Cybersecurity
Security you can describe to your board in plain language
Most organizations do not need to be frightened into acting. They need to know what is actually in place, what is not, and who is responsible for the difference.
Let's talk
What this fixes
If any of this sounds familiar, this is the conversation
Nobody can say what is actually protected
There are tools in place. Whether they are configured, monitored, or covering everything is a separate question, and it usually goes unanswered.
Insurance and customer questionnaires stall
A renewal form or a client security review asks for specifics, and assembling the answers takes weeks of chasing.
Former staff still have access
Offboarding covers email and the obvious systems. The rest depends on someone remembering which accounts existed.
An alert arrives and nobody knows the next step
Detection without an agreed response is just an interruption. The question is who acts, at what hour, and with what authority.
What changes
What the business gets, not what the software does
- You can answer where you stand without a fire drill
- Access ends when employment ends, as a process rather than a memory
- Alerts have a named owner and a defined response, including out of hours
- Insurance and customer questionnaires get completed from evidence you already hold
- Security work is prioritised by real exposure instead of by whichever vendor called last
Accountability
What we take responsibility for
Written into the scope before you sign, so there is no argument later about who owned it.
We own this
- Configuration and monitoring of the security controls in scope
- Identity and access management, including joiner and leaver processes
- Alert triage and the agreed first response
- Periodic review of configuration drift and newly opened gaps
- The written record you need for insurers and customer reviews
What is included
- Review of current exposure across identity, endpoints, email, and network
- Multi-factor authentication and conditional access setup
- Endpoint protection deployment, monitoring, and response
- Email filtering and anti-phishing configuration
- Privileged access review and least-privilege tightening
- Patch compliance reporting
- Access reviews on an agreed cycle
- A written incident response procedure naming who does what
Not included, or depends on scope
- Framework alignment work (for example CIS or NIST-informed practice) is available; we do not issue or audit certifications
- Penetration testing by an independent third party, which we coordinate rather than perform on our own work
- Security awareness training platforms, which are licensed separately
- Regulated-industry requirements, which change the scope and are priced accordingly
- 24-hour monitored response, where the coverage window is defined in writing before you sign
How it works
How the engagement runs
Find out where you stand
A review of what is in place, what is configured, and what is genuinely covering you, written in language you can hand to a non-technical board.
Fix the exposures that matter
Work is sequenced by real risk, not by product catalogue. You see the order and the reasoning before anything changes.
Put monitoring and response in place
Detection is paired with an agreed response: who is contacted, who can act, and what happens outside working hours.
Keep checking
Environments drift. Access reviews, configuration checks, and patch reporting run on a schedule and are reported to you.
Honest fit
Who this suits, and who it does not
We would rather tell you now than three months into an engagement neither of us enjoys.
A good fit if…
- You need to answer security questions from customers, insurers, or a board
- You want prioritised, practical work rather than a product list
- You are prepared to accept changes that add small amounts of friction for staff
- You want the difference between framework alignment and certification stated plainly
Probably not right if…
- You want a certification issued rather than earned
- You are looking for the cheapest tool that lets you tick a box
- You need an independent audit of work we performed ourselves
- You are not willing to change how privileged access is handled
Getting started
What the transition actually looks like
Changing providers is the part everyone dreads. Here is each phase, what we need from you, and how disruptive it is.
Understand
Step 01 of 4We go through what you have, what is breaking, and what the business is trying to do. We talk to the people who actually use the systems, not just whoever manages them.
- What we need from you
- Access to your current setup, time with a few key people, and an honest account of what frustrates you.
- What you get
- A written summary of what we found, including anything we think you should know before deciding to work with us.
Disruption to your business
None. Nothing changes during this phase, we are looking, not touching.
Straight answers
Questions we get about cybersecurity
Are you certifying us against a standard?
Do we need all of this at once?
What happens if we are attacked?
Will this make things harder for our staff?
Wondering if cybersecurity is what you need?
Describe what is going wrong. If this is not the right answer for you, we will say so rather than sell it to you.