Cyber security & anti-virus

Security Is a Cost-Benefit Decision, Not a Product Purchase

More advanced protection is always available. The right level for you depends on what you'd lose, what you're required to protect, and what you can realistically operate. We'll tell you where that line sits rather than selling you everything above it.

Managed EDR from SentinelOne or CrowdStrike, not bundled anti-virus
Layers you can buy individually rather than one fixed package
Honest answers on your cyber insurance questionnaire
partner — SOC 2 Type 2 provider
No cost

Start with a free security scan

An external scan of your public-facing footprint, with a plain-English summary of what's exposed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Authorized scanning only. We confirm ownership before testing.

How we scope it

Nobody Can Afford Every Control. Choose Deliberately.

Cyber security is risk toleration and mitigation. A careful cost-benefit analysis is what ensures you have the appropriate level of protection — not the maximum available, and not whatever came bundled with the laptops.

That conversation starts with what would actually hurt: which systems stop the business, which data carries a legal obligation, and how long you could operate without either.

Questions that set the level
What stops if this system is down?
Determines availability requirements and where redundancy is worth paying for.
What data carries a legal obligation?
PHIPA, PIPEDA, or PCI exposure raises the floor regardless of your risk appetite.
How long could you operate without it?
Sets recovery objectives — and tells you whether backup alone is sufficient.
Who is asking you to prove it?
An insurer, auditor, or client requirement often defines the minimum for you.
Who will operate the controls day to day?
A tool nobody watches is spend without protection. Managed or unmanaged changes the answer.
Defence in depth

No Single Control Stops an Attack

Each layer catches what the one before it missed. The goal isn't a perfect perimeter — it's making sure a failure at any single point isn't the whole story.

Layer 1

Email security

Filtering, impersonation protection, and safe links — because most attacks arrive by email rather than through the firewall.

Phishing, BEC
Layer 2

Identity and MFA

Multi-factor with conditional access, so a stolen password isn't sufficient on its own and unusual sign-ins get challenged.

Credential theft
Layer 3

Endpoint detection and response

Behavioural detection on every device, with the ability to isolate a machine and roll back ransomware encryption.

Malware, ransomware
Layer 4

Network and firewall

Managed firewalls, segmentation, and traffic inspection between devices to protect critical systems from each other.

Lateral movement
Layer 5

Patching and vulnerability management

Scanning on-premises and cloud to detect assets, assess vulnerabilities, and actually apply the remediation.

Known exploits
Layer 6

Backup and recovery

The layer that decides whether an incident is a bad day or an existential one. Tested restores, not assumed ones.

Everything else
Know what you're buying

Traditional Anti-Virus Is Not EDR

Plenty of providers still sell the first and describe it as the second. The difference matters most on the day something novel gets through.

Traditional anti-virus
Signature-based
Detects Files matching a known malware signature
Novel threats Missed until a signature is published
Response Quarantines a file; no wider action
Visibility Little — you learn what it blocked, not what happened
Managed EDR
Behaviour-based, watched
Detects Behaviour — what a process does, not what it is
Novel threats Caught on activity, including never-seen variants
Response Isolates the device and can roll back encryption
Visibility A forensic timeline of what happened and when
What we provide

Pick the Layers You Need

Available individually or as a package. Most clients start with the first three and add from there.

Start here

Managed anti-virus with EDR

SentinelOne or CrowdStrike deployed, tuned, and monitored — with someone actually responding to detections.

Start here

24/7 SOC and MDR

A security operations centre watching around the clock, because attacks don't wait for business hours.

Start here

Security awareness training

Simulated phishing and staff training, including onsite sessions. The cheapest control with the widest effect.

Core

System patching

Operating system and third-party patching on a managed schedule, with compliance reporting you can show an auditor.

Core

Managed firewall

Configured, maintained, and monitored — including the rule reviews most firewalls never get after installation.

Core

Internal vulnerability scanning

Continuous scanning inside the network to find what's exposed before someone else does.

Add

Microsoft 365 / Google Workspace backup

Because the platform's recycle bin is not a backup, and retention policies don't survive a malicious deletion.

Add

Infrastructure backup and DR

Servers and virtual machines with local plus offsite copies, and a recovery time you've actually measured.

Add

Penetration testing

Internal and external testing to prove what an attacker could reach, with remediation guidance and a retest.

The human element

Most Breaches Start With Someone Clicking Something

More often than not it's an unknowing team member who lets a threat in — not a technical failure. No security programme is complete without a trained workforce, and training is the cheapest control available.

We run simulated phishing and awareness training, and we'd recommend agreeing up front how results are handled internally. The point is to improve people's instincts, not to discipline anyone.

Simulated phishing

Realistic campaigns that measure click rates, credential entry, and — most usefully — how many people report it.

Onsite sessions

In-person training to supplement the digital modules, which works considerably better for non-technical teams.

Targeted follow-up

Extra support for people who need it, rather than the same generic module for the whole company.

Reporting made easy

A one-click way to report something suspicious, because a reported email is worth more than a blocked one.

Cyber insurance

Your Insurer Now Sets a Security Baseline

Cyber insurance applications have tightened considerably. Controls that were optional a few years ago are now conditions of coverage — and answering "yes" to something you haven't actually implemented can affect a claim later.

We work through the questionnaire with you, tell you honestly which answers are currently "no", and prioritise the gaps that affect either your premium or your coverage.

Commonly required for coverage
MFA on email and remote access? Required
EDR deployed on all endpoints? Required
Offsite, immutable backups? Required
Security awareness training? Common
Documented incident response plan? Common
Privileged access separated? Increasing
Questions, answered

Cyber Security FAQs

We already have anti-virus. Isn't that enough?

It depends what it is. Traditional signature-based anti-virus only recognises malware it already knows about, which is why ransomware variants get through it routinely. EDR watches behaviour instead, so a never-before-seen threat is still caught on what it does. If your current tool can't isolate a device or show you a timeline of an incident, it's the former.

Do you use SentinelOne or CrowdStrike?

Both — we're partners with each, and the right choice depends on your environment, existing tooling, and budget. We'll tell you which we'd recommend for you and why, rather than defaulting to whichever we prefer to deploy.

What does the free security scan actually cover?

An external scan of your public-facing footprint on a single public IP — exposed services, missing patches, and configuration weaknesses visible from the internet — plus a plain-English summary. It costs you nothing and the findings are yours whether or not you engage us.

How much should we be spending on security?

There's no universal figure, and any provider quoting one without seeing your environment is guessing. What we can do is scope against what you'd actually lose and what you're required to protect, then show you the cost of each layer so you can decide where to stop.

Our insurer sent a questionnaire we can't answer. Can you help?

Yes, and it's one of the most common reasons businesses call us. We'll work through it, tell you honestly which answers are currently 'no', and prioritise the controls that affect either your premium or whether you're covered at all. Answering 'yes' to something unimplemented is worse than answering 'no'.

Is training really worth it compared to better tools?

It's usually the highest return per dollar in the whole programme. Most incidents begin with a person, not a technical failure — and unlike a tool, awareness improves every layer at once. We'd rather you fund training than buy a more expensive endpoint agent.

Can you handle security without taking over all our IT?

Yes. Security is available as a standalone engagement alongside your existing internal team or another provider. We'd want clarity on who owns what, but there's no requirement to move your whole environment to us.

Let's connect

Find out what's exposed.

Start with the free external scan — it costs you nothing and the findings are yours to keep whether or not you work with us.

Request a security conversation

We'll reply within one business day.

Services of interest

We don't share your data.View Privacy Policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.