Security services sized for lean teams.

Start with one, or build a plan across all four. Everything is scoped to your size and budget. If you're not sure what you need, that's what the free consultation is for.

01 · Assessments

Know where you actually stand, in language you can take to a board.

Cyber Health Check

A quick, honest look at the fundamentals. We review your core controls, give you a simple rating by area, and tell you the three or four things worth fixing first. Designed for smaller organisations, and for anyone who wants a starting point before committing to anything larger.

You get: a plain-language summary, a simple health rating, and a short list of priorities.

Typically: 1 to 2 weeks.

Security Maturity Assessment

The full picture. We rate your security maturity across each area of the business, benchmark it against recognised frameworks, and set out a realistic path to improve it. Includes a risk register you can actually work from and a summary written for your board.

You get: a maturity rating by area, a prioritised risk register, a plain-language report, a board summary and a remediation roadmap.

Typically: 2 to 4 weeks.

Compliance Mapping

We map your existing controls against the frameworks that matter to you: Essential Eight, ACSC guidance, NIST CSF, CIS Controls and ACNC governance standards, including a maturity level for each Essential Eight control when that's specifically what's been asked for. Useful when a contract, an insurer or a funding body wants to see where you stand against a named framework.

Usually: sold alongside an assessment.

Security Questionnaires and Insurance Readiness

Practical help getting through a cyber insurance questionnaire, a customer or vendor security questionnaire, or the security section of a grant or tender. We'll also tell you which honest "no" answers are worth fixing before you submit.

Typically: A few days, depending on what has been asked.

02 · Advisory

An experienced security consultant on call, without a salary attached.

Security Advisory Retainer

Ongoing access to us for the questions and decisions that come up: a tool you're considering, a request from a client, a policy question, a "should we be worried about this?" moment. Available as a block of time you draw down through the year, or as an ongoing monthly arrangement.

Options: a block of advisory half-days, drawn down as you need them, or a monthly retainer with a quarterly review.

Security Strategy and Roadmap

A working session and a written plan: where you are now, where you need to be over the next year or two, and the order to do things in. Most useful straight after an assessment.

Typically: 1 to 2 weeks.

Vendor and Tool Review

An independent look at a security product you're considering, or the ones you already pay for. What it actually solves, what it will cost to run, and whether something you already own does the same job.

Note: We take no commission from any vendor. That's the entire point of the service.

Board and Executive Briefing

A single session that turns your security position into something a board or leadership team can act on. Available on its own, alongside an assessment, or as an annual refresher.

Typically: Half a day.

03 · AI Governance

Your team is already using AI. This is how you get in front of it.

AI Readiness and Governance Review

Where AI is already being used across your organisation, often without anyone approving it: what information is going where, what your actual exposure is, and what to put in place. For organisations building or deploying AI capability rather than just using it, this extends to a design review against our Secure AI by Design framework and the OWASP Top 10 for large language models.

Typically: 1 to 4 weeks, depending on scope.

AI Usage Policy

A workable set of AI rules your team will actually follow, plus a briefing session to walk everyone through it. A good first step if you're not ready for a full review.

Typically: 1 week.

04 · Training

The technology matters less than whether your people know what to do.

Cyber Awareness Sessions

Friendly, jargon-free training for staff and volunteers. How to spot a scam, how to handle sensitive information, and what to do when something looks wrong. No lectures and no shaming.

Typically: 60 to 90 minutes, in person or online. Available as a series.

Board and Leadership Cyber Literacy

A step up from awareness training, built around governance: what a board is accountable for, what questions to ask, and how to read a risk register and a maturity rating without needing a translator.

Typically: Half a day.

Assessment Training for IT Providers

For IT firms who want to run security assessments for their own clients. We train your team on the methodology and stay available while you find your feet.

Learn more at Keystone ↗

How an engagement runs

01
Assess

We map your assets and risks in plain language.

02
Prioritise

A risk register ranked by real-world impact, not technical severity alone.

03
Plan

A realistic remediation roadmap you can actually execute.

04
Keep it current

Your risk register and reporting stay in one place you can revisit any time, so progress stays visible without paying a consultant for every update.

Not sure which of these you need?

Most people aren't, and that's fine. Tell us what's prompted you to look, whether it's an insurance form, a board question or a general feeling that you should probably do something. We'll point you at the right starting place, even if it's not with us.

Book a free consultation