Who it is for

  • Businesses that hold customer or financial information.
  • Businesses asked about security by a customer, partner or insurer.
  • Businesses that have had a security scare and want to check for other weak points.

What we check

Identity and access

  • Password practices and multi-factor authentication
  • Admin accounts and who holds them
  • Shared and former-staff accounts

Devices

  • Update and patch status
  • Endpoint protection
  • Disk encryption on laptops

Email

  • Protection against phishing and spoofing
  • Mailbox forwarding and sharing rules

Data

  • Who can access sensitive files
  • External sharing of documents

People and process

  • What staff are expected to do when something looks wrong
  • Whether there is a plan for a security incident

What you get

  • A written report with prioritised findings.
  • Plain-English explanations of each risk.
  • Practical recommendations you can act on or pass to your IT provider.
  • A list of security gaps ranked by risk to your business.
  • A walkthrough of the report, with time for your questions.

Signs it is time for a security posture review

  • You do not know who has admin access.
  • Staff share passwords or accounts.
  • You have been asked to answer a security questionnaire.
  • Someone in the business has clicked a suspicious link.

Request a security posture review

Tell us about your business and we will reply to agree scope.

Request an audit