Practical hardening for businesses without a security team — backups that restore, patching that actually happens, access you can audit, and a plan for the day something goes wrong.
Defensive work for businesses on their own systems. We are not a penetration-testing firm — see the questions below for where that boundary sits.
Small businesses get sold security as products — a subscription, a dashboard, a badge for the website. What actually protects a business that size is duller: known-good backups that have been restored from, software that gets patched, multi-factor authentication switched on everywhere, accounts removed when people leave, and someone knowing what to do in the first hour of an incident.
We do the dull things properly and give you the evidence that they’re done — which is also, conveniently, what your insurer and your larger customers keep asking for.
Offsite, encrypted, versioned, and restore-tested on a schedule. The single highest-value control a small business has, and the one most often untested.
MFA enforced, admin rights separated from daily accounts, shared logins eliminated, and joiners/leavers handled so access ends the day employment does.
Operating systems, applications, firmware, and plugins on a defined cycle — with a record showing what was patched and when.
Disk encryption, endpoint security, and screen locks configured centrally rather than left to each user to remember.
SPF, DKIM, and DMARC configured to stop your domain being spoofed, plus filtering tuned to your actual mail flow.
Segmentation, firewall rule review, and removing the remote-access shortcuts that got set up years ago and never closed. See also networking.
A written plan naming who does what in the first hour, who to call, and how you’d operate while systems are down. Rehearsed, not filed.
Help answering the security questionnaires larger customers send — and building the evidence that makes the answers true.
We don’t perform penetration testing, red-team exercises, or offensive security work. Those are specialist disciplines with their own accreditation, and when you need one we’ll refer you to a firm that does it properly rather than improvise.
We also don’t sell compliance certifications. We can get you into a state where an assessment goes well, but the assessment itself belongs with an accredited assessor — the same people shouldn’t do the work and mark it.
We review your systems, accounts, backups, and processes against a recognised baseline, and interview the people who use them day to day.
A written report ordered by what would actually hurt your business, with each finding explained in terms of consequence rather than jargon.
The changes that are cheap, fast, and high-impact get done immediately — usually MFA coverage, a backup restore test, and closing stale accounts.
The larger items sequenced into a plan with costs and dependencies, so you can budget across quarters instead of facing one alarming number.
Documentation of what’s in place and how it’s verified — the artefact you hand to a customer, an insurer, or an auditor.
Either your team owns the schedule from here with our documentation, or we run it on a retainer and report against it.
No. Our work is defensive — hardening, monitoring, backup, and recovery on systems you own. Penetration testing is a separate specialism and we’ll refer you to an accredited firm when you need one. There’s also a sequencing argument: a pen test before the basics are in place mostly produces an expensive list of things you already suspected.
Yes, and it’s one of the most common reasons businesses call us. We’ll work through it with you, identify which answers are already true, which need a small change to become true, and which need real work — then help you close the gap and evidence it.
Get in touch and tell us what’s happening. We’ll be honest about whether we’re the right responders for the situation or whether it needs a specialist incident-response firm and your insurer involved immediately. If you have cyber insurance, call them early — policies often require it before remediation begins.
The assessment is a fixed price you’ll know up front. A meaningful share of the findings usually cost nothing but time to fix — enabling MFA, removing stale accounts, turning on encryption. We separate the free fixes from the ones that need budget so you can act on the first group immediately.
They’re necessary and not sufficient. The incidents that actually take small businesses offline are ransomware against unpatched systems, credential theft against accounts without MFA, and mail compromise leading to fraudulent invoices. Antivirus and a firewall are largely bystanders to all three. That’s why backups, patching, and identity come first in our order of work.
Access is scoped to what the engagement needs, held in named accounts rather than shared ones, and revoked at the end of the work. Assessment reports are your property. We’ll sign an NDA — send yours over with the enquiry.
If the answer is “we haven’t,” that’s the conversation to have. Tell us where you’re at and we’ll tell you what’s worth doing first.