
Defence you can evidence
Most breaches are not sophisticated. They are unattended.
An unpatched appliance, a password reused from a personal account, an ex-supplier whose access nobody revoked, a backup that turned out not to restore. We work on the unglamorous side of security — the controls that fail quietly — and we run them as a standing process with named owners and evidence, because that is both what stops incidents and what an auditor, an insurer or an enterprise client will ask you to produce.
Technologies
01Capabilities
Identity first, because that is the way in
Single sign-on, enforced MFA, least-privilege roles, joiner-mover-leaver automation and quarterly access review. Credential abuse is the entry point in the large majority of incidents, and it is the cheapest one to close.
Patching as a schedule, not a reaction
Inventory, severity-based windows, staged rollout and a record of what was applied when. Most exploited vulnerabilities had a patch available for months.
Detection with a defined response
Centralised logs, alerts routed to a person, and a written runbook per alert class with an agreed response window. We are explicit that this is business-hours managed detection, not a 24/7 analyst floor — and we say which of the two your risk actually justifies.
Recovery proven, not assumed
Off-site, encrypted, versioned backups with immutability where the platform supports it, restored on a schedule into a scratch environment. A backup nobody has restored is a hope with a filename.
02Scope
What is included
- Security baseline and hardening for Linux servers, containers and cloud accounts
- Identity: SSO, MFA enforcement, role design, joiner-mover-leaver process
- Secrets management and removal of credentials from repositories and configs
- Vulnerability scanning, dependency and supply-chain monitoring
- Patch management with severity-based windows and an audit trail
- Log aggregation, alerting and runbook-driven response
- Endpoint protection and device policy for laptops and mobiles
- Network segmentation, firewall review, WAF and rate limiting
- Backup immutability, retention design and scheduled restore testing
- Incident response plan, tabletop exercises and post-incident reports
- Phishing simulation and security awareness for the whole team
- Supplier and third-party risk assessment
- NIS2 and DORA readiness assessment for in-scope organisations
- Evidence packs for ISO 27001 audits, insurers and enterprise questionnaires
03The layers
Where the work actually happens
Security is not one product. These are the six places we work, roughly in the order they pay off.
Identity and access
SSO, MFA everywhere it can be enforced, least-privilege roles, and access that is removed the day someone leaves rather than at the next review.
- Quarterly access recertification
- Privileged access separated
- Service accounts inventoried
- Shared credentials eliminated
Systems and patching
A real inventory, hardened baselines against CIS, and patch windows sized by severity so a critical fix does not wait for the next maintenance slot.
- Asset inventory kept current
- CIS-benchmarked baselines
- Automated OS and dependency updates
- Change record for every window
Applications
Secure defaults in the codebase, dependency and container scanning in CI, and review gates on the paths that touch money, authentication or personal data.
- SCA and secret scanning in CI
- Review required on sensitive paths
- Security tests in the pipeline
- See also our web security review
Detection
Logs centralised, alerts that reach a person, and a runbook for each class so the first ten minutes are not improvised.
- Central log retention
- Alert routing and escalation
- Runbook per alert class
- Agreed response windows
Recovery
Immutable, off-site backups and a restore that is actually performed on a schedule, into an environment where a failure costs nothing.
- Immutability where supported
- Documented RPO and RTO
- Scheduled restore rehearsals
- Recovery runbook maintained
People and suppliers
Phishing simulation with training that follows a click rather than punishing it, and a risk assessment before a new supplier gets access.
- Recurring phishing simulation
- Onboarding security briefing
- Supplier assessment before access
- Contractual security terms
04Being straight about it
What we are, and what we are not
We are not a 24/7 security operations centre. Staffing analysts around the clock is a different business with a different cost base, and a supplier who implies otherwise while running a business-hours rota is selling you a feeling. What we provide is managed detection with defined response windows, an on-call rotation for critical alerts, and a runbook so the first response does not depend on who happens to answer. Where your risk profile genuinely requires round-the-clock eyes, we will say so and help you procure it.
We are not a certified penetration testing house. We do adversarial review with the source code and infrastructure in hand, which finds a different and often larger class of problem for less money. But when a certification, a client contract or a regulator requires a formal test by an accredited third party, that is what you need, and we will scope it with you and remediate what it finds.
We do not do forensic investigation for legal proceedings. We contain, preserve evidence, restore service and write the incident up. If the matter is heading to court or an insurance claim, a licensed forensic examiner needs to take custody early — and calling them late is what usually destroys the evidence.
Everything else on this page we do, run and can show you evidence of.
05Engagement
How it starts and how it continues
Assessment
A posture review against CIS and ISO 27001 controls, producing a gap list with severity, effort and cost. Often this is the IT audit, scoped to security.
Remediation sprint
The critical gaps closed in a defined block of work: identity, patching, secrets, backups. This is where most of the risk reduction happens.
Operate
Monitoring, patch windows, access recertification, restore rehearsals and phishing simulation on a calendar, with a monthly report that says what was done and what changed.
Exercise
A tabletop incident twice a year, and a real restore test quarterly. Plans that have never been rehearsed fail in the same three places every time.
05Questions
Frequently asked questions
We are a small company. Is this not overkill?
The controls scale down; the attacks do not discriminate. For a small team the work is mostly identity, patching, backups and phishing awareness — a defined block of remediation and then a modest monthly retainer. Skipping it is what turns a routine incident into an existential one, because a small company has no spare capacity to absorb two weeks of downtime.
Does NIS2 apply to us?
It applies to essential and important entities in scope sectors above certain size thresholds, and — this is the part people miss — it reaches their suppliers through contractual security requirements. Many companies encounter it not as a regulator but as a clause in a customer contract. We run a readiness assessment that tells you which category you are in and what the gap is, without guessing on your behalf.
What happens if we are breached while you are engaged?
The incident response plan runs: contain, preserve evidence, identify the entry point, restore from verified backups, then a written report with a timeline suitable for an insurer or a regulator. Notification clocks — seventy-two hours under GDPR, shorter under NIS2 for in-scope entities — are tracked from the moment of awareness, and the contract states who does what rather than leaving it to be negotiated during the incident.
Can you work alongside our existing IT provider?
Frequently, and it is often the right structure: they keep operations, we bring the security discipline and the independent view. It has to be agreed openly — security work done around an incumbent rather than with them tends to produce two half-owned systems and a gap between them.
How is this different from your web security page?
That page is the application layer and the regulatory paperwork: reviewing a Magento or WordPress codebase, cleaning up after a hacked site, GDPR data mapping, PCI DSS scope. This page is the organisation — identity, endpoints, network, monitoring, recovery, people and suppliers. Most clients need both, and we scope them together.
06Nearby
Related services
IT Audit
An independent review of your infrastructure, applications, security posture, costs and delivery process — delivered as a written report with severities, owners and a costed plan.
Infrastructure & DevOpsDevOps, Linux Servers & Managed Hosting
Linux server configuration, hardening, Docker deployments, CI/CD pipelines, monitoring and managed hosting — the infrastructure work most agencies quietly outsource.
Infrastructure & DevOpsWeb Security & Compliance
Security audits, hardening, incident recovery and the practical side of GDPR, PCI DSS and NIS2 — for teams that would rather not learn this during a breach.
What we do
Cyber Security
Hardening, identity, patching, monitoring, backup verification and incident response — run as an ongoing discipline against ISO 27001 and NIS2, not as a product you switch on.
