IT services · Security

Proportionate security, evidenced.

Practical hardening for businesses without a security team — backups that restore, patching that actually happens, access you can audit, and a plan for the day something goes wrong.

Defensive work for businesses on their own systems. We are not a penetration-testing firm — see the questions below for where that boundary sits.

The problem this solves

Small businesses get sold security as products — a subscription, a dashboard, a badge for the website. What actually protects a business that size is duller: known-good backups that have been restored from, software that gets patched, multi-factor authentication switched on everywhere, accounts removed when people leave, and someone knowing what to do in the first hour of an incident.

We do the dull things properly and give you the evidence that they’re done — which is also, conveniently, what your insurer and your larger customers keep asking for.

Advisory engagement

  • Security posture assessment against a recognised baseline
  • Findings ranked by real risk to your business, not CVSS theatre
  • Remediation plan your team can work through
  • Help completing customer security questionnaires
  • Fixed-price, with a written report you own

Managed engagement

  • Patching and update cycles run on a defined schedule
  • Backups monitored and restore-tested on a stated cadence
  • Account and access reviews at agreed intervals
  • Alerting on the signals that actually matter
  • Named contact for incidents, with an agreed response time
Scope

What we work on

Backup and recovery

Offsite, encrypted, versioned, and restore-tested on a schedule. The single highest-value control a small business has, and the one most often untested.

Identity and access

MFA enforced, admin rights separated from daily accounts, shared logins eliminated, and joiners/leavers handled so access ends the day employment does.

Patching and updates

Operating systems, applications, firmware, and plugins on a defined cycle — with a record showing what was patched and when.

Endpoint protection

Disk encryption, endpoint security, and screen locks configured centrally rather than left to each user to remember.

Email security

SPF, DKIM, and DMARC configured to stop your domain being spoofed, plus filtering tuned to your actual mail flow.

Network hardening

Segmentation, firewall rule review, and removing the remote-access shortcuts that got set up years ago and never closed. See also networking.

Incident readiness

A written plan naming who does what in the first hour, who to call, and how you’d operate while systems are down. Rehearsed, not filed.

Questionnaires and evidence

Help answering the security questionnaires larger customers send — and building the evidence that makes the answers true.

Principles

How we approach it

  • Proportionate to the business. Controls sized to your actual risk and headcount. A twelve-person firm doesn’t need an enterprise security programme, and pretending otherwise means nothing gets done.
  • Restore-tested, not just backed up. We measure backups by whether we’ve restored from them, because that is the only property that matters when it counts.
  • Boring controls first. MFA, patching, and backups prevent more real incidents than any product with a dashboard. We do those before anything else.
  • Evidence as you go. Every control produces a record. When a customer or insurer asks, the answer is a document, not a recollection.
  • No fear-selling. We’ll tell you what your realistic risks are, including when your current position is reasonable and needs no spend.
  • Security that people can work with. Controls staff route around aren’t controls. If a measure makes a common task impossible, it will be bypassed and we’ll have made things worse.

What we don’t do

We don’t perform penetration testing, red-team exercises, or offensive security work. Those are specialist disciplines with their own accreditation, and when you need one we’ll refer you to a firm that does it properly rather than improvise.

We also don’t sell compliance certifications. We can get you into a state where an assessment goes well, but the assessment itself belongs with an accredited assessor — the same people shouldn’t do the work and mark it.

Process

How an engagement runs

  1. Baseline assessment

    We review your systems, accounts, backups, and processes against a recognised baseline, and interview the people who use them day to day.

  2. Findings, ranked by real risk

    A written report ordered by what would actually hurt your business, with each finding explained in terms of consequence rather than jargon.

  3. Quick wins first

    The changes that are cheap, fast, and high-impact get done immediately — usually MFA coverage, a backup restore test, and closing stale accounts.

  4. Planned remediation

    The larger items sequenced into a plan with costs and dependencies, so you can budget across quarters instead of facing one alarming number.

  5. Evidence pack

    Documentation of what’s in place and how it’s verified — the artefact you hand to a customer, an insurer, or an auditor.

  6. Ongoing or handover

    Either your team owns the schedule from here with our documentation, or we run it on a retainer and report against it.

Questions

Common questions

Do you do penetration testing?

No. Our work is defensive — hardening, monitoring, backup, and recovery on systems you own. Penetration testing is a separate specialism and we’ll refer you to an accredited firm when you need one. There’s also a sequencing argument: a pen test before the basics are in place mostly produces an expensive list of things you already suspected.

A customer sent us a security questionnaire we can’t answer. Can you help?

Yes, and it’s one of the most common reasons businesses call us. We’ll work through it with you, identify which answers are already true, which need a small change to become true, and which need real work — then help you close the gap and evidence it.

We’ve had an incident. Can you help right now?

Get in touch and tell us what’s happening. We’ll be honest about whether we’re the right responders for the situation or whether it needs a specialist incident-response firm and your insurer involved immediately. If you have cyber insurance, call them early — policies often require it before remediation begins.

Is this expensive?

The assessment is a fixed price you’ll know up front. A meaningful share of the findings usually cost nothing but time to fix — enabling MFA, removing stale accounts, turning on encryption. We separate the free fixes from the ones that need budget so you can act on the first group immediately.

We already have antivirus and a firewall. Isn’t that enough?

They’re necessary and not sufficient. The incidents that actually take small businesses offline are ransomware against unpatched systems, credential theft against accounts without MFA, and mail compromise leading to fraudulent invoices. Antivirus and a firewall are largely bystanders to all three. That’s why backups, patching, and identity come first in our order of work.

How do you handle our credentials and data?

Access is scoped to what the engagement needs, held in named accounts rather than shared ones, and revoked at the end of the work. Assessment reports are your property. We’ll sign an NDA — send yours over with the enquiry.

Start with one question: when did you last restore from backup?

If the answer is “we haven’t,” that’s the conversation to have. Tell us where you’re at and we’ll tell you what’s worth doing first.

Request a quote