Cybersecurity foundations

Get the security basics done properly and written down

Most incidents at small and medium-sized businesses exploit missing basics: no MFA, unpatched devices, untested backups, former staff who still have access. We put those controls in place, assign owners and review them on a schedule.

Who this is for

  • Businesses answering their first customer security questionnaire.
  • Owners who suspect former staff or contractors still have access.
  • Teams after a phishing scare or a near miss.
  • Companies that want a practical plan rather than a certificate.

Problems this service solves

Passwords are the only lock
We plan and roll out multi-factor authentication, starting with email, admin and finance accounts.
No one knows who has access
An access and identity review lists every account with privileges and removes the ones that should not exist.
Backups are assumed, not proven
We assess backup coverage and test recovery for your most important data.
No plan for a bad day
A short incident-response plan names who to call, what to preserve and how to communicate.

What is included

Delivered as an assessment followed by an implementation plan, or as ongoing reviews alongside Managed IT.

Assess

  • Small-business assessment structured on the NIST Cybersecurity Framework (CSF) 2.0
  • Access and identity review
  • Backup and recovery assessment
  • Basic vulnerability review of agreed, authorised systems

Implement

  • Multi-factor-authentication rollout
  • Endpoint and patching baseline
  • Email-security configuration (SPF, DKIM, DMARC and filtering)
  • Logging for key systems

Sustain

  • Employee security awareness sessions
  • Practical security policies
  • Incident-response preparation
  • Periodic control reviews

How an engagement runs

  1. Scope and authorisation

    We agree in writing which systems we may review and how, before anything is examined.

  2. Assessment

    Interviews, configuration review and evidence collection across the CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond and Recover.

  3. Findings and roadmap

    A plain-language report with prioritised actions, owners and effort estimates.

  4. Implementation

    We implement the agreed controls ourselves or alongside your team.

  5. Review

    Controls are re-checked on a schedule, with changes reported to you.

Service windows

Assessments and implementation are scheduled work. Incident support is available only where your agreement includes it.

Standard 8×5
Eight contracted hours per business day, five days per week, in a window agreed for your timezone.
Extended 16×5
Two-shift weekday coverage for teams spread across regions or working long days.
Critical Monitoring
Continuous automated monitoring of agreed systems, with a defined Priority-1 on-call response for contracted services.

Your proposal states every window in your own timezone. Outside contracted hours, non-critical requests wait for the next window.

Incident priorities
PriorityDescriptionExample
P1 CriticalA supported business service is unavailable, or a severe security event is active, with no workaround.Production platform down
P2 HighMajor impairment affecting several users; workaround limited.Email unavailable for a department
P3 NormalAn individual issue or non-critical degradation.One user’s application problem
P4 RequestA planned change, advice or a minor inconvenience.New user setup

A response target is how quickly a qualified person starts work on your ticket. A resolution objective is what we aim for. It depends on the cause, on vendors and on access, so it is never a guarantee.

Security and data handling

  • Findings are confidential and shared only with the contacts you nominate.
  • We collect configuration evidence, not your business data. Screenshots are redacted where practical.
  • No intrusive testing is performed without written authorisation, a defined scope and agreed timing.
  • Assessment working files are deleted at the end of the agreed retention period.

Never send passwords, one-time codes, private keys, payment-card details or production secrets through this website or by email. During onboarding we agree a secure method for sharing access, and we use named, revocable accounts wherever the system supports them.

Pricing basis

Assessments are quoted on the number of users, locations and systems in scope. Implementation is quoted from the roadmap, or included in the Secure Managed Workplace plan.

Secure Managed Workplace (ongoing)
Starting from USD 90–150 per user / month

Starting-from prices are indicative and non-binding. A written proposal follows discovery. Unless the proposal says otherwise, prices exclude taxes, third-party licences, cloud consumption, hardware, travel and out-of-scope work.

View pricing

Evidence

We publish client results only with measured baselines and written client approval. References for this service are available on request during discovery.

Ask for a reference

Frequently asked questions

Will this make us compliant with ISO 27001 or GDPR?

No. Our work strengthens the controls those frameworks expect, and our reports can support a later certification or legal review, but we do not certify and we do not give legal compliance opinions.

Do you do penetration tests?

No. Where you need one, we can help you define the scope and work with a qualified testing firm you choose.

What does “NIST CSF 2.0-aligned” mean?

We organise the assessment around the six functions of the NIST Cybersecurity Framework 2.0, so findings map to a recognised structure. It is not an accreditation.

Can you help if we are hacked right now?

If you are a contracted client with incident support, use your emergency route. Otherwise, contact us and say it is an active incident. We will tell you honestly whether we can help or who to call.

Start with the controls that matter most

A foundations assessment shows where you stand on access, MFA, patching, backups and response, in plain language.

Book a Free Consultation