Same Skills.
Opposite Side.
I’m Dave. I hold a computer science degree, I’ve been writing production code for fifteen years, and I’ve spent the last three following AI-assisted attacks as they developed. Those are the same skills the people breaking into small business websites are using right now.
Website Rescue is what I do with them instead.
It Started With One Site
That Kept Getting Reinfected.
Four years ago a client’s site got hit. I cleaned it out and changed every login — and I left logging running behind it, because I wanted to know rather than guess.
One of those loggers was still running when they came back. It caught the whole thing: the exact door, and the moment it was used.
Once I could see it, closing it took minutes. Not another clean-up and not a guess — the actual way in, shut for good. It didn’t come back.
That’s why I stopped calling this a cleaning job. The clean-up was never the hard part. Seeing it was. I kept meeting the same job with a different business name on it, and eventually stopped calling it a favour and started calling it the work.
✅ Not a plugin. Not a dashboard. A method.
Find what is already there, close it, write down what was done — then keep watching, because the watching is the part everyone skips.
What This Is.
And What It Isn't.
“Cybersecurity” covers two very different trades, and the difference decides who you should be calling.
WHAT THIS IS
✓ A website rescue specialist — small business sites, WordPress, the things that actually get broken into
✓ Finding what is already on your site, closing it, and writing down exactly what was done and when
✓ Watching afterwards, on a schedule, so a change gets caught in minutes instead of months
✓ Plain English, a fixed price before anything is touched, and a record you can hand to anyone who asks
WHAT IT ISN’T
✗ Enterprise cybersecurity. I don’t reverse-engineer malware, I don’t chase nation-state actors, and I don’t sell six-figure SOC packages
✗ Attribution, forensics and boardroom reporting. If that’s what you need, I’m not your guy and I’ll say so on the first call
✗ A promise that your site can’t be broken into. There is no such thing, and anyone selling it is selling a feeling
Enterprise security asks: “Where did it come from? What does it do? Who’s behind it?”
Website Rescue asks: “How do we stop your site becoming the weapon — and what do we have written down about what was done?”
The Background
This Is Built On
No borrowed credentials, no reseller badge, and no team page full of people who don’t work here.
This is one person’s background — and it is the reason the scanner and the monitoring are ours, rather than somebody else’s plugin with our name on the box.
Computer Science Degree
Graduate Diploma (Multimedia)
Production Code, Then Team Lead
3 Years Deep in AI Threats (Daily)
Built My Own Scanner + Monitoring
I Could Have Been
The Other Guy.
I could be running this anonymously. With this background I could write AI-assisted exploits, automate them, and sit quietly on thousands of small business sites whose owners would never know anything had happened.
That’s the thing worth understanding about the modern version of this: the best villain is the one you never see. Nothing breaks. Nothing looks wrong. The site keeps taking bookings while it quietly works for somebody else as well.
But here I am. Name on it. Face public. A Perth phone number that rings a person.
That isn’t a sales line — it’s the only real test there is in this trade. Someone who understands the attack well enough to run it, who instead spends the day closing it and writing down what was closed.
Ask this of anyone you let near your website. Who are they, where are they, and what would they have to lose if they got it wrong?
How The Work
Actually Runs
Nobody should take a security promise on faith — so here is the whole sequence, in order, with what it costs.
Five steps. The first one is free. You can stop after any of them and still be better off than you started, and nothing moves to the next step without you saying so.
1 · It Starts With
A Free Scan.
We look at your site the way an attacker would — from the outside, with no access to anything of yours. WordPress version, plugin list, theme, SSL and header configuration, and the exploit paths that go with them.
No login. No card. No obligation.
And we’re straight about the ceiling on it: read from the outside, version numbers and configuration aren’t always exact. But the outside view still catches things most owners had no idea were visible from the street.
2 · Deep Audit.
We Come Inside.
The external view has a ceiling, so this is the credentialed one. You give us logins; we go through plugins, configuration, server settings, scheduled tasks and the quiet things no outside scan can reach.
Findings are cross-referenced against Wordfence Intelligence and the WordPress.org vulnerability data, and every finding says which source it came from and when that source was last updated. $485.
3 · Optimisation.
In Staging First.
Most sites we assess need work — including plenty that look completely up to date. Updated is not the same as secure.
Firewall rules tightened. Risky plugins replaced or locked down. Login security layered. File permissions corrected. PHP version checked. Admin paths taken out of sight of bots. Scheduled tasks read line by line for anything built to reinstall itself later.
Every change is made and tested in staging before it goes anywhere near your live site.
$985.
4 · AI-Era Diligence.
Written Down.
When the work is done you get the record of it: what was found, what was changed, on what date, and what state the site was left in.
It attests to what we did. It doesn’t promise what anybody else will make of that — not a court, not an insurer, not the other side’s lawyer. None of those are ours to promise, and anyone telling you otherwise is selling you a feeling.
What it does give you is the thing most owners cannot produce at the worst possible moment: a dated, specific answer to “what did you actually do about it?”
5 · Overwatch.
Then We Keep Watching.
A hardened site drifts. Plugins update, somebody adds a form, a theme changes hands. Security is a state you keep, not a job you finish.
So Overwatch runs every week, on schedule, whether or not anything looks wrong — core, plugins, server configuration — and raises an alert when something moves.
And it is software that does it, deliberately. A person checking every site every week costs what a person costs, and that lands straight on your price. Software doesn’t get bored, doesn’t skip a week and doesn’t charge by the hour — which is the only reason weekly is affordable at all.
From $360 a month.
I Didn't Read About Infections.
I Tested The Thesis.
Most people selling website security have never watched a live compromise happen. They have read about them, sat through the webinar, bought the plugin with the shield on it.
So we built a website and did the one thing we tell everybody else never to do. We left it alone. No updates. Old plugins. Default settings nobody ever changed — the exact state most people are in the day they first ring us.
Then we watched. It got found and broken into, right on schedule. That was the point: you cannot test detection on a clean site.
Then we switched Overwatch on, and it surfaced the intruder on a site that looked completely normal. Nothing defaced. Nothing obviously wrong. Still taking bookings, while somebody else was living in it.
So when we tell you what is living on your site, how it got in and what it was reaching for, that isn’t theory off a slide. It’s the thing we have already watched happen on purpose.
⚠ And here is what we won’t do: promise you a site that can’t be broken into.
There is no such thing. What we will stand behind is this — when something gets in, you find out in minutes rather than months, there is a clean backup to rebuild from, and there is a written record of what was done instead of a shrug.
Nobody Can Make You Safe.
Here's What We Can Do.
We can never make your site 100% hack-proof. Nobody can, and anyone who says otherwise is lying to you.
What I can do is make sure you are not neglecting your responsibility to the people who use your website — and give you the documentation that says so. Five things, and only five:
Find — what is already on the site today, not what a brochure says should be.
Close — the entry points, tested in staging before anything touches production.
Record — what was found, what was changed, and the date it happened.
Watch — every week, automatically, because the watching is the part everyone drops.
Answer — the phone, when it matters, as a person and not a ticket number.
That is the whole offer. If someone is promising you more than that, ask them which part a court, an insurer or an attacker has agreed to.
✓ I harden, I document, and the monitoring keeps running.
So when the AI comes knocking — and on a small Australian site it will — it doesn’t find an easy door, and you are not the one left with nothing to say about it.
Start Where Everyone Starts.
The Free Scan.
There is one way in and it costs nothing: we scan your site from the outside and show you what we can see. No card, no quote, no obligation, and no requirement to buy anything afterwards. Everything above this line only happens if you ask for it.
In A Nutshell
- One person, named, in Perth. Computer science degree, fifteen years writing production code, three years on AI-assisted attacks.
- The scanner and the monitoring are ours — not a resold plugin with our logo on the box.
- Findings are cross-referenced against Wordfence Intelligence and WordPress.org, and every finding says where it came from.
- This is website rescue, not enterprise cybersecurity. No forensics, no attribution, no six-figure SOC package.
- One way in: the free scan. Deep Audit $485, Optimisation $985, Overwatch from $360 a month. Nothing moves without you saying so.
- The weekly watching is automated on purpose — a person doing it every week is what would make it unaffordable.
- We attest to what we did. We never promise what a court, an insurer or an attacker will do about it.
✅ Everyone starts the same way.
A free external scan, and a straight conversation about what it found. Nothing else has to be decided on the same day.
Same skills as the people breaking in. Opposite side, name on it.
That is the whole of it. Everything else on this page is just the working out.
Ready to Stop Being a
Sitting Duck?
AI-Era Diligence with every plan
I don’t read about these threats in a news article three months after the fact. I watch them develop — the tutorials going up, the tooling getting cheaper, the malware getting better at not being noticed. That is what I track, and it is what informs every scan, every hardening decision and every recommendation I make.
You don’t need to panic. You need to stop guessing. Find out what is actually on your site. It costs nothing, and it takes one click.
