SERVICES

Sensible defaults, properly enforced.

Firewall, SSH hardening, patching and access control configured as standard, then kept that way.

Secured racks behind controlled access in a UK data centre
Docker
Magento
WordPress
WooCommerce
MySQL
PostgreSQL
Node.js
PHP
Amazon Web Services
Microsoft Azure
Supabase
HARDEN

A smaller attack surface

Unused services off, sensible defaults on, access restricted to what is needed.

PATCH

Kept current

Security updates applied on a schedule rather than when someone remembers.

CONTROL

Who can reach what

Key based access, firewall policy and separation between environments.

What hardening covers

Most compromises exploit something ordinary that was left open or left unpatched. The ordinary work is the work.

We configure it properly at build time and keep it that way as part of management.

INCLUDED
Firewall policy and port restriction
SSH key based access and root login policy
Operating system and package patching
Service and permission review
Access separation between environments

How hardening is kept up

We harden at build time
01

The secure configuration is the starting point, not a later project.

We keep it current
02

Patching and review as part of ongoing management.

We review as things change
03

New services, new access, new requirements, checked rather than assumed.

CloudSpace engineers reviewing a managed server build
Cloudspace have always provided great service for us. They helped configure our cloud servers initially, have been flexible about the occasional ramping up or cutting back in servers used, and have even helped resolve issues when we have experienced issues installing 3rd party software onto one of the cloud servers that they host! We would recommend them to anyone looking for a smaller scale solution than the big Azure, AWS cloud solutions.
Richard Simpson