Cybersecurity
Find the holes before someone else does.
Security work for small and medium businesses, not-for-profits, and registered charities. We come to you, learn how your organisation actually functions, test what can be tested, and leave you with policies you can follow and clear remediations you can action — plus deeper penetration testing for teams building their own software.
Security posture assessment
An on-site review of how your business actually uses technology, where the gaps are, and what to do about them first. Built for the clinic, studio, shop, or charity with no security staff and real obligations.
- Physical walkthrough — doors, desks, screens, badges, waste
- Technology inventory: accounts, devices, cloud services, vendors
- Practices review: passwords, backups, access, offboarding
- Written findings ranked by risk and cost to fix
Policies and procedures
Most small organisations have none, or a template someone downloaded in 2016. We write the short, readable ones your staff will actually follow.
- Acceptable use, password, and access policies
- Backup, retention, and data-handling standards
- Incident response plan and contact tree
- Onboarding and offboarding checklists
Application penetration testing
Manual, scoped testing of web applications, APIs, and the infrastructure behind them — for teams who build or commission their own software.
- Authenticated and unauthenticated testing
- Business-logic and access-control flaws
- Written report with reproduction steps
- Free retest of remediated findings
Software security consulting
Working alongside your developers on the decisions that create or prevent vulnerabilities.
- Architecture and threat-model review
- Code and dependency review
- Secure SDLC and release-gate advice
- Remediation support, not just findings
Phishing and social engineering testing
Controlled campaigns that test how your people respond, not how your firewall does. Every campaign is agreed with you in advance and reported without naming and shaming.
- Email, SMS, and voice phishing campaigns
- Pretexting and in-person social engineering
- Click, credential, and report-rate metrics
- Findings mapped to specific training gaps
Security awareness training
Off-the-shelf modules or training built around your organisation's own tools, sector, and the results of your campaigns.
- Custom or curated course material
- Completion tracked and chased
- Reporting for boards, funders, and insurers
- Recommended next steps after each cycle
How a posture assessment runs.
Two to three weeks end to end for a typical twenty-person organisation. Fixed price, quoted after the scoping call.
Scoping call
Thirty minutes. What you do, how many staff, what you're worried about, what's off limits.
On-site day
A physical walkthrough and interviews with the people who use the systems every day.
Testing
Technical checks on what we agreed to test — network, accounts, devices, and any software you own.
Report and debrief
Findings ranked by risk, a plain-language fix list, and a walkthrough with whoever owns the budget.
No charge
Security consulting is free for not-for-profits and charities.
Not-for-profit organisations and registered charities get our consulting time at no cost — assessments, architecture review, and remediation guidance. Nonprofits hold sensitive data with the smallest budgets; this is the part of the practice we're proudest of.