Cyber Security Services for SMEs and Online Businesses

We test websites, online shops, APIs, AI chatbots and IT systems of SMEs for vulnerabilities and support NIS2 and ISO 27001 compliance. Certified security specialists from our partner network run the tests; our own web, shop and app team can fix the findings. Every test needs your written authorisation. Every package has a fixed price after an initial analysis.

Certified specialists from our partner network
Written authorisation before every test
Fixed price after an initial analysis

When you need us

Cyber security for small businesses rarely starts with a plan; it usually starts with a trigger. Find yours:

  • A customer, insurer or auditor asks for security evidence or sends a questionnaire. → Packages 1 and 6
  • An EU customer passes NIS2 requirements down its supply chain to you. → Package 4
  • A relaunch, a new web app, a customer portal or an AI chatbot is about to go live. → Package 2
  • Your website shows spam pages, strange redirects or unknown admin accounts. → Help with a hacked website
  • A tender or a key account requires ISO 27001. → Package 5
  • You sell installable software, apps or connected products in the EU. → CRA workshop

Testing and fixing with one point of contact

Certified security specialists from our partner network test, our own web, shop and app team can fix the findings, and you have one contact for both.

Your advantages at a glance

What small and medium-sized businesses can expect from our cyber security consulting services.
01
One contact for website, shop, app and security
Sharobella coordinates testing, reporting and fixes. You explain your systems once and have one contact for every question.
02
Certified specialists from our partner network
Testing and consulting are done by specialists with certifications such as CISSP, CISM, OSCP, OSCE and ISO 27001 Lead Auditor. The people working on your systems are named in the authorisation.
03
Written authorisation, prioritised report, closing meeting
On every test you set the scope and time window in writing, receive a report ranked by urgency and discuss it with the specialists.
04
Fixed price after an initial analysis
After the first call and scoping you receive a fixed price instead of an open-ended hourly bill.
05
Our own team can fix the findings
Our team fixes code, configuration, updates, apps and plugins in your website, shop and app, followed by a re-test. Servers, Active Directory and Microsoft 365 stay with your IT.
06
Reports your management can read
Every finding is listed with its urgency, an owner and the next step, plus a summary without jargon.

Our cyber security services and approach

Penetration testing services, NIS2 and ISO 27001 consulting and ongoing protection, in eight packages ordered by what you need: 1 to 3 find where you are exposed, 4 to 6 meet obligations and assign responsibility, 7 and 8 keep you protected. Efforts are rounded typical values from comparable projects; you receive the fixed price after an initial analysis.

01.
Outside-in security check: know where your company can be attacked from the internet

After the check you know which of your systems and credentials are exposed on the internet and what to do first.

For whom: every company with a website, online shop, customer portal or Microsoft 365. Typical triggers: a security questionnaire, an upcoming relaunch, a wave of phishing e-mails or simply the question of what attackers can find about you online.

Included:

  • your written authorisation before we start
  • an inventory of your publicly visible domains, subdomains, servers, cloud and Microsoft 365 services
  • automated checks for known vulnerabilities, assessed by certified specialists; hosted platforms and cloud services such as Shopify or Microsoft 365 only within the provider's rules
  • a search for credentials of your company domain in known data breaches
  • for existing clients also: our team reviews the admin accounts, apps and plugins of your website or shop
  • findings ranked by urgency, a results call and a clear recommendation for the next step

Turnaround: typically about one week from authorisation.

Fixed price after an initial analysis

02.
Penetration testing for websites, online shops, apps and AI chatbots

Website penetration testing that shows which weaknesses your applications have, how serious they are and in what order to close them.

For whom: online shops, web apps, customer and member portals, APIs, AI chatbots and agents. Triggers: a go-live, relaunch or major release; a new login, payment or customer-data feature; an AI agent that will answer without human approval; a customer, marketplace or insurer asking for a test report.

Included:

  • scoping, kick-off and written authorisation
  • web application penetration testing along the OWASP Top 10 and the OWASP Web Security Testing Guide: login and roles, cart and payment, customer data, admin areas
  • API penetration testing of your own interfaces to ERP, CRM, apps and partners
  • AI chatbots and LLM features: prompt injection, jailbreaks, unintended data disclosure
  • on Shopify and other hosted platforms: your own code (theme customisations, custom apps, your own interfaces, headless frontend), preferably in a development store or preview environment and within the platform provider's terms; for third-party apps we review configuration and permissions, not the vendor's servers
  • every finding confirmed by hand, a prioritised report and a closing meeting
  • optional: fixes by our team and a re-test

Typical effort: usually 2 to 10 person-days, depending on the size of the application; a re-test is usually much shorter.

Fixed price after an initial analysis

03.
Penetration testing for company IT: network, Active Directory and Microsoft 365

You learn which routes an attacker could take into your network and cloud, and get the countermeasure for each one.

For whom: companies with their own servers, a Windows domain or Microsoft 365 and Azure. Triggers: NIS2 risk management, ransomware concerns, a new IT provider, a cyber insurance questionnaire or the yearly test cycle.

Included:

  • scoping, kick-off and written authorisation; for red teaming and social engineering also agreed rules of engagement and an emergency contact
  • external penetration testing: your internet-facing servers, VPN and e-mail access; scanners give leads, specialists verify and follow up every hit
  • internal penetration testing with Active Directory: starting from a machine on your network that is assumed to be taken over, the specialists look for routes to domain admin rights
  • Microsoft 365 security assessment and Azure: who can do what, how accounts and sign-ins are protected, how the cloud connects to the internal network
  • reviews of Active Directory, Microsoft 365 and network or OT architecture against IEC 62443, as a configuration review
  • red teaming with social engineering on request, for larger organisations
  • infrastructure findings are fixed by your IT team or IT provider; you receive the prioritised list

Typical effort: single tests usually 2 to 10 person-days, depending on the number of systems; red teaming several weeks.

Fixed price after an initial analysis

04.
NIS2 readiness check: clarify your duties, prioritise the measures

You know whether and how NIS2 affects you, and you have a plan with clear priorities.

For whom: medium-sized and large companies in NIS2 sectors in the EU, and suppliers inside or outside the EU whose in-scope customers pass NIS2 requirements down the supply chain.

Included:

  • NIS2 applicability: whether you are covered directly as an essential or important entity, or indirectly as a supplier
  • support with registration where it applies to you
  • a NIS2 gap analysis of your security measures against the requirements, with a prioritised plan
  • a process for reporting significant incidents: who decides, who reports, by when
  • cyber security training for management
  • supplier version: when customers pass NIS2 requirements on to you, we prepare questionnaires and evidence with you

Typical effort: usually 2 to 10 person-days, depending on size and starting point.

Fixed price after an initial analysis

Not legal advice; you complete any registration yourself.

05.
ISO 27001 and gap analysis: from baseline to certification audit

You see where you stand against a standard and reach the audit with a clear plan.

For whom: companies whose tenders, key accounts or industry rules ask for evidence against ISO 27001, TISAX, IEC 62443 or DORA, and companies that want a solid baseline without certification (CIS Controls).

Included:

  • ISO 27001 gap analysis or a cyber security gap analysis against NIS2, TISAX, IEC 62443, DORA or CIS Controls: we talk to the people responsible, review policies and evidence and rate every requirement on a maturity scale. The result is an action plan that starts with what matters most
  • ISMS set-up: together we define the scope, set the risk assessment method and draft the Statement of Applicability (SoA), plus responsibilities and a timeline towards the audit
  • ISO 27001 implementation support up to the stage 2 certification audit, including an internal audit
  • The certificate is issued by an accredited certification body of your choice; its audit fees are not included.

Typical effort: gap analysis usually 2 to 10 person-days per standard; the path to the certification audit usually takes several months.

Fixed price after an initial analysis

06.
Virtual CISO (vCISO): a named security lead without a full-time hire

Information security has a named owner in your company who reports to management.

For whom: companies without a security lead; NIS2 entities whose management must oversee the risk-management measures; companies facing a growing pile of customer security questionnaires.

Included:

  • vCISO as a service: a named person in the CISO role, reporting directly to management
  • regular meetings with your team on risks, open actions and policies
  • preparing the management review
  • answering security questionnaires from your customers and suppliers
  • coordinating tests, monitoring and fixes, with our team for web, shop and app

Typical effort: a few person-days per month.

Fixed price after an initial analysis (monthly)

07.
Continuous protection: attack surface and dark web monitoring, pentest as a service

New vulnerabilities and leaked credentials surface between two tests, not only at the next one.

For whom: companies after an outside-in check or a pentest, teams that release often, NIS2 entities, and clients of our website maintenance who want to add security monitoring.

Included:

  • attack surface and dark web monitoring after your written authorisation: your internet-facing systems are discovered and checked for new vulnerabilities on an ongoing basis; if credentials of your domain appear in data breaches or on the dark web, you are told
  • optional scanners inside your network, with all findings in one view
  • pentest as a service: you reserve person-days for the year and use them whenever your systems change significantly or findings need a re-test; each call-off starts with its own written authorisation, and the same people who already know your environment do the testing
  • optional DNS protection with an allowlist: devices on your network only connect to domains rated as trustworthy
  • we set everything up, train your team and stay on it; findings in your website, shop and app go straight to our team

Typical effort: pentest as a service with as many person-days a year as you need; monitoring and DNS protection licensed by company size.

Fixed price after an initial analysis, licence by company size

08.
Security awareness training and phishing simulation: your team learns to spot e-mail attacks

Your staff learn to recognise phishing before anyone clicks.

For whom: every team that handles e-mail, orders and payments; NIS2 entities that must train their staff and management; after a phishing incident or at your insurer's request.

Included:

  • simulated phishing e-mails after written authorisation by management, evaluated by team rather than by person and agreed with your works council where there is one
  • role-based training for staff, managers and IT
  • a short report with next steps, repeatable every year

Typical effort: depends on team size and format.

Fixed price after an initial analysis

Available as add-ons

CRA compliance: Cyber Resilience Act workshop for software and app teams. Together with your developers we clarify which of your products fall under the CRA, what that means for you as a manufacturer and how you receive, fix and report vulnerabilities. Typical effort: a few person-days. Fixed price after an initial analysis.

Fixes from one source. Our web, shop and app team fixes findings in code and configuration, installs updates and cleans up apps and plugins, followed by a re-test. Not included: fixes in the internal network, Active Directory and Microsoft 365. Scope depends on the findings; fixed price after an initial analysis.

Help with a hacked website or online shop. We assess the situation in a first call, clean the site or reinstall it cleanly, then harden it. If needed, specialists from our partner network take on the forensic analysis. Afterwards you can hand ongoing care to our website maintenance. Fixed price after an initial analysis.

Re-test of fixed vulnerabilities. It checks specifically whether the fixed findings are closed and is usually much shorter than the original test. Fixed price after an initial analysis.

How we work

The penetration testing process is the same for every test and every consulting project, and it never starts without your written authorisation: you decide what is tested and when.

Six steps from first call to re-test

01
Free 30-minute scoping call
You tell us the trigger, your systems and your deadlines. We tell you which package fits and what you can expect from it.
02
Outside-in check or scoping
Either the outside-in check shows what is visible from the internet, or we agree the scope and testing depth together.
03
Fixed-price proposal
You receive a proposal with scope, timeline and a fixed price.
04
Kick-off, confidentiality and written authorisation
We agree confidentiality, contacts and the time window. No test starts without a signed authorisation.
05
Test or assessment, report ranked by urgency, closing meeting
Depending on the brief, as a black-box, grey-box or white-box test, meaning with no, partial or full prior knowledge of your systems. Then we go through the report with you.
06
Fixes (by our team if you wish) and re-test
Our team can fix the findings in your website, shop and app; a re-test checks whether the gaps are closed.

Security for websites, online shops, apps and AI chatbots

We build and support websites, shops, apps and AI solutions ourselves. The security testing is done by certified specialists from our partner network, and our team can take care of the fixes.

Online shops: Shopify, WooCommerce, Shopware and headless

Penetration testing for online shops covers accounts and staff permissions, theme customisations and custom code, custom apps and your own interfaces, headless frontends and, on self-hosted shops such as WooCommerce or Shopware, checkout and payment. For third-party apps we review configuration and permissions, not the vendor's servers. Tests run preferably in a development store or preview environment and within the platform provider's terms; the platform itself is not part of the test. More about our work as a Shopify agency, WooCommerce agency and e-commerce agency.

Websites, web apps and APIs

WordPress sites, Laravel applications, customer and member portals and APIs: we test login, roles, data access and interfaces. API security testing looks at authentication, authorisation and what each endpoint reveals. A WordPress security audit usually centres on plugins, admin accounts and updates. More: WordPress agency, Laravel agency, web development.

AI chatbots and agents: LLM penetration testing

Prompt injection testing, jailbreaks and unintended data disclosure: we test your AI chatbot before it answers customers without human approval. More: AI agency.

Apps and the Cyber Resilience Act

If you sell apps or connected products in the EU, plan the CRA workshop (see the add-ons). More: mobile app development.

Website or online shop hacked? Call +43 1 3940 098 or write to office@sharobella.com. After the clean-up, our website maintenance can take over the ongoing updates.

EU rules in brief: NIS2 and the Cyber Resilience Act

As of October 2026. An overview, not legal advice.

  • NIS2 (Directive (EU) 2022/2555; Commission overview) covers, as a rule, medium-sized and large entities in 18 critical sectors, and member states can add smaller entities with a high risk profile. The duties come from each member state's national law.
  • In-scope entities must take cybersecurity risk-management measures, report significant incidents and address security risks in their supply chains and supplier relationships; top management is accountable. That is why suppliers receive security questionnaires.
  • Certain digital service providers that serve the EU without an EU establishment, such as cloud, data centre and managed security service providers, have to name a representative in the EU (Commission NIS2 FAQ).
  • The Cyber Resilience Act (Regulation (EU) 2024/2847; Commission summary) covers hardware and software products with digital elements made available on the EU market, such as installable software, mobile apps, firmware and connected devices. Websites and standalone SaaS are generally not covered unless they are the remote data processing of such a product. EU importers must check that non-EU manufacturers have complied.
  • CRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, also to products already on the market; the main obligations apply from 11 December 2027. The Commission published practical guidance on 27 July 2026.

Our NIS2 readiness check (package 4) clarifies where you stand; the CRA workshop does the same for your products.

Who does the work

Tests and consulting are carried out by certified security specialists from our partner network, holding certifications including CISSP, CISM, OSCP, OSCE and ISO 27001 Lead Auditor. Sharobella is your point of contact and coordinates testing, reporting and fixes.

The team that will test your systems is named in the written authorisation before the project starts. Findings in your website, shop and app can be fixed by the same team that builds websites, shops and apps with us.

Every report also states what was not tested. Nobody can promise absolute security, and neither do we. What you get: traceable findings, clear priorities and a contact who follows through.

What does cyber security cost?

Every package has a fixed price after an initial analysis. For us, the initial analysis is the free 30-minute scoping call: afterwards you know what a penetration test, a NIS2 readiness check or ISO 27001 support will cost you, before you commit.

What drives the price:

  • number of systems and IP addresses
  • size and user roles of the application
  • testing depth
  • standards in scope
  • whether you want a re-test

Typical effort (rounded values from comparable projects, not a quote):

  • penetration test of a website, shop, app, AI chatbot, external systems, Active Directory or Microsoft 365: usually 2 to 10 person-days, depending on scope
  • NIS2 readiness check or gap analysis per standard: usually 2 to 10 person-days
  • CRA workshop: a few person-days
  • red teaming: several weeks of effort
  • ISO 27001 from ISMS set-up to the certification audit: several weeks of effort spread over several months
  • vCISO: a few person-days per month
  • re-test: usually much shorter than the original test

For ISO 27001, the certification body's fees come on top. Licences for ongoing monitoring depend on company size.

Frequently asked questions

01
What is a penetration test, and what do we receive at the end?
A penetration test is an authorised, simulated attack in which specialists try to exploit weaknesses in your systems. You receive a report that ranks every finding by urgency, with evidence and a recommended fix, and states what was not tested. A closing meeting walks you through the results, and a re-test is available.
02
Is penetration testing legal?
Yes, if the system owner authorises it in writing, with an agreed scope and time window; hosting and cloud providers' testing rules apply too. Without authorisation it can be a criminal offence, for example under Austrian law (section 118a StGB) or the UK Computer Misuse Act 1990. So every project starts with a signed authorisation naming the testers.
03
Who carries out the tests?
Certified security specialists from our partner network carry out the tests and consulting, holding certifications including CISSP, CISM, OSCP, OSCE and ISO 27001 Lead Auditor. The people who will test your systems are named in the written authorisation before the project starts. Sharobella is your point of contact and coordinates testing, reporting and fixes.
04
How long does a penetration test take?
Typical efforts from comparable projects are 2 to 10 person-days, depending on scope: an external test sits at the lower end, an internal test with Active Directory at the upper end. Calendar time also depends on scheduling and on how quickly access is set up. A re-test is usually much shorter than the original test.
05
How much does a penetration test cost?
Every penetration test has a fixed price, which you receive after an initial analysis. The effort depends on the number of systems and IP addresses, the size and user roles of the application, the testing depth and whether you want a re-test. Typical range: 2 to 10 person-days, less for an external test, more for internal networks.
06
Can automated scanners or AI tools replace a manual penetration test?
Not fully. Scanners are part of the method and find known weaknesses quickly, but they report false positives and miss logic flaws, such as one customer seeing another customer's orders. The certified specialists from our partner network confirm each finding by hand and link small weaknesses into realistic attack paths, which a scan report alone does not show.
07
Can you test our online shop, web app or AI chatbot?
Yes. Certified specialists from our partner network test online shops, web apps, customer portals, APIs and AI chatbots, including prompt injection. On Shopify and other hosted platforms they test your own code (theme customisations, custom apps, a headless frontend), preferably in a development store and within the provider's terms. For third-party apps they review configuration and permissions.
08
Does NIS2 apply to companies outside the EU, for example in the UK?
Directly, only in specific cases. Certain digital service providers serving the EU without an EU establishment, such as cloud, data centre and managed security service providers, have to name a representative in the EU. More often the effect is indirect: in-scope EU companies must manage security risks in their supply chain, so their suppliers receive questionnaires and contract terms.
09
What is the difference between ISO 27001 and NIS2?
ISO/IEC 27001 is an international standard for an information security management system that you can have certified; it is not a law. NIS2 is an EU directive, implemented in national law, with binding duties for in-scope entities. An ISMS helps with many NIS2 measures, but a certificate does not replace duties such as registration or incident reporting.
10
How long does ISO 27001 certification take?
In comparable projects it usually takes several months from setting up the information security management system (ISMS) to the stage 2 certification audit, including an internal audit. The timeline depends on scope, existing documentation and how much time your team can give. The certificate is issued by an accredited certification body, not by us.
11
What does a virtual CISO do?
A virtual CISO (vCISO) takes on the chief information security officer role part-time, so you do not need a full-time hire. The person reports directly to management, holds regular meetings with your team, runs risk management and policies, prepares the management review and answers customers' security questionnaires. Typical effort is a few person-days a month.
12
Does the Cyber Resilience Act apply to our software or app?
It depends on what you ship. Installable software, mobile apps, firmware and connected devices supplied in the EU in the course of business, paid or free, usually fall under the CRA, including non-EU manufacturers' products. Websites and standalone SaaS generally do not. Reporting obligations apply from 11 September 2026, the main obligations from 11 December 2027.
Let's spend 30 minutes on your security.
Free and without obligation: tell us the trigger and your systems, and we will tell you which first step makes sense.

Prefer to get in touch directly? Write to office@sharobella.com or call +43 1 3940 098, and tell us your domain and the reason, for example a questionnaire, NIS2, a go-live or a suspected hack.

Related services: Shopify agency · e-commerce agency · Laravel agency · AI agency · mobile app development.

Take the First Step to a Better Digital Strategy.
Please complete this field
Please complete this field
Please complete this field
Please complete this field
Please complete this field
Have a nice day! :)
Failure sending form…
WhatsApp Chat