Skip to content
Agencei

Support & troubleshooting

Security for your applications, websites and servers

Agencei's security service covers the practical protection of your applications, websites and servers: configuration hardening, cleanup and recovery after a hack, vulnerability assessment, updating dependencies exposed to known CVEs, setting up a web application firewall (WAF), reliable backups and strict access management.

It is aimed at businesses running a business application, a WordPress site or PrestaShop store, an API or cloud infrastructure, that want to reduce their exposure without a dedicated security team. It also serves those that have just suffered an incident and need to regain control quickly.

Our approach is pragmatic: we start from the most likely risks for your context (OWASP Top 10, outdated dependencies, shared admin accounts, exposed server) and address what has the greatest impact first. Every action is documented so you understand what was done and why.

When do we step in?

Hacked or defaced website

Redirects to dubious sites, spam pages indexed, unknown files, a warning from Google or your host. We isolate, clean, identify the entry point and close it before bringing the site back online.

Dependencies with known vulnerabilities

Your npm, Composer or Maven audits list unpatched CVEs, or your framework version is no longer maintained. We plan and apply the updates without breaking the application.

Exposed server without hardening

SSH open with password login, unnecessary services listening, no firewall, shared root users. We apply Linux hardening best practices and monitor intrusion attempts.

Poorly controlled access

Former providers who still have access, passwords shared by email, no two-factor authentication. We restore order: named accounts, least privilege, secret rotation.

Requirement from a customer or partner

A security questionnaire, a supplier audit or a contract asks you for evidence: backup policy, patch management, logging. We put the measures in place and document them.

How we work

  1. 1

    Exposure assessment

    Mapping of applications, servers, cloud accounts and access. Dependency analysis, vulnerability scanning, configuration and log review. We produce a list of risks ranked by severity and likelihood.

  2. 2

    Emergency response if needed

    In case of compromise: isolation, forensic backup, cleanup of files and database, reset of all secrets, identification and closure of the entry vector, then monitored return to service.

  3. 3

    Hardening

    Network and application firewall (WAF), fail2ban, key-only SSH, disabling unnecessary services, HTTP security headers, up-to-date TLS, secure CMS configuration, environment separation.

  4. 4

    Updates and patches

    Updating dependencies, CMS components and systems starting with critical CVEs, with regression tests in staging before production.

  5. 5

    Backups and access

    Automated 3-2-1 backups, encrypted, stored away from the main server, with restore testing. Named accounts, least privilege, two-factor authentication, secrets manager.

  6. 6

    Monitoring and follow-up

    Alerts on intrusion attempts, file integrity and newly published vulnerabilities for your dependencies. A report summarises the measures in place and the remaining items.

Technologies we use

  • OWASP Top 10 and OWASP ZAP
  • npm audit, Composer audit and Trivy
  • fail2ban and UFW / nftables
  • WAF (Cloudflare, ModSecurity, AWS WAF)
  • Let's Encrypt and TLS
  • Wordfence and WPScan
  • AWS IAM and Secrets Manager
  • Vault and secrets management
  • Encrypted backups (restic, S3)
  • Lynis
  • CrowdSec
  • Centralised logging

Why choose Agencei?

  • We know the code as well as the server

    Many vulnerabilities are in the application: injection, broken access control, unsafe deserialisation. We fix them in the code, not only in the configuration.

  • Prioritisation by real risk

    We do not hand you a list of a hundred alerts. We first deal with what is exploitable and critical in your context, then the rest in order of importance.

  • Recovery without losing your data

    After a hack, we preserve a forensic copy before any cleanup and recover what can be recovered, rather than blindly reinstalling everything.

  • Measures that stay in place

    Monitoring, tested backups and documented procedures: security does not stop when the engagement ends.

In brief

What is this service?
Agencei's security service protects applications, websites and servers through hardening, post-hack cleanup, vulnerability assessment, dependency updates, a WAF, reliable backups and strict access management.
Who is it for?
It is aimed at businesses running a business application, a WordPress or PrestaShop site, an API or cloud infrastructure, without a dedicated security team, as well as those that have just suffered an incident.
What problem does it solve?
An exposed application with outdated dependencies, poorly managed access or an unhardened server ends up compromised, with loss of data, availability and trust. The service reduces this exposure and restores control after an incident.
How long does it usually take?
A cleanup after a hack often takes from a few hours to a few days. A full assessment and hardening usually take a few days to a few weeks depending on the scope.
What factors influence the price?
The price depends on the number of applications and servers, the extent of any compromise, how outdated the dependencies to update are, the level of monitoring desired and the documentation requirements.
How does the engagement run?
Exposure assessment, emergency response if compromised, hardening (WAF, fail2ban, SSH, headers, TLS), CVE updates, 3-2-1 backups and access management, monitoring and report.
What are the risks?
Cleaning a site without identifying the entry point leads to another compromise. Updating dependencies without tests can break the application. Ignoring access management cancels out the other measures.
What alternatives exist?
Reinstalling the site from a clean backup if one exists, subscribing to your host's security options (limited), or hiring a penetration testing firm for a formal audit and then entrusting us with the fixes.

Frequently asked questions

My site has been hacked, what should I do first?

Immediately change your admin, hosting and database passwords, then contact us before deleting anything. Preserving the state of the site makes it possible to identify the entry point. We then take care of isolation, cleanup and a secure return to service.

Is a WAF enough to protect my application?

No. A web application firewall blocks some common attacks, but it does not fix a flaw in the code or a vulnerable dependency. It is one part of a whole: updates, hardening, access management, backups and monitoring.

Do you perform penetration tests?

We carry out vulnerability assessments using automated tools and a manual review guided by the OWASP Top 10, suited to web applications and APIs. For a formal penetration test with a certified deliverable, we refer you to a specialised firm and we handle fixing the vulnerabilities found.

What does a 3-2-1 backup mean?

Three copies of the data, on two different media, one of them off-site. In practice: the database and files in production, a backup on separate storage and an encrypted copy with another provider. And above all, a restore that is tested regularly.

How long does a cleanup after a hack take?

Often from a few hours to a few days depending on the extent of the compromise, the quality of the available backups and the number of sites affected on the same server. The hardening that follows usually takes a few more days.

Tell us about your project

Describe your need in a few lines: we come back to you with a first analysis and the next steps.