
More advanced protection is always available. The right level for you depends on what you'd lose, what you're required to protect, and what you can realistically operate. We'll tell you where that line sits rather than selling you everything above it.
An external scan of your public-facing footprint, with a plain-English summary of what's exposed.
Authorized scanning only. We confirm ownership before testing.
Cyber security is risk toleration and mitigation. A careful cost-benefit analysis is what ensures you have the appropriate level of protection — not the maximum available, and not whatever came bundled with the laptops.
That conversation starts with what would actually hurt: which systems stop the business, which data carries a legal obligation, and how long you could operate without either.
Each layer catches what the one before it missed. The goal isn't a perfect perimeter — it's making sure a failure at any single point isn't the whole story.
Filtering, impersonation protection, and safe links — because most attacks arrive by email rather than through the firewall.
Multi-factor with conditional access, so a stolen password isn't sufficient on its own and unusual sign-ins get challenged.
Behavioural detection on every device, with the ability to isolate a machine and roll back ransomware encryption.
Managed firewalls, segmentation, and traffic inspection between devices to protect critical systems from each other.
Scanning on-premises and cloud to detect assets, assess vulnerabilities, and actually apply the remediation.
The layer that decides whether an incident is a bad day or an existential one. Tested restores, not assumed ones.
Plenty of providers still sell the first and describe it as the second. The difference matters most on the day something novel gets through.
Available individually or as a package. Most clients start with the first three and add from there.
SentinelOne or CrowdStrike deployed, tuned, and monitored — with someone actually responding to detections.
A security operations centre watching around the clock, because attacks don't wait for business hours.
Simulated phishing and staff training, including onsite sessions. The cheapest control with the widest effect.
Operating system and third-party patching on a managed schedule, with compliance reporting you can show an auditor.
Configured, maintained, and monitored — including the rule reviews most firewalls never get after installation.
Continuous scanning inside the network to find what's exposed before someone else does.
Because the platform's recycle bin is not a backup, and retention policies don't survive a malicious deletion.
Servers and virtual machines with local plus offsite copies, and a recovery time you've actually measured.
Internal and external testing to prove what an attacker could reach, with remediation guidance and a retest.
More often than not it's an unknowing team member who lets a threat in — not a technical failure. No security programme is complete without a trained workforce, and training is the cheapest control available.
We run simulated phishing and awareness training, and we'd recommend agreeing up front how results are handled internally. The point is to improve people's instincts, not to discipline anyone.
Realistic campaigns that measure click rates, credential entry, and — most usefully — how many people report it.
In-person training to supplement the digital modules, which works considerably better for non-technical teams.
Extra support for people who need it, rather than the same generic module for the whole company.
A one-click way to report something suspicious, because a reported email is worth more than a blocked one.
Cyber insurance applications have tightened considerably. Controls that were optional a few years ago are now conditions of coverage — and answering "yes" to something you haven't actually implemented can affect a claim later.
We work through the questionnaire with you, tell you honestly which answers are currently "no", and prioritise the gaps that affect either your premium or your coverage.
It depends what it is. Traditional signature-based anti-virus only recognises malware it already knows about, which is why ransomware variants get through it routinely. EDR watches behaviour instead, so a never-before-seen threat is still caught on what it does. If your current tool can't isolate a device or show you a timeline of an incident, it's the former.
Both — we're partners with each, and the right choice depends on your environment, existing tooling, and budget. We'll tell you which we'd recommend for you and why, rather than defaulting to whichever we prefer to deploy.
An external scan of your public-facing footprint on a single public IP — exposed services, missing patches, and configuration weaknesses visible from the internet — plus a plain-English summary. It costs you nothing and the findings are yours whether or not you engage us.
There's no universal figure, and any provider quoting one without seeing your environment is guessing. What we can do is scope against what you'd actually lose and what you're required to protect, then show you the cost of each layer so you can decide where to stop.
Yes, and it's one of the most common reasons businesses call us. We'll work through it, tell you honestly which answers are currently 'no', and prioritise the controls that affect either your premium or whether you're covered at all. Answering 'yes' to something unimplemented is worse than answering 'no'.
It's usually the highest return per dollar in the whole programme. Most incidents begin with a person, not a technical failure — and unlike a tool, awareness improves every layer at once. We'd rather you fund training than buy a more expensive endpoint agent.
Yes. Security is available as a standalone engagement alongside your existing internal team or another provider. We'd want clarity on who owns what, but there's no requirement to move your whole environment to us.
Start with the free external scan — it costs you nothing and the findings are yours to keep whether or not you work with us.