Protect Your Infrastructure Before It Becomes a Problem.
Hardening · Firewall & WAF · Vulnerability Management · Malware Removal · Monitoring
Emergency incident response and malware cleanup are available to anyone — whether or not your server is hosted with eWebGuru or covered by a support plan.
Or call 8800334921 — tell us it's a security incident.
A well-written application can still be exposed by a poorly configured server, unnecessary open ports, outdated software or a shared administrative password. Most compromises we see are not clever attacks on application code — they are old software, weak access control and services that should never have been reachable from the internet.
Our security services focus on that infrastructure layer: the servers, cloud resources, network and supporting services your applications run on. You get practical controls implemented and maintained, without building a security team of your own.
Before implementing controls, we assess what you have. The assessment is free, and the report is yours whether or not you proceed.
Default configurations are rarely production-ready. We review and tighten SSH and RDP, root and administrator access, permissions, services and login controls.
Server firewalls, cloud security groups, network ACLs, port restrictions, IP allowlists and periodic rule reviews so old rules don't outlive their purpose.
WAF deployment and rule tuning, rate limiting, IP blocking, bot control where supported, and investigation of false positives.
Version review, vulnerability scanning, risk ranking, remediation and verification — not just a report handed over for someone else to action.
Investigation of suspicious files and processes, compromise assessment, cleanup and post-cleanup hardening, plus ongoing detection where supported.
Least-privilege access, SSH key authentication, MFA where supported, administrator review, removal of stale accounts and access logging.
Security groups, IAM permissions, public exposure, storage permissions, logging and encryption settings across AWS, Azure and Google Cloud.
Failed logins, suspicious authentication, unexpected processes, firewall events and critical configuration changes, with agreed response times.
The work itself — operating system, perimeter, access and data, and the cloud control plane.
Hardening is a configuration exercise, done with an understanding of what the application actually needs. We close what isn't needed and control what is.
Every hardening change is agreed before it's applied, because a control that breaks your application is not a security improvement.
Controlling what can reach your infrastructure is the foundation. Beyond that sits application-layer filtering and, where the risk justifies it, dedicated attack protection.
Where dedicated DDoS protection is required, the appropriate cloud or third-party service is built into the architecture rather than improvised mid-attack.
Administrative access is the most common route into a server, and databases and mail are where the damage usually lands.
Already on eWebGuru hosting? Free SSL via AutoSSL is included there — the SSL work above is for servers and environments hosted elsewhere.
Cloud security is more than securing the operating system. Most cloud incidents come from the control plane: over-permissive IAM, public storage and security groups open to the world.
For full day-to-day administration of an AWS environment: Managed AWS Services
Available to anyone, hosted anywhere, with or without a support plan. Quoted per incident after a short triage so you know the cost before work starts.
We identify suspicious processes, accounts, files and activity, and establish how far the compromise reaches.
With your authorisation, we restrict affected access and stop the compromise spreading further.
Malicious files, backdoors and unauthorised access are removed from the affected systems.
We fix the weakness that allowed the incident, because cleanup without that just resets the clock.
Monitoring is increased after remediation to catch any persistence we haven't seen yet.
Services are restored from clean systems or backups where a rebuild is safer than a cleanup.
Security isn't a one-time configuration exercise. A server hardened last year drifts: packages age, rules get added for a quick fix and never removed, accounts outlive the people who used them. Security event monitoring catches the activity that indicates a problem, and the configuration changes that quietly create one.
Response times for security events are set in your service schedule. Suggested starting point: [30 minutes] for a confirmed active compromise, [4 hours] for suspicious activity needing investigation.
This is security event monitoring, which is different from the availability monitoring in our management plans — that watches whether your server is up, this watches whether something is wrong.
Some security work is already included in Server Management and Managed AWS. Here's exactly where the line sits.
| Routine OS security patching | In your management plan |
| Basic firewall rules and port management | In your management plan |
| Availability and resource monitoring | In your management plan |
| IAM users and MFA enforcement (AWS) | In Managed AWS |
| Full hardening project, Linux or Windows | Security Services |
| Vulnerability scanning and remediation | Security Services |
| Web Application Firewall | Security Services |
| Security event monitoring | Security Services |
| Malware cleanup and incident response | Security Services |
| Cloud control-plane security review | Security Services |
| Backup policy, retention and restore testing | Backup & DR |
Infrastructure security is not the same as application security or regulatory compliance. We'd rather say so up front than have it discovered later.
Where these are needed, they can be scoped as separate projects or delivered through specialist partners.
Your infrastructure doesn't have to be hosted with eWebGuru.
Start with the free assessment. Fix what it finds. Keep it that way only if you want to.
Fees exclude 18% GST. Emergency incident response and malware cleanup are available separately, quoted per incident after triage, to customers and non-customers alike.
We're not a consultancy that writes security reports. We operate hundreds of production virtual machines behind enterprise firewalls in Tier-IV facilities, and handle hardening, patching and malware cleanups as routine work.
Enterprise firewalls, outbound abuse monitoring, malware detection and hardening across our own production infrastructure since 2007 — the same practices we apply to your servers.
Security administration for both platforms from one team, which matters when a compromise crosses a mixed environment.
Security configuration across AWS, Azure and Google Cloud — including the control-plane mistakes that cause most cloud incidents.
A vulnerability report nobody actions changes nothing. We prioritise findings and implement the remediation ourselves.
Security recommendations are made with an understanding of how production systems actually run, so controls don't break the application they protect.
Migration, server management, cloud, security and recovery handled by the same team, so nothing falls between vendors.
Move it, automate it, operate it, protect it, recover it — six services, no overlap.
| Secure servers, cloud and infrastructure | Security |
| Ongoing Linux or Windows server administration | Server Management |
| Ongoing AWS infrastructure management | Managed AWS |
| Move existing workloads to the cloud | Cloud Migration |
| CI/CD and infrastructure automation | DevOps |
| Backup, disaster recovery and recovery planning | Backup & DR |
Tested backups and recovery planning — what makes a clean rebuild possible after a compromise.
ExploreDay-to-day Linux and Windows administration, including routine security patching.
ExploreThe full Managed Infrastructure Services range in one place.
ExploreDon't wait for an incident to expose a weakness. Let us assess your infrastructure, rank what we find by severity and fix what matters most first.
Security incident in progress? Call 8800334921 or 9711048349 · WhatsApp 9711048349
AWS, Microsoft Azure, Windows Server, Google Cloud and other product names are trademarks of their respective owners. eWebGuru is an independent service provider and is not affiliated with or endorsed by any of these companies.