Support, Security & Maintenance

Your site and accounts stay secure and backed up. And when something has already gone wrong, cleanup and recovery.

8 core deliverables4 stage processServing: UK

Outcomes we focus on

  • Updates, backups and uptime handled without you asking
  • Hacked site cleaned up and taken off Google's warning list
  • Shared logins replaced with a password manager and passkeys
  • Backups proven by a restore we have actually run
  • Clear scope with billable work quoted first

Deliverables you receive

  • Core and plugin updates
  • WordPress hack cleanup: malware, backdoors, rogue admins, and Safe Browsing delisting
  • Password manager rollout (self-hosted Vaultwarden or managed) with passkeys and MFA
  • Email authentication set up properly: SPF, DKIM and DMARC to enforcement
  • Remote backups we restore from on a set date to prove they work
  • Joiner and leaver checklist so access genuinely ends
  • Uptime monitoring and security checks
  • Minor content edits and small fixes

How the engagement runs

Step 1

Onboarding and health check

Result: safe baseline with backups and monitoring live. How: review plugins, hosting, and security.

Primary KPI: Backups verified and monitor active
Step 2

Stabilise and tidy

Result: current software with less bloat. How: update safely and fix quick wins.

Primary KPI: Core and plugins updated without regressions
Step 3

Ongoing maintenance

Result: predictable support with fast responses. How: apply updates, test restores, and process small requests.

Primary KPI: Mean time to first response within SLA
Step 4

Quarterly review

Result: clear picture of health and next steps. How: short report with uptime, incidents, and recommendations.

Primary KPI: Uptime above target and incidents reduced

Proof this approach works

What this is, and what it is not

Practical hardening, cleanup and recovery work. This is not an accredited penetration test. If your insurer or a tender needs CREST-accredited testing, we will tell you and point you to someone who holds it.

Controls we work to

The five Cyber Essentials controls and the NCSC Small Business Guide.

What we measure

  • Backup restores tested and passed
  • Admin accounts on MFA or passkeys
  • System uptime and availability

Client voices

  • Issues get picked up fast and we always know what changed.
    Ops lead, ecommerce, Manchester

FAQs

Our WordPress site has been hacked. Can you help today?

Usually yes, and we will confirm the same day either way. Cleanup means malware and backdoors removed, rogue admin accounts closed off, the entry point identified, and the Google 'this site may be hacked' warning lifted. You get a written note of what got in and what stops it next time.

Are you a certified security assessor?

No. We do hands-on hardening, cleanup and recovery. We work to the Cyber Essentials controls and can get you ready to pass it, but the certification itself is issued by a licensed assessor, not by us.

What is included vs billable?

Updates, backups, monitoring, and small fixes are included. New features and larger changes are quoted first.

Do you offer 24 hour cover?

Yes, there is an urgent line for retained clients.

Ask a question

Share your plugin list and hosting. We will price a plan within one business day.

What is your question about? (required)

Need a bespoke combination of services?

Tell us about your growth targets and tech stack and we’ll assemble the right pod in one business day.