Skip to content

The 3 AM problem, already handled.

We layer our defences on purpose. Because someone always needs an exception, and if one control fails, the next one catches it before it becomes a disaster. A security operations centre watches 24x7, so if something starts while the office is empty, it is handled before you get in.

How you're protected

Layered defence, standard on every plan.

Every plan runs the controls that stop the most common attacks. Where a business needs more, Compliance and Complete add the controls that catch what slips past the basics.

On every plan

A compromised laptop gets isolated, not ignored

If a device shows signs of compromise, we cut its network access remotely, any hour of the day. Confirmed threats are contained before they spread; anything uncertain gets a phone call first.

A stolen password doesn't get anyone in

Most break-ins start with a login, not a virus. We watch for odd sign-in locations, hijacked sessions and rogue app approvals, and lock the account down the moment one looks stolen.

The dangerous site never loads

Known bad domains, and ones too new to trust yet, get blocked before the connection opens. We also keep your email records locked down so nobody can send mail pretending to be you.

A restore that's been tested, not just scheduled

Servers and your full Microsoft 365 environment back up daily and get checked every business day. Once a year we run a full recovery and hand you the real time it took.

Nobody's passwords live in a browser

Every login sits in a vault we can audit, rotate and kill the day someone leaves. Dark-web monitoring flags anything already exposed.

Your tenant, hardened before anyone signs in

We configure your Microsoft 365 environment to our own security baseline, not whatever the last admin left switched on. Secure Score tracks the result over time.

On Compliance and Complete

Software that isn't approved simply doesn't run

Only vetted programs execute on your machines; everything else is blocked by default. It's the single biggest reason ransomware can't get a foothold once it's switched on.

Someone is actually reading the logs

Firewall, server and workstation activity feeds into one platform, and analysts go looking for signs of trouble instead of waiting for an alarm to fire.

The click that almost happened gets caught early

Short training lands every fortnight, paired with realistic phishing tests. Anyone who clicks gets a quick follow-up, not a lecture.

See exactly what's on each plan

Cybersecurity awareness training

Staff training, because most incidents still start with a click.

You can't buy your way out of that, but you can make the click less likely. Little and regular beats a seminar once a year, as long as it is tied to real tests.

  • Training content lands in staff mailboxes every two weeks.
  • Simulated phishing tests use whatever they were taught last.
  • A "learning moment" follows anyone who clicks one.
  • Live sessions when something emerging is worth the interruption.
  • Reporting each month or quarter on who is engaging and who isn't.

Password manager

Passwords belong in a managed vault, not a browser.

If a password sits outside the vault, we can't audit it, rotate it, or kill it the day someone leaves. When they go, what they know goes with them.

  • Zero-knowledge vault, opened with single sign-on from Microsoft 365.
  • Dark-web monitoring on your credentials, plus weak and reused password alerts.
  • Vault Transfer, so a departing staff member's records stay with the business.
  • Required in every environment we run.

Obligation ·  What every client runs

Security basics every client has to run, in writing.

You keep a documented baseline running: phish-resistant multi-factor authentication (MFA), application control, vulnerability management, awareness training, a password manager with single sign-on, HR-driven onboarding and offboarding, backups, and an incident response plan. Ours or an equivalent from another provider, either works.

Not every control fits how a business actually works, and we don't pretend otherwise. Where one doesn't, we sit down and name what you're going without. Then we agree what happens next: a mitigating control that covers the same risk, or a written acceptance of the gap and who carries it.

Where the standard slips without agreement, everything else we do works less well and our own exposure rises. You get written notice and 30 days to remedy it or agree a plan. We can't defend an environment that won't cover its own basics.

The full list sits in our Managed IT Complete Service Terms.

Common questions

What happens at 3 AM, and the AI questions we hear.

The questions that come up on discovery calls, answered straight.

If we're attacked at 3 AM, what actually happens?
We already have Microsoft 365 MFA. Isn't that enough?
Is rolling out Microsoft 365 Copilot a security risk for us?
Can our staff use ChatGPT, Claude, or other AI tools on client data safely?
Do you cover incident response? What if we have a live ransomware event?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit