SERVICE / 10

Website security review & fixes.

Older sites may have forgotten accounts, missed settings or unmaintained components. We review accessible evidence and explain what to fix first and who should take over.

Discuss this serviceSee the scope
01 / WHO IT’S FOR

Understand the risks and prioritise fixes

For website handovers, new launches or reviews of an existing site’s security readiness, with the system owner defining and authorising the scope.

A report of findings, priorities, necessary evidence and actionable improvements, distinguishing reviewed areas from those outside scope.

02 / SCOPE WE AGREE TOGETHER

Service scope

01

Define systems and review methods

Agree on URLs, environments, review accounts, authorisation, timing and methods, and plan with the owner to minimise service impact.

02

Review accounts and access

Check administrators, inactive accounts, role separation and authentication supported by the system.

03

Review settings and components

Review HTTPS, exposed information, relevant settings and update status from available evidence.

04

Review backups and recovery readiness

Review backup inventories, owners and recovery evidence. Plan tests in an agreed environment where included in scope.

05

Summarise risks and fix priorities

Connect findings to impact, recommendations, owners and items needing further investigation.

06

Apply agreed fixes and retest

Review and remediation are separate. If you choose our help with fixes, we plan backups, rollback and retest reporting for agreed items.

03 / BEFORE WORK STARTS

Budget and timeline

Begin with a one-off review, estimated by system count, roles and depth. Fixes, retests and ongoing care are separately selectable.

How we plan the schedule

We schedule review and reporting after access and scope are clear. Fix timing depends on complexity and owners; retesting follows the agreed fix plan.

Information that helps us estimate accurately

  • URLs and systems you own or are authorised to have reviewed
  • The authorising person and system contact
  • Known technologies, providers and past issues
  • Permitted review times, constraints and available backups
04 / FAQs

Common questions about this service

Is this a penetration test?

The initial scope is a review and agreed security improvements, not every form of penetration testing. A penetration test requires a separate assessment of scope, testers and methods before acceptance.

Does the review guarantee we won’t be attacked?

The report reflects findings within the scope and review period. It does not guarantee no vulnerabilities or future incidents, so continued improvement and care remain necessary.

Do we have to ask you to make the fixes?

You can give the report to your existing team, or request a separate Loremworks repair estimate with shared retest criteria.

How is this different from a care package?

A review investigates and reports on a specific scope. Care covers scheduled updates, backups and follow-up. They can connect once improvement needs are known.

Let’s discuss your project

An idea you’d like to start
Or a system you’d like to improve.

Tell us about your business, goals and concerns
Then we’ll work out a scope that fits

Discuss your project

Prepare a project brief

Start with your idea

Share what you know so far. We can work through the rest later.

Choose a service above to see questions tailored to your project.

Do not include passwords, login credentials or your customers’ personal data in the brief.

Choose a service and fill in the details. Loremworks will reply to the email you provide, or download a copy to keep for the conversation.