Cybersecurity for SMEs

Close the gaps attackers actually use.

Most SME breaches start with a weak password, an unpatched server or a convincing email, not an exotic exploit. We assess your real exposure, harden servers and Odoo, roll out MFA, set up monitoring and prove your backups restore, prioritized by risk rather than by report length.

  • Risk-ranked findings, in writing
  • Server and Odoo hardening
  • MFA and passkeys rollout
  • Monitoring and alerts
  • Backups with tested restores
Fee for the assessment, agreed up front
Backup restores on every engagement
Reports and support
Reply time on enquiries

What we secure

The controls that stop the common attacks

Security budgets are finite, so we spend yours on the controls with the best evidence behind them: fewer doors open, alarms that ring, and a recovery you have rehearsed.

Security assessment

External exposure, server configuration, Odoo access rights, email and backups reviewed, then a written report with risks ranked by impact and likelihood.

Server and Odoo hardening

TLS everywhere, firewalls with nftables or UFW, SSH keys instead of passwords, fail2ban, least-privilege database access and a patching cadence that sticks.

Identity and access

MFA and passkeys rolled out, a password manager for the team, Odoo roles reviewed, and an offboarding checklist so ex-staff accounts actually close.

Network security

Admin panels moved behind a WireGuard VPN instead of the open internet, and networks segmented so the POS, the office Wi-Fi and the servers are not one flat target.

Monitoring and alerting

Central logs, alerts on failed logins, privilege changes and unusual traffic, and uptime checks from outside, sent by email or LINE to people who can act.

Backups and ransomware recovery

Encrypted off-site backups with immutable copies, retention rules, and restore tests on a schedule, because an untested backup is not a backup.

Email security and awareness

SPF, DKIM and DMARC configured, phishing-resistant sign-in for key accounts, and short staff sessions built on realistic examples, in Thai or English.

PDPA-aligned data protection

Access control, encryption, retention and logging set up around Thailand's PDPA duties and sensible practice elsewhere. We implement controls; we do not issue certificates.

Honest scope

The basics stop most attacks, so we do the basics well

We are engineers who harden and watch the systems we also build and run, not an accredited penetration-testing or audit firm. When you need a certified test or a formal compliance audit, we will say so, refer you to a specialist and prepare your systems for it. What we claim is narrower and, for most SMEs, more useful.

  • No certifications or compliance badges claimed, and none implied
  • Accredited penetration testing referred to specialist firms, with the findings fixed by us
  • Findings ranked by real risk, not padded to justify a bigger invoice
  • Hardening done by the same engineers who run Odoo and servers in production
  1. Assess

    A fixed-fee review of exposure, access, email and backups, ranked in writing.

  2. Harden

    The highest risks are closed first, with every change documented.

  3. Watch

    Logs, alerts and uptime checks keep eyes on what matters daily.

  4. Drill

    A restore test and an incident walkthrough, timed and written up.

Where we start

Three situations we see most often

An Odoo server open to the internet

Admin login exposed, no TLS on some services and backups of unknown state. We harden the stack, move admin behind a VPN and prove a restore works.

Shared logins and no MFA

One admin password in a chat group and ex-employees still active. We clean up accounts, roll out MFA and a password manager, and review Odoo roles.

A business that just had a scare

A phishing click, a locked file share or a suspicious transfer request. We help contain it, reset credentials, close the entry point and rehearse recovery.

How we work

Assess first, then fix by risk

  1. 1. Assess

    A fixed-fee assessment of exposure, servers, Odoo, access, email and backups. The written report is yours, whoever does the fixes.

  2. 2. Agree the fixes

    You choose which risks to close first. Each fix phase has a fixed scope and price before work begins.

  3. 3. Harden

    Servers, access, network and email are hardened change by change, tested on staging where one exists, and documented as we go.

  4. 4. Monitor

    Log collection, alerts and uptime checks go live with a runbook, so the next unusual login is seen the day it happens.

  5. 5. Drill and review

    A full restore test and an incident walkthrough with your team, then periodic re-checks as systems and staff change.

Tools we run

Boring, proven tools, configured with care

  • nftables and UFW
  • WireGuard
  • fail2ban
  • SSH and TLS
  • Borg and restic
  • Prometheus
  • Grafana
  • Loki
  • Keycloak
  • Passkeys and FIDO2
  • SPF · DKIM · DMARC
  • Docker

Our commitments

Security promises without the fear talk

Security marketing leans on fear and badges. We offer neither, only work you can inspect: a ranked report, documented changes and a restore you watched succeed.

Book a security assessment
Assessment fee, agreed up front
Restore drill in every engagement
Written status note during fixes
Time zones across our offices
Reply time on business days

FAQ

Questions clients ask first

Do you do penetration testing?

We do hands-on security assessment and hardening, not accredited penetration testing. When your customers or regulators require a certified test, we refer you to a specialist firm, prepare your systems for it and fix what the test finds. That separation keeps the test independent, which is the point of having one.

What does the security assessment include?

External exposure of your domains and servers, server and Odoo configuration, user accounts and MFA coverage, email authentication, and the state of your backups. You receive a written report with each risk ranked by impact and likelihood, plus the recommended fix and its rough cost, so you can decide in order.

Can you secure our Odoo specifically?

Yes, and it is where we are strongest, because we deploy and run Odoo in production ourselves. That covers TLS and reverse proxy settings, admin access behind a VPN, role and access-right review, database and filestore backups with tested restores, a separated staging environment and a sane update cadence.

We are a small company. Are we really a target?

Yes, because most attacks are automated and scan everyone. SMEs are usually hit through an exposed service, a reused password or a convincing email, and the attacker often does not know or care who you are. The basics that stop those attacks cost little compared with a week of downtime or a locked database.

Can you help with PDPA compliance?

We implement the technical controls PDPA duties call for: access control, encryption, retention rules and logs of who accessed what. Legal interpretation and policy sit with your counsel or DPO, and we work alongside them. We do not issue certificates or badges, and we would be wary of anyone who does.

What does cybersecurity work cost?

The assessment is a fixed fee. Fix phases are quoted with a fixed scope and price each, ordered by the risks you choose to close first. Ongoing monitoring runs on a monthly plan scaled to the number of servers and services, and any security tooling licenses are billed to your own accounts.

Start with the assessment

Learn how exposed you are before an attacker does

Tell us what you run, where it is hosted and what worries you. You get a reply within one business day, then a fixed-fee assessment with every risk ranked in writing and a price for closing each one.

  • Reply within one business day
  • Fixed fee for the assessment
  • A written report you own, whoever fixes it

Prefer to talk first? Call us or WhatsApp us.

Your details stay private. We reply within one business day.