Nobody here owns the IT, and everybody knows it.
The server was set up by someone who left. Backups run — nobody has restored one. A former contractor may still have access. The last person to ask about security was a customer, on a questionnaire, and answering it took three weeks.
You do not need a full-time IT hire for this. You need it set up properly once, and then watched by someone.
Running AI agents against security questions? Lattice gives them sourced, labelled reference knowledge. See Lattice
Seven things, and you can take them one at a time.
Most firms start with the review, fix the two or three things it finds, and add monitoring after. You do not have to buy the whole list.
Network, VPN and access control
The wifi, the office network, and remote access that does not depend on one person remembering to remove someone. Who can reach what, written down as a rule rather than held in someone's head.
Remote access that works from anywhere, and an access list you can actually read.
Security monitoring
Something watching the estate around the clock, and a person reading it. When a new vulnerability appears we check whether it touches your equipment specifically, and tell you either way.
A monthly written position, and a call when something needs you before then.
Early warning, set up properly
The tooling that notices something is wrong while it is still small — a login from somewhere odd at 3am, a laptop talking to an address it should not, a server quietly filling up. We install it, connect it to the laptops, the servers, and the email and cloud accounts, and then spend the first few weeks tuning out the noise, which is most of the work (the tooling is a SIEM, extended across devices and accounts rather than the network alone — XDR, if you are comparing quotes).
Someone finding out the day something changes, instead of a customer telling you three weeks later.
Data backup that has been restored
Backups of the things that would end the business if you lost them — and a restore we have actually run, in front of you. A backup nobody has restored is a belief, not a backup.
A tested restore, and a written note of how long a full recovery takes.
Servers, VMs and VPS
The machines your software runs on, whether that is a box in your office, a virtual machine, or a rented server (a VPS). Set up once, patched, and documented so the next person is not guessing.
Working servers, and the documentation that means you are not locked to us.
Accounts, devices and offboarding
Laptops, logins, and the thing almost everyone gets wrong: removing access the day someone leaves rather than the month after.
A device and account register, and an offboarding checklist that takes ten minutes.
An IT asset review, first
Before any of the above: what you actually have. Every machine, service and account, what is exposed to the internet, and where the gaps are. It usually finds two or three things nobody knew were running.
A written inventory and a ranked list of what to fix, which is yours whether or not we do the work.
Engagements are monthly and sized to scope, and sized to land below the fully-loaded cost of one senior US engineer.
The routine part is automated. The judgement is not.
An IT provider’s cost is mostly people watching things. That is why proper monitoring has historically been priced for companies with a hundred staff, and why a twenty-person firm gets a quarterly check-in and hopes.
We run the watching on our own product, OCO — a cyber knowledge graph that cross-links vulnerabilities, detections and countermeasures, giving one console for triage, topology, incidents and response. It runs on your own infrastructure with no external AI API, so nothing about your estate leaves your site. And it is honest about its own coverage: it reports what it cannot see, which matters more than it sounds, because the failure mode of security tooling is a green dashboard over a gap nobody named.
That is what makes the arithmetic work. The gathering and cross-referencing that used to take an analyst a morning is done before a person opens it, so what you pay for is the judgement — someone deciding whether a newly exploited vulnerability touches the estate we inventoried for you, and telling you either way.
A person still decides. The tool is where they look, not what decides.
With the review, and you can stop there.
1 · The asset review
2 · Fix what it found
3 · Then watch it
Where do you actually stand? Answer these and find out now.
Tap an answer and you get the read straight away — what it usually means, and whether it is worth doing something about. Nothing is sent anywhere unless you decide to send it at the end. Most firms find two of the five are worth a week’s attention.
Who handles IT today?
Are there backups, and has anyone ever restored one?
Is two-step verification switched on?
Is there anyone who has left who might still have access to something?
Where do your working files live?
Five questions cannot assess anything, and this is not a score. It is what these answers usually mean in firms your size. Tapping an answer sends nothing anywhere; the only thing that leaves your browser is the email address you type at the end, if you decide to.
Three things we are not, so you can rule us out quickly.
Small firms have been sold managed IT before, and the complaints are consistent enough to be worth answering before you ask.
Not a break-fix helpdesk
Not a rip-and-replace
Not a compliance certificate
Start with the asset review.
Every machine, server, service and account; what is exposed; who can reach what; and whether the backups restore. You keep the inventory whether or not we do anything else — and if the answer is that you are in better shape than you feared, that is the answer you get.
Book the asset review