Controls that survive an audit, not a checklist that survives a meeting.
Everything here produces evidence: a report, a log, a register. If a control cannot be shown to a third party, it is not finished.
Email, remote access, banking portals, practice management. Including the shared accounts everyone pretends do not exist.
Managed EDR on every workstation and server, with alerts that reach a human who is on the hook for answering them.
Who can reach what, produced as a signed document each quarter. Leavers are removed before their last day, not months after.
Short, quarterly, and aimed at the attacks that actually hit small firms: invoice fraud, trust-account redirection, and fake partner emails.
Plain-English findings ranked by what it would cost you, with a fixed price to close each gap. Yours whether you hire us or not.
Who to call, in what order, with what authority — written down before you need it, and rehearsed once a year.
How it runs
We look at identity, endpoints, email, backups, and who has access to what. Nothing intrusive, nothing disruptive.
3–5 daysRanked findings, each with an owner, an effort estimate, and a fixed price to fix.
From $1,800MFA, EDR, access cleanup, and email authentication, in the order that reduces the most risk first.
Fixed feeQuarterly access reviews, quarterly training, annual runbook rehearsal, and monthly reporting.
From $38/userWhat you get in writing
Yours to keepRanked findings, priced remediation, plain English.
Signed quarterly record of who can reach what.
Call order, authority, and client-notification wording.
Who was trained, on what, and when — for your insurer.
Where small firms actually get hurt
Not ransomware. Someone reads a mailbox for three weeks, then emails your client new banking details in your own writing style.
Accounts, mailbox delegations, and VPN profiles that outlive the employment. Most firms find several on the first access review.
Cyber policies increasingly ask whether MFA is enforced. Answering optimistically is how claims get denied.
Questions about cybersecurity
Do we need this if we are only six people?
Attackers do not filter by headcount, they filter by whether money moves through your inbox. A six-person practice holding client funds is a better target than a large firm with a security team.
Is this enough for PIPA or PIPEDA?
It covers the technical and organisational safeguards those regimes expect, and produces the documentation to demonstrate them. Legal interpretation is your counsel's call, not ours.
Will MFA slow everyone down?
Configured properly, most staff authenticate once per device per fortnight. The friction people complain about is usually a sign it was set up badly.
Can we buy just the exposure report?
Yes. It is a fixed-fee engagement, the findings are yours to keep, and there is no obligation to have us fix anything.