Cybersecurity & Digital Protection · Hardening

Security Hardening

The fixing job: headers, permissions, versions and configuration put right

Buy now

From$499USD one-off

One payment. Work starts once we have confirmed your requirements.

The four questions this page answers

  1. 1

    What you buy

    A one-off remote engagement in which we apply security fixes to a website or server. Where an assessment tells you what is wrong, this is the product that changes it.

  2. 2

    What you get

    5 deliverables, listed in full below

    • The agreed findings applied to your live site, item by item
    • A written change log naming every change made and how to reverse it
    • A verification report showing each item re-checked after the work
    + 2 more
  3. 3

    How it is delivered

    Remote Setup

    Carried out remotely by our team. Nothing is posted and no one visits.

    REMOTE SERVICE

  4. 4

    How long it takes

    5–8 business days from agreement of the scope list and a maintenance window

    Measured from the point everything under “what we need from you” is with us, not from the moment you pay.

A hardening pass taking every configuration check from failing to passing — illustrative concept, not a screenshot of a client system
A hardening pass taking every configuration check from failing to passing. Illustrative interface concept — not a screenshot of a client deployment.

What is this, in plain English?

A one-off remote engagement in which we apply security fixes to a website or server. Where an assessment tells you what is wrong, this is the product that changes it.

Works from an agreed findings list, whether it came from our own audit, another supplier or your insurer. Each item is applied in a staging copy first where one exists, then live, then verified. Configuration, headers, permissions, account clean-up and software versions are all in scope. Rewriting your application’s source code is not.

The problem it solves

You are holding a list of security findings and there is nobody in the business who can apply them without a real chance of taking the site down.

If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.

What you get

The concrete things that exist at the end and that you own.

5 deliverables

  • The agreed findings applied to your live site, item by item
  • A written change log naming every change made and how to reverse it
  • A verification report showing each item re-checked after the work
  • A pre-work backup handed to you, so you hold your own restore point
  • A short list of anything on the list we recommend against doing, with the reason

What's included

The work covered by the figure in the buy box, at no extra cost.

  • Up to twelve agreed hardening items on one site or server
  • Pre-work backup with a confirmed restore
  • Staging application where a staging environment exists
  • Header, permission, version and account work
  • Post-change verification
  • Change log with rollback notes

Not seeing something you expected? Check what you are not buying before you order.

What does it do?

Everything listed here is delivered as part of this product. Nothing on this list is aspirational.

  • Security headers set and verified as served, including content security, frame, referrer and transport policies
  • File and directory permissions corrected across the web root
  • Platform, plugin and library versions brought up to a supported release, tested as we go
  • Unused accounts, default logins and dormant plugins removed
  • Administrative areas restricted and login attempts rate limited
  • Configuration files, error output and directory listings closed to the public
  • Every change recorded with a rollback note against it

How it works

The delivery sequence from order to handover.

  1. 1

    Agree the list

    We go through the findings together and fix which items are in scope. That list is the scope, and it does not change without a written variation.

  2. 2

    Take a restore point

    A full backup of files and database is taken and its restore confirmed before anything is touched.

  3. 3

    Apply in staging

    Where a staging copy exists, changes go there first and the site is exercised before they go anywhere near live.

  4. 4

    Apply live

    Changes are applied in an agreed maintenance window, in an order that keeps the site usable throughout.

  5. 5

    Verify and document

    Each item is re-checked as served, and you receive a change log with a rollback note against every entry.

Delivery & fulfilment

Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.

REMOTE SERVICEHow this is delivered
  1. 1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
  2. 2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
  3. 3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.

Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 5–8 business days from agreement of the scope list and a maintenance window.

Delivery method
Remote Setup
Expected delivery time
5–8 business days from agreement of the scope list and a maintenance window
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.

Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.

What we need from you

Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.

  • Administrator access to the site, hosting and, where relevant, the server
  • An agreed findings list, from us or from another assessment
  • A maintenance window, and acceptance that brief downtime is possible
  • A named contact who can approve a change mid-engagement if something unexpected appears

Who this is for

  • Businesses that have had an audit and now need the work done
  • Companies running an out-of-date content management system
  • Owners whose insurer or client has set remediation as a condition
  • Teams whose original developer is no longer available

Business needs this addresses: Improve IT infrastructure

What's not included

Just as plainly as the list above: the things this package is not.

  • Rewriting application source code, which is quoted as development work
  • Findings that can only be resolved by rebuilding or replacing the site
  • Firewall subscriptions, paid plugin licences and platform upgrade fees, which you pay those providers directly
  • Cleaning a site that is already compromised, which is Malware Removal & Cleanup
  • Ongoing monitoring or patching after this engagement ends
  • Any promise that the site will not be breached; hardening reduces exposure, it does not remove it

Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.

FAQs

What happens if a fix breaks something?

We take a restore point before starting and record a rollback note against every change, so a broken item can be reversed rather than debugged under pressure. Where a staging copy exists, breakages are found there instead of on your live site. If a change cannot be made safely, we leave it and tell you why.

Do we need the audit first?

Not necessarily. If you already hold a findings list from another supplier, we will work from that. If you have nothing, the Website Security Audit produces the list and this product applies it, which is usually the cheaper route than us discovering the scope as we go.

Will our site be secure afterwards?

It will be materially harder to attack through the routes we closed, and you will have a written record of exactly what changed. It will not be secure in an absolute sense, because new vulnerabilities are published constantly and your software will drift out of date again. That is what the monitoring plans are for.

What if a plugin we rely on is no longer maintained?

We flag it and stop. Updating something the vendor has abandoned is not possible, so the honest options are replacing it or accepting the risk knowingly. Finding a replacement and migrating the data is separate work and is quoted before we do it, never absorbed silently into this scope.

Refund & cancellation

What happens if you change your mind, and what happens to money already paid.

Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.

The full terms, item type by item type, are in the Refund & Cancellation Policy. How the work reaches you is covered by the Delivery & Fulfilment Policy.

Not sure this is the right product?

We would rather point you at the right thing than sell you the nearest one. Ask us before you buy — no obligation.

Related products

Others that solve nearby problems, in case this is not quite the right fit.

Or see all 11 in Cybersecurity & Digital Protection.

Contact us