Blanchards Bailey
New identity for leading solicitor
Security is built into how we work rather than added at the end. Every site we build comes with certified hosting, an enterprise firewall and a content management system chosen for how few doors it leaves open.
Your website holds customer data, enquiry forms and your reputation. Protecting it is part of the job.
No single measure keeps a website safe. We combine certified working practices, enterprise hosting, a managed firewall and a CMS that gives attackers less to aim at, then maintain all four for as long as we look after the site.
Fathom holds Cyber Essentials certification, the UK government-backed standard for defending against common cyber attacks. It covers how we configure our devices, control access to systems, manage software updates and defend against malware.
Certification requires independent assessment and annual renewal. The practices behind it run every day: strong access controls, patched software, and a team trained to spot a phishing attempt before it becomes a problem.
We host client sites with two UK providers: ANS and Rackspace, both running UK data centres.
ANS holds many certifications including ISO 27001, ISO 27017 and ISO 27018 for information security, plus Cyber Essentials Plus, PCI DSS Level 1 and SOC 2 Type 2. Rackspace adds 24/7 managed support and global infrastructure for clients who need it.
Our ANS servers also run Managed XDR, which watches the whole environment rather than one part of it: servers, network, applications and identities. Suspicious activity is correlated into a single incident and dealt with automatically, with a UK-based security operations team monitoring around the clock and stepping in when a human decision is needed.
Two providers give us room to match the hosting to the site. A corporate brochure site, a campaign microsite expecting heavy traffic and an e-commerce platform taking payments all have different requirements.
Cloudflare sits in front of every site we build. Its firewall filters traffic before it reaches the server, blocking malicious requests, absorbing denial-of-service attacks and managing SSL certificates. Pages load faster as a result, which clients tend to notice first.
WordPress sites get a second layer. Attackers target WordPress more than any other CMS. Most attacks arrive through outdated third-party plugins, so we add Sucuri for malware scanning, virtual patching and its own web application firewall.
We recommend Craft CMS for almost every project. Craft has a small, curated plugin marketplace where WordPress has tens of thousands of plugins, so there is far less third-party code to go wrong and far less for an attacker to probe.
Craft ships with CSRF token validation, prepared database queries and modern password hashing enabled by default. A commercial team maintains it and funds the security work, which shows in how quickly patches arrive.
Where a client needs WordPress, we build it carefully and protect it with Sucuri. For everything else, Craft is the safer place to start.
Software changes after a site goes live. Vulnerabilities get disclosed, platforms release patches and attack methods move on. A website left untouched for two years is a website with a problem building quietly in the background.
Our support agreements cover CMS and plugin updates, SSL renewal, uptime monitoring and off-site backups. When a patch is released, we test it and apply it. If something does go wrong, we can restore the site from a known-good backup.
We work with organisations in defence, aerospace, financial services and law. Their IT and procurement teams ask detailed questions about where the site is hosted, how data is handled and what certifications sit behind it. We are used to answering those questions and can supply the documentation to back up the answers.
If you do not know how your current site is hosted, what sits in front of it or when it was last updated, that is worth finding out. Send us the address and we will tell you what we can see from the outside.