PROTECT · Service · OPSEC Website Audit

Your website tells the world too much. We find what to remove.

Employee bios, client mentions, machinery photos, clearance-required job posts, technology stack details. Media Express audits everything publicly visible on your website to identify what hurts your compliance posture with government buyers — and helps competitors, attackers, or foreign intelligence.

⚜ Plain English · Quotable
An OPSEC website audit is a systematic review of everything publicly visible on your website — pages, images, PDFs, code, metadata, cached content — to identify information that hurts your compliance posture with government or prime contractors, and helps competitors, attackers, or foreign intelligence gather actionable intel about your operations. Media Express delivers a prioritized PDF report with recommended fixes, and optionally handles implementation. Especially relevant for defense manufacturers, aerospace suppliers, utility vendors, and IT services for regulated clients.
🔍 What We Find

Eight categories of public information that hurt you.

Every audit maps against these eight categories. Most sites have issues in at least three of them. Nobody realizes it until we look.

👤
Named Employees

Detailed bios, org charts, LinkedIn-linked staff pages. Reconnaissance-friendly — helps social engineering and spear-phishing.

Example: full employee grid with photos, roles, and email addresses.
🏤
Client Names & Logos

Prime contractor logos, marquee client mentions, "As trusted by..." reveals your supply chain. Often violates prime-contractor flow-down clauses.

Example: "Boeing logo" or "Serving Lockheed since 2018" on homepage.
🔧
Machinery & Capabilities

Specific machine models, tolerances, envelope sizes. Tells attackers — and competitors — exactly what you can and can't produce.

Example: "Our Haas VF-4SS handles parts up to 20" x 40"" in shop tour photo.
🔐
Clearance-Required Jobs

"Must hold Secret clearance" or "Active Top Secret required" in job posts reveals classified programs and staffing gaps.

Example: "Senior Engineer — DoD program experience, TS/SCI required" on careers page.
🖥️
Technology Stack

Powered by / Built with badges, framework versions, plugin lists, CMS fingerprints. Reveals attack surface to threat actors.

Example: "WordPress 5.2 · WooCommerce · Elementor" fingerprint in HTML headers.
🏣
Facility Details

Interior photos, entry/exit locations, security guard positions, badge readers visible in tour videos. Physical reconnaissance material.

Example: 360° shop tour showing badge readers, servers, secure areas.
📧
Exposed Personal Contacts

Owner's personal cell, direct emails for high-value staff, home addresses on legal filings linked from site. Personal targeting vectors.

Example: CEO direct mobile number listed on About page.
📁
Orphaned Documents

Old PDFs, brochures, presentations, quote docs left in /uploads folders. Metadata reveals authors, machines, software, edit history.

Example: 2019 pitch deck still linked from a blog post, with your pricing history.
📜 What You Get

A prioritized PDF report. Ready to act on.

📜 Deliverable

OPSEC score. Findings. Fixes. Timeline.

Every audit produces a structured PDF report you can hand to your web team, IT team, or Media Express for implementation. No 100-page consultant report — just clear findings, prioritized by risk, with the specific fix each one needs.

  • Overall OPSEC readiness score (0-100)
  • Findings by category with severity ratings
  • Specific pages, images, and files flagged with URLs
  • Recommended fix for each finding
  • Estimated effort per fix (in hours)
  • Prioritized 30-day, 60-day, 90-day action list
⚜ How We Deliver

Five-step process. Zero surprises.

1
Automated Scan (Day 1)

Crawl your site, catalog every page/image/PDF/script, extract metadata, fingerprint the tech stack. Result: full inventory of what's public.

2
Manual Review (Day 2-4)

Human eyes on every page. We map findings against the eight OPSEC categories, note context (what makes each item risky given your industry and clients), and gather concrete evidence with URLs and screenshots.

3
Prioritized Report (Day 5)

PDF audit report delivered. OPSEC readiness score, findings by category and severity, specific pages flagged, recommended fixes, effort estimates, 30/60/90 day action list.

4
Fix Implementation (Optional, +7 days)

If you order Audit + Fix package, we remove or replace the flagged items, redact metadata from files, adjust image publication, restructure pages, and set up canonicalization for legacy URLs.

5
Ongoing Monitor (Optional Retainer)

Monthly re-scan for new exposures. Quarterly full re-audit. Alerts when your team publishes something risky. Keeps you clean over time as your site evolves.

💰 Pricing

Four ways to buy.

From a self-service automated scan to a full audit + fix + ongoing monitor. Pick the level that matches your risk exposure.

Automated Scan
Self-Service
$197
One-time, or $47/mo recurring
  • Automated crawl + fingerprint
  • Basic findings summary PDF
  • Tech stack + metadata inventory
  • No manual review
  • Best for early triage
Audit + Fix
Done-For-You
$3,500 – $6,000
Audit + implementation in 2 weeks
  • Everything in Full Audit
  • Implementation of all high-severity fixes
  • Metadata redaction from PDFs / images
  • URL canonicalization for legacy content
  • Client-visible pages restructured
  • Final "clean sweep" verification scan

Ongoing monitor + quarterly re-audit: $300-800/mo. Recommended for anyone with active gov contracts.

Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.

⚜ Free Consultation →
❓ Common Questions

FAQ.

Is this the same as a security audit or penetration test?

No. Traditional security audit looks for vulnerabilities in your systems (SSL misconfiguration, injection risks, weak passwords). OPSEC audit looks at what's INTENTIONALLY public but shouldn't be — the marketing, employee info, client references, and technical details that expose your organization. Both matter; they're complementary.

Who needs an OPSEC audit?

Any business pursuing federal, state, or prime contractor work — especially defense, aerospace, utility supply chain, IT services for regulated clients. Also useful for law firms handling classified matters, healthcare providers with sensitive patient bases, and any business with valuable IP or sensitive customer lists.

How long does an audit take?

Full audit: 5-7 business days for a small site (up to 50 pages), 10-15 business days for larger sites. Rush option available. Automated scan is instant.

Do you also fix the findings?

Yes — via the Audit + Fix tier. The Full Audit tier delivers a PDF report your web team can act on. Audit + Fix includes implementation: we remove or replace flagged items, redact metadata, adjust image publication, restructure pages, and verify with a clean sweep scan.

What if my findings are sensitive?

Everything about the audit is confidential. Media Express signs an NDA at the start. The report is delivered encrypted. We don't share your findings, screenshots, or company details with anyone. Standard.

Can you audit sites you didn't build?

Yes. Most OPSEC audits are on sites Media Express did not build. We work with WordPress, static, custom stacks, subdomain sprawls, and legacy CMS. If your web team owns the site, we deliver the report and they implement. If you want us to implement, we work with your web team's access.

How often should I re-audit?

Full re-audit annually at minimum. Quarterly if you actively publish new content, hire employees regularly, or add new client references. Monthly automated re-scan is included in the retainer.

📚 Related

Also worth knowing.

OPSEC audits pair with framework readiness and capability statements to build a complete compliance-visible posture.

What's on your website that shouldn't be?

Book an OPSEC audit and find out. Full manual review with prioritized PDF report in 5-7 business days. Optional fix implementation available.

Media Express LLC · Chicago IL · Est. 1995 · Independent · 31+ years