A baseline you can trust
Most businesses don’t need a 200-page audit. They need clarity.
This stage gives you a focused view of your current security posture and a roadmap
for the next 6–12 months that fits your size, pace, and budget.
I look at how your people, data, identity, and systems are structured today -
then map out the next steps that genuinely reduce risk without overcomplicating anything.
What I look at
- Identity & access: accounts, MFA coverage, admin access and basic hygiene.
- Data: what you hold, where it lives, and how it’s protected and backed up.
- Cloud & infrastructure: key systems and SaaS platforms at a practical, risk-based level.
- Governance: how risks are discussed, who owns what, and how decisions are made.
- People & awareness: how staff are supported to recognise and handle everyday risks.
What you walk away with
- A clear, plain-English summary of your current security posture.
- A risk view that links issues to business impact - not just technical detail.
- A simple, maintainable view of your key assets and data.
-
A prioritised 6–12 month roadmap of improvements, grouped by effort and impact,
so you know what to do now, next, and later.
- A live walkthrough session where we go through everything together.
Fixed fee · typically ~2 weeks from kickoff
Who this is for
- Small and mid-sized businesses who’ve “done some basics” but want a clearer picture.
- Leaders getting ready for growth, bigger customers, or more formal security expectations.
- Teams that don’t need a full-time security lead, but do want sharp, honest guidance.
There’s no tool-pushing and no fear tactics - just a realistic view of where you are
and a path forward that makes sense for your business.
Next step: a short intro call to confirm fit, scope and timelines.
Ask about an assessment