Skip to Content

Security handled properly.

CYBER SECURITY CONSULTING

For businesses that need security done properly and have nobody in-house to do it. Assessments, hardening, architecture and compliance, quoted as fixed price work rather than an ongoing contract.


Start here if you are not sure what you need

Most people arrive at this page knowing something needs attention without knowing what to ask for. That is normal, and working out the question is part of the job.


Find out where you stand

  • Security assessment. A structured look at your environment against whatever applies to you, or against no standard at all if the question is simply whether your setup is sound.
  • Vulnerability assessment. What is exposed, what an attacker would find, and what to fix first.
  • Independent review of your IT provider. Whether the work you are paying for has actually been done, and done well.
  • Audit and evidence review. Whether what you claim about your security holds up when someone checks.


Fix what needs fixing

  • Microsoft 365 and Google Workspace hardening. Both ship with defaults that suit a vendor rather than a business holding client data. Conditional access, MFA enforcement, mail security, sharing controls, logging and retention.
  • Endpoint and device security. Managed devices, staff phones, and everything running on a laptop nobody has looked at in three years.
  • Social media and public exposure. Account security, access control, and what your business is publishing about itself without meaning to.
  • Access control and offboarding. Who has access to what, and what happens the day someone leaves.


Build it right the first time

  • Security architecture. Designing systems so the security is structural rather than bolted on afterwards. Useful when you are moving platforms, growing quickly, or replacing something that has been patched together over years.
  • Security engineering. Implementing the controls, not just recommending them.

Governance, risk and compliance

  • Policy and documentation. Written to match what you actually do, rather than a template describing a business you are not.
  • Risk assessment. What could go wrong, what it would cost, and what is worth spending money on.
  • Vendor and supplier due diligence. Where their data goes, who else can reach it, and whether a certification badge on their website means what it appears to mean.
  • Privacy and regulatory obligations. What applies to your business, and what you need to be able to demonstrate.


How we work

You get in touch with a problem. We work out what is actually involved, quote a fixed price, and do the work.

Nothing on the list above is a package you have to buy whole. Larger pieces get broken into projects, each quoted on its own, so you can see what each one costs and choose what to run.

We take no commission, no rebate and no margin on software. More on how we stay independent.


Not sure where to start?

The list above covers what we get asked for most, not everything we do. If your question is security-shaped, start with a call and we will tell you whether we are the right people for it.

Free, practical security advice for small businesses

Every week or so I explain something from the news, what it means for a business your size, and one thing you can check yourself in five minutes.


I'll only use your address to send The Check. Unsubscribe from the link in any issue. Privacy policy

Thanks for registering!