Security assessment
External and internal review: exposed services, patch state, password practice, backup integrity and segmentation. Findings ranked by what an attacker would reach first.
Hardening, segmentation, endpoint control and incident response: sized for companies without a security team
At a glance
Cybersecurity usually runs assessment in 2–5 days. hardening takes a day to three weeks, depending on the size of the estate.
We sit with the people who use the system, walk the site, and read the network. No proposal before we understand how the work is done today and where it breaks.
Discover
2–5 days
Current-state map of systems and traffic
Ranked list of what is costing you time or money
A go / no-go recommendation, in writing
For CybersecurityA fixed-price security assessment. You get a ranked findings report you can act on with or without us.
Design
1–3 days
Solution architecture and integration plan
Bill of materials with lead times
Fixed-scope statement of work
Build & deploy
1 day – 3 weeks
Working increments on anything that takes more than a fortnight
Staged cutover with a tested rollback
Handover documentation as it is built, not after
Run & improve
Ongoing
Monitored uptime with agreed response times
Quarterly review against the original goals
Capacity and security roadmap, refreshed each quarter
A security proposal that starts with a product list has started in the wrong place. We start from the attacker's side: what would they reach first, what would it cost you, and what is the cheapest thing that stops it. The short version of that order is here.
1. Know what you have. An asset register and a network read. You cannot protect what you have not listed.
2. Close the front door. Multi-factor authentication on email, VPN and remote desktop. Remove direct RDP exposure. This single step removes more risk than everything after it combined.
3. Make the blast radius small. Segment the network so a compromised workstation cannot reach the file server, the cameras and the PLCs. Remove local administrator rights from daily-use accounts.
4. Make recovery real. Backups that are off-site, offline or immutable, and a restore that has been performed and timed. We give you your real recovery time. Usually nobody has measured it before.
5. Then buy tooling. Managed endpoint detection, log collection, alerting. Worth real money, once the four steps above are done.
We install camera systems, access control and alarms as well as firewalls, and the overlap matters more than most vendors admit. An IP camera on the office network with a default password is a route into the ledger. A server room with a broken door lock makes disk encryption academic.
Because we do both sides, they get designed as one system.
We work to ISO 27001 practices (documented access control, data handling and incident response) and build to GDPR principles wherever personal data is involved. If you need a certificate for a contract or a tender, ask us for our current position in writing before you rely on it. We would rather lose the line item than have you discover a gap during an audit.
You receive
Who this is for
How it starts
A fixed-price security assessment. You get a ranked findings report you can act on with or without us.
Start hereNobody is targeting you specifically. That is the point. Modern ransomware is indiscriminate: automated scanning finds an exposed service or a reused password and the payload does not care what your revenue is. Small and mid-sized companies now make up the clear majority of incidents precisely because they are the least defended.
Often bought together
A call, then a written recommendation. No obligation.