Skip to content
RO

Find out what is actually exposed

Somebody has asked whether you are secure. An insurer, a customer doing due diligence, or your own board. The honest answer is usually that nobody has checked, and the tempting answer is a scan report full of severity ratings that nobody can act on.

What I do is read-only. Nothing is changed on your machines without you saying so, every finding comes with the evidence it was based on, and the report is written so your existing IT provider can act on it without me.

What you get

  • A read-only audit of your Windows estate against 17 checks, nothing changed without your say-so
  • Every finding rated by severity with the evidence it was based on, so you can verify it yourself
  • Findings mapped to the relevant Cyber Essentials control if you are preparing for certification
  • A plain-English report your IT provider can act on, and a re-audit that shows what actually got fixed

Who it's for

Businesses that have been asked by an insurer, a customer or their own board whether they are secure, and want a better answer than a shrug.

How it's priced

Fixed price per audit, based on the number of machines. Re-audits at a lower rate. No retainer required and no obligation to have me do the remediation.

Case study

Systems I manage

193,000 failed logins, and three doors I had left open

The problem. A production server carrying live sites and internal services. No breach, no incident, nothing wrong on the surface. I went looking anyway, because nobody had actually checked.

What I did.

  • Read a month of authentication logs properly instead of glancing at them: roughly 193,000 failed password attempts, continuous and automated
  • Found password authentication and root login still enabled, a database running without authentication, and an application port published straight to the internet
  • Closed all three, then verified from outside rather than by reading the config back

Outcome. Failed password attempts went from 66,760 in a week to zero, and have stayed there. The bots still knock; there is no longer anything to knock on.

The full write-up, with the numbers →

Questions people ask

Will this disrupt anything?
No. The audit only reads. It queries Windows for its own configuration, checks what is listening on the network, and writes nothing to your machines. It can run during working hours.
Do I have to use you to fix what you find?
No, and I would rather you did not feel obliged. The report is written for whoever already looks after your IT. If you want me to do the remediation that is a separate conversation and a separate price.
Can you certify us for Cyber Essentials?
No, and neither can anyone who is not an IASME-licensed certification body. What I can do is map the findings to the relevant Cyber Essentials controls so you know where you stand before you pay for an assessment. Going in unprepared is how people fail it twice.
How do I know the findings are real?
Every one carries the evidence. If the report says SMBv1 is enabled, it shows you the registry value it read. You can verify any finding yourself, which is the point.

Talk about your project

Tell me what you're trying to do and roughly what it's worth to you. The first call is free, half an hour, and you get a straight answer about whether I'm the right person.

The other two things I do