Security work usually arrives in pieces. A client makes Cyber Essentials a condition of the contract, an insurer asks whether anyone has tested the network, a phishing email gets through and training suddenly matters. Handled one at a time, each becomes a project with a start and an end, and the controls drift once the certificate is filed. Run as one service they become a state you stay in, kept there by the same Sheffield desk that answers the phone when a laptop will not start.
Cyber Essentials certified. ISO 27001 aligned. Microsoft Cloud Solutions Provider. Registered with the ICO under ZC071809 and registered with Ofcom.
Certification, testing, training
Controls that are still in place a year later
What is included
- Cyber Essentials and Cyber Essentials Plus, gap review to certificate
- Penetration testing, scoped to the risks you actually carry
- Security awareness training and simulated phishing
- Endpoint protection and monitoring that a person reviews
- Access reviews, logging and evidence kept between audits
- Annual recertification managed rather than restarted
What changes
Security stops being a series of projects
Certification, testing and training run on a schedule instead of arriving as separate emergencies, each one needing a quote and a start date.
The evidence exists before anyone asks
Security questionnaires take a week because nobody was collecting anything until the questionnaire arrived. Logs, access reviews and configuration records are gathered as you go.
One team holds all of it
The people who certify the controls are the people who run them day to day, so nothing sits in the gap between two suppliers blaming each other.
What each of these actually involves
Cyber Essentials
Five controls — firewalls, secure configuration, user access control, malware protection and security update management. The base certification is a self-assessment you sign. Plus adds a hands-on audit by an independent assessor. We put right whatever would fail before anything is submitted. More on certification.
Penetration testing
Specialist testers attempting to get in, on your terms and within an agreed scope — external systems, the internal network, web applications, or a combination. What comes back is ranked by severity, in plain English, and the findings then get fixed rather than filed. More on testing.
Awareness training
Short sessions and simulated phishing, run through the year rather than once at induction. The measure that matters is whether people report a suspicious message, not whether everybody passed a quiz in January. More on training.
What managed security includes
Month to month: monitoring and endpoint detection that a person actually reviews, vulnerability reporting, access reviews that find the leftover permissions, and an evidence pack you can hand to an auditor or insurer. An alert landing in an unwatched mailbox is not a control. More on compliance.
What it costs
Support on its own is £19.99 per user, per month, and a fully managed endpoint is £39.99. There is no onboarding fee and no minimum head count, and the contract runs twelve months with a sixty day guarantee. The full numbers are published rather than held back for a quote.
Who this is for
Written for the sectors that have to prove it
Security work is usually bought because somebody outside the business asked for evidence — a client, an insurer, an auditor or a tender. What that evidence has to look like depends on the sector you are in, and so does what happens when it is missing.
Method
How we work
Assess
Document what exists, including the parts nobody wants to discuss.
Standardise
Remove the variation that causes most incidents.
Secure
Apply controls and prove they are working.
Operate
Run it day to day against agreed measures.
Improve
Review quarterly with real data, not a slide.
Then round again — reviewed quarterly
Questions
Questions we get asked about security work
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The same five controls, assessed two different ways. Cyber Essentials is a self-assessment questionnaire you complete and sign off. Cyber Essentials Plus adds a hands-on technical audit, where an assessor tests a sample of your devices rather than taking the answers on trust. More client contracts and tenders now ask for Plus specifically.
Is your service desk in the UK?
Yes. It is UK based, and you speak to the people who look after your systems rather than a queue that hands you on.
Do we have to use Microsoft?
No. We manage both Microsoft 365 and Google Workspace.
