Security advisory
How do you know what actually matters? Not the list of everything that could go wrong, but the few things worth doing something about first.
The problem this solves
Most businesses have had a security conversation that went one of two ways. Either nothing much was said, because nobody wanted to worry you. Or you were handed a long list of everything that could theoretically go wrong, with a quote attached to fixing all of it.
Neither answers the question you actually have: of everything on that list, which parts matter for a business your size, doing what you do, with the systems you already run? That is the question we answer.
Why the ranking is the whole job
Severity is not the same as risk.
A flaw with an alarming score that nobody is exploiting, on a system nobody outside your office can reach, is not your problem this month. A dull misconfiguration on the account that controls everything else is.
This is not a hunch. We analysed 248,176 public vulnerability records against the catalogue of flaws confirmed as used in real attacks, and found that 97% of critical-rated vulnerabilities are never exploited by anyone. Sorting by severity hands a small business tens of thousands of things to fix, almost all of which will never be used against them. There is a better rule, and it is the same principle applied to everything else: work out what is actually reachable, actually being used, and actually load-bearing for your business, then start there.
So you get a short list in that order, with the reasoning shown, so you can disagree where you know your business better than we do.
What we help with
- Posture reviews. Where you stand across accounts, access, backups, suppliers, and the systems your business would stop without. What is genuinely exposed, and what is fine despite looking untidy.
- Cyber Essentials and ISO 27001. Whether you need certification at all, which one fits, what it will really take, and how to get there without a year of paperwork. Sometimes the answer is that you are not ready yet, and there is a cheaper thing to do first.
- Incident preparedness. What happens on the day it goes wrong. Who is called, what gets turned off, how you keep operating, and whether your backups would actually restore. Most plans have never been tested.
- Supplier and third-party risk. The systems you depend on but do not run. Which suppliers could take you offline, what your contracts say about it, and what to ask them. Increasingly your customers are asking you the same questions.
- A second opinion. If your IT provider or MSP has told you something and you want to know whether it holds up, that is a legitimate piece of work and we are glad to do it.
Where we are useful, and where we are not
This is for smaller and mid-sized UK businesses that depend on their technology but do not have a full-time security person, and would rather not hire one yet. Often there is already an IT provider in place, and the question is whether what they are doing is right.
If you already have a security team and you want penetration testing or a red team exercise, we are not the right first call. We can point you to people who are.
What you get
A written assessment in plain English, findings ranked, the reasoning for the ranking shown, and a recommended order of work. It is yours: no watermark, no portal, no licence that expires. If you take it to another supplier to implement, that is a perfectly good outcome.
We also tell you what to ignore. A review that only ever adds to your to-do list is not much use.
Scope and price
The first piece of work is tightly scoped and fixed price, agreed in writing before it starts. You know the deliverable and the cost up front. After that, if it makes sense to keep working together, the arrangement can be whatever the work requires.
We take no commissions and resell nothing, so no recommendation we make earns us a margin.