Five guides and a monthly briefing. Written to be useful whether or not you ever hire us.
Free to read · no email · PDF available
Setting up IT for a small firm
Six things worth building properly when nobody owns the IT: remote access, the office network, filtering, file sharing, licences and accounts. What each costs you to skip, and the order to do them in.
Read it now →The AI SDLC Playbook
The two ceilings nobody warns you about, why a green test suite can sit over a broken product, and seven practices that hold quality as a codebase grows.
Read it now →Surviving the enterprise security questionnaire
Your deal has stalled in security review and SOC 2 is months away. What you can answer from evidence in the meantime, and what you must never claim.
Read it now →What technical due diligence actually looks for
Auditors rarely fail a deal on ugly code. They fail it on unmanaged risk. What gets examined at Series A, and what you can still fix.
Read it now →The first 15 seconds
A one-page plan for the moment you suspect a machine or account is compromised: isolate, freeze the accounts, call for help. With the data on why the window is that short.
Read it now →Monthly · email required
Day-0 Watch
One question, once a month: of everything that became newly exploited, what actually matters for an estate the size of yours — and what do you do about it. Written for people without a security team.
What it is, and subscribe →Start with one piece of work.
Give us one piece of work and read access to one system. We map it and come back with what we found, what we would build and what it would take — before any commitment. You decide using our output, not our pitch.
Talk to us