By agreement

Cybersecurity and website security

Cybersecurity for businesses without the scare tactics: we check your website, close common gaps, set up monitoring and prepare recovery.

Cybersecurity for businesses

Cybersecurity for businesses is not only a topic for large corporations. Your website, email, hosting and domain account are the front door, even for a small company. If one of them is taken over, orders, customer trust and daily work all suffer.

KVANTS helps you sort out website security in a practical way. We check what is poorly protected, close the typical weak points, set up monitoring and prepare backups. If trouble has already happened, we help you get back to work and understand what went wrong.

We are two people who build and run projects ourselves, so we know how things look from the inside. Nobody can promise complete protection. Our aim is to reduce the risk, spot problems early and make recovery fast and clear.

Small firms are targets too

In the first quarter of 2026, CERT.LV manually handled 846 cyber incidents, the second highest quarterly figure on record. On 22 June a ransomware attack was detected at AS «Latvijas valsts meži» and, according to CERT.LV, about 44 GB of data leaked.

From 8 to 10 August, CSDD data leaked through a vulnerability in the web application med.csdd.lv, affecting payment receipt data of about 1.2 million people. The review commission found that two-factor authentication was not used, monitoring was insufficient, and there was no control of request volumes or anomaly detection. In early September the website of TSC, an LMT group smart-device repair company, was hacked and attackers obtained about 7% of customer data. The State Police urged all companies to check their websites.

The conclusion is simple: the same basics, namely 2FA, monitoring, request limiting and updates, matter for a small business too. Attacks are often automated and do not choose victims by size. A bot simply looks for an old plugin or an open login page.

Security audit

A security audit is a check of your website and the systems connected to it. You receive a written list of findings by priority and a fix plan that either we or your own developer can carry out.

Software

We check the CMS core, plugins, themes and PHP versions, and look for outdated software.

Open doors

We look for reachable admin panels, forgotten test copies and wrong file permissions.

Connection settings

We review security headers (HSTS, CSP and others) and the TLS configuration.

Custom code

We check basic OWASP Top 10 issues, such as injection and broken access control.

Access

We find out who has access to what, and which accounts are no longer needed.

Everyday protection

Most problems come from small things that are not done regularly. That is why security is a set of habits, not a one-off task.

Scheduled updates

We update the CMS, plugins and other software regularly, always making a backup first.

Cloudflare in front

With WAF rules and DDoS protection we filter clearly harmful traffic. Rate limiting on login pages, forms and APIs slows down bots and password guessing.

2FA and access

We set up two-factor authentication (2FA) for the admin panel, hosting, email and the domain/DNS account. We remove old users and move to unique passwords in a password manager.

Backups and monitoring

We make backups on the 3-2-1 principle: three copies, in two different locations or on different media, one of them off-site. Backups are kept on a separate server, not on the one where the website runs. We also test restoring regularly, because a backup that has never been restored is only a hope.

Monitoring lets you learn about a problem before your customers do. We watch site availability, unexpected file changes, SSL expiry and unusual traffic or login attempts, and send alerts. Sites of KVANTS hosting clients are also monitored through status.kvants.lv.

  • availability and response time
  • unexpected file changes
  • SSL certificate expiry date
  • unusual traffic and login attempts

If your site is hacked

If your website has been hacked, the key is to act calmly and in order. Hacked website recovery usually goes like this:

  • isolate the site so the damage does not spread
  • find the entry point
  • remove malware and backdoors
  • restore from a clean backup
  • change all passwords and keys
  • close the vulnerability
  • check whether the site has landed on Google blocklists

Reporting an incident

You can report an incident to CERT.LV. If personal data has leaked, the company as data controller must notify the Data State Inspectorate (DVI) within 72 hours of learning about the breach, under Article 33 of the GDPR, if the breach poses a risk to people.

We help gather the facts and prepare the technical part. The legal decisions are yours, including whether and how to report.

NIS2 and suppliers

The National Cybersecurity Law has been in force since 1 September 2024 and transposes the requirements of the EU NIS2 directive. It mainly applies to medium and large companies in regulated sectors.

However, their suppliers increasingly receive security requirements in contracts: 2FA, backups, incident reporting, updates. We help small suppliers meet such technical requirements. We do not offer compliance certification.

What's included?

Security audit of the website and connected systems

Written list of findings by priority

Fix plan

Regular updates with a backup beforehand

Cloudflare setup: WAF, DDoS protection, rate limiting

2FA setup and removal of old users

Password manager setup

3-2-1 backups on a separate server and restore tests

Monitoring and alerts

Cleanup and recovery after a hack

Help with the technical part of an incident report

Why choose us?

Full cycle

Development, design, hosting, email, maintenance — all in one place. No need to coordinate multiple vendors.

Own infrastructure

Client projects run on our servers with 24/7 monitoring. We catch issues before your visitors do.

Clear pricing

A development plan before work starts and a fixed project price. No upfront payment for small jobs.

Direct contact

You talk directly to the developer, not a project manager. Faster decisions, fewer misunderstandings.

How we work

1

Short conversation

We learn what you have: website, online store, hosting, and who works with them.

2

Audit

We check the site and access rights and find the weak points.

3

Written plan

You receive findings by priority and a quote; the price depends on scope.

4

Fixes

We close the most important problems and set up 2FA, Cloudflare and backups.

5

Monitoring

We keep following updates, alerts and restore tests.

Frequently asked questions

Can my small website really be a target?

Yes. Attacks are often automated and look for old versions or weakly protected login pages, whatever the size of the company. A small site can be used to send spam or as a route to other systems.

What does a security audit cover, and do you need access?

The audit covers software versions, open entry points, security headers, TLS, basic code issues and access rights. We usually need read-only access to the site or hosting, agreed in advance. The result is a written list with priorities.

Do you work with WordPress, other CMSs and custom code?

Yes. We handle WordPress security, other CMSs, and custom-built sites and applications. Each type has its own typical risks, and we take them into account in the audit.

Is Cloudflare enough?

No. Cloudflare with WAF and DDoS protection is useful, but it does not replace updates, 2FA, backups and monitoring. Security is made of several layers.

What should I do first if my website is hacked?

If possible, take the site offline for the public for a while, change passwords from a safe computer and do not delete anything, because the files help find the cause. Then contact us or your developer to start isolation and recovery.

Do I have to report to the DVI?

If a personal data breach has occurred that poses a risk to people, the controller must report to the DVI within 72 hours of learning about it (GDPR Article 33). The decision is yours; we help with the technical facts.

Does NIS2 apply to me?

The law mainly applies to medium and large companies in regulated sectors. If you supply them, security requirements may appear in your contract. If you are unsure, write to us and we will read the requirements together.

Can the website never be hacked after this?

Honestly, nobody can promise that. We reduce the risk, spot problems early and prepare fast recovery. We prepare the price and scope of work in writing after a short conversation.

Price

Custom quote

  • Free consultation
  • Custom quote
  • Fast technical support

Need help?

Our team is ready to answer your questions.

Ready to start your project?

Get in touch today for a free consultation.

Start now