004 Is this you

Someone told me it isn't secure

It usually arrives as a question on a form, not as an incident. That is the good version — you have been warned before anything happened.

Tell us what breaks

Someone told you your system is not secure. It was probably not a hacker. It was an insurance renewal form asking which software versions you run, or a customer’s IT department sending a security questionnaire before signing, or a consultant who looked at your site for ten minutes.

Your first reaction is reasonable: is this real, or is somebody selling something?

It is usually real, and it is usually not as dramatic as it sounds.

What “not secure” almost always means

Nine times in ten it means one specific thing: you are running a version of some software that no longer receives security fixes.

Here is the mechanism, in plain terms. Your system is built on other software — the language it is written in, the pieces other people wrote that it uses, the server it sits on. Each of those is maintained by someone for a few years. During that time, when a flaw is found, they publish a fix and you install it.

Then support ends. The flaws keep being found, because researchers keep looking. They get published, in public, with details. But no fix is ever released for your version. Every published flaw after that date is a permanently open door.

Your system does not change on that date. Nothing breaks. It just stops being defended, silently, and the number of known ways in grows every month.

The second thing “not secure” can mean is that the software is current but configured badly — a database reachable from the internet, a test copy of your site still visible to the public, an administration screen with no protection on it. These are usually quick to fix once someone has looked.

Why they know, and why you can check too

Something that surprises most owners: nobody needed inside access to work this out.

Web servers announce information about themselves to anyone who asks. Search engines index that. There are services that keep a running list of what every public web address appears to be running. It takes under a minute to look up a company and get a decent picture of how old their software is.

That is uncomfortable, but it cuts both ways: everything they can read, you can read. The fastest route is not a tool at all — your hosting company can tell you which versions the account runs and whether they still receive fixes, in writing, for free.

If it comes back clean, you have spent two minutes and can answer the questionnaire honestly. If it does not, you now know the specific thing to fix rather than a vague sense of unease.

What to do first, in order

Find out what you are running. Everything else depends on this. Guessing produces either panic or false comfort.

Get a test copy and working backups before changing anything. This is the step people skip and regret. Security work means changing versions, and changing versions on a live system with no way back is how a security problem becomes an outage. Backups that have never been restored are not backups; they are a hope. The first thing worth paying for is the ability to undo.

Update the things with published holes, oldest first. Not everything at once. Step by step, each one live and checked before the next. If something goes wrong you are one small step back, not a month back.

Put a shield in front of the site. A modern hosting setup includes a layer that filters obvious attacks before they reach your system. This does not fix an unpatched version — do not let anyone tell you it does — but it removes a large volume of automated noise and buys time while the real work happens.

Then keep it that way. This is the part that determines whether you are back here in three years. Security is not a project with an end. Something has to install the patches every month, and someone has to be told when it goes wrong.

About the questionnaire in front of you

If a customer or insurer is waiting on an answer, you do not need everything fixed to respond well. What they are assessing is whether you know the state of your own systems and have a plan. “We are on version X, we have identified the gaps, here is our schedule for closing them” is a substantially better answer than silence, and often better than a vague claim of being secure.

What you want in hand is a written document that describes the current state honestly and what happens next. That is exactly what the audit produces, and it is written to be handed to someone else — your insurer, your customer, or a different developer.

What it costs to know

Five business days and $2,400, fixed. You get a written report in plain language covering what you have, what is dangerous, what it costs to fix, and which items actually matter versus which are theoretical. You own it. If you take it to a different developer, it is immediately useful to them.

Making a system safe to touch — backups, alarms, a test copy — starts at $6,000 and takes two to three weeks. Ongoing monthly care covers the patching so this does not silently return. Everything is priced here.

If we look and conclude that your system is in reasonable shape, you get that in writing. That happens, and it is a legitimate outcome — you have paid to stop worrying, which is cheaper than the alternative.

What this is not

It is not a reason to rebuild. Rebuilding is what tends to get proposed to an owner who has just been frightened, and it is almost always the wrong answer. Your system encodes years of how your business actually works. Replacing what has rotted underneath it is a fraction of the cost and carries a fraction of the risk.

It is also not an emergency in the sense of dropping everything today. It is a thing with a known shape, a known order of operations, and a known price.

0FQ Questions people ask

Questions people ask about this

Have I already been broken into?

Running unsupported software does not mean you were breached. It means the door has been unlocked for a while. Whether anyone walked through is a separate question, and the audit looks for the specific traces that answer it.

Can't I just install an antivirus or a firewall and be done?

A shield in front of the site helps and is worth having. It does not fix the underlying problem, which is that the software itself has known holes with published instructions for using them.

Who told them my software is out of date?

Nobody had to. Web servers announce their version publicly, and there are search engines that index this. Anyone can look up your address in under a minute, without touching it and without you ever knowing.

What if I just do nothing?

Often nothing happens for a long time. The risk is not steady, it is lumpy: a new hole gets published, automated tools sweep the internet for anyone running the affected version, and you are either patched or you are not.

Will fixing this break my site?

It can, if it is done carelessly on the live system with no way back. That is why the first phase is a test copy and working backups, before anything is changed.

0GO If this sounds like you

Tell us what’s actually breaking.

Describe it in your own words. A person reads it and replies within one business day — what we think is happening and whether we’re the right people for it. Free, and a person is what’s at the other end.

Write to us

Or read the numbers first.

Every price is published, with what each one buys, if you would rather see them before talking to anyone. The work section shows what the audits found on real systems, including the parts that did not go well.

Read the work

0WK This, on a real system

What it looked like when we fixed it

Anonymized write-ups of the same problem on systems we were handed: what we found, what we changed, and the part that did not go well.

0RL Related

Other sentences that might sound familiar