Find out what is actually exposed
Somebody has asked whether you are secure. An insurer, a customer doing due diligence, or your own board. The honest answer is usually that nobody has checked, and the tempting answer is a scan report full of severity ratings that nobody can act on.
What I do is read-only. Nothing is changed on your machines without you saying so, every finding comes with the evidence it was based on, and the report is written so your existing IT provider can act on it without me.
What you get
- A read-only audit of your Windows estate against 17 checks, nothing changed without your say-so
- Every finding rated by severity with the evidence it was based on, so you can verify it yourself
- Findings mapped to the relevant Cyber Essentials control if you are preparing for certification
- A plain-English report your IT provider can act on, and a re-audit that shows what actually got fixed
Who it's for
Businesses that have been asked by an insurer, a customer or their own board whether they are secure, and want a better answer than a shrug.
How it's priced
Fixed price per audit, based on the number of machines. Re-audits at a lower rate. No retainer required and no obligation to have me do the remediation.
Case study
Systems I manage
193,000 failed logins, and three doors I had left open
The problem. A production server carrying live sites and internal services. No breach, no incident, nothing wrong on the surface. I went looking anyway, because nobody had actually checked.
What I did.
- Read a month of authentication logs properly instead of glancing at them: roughly 193,000 failed password attempts, continuous and automated
- Found password authentication and root login still enabled, a database running without authentication, and an application port published straight to the internet
- Closed all three, then verified from outside rather than by reading the config back
Outcome. Failed password attempts went from 66,760 in a week to zero, and have stayed there. The bots still knock; there is no longer anything to knock on.
Questions people ask
- Will this disrupt anything?
- No. The audit only reads. It queries Windows for its own configuration, checks what is listening on the network, and writes nothing to your machines. It can run during working hours.
- Do I have to use you to fix what you find?
- No, and I would rather you did not feel obliged. The report is written for whoever already looks after your IT. If you want me to do the remediation that is a separate conversation and a separate price.
- Can you certify us for Cyber Essentials?
- No, and neither can anyone who is not an IASME-licensed certification body. What I can do is map the findings to the relevant Cyber Essentials controls so you know where you stand before you pay for an assessment. Going in unprepared is how people fail it twice.
- How do I know the findings are real?
- Every one carries the evidence. If the report says SMBv1 is enabled, it shows you the registry value it read. You can verify any finding yourself, which is the point.
Talk about your project
Tell me what you're trying to do and roughly what it's worth to you. The first call is free, half an hour, and you get a straight answer about whether I'm the right person.
That's with me.
I read these myself and reply within a working day, usually sooner. If it's urgent, ring 07853 610930.
The other two things I do
Software builds
Web apps, client portals and internal tools. Built, deployed, and running on infrastructure I look after.
Servers and infrastructure
Provisioning, hardening and keeping Linux servers running. Including being the person who gets the call.
Website care plans
Hosting, security updates, tested backups and your monthly changes. For any small business site, whether I wrote it or not.
