Security that stands up to scrutiny
Attackers, insurers, auditors and enterprise customers are all asking harder questions. We harden your Microsoft estate, get you certified, and watch it — so the honest answer to every one of those questions is "yes, and here's the evidence."
What's included.
Assessment through to certification and ongoing monitoring, from one senior team.
Security assessment & hardening
A full review of your Microsoft estate against best-practice baselines — identity, email, endpoints, data — with every gap fixed, not just listed.
Identity & zero trust
Conditional access, phishing-resistant MFA, privileged access management and least-privilege reviews — the controls that stop 99% of account attacks.
Compliance & certification
Cyber Essentials and Cyber Essentials Plus taken end-to-end, plus audit-ready evidence packs for ISO 27001, SOC 2 and insurer questionnaires.
Monitoring & response
Microsoft Defender and Sentinel tuned to your estate, with alerting that reaches a human who knows your environment — not a dashboard nobody reads.
Fix the boring things first.
Most breaches don't start with a sophisticated exploit — they start with a phished password, a forgotten admin account, or a sharing link that was public when it shouldn't have been. So we start where attackers start: identity, email and the basics done properly. It's less glamorous than buying another security product, and considerably more effective.
Everything we harden is measured against recognised baselines — Microsoft Secure Score, the NCSC's Cyber Essentials controls, and CIS benchmarks — so progress is a number the board can see, not a feeling. Changes are rolled out in report-only mode first, then enforced, so the sales team doesn't get locked out of hotel Wi-Fi the week controls go live.
Certification is treated as a by-product of genuinely good posture, not a box-ticking sprint. When Cyber Essentials Plus assessment day arrives, nothing needs to be temporarily "arranged" — the controls have been running for weeks, evidence is already collected, and the assessment is a formality. The same evidence pack then answers insurer and enterprise-customer questionnaires in minutes instead of days.
What you'll walk away with.
Concrete artefacts, not just advice — everything documented and yours to keep.
- Security assessment report — findings, risk ratings and a prioritised fix list in plain English
- Hardened baseline implemented: conditional access, MFA, anti-phishing, device compliance
- Cyber Essentials / Cyber Essentials Plus certification, managed end-to-end
- Evidence pack for ISO 27001, SOC 2, insurers and enterprise customer questionnaires
- Incident response plan — who does what in the first hour, tested with a tabletop exercise
- Monthly security report: Secure Score trend, incidents, and what changed
Ways to work with us.
Start small and scale when it's earning its keep — every engagement is fixed-scope with a named senior engineer.
One to two weeks. The full estate review with written findings, risk ratings and a prioritised fix list. Fixed price, yours to action with anyone.
Three to six weeks. We implement the fix list, run the tabletop exercise, and take you through Cyber Essentials Plus first time.
Monthly. Defender and Sentinel monitored by engineers who know your estate, patching verified, and the monthly posture report.
You're in the right place if.
- An insurer, auditor or enterprise customer has sent a security questionnaire you can't confidently answer.
- You need Cyber Essentials or Cyber Essentials Plus to win or keep a contract.
- You suspect MFA and conditional access aren't set up as well as your last provider claimed.
- Security alerts go to a mailbox nobody owns. (Be honest.)
Certified first time, contract kept.
An anonymised engagement — details available on a call.
A 60-person manufacturer supplying a major retailer was given 90 days to achieve Cyber Essentials Plus or lose the contract at renewal.
The estate was a mix of unmanaged laptops, shared logins on the shop floor, and a firewall nobody had touched since installation. A previous self-assessment attempt had failed.
A two-week assessment, then a focused hardening sprint: Intune enrolment for every device, shared logins eliminated, MFA and conditional access enforced in stages, patching automated and verified.
Cyber Essentials Plus passed first time with weeks to spare. The contract renewed, the insurer reduced the premium at the next renewal, and the monthly report keeps the board's questions answered.
Questions we're asked a lot.
How long does Cyber Essentials Plus take?
From a standing start, typically four to eight weeks depending on estate size — assessment, hardening sprint, then certification. Because controls run for weeks before assessment day, first-time passes are the norm.
Do you do penetration testing?
We scope and coordinate penetration tests through CREST-accredited testing partners, then implement the remediations ourselves — you get independent testing and one team accountable for fixing what it finds.
Will tighter security lock my staff out of things?
Not if it's done properly. Every control is rolled out in report-only mode first so we can see exactly who'd be affected, then enforced in stages with exceptions agreed in advance. Security that breaks the business doesn't last.
We already have an IT provider — can you work alongside them?
Yes. Security assessments and certifications are often delivered alongside an incumbent provider. You get an independent view of your posture, and they get a clear fix list.
What happens if we'd fail the assessment today?
That's the most common starting point. The assessment tells you exactly where the gaps are, the hardening sprint closes them, and we don't book the certification until the evidence says you'll pass.
Free AI & Cloud Audit.
The audit includes a security check — Secure Score, identity gaps and sharing risks — with a written report. No sales deck.