HomeWeb DevelopmentWebsite Security & Care
Specialty · Web Development

Website security
& ongoing care.

Security hardening, updates, backups and monitoring for your website or shop. Honest in scope: I secure your web presence and keep it running — for corporate networks, endpoints and SOC operations I refer specialised partners.

Website-Sicherheit & Wartung
Why now

Outdated websites are the no. 1 entry point.

Attacks on CMS and shops are fully automated in 2026: bots scan around the clock for outdated plugins, exposed logins and missing security headers. Leaving updates, backups and monitoring to chance risks downtime, data loss and Google penalties. The countermeasures are well known and affordable — they just need to be run consistently.
Alexander Ohl Alexander OhlFounder · Pragma-Code
Cybersecurity & Compliance

Cyber Resilience and NIS2 Compliance

Since 2025, the EU NIS2 directive obliges thousands of companies across the DACH region to implement active risk management. Non-compliance means severe fines and personal liability for management.

NIS2 Directive and Cyber Resilience for SMEs

What NIS2 Means for Your Business

📋 NIS2 Scope & Obligations

Does the NIS2 directive apply to your company? From as few as 50 employees or €10M revenue, strict obligations kick in: risk management, 24-hour incident reporting, and supply chain security.

⚠️ Avoiding Severe Penalties

Violations can result in fines of up to €10M or 2% of global annual revenue. Additionally, personal liability of managing directors is at stake — a risk no SME should ignore.

🛡️ My Contribution: the Web Layer

I harden the part attackers scan first: website, shop and hosting environment — with documented security measures, secure forms, backups and monitoring. For network, endpoint and SOC topics I work with specialised security partners.

🔍 Free Website Check

The free website check identifies weaknesses at the web level and delivers a prioritised action plan. For full NIS2 certification I refer vetted compliance specialists on request.

Read the NIS2 Guide for SMEs
Services · 04

Four building blocks for a secure website.

What I concretely implement and continuously operate.

Hardening & security headers

CSP, HSTS and modern TLS configuration, hardened logins with 2FA, bot and spam protection for forms, least-privilege CMS roles.

Update & patch management

Keeping CMS core, plugins and dependencies current — tested in staging instead of blindly in production, with documented rollback.

Backups & recovery

Automated, versioned backups stored off the web server — including regular restore tests so the backup actually works when needed.

Monitoring & response

Uptime, malware and blacklist monitoring with clear response paths. Technical GDPR implementation (consent, embeds, forms) included.

Process · 04 steps

From check to secure operations.

Systematically harden instead of patching ad-hoc.

01 Free

Website check

Free automated check plus manual review: headers, TLS, update status, backup situation, GDPR basics.

02

Hardening

Quick wins first: critical updates, security headers, login hardening, form protection — with before/after evidence.

03

Safeguarding

Set up backup strategy and monitoring, prepare a staging environment for future updates.

04

Ongoing care

Monthly maintenance with a short report: what was updated, what monitoring flagged, what comes next.

FAQ · 04

Frequently asked.

Answers on scope, limits and cost.

What does ongoing maintenance cover?
Updates of CMS, plugins and dependencies (tested in staging), backup operations with restore tests, uptime and malware monitoring, small fixes and a short monthly report. Larger rebuilds run as separate projects with their own quote.
Do you also cover firewalls, endpoints and SOC?
No — and I say that openly on purpose. My focus is the security of your web presence: website, shop, hosting environment. For corporate networks, endpoint protection and 24/7 SOC operations I recommend specialised security providers and help with selection and integration.
Does this help with GDPR and NIS2?
At the website level: yes. Clean consent integration, data-minimal forms, EU hosting advice and documented security measures are part of the hardening. It does not replace legal advice or a full NIS2 compliance certification.
What does website security & maintenance cost?
One-off hardening runs as a fixed-price project after the free website check. Ongoing care is the core of the Web & Tech package from €390/month — scope and cadence depend on the size and criticality of your site.
Free & no obligation

How secure is your website today?

The free website check shows you the biggest weaknesses in minutes — with concrete, prioritised actions.

Alexander Ohl

Alexander Ohl

Pragma-Code Support (AI) • Online

Hello! I am the Pragma-Code Assistant. How can I help you today? You can ask me about our services or select a topic below.