The Cyber Security Part of the CAQA group

Cyber security

The attack you get is the boring one

Practical security for small organisations: the phishing, the weak password, the unpatched box and the backup nobody tested.

IWhat we do

Three things, done properly.

i

Assessment

Finding the exposures that realistically apply to an organisation your size.

ii

Hardening

Multi factor authentication, patching and backup, done properly, which covers most of the actual risk.

iii

Response

What to do in the first hour, decided before the first hour.

IIWhat goes wrong

The two failures we see most.

We publish these because most of the value in hiring anyone is knowing which mistakes are common, and that knowledge is not worth hiding.

Buying tools before basics

Advanced tooling on top of shared passwords and unpatched systems protects almost nothing.

The untested restore

Ransomware recovery depends entirely on a restore nobody has ever performed. That is the whole plan, untested.

IIIHow we work

We tell you what we find.

Including when the answer is that you do not need what you came to ask for. Anyone who never says that is not giving you information, they are giving you an invoice.

Scope

Where something needs a legal opinion, a financial audit or a clinical judgement, we will say so and stop rather than improvise past the edge of what we do.

Start a conversation.

Tell us the situation rather than the service you think you need. We would rather start from your problem.