Services

What we actually do

Security and compliance is the centre of gravity. The rest of this list exists because security work keeps running into it — and because a small business shouldn't need four vendors to fix one problem.

01 / Core

Security & compliance

Programs, evidence and controls that survive an audit — and remediation that closes the gaps rather than documenting them.

  • SOC 2 readiness & audit preparation
  • Security & risk management programs
  • Policy and standards development
  • Gap assessments & control mapping
  • Vulnerability management & scanning cadence
  • Ransomware protection & recovery readiness
  • Patch management strategy & rollout
  • Email filtering & phishing protection
  • Security awareness training & simulations
  • Blue-team hardening & defensive architecture
  • Logging, monitoring & alert tuning
  • Incident response planning & tabletop exercises
  • Vendor & security questionnaire support
  • Cyber insurance questionnaire review
02

Identity, endpoint & cloud

Identity is the perimeter now. This is where most real-world compromise starts, and where the highest-return fixes live.

  • Single sign-on (SSO) design & rollout
  • MFA & conditional access policy
  • Microsoft Intune / MDM deployment
  • Endpoint hardening & compliance baselines
  • Microsoft 365 tenant security review
  • Google Workspace security review
  • Google Cloud Platform configuration & IAM
  • Least-privilege & admin-role cleanup
  • Offboarding & access lifecycle process
  • Device encryption & remote wipe
  • Shared-mailbox & delegation audit
  • Cloud tenant migration & consolidation
03

Infrastructure & continuity

The parts that decide whether a bad day is an inconvenience or an existential event.

  • Network engineering & administration
  • Firewall, VLAN & segmentation design
  • VPN & remote access
  • Backup solution design & restore testing
  • Disaster recovery & continuity planning
  • NAS & storage architecture
  • SFTP setup, hardening & automation
  • SQL Server administration & queries
  • Database reporting & data extracts
  • Physical security camera systems
  • Access control & site security review
  • Audio/video systems consulting
  • Conference room & AV buildouts
04

Automation & applications

Manual processes are a security problem as much as an efficiency one. Fewer hands on the data, fewer places it leaks.

  • AI integration with security guardrails
  • AI tool policy & data-handling review
  • Automated workflow building (Make, Zapier & similar)
  • System-to-system integrations & APIs
  • Custom web application development
  • Internal tools & dashboards
  • Salesforce administration & cleanup
  • Project management software selection & setup
  • File transfer & data pipeline automation
  • Reporting automation
  • Documentation & runbook creation
05

Web & growth

A website is an asset and an attack surface. We treat it as both — and make sure people can actually find it.

  • Website design & build
  • Website security & hosting review
  • Technical SEO audits
  • Search ranking diagnostics
  • Google Business Profile setup & optimisation
  • Local search & listings cleanup
  • Analytics & conversion tracking setup
  • Site performance & Core Web Vitals
  • Domain, DNS & email deliverability (SPF, DKIM, DMARC)
  • Practical marketing & positioning input

Engagement models

Three ways to work together

Most clients start with an assessment, fix the urgent items as a project, then keep us on a light retainer so it doesn't drift back.

Security assessment

Fixed scope · fixed price

A defined review of identity, endpoints, cloud tenants, network, backups and process. You get a prioritised findings list with effort estimates, an executive summary you can hand to leadership, and a remediation plan — not a tool dump.

Project work

Scoped deliverable

One clear outcome: SOC 2 readiness, an Intune or SSO rollout, a backup rebuild, a network re-architecture, a migration, an automation build, a website. Defined start, defined finish, defined handover documentation.

Ongoing advisory

Monthly retainer

The security owner you don't have on payroll. Patch and vulnerability cadence, awareness training, questionnaire and audit support, quarterly posture review, and a person to call when something looks wrong.

Next step

Not sure where your problem sits on this list?

Describe the symptom — a failed questionnaire, a suspicious email, an environment nobody has reviewed in years — and we'll tell you what it is and what it takes to fix.