Website Security

Incident investigation and recovery

Find how it happened and recover. Removing malware is not enough if the way in is still open. We investigate how the attacker got in, find every foothold they left, close them, recover the site and give you a written report.

Book a free call See our work Fixed quote after a free call

What you get

  • Evidence first
  • Timeline
  • Every foothold
  • Closing the way in
  • Credentials
  • Written report

Sound familiar?

  • The site was cleaned, and the hack came back a few days later.
  • You do not know how the attacker got in, or what they took.
  • A hidden admin account or an unknown plugin appeared.
  • Your host, bank or payment provider is asking what happened.

Who it helps

  • Sites hacked more than once

    Reinfection traced to the foothold the last cleanup missed.

  • Stores and sites with customer data

    A clear picture of what was exposed, to decide what to tell customers.

  • Agencies

    Investigation of a client site, reported under your brand.

What is included

  • Evidence first Files, database and logs preserved before anything is changed
  • Timeline When the attacker got in and what they did, from server logs and file dates
  • Every foothold Admin accounts, application passwords, API keys, scheduled tasks, hidden plugins and changed files
  • Closing the way in The vulnerable plugin, weak login or exposed tool fixed
  • Credentials Passwords and keys rotated with you, including the kinds that survive a password change
  • Written report What happened, what was affected and what was done, in plain words

Not included

  • Legal advice on breach notification (we give you and your lawyer the facts)
  • Recovering data the attacker deleted when no backup exists

Why hacks come back

Attackers rarely leave just one way back in. A cleanup that deletes the visible malware but misses a hidden administrator, an application password, a stolen API key, a scheduled task or a fake plugin that hides itself from the Plugins screen is undone within days. Changing the main password removes none of those. Finding them all is the heart of an investigation.

Evidence before anything is deleted

Once a file is deleted or a log rotates, the story of the attack is gone. We copy the evidence first, then investigate: the server access logs around the time files changed, database records, user accounts and everything that runs on a schedule. The result is a timeline of what happened, which tells us what to close and tells you what may have been exposed.

Built from real incidents

Our own security plugin, Guardian Shield Lite, was built from incidents we investigated in 2026: hidden admin accounts, droppers that restore themselves, browser-side loaders and credential stealers. The same knowledge goes into every investigation.

How it works

  1. Get in touch

    Tell us what you see, and mark it urgent.

    From you: Hosting or cPanel access.
  2. Preserve

    Evidence copied before anything is cleaned.

  3. Investigate

    Logs, files and database examined to rebuild the timeline.

  4. Close and recover

    Footholds removed, the entry point closed, credentials rotated and the site restored.

    From you: Your help rotating passwords only you control.
  5. Report and protect

    A written report, and monitoring so a repeat attempt is caught early.

What affects the price

Every project gets a fixed quote after a free call, so you know the total before anything starts. These are the things that move it.

  • Size of the site and the hosting access available
  • How long the attacker had access
  • Number of sites on the same hosting account
  • Whether logs and backups exist
  • Monitoring afterwards

Where we have done this

WordPress security plugin

Guardian Shield Lite

Our WordPress security plugin: code stays locked, known malware is removed with evidence kept, and every site reports to one hub.

  • Code locked, changes in recorded windows
  • Known malware removed, evidence kept
  • Every site watched from one hub

Questions about incident investigation and recovery.

What is the difference between malware removal and incident recovery?

Malware removal cleans the infection. Incident recovery also finds how the attacker got in, everything they left behind to get back, and what they could reach, then closes it all and reports on it.

Can you tell what data was taken?

Often we can tell what the attacker could reach and what they accessed, from logs and file records. If logs are missing, we say what cannot be known.

Should I just restore a backup?

A backup can bring the site back quickly, but if the entry point is still open, the attacker comes straight back. We restore when it helps, and still close the way in.

Do I need to tell my customers?

That depends on what was exposed and on the laws where you and your customers are. We give you and your lawyer the facts to decide.

Can you stop it happening again?

We close the entry point, harden the site and can monitor it afterwards, so a repeat attempt is caught early.

Tell us your goal. We'll show you the plan.

Book a free 30-minute call. You'll leave with a clear plan and a fixed quote, whether you hire us or not.

Book my free call
Free call, no obligationBook my call