Case studies

The work, written up properly

Three write-ups. The first is a client job, named. The other two are systems we manage, put through exactly the same checks we run for everybody else, because a security company that will not publish its own findings is asking you to take quite a lot on trust.

Client work

STF Electrics

An electrical contractor working across East London. We built the site, we host it, and we look after their IT, which is the part that matters when something breaks: one number to ring instead of two suppliers pointing at each other.

The STF Electrics homepage, a dark site with an animated network background and a Request a Consultation button.
The site we built for STF Electrics. Navigation goes straight to pricing and tools, not just services and a contact form.

What most electricians' websites do

They list services, they show a gallery, and they hide the prices behind a contact form. A customer has two questions before they ring anybody. What will this cost me, and is this even a job I need an electrician for. A site that answers neither is asking for a phone call from somebody who has decided nothing yet, which is the most expensive kind of phone call there is, because it takes twenty minutes and half of them were only ever going to ask a mate.

What this one does instead

The prices are on the page. A double socket is £80 to £120. A faulty socket is £60 to £90. A modern RCBO consumer unit runs £400 to £650, an emergency same-day visit is £90 to £150, and full rewires stay on quote, because a Victorian three-bed and a new build are not the same job and pretending otherwise helps nobody.

The published price list on the STF Electrics site, showing fixed price bands for socket installation, consumer unit upgrades and emergency call-outs.
The price list. Most trades sites will not put this on a page at all.

Then the tools. Three of them, working, free, no email required: an Ohm's law calculator that fills in whichever two values you leave blank, a running-cost estimator that turns appliance wattage and hours per day into a figure for the year, and a cable size calculator that takes the system type and gives an estimate. Every one of them carries a disclaimer saying the work still has to be designed and certified by a qualified electrician. That disclaimer is deliberate. Giving away a calculator is not the same as giving away the job, and the line between those two is exactly where a trades website earns its keep or embarrasses somebody.

Why give the calculations away

Because the people using them were never the ones costing you work.

Somebody working out whether their tumble dryer is expensive to run is not about to rewire a kitchen themselves. What they are doing is landing on an electrician's website, finding something genuinely useful, and remembering where it was. Months later the shower packs in and they already know who to ring.

The rest of the build is ordinary, deliberately. Four service areas, from domestic rewires through to commercial fit-outs, data cabling and three-phase, plus EV charger installation. A projects section with real jobs in it, a gallery, and a language switcher, because East London is not monolingual and neither are we.

What it runs on

The same arrangement as everything else we host: UK hosting, SSL, daily backups kept thirty days, uptime monitoring and security updates, on the care plan published on our pricing page. No separate web company. No separate hosting company. Nobody to blame but us.

One thing this page does not have is a conversion figure. We would rather publish nothing than publish a number we have not measured properly, and given how many agency case studies quote a percentage that nobody outside the agency can check, that seems worth saying out loud.

Visit stfelectrics.co.uk →

A server we manage

The door that was open by default

We pointed our audit tool at a production server we manage, from outside its network. That is the only view that shows what the internet can genuinely reach.

It found a door on the latch. The server would accept a password instead of demanding a key, and it would let the administrator account log straight in. Neither setting is exotic. Both came as defaults when the server was built, both worked perfectly well, and so nobody had looked. That is how nearly every finding starts.

1,241password attempts in 24 hours
470addresses already blocked
20 minto fix it, once found
Terminal output showing password authentication disabled and direct root login refused on the server, with fail2ban reporting 8,709 failed logins and 498 bans.
After the change: the server states that it will not accept a password, and a password login is refused outright.

None of that traffic was targeted. Anything with an open door gets tried, constantly, by software that does not know or care who you are.

The part we nearly got wrong

We changed the setting. The configuration test passed. Password logins were still enabled.

A second file, written automatically when the server was first built, was quietly overriding the one we had just edited. The only way to catch that is to ask the running service what it actually decided rather than trusting the file in front of you. Without that check we would have marked the job done and left the door open.

We mention it because it is the honest difference between changing a setting and fixing a problem, and because it happened on a box we look after, in the one area we are supposed to be good at.

Where it ended up

Passwords are not accepted at all now, and the administrator account cannot log in with one. We proved it three ways before calling it finished: a key login worked, an automated file transfer worked, and a password attempt was refused outright.

The automatic blocking stayed switched on. It was catching around a thousand attempts a day, and there is no sense removing a lock because you have fitted a better one.

Read the long version, including what this means for remote desktop →

A system we manage

Four things a full audit found on a business that was mostly getting it right

The second is far less dramatic, which is why it is worth reading. A full readiness assessment across an entire small estate. One workstation, two servers, the cloud accounts.

Plenty came back clean. Multi-factor authentication was switched on for every cloud service. The office perimeter was completely dark from outside, twelve ports probed and not one of them answered. Nothing anywhere was running software past its support date, which is the expensive problem most small businesses run into, and it was not there.

Then four things came back that should not have.

Readiness assessment extract listing three passes for perimeter, multi-factor authentication and supported software, and four failures for router password, administrator accounts, password length and unapplied patches.
The findings extract, and underneath it the two settings that caused the fourth one: patches are applied automatically, and the machine is told never to reboot.
The router was still on the password it shipped with.

Not a weak password. The factory one, printed in the manual, identical on every unit of that model ever sold. Its admin page was not reachable from the internet, so the exposure was limited to somebody already in the building or on the wifi. It fails anyway, and changing it takes about four minutes.

The everyday account was a full administrator.

One account for email, for browsing and for admin work. Anything that account runs by accident runs with the power to change the machine. The fix is a separate account for admin work and a demotion for the first one, which is more annoying than technical, because it changes a daily habit rather than a setting.

The minimum password length was zero.

Nothing enforced a length at all. That mattered less than it sounds, since the only account in use signs in through a provider with multi-factor authentication sitting on top of it. But it becomes load-bearing the moment you create the second local account described above, which is exactly what we were about to do. Order matters here. Set the policy first, then make the account.

The server installed its security patches and never restarted into them.

This is the sneaky one. Automatic updates were on and working correctly. They had been downloading and applying kernel patches for months. A kernel patch does nothing at all until the machine boots into it, and the configuration said never reboot, so the box had been running an old kernel while every report it produced showed it fully patched. It reads as green on every dashboard you might look at.

What it cost to fix

Nothing, in money. Three of the four were configuration changes and the fourth was a reboot at a quiet time.

That is the part worth taking away. Everything expensive was already right, and everything wrong was free. It is the usual shape of these things. Businesses spend on tools and skip the four-minute jobs, because the four-minute jobs are boring and nobody ever got a purchase order signed for one.

Want the same view of your own systems?

The outside-in check is free and takes about half an hour. Nobody visits, nothing is installed, and you keep the findings whether or not you use us afterwards.

Call usFree consultation