Skip to content
IT and security · for firms without IT staff

Nobody here owns the IT, and everybody knows it.

The server was set up by someone who left. Backups run — nobody has restored one. A former contractor may still have access. The last person to ask about security was a customer, on a questionnaire, and answering it took three weeks.

You do not need a full-time IT hire for this. You need it set up properly once, and then watched by someone.

Running AI agents against security questions? Lattice gives them sourced, labelled reference knowledge. See Lattice

What is included

Seven things, and you can take them one at a time.

Most firms start with the review, fix the two or three things it finds, and add monitoring after. You do not have to buy the whole list.

01

Network, VPN and access control

The wifi, the office network, and remote access that does not depend on one person remembering to remove someone. Who can reach what, written down as a rule rather than held in someone's head.

What you end up with

Remote access that works from anywhere, and an access list you can actually read.

02

Security monitoring

Something watching the estate around the clock, and a person reading it. When a new vulnerability appears we check whether it touches your equipment specifically, and tell you either way.

What you end up with

A monthly written position, and a call when something needs you before then.

03

Early warning, set up properly

The tooling that notices something is wrong while it is still small — a login from somewhere odd at 3am, a laptop talking to an address it should not, a server quietly filling up. We install it, connect it to the laptops, the servers, and the email and cloud accounts, and then spend the first few weeks tuning out the noise, which is most of the work (the tooling is a SIEM, extended across devices and accounts rather than the network alone — XDR, if you are comparing quotes).

What you end up with

Someone finding out the day something changes, instead of a customer telling you three weeks later.

04

Data backup that has been restored

Backups of the things that would end the business if you lost them — and a restore we have actually run, in front of you. A backup nobody has restored is a belief, not a backup.

What you end up with

A tested restore, and a written note of how long a full recovery takes.

05

Servers, VMs and VPS

The machines your software runs on, whether that is a box in your office, a virtual machine, or a rented server (a VPS). Set up once, patched, and documented so the next person is not guessing.

What you end up with

Working servers, and the documentation that means you are not locked to us.

06

Accounts, devices and offboarding

Laptops, logins, and the thing almost everyone gets wrong: removing access the day someone leaves rather than the month after.

What you end up with

A device and account register, and an offboarding checklist that takes ten minutes.

07

An IT asset review, first

Before any of the above: what you actually have. Every machine, service and account, what is exposed to the internet, and where the gaps are. It usually finds two or three things nobody knew were running.

What you end up with

A written inventory and a ranked list of what to fix, which is yours whether or not we do the work.

Engagements are monthly and sized to scope, and sized to land below the fully-loaded cost of one senior US engineer.

Why we can do this at a small firm’s price

The routine part is automated. The judgement is not.

An IT provider’s cost is mostly people watching things. That is why proper monitoring has historically been priced for companies with a hundred staff, and why a twenty-person firm gets a quarterly check-in and hopes.

We run the watching on our own product, OCO — a cyber knowledge graph that cross-links vulnerabilities, detections and countermeasures, giving one console for triage, topology, incidents and response. It runs on your own infrastructure with no external AI API, so nothing about your estate leaves your site. And it is honest about its own coverage: it reports what it cannot see, which matters more than it sounds, because the failure mode of security tooling is a green dashboard over a gap nobody named.

That is what makes the arithmetic work. The gathering and cross-referencing that used to take an analyst a morning is done before a person opens it, so what you pay for is the judgement — someone deciding whether a newly exploited vulnerability touches the estate we inventoried for you, and telling you either way.

A person still decides. The tool is where they look, not what decides.

How it starts

With the review, and you can stop there.

1 · The asset review

We find out what you have and what is exposed. A week, and you keep the inventory whether or not you go further.

2 · Fix what it found

Usually two or three things, in the order that matters. Priced when we know what they are, not before.

3 · Then watch it

Monitoring, a monthly written position, and a call when something needs you sooner.
Five questions, right here

Where do you actually stand? Answer these and find out now.

Tap an answer and you get the read straight away — what it usually means, and whether it is worth doing something about. Nothing is sent anywhere unless you decide to send it at the end. Most firms find two of the five are worth a week’s attention.

01

Who handles IT today?

02

Are there backups, and has anyone ever restored one?

03

Is two-step verification switched on?

04

Is there anyone who has left who might still have access to something?

05

Where do your working files live?

Five questions cannot assess anything, and this is not a score. It is what these answers usually mean in firms your size. Tapping an answer sends nothing anywhere; the only thing that leaves your browser is the email address you type at the end, if you decide to.

What it is not

Three things we are not, so you can rule us out quickly.

Small firms have been sold managed IT before, and the complaints are consistent enough to be worth answering before you ask.

Not a break-fix helpdesk

We set things up and watch them; we are not the number you ring when a printer jams. Most firms our size keep a local person for that, and we work alongside them rather than replacing them.

Not a rip-and-replace

We start from what you have. Replacing working equipment to suit a supplier's standard kit is how these engagements get expensive without getting safer.

Not a compliance certificate

We do not hold SOC 2 and cannot grant you one. What we can do is leave you able to answer a customer's security questionnaire from evidence rather than assertion.

Start with the asset review.

Every machine, server, service and account; what is exposed; who can reach what; and whether the backups restore. You keep the inventory whether or not we do anything else — and if the answer is that you are in better shape than you feared, that is the answer you get.

Book the asset review