01 / 06
You finally know what you have
Most companies cannot list their systems, accounts, data locations and suppliers with any confidence. We build and maintain that inventory, because nothing else in security works without it.

Practical cybersecurity for mid-sized companies, delivered as a monthly subscription instead of a one-off project.
Both routes are a valid start: the check if you want a structured picture first, the intro call if you already know what is keeping you awake.
Three pressures at once: regulators asking for evidence, clients asking for security answers, and an IT setup that nobody is formally responsible for.
Very few mid-sized companies have a security problem in the dramatic sense. They have an ownership problem: systems, accounts and suppliers that grew faster than anyone's ability to keep track of them.
NIS2, GDPR and client security questionnaires arrive, and nobody can produce evidence of what is actually in place.
Backups exist, but no one has restored from them under pressure to see whether they work.
Former employees, external suppliers and old tools still hold access that was never withdrawn.
Your IT partner keeps the systems running, but is not responsible for risk, policy or reporting.
A single ransomware incident or long outage would stop production or delivery, and the plan for that day is in nobody's head.
Security is not a product you buy once. It is a set of routines that need an owner and a rhythm.
WE WORK ON WHAT WOULD ACTUALLY HURT YOU, NOT ON A STANDARD CHECKLIST
Every engagement follows the same rhythm: we establish what you have and what it would cost you to lose it, we fix the gaps that matter in a sensible order, and then we keep the routines running month after month so the picture stays current.
A structured review of your systems, data, accounts, suppliers and current obligations. You get a plain-language risk picture with a short list of what would genuinely hurt the business, ranked by consequence and not by technical severity.
We put the essentials in place: access control, backup and restore that has actually been tested, endpoint and email protection, policies your people can follow, and the documentation that regulators and clients ask to see.
Monitoring, patch and vulnerability routines, awareness training, incident readiness and a regular review with management. Security ages faster than most things in a business, so it is maintained rather than delivered once.
Six things a subscription gives you that a one-off audit or a hardware purchase does not.
01 / 06
Most companies cannot list their systems, accounts, data locations and suppliers with any confidence. We build and maintain that inventory, because nothing else in security works without it.
Browse
01 / 06
Most companies cannot list their systems, accounts, data locations and suppliers with any confidence. We build and maintain that inventory, because nothing else in security works without it.
Cybersecurity Readiness Check
Your 7-minute starting point
Twenty-four questions, about seven minutes. It measures six areas of practical security and tells you which one would hurt you first.
About this check: 24 questions, roughly 7 minutes. It measures six dimensions of practical cybersecurity (visibility, access control, resilience, people, suppliers, governance) and factors in your role, company size, IT setup and data sensitivity. You receive a scored PDF report with a security profile diagram, your main exposure, an estimated cost of a serious incident and a prioritised action plan, delivered free by email.
Your report is the starting point. In the free conversation that follows, we review the findings together, put them into the context of your business and discuss which subscription level would currently be most useful.
So we can send your scored report and address you properly. Two fields, twenty seconds.
Used only to send your report and, if you allow it, follow up once. Never shared.
Where to start
Before any package makes sense, you need an honest view of where you stand. The security check takes about seven minutes, gives you a scored report by email, and costs nothing. If you would rather just talk it through, book a call.
All levels run on the same principle: a fixed monthly fee, a named security lead, and no billing by the hour.
Pick the level that matches what you would lose in a bad week, not the size of your IT department.
Baseline review and initial implementation, 4 to 6 weeks.
12 months of working together. Then flexible in 3-month periods.
For companies that need the fundamentals in place and documented, without building an internal security function. A structured baseline review, the essential protective measures, and a maintained set of documentation you can show to clients and auditors.
Everything in Baseline, plus:
Baseline review, implementation and response plan, 6 to 10 weeks.
12 months of working together. Then flexible in 3-month periods.
For companies where an outage or a data loss would directly stop production, delivery or client service. Everything in Baseline, plus continuous monitoring, tested incident readiness, supplier risk management and regular staff training.
Everything in Resilience, plus:
Baseline review, implementation and governance framework, 10 to 14 weeks.
12 months of working together. Then flexible in 3-month periods.
For companies under formal obligation, whether through NIS2, sector regulation, group requirements or contractual duty towards large clients. Everything in Resilience, plus an acting security officer function, formal governance, audit preparation and board-level reporting.
Not sure which level fits? The security check gives you a scored picture of where you stand and which level matches your current exposure. Start the 7-minute check
All prices net, plus VAT. The setup fee covers the baseline review and the initial implementation phase. Initial minimum term of 12 months, then automatic extension in three-month periods, cancellable with 30 days notice before the next period begins.
Straight answers on how the subscription works and what it does and does not cover.