Cybersecurity

Security you can describe to your board in plain language

Most organizations do not need to be frightened into acting. They need to know what is actually in place, what is not, and who is responsible for the difference.

Let's talk
An Amplaphi engineer working through a problem alongside a client

What this fixes

If any of this sounds familiar, this is the conversation

Nobody can say what is actually protected

There are tools in place. Whether they are configured, monitored, or covering everything is a separate question, and it usually goes unanswered.

Insurance and customer questionnaires stall

A renewal form or a client security review asks for specifics, and assembling the answers takes weeks of chasing.

Former staff still have access

Offboarding covers email and the obvious systems. The rest depends on someone remembering which accounts existed.

An alert arrives and nobody knows the next step

Detection without an agreed response is just an interruption. The question is who acts, at what hour, and with what authority.

What changes

What the business gets, not what the software does

  • You can answer where you stand without a fire drill
  • Access ends when employment ends, as a process rather than a memory
  • Alerts have a named owner and a defined response, including out of hours
  • Insurance and customer questionnaires get completed from evidence you already hold
  • Security work is prioritised by real exposure instead of by whichever vendor called last

Accountability

What we take responsibility for

Written into the scope before you sign, so there is no argument later about who owned it.

We own this

  • Configuration and monitoring of the security controls in scope
  • Identity and access management, including joiner and leaver processes
  • Alert triage and the agreed first response
  • Periodic review of configuration drift and newly opened gaps
  • The written record you need for insurers and customer reviews

What is included

  • Review of current exposure across identity, endpoints, email, and network
  • Multi-factor authentication and conditional access setup
  • Endpoint protection deployment, monitoring, and response
  • Email filtering and anti-phishing configuration
  • Privileged access review and least-privilege tightening
  • Patch compliance reporting
  • Access reviews on an agreed cycle
  • A written incident response procedure naming who does what

Not included, or depends on scope

  • Framework alignment work (for example CIS or NIST-informed practice) is available; we do not issue or audit certifications
  • Penetration testing by an independent third party, which we coordinate rather than perform on our own work
  • Security awareness training platforms, which are licensed separately
  • Regulated-industry requirements, which change the scope and are priced accordingly
  • 24-hour monitored response, where the coverage window is defined in writing before you sign

How it works

How the engagement runs

  1. Find out where you stand

    A review of what is in place, what is configured, and what is genuinely covering you, written in language you can hand to a non-technical board.

  2. Fix the exposures that matter

    Work is sequenced by real risk, not by product catalogue. You see the order and the reasoning before anything changes.

  3. Put monitoring and response in place

    Detection is paired with an agreed response: who is contacted, who can act, and what happens outside working hours.

  4. Keep checking

    Environments drift. Access reviews, configuration checks, and patch reporting run on a schedule and are reported to you.

Honest fit

Who this suits, and who it does not

We would rather tell you now than three months into an engagement neither of us enjoys.

A good fit if…

  • You need to answer security questions from customers, insurers, or a board
  • You want prioritised, practical work rather than a product list
  • You are prepared to accept changes that add small amounts of friction for staff
  • You want the difference between framework alignment and certification stated plainly

Probably not right if…

  • You want a certification issued rather than earned
  • You are looking for the cheapest tool that lets you tick a box
  • You need an independent audit of work we performed ourselves
  • You are not willing to change how privileged access is handled

Getting started

What the transition actually looks like

Changing providers is the part everyone dreads. Here is each phase, what we need from you, and how disruptive it is.

Understand

Step 01 of 4

We go through what you have, what is breaking, and what the business is trying to do. We talk to the people who actually use the systems, not just whoever manages them.

What we need from you
Access to your current setup, time with a few key people, and an honest account of what frustrates you.
What you get
A written summary of what we found, including anything we think you should know before deciding to work with us.

Disruption to your business

None. Nothing changes during this phase, we are looking, not touching.

Straight answers

Questions we get about cybersecurity

Are you certifying us against a standard?
No, and anyone who says they can is describing something different. We can align your practices to a recognised framework and produce the evidence, but certification is issued by an accredited independent body.
Do we need all of this at once?
No. Most organizations get the majority of the risk reduction from a small number of changes, usually around identity and access. We sequence by exposure and tell you what can wait.
What happens if we are attacked?
The response procedure is written before it is needed: who is contacted, who has authority to isolate systems, what gets preserved for investigation, and who talks to insurers. We run it with you rather than at you.
Will this make things harder for our staff?
Some of it adds a step, and we will tell you which parts. We would rather have the conversation about friction upfront than deploy something your team quietly works around.

Wondering if cybersecurity is what you need?

Describe what is going wrong. If this is not the right answer for you, we will say so rather than sell it to you.