
Cybersecurity
Find out where you're exposed, then fix it in priority order.
Who it's for
You are probably here because
-
01
Someone in finance nearly paid a fake invoice.
-
02
You have backups but have never restored one.
-
03
A client or insurer is asking what controls you have.
-
04
Staff use the same password everywhere and you know it.
What's included
What you actually get.
We are precise about what this is and what it is not. This is assessment, hardening, recovery and training. We do not imply penetration testing or certification we cannot deliver, and we will tell you when you need a specialist firm instead of us.
Security assessment and report
What is exposed, ranked by what it would cost you.
Vulnerability scanning
Scheduled, with the results explained in plain terms.
Endpoint protection rollout
Across every device on the register.
Email security and anti-phishing
The attack that actually reaches you.
Access control and MFA
Least privilege, and a joiner-mover-leaver process.
Backup and ransomware recovery
Offline copies, and restores you have watched.
Staff awareness training
Because most incidents start with a person, not a firewall.
Incident response support
A number to call on the worst day.
How it runs
Each stage, and what it produces.
-
01
Assess
Devices, accounts, email, backups, network exposure.
Output
A findings report ranked by risk, in plain language.
-
02
Prioritise
What to fix now, next quarter, and never.
Output
A remediation plan with costs against each item.
-
03
Harden
MFA, endpoint protection, email controls, segmentation, backups.
Output
Each control implemented and evidenced.
-
04
Train and rehearse
Staff awareness, and a walked-through recovery.
Output
A tested restore and a trained team.
The questions people actually ask first
“Do you do penetration testing?”
Not as a certified engagement, and we will not pretend otherwise. We do assessment, hardening and recovery, and we will refer you to a specialist firm when a formal pen test is what you actually need.
“Can you certify us?”
No. We can prepare you and evidence your controls, but certification comes from a certifying body, which is the point of it.
“Is training really worth it?”
It is the single highest-return item on most reports. Almost every incident we are called to started with a person, not a firewall.
Technology
Proof
One project, in full.

Stock and dispatch system for a regional distributor
Four branches on separate spreadsheets, month-end taking a week.
One day
Month-end close
Four branches tracked stock in separate spreadsheets. Dispatch errors were routine, nobody could see group stock in one place, and month-end close took a week of reconciliation that one person held in their head.
One day
Month-end close
Four
Branches on one system
Single view
Group stock
Commercials
How buying this works.
Engagement
Fixed-price assessment, then remediation quoted per item, then a retainer.
Price
On request, after scope
What sets the price
Number of users and devices, how many sites, and how much of the estate is already documented.
Remediation is quoted per item against the ranked report, so you fix what matters and are not sold a bundle.
Every project is quoted after we understand the scope. You will have a written, fixed quote before any build work begins. No open-ended billing.
Questions
Answered plainly.
For a typical office, a day on site and a few days to write it up properly. The report is the deliverable, so it gets the time.
The report is ranked by what an incident would actually cost you, and it includes a 'do nothing' column. Some risks are worth carrying.
Call us. Incident response support is available to retainer clients with a stated response, and we will help non-clients where we can.
Yes, on site or remotely, with certificates of attendance.
Often bought alongside
Run
Book a free security health check
Two hours on site, a written findings sheet, no obligation and no scare tactics.
We reply to every enquiry within one working day.