Cyber Security

Cyber Security Consultancy

Independent security review, architecture and remediation for organisations that carry real technology risk but have no in-house security function.

The problem

Most SMEs cannot answer a simple question with confidence

“How secure are we, and what would actually happen if something went wrong?”

The reason is rarely negligence. Systems grow over years. Staff join and leave. A migration is done in a hurry. A supplier is given access for a project and never removed. Each decision was reasonable at the time, and no single one created the exposure — but the accumulation did.

Meanwhile the questions get harder. Insurers ask for specifics. Clients send security questionnaires. Regulators expect evidence. And the honest internal answer is often that nobody has looked properly at the whole picture for several years.

That is the gap we fill: an independent, senior look at what you have, what it exposes you to, and what is worth doing about it — followed by the work to fix it.

Engagement at a glance

Typical client
20–500 staff, established, no dedicated security team
Starting point
Free scoping conversation, no obligation
Assessment
Read-only, no service disruption
Deliverable
Business-language report plus technical appendix
Then what
We implement, or support your IT provider to
Independence
No resale, no vendor commission

What we cover

Fourteen areas, reviewed against how your business runs

Not every engagement covers all of these — scope follows risk. But this is the ground a full cyber security review examines.

Security reviews

A structured assessment of identity, cloud configuration, endpoints, email and network exposure, mapped against how the business actually operates rather than a generic template.

Vulnerability assessment

Internal and external scanning, patch and version review, and — importantly — triage. You get the handful of findings that matter, not a 400-page tool export.

Security architecture

How systems connect, where trust boundaries sit, and which paths an attacker would realistically take. Design work for new systems, and correction for existing ones.

Microsoft 365 security

Tenant configuration, admin roles, sharing behaviour, mailbox rules and audit settings reviewed and corrected. Usually the highest-value place to start.

Identity and access

Entra ID configuration, group and licence structure, privileged role assignment, guest access, and a joiner/mover/leaver process that is actually followed.

Multi-factor authentication

MFA coverage checked properly — including service accounts, legacy protocols and the exclusions that quietly accumulate — and strengthened against prompt-bombing and token theft.

Endpoint protection

Device compliance, patching, disk encryption, local administrator rights, and whether your detection tooling is actually configured to detect and respond.

Permissions and data access

Who can reach what, across SharePoint, OneDrive, Teams and file shares. Over-broad access is the single most common finding and the most consequential during an incident.

Email security

SPF, DKIM and DMARC, anti-impersonation controls, external sender handling, and protection against the invoice-redirection fraud that affects SMEs disproportionately.

Backup

What is genuinely protected, including Microsoft 365 data, how long retention lasts, and whether a restore has ever been performed rather than assumed.

Resilience

Which systems the business cannot operate without, how quickly each could be restored, and what the gap is between that and what the business expects.

Monitoring and logging

Whether the events that matter are being recorded, retained long enough to investigate an incident, and seen by anyone.

Incident preparedness

A plan people can follow under pressure: who decides, who communicates, who to call, and what to do in the first hour.

Third-party risk

Suppliers, integrations and applications with access to your data or tenant — reviewed, documented, and reduced where the access is no longer justified.

Microsoft 365 is where most SME risk concentrates, so it usually gets the deepest attention. If that is your immediate concern, our Microsoft 365 security review covers it as a standalone engagement.

Outcomes

What you are left with

  • A clear, evidenced statement of your current security position.
  • A prioritised remediation plan with effort and business impact attached to each item.
  • The high-value fixes implemented, not just recommended.
  • Documentation your IT provider or internal team can maintain.
  • A defensible answer for insurers, clients and tender questionnaires.
  • A realistic view of what would happen in an incident, and what to do about it.

We measure success by what changed

A report that sits in a shared drive has not reduced any risk. Engagements are structured so that the highest-value findings are implemented before the engagement closes, and the rest have an owner and a date.

Process

How a security engagement runs

Four stages. You can stop after any of them, and you will still have something useful.

  1. 01

    Scoping conversation

    What you have, what concerns you, what has changed recently, and what constraints exist. Usually under an hour, at no cost.

  2. 02

    Assessment

    Read-only review of configuration, identity, endpoints and cloud services, plus interviews with the people who run them day to day.

  3. 03

    Findings and priorities

    A written report in business language, with a technical appendix, ranked by real exposure rather than tool severity scores.

  4. 04

    Remediation and handover

    We implement the agreed changes — or work alongside your IT provider while they do — and document what changed and why.

Positioning

Not another IT support contract

We are not trying to take over your IT. In most engagements, we never touch the help desk at all.

Managed service providers and internal IT teams are measured on keeping things running: tickets closed, systems available, users unblocked. That is demanding, valuable work, and it is a genuinely different job from deciding what your security architecture should be, judging whether a supplier's access is justified, or designing how an AI system should reach your data.

Bringing in independent advice is not a criticism of your provider. It is the normal way organisations without a CISO get a senior second opinion — and good providers tend to welcome it, because it gives them a mandate and a prioritised plan instead of a vague instruction to “improve security”.

What we do

  • Assess risk and set technical direction
  • Design and implement security changes
  • Review third-party and supplier access
  • Deploy AI and automation securely
  • Provide independent advice on major decisions
  • Document and hand over

What we do not do

  • Day-to-day user support or a help desk
  • Hardware supply or software resale
  • Licence brokerage and renewals
  • Long tie-in contracts as a condition of advice
  • Recommend products we have a commercial interest in

Reassurance

How we handle access and information

Assessment work is done with the least access that will do the job, using named accounts with MFA, and read-only permissions wherever the task allows. Administrative access is time-limited and removed when the engagement ends.

Findings are confidential. Client names are not published, and case studies on this site are anonymised as a matter of policy. Where an assessment produces evidence that needs careful handling — credentials found in a public repository, for example — we agree how it will be stored and destroyed before we start.

If you need a signed non-disclosure agreement in place before a scoping conversation, that is entirely reasonable and we will sign yours.

FAQ

Cyber security consultancy: common questions

Do we need a cyber security consultant if we already have an IT provider?

Frequently, yes. Support providers are measured on availability and response times, not on reducing risk. Security review, architecture and remediation planning are a different discipline and usually sit outside a support contract. We work alongside your provider rather than replacing them.

How long does a security review take?

For a typical SME of 20 to 200 staff, assessment and reporting usually take two to three weeks from access being granted. Remediation length depends entirely on what is found and how much can be changed without disrupting people.

Will the assessment disrupt our systems?

Assessment work is read-only and carried out during normal hours without service impact. Any change that could affect users — MFA enforcement or Conditional Access, for example — is planned, communicated and usually piloted with a small group first.

Do you help with Cyber Essentials or insurance questionnaires?

We help you meet the underlying technical requirements and answer questionnaires accurately, which is the part most organisations struggle with. We are not a certification body and do not issue certificates ourselves.

What if the review finds something serious?

We tell you immediately rather than saving it for the report, and we help you deal with it. If there is evidence of an active compromise, containment takes priority over completing the assessment.

Do you work with organisations outside Dorset?

Yes. We are based in Dorset and work on site across the South West, but the majority of security assessment and remediation work is delivered remotely for clients throughout the UK.

Find out where you actually stand.

A scoping conversation costs nothing and takes under an hour. If there is no worthwhile work to do, we will tell you that.