Skip to content
AI GUIDERPROAIGuiderPRO — Smarter Search. Better Growth.
Get leverage · Cyber Security

Protect the asset every channel depends on.

Visibility work compounds on a site that stays up, stays clean and stays trusted. A single compromise can undo a year of it — and search engines act faster than most teams can respond.

What cyber security here means

Cyber security for a marketing estate covers assessment, hardening and monitoring of the websites, applications, APIs and cloud infrastructure a business depends on. Scope spans vulnerability assessment, firewall and SSL configuration, malware detection and removal, backup and disaster recovery, continuous monitoring and incident response.

What we defend against

Malware and defacement

Search engines de-index compromised sites quickly, and recovery takes far longer than the outage itself.

Credential compromise

Reused or unrotated admin credentials remain the most common route into a marketing estate.

Vulnerable dependencies

Plugins, themes and packages left unpatched are the largest exposed surface on most sites.

Bot and scraping abuse

Automated traffic distorts analytics, inflates ad spend and probes for weaknesses continuously.

Data exposure

Misconfigured storage, verbose errors and unprotected endpoints leak more than most teams realise.

Downtime during peak demand

Infrastructure that fails exactly when a campaign works converts marketing spend into lost revenue.

Defence in depth

No single control stops everything. Each layer assumes the one outside it has already failed, so a breach at the edge does not become a breach of the data.

Which layers are in scope depends on your plan. The lower tiers cover transport and application hardening; monitoring, tested recovery and incident response arrive at the enterprise tiers.

Defence in depthFour concentric protective layers around core data: edge, transport, application and data.Data
  1. 01EdgeWAF, DDoS filtering, bot mitigation
  2. 02TransportTLS, HSTS, security headers
  3. 03ApplicationInput validation, auth, rate limits
  4. 04DataEncryption, backup, tested recovery
Layered security model applied on every engagement.

Incident response

Every engagement has a written path for what happens when something goes wrong. Deciding it during an incident is how small incidents become large ones.

  1. 1DetectMonitoring flags anomalous behaviour or a failed integrity check.
  2. 2TriageSeverity and blast radius assessed against a documented matrix.
  3. 3ContainIsolate the affected surface, revoke credentials, block the vector.
  4. 4EradicateRemove the malware or close the vulnerability at its root.
  5. 5RecoverRestore from a tested backup and verify integrity before reopening.
  6. 6ReviewWritten post-incident report with the fix that prevents recurrence.
Incident response sequence. Response times are contractual only on Fortune-tier engagements.

What is included, by plan

Security ladders across every tier rather than sitting only at the top. This table is generated from the same pricing data as the pricing page, so the two cannot disagree.

Security capabilities by plan tier
CapabilityFirst available on
SSL and security header hardeningStarter
Automated malware scanningProfessional
Malware removal and cleanupBusiness
Web application firewall (WAF)Business Pro
Automated backup and disaster recoveryEnterprise(Weekly)
Vulnerability assessmentCorporate(Quarterly)
24/7 security monitoring and alertingElite
Penetration testingGlobal Enterprise(Annual)
Server and infrastructure hardeningGlobal Enterprise
Incident response retainerFortune
Enterprise security consultingFortune

How an engagement runs

  1. Weeks 1–2

    Audit

    Security assessment across website, application, API and cloud surface, with findings ranked by exploitability and blast radius.

  2. Weeks 3–6

    Build

    Hardening: SSL and security headers, WAF rules, access control, dependency and platform patching.

  3. Weeks 7–12

    Ship

    Malware scanning, automated backup with a tested restore, and monitoring with alert routing.

  4. Month 4+

    Compound

    Quarterly vulnerability assessment, annual penetration testing and a standing incident response path.

Who this is wrong for

Organisations needing formal certification audits — ISO 27001, SOC 2 or PCI DSS attestation. We harden and monitor systems and can prepare you for an audit, but we are not a certification body and will not pretend the two are the same.

Frequently asked questions

  • Four layers running continuously: reducing the exposed surface through patching and configuration, controlling access with unique credentials and MFA, detecting problems through monitoring, and recovering through a backup you have actually restored.

Find out what AI says about you right now.

We run your real buyer prompts through four assistants and send you the transcript, with your position and your competitors’. No charge, no call required to receive it.

Typical turnaround: 3 working days.