For the estate somebody else left you.
Undocumented servers, a panel nobody dares update, mail that lands in spam, and backups nobody has restored. We audit it, fix it, document it, and leave your team able to run it.
- Estates rescued last year
- 34Estates rescued last year
- Median inbox placement post-fix
- 94%Median inbox placement post-fix
- Typical audit turnaround
- 5 daysTypical audit turnaround
Symptoms we are usually called about
- Newsletters and invoices landing in spam
- A Plesk update nobody wants to be responsible for
- The only person who knew the setup has left
- Backups that have never been restored
- An outage that took six hours to even diagnose
Four problems, and what fixed looks like.
Every claim below is measured, not asserted — because on infrastructure, adjectives are worthless.
Servers that survive contact with the internet
We baseline every host against CIS, close what should never have been open, and leave you with a scored report you can hand to an auditor.
- CIS-mapped baselines for Linux and Windows
- Panel, SSH and RDP exposure locked down
- Patching automation with maintenance windows
- Audit logging shipped off-host and retained
- Median CIS score
- 72 → 96Median CIS score
- Audit turnaround
- 5 daysAudit turnaround
- Undocumented changes
- 0Undocumented changes
CIS baseline · web-01
72 / 100- SSH root login disabledpass
- Automatic security updatespass
- Host firewall default-denypass
- Panel behind IP allowlistwarn
- Unattended legacy PHP 7.4 poolfail
- Audit logging shipped off-hostpass
Every finding arrives with the exact command to fix it, the blast radius, and whether it needs a maintenance window.
Start with an audit you own outright.
The audit deliverable is yours whether or not you hire us for the remediation. No lock-in, no dependency by design.
Infrastructure audit
A full read of your servers, panels, mail estate, backups and exposure. You get a prioritised remediation plan with effort estimates — and it is yours to execute with or without us.
- Asset and dependency inventory
- CIS-mapped hardening gap analysis
- Mail deliverability report
- Prioritised remediation backlog
Remediation sprint
We execute the backlog: hardening baselines, panel rebuilds, mail authentication, backup and restore verification, monitoring and alerting that actually pages someone.
- Hardened baselines applied
- SPF, DKIM, DMARC and rDNS in place
- Verified restore from off-site backup
- Monitoring, alerting and runbooks
DevOps retainer
CI/CD pipelines, infrastructure as code, release engineering and on-call cover. The team that knows your stack stays available instead of re-learning it every incident.
- CI/CD pipelines and IaC
- Release and rollback procedures
- Quarterly DR drills
- 24/7 on-call escalation
What we actually work on.
If it is not on this list, ask — the list is what we run in production, not everything we can read a manual for.
Linux
- Ubuntu LTS
- Rocky / AlmaLinux
- Debian
- RHEL
Windows
- Server 2019 / 2022
- IIS
- Active Directory
- MSSQL
Panels
- Plesk Obsidian
- cPanel / WHM
- Webmin
- Virtualmin
- MailEnable
- Postfix + Dovecot
- Exim
- Rspamd / SpamAssassin
Web & data
- Nginx
- Apache
- MySQL / MariaDB
- PostgreSQL
- Redis
DevOps
- Docker
- Kubernetes
- Terraform
- Ansible
- GitHub Actions
- GitLab CI
Observability
- Prometheus
- Grafana
- Loki
- Zabbix
- Uptime Kuma
Security
- CrowdSec / Fail2ban
- WAF
- CIS baselines
- Wazuh
Want us to run the servers as well as fix them? Managed cloud hosting puts the same engineers on a 24/7 rota with an uptime SLA.
Find out what you are actually running.
Five days, read-only access, no changes without your sign-off. You end up with an inventory, a scored hardening report, a deliverability verdict and a costed backlog.
- Read-only access first — nothing changes during the audit
- Findings ranked by risk with effort estimates
- Written in plain language your board can read
- Yours to keep, execute in-house or take elsewhere
Mid-incident right now? Call +1 (727) 435-5151 — we take emergency engagements and stabilise first, paperwork after.
Consultancy, answered.
Almost always. The usual causes are missing or misaligned SPF, DKIM and DMARC, no reverse DNS, a shared IP with a poisoned reputation, or an open relay someone is abusing. We audit the whole path, fix the authentication, warm the IP if needed, and monitor blacklists afterwards. Median inbox placement across the estates we have fixed is 94%.
That is most of what we do. We take over inherited estates — undocumented, unpatched, sometimes with the previous admin unreachable. The audit exists precisely to map what is actually running before anyone changes anything.
No. Consultancy is independent of where the servers live. We work on AWS, Azure, GCP, DigitalOcean, Hetzner, OVH, local providers and on-premise racks. If moving would genuinely help, we will say so and quote it — but the audit is not a sales funnel.
Nothing changes without a rollback path. We snapshot, apply in a maintenance window agreed with you, verify against a checklist, and hold a rollback window afterwards. Every change is recorded in a runbook you keep.
Yes, under the DevOps retainer. We take first-line pages on agreed services with a defined escalation path back to your engineers, and run quarterly DR drills so the procedure is proven rather than assumed.