Remote cyber security via SSH
AURIUS INTERNATIONAL LTD delivers boutique server security over SSH: audits, hardening, remediation and monthly care. Findings, decision and approved critical fixes within 24 hours. Contact via the form at https://aurius.uk/#contact. Address: Forth House, Rutland Square, Edinburgh, EH1 2BW, United Kingdom.
Pricing (GBP, ~half UK market)
| Plan | Price |
|---|---|
| Initial Security Audit | Free |
| Hardening Engagement | £2,490 one-off |
| Deep Server Review | £2,990 one-off |
| Watch & Patch | £990 / month |
| Always-on Care | £1,490 / month |
Initial audit is free — you only pay if we proceed to hardening, network work or a retainer.
What we do over SSH
SSH/keys/fail2ban; firewall; nginx/OLS/Apache/PHP-FPM; TLS; open ports; cron/systemd; disk and backups; incident cleanup and hardening rollouts. Team countries A–Z: Australia, China, Lithuania, Singapore, United Kingdom, United States.
Full capability list
- SSH hardening, key-only auth, SSH certificate authorities, TOTP/FIDO2, bastion hosts, SFTP chroot, session recording
- Users and privileges: sudoers audit, PAM policy, LDAP/FreeIPA/Active Directory, setuid and capability audits
- Firewalling: nftables, iptables, UFW, firewalld, cloud security groups, listener inventory, IPv6 exposure cleanup
- Private networking: WireGuard, OpenVPN, IPsec/strongSwan, Tailscale, Netbird, egress filtering, tcpdump analysis
- Intrusion defence: fail2ban, CrowdSec, auditd, AIDE, Tripwire, rkhunter, chkrootkit
- Incident response: compromise triage, forensic timeline, persistence removal, credential rotation, post-incident report
- Malware cleanup: webshells, crypto-miners, reverse shells, phishing kits, infected WordPress and Magento, spam outbreaks
- Web servers: nginx, Apache, OpenLiteSpeed, Caddy, HAProxy, Traefik, Varnish, ModSecurity and Coraza WAF, bot blocking, HTTP/2 and HTTP/3
- TLS: Let’s Encrypt, ACME DNS-01, wildcards, mTLS, cipher hardening, HSTS, OCSP stapling, expiry monitoring
- HTTP security headers: Content-Security-Policy, frame and referrer policy, CORS, cookie flags
- App runtimes: PHP-FPM tuning, PHP 7.4–8.5 upgrades, Node.js/PM2, Python gunicorn and uvicorn, Java, .NET, Go, systemd services
- Databases: MySQL and MariaDB tuning and replication, PostgreSQL PITR and PgBouncer, Redis hardening, MongoDB, Elasticsearch
- Mail: Postfix, Exim, Dovecot, SPF, DKIM, DMARC, BIMI, MTA-STS, blacklist delisting, queue surgery, imapsync migrations
- DNS: BIND, PowerDNS, Knot, DNSSEC, secondary DNS, TTL cutover planning
- Storage: LVM, ZFS, Btrfs, mdadm RAID, SMART, quotas, LUKS, disk and inode exhaustion rescue
- Backups and disaster recovery: restic, Borg, rsync, rclone, S3 and B2 offsite, immutable targets, verified restore drills, RPO/RTO
- Performance: load and OOM diagnosis, sysctl and TCP tuning, perf, strace, bpftrace, caching and CDN offload
- Patching: unattended-upgrades, kernel live patching, CentOS 7 to AlmaLinux, Ubuntu LTS and Debian upgrades
- Monitoring: Prometheus, Grafana, Zabbix, Netdata, Uptime Kuma, Loki, ELK, Telegram and email alerting
- Containers: Docker and Compose hardening, rootless Docker, image scanning, k3s and kubeadm, ingress and secrets
- Automation: Ansible, Terraform, cloud-init, CI/CD over SSH, Vault, SOPS, age
- Compliance: CIS benchmarks, Lynis, OpenSCAP, Cyber Essentials, ISO 27001 evidence, access reviews
- Cloud: AWS, Azure, GCP, Hetzner, OVH, DigitalOcean, Linode, Vultr, Contabo, IMDSv2 hardening, rescue-mode recovery, provider migration
- CMS: WordPress, WooCommerce, Magento, PrestaShop, OpenCart, Joomla, Drupal, Laravel, Django, staging and git deploys
- Voice and media: Asterisk, FreePBX, FusionPBX, game servers, TeamSpeak, Plex, Jellyfin, Home Assistant
- Emergencies: boot failure, SSH lockout, forgotten root password, full disk, ransomware, DDoS, hacked site restoration
Control panels and platforms
- DirectAdmin: CustomBuild, per-user PHP-FPM, CSF/LFD, reseller ACLs, backups, port 2222 hardening, migrations
- cPanel and WHM: EasyApache 4, MultiPHP, cPHulk, ModSecurity, CageFS, whmapi1, AutoSSL, JetBackup, licence-cost exits
- Plesk Obsidian: plesk CLI, Plesk Firewall, Fail2Ban, WordPress Toolkit, Advisor, Migration Manager, psa recovery
- aaPanel and BT panel: entry point and port hardening, IP allowlists, multi-PHP, phpMyAdmin exposure removal, offsite backups
- CyberPanel and OpenLiteSpeed: LiteSpeed Cache, CVE patching, admin hardening, snapshots
- HestiaCP and VestaCP: end-of-life risk review, migration to HestiaCP, mail stack repair
- CloudPanel, RunCloud, ServerAvatar, GridPane, SpinupWP, Ploi, Laravel Forge, Cloudways
- Webmin and Virtualmin, ISPConfig, CentOS Web Panel, Froxlor, KeyHelp, Enhance, Ajenti
- Docker platforms: Portainer, Coolify, CapRover, Dokku
- Hypervisors: Proxmox VE, Proxmox Backup Server, VMware ESXi, XCP-ng, oVirt
- Backup and security add-ons: JetBackup, Acronis, R1Soft, Imunify360, CSF, Maldet, ClamAV, Wazuh, CrowdSec, Patchman
- Cross-panel migrations and de-panelling to a clean nginx or Docker stack, plus licence cost reduction