See your business the way an attacker sees it
A free, no-obligation look at how exposed your business really is – the systems facing the internet, the computers your team works on, your Microsoft 365, and how your people react when something dodgy lands in their inbox.
You get a plain-English report within three working days, and a walkthrough with an engineer who can answer the only question that matters: so what does this mean for us?
No cost. No tie-in. The report is yours to keep whatever you decide to do next.
Why it's worth an hour of your time
Most businesses don’t discover a gap in their defences. They discover the person who walked through it.
An old admin account nobody switched off. A server quietly answering the internet because a firewall rule was added “just for now” in 2021. A member of the team who clicks the link because it looked exactly like a message from the boss.
None of it shows up in your day-to-day. All of it is findable – by us in a few days, or by someone else on a timescale you don’t control. And when it goes wrong, IT interruption costs UK businesses an average of £3,500 an hour, before you count the stress and the awkward phone calls to customers.
This assessment tells you what’s actually there. Then you decide what to do about it.
What we look at
Five areas. You choose which ones – take all five, or just the one that’s been nagging at you.
1. Your front door
We scan the systems you expose to the internet – open ports, forgotten remote access – and tell you what a stranger can reach from outside.
2. Your computers and servers
We check your computers, laptops and servers for missing updates and known weaknesses, then rank the gaps so you fix the ones that matter.
3. Your Microsoft 365
We check your Microsoft 365 tenant – Microsoft Secure Score, dormant accounts, admin rights and licence spend – so you see who still has a way in.
4. Your email's reputation
We check the DNS records that stop someone sending email that looks like it came from you – SPF, DKIM and DMARC – set up properly or half-done.
5. Your team
We send your team a realistic phishing email, then give you a risk score and a clear picture of who spotted it and who clicked.
What we need from you
Everything here is opt-in. You’re welcome to say no to any of it, and we’ll still run the rest and still send you the report. But it’s only fair to be straight about what we can’t tell you if you do.
| Area | What we need from you | If you’d rather not |
|---|---|---|
| Your front door | Your public IP addresses or ranges, and your website address. Written confirmation that you own or control them. | We can’t tell you what’s exposed to the internet – the area attackers look at first. |
| Your computers and servers | A small piece of software installed on the computers you want checked, or access to your existing management tools if you have them. | We can’t tell you which machines are carrying known weaknesses, or which ones matter most. |
| Your Microsoft 365 | A read-only role in your Microsoft 365 tenant, granted by you and revoked by you. | We can’t check dormant accounts, admin rights, settings or licence waste – and dormant accounts are one of the most common ways in. |
| Your email’s reputation | Just your domain name. We read public DNS records – nothing to install, no access needed. | Nothing to grant, so there’s rarely a reason to skip this one. |
| Your team | Your say-so to send a simulated phishing email, and a list of the people to include. You’ll need to be someone who can authorise that. | You won’t know how your team reacts to a real one – which for most businesses is the biggest unknown of the lot. |
About that Microsoft 365 access
We’d ask for a role called Global Reader. The name is Microsoft’s, and it does what it says: it can read, and it cannot change a single thing. We can’t open your email, we can’t read your files, we can’t reset a password, we can’t alter a setting.
It’s granted by you, through Microsoft’s own partner permissions, and you can revoke it yourself at any time – during the assessment or the moment it’s finished. We remove it at our end as soon as the report is written.
If that’s still a step too far, that’s completely fine. Say no and we’ll cover the other four areas.
About the phishing simulation
One piece of advice, and it’s the bit people find counter-intuitive: don’t tell your team it’s coming. A heads-up gets you a flattering result rather than a true one, and a flattering result protects nobody.
This isn’t about catching anyone out. Nobody gets named and shamed, there’s no league table, and the point of the exercise is to find out where a bit of training would help most. We’ll talk you through how to share the results with your team in a way that lands as support rather than a telling-off – we’ve done this a lot.
The simulation runs for seven days, so you get a genuine picture rather than a single morning’s snapshot.
What you get
A written report, in plain English
What we found, what it means for your business and what we’d suggest doing about it – ordered by what matters most, not by what is most technical.
A walkthrough with an engineer
We go through the report with you, in person or on a call – you ask the awkward questions, we give you straight answers.
Recommendations you can act on without us
Some fixes take five minutes and cost nothing – we tell you which those are and how to do them, whether or not you become a client.
How it works
1. You ask
Fill in the form below and tick the areas you’d like covered. Two minutes.
2. A short call to agree the details
About fifteen minutes to agree what we look at, sort out any access and pick a date – nothing starts until you say so.
3. We do the work
Quietly, in the background. Nothing we do interrupts your team or takes anything offline.
4. Your report, within three working days
Then we book the walkthrough. If you’ve included the phishing simulation, the full team results follow after seven days.
Request your assessment
Tick the areas you’d like us to look at. You can change your mind on the call, and nothing runs until you’ve agreed it.
It takes about two minutes. We’ll come back to you within one working day.
Questions people ask
Anything else you’d like to know, just ask – we’d rather answer it now than have you wondering.
Is this just a sales pitch?
Fair question, so here’s the honest answer. We do it because businesses who see clearly what’s exposed often decide they’d rather not manage it alone – and when they want a partner, we’d like to be on the list. That’s the whole commercial logic, and we’re not going to pretend otherwise.
What it isn’t: a report engineered to frighten you, or a document that stops short of anything useful until you sign something. You get the findings, you get the recommendations, and you get them in enough detail to act on with your existing IT person if that’s what suits you. No pressure follow-up, and one call from us afterwards to ask what you thought – that’s it.
Do we have to give you access to Microsoft 365?
No. Every part of the assessment is opt-in, and saying no to one area doesn’t stop the others. The only consequence is what we can’t tell you: without a read-only role, we can’t check dormant accounts, admin rights, settings or licence waste.
If it helps, the role we’d ask for can read and cannot change anything – and you can revoke it yourself at any time.
Will any of this disrupt the team?
No. Nothing we do takes a system offline or interrupts anyone’s work. The scans run quietly in the background, and the only thing your team might notice is the simulated phishing email – which is rather the point.
Should we tell the team about the phishing test?
We’d suggest not. A heads-up gets you a flattering result rather than a true one, and a flattering result protects nobody.
Nobody gets named and shamed. The point is finding out where a bit of training would help most, and we’ll help you share the results in a way that lands as support rather than a telling-off.
What does it cost?
Nothing. There’s no charge, no tie-in, and no obligation to buy anything afterwards. The report is yours to keep whatever you decide to do next.
How long does it take?
Your report lands within three working days of us starting. If you’ve included the phishing simulation, the full team results follow after seven days – that’s how long we run it for, so you get a genuine picture rather than a single morning’s snapshot.
Not ready to fill in a form?
Perfectly reasonable. Give us a call and ask whatever you like – including “is this actually worth doing for a business our size?” We’ll tell you honestly.
Engineers in Bournemouth, not Bangalore. Real people, on the end of a phone.