πŸ”„ Topic

Packaging what I learned about web security into a small, honest audit service for local Italian businesses.


🎯 Goal

Turn scattered web security knowledge into a repeatable check-up process with a checklist, report templates, and a real first audit.


πŸ›  What I Did

I built a β€œWebsite Trust & Security Mini-Audit” service: an external, non-invasive check-up of a small business website, delivered as a simple PDF report with clear priorities. It is explicitly not a penetration test. I created the operating structure β€” checklist, report template, outreach messages, a client-folder script, and a PDF generator β€” then ran the full process against a real production website and produced both a short outreach analysis and a complete report.

Main areas covered:

  • HTTPS / SSL / TLS checks
  • browser hardening headers
  • mobile usability and speed
  • basic SEO and broken links
  • privacy and cookie visibility
  • prioritized findings with business impact
  • repeatable client-folder and PDF tooling

πŸ”— Key Cybersecurity Connections

This is security work at the trust boundary most small businesses actually live on: their public website. Checking TLS, headers, exposed information, and privacy posture is the entry level of external attack-surface review.


πŸ” Investigation Questions

  • Is HTTPS configured correctly end to end?
  • Which security headers are missing?
  • What information does the site leak by default?
  • Is there a visible privacy and cookie posture?
  • Do the findings translate into business impact the owner understands?

🚨 Detection Opportunities

Potential monitoring ideas:

  • TLS certificate expiry
  • security header regressions after deployments
  • broken link accumulation
  • unexpected third-party scripts
  • performance degradation over time

Example:

project=website-mini-audit
change_type=external_posture_check
risk_area=public_web_surface
triage=compare_findings_against_previous_report

🧭 MITRE ATT&CK Techniques

Possible mappings depending on confirmed behavior:

  • T1595 β€” Active Scanning
  • T1190 β€” Exploit Public-Facing Application
  • T1592 β€” Gather Victim Host Information

πŸ—Ί Visual Investigation Diagram

Checklist
    ↓ External checks
    ↓ Findings + priorities
    ↓ PDF report
    ↓ Client conversation

⚠ Challenges

The challenge was scoping honestly. It is tempting to make the service sound like a full security assessment. It is not. It is a structured external check-up, and the report has to say so clearly.


πŸ“š What I Learned

I learned that a checklist plus a template is what turns knowledge into a service. Without the repeatable structure, every audit would be improvised and inconsistent.


➑ Next Steps

  • Refine the report template from the first real run
  • Prepare outreach for more local businesses
  • Automate more of the evidence collection
  • Keep the non-invasive scope boundary explicit

🧠 Reflection

This was useful because it connected study to the real world: the same checks I practice in labs became something a business owner can pay for and act on.


🧩 Lessons Learned

What worked

Building the checklist and templates before selling anything.

What broke

Early report drafts that mixed technical evidence with sales tone.

Why it broke

A report serves the client’s decisions, not my marketing.

Fix / takeaway

Separate the outreach message from the report, and keep the report factual and prioritized.


πŸ“ˆ Skill Progression Context

This supports my cybersecurity progression because external posture assessment, evidence collection, and clear reporting are core skills in any security role.


πŸ˜„ TL;DR

Turned a checklist into a service, honestly scoped.