope review. Here is what is involved, activity by activity, so you can see what is actually covered.

Breakdown of the engagement activities and what each one involves.
ActivityWhat's involved
Scope and accessAgreeing what is in scope and what is out, and getting read-only access to the right places
Hosting and accountsWho can log in and how they authenticate, who controls the domain and DNS, and where backups actually live
Environment reviewPatch levels, what is reachable from the internet, and the old staging sites and subdomains nobody retired
Website reviewThe platform, its themes and plugins and their known vulnerabilities, admin accounts, forms and file handling
Code and dependency reviewOut-of-date libraries with published vulnerabilities, credentials committed to source control, and how access is enforced
AI integration reviewWhat each AI feature can reach, and what happens when somebody tries to talk it into something else
Backup and recovery checkWhether a backup exists, how far back it reaches, and whether anybody has ever restored one
Report, ranking and fix listFindings written for a decision-maker, ranked by business impact, with an ordered fix list, owners and the scope statement

Fixing what the review finds is scoped separately, from the fix list it produces.

Delivery process

How an engagement runs.

STEP 01

Scope and access

We agree what is in scope and what is not, get read-only access to the right places, and put in writing what we will not touch. Nothing starts before that is settled.

STEP 02

The review

Hosting and the accounts that control it, the environment and what it exposes, the website and what it runs on, the code and its dependencies, and anything connected to an AI model.

STEP 03

Report and fix list

Ranked findings, an ordered fix list with owners, and the scope statement. Anything genuinely serious reaches you the day we find it, not a fortnight later in a document.

STEP 04

Fix and retest

On your sign-off we fix what we found, or work alongside whoever will, then retest and confirm in writing what has actually changed.

Pricing approach: discovery is a fixed fee. Build work is quoted as a fixed scope and price once discovery is complete, so you decide with the numbers in front of you. Ongoing support is a monthly retainer you can stop at any time.

Want to start with the people side?

The Shadow AI Audit covers the other half of this: which AI tools your team has already started using, and what they are putting into them. Twenty-four questions, about fifteen minutes, free.

Start the Shadow AI Audit →
Questions

Frequently asked.

Will this take our website down?+

No. The review is read-only: we look at how things are configured and what you are running, rather than trying to break in. We do not exploit what we find. If anything intrusive is genuinely warranted, it happens only with your written agreement, at a time you pick, with a way back.

Is this a penetration test?+

No, and the difference is worth being clear about. A penetration test tries to break in and demonstrates what an attacker could reach. This is a review of how you are set up and what you are running. For most small businesses a review finds the things a penetration test would find in its first hour, for far less effort. If what you actually need is a formal penetration test or a certification, we will tell you that rather than sell you this instead.

We are a small business. Are we really a target?+

Rarely a chosen one, and that is the point people miss. Most of what arrives at a small business site is automated and indiscriminate: it finds an address, tries a list of known weaknesses, and moves on if nothing works. Being uninteresting is not protection. Being up to date is.

How is this different from the free Shadow AI Audit?+

They answer different questions and barely overlap. The Shadow AI Audit is about people: which AI tools your team has started using and what they are putting into them. This is technical: your hosting, your environment, your website and your code. Plenty of businesses should do both, and the free one is a sensible place to start.

We have AI features on our site. Does that change anything?+

Yes, and it is the part most reviews still skip. Anything that takes text from the public and passes it to a model can be talked into behaving in ways you did not intend, and anything that gives a model access to your systems can reveal more than you meant through an ordinary-looking answer. We look at what each AI feature is allowed to reach, and what happens when somebody tries to push it past that.

What happens if you find something serious?+

You hear about it the day we find it, with what to do about it, even when the answer is that somebody other than us should do it. Serious findings do not wait for the report.

What does it cost?+

The review is fixed-price, so you know where you stand before committing to anything further. Remediation is quoted from the fix list, which means you are approving specific work rather than an open-ended engagement. Book a call and we will scope it properly.

Further reading: How small business websites actually get hacked · 7 minute read, What Australian privacy law asks of you · 7 minute read

Tell us what you are running, and we will tell you where you stand.

We will tell you honestly whether this is the right answer for it.

Book a Security Review →