Endpoint protection & EDR
Managed antivirus on every device, upgraded to endpoint detection and response on Professional plans so suspicious behaviour is caught, not just known malware.
- Managed antivirus
- EDR on Professional+
- MDR on Complete
Layered defence for businesses with no security team of their own. Monitoring, prevention, staff training, and a plan for the day something gets through anyway.
Enterprise security advice tends to assume you have a security team. You almost certainly do not. What a 10 to 50 person business in East London actually needs is a small number of controls that work reliably, are monitored by someone, and do not depend on every member of staff making a perfect decision every day.
That is how we build it. Prevention where prevention is cheap, detection where prevention is unrealistic, and a written, tested plan for the cases where something still gets through.
Managed antivirus on every device, upgraded to endpoint detection and response on Professional plans so suspicious behaviour is caught, not just known malware.
Email is still the way most attacks arrive. Filtering, impersonation protection and link rewriting stop the bulk of it before it reaches an inbox.
Perimeter and internal controls, configured properly and kept that way. Not a router still sitting on its factory settings.
Simulated phishing and short, practical training. The cheapest control available and consistently the most effective.
SIEM and log retention on the Complete tier, so there is an evidence trail when you need one, whether that is for an investigation or an insurer.
A written plan, agreed before you need it. How to contain it, how to recover, and who has to be told. That last part includes the ICO.
How we work
Most security quotes begin with a conversation and end with a list of products you're asked to trust. Ours begins with a scan.
We built our own audit software, ShadowAudit, because the tools we could buy either cost more than our clients' entire IT budget or produced hundred-page reports nobody reads. It checks fifteen configuration controls on every Windows machine, finds the devices on your network that nobody remembers plugging in, and looks at your business from outside to see what the internet can reach.
Every finding carries the evidence that produced it. Not "your password policy is
weak" but net accounts: minimum length 0, and the setting that fixes it.
You can check our work, and so can anyone you hire after us.
First we look from outside. Before we visit, we scan what your business publishes to the internet from our own systems. Open ports, certificate problems, forgotten subdomains, mail records that let anyone send email as you. This is the half most firms have never had checked, and it's the half an attacker starts with.
Then we look from inside. On site, we check each Windows machine against the same fifteen controls: patching, encryption, firewall, antivirus, account policy, legacy protocols. We sweep the network and list every device on it. That list alone tends to produce a surprise or two.
Then you get a report you can act on. Findings ordered by what an attacker would use first, each with the fix, the effort involved, and what breaks if it's applied carelessly. Written for whoever signs things off, not for an engineer.
We do not touch a system without written authority. The free perimeter check takes one signed form. A paid audit takes three: the engagement letter, a scope schedule naming every machine we may look at and everything we may not, and a data processing agreement covering the personal data an audit inevitably sees.
All four are published on our downloads page, blank and in full. Read exactly what you would be agreeing to, and what we are promising not to do, before you speak to anyone here.
Read the case study: 1,241 password attempts in a day on our own server
| What | Price | What you get |
|---|---|---|
| Perimeter check | Free | What the internet can reach on your domain and public address. Remote, no visit, no obligation. You get the findings whether or not you hire us. |
| Full audit | £450 to £650 | Everything above, plus every Windows machine checked on site, a device inventory, and the written report. |
| Cyber Essentials readiness | £650 to £950 | The full audit mapped to the five controls, with a pass or fail against each and the work needed to close the gaps. |
| Managed Cyber Essentials | £99 per client, per month | Gap assessment, the remediation work, the submission itself, and keeping the controls in place between renewals. |
Prices exclude VAT. The IASME certification fee is set by the scheme and paid separately, from £300 + VAT depending on your size. We're not a certification body, so that fee never comes to us.
Worth being straight about, because plenty of firms aren't.
It isn't a penetration test. Nothing we run exploits anything, guesses a password or tries to break in. It's a configuration and exposure audit. If you need someone to actively attack your systems, that's a different engagement with a signed scope, and we'll tell you so rather than dress this up as one.
The Cyber Essentials mapping is readiness, not certification. We tell you whether you'd pass. The certificate is issued by an IASME-accredited body once the questionnaire goes in, and we handle that submission for you.
It won't find everything. Nothing does. It checks Windows machines properly and treats printers, phones and network kit as devices with open ports rather than auditing them internally. We say that in every report rather than letting a clean page imply more than it should.
Not everything needs a retainer. A security audit is £1,485 as a fixed fee. You get a point-in-time review of your environment, then a prioritised list in plain English of what to fix and what each item costs. Ongoing UK GDPR support is £13 per user per month.
If you are being asked for a certification rather than a general improvement, the specific schemes are covered on our Cyber Essentials and Cyber Essentials Plus pages.
Security is included at increasing depth across the managed IT plans: Essential covers endpoint antivirus and patching; Professional adds EDR, email security and phishing training; Complete adds SIEM, log retention, MDR and compliance reporting.
Most attacks are not targeted at all. They are automated and opportunistic, sweeping the internet for unpatched systems and reused passwords. Being small does not make you invisible to a script; it usually just means fewer controls in the way.
Antivirus matches files against known-bad signatures. EDR watches behaviour instead. A process encrypting files unusually fast, or a login from a country you have never traded with. That way it can catch something nobody has seen before.
Our fixed-fee £1,485 security audit is a configuration and vulnerability review rather than a full adversarial penetration test. If you need a formal pen test for a contract or an insurer, tell us and we will scope it properly.
Managed clients have an agreed incident response plan: contain, assess scope, recover from tested backups, then handle notification. Under UK GDPR a reportable personal-data breach must reach the ICO within 72 hours, and we help you make that assessment.
Badly configured ones will, which is how they end up disabled. We tune controls around how your team actually works. Protection that gets switched off protects nothing.
Tell us about your setup and we'll come back within one business day with a free, no-obligation IT health check.