Businesses deserve straight answers about technology.
Steelwise is a technology advisory practice based in Sheffield. We help businesses make smart decisions about security, infrastructure, and AI, backed by over two decades of doing the work, not just advising on it.
Come for a coffee and tell us what's going on with your techServices
You know what your business needs to do. You don't always know what's technically possible, which technology fits, or who's best placed to deliver and maintain it. That's what we're here for.
Security advisory
Honest assessment of where you stand, what actually matters, and what to do next. Cyber Essentials, ISO 27001, posture reviews, incident preparedness, all prioritised by real risk, not fear. We tell you what's enough, not sell you the maximum.
Web and infrastructure advisory
Architecture decisions, platform choices, hosting strategy, reliability, performance. We don't sell hosting or software. We help you choose what's right, whether you're building something new or making sense of what you've already got.
AI advisory
Practical guidance on where AI fits in your business, and where it doesn't. Readiness assessments, risk and governance, separating genuine value from hype. Not every business needs AI right now, and we'll say so.
Coordinated delivery
When you need more than advice, we coordinate delivery through a network of specialists, not tied to any vendor or product. One relationship, one person accountable, and someone joining up security, infrastructure, and AI so you don't have to manage it all yourself.
How we work
We don't start with a sales pitch. We start with a conversation.
A coffee and a conversation
Free, face to face, no strings. Tell us what's going on with your tech, what's keeping you up at night, or what you're trying to figure out. If we can help, we'll say so. If we can't, we'll point you to someone who can.
A first piece of work
A defined engagement: a security review, an architecture assessment, a clear deliverable. Scoped tightly to what you actually need and quoted at a fixed price, agreed in writing before anything starts. Designed to demonstrate value before asking for commitment.
An ongoing relationship
For most clients, the real value is having someone to call. We become your technology person, across security, infrastructure, and AI. When you need deeper specialist work, we coordinate it through our network. One relationship, no vendor lock-in, and someone who knows your business.
Recent filings
Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.
-
Your MFA is on, and it did not apply
· Security
Attackers compromised 78 Microsoft accounts across 64 organisations by replaying old passwords through a legacy sign-in route that never asks for a second factor. Most of those businesses had multi-factor authentication switched on. It just did not cover the door the attacker used.
-
The passkey the attacker added to your account
· Security
When an account is compromised, the standard response is to change the password and sign out every session. A phishing kit on sale for $10,000 is built to survive exactly that, by quietly registering the attacker's own passkey on the account. Passkeys are still the right answer. Your incident checklist needs one more line.
-
The safety number that was zero until someone tried
· AI Security Commentary
A commissioned evaluation put the attack success rate against Claude Code's Auto Mode at 0.00%. An independent researcher then hijacked it about 60 to 80% of the time. Both numbers are probably honest, and the gap between them is the thing worth understanding before you let an AI agent near your systems.
-
The AI Act questions you can now ask your supplier
· AI Security Commentary
Brussels has started enforcing the EU AI Act, sending its first formal information requests to the companies behind the big AI models. Almost nothing lands on a UK SME directly. What changes is what your suppliers must now be able to evidence, and therefore what you can reasonably ask them.
-
The AWS key you leaked years ago probably still works
· Security Infrastructure
Researchers verified 64,000 AWS access keys found lying around the public internet. Of the ones they could fully test, 88% still worked, some more than five years after they leaked, and hundreds carried full admin rights. The lesson is not that keys leak. It is that almost nobody turns off the ones that did.
About
Steelwise exists because most businesses can't get a straight answer about technology. The security industry defaults to jargon and fear. MSPs want to sell you a contract. Consultancies send juniors. What's missing is a practice that's experienced, broad, honest, and genuinely interested in your specific problem.
We're built on a partnership model: a small, trusted team backed by a network of specialists. You always get senior people who've actually done the work. No juniors, no handoffs, no learning on your time.
Our founder, Carl, has spent over 22 years working across security, web infrastructure, data, and AI. He's served as CTO, CISO, and DPO for a web hosting company in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.
That breadth is unusual. Most advisors specialise in one lane. We deal with all of it, because that's what running a real technology business actually requires.
We're not tied to any product or vendor. We don't take commissions, and everything we deliver is yours. If you need a second opinion on what your IT provider is telling you, that's exactly the kind of conversation we're here for.
More about how we work, or read about Carl Heaton, who founded the practice.