Skip to content
04Services

Cybersecurity

Attackers do not break in through the firewall any more. They log in with credentials someone gave them.

Technical controls come first and they are not optional: multi-factor authentication everywhere, endpoint detection and response, email filtering, DNS filtering, least-privilege access, and encrypted, immutable backups that are restored on a schedule to prove they work.

But the control that changes outcomes most is the one people find least interesting. We run continuous phishing simulation and short, specific training, and we report on it. Staff who have seen a convincing fake invoice in a safe setting behave differently when a real one arrives.

We also write down what happens when something goes wrong: who is called, in what order, what gets isolated, who talks to clients, who talks to insurers. An incident response plan invented during an incident is not a plan.

04What's included

Multi-factor authentication

Enforced across email, remote access, and administrative accounts.

Endpoint detection & response

Behavioural detection with the ability to isolate a machine remotely.

Email & DNS filtering

The two cheapest, highest-yield controls available. Both belong in place.

Phishing simulation & training

Continuous campaigns with per-department reporting, not an annual video.

Backup & disaster recovery

Immutable, offsite copies with documented recovery objectives and scheduled test restores.

Incident response planning

A written plan with roles, contacts, and decision points agreed in advance.

Security assessments

Vulnerability scanning and a prioritized remediation plan you can work through.

Cyber insurance support

Help completing the technical sections of insurer questionnaires accurately.

Common questions
Are we too small to be a target?

Targeting is largely automated. Attacks are aimed at whatever is exposed and unpatched, and smaller organizations are attractive precisely because their controls are usually weaker. Size is not protection.

Our insurer sent a questionnaire we cannot answer. Can you help?

Yes, and it is worth doing carefully. Those forms are warranties — an inaccurate answer can void a claim at exactly the wrong moment. We will help you answer them truthfully and close the gaps the questions reveal.

Does this guarantee we will not be breached?

No, and be skeptical of anyone who says otherwise. The goal is to make compromise substantially harder, detect it quickly when it happens, and recover without paying anyone.

Next step

Let's talk about cybersecurity.

Tell us what your setup looks like and what has been going wrong. We will tell you what we would do about it, and roughly what it costs.