Service & security agreements
Ongoing responsibility for websites, including updates, security checks, backups, recovery readiness, logging and a prioritised incident path.
3ON × SecuureIT · Security Research & Response
Technical field reports and lessons from incidents, recoveries and systems running in production. We publish methods, measurements, limitations and mitigations — while anonymising client work where confidentiality requires it.
SecuureIT is the security practice within the 3ON group. Security Lab brings together production experience from incident response, web and application security, hosting and emerging risks from AI agents and crawlers.
Field reports & response cases
Meta-ExternalAgent generated 161,989 requests in the analysed dataset, with 154,206 targeting a WooCommerce cart. After an early crawler guard was deployed, observed CPU fell from 99.7% to 1.8% while the bot continued attempting cart requests.
The client suffered a compromise where weaknesses had been exploitable over an extended period. We recovered two websites, analysed intrusion paths and underlying weaknesses, removed residual risk and hardened the environments to reduce the likelihood of re-entry. The client name and technical details that could increase attack surface are not published.
Security operations
Ongoing responsibility for websites, including updates, security checks, backups, recovery readiness, logging and a prioritised incident path.
Fast analysis during compromise or abnormal load, prioritising recovery first and then root cause, persistence, weak points and hardening.
WordPress, web apps, APIs, WAF, permissions, forms, file handling, hosting and safer architecture from day one.
Lab principles
We separate log data and verified measurements from conclusions and hypotheses. Raw evidence is retained when privacy and security allow.
We describe which data was analysed, what was counted and which limitations apply so conclusions can be reviewed.
The first goal is to stabilise production. Then we document root cause, residual risk and what other operators can do.
What belongs here?
Security Lab covers classic web and WordPress security, hosting, incident response and application risk — but also emerging production failures where legitimate automated systems behave in ways that create unintended damage. Client cases are published only when this can be done without exposing the client, infrastructure or useful attack details.
Need help?
We can step into active incidents or take ongoing service and security responsibility for websites where operations, backup, updates and security need a clear technical owner.
Security / SecuureIT →