Stage 1 · Scope
Systems, data and what matters most.
Four services for small and mid-sized organisations, authorised in writing before anything starts.
We assess against an established framework rather than a personal checklist, then translate it into plain findings: what is exposed, how badly, and what order to fix it in. A small organisation cannot do forty things, so we tell you which six matter.
Systems, data and what matters most.
Controls, configuration and practice.
Ranked by real risk to you.
In an order you can actually follow.
Scope, window and techniques, in writing.
Within scope, with contact throughout.
Reproducible findings, ranked.
After you have fixed things.
Testing happens under a signed engagement letter and rules of engagement that state exactly what is in scope, when, and which techniques are permitted. We test only what you own or can authorise, and a retest after remediation is included rather than sold separately.
We work out what a requirement actually demands of an organisation your size, find the gaps, and help produce the evidence and documentation. We prepare you for an audit; we do not perform the audit or issue certification, and anyone promising you a pass is not being straight.
What genuinely applies to you.
Against the real requirements.
Policies and records that stand up.
Reviewed before the auditor comes.
What would realistically happen to you.
Roles, decisions and contacts named.
Rehearsed with the actual people.
Updated with what the exercise exposed.
Most organisations discover during an incident that nobody knows who decides, who calls the insurer, or where the backups are. We write that down beforehand and then rehearse it, because a plan nobody has practised tends to fail in the first hour.
A free scoping call on what you actually need, and what it would cost.