Compromised modules, injections in templates and overrides, fraudulent payment modules, persistence with falsified timestamps: attack patterns our PrestaShop playbooks detect methodically.
Any one of these signals warrants triage. It is included and billed only if an engagement starts.
Confirmed compromise or false positive? Scope, exposed data, legal obligations. Engagement authorisation signed online, secure access established.
Web server logs, integrity comparison of core and modules, analysis of tamper-resistant filesystem metadata, review of overrides and hooks, third-party access inventory.
File-level and database eradication, full credential rotation, critical file locking, server and CDN cache purge, verification re-scan.
Integrity probes and automated watch for 30 days, with an alert channel validated by a real end-to-end test.
Published rates, signed scope, best-efforts obligation stated in writing.
First response from an engineer within 4 business hours, 7 days a week. For confirmed emergencies, triage begins as soon as the engagement authorisation is signed online.
Not before speaking with us. Shutting down destroys volatile evidence and does not remove persistence. We move the site into controlled maintenance instead.
Triage is included: if no engagement starts, it is not billed.
No — and be wary of anyone who promises that. We are bound by a best-efforts obligation stated in the contract: industry standards, a defined scope, and 30 days of monitoring to verify the eradication holds.
Yes, as an option: we assemble remediation evidence in the expected format, file the review request and follow it through to removal of the flag — the same process applies to cyber insurance claims.
An engineer replies within 4 business hours — immediately for confirmed emergencies.
✉ emergency@cerbexia.com · sos@cerbexia.com
Remote engagements across Europe — EN / FR / ES / IT / PT / PL / HU / CS