NodeOps Security Infrastructure · Assurance
Primary activity · EMTAK 62201

IT infrastructure and cybersecurity, delivered remotely.

Our core practice covers technical security auditing, Linux and Windows server infrastructure, database performance and DevOps support. Engagements are scoped in writing and quoted as a fixed fee wherever the work allows it.

Four connected columns describing the stack we operate: edge, compute, data and assurance.
Primary service

Technical security audits

A scanner gives you a list. An audit tells you which items on that list an attacker could actually chain together, and what it would cost you if they did. We verify every finding by hand before it reaches your report.

What we look at

  • Internet-facing attack surface: what is exposed, and should it be
  • Operating system hardening against CIS-style baselines
  • Identity and access: privilege paths, stale accounts, shared credentials
  • Remote access: SSH, RDP, VPN and jump host configuration
  • Web and application server configuration, TLS and certificate hygiene
  • Patch and vulnerability management in practice, not on paper
  • Backup coverage - and whether a restore has ever been tested
  • Logging and detection: would you know, and how soon

What you get

  • Findings report ranked by exploitability and business impact
  • A concrete, specific remediation step for every finding
  • Executive summary written for non-technical decision makers
  • Prioritised remediation roadmap with effort estimates
  • Walkthrough call with your technical team
  • Free re-test of remediated findings within the agreed window
CIS BENCHMARKSOWASPOPENSCAPNMAPLYNISSSH / RDP / VPNTLS / PKI
Primary service

Linux infrastructure

Most Linux estates are not insecure because of an exotic exploit. They are insecure because nobody owns them, nothing is documented and patching stopped two years ago. We make servers boring again.

What we look at

  • Debian, Ubuntu, RHEL, Rocky Linux and AlmaLinux estates
  • Provisioning and configuration management with Ansible
  • Web and application stacks: Nginx, Apache, PHP-FPM, Node.js
  • DNS, mail delivery, SPF/DKIM/DMARC and TLS certificate lifecycle
  • Firewalling, segmentation and host-based controls
  • Storage, filesystem layout and capacity headroom
  • Kernel and package patch cadence, including reboot strategy

What you get

  • Documented, reproducible server builds - no more snowflakes
  • Configuration in version control that you own
  • Monitoring and alerting tuned to be worth waking up for
  • Centralised logging with sensible retention
  • A patch schedule that fits your maintenance windows
  • Runbooks for the tasks your team performs most often
DEBIAN / UBUNTURHEL / ROCKY / ALMAANSIBLENGINXAPACHESYSTEMDNFTABLESPROMETHEUSGRAFANA
Primary service

Windows Server infrastructure

Active Directory tends to accumulate: old service accounts, nested groups nobody can explain, Group Policy layered over a decade. We clean it up without breaking the business that depends on it.

What we look at

  • Active Directory structure, trusts, delegation and privilege escalation paths
  • Group Policy review, consolidation and security baselines
  • Service accounts, stale objects and password policy
  • File, print and Remote Desktop Services
  • Microsoft Defender, endpoint policy and application control
  • Update management and reboot orchestration
  • Backup coverage for domain controllers and critical roles

What you get

  • A documented, current map of your directory
  • A rationalised Group Policy set with a tested baseline
  • Tiered administration model for privileged accounts
  • Patch and update process with reporting
  • Verified backup and directory recovery procedure
  • Change log of everything we touched, with rollback notes
WINDOWS SERVERACTIVE DIRECTORYGROUP POLICYPOWERSHELLWSUS / INTUNEDEFENDERRDSHYPER-V
Primary service

Database optimisation

Slow databases are usually a handful of queries, a missing index and a default config that was never revisited after launch. Fixing that is often cheaper than the bigger server somebody is about to buy.

What we look at

  • Slow query capture and execution plan analysis
  • Index strategy: what is missing, what is redundant, what is never used
  • Schema and data type review for growth
  • Server configuration: memory, checkpoints, autovacuum, buffer pools
  • Connection handling and pooling
  • Replication topology, failover behaviour and lag
  • Backup strategy, point-in-time recovery and restore testing

What you get

  • Before-and-after measurements on the queries that matter
  • Applied index and configuration changes, with rationale
  • Documented backup and recovery procedure that has been run
  • Capacity forecast so the next bottleneck is not a surprise
  • Monitoring for query performance regressions
  • Guidance your developers can apply to future queries
POSTGRESQLMYSQLMARIADBSQL SERVERREDISPGBOUNCERREPLICATIONPITR
Primary service

DevOps support

Automation is only useful if your team can read it, change it and trust it. We build pipelines and infrastructure code that stay maintainable after we leave.

What we look at

  • CI/CD pipelines: build, test, deploy and rollback
  • Infrastructure as code with Terraform and Ansible
  • Containerisation and environment parity between dev and production
  • Secrets management and credential rotation
  • Release process, change control and deployment windows
  • Build and dependency hygiene, including supply chain basics

What you get

  • Pipelines documented in the repository they belong to
  • Reproducible environments from code, not from memory
  • A rollback path that has actually been exercised
  • Secrets out of source control and into a managed store
  • Handover sessions so your team owns it, not us
GITLAB CIGITHUB ACTIONSTERRAFORMANSIBLEDOCKERKUBERNETESVAULTGIT
Primary service

Managed remote operations

An ongoing contract for the infrastructure work that never makes it to the top of anyone’s sprint: patching, monitoring, capacity, backups and the call at two in the morning.

What we look at

  • Proactive patching across Linux and Windows estates
  • Monitoring, alert triage and noise reduction
  • Backup verification and periodic restore tests
  • Certificate, domain and licence expiry tracking
  • Capacity and cost review
  • Incident response with an agreed escalation path

What you get

  • Agreed response targets, written into the contract
  • A named engineer who knows your environment
  • Monthly report a non-technical director can act on
  • Living documentation and runbooks that stay current
  • Quarterly review of risks, capacity and spend
MONITORINGPATCH MANAGEMENTBACKUP / DRINCIDENT RESPONSEON-CALL ESCALATION
What a report looks like

Every finding arrives with its fix.

We do not hand over a scanner export and call it an audit. Findings are verified by hand, ranked by what they would actually let someone do, and paired with a specific remediation step - not “review your configuration”.

  • Severity based on exploitability and business impact, not CVSS alone
  • Evidence for each finding, so your team can reproduce it
  • Executive summary separate from the technical detail
  • Re-test of remediated items included in the engagement
Terminal output from a security audit next to a panel summarising findings by severity.

Not sure which of these you need?

Describe your environment and the problem you are trying to solve. We will tell you what we would look at first - and if it is not something we should be doing, we will say so.