Hardening & backup
Reduce the attack surface, harden access, guarantee tested and restorable backups.
The service
Security isn't caught up by a patch after an attack. It's built in from the choice of tools and configurations. The goal: that your data, your backups and the access to your systems hold up against common attacks, including ransomware.
For whom?
SMBs handling sensitive data (customer, financial, medical), or whose IT downtime for a few days would be critical. Also for those who want to reach compliance or prepare for an external audit.
- 01 /Security audit & configuration review
- 02 /App & infra hardening
- 03 /Recognized security best practices
- 04 /Ransomware-protected backups
- OWASPStandards & ZAP
- PortSwiggerBurp Suite: web analysis
- WiresharkNetwork analysis
- pfSenseSoftware firewall
CrowdSecRuntime protection- WireGuardModern VPN
- VaultSecret management
- Let's EncryptTLS encryption
- LinuxServer hardening
resticImmutable backups
- 01
Comprehensive audit of entry points, configurations and existing backups
- 02
Concrete checks of access and configurations, not just theoretical analysis
- 03
Application and server hardening following recognized standards
- 04
Offline or immutable backups, tested regularly
I go as far as security hygiene and a step beyond: reviewing configurations and access, testing backups, application analysis with Burp Suite and OWASP ZAP. Past that — a deep penetration test, a genuinely critical exposure — it is another job, and I bring in a specialist rather than playing one:
- Penetration testers · offensive security
How much does a security assessment cost for an SMB?
The assessment starts from €1,900 excl. VAT. I analyse your application, its infrastructure and its deployment chain, and you receive a clear report: what is fragile, what is exposed, and a prioritised, priced action plan. Regulatory compliance audits (GDPR, ISO) have a scope of their own. The amount is set in the quote, after a free initial scoping session that puts the scope in writing before any commitment.My site is small, am I really targeted by hackers?
Yes. The vast majority of attacks are automated and scan the entire web without specific targeting. A WordPress site with an outdated plugin will be detected within hours, regardless of its size or traffic. Ransomware specifically targets SMBs because they're less prepared and they pay.What do I do if I'm under attack right now?
Standard procedure: isolate the attacked system, identify the entry vector, restore from a clean backup, harden before going live again. Never pay the ransom: it funds future attacks and doesn't guarantee data recovery.Is my company GDPR-compliant?
The audit includes a basic GDPR review: data storage, retention periods, cookie policies, access rights. For full compliance (processing registry, DPIA, processor contracts), I work with a partner DPO if needed, no pretense of covering the full legal scope alone.Concretely, how do you harden my systems?
I review the configuration of your servers and applications, cut access rights down to the strict minimum, enable strong authentication on sensitive access, and put a tracked update process in place. On the data side, I make sure your backups are offline or immutable, and above all tested: a backup you've never restored is just a hypothesis.
A hardening & backup project in Bordeaux?
Request a detailed quote: reply within 2 business days, quote within 5 business days, no commitment.
Request a quoteLet's talk aboutyour project.
Describe your need in a few lines. Reply within 2 business days to plan next steps, detailed quote within 5 business days.
- Reply within 2 business days
- NDA on request
- Remote anywhere in France