Direct answer: Every project requires a named sponsor, written authorisation, permitted systems, time windows, escalation contacts and an agreed report format. Work outside our own expertise is only offered with suitable specialists.
Services
Security coordination
Organise owners, suppliers, timelines, evidence and actions in one accountable workflow.
Incident documentation
Build a structured timeline of affected accounts, indicators, decisions and communication.
Email & domain
Review MFA, roles, DNS, SPF, DKIM, DMARC, recovery and administration paths.
Web exposure
Review publicly visible misconfiguration and web risk within the agreed passive or authorised scope.
Recovery readiness
Test backups, emergency contacts, ownership evidence and account recovery processes organisationally.
Management report
Translate risks, priorities, owners and next steps into a decision-ready report.
How we work
Qualify the organisation and hold a confidential initial discussion
Agree NDA, owners and written authorisation
Define scope, methods, windows and emergency contacts
Deliver through the appropriate specialist roles
Provide management report, evidence and improvement plan
Fair delivery guarantee
We guarantee the contractually defined execution and documentation. No responsible provider can promise prevention of every attack or discovery of every weakness.
Frequently asked questions
Do you offer penetration testing?
Only when the scope, authorisation and a suitably qualified technical specialist are explicitly named in the offer.
Why only larger organisations?
Security projects need governance, contacts, approvals and budget. Smaller businesses are supported primarily with basic hardening, accounts, domains and recovery.
Is 24/7 incident response available?
No. We provide project-based coordination and agreed response times, not a continuously staffed security operations centre.
Can you guarantee absolute security?
No. The goal is measurable risk reduction, better detection, reliable recovery and clear accountability.