The City of London tower cluster at first light, offices still lit against a blue sky.
What happens first

Thirty days to get cybersecurity under control.

We establish where you are, what matters, what happens next and who owns it.

4Phases
30Days
12Months planned ahead
1Accountable owner

Nothing is guessed at.

The register and the roadmap come out of the first month, and the retainer then runs against them.

  1. UnderstandWeek one

    Technical and organisational review, existing suppliers, controls, obligations, incidents and previous assessments. We establish where you actually stand, rather than where the last report said you stood.

  2. AssessWeeks one–two

    Leadership interviews and technical review expose the gap between documented security and operational reality. Most of the real risks surface here.

  3. PrioritiseWeeks two–three

    The risk register, scored and written down, with the risks that matter separated from the ones that only look urgent.

  4. PlanWeeks three–four

    A sequenced, costed rolling security roadmap, prioritised across the next 12 months and agreed with leadership. This is the plan the rest of the engagement runs against.

Day 31Ownership

Now ongoing CISO ownership begins.

By Day 30, you can answer five questions.

Where are we?

A documented baseline.

What are our biggest risks?

A prioritised risk register.

What happens next?

A rolling security roadmap.

Who owns it?

Named accountability.

What decisions do we need to make?

Clear decisions, costs and trade-offs.

What exists on Day 30

Cybersecurity baseline
A documented view of the current security position.
Risk register
Material risks prioritised, scored and assigned.
Rolling security roadmap
Sequenced and costed work, prioritised across the next 12 months.
Executive view
What leadership needs to know, decide and fund.
Ownership map
Who is responsible for what across internal teams, MSPs and other suppliers.

What we look at

Leadership & governance

Ownership, reporting, decision-making.

Technology & exposure

Identity, endpoints, cloud, infrastructure and external attack surface.

People & suppliers

IT providers, MSPs, critical vendors and internal responsibilities.

Resilience

Incident readiness, backup, recovery and business continuity.

Obligations

Customer requirements, insurance, regulation and compliance.

The first 30 days are on us.

At the end of the first 30 days, you receive the baseline, risk register and rolling security roadmap.

If we haven’t delivered the agreed cybersecurity foundation for reasons within our control, you don’t pay.

If we have, the first quarterly payment becomes due and we move from assessment to ongoing ownership.

Then we own the plan with you.

From month two, Secure & Scale shifts from establishing the plan to driving it.

We maintain the risk register, drive the roadmap, challenge suppliers, prepare leadership decisions and report progress to the board.

Put cybersecurity under control.

A first conversation takes about thirty minutes and costs nothing.