Security reviews
A structured assessment of identity, cloud configuration, endpoints, email and network exposure, mapped against how the business actually operates rather than a generic template.
Cyber Security
Independent security review, architecture and remediation for organisations that carry real technology risk but have no in-house security function.
The problem
“How secure are we, and what would actually happen if something went wrong?”
The reason is rarely negligence. Systems grow over years. Staff join and leave. A migration is done in a hurry. A supplier is given access for a project and never removed. Each decision was reasonable at the time, and no single one created the exposure — but the accumulation did.
Meanwhile the questions get harder. Insurers ask for specifics. Clients send security questionnaires. Regulators expect evidence. And the honest internal answer is often that nobody has looked properly at the whole picture for several years.
That is the gap we fill: an independent, senior look at what you have, what it exposes you to, and what is worth doing about it — followed by the work to fix it.
Engagement at a glance
What we cover
Not every engagement covers all of these — scope follows risk. But this is the ground a full cyber security review examines.
A structured assessment of identity, cloud configuration, endpoints, email and network exposure, mapped against how the business actually operates rather than a generic template.
Internal and external scanning, patch and version review, and — importantly — triage. You get the handful of findings that matter, not a 400-page tool export.
How systems connect, where trust boundaries sit, and which paths an attacker would realistically take. Design work for new systems, and correction for existing ones.
Tenant configuration, admin roles, sharing behaviour, mailbox rules and audit settings reviewed and corrected. Usually the highest-value place to start.
Entra ID configuration, group and licence structure, privileged role assignment, guest access, and a joiner/mover/leaver process that is actually followed.
MFA coverage checked properly — including service accounts, legacy protocols and the exclusions that quietly accumulate — and strengthened against prompt-bombing and token theft.
Device compliance, patching, disk encryption, local administrator rights, and whether your detection tooling is actually configured to detect and respond.
Who can reach what, across SharePoint, OneDrive, Teams and file shares. Over-broad access is the single most common finding and the most consequential during an incident.
SPF, DKIM and DMARC, anti-impersonation controls, external sender handling, and protection against the invoice-redirection fraud that affects SMEs disproportionately.
What is genuinely protected, including Microsoft 365 data, how long retention lasts, and whether a restore has ever been performed rather than assumed.
Which systems the business cannot operate without, how quickly each could be restored, and what the gap is between that and what the business expects.
Whether the events that matter are being recorded, retained long enough to investigate an incident, and seen by anyone.
A plan people can follow under pressure: who decides, who communicates, who to call, and what to do in the first hour.
Suppliers, integrations and applications with access to your data or tenant — reviewed, documented, and reduced where the access is no longer justified.
Microsoft 365 is where most SME risk concentrates, so it usually gets the deepest attention. If that is your immediate concern, our Microsoft 365 security review covers it as a standalone engagement.
Outcomes
A report that sits in a shared drive has not reduced any risk. Engagements are structured so that the highest-value findings are implemented before the engagement closes, and the rest have an owner and a date.
Process
Four stages. You can stop after any of them, and you will still have something useful.
What you have, what concerns you, what has changed recently, and what constraints exist. Usually under an hour, at no cost.
Read-only review of configuration, identity, endpoints and cloud services, plus interviews with the people who run them day to day.
A written report in business language, with a technical appendix, ranked by real exposure rather than tool severity scores.
We implement the agreed changes — or work alongside your IT provider while they do — and document what changed and why.
Positioning
We are not trying to take over your IT. In most engagements, we never touch the help desk at all.
Managed service providers and internal IT teams are measured on keeping things running: tickets closed, systems available, users unblocked. That is demanding, valuable work, and it is a genuinely different job from deciding what your security architecture should be, judging whether a supplier's access is justified, or designing how an AI system should reach your data.
Bringing in independent advice is not a criticism of your provider. It is the normal way organisations without a CISO get a senior second opinion — and good providers tend to welcome it, because it gives them a mandate and a prioritised plan instead of a vague instruction to “improve security”.
Reassurance
Assessment work is done with the least access that will do the job, using named accounts with MFA, and read-only permissions wherever the task allows. Administrative access is time-limited and removed when the engagement ends.
Findings are confidential. Client names are not published, and case studies on this site are anonymised as a matter of policy. Where an assessment produces evidence that needs careful handling — credentials found in a public repository, for example — we agree how it will be stored and destroyed before we start.
If you need a signed non-disclosure agreement in place before a scoping conversation, that is entirely reasonable and we will sign yours.
FAQ
Frequently, yes. Support providers are measured on availability and response times, not on reducing risk. Security review, architecture and remediation planning are a different discipline and usually sit outside a support contract. We work alongside your provider rather than replacing them.
For a typical SME of 20 to 200 staff, assessment and reporting usually take two to three weeks from access being granted. Remediation length depends entirely on what is found and how much can be changed without disrupting people.
Assessment work is read-only and carried out during normal hours without service impact. Any change that could affect users — MFA enforcement or Conditional Access, for example — is planned, communicated and usually piloted with a small group first.
We help you meet the underlying technical requirements and answer questionnaires accurately, which is the part most organisations struggle with. We are not a certification body and do not issue certificates ourselves.
We tell you immediately rather than saving it for the report, and we help you deal with it. If there is evidence of an active compromise, containment takes priority over completing the assessment.
Yes. We are based in Dorset and work on site across the South West, but the majority of security assessment and remediation work is delivered remotely for clients throughout the UK.
A scoping conversation costs nothing and takes under an hour. If there is no worthwhile work to do, we will tell you that.