Services
Security expertise, without the full-time cost.
From your first assessment to certification and ongoing managed security.
What we do
Five bundles. One platform.
Governance, Risk, Advisory, Protection and Education. Each one closes a specific gap, and each one is stronger because the others are there.
A senior security officer embedded in your business for a set number of hours each month — owning your programme, attending your board and turning cyber risk into decisions your leadership team can act on.
- CSO-as-a-Service: Advisor, Active and Embedded tiers
- Security strategy, roadmap and annual board reporting
- Risk register ownership, incident command and vendor governance
- SMB1001 and ISO 27001 certification programme management
Fractional CSO at 10–20% of the cost of a full-time hire.
More on GovernanceA ranked view of what actually threatens the business, including the suppliers you depend on. Not a hundred page report: a short list of what matters and what to do about it.
- A live risk register, ranked by what an incident would cost you
- Continuous supplier monitoring with no questionnaires to chase
- Vulnerability scanning across the systems you already run
- Early warning when a supplier's exposure changes
Supplier monitoring runs on Black Kite. Few firms our size offer it.
More on RiskA senior security leader in your corner for a set number of hours each month. Someone who owns the plan, sits in the meetings that matter, and turns the technical into decisions you can actually make.
- CSO-as-a-Service at three levels, from light guidance to full ownership
- A security roadmap and a budget you can take to the board
- Someone on the end of the phone when an incident happens
- Independent advice on what to buy and, more often, what not to
Advisor, Active and Embedded tiers. Move between them as things change.
More on AdvisoryThe day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.
- Monitoring and response running 24 hours a day
- Protection on every laptop, server and phone
- Email and domain security, so nobody can send mail pretending to be you
- Backup for your cloud applications, and testing to find the holes first
Delivered with CrowdStrike, Arctic Wolf and other established partners.
More on ProtectionMost incidents start with a person, not a firewall. This is the bundle that changes behaviour, in short pieces people will actually finish rather than an annual video nobody watches.
- Short training modules built around the roles people actually do
- Simulated phishing that teaches rather than embarrasses
- A human risk score, so you can see who needs more support
- Onboarding for new starters that runs itself
Training records roll straight into your Governance evidence.
More on EducationHow it fits together
Start with one. Add the rest
when you are ready.
The platform maps your controls and collects your evidence. The bundles fill the gaps it surfaces. For most businesses the journey runs the same way: start with an assessment, target Gold certification, then keep Protection and Education running so the controls stay in place year after year.
Every bundle supports a specific part of your certification journey. None of them exists to sell you something extra.
- Gap analysis
- Readiness review
- A costed roadmap
- Bronze to Gold managed end to end
- Evidence and submission
- Platform monitoring
- Protection and monitoring
- Education programmes
- Advisory leadership
Questions
Common questions.
Everything we sell sits under one of five bundles: Governance, Risk, Advisory, Protection and Education. Between them they cover policy and certification, risk and supplier monitoring, CSO-as-a-Service, 24/7 managed security, and security awareness training.
No. Most clients start with whichever bundle is hurting most and add others as the business grows. Because everything runs on the same platform, nothing has to be rebuilt when you expand, and the work you did in your first month still counts in your fifth year.
It sits in the Advisory bundle and gives your business executive-level security leadership at a fraction of the cost of a full-time hire. Engagements run at three levels and include board-ready reporting, security strategy, vendor governance and incident response leadership.
Managed Detection and Response is required for SMB1001 Diamond certification (control 1.12.1.0) and recommended for Platinum. For Bronze through Gold, endpoint protection and awareness training are the primary controls. MDR sits in the Protection bundle.
We take your business from wherever you are today to certification at your target tier, handling the gap assessment, remediation planning, policy drafting, evidence collection and submission. For Platinum and Diamond we coordinate the independent audit with an accredited certifier.
Book a free consultation. Most clients begin with a security assessment so we can see where you stand before recommending anything, and that assessment tells you which bundle to start with.
Not sure where to start?
Book a free consultation and we will tell you which bundle makes sense for your business and your target certification tier.

