GMB Structural
GMB Structural are Sydney civil, structural and remedial engineers whose website had been compromised three times in nine weeks on shared WordPress hosting. Rather than clean it a fourth time, we removed the attack surface entirely: the site was rebuilt as a static build on Azure Static Web Apps, with a single Azure Function handling the contact form.

The Challenge
Three compromises in nine weeks, the last one arriving through a neighbouring account on the same shared server — not through anything wrong with GMB's own site. That is the part conventional hardening cannot fix. No amount of plugin patching protects you from the tenant next door, and for an engineering consultancy whose clients are architects, builders and strata managers, a site serving malware is a professional credibility problem, not just an IT one.
Our Solution
We rebuilt the site as static HTML, CSS and JavaScript with no database, no plugins and no server-side application to exploit, and deployed it to Azure Static Web Apps. The one piece of genuine server logic — the contact form — runs as a single Azure Function that sends through Azure Communication Services, so there is no mail stack on the host either. DNS moved to Cloudflare and TLS is Azure-managed, so certificates renew without anyone remembering to. Deployment is git-driven: the published site is whatever is in the repository, which makes an unauthorised change visible rather than silent.
The Results
The site has been stable since cutover with no further compromises, and the recurring clean-up work is gone. Hosting costs dropped to effectively nothing on Azure's free tier, pages are served from the edge rather than a busy shared host, and recovery from any future problem is a redeploy rather than a forensic exercise.
Technologies Used
Have a similar project in mind?
Let's talk about how we can deliver the same kind of results for your business.

