Skip to content

Home Cybersecurity

Cybersecurity

You do not know what is exposed until someone looks.

We review the perimeter, harden the configuration and write down internal policies aligned to ISO 27001. The report reads without being technical, because whoever approves the budget usually is not.

Request a security review

Symptoms

Do any of these sound familiar?

If two of them describe you, there is something to look at.

The firewall was configured once and nobody looked again.
Nobody knows for sure who has access to what.
Accounts of people who no longer work here are still active.
The network equipment still has its factory passwords.

Scope

Exactly what we deliver

Named documents and configurations, not adjectives.

01

Perimeter review

What is exposed to the outside and should not be. Most breaches at mid-sized companies start here.

02

Router and firewall hardening

Configuration corrected, default credentials removed and rules documented.

03

Access and permission review

Who can get into what, and which accounts are surplus. Starting with those of people who left.

04

Internal policies aligned to ISO 27001

Written so your team can follow them, not to pass an audit you are not going to take.

Evidence

A new service, and we say so

This service is new and has no published cases yet. We would rather say so than invent one: in security, a credential that collapses at the first technical question costs the whole contract. What we can show you is the method and the document it produces — ask and we will walk you through an anonymised example.

Frequently asked

What people ask before hiring us

Do I need to be ISO 27001 certified?
Almost no mid-sized company needs it. What does help is having internal policies structured according to the standard, which is what we do. Certification is an expensive process that only makes sense when a large client demands it in a contract.
Are you certified?
No. We work aligned to ISO 27001, which means we apply its controls and structure policies according to the standard, without an external audit. We say it plainly because in security the difference matters.
How do I know if I am exposed?
By reviewing the perimeter, the access and the configuration. Most breaches at mid-sized companies do not come from a sophisticated attack, but from an open port and a default password.
Is this one-off or ongoing?
The review is one-off; keeping it secure is not. We tell you which of the two you need, even when it is the one that bills less.

Cybersecurity

You do not know what is exposed until someone looks.

Tell us what you have today. We will tell you what we found and what to do about it, even when the answer is that nothing needs doing.