Cyber security · SSH

Boutique SSH security

Free initial audit, then hardening and monthly care — clear findings, fast fixes, 24-hour response.

What we do over SSH — and AI

Once you grant controlled SSH access, we run a production-grade security review — then fix what matters. One-off clean-up or monthly retainer. NEW: AI Calling, email Auto Processor and Chat — wired to Stripe / your books so they can stand in for a receptionist. Below is the short version; the full capability list runs to several hundred tasks.

Security audits

  • SSH, keys, fail2ban, sudo / users
  • Firewall (UFW, nftables, cloud SGs)
  • Web stack (nginx, OLS, Apache, PHP-FPM)
  • TLS, headers, open ports, admin panels
  • Cron, systemd, suspicious processes
  • Disk, logs, backup presence

What we help you solve

  • Brute-force noise and compromised hosts
  • Weak defaults, leftover test files
  • World-writable paths / path leaks
  • Broken SSL, outdated PHP / kernels
  • Mail, SIP, VPN exposure that should not be public
  • Prioritised fix plan you can approve in one call

Ongoing care

  • Scheduled remote checks with change notes
  • Patch triage and safe hardening rollouts
  • Watchdogs for SSH, firewall, disk, services
  • Incident response over SSH when something breaks
  • Clear English reports — found / fixed
  • Optional Telegram / email ops alerts

Full capability list

Everything a senior engineer can do on your box once SSH is open — audit, build, fix, migrate or keep it running. If it is not listed, ask: the answer is usually yes.

SSH & access

  • sshd hardening, ciphers, Match blocks
  • Key-only login, password auth off
  • SSH certificate authority, short-lived keys
  • TOTP or FIDO2 second factor
  • Bastion / jump host architecture
  • SFTP-only chroot accounts
  • Revoke ex-staff keys and sessions
  • Session recording with auditd / tlog
  • Non-default port, source allowlists

Users & privileges

  • sudoers audit, remove risky NOPASSWD
  • PAM stack and lockout policy
  • LDAP / FreeIPA / Active Directory join
  • Dormant and orphaned account cleanup
  • setuid / setgid and capability audit
  • POSIX ACLs on shared directories
  • Separate deploy and admin identities
  • Break-glass access documented

Firewall & ports

  • nftables, iptables, UFW, firewalld
  • Map every listener and open port
  • Close services that should be private
  • Align host rules with cloud security groups
  • Rate-limit floods, log drops
  • IPv6 exposure cleanup
  • Country / netblock blocking where sensible
  • Management ports behind allowlists

Private networking

  • WireGuard client and site-to-site
  • OpenVPN and IPsec / strongSwan
  • Tailscale or self-hosted Netbird mesh
  • Egress filtering to approved destinations
  • Routing, NAT and port forwarding
  • DNS resolution and split-horizon fixes
  • MTU, bonding, packet-loss debugging
  • tcpdump capture and analysis

MikroTik

  • RouterOS secure baseline and upgrades
  • Firewall filter, NAT and raw rules
  • Winbox / WebFig / API lockdown
  • WireGuard, L2TP/IPsec, SSTP VPN
  • VLAN, bridge and hotspot isolation
  • BGP / OSPF where required
  • Backup, Netwatch and logging
  • Compromised MikroTik cleanup

Cisco

  • IOS / IOS-XE switch and router hardening
  • ASA / Firepower policy review basics
  • AAA, local users and enable secrets
  • Management plane ACLs and SSH-only
  • SNMP v3, logging and NTP hygiene
  • VLAN, trunk and port-security baselines
  • Site-to-site and remote-access VPN
  • Config backup and change documentation

HP / Aruba

  • Aruba / ProCurve / HPE switch hardening
  • Instant On and Central-managed estates
  • Secure management and admin roles
  • 802.1X and port-access policies
  • VLAN and uplink design review
  • Firmware lifecycle and CVEs
  • Stack / VSF health checks
  • Guest and IoT network isolation

UniFi / Ubiquiti

  • UniFi OS and Network Application hardening
  • UDM / UXG / USG gateway security
  • Switch and AP secure defaults
  • VLAN, guest Wi-Fi and client isolation
  • Traffic rules, IDS/IPS and GeoIP
  • Site-to-site and Teleport / WireGuard VPN
  • Admin 2FA, SSO and role lockdown
  • Protect / Access / Talk exposure review

Special VPN

  • WireGuard mesh and hub-and-spoke
  • IPsec site-to-site (strongSwan, Cisco, MikroTik)
  • OpenVPN access servers
  • Split-tunnel vs full-tunnel design
  • Always-on remote staff access
  • Admin ports behind VPN only
  • Certificate and PSK rotation
  • Failover and dual-site VPN

Intranet & LAN

  • Office / warehouse VLAN segmentation
  • Servers, users, printers, CCTV, IoT zones
  • Inter-VLAN firewall rules
  • Private intranet apps not on the WAN
  • Guest Wi-Fi that cannot reach LAN
  • DNS and DHCP hygiene per segment
  • Jump host for admin access
  • Documented network map for the team

Intrusion defence

  • fail2ban jails for SSH, web, mail
  • CrowdSec engine and firewall bouncer
  • auditd watch rules for sensitive paths
  • AIDE / Tripwire file integrity baselines
  • rkhunter and chkrootkit sweeps
  • Brute-force and credential-stuffing blocks
  • Abuse feeds and blocklist integration
  • Alerting on anomalous logins

Incident response

  • Compromise triage within hours
  • Forensic timeline from logs and artefacts
  • Evidence preserved before remediation
  • Persistence removal — cron, systemd, preload
  • Planted authorized_keys and kernel modules
  • Rebuild vs surgical clean decision
  • Full credential rotation after breach
  • Written post-incident report

Malware cleanup

  • Webshell and dropper removal
  • Crypto-miner eradication and prevention
  • Reverse shell and C2 beacon hunting
  • ClamAV, Maldet, Imunify scans
  • Infected WordPress / Magento cleanup
  • Phishing kit takedown from web roots
  • Spam outbreak containment
  • Reinfection prevention hardening

Web servers

  • nginx, Apache, OpenLiteSpeed, Caddy
  • HAProxy and Traefik load balancing
  • Reverse proxy and Varnish caching
  • vhosts, rewrites, redirect loops
  • Rate limiting and bot blocking
  • ModSecurity / Coraza WAF rules
  • HTTrack and scraper defence
  • HTTP/2 and HTTP/3 enablement

TLS & certificates

  • Let’s Encrypt issuance and renewal
  • ACME DNS-01 and wildcard certificates
  • Mutual TLS (mTLS) between services
  • Cipher suites and protocol hardening
  • HSTS, OCSP stapling, chain repair
  • Certificate expiry monitoring
  • Commercial certificate installation
  • Mixed-content and redirect fixes

HTTP security

  • Content-Security-Policy design
  • Frame, referrer and permissions policy
  • CORS allowlists that are not wildcards
  • Secure and SameSite cookie flags
  • Server banners and version leakage
  • Admin paths hidden or IP-restricted
  • security.txt and well-known hygiene
  • Header scoring verification

App runtimes

  • PHP-FPM pools, isolation, tuning
  • PHP 7.4 → 8.5 upgrades, opcache
  • Node.js under PM2 or systemd
  • Python gunicorn / uvicorn services
  • Java, Tomcat, .NET and Go binaries
  • Supervisor and process managers
  • cron converted to systemd timers
  • Per-user resource limits

MySQL & MariaDB

  • InnoDB buffer and I/O tuning
  • Slow query analysis and indexing
  • Primary–replica replication setup
  • Corrupted table repair and recovery
  • Major version upgrades
  • mysqldump and XtraBackup strategies
  • Remote access lockdown, credential rotation
  • Accidental DROP recovery from binlogs

PostgreSQL & Redis

  • PostgreSQL memory and autovacuum tuning
  • WAL archiving and point-in-time recovery
  • Streaming replication and PgBouncer
  • pg_hba and listen address lockdown
  • Redis AUTH, binding, persistence
  • Eviction policy and memory limits
  • MongoDB, Elasticsearch, OpenSearch basics
  • Encrypted database traffic

Mail & deliverability

  • Postfix, Exim and Dovecot hardening
  • SPF, DKIM, DMARC and BIMI
  • MTA-STS, TLS-RPT, rDNS alignment
  • Open relay closure
  • Blacklist delisting requests
  • rspamd / SpamAssassin tuning
  • Mail queue surgery under load
  • Mailbox migration with imapsync

DNS

  • BIND, PowerDNS and Knot administration
  • Zone design and record cleanup
  • DNSSEC signing and key rollover
  • Cloudflare and Route 53 integration
  • Secondary / slave DNS resilience
  • TTL planning for migrations
  • Glue and NS consistency checks
  • Open resolver closure

Storage & disks

  • Disk and inode exhaustion rescue
  • LVM growth and filesystem resize
  • ZFS, Btrfs, mdadm RAID administration
  • SMART health and failing disk swaps
  • Quotas, log rotation, journal growth
  • Permission and ownership repair
  • LUKS encryption at rest
  • Runaway file growth hunting

Backups & DR

  • restic, Borg, rsync, rclone pipelines
  • Offsite copies to S3, B2 or SFTP
  • 3-2-1 strategy and key escrow
  • Immutable, ransomware-resistant backups
  • Restore drills that actually get run
  • RPO / RTO defined with you
  • Bare-metal and snapshot recovery
  • Disaster recovery runbooks

Performance

  • Load, CPU steal and OOM diagnosis
  • Memory, swap and zram tuning
  • I/O bottleneck identification
  • sysctl, TCP and kernel tuning
  • perf, strace and bpftrace profiling
  • Slow website end-to-end debugging
  • Object, page and CDN caching
  • Worker sizing for real traffic

Patching & upgrades

  • unattended-upgrades and dnf-automatic
  • Kernel live patching where available
  • CentOS 7 → AlmaLinux / Rocky migration
  • Ubuntu LTS and Debian dist-upgrades
  • Package pinning and repo hygiene
  • Third-party repository risk review
  • Reboot windows planned with you
  • EOL software replacement plans

Monitoring

  • Prometheus, node_exporter, Grafana
  • Zabbix, Netdata, Uptime Kuma
  • Log shipping to Loki or ELK
  • Alerts to Telegram, email or Slack
  • Disk, load, service-down thresholds
  • Certificate expiry and domain checks
  • Synthetic HTTP and TCP probes
  • Backup freshness monitoring

Containers

  • Docker and Compose hardening
  • Rootless Docker where feasible
  • Image CVE scanning and registries
  • k3s and kubeadm cluster basics
  • Ingress, secrets, resource limits
  • Privileged mode and mount review
  • Container escape exposure assessment
  • Volume backup and image pruning

Automation & IaC

  • Ansible hardening playbooks
  • Terraform for cloud resources
  • cloud-init and golden images
  • Bash and Python operational tooling
  • CI/CD deployment over SSH
  • Secrets with Vault, SOPS or age
  • Idempotent baselines across a fleet
  • Configuration under version control

Compliance evidence

  • CIS benchmark assessment and remediation
  • Lynis and OpenSCAP reports
  • Cyber Essentials technical controls
  • ISO 27001 supporting evidence
  • GDPR-minded log retention
  • Periodic access reviews
  • Runbooks and asset inventory
  • Penetration-test remediation support

Cloud instances

  • AWS EC2 / Lightsail, Azure, GCP VMs
  • Hetzner, OVH, DigitalOcean, Linode
  • Vultr, Contabo and budget VPS estates
  • IMDSv2 and metadata hardening
  • Snapshots, images and floating IPs
  • Provider firewall alignment
  • Rescue-mode recovery of dead instances
  • Migration between providers

CMS & applications

  • WordPress and WooCommerce hardening
  • WP-CLI cleanup and bulk operations
  • Magento, PrestaShop, OpenCart
  • Joomla, Drupal, Laravel, Django
  • Staging environments and git deploys
  • wp-config, uploads and cron lockdown
  • Abandoned plugin and theme removal
  • Cache purging and asset optimisation

Voice, game & media

  • Asterisk, FreePBX, FusionPBX exposure
  • SIP brute-force and toll-fraud defence
  • Game server hosts and Minecraft
  • TeamSpeak and self-hosted voice
  • Plex and Jellyfin media servers
  • Home Assistant and IoT gateways
  • Tor / open-proxy abuse detection
  • Unintended public service closure

AI voice, email & chat NEW

  • Receptionist-grade AI across phone, email and chat
  • Stripe / billing lookup — invoices, plans, payments
  • CRM & helpdesk hooks — tickets, orders, shipments
  • AI Calling Assistant — inbound and outbound voice
  • AI Auto Processor — classify, draft, route, escalate
  • AI Chat — same knowledge on your site widget
  • Human handoff when the case needs a person
  • Prompts, tools, logging and QA review included

Emergencies

  • Server will not boot
  • Locked out of SSH
  • Forgotten root password recovery
  • Disk full, site down
  • Active ransomware containment
  • DDoS mitigation at host and edge
  • Hacked site restored under pressure
  • Provider abuse notice response

Control panels & platforms

Panel access is welcome too — we work inside DirectAdmin, cPanel, Plesk, aaPanel and the rest, or take you off them entirely if the licence is not earning its keep.

DirectAdmin

  • Install, licence bind, hostname SSL
  • CustomBuild stack rebuilds
  • Per-user PHP-FPM pools
  • CSF / LFD integration and tuning
  • Reseller and user ACL lockdown
  • Admin backups, restores, retention
  • Port 2222 TLS and access allowlists
  • Account migration in and out

cPanel & WHM

  • EasyApache 4 profile rebuilds
  • MultiPHP, PHP-FPM and handlers
  • cPHulk, ModSecurity, CageFS
  • whmapi1 / UAPI automation
  • AutoSSL and DNS cluster fixes
  • JetBackup jobs and restores
  • Transfer Tool account moves
  • Licence cost exit planning

Plesk Obsidian

  • Subscriptions, plans and resellers
  • plesk CLI and repair utilities
  • Plesk Firewall and Fail2Ban jails
  • WordPress Toolkit hardening
  • Advisor recommendations applied
  • Migration Manager imports
  • Extension audit and cleanup
  • psa database and panel recovery

aaPanel / BT panel

  • Entry point, port and SSL hardening
  • Panel restricted to allowlisted IPs
  • Multi-version PHP and extensions
  • nginx ↔ OpenLiteSpeed switching
  • phpMyAdmin exposure removal
  • Site isolation under separate users
  • Backups off the box, not just local
  • Post-CVE incident cleanup

CyberPanel & OLS

  • OpenLiteSpeed vhosts and listeners
  • LiteSpeed Cache configuration
  • Known CVE patching, urgent
  • Admin URL and port hardening
  • Snapshots and incremental backups
  • PowerDNS and mail integration
  • ACL and package limits
  • Post-exploit rebuild planning

HestiaCP & VestaCP

  • VestaCP end-of-life risk assessment
  • VestaCP → HestiaCP migration
  • v- CLI scripts and templates
  • Exim / Dovecot mail stack repair
  • Let’s Encrypt for sites and panel
  • Firewall and fail2ban defaults
  • Quota and package enforcement
  • Legacy CentOS 7 rebuild advice

CloudPanel & RunCloud

  • CloudPanel install and site isolation
  • nginx vhosts and PHP-FPM pools
  • RunCloud agent and stack setup
  • Git webhooks and deploy scripts
  • Queue workers and supervisors
  • Firewall and SSH hardening
  • Backups to remote destinations
  • Migration from aaPanel or cPanel

Forge, Ploi & GridPane

  • Laravel Forge server provisioning
  • Ploi sites, daemons and workers
  • GridPane WordPress stacks and cache
  • SpinupWP and ServerAvatar estates
  • Zero-downtime deployment setup
  • Redis object cache and FastCGI
  • Per-site system user isolation
  • Incident response on managed hosts

Virtualmin, ISPConfig, CWP

  • Webmin / Virtualmin hardening
  • ISPConfig multi-server setups
  • CentOS Web Panel security review
  • Froxlor, KeyHelp, Enhance, Ajenti
  • Jailkit and chroot SSH options
  • Panel interface exposure lockdown
  • Backup and rescue scripting
  • Migration onto maintained panels

Docker platforms

  • Portainer exposure and RBAC
  • Coolify install and app deploys
  • CapRover and Dokku production setup
  • Compose stacks and persistent volumes
  • Traefik / Caddy TLS termination
  • Registry credentials and image hygiene
  • Disk growth and image pruning
  • Post-exposure hardening

Proxmox & hypervisors

  • Proxmox VE install, cluster, storage
  • VM and LXC provisioning, templates
  • ZFS, Ceph and NFS datastores
  • Proxmox Backup Server integration
  • VMware ESXi hardening baselines
  • XCP-ng and Xen Orchestra backups
  • Management network isolation
  • IPMI / iLO out-of-band lockdown

Backup platforms

  • JetBackup jobs, destinations, restores
  • Acronis Cyber Protect agents
  • R1Soft disk-safes and bare-metal restore
  • Proxmox Backup Server datastores
  • restic / Borg alongside panels
  • Pre-backup database dumps
  • Encryption keys held safely
  • Monthly verified restore drills

Security add-ons

  • Imunify360 and ImunifyAV
  • CSF / LFD and ConfigServer tools
  • Maldet (LMD) and ClamAV
  • Wazuh agents and file integrity
  • CrowdSec scenarios and bouncers
  • Patchman CMS vulnerability patching
  • False-positive tuning that keeps sites up
  • Conflicting WAF resolution

Panel migrations

  • cPanel → DirectAdmin or Plesk
  • Plesk → CyberPanel or clean nginx
  • aaPanel → CloudPanel rebuilds
  • VestaCP → HestiaCP moves
  • Mail-first cutover with dual MX
  • TTL planning and rollback window
  • Cron, PHP path and SSL remapping
  • Post-move smoke tests

Panel exposure hardening

  • Admin ports behind WireGuard or VPN
  • IP allowlists on every panel
  • Default entry points and ports changed
  • Two-factor on all admin accounts
  • Brute-force lockout configured
  • phpMyAdmin and webmail off the internet
  • Stale admin and reseller accounts removed
  • Alerting on panel login anomalies

Licences & consolidation

  • cPanel licence cost assessment
  • Cheaper panel or de-panelled options
  • Multi-server consolidation plans
  • Unused CloudLinux / Imunify seats dropped
  • Right-sizing VPS after migration
  • Reseller and white-label review
  • Runbooks replacing GUI clicking
  • Written cost-saving summary

24-hour SLA

Audit answer, decision and approved fixes — not a PDF that sits unread.

  1. Access — you grant SSH (key-based preferred) and a short scope note.
  2. Free audit answer — findings delivered within 24 hours, at no charge.
  3. Decision — we recommend what to fix now vs later; you approve.
  4. Implementation — approved remediations applied in the same 24-hour window for critical items (paid packages).
Two engagement models

One-off: free initial audit, then harden if you approve — or leave a retainer open. Monthly: continuous care under subscription — checks, patches, and a priority channel.

Pricing in £

UK SME assessments commonly run £3,000–£8,500+ one-off (day rates ~£1,000–£1,500). Network engineers contract at ~£480–£800/day. Managed retainers often sit at £2,000–£4,500+/mo. I aim for roughly half of that — and the initial audit is free. You only pay when we move to hardening or care.

Base currency · today’s mid-market rates

SSH & servers

Deep Server Review

Multi-service / multi-vhost hosts, mail/voice/DB exposure, re-check.

£2,990one-off · market ~£6–8k

Network & edge ≈ half UK day-rate packages

MikroTik Secure Setup

RouterOS hardening, firewall filter, VPN, Winbox lockdown, firmware hygiene.

£990one-off · market ~£2,000

Cisco Switch / Router

IOS / IOS-XE / ASA-class baselines: AAA, ACLs, SNMP, management plane.

£1,790one-off · market ~£3,500

HP / Aruba Edge

Aruba / ProCurve / HPE switches and Instant On — secure management and access.

£1,490one-off · market ~£3,000

Intranet & LAN Segmentation

VLANs, inter-VLAN ACLs, guest / IoT isolation, intranet services kept private.

£1,990one-off · market ~£4,000

Multi-vendor Network Sweep

End-to-end review across MikroTik, Cisco, HP/Aruba, UniFi and the firewall edge.

£2,490one-off · market ~£5,000

Network Watch

Monthly edge checks: firmware, VPN health, VLAN drift, exposed management.

£490per month · market ~£1,000

Retainers

Watch & Patch

Monthly posture checks, patch watch, ticket channel, 24h SLA.

£990per month · market ~£2,000

AI services NEW receptionist stack · Stripe / books · voice · email · chat

Not a chatbot toy — a full front-desk product. We wire Calling, Email Auto Processor and Chat to your Stripe (or other accounting / CRM): the AI can recognise the customer, check invoices and plans, answer status questions, take requests and hand off to a human when needed. Same brain on phone, mailbox and website — so it can stand in for a receptionist without losing the books.

AI stack configuration

Prompts, Stripe / CRM tools, telephony, IMAP, chat widget, escalation paths and logging — so usage stays lean and the assistant actually knows your business.

£490from · calling / email / chat wiring

Team A–Z

Operators and engineers across six countries — coverage that follows the sun.

Australia China Lithuania Singapore United Kingdom United States

Contact

Tell me what is exposed and I will reply within the SLA.

Remote cyber security via SSH

AURIUS INTERNATIONAL LTD delivers boutique server security over SSH: audits, hardening, remediation and monthly care. Findings, decision and approved critical fixes within 24 hours. Contact via the form at https://aurius.uk/#contact. Address: Forth House, Rutland Square, Edinburgh, EH1 2BW, United Kingdom.

Pricing (GBP, ~half UK market)

PlanPrice
Initial Security AuditFree
Hardening Engagement£2,490 one-off
Deep Server Review£2,990 one-off
Watch & Patch£990 / month
Always-on Care£1,490 / month

Initial audit is free — you only pay if we proceed to hardening, network work or a retainer.

What we do over SSH

SSH/keys/fail2ban; firewall; nginx/OLS/Apache/PHP-FPM; TLS; open ports; cron/systemd; disk and backups; incident cleanup and hardening rollouts. Team countries A–Z: Australia, China, Lithuania, Singapore, United Kingdom, United States.

Full capability list

Control panels and platforms

Canonical links