Sound Familiar
Almost nobody arrives asking for a service by name. They arrive with one of these — so each one below says what we would actually do about it.
We're on Microsoft 365, but nobody set it up properly and we don't know what's exposed.
A security assessment against a defined baseline, then remediation in the order that reduces risk fastest.
Security Assessment and RemediationA customer, insurer or tender has asked us security questions we can't answer.
A gap analysis against the scheme's requirements, and the evidence to answer the questionnaire honestly.
Cyber Essentials ReadinessWe're moving off Google Workspace, an old mail system, or another provider's tenant.
Tenant design and a staged migration — data copied, never cut off, with the old platform live until you are satisfied.
Microsoft 365 MigrationWe've acquired a business and now have two of everything.
Tenant-to-tenant consolidation — identity, mail, files, Teams and licensing landed together, then the duplicate decommissioned.
Tenant ConsolidationWe're opening a second site, or half the team has gone permanently remote.
Connectivity ordered against carrier lead times, the network built and tested, and secure remote access rolled out.
Networks and ConnectivityWe spend a lot on IT and can't tell whether it's the right amount.
A supplier and contract register, a budget forecast, and a costed roadmap separating the necessary from the optional.
Strategy and RoadmapOur internal IT person needs specialist support for one project.
A scoped engagement alongside your own person, against a written statement of work with a defined end.
How an Engagement RunsWe need Cyber Essentials and don't know how far off we are.
A gap analysis against the current requirements and the remediation to be ready. We prepare you; we are not the certifying body.
Cyber Essentials ReadinessThe Work
Nine kinds of engagement. Each ends with something written down that you own.
A current-state assessment, a prioritised risk register and a costed 12 to 24 month plan you can take to a board.
StrategyTenant design, mail and data migration, tenant-to-tenant consolidation, and decommissioning whatever it replaces.
Microsoft 365Identity, device, email and data protection reviewed against a defined baseline — then fixed in the order that reduces risk fastest.
A managed device standard built once — enrolment, configuration, encryption, patching and application delivery — so every laptop starts the same.
A gap analysis against the scheme's current requirements and the remediation needed to be ready for assessment. We prepare you; we are not the certifying body.
Replacing legacy remote access with something built for how the team actually works now, rather than how it worked in 2019.
ConnectivityHost refresh and consolidation, virtual infrastructure design and migration, and moving workloads off ageing hardware. Including the single old server nobody wants to touch.
Deciding what must be recoverable and over what period — then proving it can be, rather than assuming it.
The environment record most businesses discover they never had — and the reason the next change is cheaper than the last one.
Pricing
Which one applies depends on how knowable the work is at the start. We will tell you which, and why.
For well-defined work — assessments, migrations and defined remediation packages. One price, agreed up front, with the exclusions written down so there are no arguments later.
Where the scope genuinely cannot be known in advance — investigation and diagnostic work, mostly. Always with an agreed cap and reporting against it, so an open-ended engagement is not an open-ended invoice.
Ongoing strategy input for businesses that want a technical voice in the room a few times a quarter. Typically taken alongside a support agreement.
Assessments and reports are delivered whether or not you proceed with the remediation, and they are written so another provider can act on them. We would rather you had a good decision than a dependency on us.
Evidence
A group of related operating companies with inconsistent security across entities. The work was structured in tiers, sequenced so the highest-risk items were closed first, and delivered against a documented effort log the client could audit.
The outcome was a single security baseline across the group and a prioritised register of what remained, with cost attached to each item.
Presented anonymously. No client configuration, weakness or exposure detail is published here or anywhere else on this site.
Aflame Fire Services Limited, a Leicester fire suppression specialist, came to us with no documentation, ageing devices and licences being paid for but not deployed. We audited the estate, documented it, and configured secure remote access for newly acquired laptops.
Priority findings were closed within days, with no disruption to day-to-day operations. The engagement later became a managed support agreement.
Read the Case StudyThe Other Pillars
Consult designs and changes; Support runs what results. Many customers start with an assessment and move into a support agreement afterwards — it is common, but it is never a condition.
Explore SupportA Consult recommendation often changes what licences you need. Software covers the supply, the right-sizing and the renewals that follow.
Explore SoftwareThe specification behind the roadmap work on this page — what the assessment covers, what the plan contains, and how it is reviewed.
See the DetailNext Step
A conversation about the problem, not a sales meeting. We will tell you what we think it will take, and we will tell you if we think you do not need it.
Four fields. We reply within one working day.