Evidence from assessments, reviews, and readiness sessions

Quotes and short project notes from organisations that commissioned website and hosting security guidance.

“The assessment flagged an abandoned staging subdomain we had forgotten after a redesign. The remediation list was ordered by what our one developer could finish in a week, which mattered more than a long theoretical report. I still wish the first call had been shorter — we spent time restating hosting details already in the questionnaire — but the written pack was clear enough for our host's support team to act without another round of meetings.”

Thandi Mokoena · Operations lead, retail catalogue site · Website Security Assessment

“We run two WordPress sites on the same cPanel account. Content Sprucefield walked through FTP users left over from a 2022 freelancer and showed us how to jail new accounts to a single folder. Backup restore paths were documented in language our office manager could follow.”

Pieter van der Berg · Owner, regional services firm · Hosting Security Review

“Before the retainer I forwarded every malware scanner email to our developer at midnight. Now we have a short severity guide: which alerts wait until morning, which mean we pull the site. The monthly call is practical — screenshots of our actual panel, not slides.”

Lerato Dlamini · Marketing coordinator · Monitoring Guidance Retainer

“We practised restoring a backup to a subdomain while the facilitator timed us. Discovering that our 'daily' backup had been failing silently for eleven days was uncomfortable, but better in a workshop than during a real defacement. The one-page playbook now sits with the board secretary.”

James Nkosi · IT volunteer, community nonprofit · Incident Readiness Session

Website Security Assessment

Catalogue site after a plugin compromise

A Sedibeng retailer contacted us after customers reported phishing redirects on product pages. The CMS was patched, but an abandoned staging host still served an older plugin with a known upload flaw. The assessment mapped the exposure, confirmed the production database had not been altered, and produced a remediation order: remove staging DNS, rotate credentials, and re-enable monitoring with certificate and malware checks. The retailer kept their existing host; no platform migration was required.

Hosting Security Review

Shared mailbox access on a family business site

A family-run service business shared one cPanel password among four people and a designer. The review created separate SFTP users, enabled panel two-factor authentication, and retired mailboxes for former staff. Two weeks later a password-reset attempt against the CMS failed because the recovery address had been moved to a monitored inbox instead of a forwarded group alias.