What a penetration test is, and when a small business needs one

A penetration test is a controlled attempt to break into your website or app, with your written permission, so the holes are found by someone who will tell you about them.
Review first, then test
We start with a review of the setup because that is where most small-business problems are: an admin login with no rate limiting, a forgotten staging site still online, email without SPF and DKIM so anyone can spoof your address, a plugin three years out of date. These are cheap to find and cheap to fix.
The test itself then probes the site the way an attacker would: injection, broken access control, exposed data, weak sessions, misconfiguration. It is careful, scoped in advance and never touches live payments or customer data without agreement.
When you need one
- You take payments or hold customer details.
- You have a login area for customers or staff.
- A partner, insurer or larger customer has asked for evidence of due diligence.
- The site was built a while ago and nobody has looked at it since.
What you get
A short written report. Each finding has a severity, what it means for the business in plain English, and how to fix it. If we manage your site, we fix it. If we do not, we can talk to whoever does, and re-test when they are done.
Security is mostly about doing the boring things reliably. That happens to be what a managed service is for.
Want a hand with this?
Send a few lines and you get a plain answer within two working days.
More from the blog

Why a managed website beats a one-off build for most small businesses
A website is not a purchase, it is a running service. Here is what goes wrong with the one-off model and why paying monthly usually works out better.

Editing your own website without breaking it
Every site we build comes with a simple editor. Here is what you can safely change yourself, what to leave to us, and a few habits that keep things tidy.
