Cybersecurity

We look for the weak points in your systems before anyone else does, then we help you close them.

Strictly defensive work. We only act on systems you own or for which you hold written authorisation. Every engagement is covered by a signed mandate setting out the exact scope, the testing window and the limits. We carry out no action against third parties.

What you get out of it

A small business doesn't need a bank's security programme. It needs the obvious doors closed.

  • You know where you're exposedA readable report, free of jargon, ranking weaknesses by severity and by effort to fix.
  • Less risk of downtimeA successful attack means days of stopped trading. Prevention costs considerably less than recovery.
  • Customer data protectedA data leak destroys trust and exposes you legally. We reduce that risk at the source.
  • A team that stops clickingMost intrusions start with an email. We train your staff to recognise them.
  • Compliance made easierThe practices we put in place overlap substantially with your data protection obligations.

What we do

All carried out under contract, with your prior authorisation.

Security audit

A review of your website, servers and access, with a prioritised report and a plan to fix what's found.

Vulnerability assessment

Checking your authorised systems for known weaknesses: outdated versions, risky configurations, exposed services.

Website hardening

Patching, configuration hardening, certificates, application firewall and form protection.

Account protection

Two-factor authentication, password management, and a review of access rights and dormant accounts.

Monitoring and maintenance

Uptime tracking, alerts when something looks wrong, and regular application of security patches.

Staff awareness

Short, practical sessions on phishing, passwords and what to do when something looks suspicious.

How an audit runs

A clear framework, from the mandate through to verifying the fixes.

  1. Mandate and scope

    We define in writing what will be tested, when, how, and what is excluded. Nothing starts without your signature.

  2. Assessment

    We examine your authorised systems for risky configurations and known vulnerabilities.

  3. Report

    You receive the findings ranked by severity, explained in plain language, with a recommended fix for each.

  4. Fix and re-test

    We apply the fixes or support your team in doing so, then verify the weaknesses are genuinely closed.

Common questions

Do you do offensive penetration testing?

We test only the systems you explicitly authorise us to test, under contract. We never act on systems belonging to third parties, and we decline any request in that direction.

Could an audit break my website?

The risk is low but not zero. We agree a testing window in advance, confirm a recent backup exists, and stay reachable throughout.

What if we're already under attack?

Contact us and say it's urgent. Depending on the situation we'll point you to the first steps to take and, if the incident goes beyond our scope, to the appropriate authorities.

Are we really a target?

Most attacks aren't aimed at anyone in particular: they sweep the internet automatically looking for vulnerable systems. Being small is not protection.

Let's talk about your project

Thirty minutes is enough to know what's achievable, how long it takes and what it costs.