Define systems and review methods
Agree on URLs, environments, review accounts, authorisation, timing and methods, and plan with the owner to minimise service impact.
SERVICE / 10
Older sites may have forgotten accounts, missed settings or unmaintained components. We review accessible evidence and explain what to fix first and who should take over.
For website handovers, new launches or reviews of an existing site’s security readiness, with the system owner defining and authorising the scope.
A report of findings, priorities, necessary evidence and actionable improvements, distinguishing reviewed areas from those outside scope.
Agree on URLs, environments, review accounts, authorisation, timing and methods, and plan with the owner to minimise service impact.
Check administrators, inactive accounts, role separation and authentication supported by the system.
Review HTTPS, exposed information, relevant settings and update status from available evidence.
Review backup inventories, owners and recovery evidence. Plan tests in an agreed environment where included in scope.
Connect findings to impact, recommendations, owners and items needing further investigation.
Review and remediation are separate. If you choose our help with fixes, we plan backups, rollback and retest reporting for agreed items.
Begin with a one-off review, estimated by system count, roles and depth. Fixes, retests and ongoing care are separately selectable.
We schedule review and reporting after access and scope are clear. Fix timing depends on complexity and owners; retesting follows the agreed fix plan.
The initial scope is a review and agreed security improvements, not every form of penetration testing. A penetration test requires a separate assessment of scope, testers and methods before acceptance.
The report reflects findings within the scope and review period. It does not guarantee no vulnerabilities or future incidents, so continued improvement and care remain necessary.
You can give the report to your existing team, or request a separate Loremworks repair estimate with shared retest criteria.
A review investigates and reports on a specific scope. Care covers scheduled updates, backups and follow-up. They can connect once improvement needs are known.
Further reading
OWASP: Application Security Verification Standard ↗Let’s discuss your project
Tell us about your business, goals and concerns
Then we’ll work out a scope that fits