Security engineering

Security that considers the application, infrastructure and the way people operate it.

We help businesses reduce risk across web applications and eCommerce platforms through technical review, patching, hardening, code assessment, access controls and incident support. Security is treated as an operating discipline rather than a one-off scanner report.

The bigger picture

Start with the business and technical reality

Web security failures frequently cross boundaries. An outdated extension can provide the entry point, weak server permissions can increase impact, and poor monitoring can allow compromise to remain undetected. Cleaning one malicious file without understanding the path of entry leaves the original risk in place.

Our work considers application code, dependencies, admin access, deployment, hosting, logs, backups and third-party services. For Magento, patch status, extension quality, admin exposure and filesystem integrity are particularly important alongside the wider server environment.

Where an incident has already occurred, containment and evidence preservation come before cosmetic cleanup. The recovery plan then needs to reduce the chance of immediate reinfection.

Typical situations

When clients bring us in

  • A site has been compromised or modified unexpectedly
  • Magento or plugin patching has fallen behind
  • The business wants an independent security review
  • Admin accounts or permissions have grown without governance
  • Hosting was migrated and hardening was never reviewed
  • A development supplier has left and access needs to be audited
The objective

What good delivery should leave behind

A successful engagement should improve more than the immediate feature or incident. It should make the system easier to understand, safer to change and more visible to the people responsible for operating it.

  • Clear technical ownership and responsibilities
  • Maintainable code and configuration
  • Visible failures rather than silent data loss
  • Controlled release and recovery paths
  • Documentation for future developers and operators
  • A sensible next-step roadmap rather than permanent firefighting
What the work covers

Technical depth across the parts that matter

The exact scope depends on the existing environment and commercial priorities. We focus on the areas that materially affect reliability, maintainability and delivery rather than adding process for its own sake.

Application review

Assess code, extensions, dependencies and exposed functionality for practical risk.

Patch & dependency posture

Identify outdated components and plan updates with regression risk in mind.

Access

Review admin users, SSH, API credentials, service accounts and least-privilege expectations.

Infrastructure

Assess file permissions, web server, PHP, database exposure, firewall/CDN controls and backups.

Detection

Use logs, integrity checks and monitoring to identify suspicious changes or behaviour.

Incident recovery

Contain, investigate, clean, patch and validate before returning systems to normal operation.

Problems we look for

Common failure patterns that create unnecessary cost

Many technical problems are recurring patterns rather than isolated defects. Identifying them early helps avoid repeatedly paying to treat the visible symptom.

  • Removing malware without finding persistence
  • Old admin or supplier accounts left active
  • Shared credentials with no audit trail
  • Backups that have never been tested for recovery
  • Security tools generating alerts nobody reviews
  • Patches postponed because deployment confidence is low
How we work

A controlled route from uncertainty to production

We prefer visible, reviewable delivery. The exact sequence changes with the project, but the principle is to reduce uncertainty early and keep each production change understandable.

01Establish scope and urgency
02Preserve evidence where incident response is required
03Review application and access paths
04Prioritise exploitable risk
05Remediate and test changes
06Improve monitoring and recovery readiness
Engineering judgement

Technology is part of the answer, not the starting question

No web platform can be made risk-free. The goal is layered defence, reduced exposure, useful detection and a practical recovery route. Security work should also respect availability: a rushed production patch that breaks checkout is not a good security outcome.

Where specialist capability comes from our wider engineering team, we are transparent about the proposed delivery model and match the person or team to the actual requirement rather than presenting a long list of technologies as if every project needs all of them.

Delivery models

Use the level of ownership that fits your team

Defined project

Midoriweb owns an agreed scope with clear milestones, acceptance criteria and release responsibilities.

Specialist workstream

Bring us into one technically difficult area while your existing team or agency owns the wider programme.

Team augmentation

Add developers to your existing process for a fixed period or an ongoing roadmap.

Ongoing technical partner

Combine support, maintenance, monitoring and planned improvement under continuing technical ownership.

Frequently asked questions

Questions worth answering before work starts

Can you clean a hacked Magento site?

We can assist with investigation and remediation subject to access and scope, including identifying persistence, vulnerable components and required hardening.

Do you provide penetration testing?

We can perform technical security review and coordinate specialist testing where a formal penetration-test scope or certification is required.

Can you review third-party extensions?

Yes. Extension quality, update status and unnecessary attack surface are important parts of platform review.

Do you manage patching?

Yes. Patch management can be part of ongoing maintenance and support.

Can you help after an incident if another provider manages hosting?

Yes. We can coordinate with the host and other suppliers while focusing on application and technical evidence.

Should security be ongoing?

Yes. Dependencies, access and threats change, so periodic review and monitoring are more effective than one annual exercise.

Related expertise

Continue exploring

Have a requirement in this area?

Send the current situation, desired outcome, platform or systems involved and any important deadline. We can review the detail first or discuss it in a short consultation.