Protect the asset every channel depends on.
Visibility work compounds on a site that stays up, stays clean and stays trusted. A single compromise can undo a year of it — and search engines act faster than most teams can respond.
What cyber security here means
Cyber security for a marketing estate covers assessment, hardening and monitoring of the websites, applications, APIs and cloud infrastructure a business depends on. Scope spans vulnerability assessment, firewall and SSL configuration, malware detection and removal, backup and disaster recovery, continuous monitoring and incident response.
What we defend against
Malware and defacement
Search engines de-index compromised sites quickly, and recovery takes far longer than the outage itself.
Credential compromise
Reused or unrotated admin credentials remain the most common route into a marketing estate.
Vulnerable dependencies
Plugins, themes and packages left unpatched are the largest exposed surface on most sites.
Bot and scraping abuse
Automated traffic distorts analytics, inflates ad spend and probes for weaknesses continuously.
Data exposure
Misconfigured storage, verbose errors and unprotected endpoints leak more than most teams realise.
Downtime during peak demand
Infrastructure that fails exactly when a campaign works converts marketing spend into lost revenue.
Defence in depth
No single control stops everything. Each layer assumes the one outside it has already failed, so a breach at the edge does not become a breach of the data.
Which layers are in scope depends on your plan. The lower tiers cover transport and application hardening; monitoring, tested recovery and incident response arrive at the enterprise tiers.
- 01EdgeWAF, DDoS filtering, bot mitigation
- 02TransportTLS, HSTS, security headers
- 03ApplicationInput validation, auth, rate limits
- 04DataEncryption, backup, tested recovery
Incident response
Every engagement has a written path for what happens when something goes wrong. Deciding it during an incident is how small incidents become large ones.
- 1DetectMonitoring flags anomalous behaviour or a failed integrity check.
- 2TriageSeverity and blast radius assessed against a documented matrix.
- 3ContainIsolate the affected surface, revoke credentials, block the vector.
- 4EradicateRemove the malware or close the vulnerability at its root.
- 5RecoverRestore from a tested backup and verify integrity before reopening.
- 6ReviewWritten post-incident report with the fix that prevents recurrence.
What is included, by plan
Security ladders across every tier rather than sitting only at the top. This table is generated from the same pricing data as the pricing page, so the two cannot disagree.
| Capability | First available on |
|---|---|
| SSL and security header hardening | Starter |
| Automated malware scanning | Professional |
| Malware removal and cleanup | Business |
| Web application firewall (WAF) | Business Pro |
| Automated backup and disaster recovery | Enterprise(Weekly) |
| Vulnerability assessment | Corporate(Quarterly) |
| 24/7 security monitoring and alerting | Elite |
| Penetration testing | Global Enterprise(Annual) |
| Server and infrastructure hardening | Global Enterprise |
| Incident response retainer | Fortune |
| Enterprise security consulting | Fortune |
How an engagement runs
- Weeks 1–2
Audit
Security assessment across website, application, API and cloud surface, with findings ranked by exploitability and blast radius.
- Weeks 3–6
Build
Hardening: SSL and security headers, WAF rules, access control, dependency and platform patching.
- Weeks 7–12
Ship
Malware scanning, automated backup with a tested restore, and monitoring with alert routing.
- Month 4+
Compound
Quarterly vulnerability assessment, annual penetration testing and a standing incident response path.
Who this is wrong for
Organisations needing formal certification audits — ISO 27001, SOC 2 or PCI DSS attestation. We harden and monitor systems and can prepare you for an audit, but we are not a certification body and will not pretend the two are the same.
Frequently asked questions
Four layers running continuously: reducing the exposed surface through patching and configuration, controlling access with unique credentials and MFA, detecting problems through monitoring, and recovering through a backup you have actually restored.
Find out what AI says about you right now.
We run your real buyer prompts through four assistants and send you the transcript, with your position and your competitors’. No charge, no call required to receive it.
Typical turnaround: 3 working days.