Same Skills.
Opposite Side.

I’m Dave. I hold a computer science degree, I’ve been writing production code for fifteen years, and I’ve spent the last three following AI-assisted attacks as they developed. Those are the same skills the people breaking into small business websites are using right now.

Website Rescue is what I do with them instead.

A wall of hand tools split down the middle, the same set lit red on one side and green on the other

It Started With One Site
That Kept Getting Reinfected.

Four years ago a client’s site got hit. I cleaned it out and changed every login — and I left logging running behind it, because I wanted to know rather than guess.

One of those loggers was still running when they came back. It caught the whole thing: the exact door, and the moment it was used.

Once I could see it, closing it took minutes. Not another clean-up and not a guess — the actual way in, shut for good. It didn’t come back.

That’s why I stopped calling this a cleaning job. The clean-up was never the hard part. Seeing it was. I kept meeting the same job with a different business name on it, and eventually stopped calling it a favour and started calling it the work.

✅ Not a plugin. Not a dashboard. A method.

Find what is already there, close it, write down what was done — then keep watching, because the watching is the part everyone skips.

A wall painted over several times with the same dark stain bleeding back through the newest coat
A roll of fine precision hand tools on a bench beside a heavy blunt hammer

What This Is.
And What It Isn't.

“Cybersecurity” covers two very different trades, and the difference decides who you should be calling.

WHAT THIS IS

 A website rescue specialist — small business sites, WordPress, the things that actually get broken into

 Finding what is already on your site, closing it, and writing down exactly what was done and when

 Watching afterwards, on a schedule, so a change gets caught in minutes instead of months

 Plain English, a fixed price before anything is touched, and a record you can hand to anyone who asks

WHAT IT ISN’T

✗  Enterprise cybersecurity. I don’t reverse-engineer malware, I don’t chase nation-state actors, and I don’t sell six-figure SOC packages

✗  Attribution, forensics and boardroom reporting. If that’s what you need, I’m not your guy and I’ll say so on the first call

✗  A promise that your site can’t be broken into. There is no such thing, and anyone selling it is selling a feeling

Enterprise security asks: “Where did it come from? What does it do? Who’s behind it?”

Website Rescue asks: “How do we stop your site becoming the weapon — and what do we have written down about what was done?”

The Background
This Is Built On

No borrowed credentials, no reseller badge, and no team page full of people who don’t work here.

This is one person’s background — and it is the reason the scanner and the monitoring are ours, rather than somebody else’s plugin with our name on the box.

A deeply scarred timber workbench with a pegboard of tools behind it

Computer Science Degree

Graduate Diploma (Multimedia)

Production Code, Then Team Lead

3 Years Deep in AI Threats (Daily)

Built My Own Scanner + Monitoring

I Could Have Been
The Other Guy.

I could be running this anonymously. With this background I could write AI-assisted exploits, automate them, and sit quietly on thousands of small business sites whose owners would never know anything had happened.

That’s the thing worth understanding about the modern version of this: the best villain is the one you never see. Nothing breaks. Nothing looks wrong. The site keeps taking bookings while it quietly works for somebody else as well.

But here I am. Name on it. Face public. A Perth phone number that rings a person.

That isn’t a sales line — it’s the only real test there is in this trade. Someone who understands the attack well enough to run it, who instead spends the day closing it and writing down what was closed.

Ask this of anyone you let near your website. Who are they, where are they, and what would they have to lose if they got it wrong?

Two identical empty chairs at the same bench, one lit red and one lit green

How The Work
Actually Runs

Nobody should take a security promise on faith — so here is the whole sequence, in order, with what it costs.

Five steps. The first one is free. You can stop after any of them and still be better off than you started, and nothing moves to the next step without you saying so.

I Didn't Read About Infections.
I Tested The Thesis.

An observation camera on a tripod trained on a single closed laptop in a bare red-lit room

Most people selling website security have never watched a live compromise happen. They have read about them, sat through the webinar, bought the plugin with the shield on it.

So we built a website and did the one thing we tell everybody else never to do. We left it alone. No updates. Old plugins. Default settings nobody ever changed — the exact state most people are in the day they first ring us.

Then we watched. It got found and broken into, right on schedule. That was the point: you cannot test detection on a clean site.

Then we switched Overwatch on, and it surfaced the intruder on a site that looked completely normal. Nothing defaced. Nothing obviously wrong. Still taking bookings, while somebody else was living in it.

So when we tell you what is living on your site, how it got in and what it was reaching for, that isn’t theory off a slide. It’s the thing we have already watched happen on purpose.

⚠ And here is what we won’t do: promise you a site that can’t be broken into.

There is no such thing. What we will stand behind is this — when something gets in, you find out in minutes rather than months, there is a clean backup to rebuild from, and there is a written record of what was done instead of a shrug.

Nobody Can Make You Safe.
Here's What We Can Do.

We can never make your site 100% hack-proof. Nobody can, and anyone who says otherwise is lying to you.

What I can do is make sure you are not neglecting your responsibility to the people who use your website — and give you the documentation that says so. Five things, and only five:

Find — what is already on the site today, not what a brochure says should be.

Close — the entry points, tested in staging before anything touches production.

Record — what was found, what was changed, and the date it happened.

Watch — every week, automatically, because the watching is the part everyone drops.

Answer — the phone, when it matters, as a person and not a ticket number.

That is the whole offer. If someone is promising you more than that, ask them which part a court, an insurer or an attacker has agreed to.

✓ I harden, I document, and the monitoring keeps running.

So when the AI comes knocking — and on a small Australian site it will — it doesn’t find an easy door, and you are not the one left with nothing to say about it.

A heavy door with three locks engaged and a thin strip of light still showing under the threshold
Security badge: Fighting AI with AI, cross-referenced against known attack database

Start Where Everyone Starts.
The Free Scan.

There is one way in and it costs nothing: we scan your site from the outside and show you what we can see. No card, no quote, no obligation, and no requirement to buy anything afterwards. Everything above this line only happens if you ask for it.

One well-worn hand tool lying alone on a dark bench under a soft green light

In A Nutshell

  • One person, named, in Perth. Computer science degree, fifteen years writing production code, three years on AI-assisted attacks.
  • The scanner and the monitoring are ours — not a resold plugin with our logo on the box.
  • Findings are cross-referenced against Wordfence Intelligence and WordPress.org, and every finding says where it came from.
  • This is website rescue, not enterprise cybersecurity. No forensics, no attribution, no six-figure SOC package.
  • One way in: the free scan. Deep Audit $485, Optimisation $985, Overwatch from $360 a month. Nothing moves without you saying so.
  • The weekly watching is automated on purpose — a person doing it every week is what would make it unaffordable.
  • We attest to what we did. We never promise what a court, an insurer or an attacker will do about it.

✅ Everyone starts the same way.

A free external scan, and a straight conversation about what it found. Nothing else has to be decided on the same day.

Same skills as the people breaking in. Opposite side, name on it.

That is the whole of it. Everything else on this page is just the working out.

AI-Era Diligence Certificate badge

Ready to Stop Being a
Sitting Duck?

AI-Era Diligence with every plan

I don’t read about these threats in a news article three months after the fact. I watch them develop — the tutorials going up, the tooling getting cheaper, the malware getting better at not being noticed. That is what I track, and it is what informs every scan, every hardening decision and every recommendation I make.

You don’t need to panic. You need to stop guessing. Find out what is actually on your site. It costs nothing, and it takes one click.