Services

Senior security work, scaled to the firm in front of us.

Choose the support you need now, from a focused review through to ongoing security leadership. Every engagement stays practical, proportionate and led by Michael.

Scroll to explore
02Three service pillars
03How it works

How it works

Urgent first, then useful

Most firms start with a short assessment. The result is a plain-English view of what needs action, who should own it and what can wait. Tier 1 can then help deliver the plan or stay on as the security lead.

04What useful work leaves behind

What useful work leaves behind

Decisions and evidence your firm can keep using

A useful engagement should make the next decision easier. The exact documents depend on scope, but the work is organised around practical outcomes rather than a report that sits unread.

A prioritised risk view

A short account of the material gaps, their business effect and the order in which they should be addressed.

Named ownership

Clear responsibility across leadership, staff, IT providers and other advisers, including decisions that cannot be delegated.

Control evidence

Records that show what is configured, approved, tested or still accepted as a visible risk.

A workable cadence

A review rhythm that matches the firm, with changes, exceptions and overdue actions brought back to leadership.

05Questions

Straight answers

Common questions

We are only a few people. Are we really a target?

Yes. Small firms can still hold valuable information and move significant payments. Good basic security reduces the opportunity for an attacker without forcing a small team into an enterprise-sized program.

Do we need an expensive certification?

Usually not to start. Most firms gain more by getting the fundamentals right first. We help you decide whether a formal standard is worthwhile based on your risks, client expectations, contracts and insurer requirements.

We already have an IT provider. Why do we need you?

General IT keeps systems running. Security governance sets priorities, tests whether controls are effective and gives leadership a clear view of risk. We work alongside your existing provider and make the boundaries visible.

How much of our time will this take?

As little as practical. We do the heavy lifting and ask for input where leadership context or a business decision is required. The aim is to take security work off your plate, not create another reporting burden.

Where should we start?

Start with a short review of the information, payments, systems and obligations that matter most. You will receive a prioritised view of the urgent gaps, the sensible next steps and which work can wait.

A quiet first step

Book a confidential call

Talk directly with Michael about what your firm needs to protect and the practical next step.

Book a confidential call