Website security audits for UK small businesses
A website security audit should end with a list you can act on, in an order that makes sense, written so the person paying for it understands what they are buying. Not a 90-page scanner dump with 400 informational findings and no priorities.
This is a focused, fixed-price review of one website or web application, carried out by the engineers who build production systems, not by people who stopped writing code a decade ago.
What the audit covers
We look at your site the way an attacker with time and no inside knowledge would, then at the parts an attacker cannot see but a developer can. This is the standard scope; anything unusual about your setup gets discussed before we agree a price.
Authentication and sessions
Login, password reset, session handling, multi-factor options and whether one account can reach another account's data.
Access control
Whether the permissions the interface implies are actually enforced on the server, which is where most real breaches of small sites begin.
Input handling and injection
Forms, search, uploads and URL parameters checked for injection, cross-site scripting and the handling of files you'd rather not host.
Data exposure
What leaks through APIs, error messages, backups, directory listings, source maps and metadata that shouldn't be public.
Configuration and transport
TLS, security headers, cookie flags, CORS, admin interfaces reachable from the internet and default credentials nobody changed.
Dependencies and hosting
Out-of-date libraries, plugins and platform versions with known vulnerabilities, and whether your host's defaults are working for you.
Authorisation, and what we will not test
Testing a system without written permission from whoever owns it is a criminal offence under the Computer Misuse Act 1990, so nothing starts until we have a signed authorisation naming the exact domains, applications and IP addresses in scope, a dated window for the work, and a contact who can stop it. If you don't own the platform, your hosting provider or SaaS vendor has to agree too, and we'll help you ask.
Everything else is passive by default: we read what your site tells the world, review configuration and inspect code where you give us access. Active testing that could affect availability or data - anything that writes, deletes, floods or brute-forces - happens only on a staging copy, or in a scheduled window you have agreed in writing, and never without both. Testing of third-party services you merely use, social engineering of your staff, and physical access are all out of scope unless separately agreed.
What the report contains
One document, written to be read by two different people: the owner deciding what to spend, and the developer doing the fixing. It opens with a plain-English summary of your actual risk, in a page, with no jargon and no scare tactics.
Findings, ranked by real risk
Each with what it is, what an attacker could actually do with it, how likely that is for a business like yours, and evidence we found it.
A fix for every finding
Specific and technical enough for whoever maintains the site to act on, not "implement industry best practice".
An ownership matrix
Who fixes what: you, us, your host, your platform vendor or your developer. Nothing sits in the gap between suppliers.
What we checked and found nothing
The negative results too, so you know what the audit covered, and not only what it caught.
What we could not test
Stated explicitly, with the reason, so nobody mistakes the scope of this review for a clean bill of health.
A retest
Once you've fixed things, we verify the fixes actually work. Included, not a second engagement.
Timescale, price and confidentiality
A typical small business website or web application takes about a week from authorisation to report, and it is a fixed price agreed beforehand, not an open-ended day rate. The figure depends on how much there is: a brochure site is a fraction of an application with user accounts, payments and an admin area. You'll know the number before anything begins.
Findings are confidential and we're happy to sign your NDA before we look at anything. We do not publish client names, screenshots or findings, we do not use your vulnerabilities as marketing, and evidence is shared over an encrypted channel and deleted on the schedule we agree with you.
What this audit is not
It is not a formal penetration test by an accredited tester, and it is not a certification. If you need CREST-accredited testing, Cyber Essentials Plus, PCI DSS assessment or an ISO 27001 audit for a contract or a regulator, that requires an accredited body and we will tell you so plainly and help you find one, rather than stretching what we do to fit the words on your tender document.
It is also not a compliance verdict. We can tell you that your site leaks personal data through an unauthenticated API, and what to do about it. We cannot tell you that you are GDPR compliant, because nobody outside a regulator or an accredited auditor can.
What it is: a thorough, honest, senior look at how your site would actually be attacked, and a prioritised plan for fixing what matters, at a price a small business can justify. For most small organisations that is the thing they need and have never been offered.
Common questions
How much does a website security audit cost?
It is a fixed price agreed before we start, never an open-ended day rate, and it depends on how much there is to review. A brochure site is a fraction of the cost of a web application with user accounts, payments and an admin area. A review of a single website costs far less than most people fear when they hear "security consultant", and we'll tell you up front if what you actually need is smaller than what you asked for. The retest after you've fixed things is included.
Will the audit take my site down?
No. The default scope is passive: we read what your site already exposes, review its configuration and inspect code where you give us access, none of which affects availability. Anything active - testing that writes, deletes or floods - happens only against a staging copy or inside a window you have agreed in writing, and never without both. You get a named contact who can stop the work at any point.
What do you need from us before starting?
A signed authorisation naming the exact domains and applications in scope, a window for the work, and someone who can stop it. If your site sits on a platform or host you don't own, we need their agreement too, and we'll help you write that request. Beyond that, read-only access to the code and a walkthrough of how the site is meant to work make the audit considerably better, but neither is essential.
Is this a penetration test?
Not in the formal sense. A pen test in the sense a regulator or a tender means is carried out by an accredited tester against a defined standard, and produces a certificate. This is a technical security review by senior developers that finds the same categories of problem and tells you how to fix them, at a fraction of the cost. If you need the accredited version for a contract or a regulator, we'll say so and point you to someone who does it.
What happens after the report?
You decide. Plenty of clients take the report to their own developer and never speak to us again, which is a perfectly good outcome and the report is written to make that easy. If you'd rather we fixed things, we'll quote the remediation separately so the audit fee never depends on us finding work for ourselves. Either way, the retest to confirm the fixes landed is included.
Read this before you commit
Security consulting
The wider service: GDPR guidance, secure-by-design builds and incident readiness.
How we build securely
The practices every system we build inherits, and the commitments we're prepared to put in writing.
Website development
When the audit concludes that rebuilding is cheaper and safer than patching.
Hosting and maintenance
Keeping it secure after the fixes: dependency updates, patches and monitoring.
A confidential first conversation
Tell us what you run and what worries you. Free, and covered by your NDA if you have one.
Related services
Security Consulting
Beyond one website: GDPR, secure builds and incident readiness.
Explore security consultingWebsite Development
Rebuild with security designed in, if that's the cheaper answer.
Explore website developmentHosting & Maintenance
Patches, updates and monitoring so it stays fixed.
Explore hosting & maintenanceWorried about one specific site?
Tell us the address and what you're most concerned about. The first conversation is free and confidential, and we'll tell you honestly whether an audit is what you need.
Start the conversation