Businesses deserve straight answers about technology.
Steelwise is a technology advisory practice based in Sheffield. We help businesses make smart decisions about security, infrastructure, and AI, backed by over two decades of doing the work, not just advising on it.
Come for a coffee and tell us what's going on with your techServices
You know what your business needs to do. You don't always know what's technically possible, which technology fits, or who's best placed to deliver and maintain it. That's what we're here for.
Security advisory
Honest assessment of where you stand, what actually matters, and what to do next. Cyber Essentials, ISO 27001, posture reviews, incident preparedness, all prioritised by real risk, not fear. We tell you what's enough, not sell you the maximum.
Web and infrastructure advisory
Architecture decisions, platform choices, hosting strategy, reliability, performance. We don't sell hosting or software. We help you choose what's right, whether you're building something new or making sense of what you've already got.
AI advisory
Practical guidance on where AI fits in your business, and where it doesn't. Readiness assessments, risk and governance, separating genuine value from hype. Not every business needs AI right now, and we'll say so.
Coordinated delivery
When you need more than advice, we coordinate delivery through a network of specialists, not tied to any vendor or product. One relationship, one person accountable, and someone joining up security, infrastructure, and AI so you don't have to manage it all yourself.
How we work
We don't start with a sales pitch. We start with a conversation.
A coffee and a conversation
Free, face to face, no strings. Tell us what's going on with your tech, what's keeping you up at night, or what you're trying to figure out. If we can help, we'll say so. If we can't, we'll point you to someone who can.
A first piece of work
A defined engagement: a security review, an architecture assessment, a clear deliverable. Scoped tightly to what you actually need and quoted at a fixed price, agreed in writing before anything starts. Designed to demonstrate value before asking for commitment.
An ongoing relationship
For most clients, the real value is having someone to call. We become your technology person, across security, infrastructure, and AI. When you need deeper specialist work, we coordinate it through our network. One relationship, no vendor lock-in, and someone who knows your business.
Recent filings
Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.
-
If you self-host GitLab, patch it today: this one is CVSS 10
· Security
CVE-2026-85706 lets an attacker read arbitrary files from a self-hosted GitLab server without logging in. It's rated CVSS 10, the maximum possible severity, and it's already being probed in the wild days after GitLab shipped the fix.
-
When the request looks official, check anyway
· Security
Revolut handed over customer passports, selfies, and financial records after a fraudster emailed from a genuine government domain. The email being real did not make the request real. Here is what to ask about your own process.
-
Your policy is why they went around you
· AI Security
NCSC says 71% of employees have used AI tools their employer never approved, and points at an uncomfortable cause: when security policy cannot meet what the job actually needs, staff route around it. The fix is not a firmer ban.
-
Your supplier's docs now tell your AI what to install
· AI Security
Researchers scanned 6,214 corporate domains and found 120 published documentation files pointing at software packages nobody owned. They registered some. A Fortune 500 company's coding agent installed one within the hour.
-
Work out the number before your insurer does
· Security Commentary
Only 22% of UK business leaders think their insurance would cover an attack, and one in five have never worked out what an attack would cost them. The second number is why the first one is so low.
About
Steelwise exists because most businesses can't get a straight answer about technology. The security industry defaults to jargon and fear. MSPs want to sell you a contract. Consultancies send juniors. What's missing is a practice that's experienced, broad, honest, and genuinely interested in your specific problem.
We're built on a partnership model: a small, trusted team backed by a network of specialists. You always get senior people who've actually done the work. No juniors, no handoffs, no learning on your time.
Our founder, Carl, has spent over 22 years working across security, web infrastructure, data, and AI. He's served as CTO, CISO, and DPO for a web hosting company in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.
That breadth is unusual. Most advisors specialise in one lane. We deal with all of it, because that's what running a real technology business actually requires.
We're not tied to any product or vendor. We don't take commissions, and everything we deliver is yours. If you need a second opinion on what your IT provider is telling you, that's exactly the kind of conversation we're here for.
More about how we work, or read about Carl Heaton, who founded the practice.