Findings you can act on,
not a document to file.
Audits, security reviews and migration planning, delivered as findings you can act on rather than a document that sits on a shelf. Most breaches are not sophisticated, and most estates have never been written down in one place.
How it runs.
Audit
Free, no obligation
We go through everything you are actually running.
What it costs, what is about to expire and what it exposes. No charge, no obligation.
Written findings
Free, no obligation
What we found, ranked by what saves or risks the most.
What we would do about it, in language you can hand to a board. Yours to keep.
Proposal
Only if you want one.
The work, sequenced, against findings you have already read.
Implementation
Done in a sequence that keeps the business running.
Migrations, cleanups, consolidation, patching, segmentation and access tidy-up.
Verification & documentation
We re-test what we fixed and prove it works.
Including restoring from a backup. Then the estate is written down properly, so the next person does not start from nothing.
Ongoing review
An audit is only a snapshot.
Licences renew and estates drift, so we come back to it.
What is in scope.
Infrastructure & security audit
A full picture of what you are actually running and what it exposes: what it costs, what is out of support, what is duplicated, which renewal is about to arrive, what is patched and what is not, which accounts still exist for people who left, and what the firewall permits that nobody remembers permitting. Usually the first time anyone has written it all down in one place.
- Includes
- Asset inventory Exposure review Patch status Account audit
Monitoring, response & compliance support
Detection and response where it is warranted, plus the evidence-gathering and control work behind standards like ISO 27001 or PCI DSS. We help you meet them; the certification itself is awarded by an accredited auditor, not by us.
- Includes
- 24/7 monitoring Incident response Evidence gathering Control mapping
Ongoing support
Help desk and on-site support for organisations without an internal IT function, or alongside one that is stretched. Scope, hours and escalation are agreed in writing before anything starts - we do not publish a response time we have not committed to you specifically.
- Includes
- Help desk On-site callouts Escalation path Agreed scope
Also covered
Licensing & contracts
Finding the AMC nobody remembers signing, the licences you pay for twice, and the seats nobody uses.
Migration planning
On-premises to cloud, or between platforms, sequenced so the business keeps running through it.
Vendor management
We deal with the suppliers so your team does not have to chase three of them for one fault.
Access control & patch discipline
Who can reach what, enforced rather than assumed, with joiners, movers and leavers handled as a process - and a patch schedule that actually runs, on the machines that actually exist, with someone accountable for it.
Backup & recovery
Backups that have been restored from at least once. An untested backup is a hope, not a control.
Tell us what
you are building.
Tell us about the building and what it consultancy & cybersecurity has to do in it. We will come and look before anyone talks about a quote.
Survey, audit and written findings - free, and yours to keep