Security on small business sites is usually one plugin, installed years ago, with a dashboard nobody reads. That catches the noisy automated attacks and nothing else.
I review the things that actually matter: who can log in and with what permissions, what happens to every value a user can submit, which third-party dependencies are stale, and whether your backups would genuinely restore. Where a site has already been compromised, I clean it, close the way in, and tell you honestly what was exposed.
My master’s research is on securing systems built around large language models — specifically, detecting instructions hidden inside content those systems are asked to read. If you are adding AI features to a product, that is a conversation worth having before launch rather than after.