🚨 Hacked right now? Emergency Rescue — we stop the bleeding first · In a nutshell ↓
Find Out In Minutes.
Not From A Lawyer.
Nobody can guarantee you won’t get hit. Anyone who does is lying to you. The difference is whether you find out in minutes and handle it in the open — or find out from somebody’s lawyer.
Overwatch is the watch that never clocks off. Automated, every day, on the position we engineered. A person steps in when it screams. From $360 a month. About twelve bucks a day.
We Don't Read About Infections.
We Tested Our Thesis.
Most security companies have never watched a live infection happen. They’ve read the case study. Sat through the webinar. Bought the plugin with the shield icon on it. Actually watched one move in, in the wild, on a real site, in real time? Almost none of them.
So we built a website and did the one thing we tell everybody never to do. We left it alone.
No updates. Old plugins. Default settings nobody ever changed. The exact state most people are in the day they first call us — half-built, un-hardened, quietly exposed. Then we watched.
That isn’t carelessness. It’s a test. You cannot test monitoring on a clean site, because there’s nothing there to catch. You test it on a sitting duck. So we built one, on purpose, and left the door open.
It got found. Exactly on schedule, and for a reason nobody tells small-business owners: the moment you switch on the padlock, your website’s name is published to a public list. It has to be — that’s how the padlock works. And that list is read, in real time, by machines.
We didn’t write the malware and we didn’t stage the break-in. We left a brand-new site with out-of-date plugins sitting online, and precisely what we warn you about happened to it. Nothing about it looked wrong from the outside — the site kept loading perfectly for every visitor.
Then we switched Overwatch on. It surfaced the intruder in four minutes. A quiet tenant, already resident, that nothing else had flagged.
So when we tell you what’s living on your site, how it got in, and what it’s been reaching for — we’re not reciting theory. We watched it happen on our own property. Then we took it apart.
✅ Tested against a real infection, in the same conditions you’re in.
Not a demo. Not a slide in a training deck. Our own gear, against a live tenancy, on a site we deliberately left exposed for exactly that purpose.
The Question Isn't “Have I Been Hacked.”
It's “Would I Know?”
Ask a small-business owner if they’ve been hacked and they picture a black screen with a skull on it. That’s the loud minority. Low-skill. Showing off.
WHAT PEOPLE PICTURE
✗ A defaced homepage. Something obviously, visibly wrong.
WHAT ACTUALLY HAPPENS
✓ Your site keeps working perfectly — because a normal-behaving site is a site nobody investigates.
✓ They set up quietly and stay. A backdoor here. A scheduled job there. Something that phones home at 4am and goes back to sleep.
✓ They come back on a schedule, sweeping files and logs for saved logins, API keys, config files, session tokens — anything a customer typed into a form.
✓ Often it runs itself: planted code that activates and exfiltrates with nobody typing a command. That’s how one operation covers thousands of sites.
That isn’t defacement. That’s residency.
And here’s the part that should genuinely bother you. Your website isn’t the prize. Your website is the delivery van. An email from your domain gets opened. A file from your site gets downloaded. That trust is what they’re buying when they move in.
⚠️ A green tick means “recognised nothing”. It does not mean “nothing there”.
A scan asks one question: do I recognise anything on this list? Those are wildly different sentences, and one of them has been sold to you as the other for years. Clean-to-a-scanner is the floor, not the finish line.
You Don't Catch A Tenant By Scanning.
You Catch Them By Watching.
Here’s the shift, and it’s the whole product. Scanning looks for the obvious thing that usually isn’t there. Monitoring looks for the mundane thing that shouldn’t have moved. Nobody breaks in and leaves a signed note — but everybody leaves a footprint, because living in a house means touching things.
None of these look like an attack. Every one of them is one.
A file that changed at 3:14am — on a Tuesday, when nothing was scheduled.
An admin account — that you have never heard of.
A cron job — that nobody created.
Traffic leaving your server — for somewhere you have never sent anything.
An edit to a file — that hasn’t legitimately changed since the day it was installed.
That’s what Overwatch watches. Every day. Not the skull on the homepage — the doorknob that turned. And it doesn’t only watch the files, it watches the pace. A real compromise isn’t a moment, it’s a tenancy, which means there is always a second event. And a third. Every one of those is another chance to catch them — the chance a one-off scan never gets.
The watching is automated, and that is exactly why it is affordable. A person doesn’t sit and stare at your logs at 3am. The machine does that, every day, and a person steps in when it screams.
✅ Overwatch never takes your site down. Ever.
It is passive. It watches, it verifies, it tells you. It does not reach in and pull the plug on your business because a script got nervous at 2am. Your phone keeps ringing. Your checkout keeps working. If something is serious enough to need the site offline, that is a decision, and it is yours — we’ll ring you with the facts and a recommendation.
When Something Happens, You Get
An Evidence Log. Not A Shrug.
Most people’s experience of “we found something” is a list of deleted filenames and a green tick. Which tells you nothing you can act on. It doesn’t tell you how they got in, so it can happen again on Thursday. And it doesn’t tell you what they could reach while they were there — which is the only question your customers will actually ask.
So the deliverable per incident is an evidence log. Two halves, both in plain English.
Entry point. How they got in. Which door. Which plugin, which credential, which upload path.
Blast radius. What was reachable from there. Which files. Which database tables. Which customer data was inside the perimeter they had.
Timestamped, and written for a business owner rather than a security conference. That is the difference between “we cleaned it up” and being able to show what did and didn’t happen. One of those is a shrug. The other is a document.
The rest of the month is deliberately boring: one email telling you what we handled. That’s the whole job on your end. Site up. Certificate current. Phone ringing.
✅ We attest to what we did. We don’t promise what it does for you.
We can’t tell you what a court, an insurer or a regulator will make of it — nobody honest can. What we can tell you is that when something happens, you’ll be holding a file instead of a feeling.
The Watch Moves. And Nothing Ships
Until It Has Survived A Copy.
Most monitoring runs the same scan, the same way, at the same time, forever. Same blind spots. Same predictable window. Learn the pattern once and you can work around it every night after that.
Ours rotates. Different checks, different depths, different areas, week to week. Deeper sweeps arrive unannounced, from the outside, with the timing jittered and never published. By the time somebody works out what’s being watched, we’re watching something else.
Updates get the same treatment. Plugin vendors push them constantly, and most operators install them blind and hope. But a “security patch” can introduce its own hole, fail to fix the one it claimed to fix, or drag in a compromised dependency from further down the supply chain. So nothing goes onto your live site until it has been:
Cross-referenced — against Wordfence Intelligence and the WordPress.org release data.
Tested on a copy — of your site. Not on your site.
Screenshotted before, pixel-compared after — so an update can’t quietly destroy your layout and let you find out from a customer.
Lands clean? It ships fast, because a security patch is worth nothing sitting in a queue. Doesn’t land clean? We hold it and tell you exactly why.
Vulnerability data: Wordfence Intelligence and WordPress.org release data.
✅ And your customisations survive it.
Updates wipe custom styling on a huge number of WordPress sites — so every few weeks something looks wrong, you ring your developer, and you pay him to put it back. During hardening we move your custom CSS and JS to update-safe locations. Once. Properly. After that, updates ship at security speed and your site keeps looking the way it’s meant to.
The Five Things People Say
Right Before They Get Found Out.
“My Web Guy
Handles All That.”
Does he? Or does he log in once a month, click “update all”, and tell you it’s sorted?
Those are not the same activity. One of them is maintenance. The other is a click.
And I’m not having a go at him. Your developer builds. That’s a completely different skill, a different toolkit and a different mindset. He’s paid to make it work. We’re paid to assume somebody is already inside.
Ask him one question. Not to catch him out — genuinely ask. “If someone got in three weeks ago and the site still worked perfectly, how would you know?”
If the answer involves the word “probably”, you’ve got your answer.
Send him our report. He’ll thank you. It was never in his scope and it was never in his retainer.
“I’ve Already Got
A Security Plugin.”
Good. Keep it. It stops a lot of noise at the front door and that’s worth having.
But think about where it lives.
It’s a piece of software installed inside the thing it’s guarding. If somebody is already inside with the right level of access, they are standing next to your guard.
There’s a reason banks don’t put the CCTV recorder in the room with the safe.
Overwatch watches from outside, against a known-good picture of what your site is supposed to look like. Not against a list of things that have already been catalogued as bad.
That’s the difference between recognising a burglar and noticing a window that’s open when it shouldn’t be.
“I’ve Got Two-Factor
On Everything.”
On your phone, brilliant. On a machine that is already compromised, it does very little.
Resident malware is inside the computer. It logs the keys you press. It screenshots the code as you read it. Better still, it lifts the session token — the “you’re already logged in” pass — and replays it.
Two-factor never fires. Because from where it is sitting, you never logged in again.
Two-factor is a door lock. It is worth having. It just doesn’t help with somebody who is already in the hallway, and it was never designed to.
Watching does. Because a tenant who is already inside still has to touch things — and touching things is what gets noticed.
“My Scan Came
Back Clean.”
A scan asks exactly one question: do I recognise anything on this list?
A green tick means “recognised nothing”. It does not mean “nothing there”. Those are wildly different sentences, and one of them has been sold to you as the other for years.
There’s a second problem, and it’s the one nobody mentions. A scan is a photograph. “Clean” at 9am Monday tells you nothing about 3am Thursday. The scan wasn’t lying to you — it just went out of date, quietly, not long after you read it.
Clean-to-a-scanner is the floor. Not the finish line.
You can’t answer a continuous question with a one-off answer. That’s the entire argument for monitoring, and there isn’t a second one.
“Why Would Anyone
Bother With Me?”
Every owner I talk to says a version of that line. “I’m nobody.”
Correct. Nobody chose you.
Something cheap and automated swept everything it could reach, and your site answered the door. Being small didn’t hide you. Being small is exactly why the automated thing got a clean run at you — you’re the address with nobody watching it.
And here’s why that changes what you actually need. A human attacker picks a target, does the job and moves on. One event. You could scan once afterwards and get a straight answer.
The cheap automated thing doesn’t pick. It sweeps. And a sweep that ran last night runs again tonight, and again next Tuesday, because running it costs the operator practically nothing.
The thing that found you is still running. It will come back. Something has to be awake when it does.
The Certificate Is Live.
Which Means It Can Break.
Your AI-Era Diligence isn’t a photo of one good afternoon. It’s dated today. Valid today. Maintained for exactly as long as the chain of custody holds.
WHAT KEEPS IT VALID
✓ Overwatch running, so there is a current state to attest to
✓ Changes going through our pipeline, so the chain is unbroken
WHAT VOIDS IT — the whole list
✗ You cancel Overwatch. We can’t attest to a state we’re no longer watching.
✗ Someone modifies the site outside our pipeline. The chain is broken, so the document says so.
Both are deliberate actions, not fuzzy drift. That’s what keeps the artefact clean. And a certificate that can’t break is worth nothing — that’s the whole point. Anyone can print a badge. What makes this one carry weight is that every claim on it is backed by timestamped logs: every update applied, every check that ran, every alert that fired and what happened next. Receipts, not a graphic in your footer.
After a break there’s no topping it up. Full re-scan, full re-hardening pass, then a current document again. The integrity is the chain.
Which is also why WordPress admin stays with us. It is the most dangerous tool in your business — one wrong click and months of hardening is gone, along with the custody that makes the document mean anything. You tell us what the site needs. We do it. Same day for anything small. It’s the same arrangement you already have with your books, your legals and your gas line.
✅ The certificate attests. It does not guarantee.
It records what we did and when we did it — monitored since this date, updates applied on these dates, last verified today. What anyone else does with that is theirs to decide, not ours to promise.
You Can't Buy Overwatch Cold.
And That's Deliberate.
You’ve probably noticed there is no “add to cart” on this page. Here’s why, and it isn’t a sales trick. Monitoring works by comparing your site today against what your site is supposed to be — so somebody has to establish what it is supposed to be. Properly. With evidence. Switch monitoring on over an unknown site and all you’ve done is take a very detailed photograph of a possible crime scene and call it a baseline.
01
Free Scan
$0, no card
What an attacker can see from the outside, in about fifteen minutes. No card, no call, no obligation. This is the only entry point, for everybody.
02
The Deep Audit
from $485
Inside the site, credentialed. What’s actually there, not just what shows from the street. This is where the known-good picture starts being written down.
03
Optimisation
from $985
The fixing and the hardening. Then a fortnight of intensified watching, to prove nothing survived it. That fortnight is what turns a fix into a baseline.
04
Overwatch
from $360/month
The watch that never stops. Daily, automated, on the position we engineered — and a person on the end of it when something needs a person.
Each stage builds the thing the next stage stands on. That’s a chain of custody, not an upsell ladder. Skip one and the chain breaks — and a broken chain is exactly the thing we’re selling you protection from. It’s also why the certificate is earned across the chain, and why it lapses the day Overwatch does.
The Deal.
Straight Up.
$360/month (S) · $497/month (M) · $797/month (L). Priced on the size and complexity of your site. See which tier you’re in.
No lock-in contract. Cancel any time. No setup fee. And a $250 auto-replenishing fix pool included every month — so the small stuff just gets done instead of turning into a quote.
What it covers:
Daily monitoring — of the position we engineered. File integrity, admin accounts, scheduled jobs, outbound traffic, the lot. Automated, which is exactly why it costs twelve bucks a day instead of a salary.
Rotating deep sweeps — so the pattern can’t be learned.
Unannounced probing — of the same surfaces a paid attacker would go for. Timing jittered, never published.
Updates verified off-site — tested on a copy, visually compared, then shipped.
Your customisations kept alive — through every patch.
An evidence log — for anything we find. Entry point and blast radius, in plain English.
A live AI-Era Diligence — dated today.
A direct line to us — not a ticket queue.
The watching is automated. The judgement isn’t. A person looks at anything that matters before you ever hear about it — which is how you get told about the one thing that counts instead of the four hundred that don’t.
What it does not cover, said plainly: new features, redesigns, 24/7 phone support, and a promise you’ll never be hacked.
✅ What we will never promise you.
A website that can’t be broken into. There’s no such thing, and anyone selling you a “hack-proof” site is either lying or doesn’t understand what they’re up against. A large part of this industry runs on selling a feeling of safety that isn’t real — and the feeling costs the same as the real thing.
Here’s what we’ll actually stand behind. When something gets in, you’ll know in minutes rather than months. There’ll be a clean backup to rebuild from. There’ll be an evidence trail rather than a shrug. And you won’t find out from an angry customer’s solicitor.
That isn’t a smaller promise than “you’ll never get hit”. It’s the only one that’s true.
The Threat Isn't The Cleverest Model.
It's The Jailbroken One.
There’s a comforting idea doing the rounds — that the dangerous AI is locked in a lab somewhere, and until it gets out you’re fine. Let it go.
You do not need a frontier model to be taken apart. You need a cheap one. A jailbroken, off-the-shelf model, the sort anyone can rent for a few dollars a month, running exploits that aren’t even secret. They’re published. Catalogued. Sitting in public databases that anybody can read, including us.
That was never the problem. The problem used to be skill — knowing which three boring little weaknesses to chain together, in what order, to turn “not much” into “administrator”. That took a person who knew what they were doing, and there were only so many of those.
That was the barrier. The barrier is gone. The model does the chaining now, for almost nothing, all night, without getting bored or distracted by anything better to do.
So the thing that finds your website isn’t a genius. That’s the whole point. It doesn’t have to be.
⚠️ A scan is a photograph of something that’s still moving.
“Clean” at 9am Monday tells you nothing about 3am Thursday. The scan wasn’t lying to you — it just went out of date, quietly, not long after you read it. You can’t answer a continuous question with a one-off answer. That’s the entire argument for monitoring, and there isn’t a second one.
In A Nutshell
The whole thing, in one place:
- Cheap automated attacks run every night, across everything with a domain. You weren’t picked out. You were found.
- A one-off scan can’t answer a question that keeps getting asked. Watching can.
- Overwatch watches your site daily and tests every update on a copy before it touches your live site.
- If something happens you get an evidence log — how they got in, and what they could reach, in plain English.
- It never takes your site down. That call stays yours, always.
- From $360 a month, including a $250 auto-replenishing fix pool.
But it’s the last link in the chain, not the first — so start with the free scan and we’ll tell you what you’re actually dealing with.
✅ Nobody can guarantee you won’t get hit.
The difference is whether you find out in minutes and handle it in the open — or find out from a lawyer. That’s the whole product, and it’s the only promise on this page we can actually keep.
You don’t have a CISO. You’ve got a business to run, a phone that needs to ring, and a certificate that needs to stay current. That’s the whole job. We’ll take it.
Find Out Who's
Already In There.
Here is the whole argument in four lines. A cheap automated sweep found a brand-new site of ours within the window the padlock announced it. Nothing looked wrong from the outside — it kept loading perfectly for every visitor. Overwatch surfaced the intruder in four minutes. That is the difference between finding out yourself and finding out from somebody else’s lawyer.
Scanning asks whether it recognises something bad. Watching asks whether something moved that had no business moving. Only one of those catches a quiet tenant, and it is the one that never clocks off.
New to us? Start with the Free Scan. No card, no call, no obligation. You’ll see what an attacker sees from the outside, and you’ll know whether you need the next step.
Already audited and optimised with us? Then Overwatch is the next link in the chain. From $360 a month. No lock-in. No setup fees. No 2am phone calls. We watch. You sleep.
