Most breaches start with something boring

An outdated plugin. A login that belonged to someone who left in 2023. A backup nobody ever tried to restore. We handle the unglamorous work that stops most of what actually happens to businesses your size.

The reality

Security for a business without a security team

Small and mid-size businesses rarely get attacked by someone who chose them. They get swept up by automated scanning that finds a known vulnerability in a component that has been out of date for eleven months.

That is good news, because the defense is unexciting and affordable. Keep software current, keep the list of people with access short, keep backups you have actually tested, and know within hours rather than weeks when something changes.

We do that work as part of ongoing maintenance rather than as a separate security product, because a security posture that depends on a quarterly project does not survive a busy quarter.

The work

What we handle

On a retainer, most of this happens on a schedule you never have to think about.

Dependency and platform updates

Plugins, gems, packages, themes, and the language runtime underneath them. We watch published advisories for the specific versions you run, and we patch on staging first so an update never takes your site down at 4pm on a Friday.

Access review and offboarding

Named accounts, least-privilege roles, multi-factor authentication on anything that matters, and a real removal step when someone leaves. Old accounts are the most common thing we find during onboarding.

Secrets kept out of the code

API keys, database passwords, and payment credentials belong in a secrets store, not in a repository or a shared document. When we inherit a codebase, we check the history for keys that were committed and rotate what we find.

Backups we have restored

A backup nobody has tested is a hope, not a plan. We run a restore periodically so we know how long recovery takes and what it costs you in lost data.

Transport and browser hardening

HTTPS enforced, certificates renewed automatically, sensible security headers, and a content policy that limits what third-party scripts can do on your pages.

Monitoring and error tracking

Uptime checks, error reporting, and alerts that go to a person. Most incidents are survivable if somebody notices the same day.

Incident response

What happens when something looks wrong

Agreed in advance, so nobody is inventing a process while a site is down.

Contain

Stop it from getting worse

Take the affected path offline, rotate credentials, and block the route in. Containment comes before diagnosis, because the investigation takes longer than the damage does.

Tell you

You hear it from us, early and plainly

What we know, what we do not know yet, and what we are doing about it. Including when the cause turns out to be something we did. If regulated data may be involved, your compliance and legal contacts are in the conversation from the start.

Restore

Get you back up on clean ground

Restore from a known-good backup rather than trying to clean a compromised system in place. Cleaning a defaced or injected site by hand misses things almost every time.

Close

Fix the way in, not just the symptom

Patch the vulnerability, remove the access that was abused, and check whether the same weakness exists anywhere else in your stack.

Write it up

A short account you can hand to anyone

Timeline, cause, impact, and the changes made. Useful for your insurer, your board, and your own team the next time somebody asks whether this could happen again.

Straight answer

Where we stop and bring in a specialist

We are a development team that takes security seriously. We are not a penetration testing firm, a managed security operations center, or a SOC 2 auditor.

If you need a formal penetration test, a compliance certification, or forensics after a confirmed breach, you need a specialist, and we will help you find and brief one. We stay involved as the people who know your systems, which usually makes their engagement shorter and cheaper.

We would rather tell you that than sell you an assessment we are not the right people to run.

Proof

Security work inside a live engagement

At Spectrum Medical Care we run the development team for a clinic where the data is sensitive and the site changes every week. Security review is part of the sprint, not a project.

Running the development team for a Phoenix healthcare clinic
Back-end Ongoing Support

Running the development team for a Phoenix healthcare clinic

A specialty-care clinic serving LGBTQ+ patients and people living with HIV needed their digital side to move as fast as their clinical side. We joined as their ongoing development team in late 2025. We run three-week sprints against a shared backlog, shipped a full site refresh, handled a HIPAA-aware data incident, and absorb same-day press requests without losing the roadmap.
Common questions

Questions we get about this

Our site got hacked. Can you clean it up?

Usually yes. We contain first by taking the affected path offline and rotating credentials, then restore from a known-good backup rather than cleaning a compromised system in place, because hand-cleaning misses things.

After that we find and close the way in, check whether the same weakness exists elsewhere, and write up a short account you can give your insurer or your board. If the incident involves regulated data or needs forensic evidence preserved, we will tell you to bring in a specialist and help you brief them.

Who is responsible for security updates if we are on a retainer?

We are. Plugin, package, theme, and runtime updates run on a schedule, patched on staging first so an update never takes your site down unannounced. We watch published advisories for the versions you actually run rather than waiting for something to break.

What stays with you is the human side: who gets an account, and telling us when someone leaves.

Do you do penetration testing?

Not as a formal service. We review code, dependencies, configuration, and access as part of ongoing work, and that catches most of what realistically threatens a business your size.

If you need a formal penetration test for a compliance requirement or a customer contract, you want a specialist firm. We will help you pick one, brief them on your systems, and fix what they find.

How fast do you respond to emergencies?
Response SLAs are tier-dependent and written into your contract. The Steady tier is within two business days for non-urgent work and within twenty-four hours for site-down emergencies. Active and In motion tiers tighten that further.
Will you maintain a site you didn't build?
Yes, often. Our retainer practice started largely with sites built by other teams. We'll do a short technical and accessibility audit before the retainer starts so we both know what we're working with.
Let's talk

Not sure when your site was last updated?

That question alone is usually enough to start with. In a free consultation we will look at what you are running, who still has access, and whether your backups would actually come back.

No fear pitch. Just the two or three things worth doing first.

Book a free consultation