Someone told you your system is not secure. It was probably not a hacker. It was an insurance renewal form asking which software versions you run, or a customer’s IT department sending a security questionnaire before signing, or a consultant who looked at your site for ten minutes.
Your first reaction is reasonable: is this real, or is somebody selling something?
It is usually real, and it is usually not as dramatic as it sounds.
What “not secure” almost always means
Nine times in ten it means one specific thing: you are running a version of some software that no longer receives security fixes.
Here is the mechanism, in plain terms. Your system is built on other software — the language it is written in, the pieces other people wrote that it uses, the server it sits on. Each of those is maintained by someone for a few years. During that time, when a flaw is found, they publish a fix and you install it.
Then support ends. The flaws keep being found, because researchers keep looking. They get published, in public, with details. But no fix is ever released for your version. Every published flaw after that date is a permanently open door.
Your system does not change on that date. Nothing breaks. It just stops being defended, silently, and the number of known ways in grows every month.
The second thing “not secure” can mean is that the software is current but configured badly — a database reachable from the internet, a test copy of your site still visible to the public, an administration screen with no protection on it. These are usually quick to fix once someone has looked.
Why they know, and why you can check too
Something that surprises most owners: nobody needed inside access to work this out.
Web servers announce information about themselves to anyone who asks. Search engines index that. There are services that keep a running list of what every public web address appears to be running. It takes under a minute to look up a company and get a decent picture of how old their software is.
That is uncomfortable, but it cuts both ways: everything they can read, you can read. The fastest route is not a tool at all — your hosting company can tell you which versions the account runs and whether they still receive fixes, in writing, for free.
If it comes back clean, you have spent two minutes and can answer the questionnaire honestly. If it does not, you now know the specific thing to fix rather than a vague sense of unease.
What to do first, in order
Find out what you are running. Everything else depends on this. Guessing produces either panic or false comfort.
Get a test copy and working backups before changing anything. This is the step people skip and regret. Security work means changing versions, and changing versions on a live system with no way back is how a security problem becomes an outage. Backups that have never been restored are not backups; they are a hope. The first thing worth paying for is the ability to undo.
Update the things with published holes, oldest first. Not everything at once. Step by step, each one live and checked before the next. If something goes wrong you are one small step back, not a month back.
Put a shield in front of the site. A modern hosting setup includes a layer that filters obvious attacks before they reach your system. This does not fix an unpatched version — do not let anyone tell you it does — but it removes a large volume of automated noise and buys time while the real work happens.
Then keep it that way. This is the part that determines whether you are back here in three years. Security is not a project with an end. Something has to install the patches every month, and someone has to be told when it goes wrong.
About the questionnaire in front of you
If a customer or insurer is waiting on an answer, you do not need everything fixed to respond well. What they are assessing is whether you know the state of your own systems and have a plan. “We are on version X, we have identified the gaps, here is our schedule for closing them” is a substantially better answer than silence, and often better than a vague claim of being secure.
What you want in hand is a written document that describes the current state honestly and what happens next. That is exactly what the audit produces, and it is written to be handed to someone else — your insurer, your customer, or a different developer.
What it costs to know
Five business days and $2,400, fixed. You get a written report in plain language covering what you have, what is dangerous, what it costs to fix, and which items actually matter versus which are theoretical. You own it. If you take it to a different developer, it is immediately useful to them.
Making a system safe to touch — backups, alarms, a test copy — starts at $6,000 and takes two to three weeks. Ongoing monthly care covers the patching so this does not silently return. Everything is priced here.
If we look and conclude that your system is in reasonable shape, you get that in writing. That happens, and it is a legitimate outcome — you have paid to stop worrying, which is cheaper than the alternative.
What this is not
It is not a reason to rebuild. Rebuilding is what tends to get proposed to an owner who has just been frightened, and it is almost always the wrong answer. Your system encodes years of how your business actually works. Replacing what has rotted underneath it is a fraction of the cost and carries a fraction of the risk.
It is also not an emergency in the sense of dropping everything today. It is a thing with a known shape, a known order of operations, and a known price.