Our services, in detail

Four services for small and mid-sized organisations, authorised in writing before anything starts.

Program 01 · Where you actually stand

Security risk assessment

We assess against an established framework rather than a personal checklist, then translate it into plain findings: what is exposed, how badly, and what order to fix it in. A small organisation cannot do forty things, so we tell you which six matter.

  • 2 to 4 weeks
  • Organisations
  • Quoted in writing
  • Access and interviews

Start this program

Stage 1 · Scope

Systems, data and what matters most.

Stage 2 · Review

Controls, configuration and practice.

Stage 3 · Findings

Ranked by real risk to you.

Stage 4 · Roadmap

In an order you can actually follow.

Stage 1 · Rules of engagement

Scope, window and techniques, in writing.

Stage 2 · Testing

Within scope, with contact throughout.

Stage 3 · Reporting

Reproducible findings, ranked.

Stage 4 · Retest

After you have fixed things.

Program 02 · Only what you authorise

Penetration testing

Testing happens under a signed engagement letter and rules of engagement that state exactly what is in scope, when, and which techniques are permitted. We test only what you own or can authorise, and a retest after remediation is included rather than sold separately.

  • 1 to 3 weeks
  • Organisations
  • Quoted in writing
  • Signed authorisation

Start this program

Program 03 · Before the auditor arrives

Compliance readiness

We work out what a requirement actually demands of an organisation your size, find the gaps, and help produce the evidence and documentation. We prepare you for an audit; we do not perform the audit or issue certification, and anyone promising you a pass is not being straight.

  • Per framework
  • Organisations
  • Quoted in writing
  • Documentation access

Start this program

Stage 1 · Applicability

What genuinely applies to you.

Stage 2 · Gap analysis

Against the real requirements.

Stage 3 · Evidence

Policies and records that stand up.

Stage 4 · Readiness

Reviewed before the auditor comes.

Stage 1 · Scenarios

What would realistically happen to you.

Stage 2 · Plan

Roles, decisions and contacts named.

Stage 3 · Tabletop

Rehearsed with the actual people.

Stage 4 · Revision

Updated with what the exercise exposed.

Program 04 · Written before you need it

Incident response planning

Most organisations discover during an incident that nobody knows who decides, who calls the insurer, or where the backups are. We write that down beforehand and then rehearse it, because a plan nobody has practised tends to fail in the first hour.

  • 2 to 3 weeks
  • Organisations
  • Quoted in writing
  • Leadership time

Start this program

Client asking for a security review?

A free scoping call on what you actually need, and what it would cost.