What we actually do, and for whom.
Every engagement is scoped and priced for businesses under 100 people. We do not adapt enterprise services downward — we build from the right starting point.
SME Security Audit
For: any business that wants to understand where the gaps are before something goes wrong.
A structured review of your current controls, policies, and configurations across the five key risk areas for small businesses: access management, email security, endpoint controls, data handling, and physical security. Conducted remotely or on-site. Delivered without assuming any prior technical knowledge.
The output is a written report ordered by risk priority — not by technical category. The highest-priority items come first, with plain-language explanations of what each gap means in practice.
- Pre-assessment call to scope the review
- Half-day structured assessment session
- Written report with prioritised findings
- 30-minute debrief to walk through the report
- 12 months of email follow-up questions included
- Optional re-assessment after remediation
Scope note: the audit covers controls and configurations, not active penetration testing. It is designed to find what is missing or misconfigured — not to simulate an active attack. If a penetration test is more appropriate, we'll say so at the initial call.
Email Security & Phishing Controls
For: businesses that have had a near-miss, recently received a suspicious email, or simply want to close a gap they know exists.
Phishing defence sits at the intersection of technical controls and staff behaviour. Most implementations address only one side. We cover both: reviewing and correcting your email gateway configuration (SPF, DKIM, DMARC, filtering rules) and running a practical staff awareness session that focuses on decision-making rather than jargon.
- Email gateway configuration review
- SPF / DKIM / DMARC alignment check and correction
- Written reporting procedure for staff
- 60-minute staff awareness session (remote or on-site)
- Post-session reference card for staff
Scope note: this covers inbound email controls and staff awareness. It does not include email encryption or archiving setup, which are treated as separate engagements.
Security Awareness Training
For: businesses onboarding new staff, responding to a security incident, or preparing for Cyber Essentials certification.
A 90-minute session, delivered remotely or in person, covering the security decisions staff make most often: identifying suspicious emails, handling passwords, sharing files, and what to do when something looks wrong. Written in plain English, using examples from the kind of business your staff actually work in.
- 90-minute session for up to 25 participants
- Scenario-based format, not slide-deck lecture
- Session recording available on request
- Post-session written summary for records
Scope note: sessions cover general security awareness. Role-specific training (finance team wire fraud prevention, developer secure coding) is available as a separate engagement.
Cyber Essentials Support
For: businesses pursuing Cyber Essentials or Cyber Essentials Plus certification, typically for procurement requirements or as a benchmark.
Cyber Essentials covers five technical controls: firewalls, secure configuration, access control, malware protection, and patch management. We review your current state against the scheme requirements, identify what needs to change, and support you through the self-assessment process. For Plus, we assist with preparing for the technical verification.
- Gap analysis against current scheme requirements
- Remediation guidance for each gap found
- Support completing the self-assessment questionnaire
- Cyber Essentials Plus preparation and mock assessment
Scope note: we support the certification process but do not issue certificates. Certification is issued by an accredited certification body. We can recommend one if needed.
Incident Response Planning
For: businesses that want to know what to actually do if something goes wrong — before something goes wrong.
An incident response plan for a small business does not need to be a 40-page document. It needs to answer three questions clearly: who decides what, in what order, and who gets called. We help you build a response plan that your staff will actually follow under pressure, including a one-page quick-reference that works when people are panicking.
- Tabletop walkthrough of likely incident scenarios
- Written incident response plan (proportionate in length)
- Contact list and escalation path
- One-page quick-reference card
- Annual review option available
Scope note: this produces a plan and supports your team in using it. It does not include live incident response support (active breach management). Referrals to incident response providers are available if needed.
Not sure which of these fits?
Tell us what's on your mind and we'll tell you honestly which service, if any, makes sense.
Get in Touch