Skip to content

04Services

Five ways we reduce what can be done to you

Each of these can be bought on its own or run as a programme. Every engagement is scoped in writing and fixed in price before any work begins.

01Service

Security Assessments & Vulnerability Testing

Find out what is actually exposed.

A hands-on examination of what you have running, from the internet-facing edge to the accounts and laptops inside the building.

We start where an attacker would: everything of yours that answers on the public internet, then the identity layer, then the machines your people use every day. Automated scanning is part of the work but never the whole of it. Every finding is confirmed by hand, so you are not handed a list of theoretical issues to chase, and each one is rated by what it would let someone actually do to your business rather than by a generic severity score.

What you will get

  • External and internal scanning, with every finding verified manually
  • Review of identity and access, including dormant, shared and over-privileged accounts
  • Endpoint, server and cloud configuration measured against a hardening baseline
  • Findings rated by business impact, with the reasoning shown rather than asserted
  • A remediation plan ordered by risk, with honest effort estimates against each item
  • A short summary written for leadership alongside the full technical detail

02Service

Threat Modeling & Risk Management

Decide what is worth defending first.

Structured work to establish what you hold, who would want it, how they would reach it, and what it would cost you if they did.

No budget covers everything, so the useful question is never whether you are protected but what gets protected first. We map your systems, data and third-party access alongside the people who run them, work through who realistically targets an organisation of your size and sector, and trace the routes they would take. What comes out is a ranked picture of risk you can put in front of a board, an insurer or a client without having to translate it.

What you will get

  • Asset and data-flow mapping across systems, suppliers and third-party access
  • Threat scenarios built for your sector and size, not a generic catalogue
  • Attack-path analysis showing how one foothold could become full access
  • A risk register with named owners, agreed ratings and review dates
  • Clear separation of what to fix, what to insure and what to formally accept
  • A working session that hands the model to your team so it stays current

03Service

Incident Response Readiness

Make the decisions now, not at three in the morning.

The plan, the roles and the rehearsal that turn an incident from a crisis into a procedure your team has already practised.

Every decision taken during an incident is worse than the same decision taken calmly beforehand. We write a response plan that names who declares an incident, who speaks to customers, who is allowed to authorise pulling a production system offline, and where the evidence and the clean backups actually live. Then we run it with your people, because a plan nobody has rehearsed is a document rather than a capability.

What you will get

  • An incident response plan written around your systems and your staffing
  • Named roles, escalation paths and contact routes that work out of hours
  • Containment and recovery runbooks for the scenarios most likely to hit you
  • A tabletop exercise run with both technical staff and leadership
  • Backup restoration tested end to end and timed, never assumed
  • Customer, regulator and insurer notification templates prepared in advance

04Service

Security Hardening & Monitoring

Close the easy routes in, then watch them.

Configuration work that removes the obvious ways through, plus monitoring that tells a real person when something changes.

Most organisations already own more security capability than they have switched on. We finish the configuration: multi-factor authentication everywhere it belongs, administrative rights cut back to what each role genuinely needs, patching that completes instead of stalling, email and endpoint defences tuned to your environment rather than left on the vendor default. Then we make sure the alerts arrive somewhere a person will read them and act.

What you will get

  • Hardening across identity, endpoints, servers, the network edge and cloud tenancy
  • Multi-factor authentication and privileged access brought under control
  • A patching process that is reviewed, measurable and verifiably completing
  • Logging enabled where it matters and retained long enough to investigate with
  • Alerting tuned so genuine events are not buried under routine noise
  • Ongoing managed support with a named contact and agreed response times

05Service

Compliance & Security Program Support

Evidence, not assurances.

Support for the frameworks, questionnaires and audits you are being asked to satisfy, without turning security into a paper exercise.

Clients, insurers and regulators increasingly want proof of controls rather than a statement that you take security seriously. We map what you already do against the framework you are working to, close the gaps that are real, and produce policies and evidence in the form an assessor will accept. Where a control genuinely does not fit how your business operates, we say so and document the compensating measure instead of pretending otherwise.

What you will get

  • Gap analysis against the framework or client requirement you are working to
  • Policies and procedures written to match how your organisation actually works
  • Evidence collection organised so that audits stop being an annual scramble
  • Security questionnaires and client due-diligence responses handled for you
  • Staff awareness material, with a record of who completed it and when
  • A rolling program calendar so nothing lapses between assessment cycles

Next step

Not sure which of these you need

Most people are not, and that is a reasonable place to start from. Describe what you run and what worries you, and we will tell you where we would begin.

Already dealing with an incident? Call +1 (512) 555-0182 rather than filling in a form.