Cyber Security Services for SMEs and Online Businesses
We test websites, online shops, APIs, AI chatbots and IT systems of SMEs for vulnerabilities and support NIS2 and ISO 27001 compliance. Certified security specialists from our partner network run the tests; our own web, shop and app team can fix the findings. Every test needs your written authorisation. Every package has a fixed price after an initial analysis.
When you need us
Cyber security for small businesses rarely starts with a plan; it usually starts with a trigger. Find yours:
- A customer, insurer or auditor asks for security evidence or sends a questionnaire. → Packages 1 and 6
- An EU customer passes NIS2 requirements down its supply chain to you. → Package 4
- A relaunch, a new web app, a customer portal or an AI chatbot is about to go live. → Package 2
- Your website shows spam pages, strange redirects or unknown admin accounts. → Help with a hacked website
- A tender or a key account requires ISO 27001. → Package 5
- You sell installable software, apps or connected products in the EU. → CRA workshop
Testing and fixing with one point of contact
Certified security specialists from our partner network test, our own web, shop and app team can fix the findings, and you have one contact for both.
Your advantages at a glance
Our cyber security services and approach
Penetration testing services, NIS2 and ISO 27001 consulting and ongoing protection, in eight packages ordered by what you need: 1 to 3 find where you are exposed, 4 to 6 meet obligations and assign responsibility, 7 and 8 keep you protected. Efforts are rounded typical values from comparable projects; you receive the fixed price after an initial analysis.
Outside-in security check: know where your company can be attacked from the internet
After the check you know which of your systems and credentials are exposed on the internet and what to do first.
For whom: every company with a website, online shop, customer portal or Microsoft 365. Typical triggers: a security questionnaire, an upcoming relaunch, a wave of phishing e-mails or simply the question of what attackers can find about you online.
Included:
- your written authorisation before we start
- an inventory of your publicly visible domains, subdomains, servers, cloud and Microsoft 365 services
- automated checks for known vulnerabilities, assessed by certified specialists; hosted platforms and cloud services such as Shopify or Microsoft 365 only within the provider's rules
- a search for credentials of your company domain in known data breaches
- for existing clients also: our team reviews the admin accounts, apps and plugins of your website or shop
- findings ranked by urgency, a results call and a clear recommendation for the next step
Turnaround: typically about one week from authorisation.
Fixed price after an initial analysis
Penetration testing for websites, online shops, apps and AI chatbots
Website penetration testing that shows which weaknesses your applications have, how serious they are and in what order to close them.
For whom: online shops, web apps, customer and member portals, APIs, AI chatbots and agents. Triggers: a go-live, relaunch or major release; a new login, payment or customer-data feature; an AI agent that will answer without human approval; a customer, marketplace or insurer asking for a test report.
Included:
- scoping, kick-off and written authorisation
- web application penetration testing along the OWASP Top 10 and the OWASP Web Security Testing Guide: login and roles, cart and payment, customer data, admin areas
- API penetration testing of your own interfaces to ERP, CRM, apps and partners
- AI chatbots and LLM features: prompt injection, jailbreaks, unintended data disclosure
- on Shopify and other hosted platforms: your own code (theme customisations, custom apps, your own interfaces, headless frontend), preferably in a development store or preview environment and within the platform provider's terms; for third-party apps we review configuration and permissions, not the vendor's servers
- every finding confirmed by hand, a prioritised report and a closing meeting
- optional: fixes by our team and a re-test
Typical effort: usually 2 to 10 person-days, depending on the size of the application; a re-test is usually much shorter.
Fixed price after an initial analysis
Penetration testing for company IT: network, Active Directory and Microsoft 365
You learn which routes an attacker could take into your network and cloud, and get the countermeasure for each one.
For whom: companies with their own servers, a Windows domain or Microsoft 365 and Azure. Triggers: NIS2 risk management, ransomware concerns, a new IT provider, a cyber insurance questionnaire or the yearly test cycle.
Included:
- scoping, kick-off and written authorisation; for red teaming and social engineering also agreed rules of engagement and an emergency contact
- external penetration testing: your internet-facing servers, VPN and e-mail access; scanners give leads, specialists verify and follow up every hit
- internal penetration testing with Active Directory: starting from a machine on your network that is assumed to be taken over, the specialists look for routes to domain admin rights
- Microsoft 365 security assessment and Azure: who can do what, how accounts and sign-ins are protected, how the cloud connects to the internal network
- reviews of Active Directory, Microsoft 365 and network or OT architecture against IEC 62443, as a configuration review
- red teaming with social engineering on request, for larger organisations
- infrastructure findings are fixed by your IT team or IT provider; you receive the prioritised list
Typical effort: single tests usually 2 to 10 person-days, depending on the number of systems; red teaming several weeks.
Fixed price after an initial analysis
NIS2 readiness check: clarify your duties, prioritise the measures
You know whether and how NIS2 affects you, and you have a plan with clear priorities.
For whom: medium-sized and large companies in NIS2 sectors in the EU, and suppliers inside or outside the EU whose in-scope customers pass NIS2 requirements down the supply chain.
Included:
- NIS2 applicability: whether you are covered directly as an essential or important entity, or indirectly as a supplier
- support with registration where it applies to you
- a NIS2 gap analysis of your security measures against the requirements, with a prioritised plan
- a process for reporting significant incidents: who decides, who reports, by when
- cyber security training for management
- supplier version: when customers pass NIS2 requirements on to you, we prepare questionnaires and evidence with you
Typical effort: usually 2 to 10 person-days, depending on size and starting point.
Fixed price after an initial analysis
Not legal advice; you complete any registration yourself.
ISO 27001 and gap analysis: from baseline to certification audit
You see where you stand against a standard and reach the audit with a clear plan.
For whom: companies whose tenders, key accounts or industry rules ask for evidence against ISO 27001, TISAX, IEC 62443 or DORA, and companies that want a solid baseline without certification (CIS Controls).
Included:
- ISO 27001 gap analysis or a cyber security gap analysis against NIS2, TISAX, IEC 62443, DORA or CIS Controls: we talk to the people responsible, review policies and evidence and rate every requirement on a maturity scale. The result is an action plan that starts with what matters most
- ISMS set-up: together we define the scope, set the risk assessment method and draft the Statement of Applicability (SoA), plus responsibilities and a timeline towards the audit
- ISO 27001 implementation support up to the stage 2 certification audit, including an internal audit
- The certificate is issued by an accredited certification body of your choice; its audit fees are not included.
Typical effort: gap analysis usually 2 to 10 person-days per standard; the path to the certification audit usually takes several months.
Fixed price after an initial analysis
Virtual CISO (vCISO): a named security lead without a full-time hire
Information security has a named owner in your company who reports to management.
For whom: companies without a security lead; NIS2 entities whose management must oversee the risk-management measures; companies facing a growing pile of customer security questionnaires.
Included:
- vCISO as a service: a named person in the CISO role, reporting directly to management
- regular meetings with your team on risks, open actions and policies
- preparing the management review
- answering security questionnaires from your customers and suppliers
- coordinating tests, monitoring and fixes, with our team for web, shop and app
Typical effort: a few person-days per month.
Fixed price after an initial analysis (monthly)
Continuous protection: attack surface and dark web monitoring, pentest as a service
New vulnerabilities and leaked credentials surface between two tests, not only at the next one.
For whom: companies after an outside-in check or a pentest, teams that release often, NIS2 entities, and clients of our website maintenance who want to add security monitoring.
Included:
- attack surface and dark web monitoring after your written authorisation: your internet-facing systems are discovered and checked for new vulnerabilities on an ongoing basis; if credentials of your domain appear in data breaches or on the dark web, you are told
- optional scanners inside your network, with all findings in one view
- pentest as a service: you reserve person-days for the year and use them whenever your systems change significantly or findings need a re-test; each call-off starts with its own written authorisation, and the same people who already know your environment do the testing
- optional DNS protection with an allowlist: devices on your network only connect to domains rated as trustworthy
- we set everything up, train your team and stay on it; findings in your website, shop and app go straight to our team
Typical effort: pentest as a service with as many person-days a year as you need; monitoring and DNS protection licensed by company size.
Fixed price after an initial analysis, licence by company size
Security awareness training and phishing simulation: your team learns to spot e-mail attacks
Your staff learn to recognise phishing before anyone clicks.
For whom: every team that handles e-mail, orders and payments; NIS2 entities that must train their staff and management; after a phishing incident or at your insurer's request.
Included:
- simulated phishing e-mails after written authorisation by management, evaluated by team rather than by person and agreed with your works council where there is one
- role-based training for staff, managers and IT
- a short report with next steps, repeatable every year
Typical effort: depends on team size and format.
Fixed price after an initial analysis
Available as add-ons
CRA compliance: Cyber Resilience Act workshop for software and app teams. Together with your developers we clarify which of your products fall under the CRA, what that means for you as a manufacturer and how you receive, fix and report vulnerabilities. Typical effort: a few person-days. Fixed price after an initial analysis.
Fixes from one source. Our web, shop and app team fixes findings in code and configuration, installs updates and cleans up apps and plugins, followed by a re-test. Not included: fixes in the internal network, Active Directory and Microsoft 365. Scope depends on the findings; fixed price after an initial analysis.
Help with a hacked website or online shop. We assess the situation in a first call, clean the site or reinstall it cleanly, then harden it. If needed, specialists from our partner network take on the forensic analysis. Afterwards you can hand ongoing care to our website maintenance. Fixed price after an initial analysis.
Re-test of fixed vulnerabilities. It checks specifically whether the fixed findings are closed and is usually much shorter than the original test. Fixed price after an initial analysis.
How we work
The penetration testing process is the same for every test and every consulting project, and it never starts without your written authorisation: you decide what is tested and when.
Six steps from first call to re-test
Security for websites, online shops, apps and AI chatbots
We build and support websites, shops, apps and AI solutions ourselves. The security testing is done by certified specialists from our partner network, and our team can take care of the fixes.
Online shops: Shopify, WooCommerce, Shopware and headless
Penetration testing for online shops covers accounts and staff permissions, theme customisations and custom code, custom apps and your own interfaces, headless frontends and, on self-hosted shops such as WooCommerce or Shopware, checkout and payment. For third-party apps we review configuration and permissions, not the vendor's servers. Tests run preferably in a development store or preview environment and within the platform provider's terms; the platform itself is not part of the test. More about our work as a Shopify agency, WooCommerce agency and e-commerce agency.
Websites, web apps and APIs
WordPress sites, Laravel applications, customer and member portals and APIs: we test login, roles, data access and interfaces. API security testing looks at authentication, authorisation and what each endpoint reveals. A WordPress security audit usually centres on plugins, admin accounts and updates. More: WordPress agency, Laravel agency, web development.
AI chatbots and agents: LLM penetration testing
Prompt injection testing, jailbreaks and unintended data disclosure: we test your AI chatbot before it answers customers without human approval. More: AI agency.
Apps and the Cyber Resilience Act
If you sell apps or connected products in the EU, plan the CRA workshop (see the add-ons). More: mobile app development.
Website or online shop hacked? Call +43 1 3940 098 or write to office@sharobella.com. After the clean-up, our website maintenance can take over the ongoing updates.
EU rules in brief: NIS2 and the Cyber Resilience Act
As of October 2026. An overview, not legal advice.
- NIS2 (Directive (EU) 2022/2555; Commission overview) covers, as a rule, medium-sized and large entities in 18 critical sectors, and member states can add smaller entities with a high risk profile. The duties come from each member state's national law.
- In-scope entities must take cybersecurity risk-management measures, report significant incidents and address security risks in their supply chains and supplier relationships; top management is accountable. That is why suppliers receive security questionnaires.
- Certain digital service providers that serve the EU without an EU establishment, such as cloud, data centre and managed security service providers, have to name a representative in the EU (Commission NIS2 FAQ).
- The Cyber Resilience Act (Regulation (EU) 2024/2847; Commission summary) covers hardware and software products with digital elements made available on the EU market, such as installable software, mobile apps, firmware and connected devices. Websites and standalone SaaS are generally not covered unless they are the remote data processing of such a product. EU importers must check that non-EU manufacturers have complied.
- CRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, also to products already on the market; the main obligations apply from 11 December 2027. The Commission published practical guidance on 27 July 2026.
Our NIS2 readiness check (package 4) clarifies where you stand; the CRA workshop does the same for your products.
Who does the work
Tests and consulting are carried out by certified security specialists from our partner network, holding certifications including CISSP, CISM, OSCP, OSCE and ISO 27001 Lead Auditor. Sharobella is your point of contact and coordinates testing, reporting and fixes.
The team that will test your systems is named in the written authorisation before the project starts. Findings in your website, shop and app can be fixed by the same team that builds websites, shops and apps with us.
Every report also states what was not tested. Nobody can promise absolute security, and neither do we. What you get: traceable findings, clear priorities and a contact who follows through.
What does cyber security cost?
Every package has a fixed price after an initial analysis. For us, the initial analysis is the free 30-minute scoping call: afterwards you know what a penetration test, a NIS2 readiness check or ISO 27001 support will cost you, before you commit.
What drives the price:
- number of systems and IP addresses
- size and user roles of the application
- testing depth
- standards in scope
- whether you want a re-test
Typical effort (rounded values from comparable projects, not a quote):
- penetration test of a website, shop, app, AI chatbot, external systems, Active Directory or Microsoft 365: usually 2 to 10 person-days, depending on scope
- NIS2 readiness check or gap analysis per standard: usually 2 to 10 person-days
- CRA workshop: a few person-days
- red teaming: several weeks of effort
- ISO 27001 from ISMS set-up to the certification audit: several weeks of effort spread over several months
- vCISO: a few person-days per month
- re-test: usually much shorter than the original test
For ISO 27001, the certification body's fees come on top. Licences for ongoing monitoring depend on company size.
Frequently asked questions
Prefer to get in touch directly? Write to office@sharobella.com or call +43 1 3940 098, and tell us your domain and the reason, for example a questionnaire, NIS2, a go-live or a suspected hack.
Related services: Shopify agency · e-commerce agency · Laravel agency · AI agency · mobile app development.