Work with me
Four things, kept separate on purpose. Most people need one of them.
Software builds
Web apps, client portals and internal tools. Built, deployed, and running on infrastructure I look after.
Who it's for
Small businesses and IT firms with a process currently held together by a spreadsheet, or a product idea that needs building properly the first time.
- A working application, not a prototype, deployed to a server you own
- Multi-tenant and role-based access where the job needs it
- The deployment, the database and the backups set up and documented
- Source code and credentials handed over, yours to keep
How it's priced
Fixed price per project, quoted after a free scoping call. Larger builds split into stages you sign off one at a time, so you are never far from a working thing.
Case study
A multi-tenant portal two companies run their week on
The problem. An IT firm needed its client companies to see their own devices, tickets and security findings, with no possibility of one client ever seeing another. The usual approach, a shared database with a tenant column on every table, fails the moment one query forgets its filter.
What I did.
- Gave every client company its own database, created when the company is added and deleted with it, so a missing filter cannot cross a boundary that does not exist
- Built six roles across two tiers after splitting one overloaded permission check that had been guarding two unrelated powers
- Added TOTP two-factor, and session revocation by version number so a password change signs out every other device without the server storing sessions
Outcome. Around 15,000 lines of TypeScript, in production, used daily by two client companies. I still run the server it sits on.
Security audits
Find out what is actually exposed, with the evidence attached. Not a scan report you cannot act on.
Who it's for
Businesses that have been asked by an insurer, a customer or their own board whether they are secure, and want a better answer than a shrug.
- A read-only audit of your Windows estate against 17 checks, nothing changed without your say-so
- Every finding rated by severity with the evidence it was based on, so you can verify it yourself
- Findings mapped to the relevant Cyber Essentials control if you are preparing for certification
- A plain-English report your IT provider can act on, and a re-audit that shows what actually got fixed
How it's priced
Fixed price per audit, based on the number of machines. Re-audits at a lower rate. No retainer required and no obligation to have me do the remediation.
Case study
Systems I manage
193,000 failed logins, and three doors I had left open
The problem. A production server carrying live sites and internal services. No breach, no incident, nothing wrong on the surface. I went looking anyway, because nobody had actually checked.
What I did.
- Read a month of authentication logs properly instead of glancing at them: roughly 193,000 failed password attempts, continuous and automated
- Found password authentication and root login still enabled, a database running without authentication, and an application port published straight to the internet
- Closed all three, then verified from outside rather than by reading the config back
Outcome. Failed password attempts went from 66,760 in a week to zero, and have stayed there. The bots still knock; there is no longer anything to knock on.
Servers and infrastructure
Provisioning, hardening and keeping Linux servers running. Including being the person who gets the call.
Who it's for
Anyone running a VPS or a small server estate who inherited it, is not sure what state it is in, or is currently the only person who knows how it works.
- Provisioning and hardening: firewall, SSH key-only access, fail2ban, audited against Lynis
- nginx, TLS certificates that renew themselves, and deployments that can be rolled back
- Encrypted off-site backups that are tested by restoring them, not assumed
- Documentation written so somebody who is not me can pick it up
How it's priced
One-off hardening and setup at a fixed price, or a monthly arrangement if you want somebody on the end of the phone. Priced per server, not per hour.
Case study
Systems I manage
Every script backs up what it touches
The problem. Hardening scripts are the ones you least want to run on a live box on a Thursday afternoon, which means they sit unrun and the machine stays unhardened. The risk is not the script. It is the hesitation.
What I did.
- Made every script copy what it is about to change to a timestamped backup first, so a bad change is one move from undone
- Made every script safe to run twice, because you will run it twice and so will somebody else
- Kept the working session open and tested changes from a second one, so a lockout is always recoverable
Outcome. Changes get made on live servers in working hours instead of waiting for a weekend that never comes. The confidence is the deliverable; the backup file is how you buy it.
Website care plans
Hosting, security updates, tested backups and your monthly changes. For any small business site, whether I wrote it or not.
Who it's for
Anyone whose website is currently maintained by nobody, or who is about to discover that the person who built it three years ago has stopped answering emails.
- Hosting on a Linux server I run and patch myself, not resold from somebody else
- A TLS certificate that renews on its own, and gets checked rather than assumed
- Daily off-site backups, tested by restoring them
- Security updates and version upgrades, applied and verified
- Uptime monitoring, so I find out it is down before you do
- Up to an hour of content changes a month
How it's priced
£49 a month, no minimum term, whether or not I built the site. If you do not have a website yet, I build you a one page site at no charge when you take the plan, with the first year's domain included.
Case study
Systems I manage
The backup that had not failed
The problem. A server I run flagged its own backups as failing. I believed the banner and wrote down that the most important machine I administer had no backup. It had eight, one a day, the most recent from the previous evening. What had actually broken was a manual export almost nobody presses, taking a different path through the same code.
What I did.
- Counted the files on disk before accepting what the status page said about them
- Traced the real fault to a module that was never a dependency, and fixed it without upgrading a live server pinned on purpose
- Moved the backups off the machine they were protecting, pulled from the far end so a compromised server cannot reach the copies
Outcome. The two things worth fixing had never raised a warning, because neither of them was an error. That is the argument for paying somebody to look: alerts tell you what broke, and nobody sends you an alert about the backup sitting on the disk it is meant to survive.
What I won't pretend
- I am one person. I take on a small number of projects at a time, and I will tell you if I am booked rather than start late.
- I do not hold Cyber Essentials certification and cannot certify anyone. I can map findings to the controls and get you ready for an assessor who is licensed to do it.
- I work with UK small businesses. If you need a team of five by next month, I am the wrong call and will say so on the first one.
Start a project
Tell me what you're trying to do and roughly what it's worth to you. The first call is free, half an hour, and you get a straight answer about whether I'm the right person. If I'm not, I'll say so.
Freelance work is separate from my day job. I take it on self-employed and invoice it myself.
That's with me.
I read these myself and reply within a working day, usually sooner. If it's urgent, ring 07853 610930.
