Our Process · Scan → Report → Fix → Protect

A clear path from “something's wrong” to secured.

No black boxes and no surprise changes. You see exactly what we found, what it means, what we intend to do about it — and proof that it worked. Non-destructive at every stage.

Non-destructiveBackup-first48-hour report
Scan
Clean
Harden
Monitor
01Day 1

Scan & investigate

We map your entire attack surface and establish what is actually happening — before touching anything.

What happens in this phase

  • Stack & version fingerprinting
  • Malware and injected-code scan
  • Known-CVE matching (WPScan, Patchstack)
  • Config, headers, TLS & exposure checks
  • User, access & endpoint review
  • Blacklist and reputation status
02Within 48h

Report & prioritise

You get a clear, evidence-backed report — findings ranked by real risk, not scanner noise.

What happens in this phase

  • Executive summary in plain English
  • Severity-rated findings with CVSS
  • Evidence & indicators of compromise
  • Confirmed vs. suspected, clearly marked
  • Prioritised P0–P3 remediation plan
  • Business-impact explanation
03On approval

Fix & harden

We remove what is malicious, patch what is vulnerable, and close the door that let it in.

What happens in this phase

  • Full backup taken first
  • Malware, backdoors & persistence removed
  • Infection vector closed
  • Core/plugin/theme integrity restored
  • Headers, 2FA, WAF & least-privilege applied
  • Credentials, salts & keys rotated
04Ongoing

Verify & protect

We prove the fix worked, get you de-listed if needed, and keep watching so it stays clean.

What happens in this phase

  • Full re-scan & verification
  • Blacklist / Safe Browsing review submitted
  • Change documentation handed over
  • File-integrity & malware monitoring
  • Uptime, blacklist & SSL alerts
  • Priority response if anything changes
48h
Report turnaround
4
Clear phases
100%
Backup-first changes
1:1
Sign-off before changes
How we work

The principles behind every engagement

Non-destructive by default

We never modify data, orders or availability while testing. Risky exploits are documented, not executed.

Evidence for every finding

Each item carries proof and a confidence level, so you never act on a guess.

Backup before every change

Nothing is touched until a restore point exists. Every change is reversible.

Your sign-off at each step

We explain what we intend to change and why — you approve before we proceed.

Root cause, not symptoms

We close the entry point so the problem does not simply come back next month.

Verified, then monitored

We retest after fixing and can watch the site continuously afterwards.

FAQ

Process questions

How long does the whole process take?
A scan and report is typically delivered within 48 hours. Cleanup and hardening usually complete within 24–48 hours of approval. Blacklist reviews add up to another 72 hours on Google’s side. Emergency cases are prioritised and start immediately.
What do you need from me to start?
For a scan, just your URL. For cleanup and hardening we typically need WordPress admin plus hosting/file access (SFTP or control panel). We only request what the work requires and you can revoke access afterwards.
Will you change things without telling me?
No. You get the report first, and we agree the remediation plan before anything is changed. Every change is documented and handed back to you at the end.
What if you find nothing wrong?
That is a good outcome and you still get the full report — confirmation of what was checked, your hardening gaps, and recommendations to reduce risk going forward.

Ready to see where your site stands?

Start with a non-destructive scan. You'll get a clear report and a prioritised plan — then decide what to fix.