Security & IT
A small-business security baseline you can set up this week
You do not need an enterprise budget to stop the most common attacks. These basics, spread over five working days, close the doors attackers try first.
5 min read
Guard the perimeter. Keep the lights on.
Security assessments, hardening, monitoring and day-to-day IT support that keep your systems protected and available.
Most security incidents begin with something ordinary: a reused password, a missed update, an open port nobody remembered. We find those gaps, close them and keep watch so they stay closed. Alongside that, we provide the everyday IT support that keeps your people working.
This service suits small and mid-sized businesses without a dedicated security or IT team, and product teams who want a second pair of eyes on their infrastructure before and after launch. We explain risk in plain language and fix the important things first.
At a glance
Every engagement is scoped to your needs. These are the pieces this service usually includes, so you know what to expect before we start.
A review of accounts, devices, network, cloud setup and applications, with findings ranked by risk.
Practical fixes for servers, cloud services, endpoints and web apps, applied in order of priority.
Multi-factor authentication, password management and least-privilege access across your tools.
Automated, tested backups and a written plan for restoring systems when something goes wrong.
Uptime, log and security monitoring, with alerts that reach someone who can act on them.
A regular schedule for operating system, software and dependency updates.
Help with accounts, devices, email, networks and software for everyone on your team.
Short, practical sessions on phishing, passwords and safe habits for your staff.
Our four-step rhythm, tuned for this discipline. You always know what is happening now and what comes next.
Step 01
We build an inventory of your systems, accounts and data. You cannot protect what you do not know you have.
Step 02
Every finding is rated by likelihood and impact, then written up in a short report that puts the most dangerous gaps at the top.
Step 03
We enable MFA, patch systems, tighten configurations, clean up access and set up backups, verifying each fix as we go.
Step 04
We keep watch with monitoring and scheduled reviews, and stay on hand for the daily IT requests that keep work moving.
These are working practices, not badges. We follow recognised public guidance and make no certification claims.
Not quite your situation? Tell us anyway. If we are not the right team, we will say so.
Check your fit with usQuestions worth asking about this service. If your question is not here, ask us directly.
No honest provider can promise that. What we can do is lower the odds, limit the damage if something does happen and make sure you can recover quickly. We will always be straight with you about the risk that remains.
We carry out security assessments, configuration reviews and vulnerability scanning, and we test web applications against common weaknesses such as the OWASP Top 10. If you need a formal, accredited penetration test for compliance, we will tell you and help you scope it with a specialist firm.
Primarily remote, which covers most day-to-day issues. If you need hands on site, tell us where you are and we will let you know what is possible.
We can help you put sensible controls in place and document them, which is the groundwork most frameworks ask for. We do not issue certifications, and we will say so clearly if you need an accredited auditor.
A practical guide on this topic, useful whether or not you end up working with us.
Security & IT
You do not need an enterprise budget to stop the most common attacks. These basics, spread over five working days, close the doors attackers try first.
5 min read
Start with an assessment. You will get a plain-language picture of your risks and a prioritised list of fixes.