See your business the way an attacker sees it
A free, no-obligation look at how exposed your business really is – the systems facing the internet, the computers your team works on, your Microsoft 365, and how your people react when something dodgy lands in their inbox.
You get a plain-English report within three working days, and a walkthrough with an engineer who can answer the only question that matters: so what does this mean for us?
No cost. No tie-in. The report is yours to keep whatever you decide to do next.
Why it's worth an hour of your time
Most businesses don’t discover a gap in their defences. They discover the person who walked through it.
An old admin account nobody switched off. A server quietly answering the internet because a firewall rule was added “just for now” in 2021. A member of the team who clicks the link because it looked exactly like a message from the boss.
None of it shows up in your day-to-day. All of it is findable – by us in a few days, or by someone else on a timescale you don’t control. And when it goes wrong, IT interruption costs UK businesses an average of £3,500 an hour, before you count the stress and the awkward phone calls to customers.
This assessment tells you what’s actually there. Then you decide what to do about it.
What we look at
Five areas. You choose which ones – take all five, or just the one that’s been nagging at you.
1. Your front door
What we check: the systems your business exposes to the internet – your public IP addresses and the services running on them. Open ports, forgotten remote access, kit still listening that everyone assumed was switched off years ago.
What you’ll learn: exactly what a stranger can see and reach from outside your building, and which of it shouldn’t be reachable at all.
2. Your computers and servers
What we check: the computers, laptops and servers your team works on, for missing updates and known weaknesses in the software they’re running.
What you’ll learn: where the gaps are, ranked by how much they matter – so you’re fixing the three that count rather than a list of three hundred.
3. Your Microsoft 365
What we check: the health of your Microsoft 365 tenant. Your Microsoft Secure Score, accounts nobody has used for months, admin rights sitting where they shouldn’t, and a full breakdown of the licences you’re paying for.
What you’ll learn: who still has a way in that they no longer need, where your settings leave you open – and, more often than owners expect, how much you’re spending on licences for people who left.
4. Your email's reputation
What we check: the DNS records that prove your email is genuinely from you – SPF, DKIM and DMARC – and whether they’re set up properly or just half-done.
What you’ll learn: how easily somebody could send an email that looks like it came from your business, to your customers or your own team. This is the single most common gap we find, and usually the quickest to fix.
5. Your team
What we check: we send a realistic phishing email to your people and see what happens – who spots it, who clicks, and who goes on to hand over a password.
What you’ll learn: a risk score for your business, a clear picture of how your team responds under normal conditions, and the names of anyone who’d have been caught out – so support goes where it’s actually needed.
What we need from you
Everything here is opt-in. You’re welcome to say no to any of it, and we’ll still run the rest and still send you the report. But it’s only fair to be straight about what we can’t tell you if you do.
| Area | What we need from you | If you’d rather not |
|---|---|---|
| Your front door | Your public IP addresses or ranges, and your website address. Written confirmation that you own or control them. | We can’t tell you what’s exposed to the internet – the area attackers look at first. |
| Your computers and servers | A small piece of software installed on the computers you want checked, or access to your existing management tools if you have them. | We can’t tell you which machines are carrying known weaknesses, or which ones matter most. |
| Your Microsoft 365 | A read-only role in your Microsoft 365 tenant, granted by you and revoked by you. | We can’t check dormant accounts, admin rights, settings or licence waste – and dormant accounts are one of the most common ways in. |
| Your email’s reputation | Just your domain name. We read public DNS records – nothing to install, no access needed. | Nothing to grant, so there’s rarely a reason to skip this one. |
| Your team | Your say-so to send a simulated phishing email, and a list of the people to include. You’ll need to be someone who can authorise that. | You won’t know how your team reacts to a real one – which for most businesses is the biggest unknown of the lot. |
About that Microsoft 365 access
We’d ask for a role called Global Reader. The name is Microsoft’s, and it does what it says: it can read, and it cannot change a single thing. We can’t open your email, we can’t read your files, we can’t reset a password, we can’t alter a setting.
It’s granted by you, through Microsoft’s own partner permissions, and you can revoke it yourself at any time – during the assessment or the moment it’s finished. We remove it at our end as soon as the report is written.
If that’s still a step too far, that’s completely fine. Say no and we’ll cover the other four areas.
About the phishing simulation
One piece of advice, and it’s the bit people find counter-intuitive: don’t tell your team it’s coming. A heads-up gets you a flattering result rather than a true one, and a flattering result protects nobody.
This isn’t about catching anyone out. Nobody gets named and shamed, there’s no league table, and the point of the exercise is to find out where a bit of training would help most. We’ll talk you through how to share the results with your team in a way that lands as support rather than a telling-off – we’ve done this a lot.
The simulation runs for seven days, so you get a genuine picture rather than a single morning’s snapshot.
What you get
A written report, in plain English
What we found, what it means for your business, and what we’d suggest doing about it – ordered by what matters most, not by what’s most technical. Written so you can hand it to your accountant or your board and they’ll follow it.
A walkthrough with an engineer
We sit down with you – in person or on a call – and go through it properly. You ask the awkward questions, we give you straight answers. Bring whoever you like.
Recommendations you can act on without us
Some fixes take five minutes and cost nothing. We’ll tell you which those are and how to do them, whether or not you ever become a client. It’s your report – do what you like with it.
How it works
1. You ask
Fill in the form below and tick the areas you’d like covered. Two minutes.
2. A short call to agree the details
About fifteen minutes. We confirm what you’d like us to look at, sort out any access you’re happy to grant, and agree a date. Nothing starts until you say so.
3. We do the work
Quietly, in the background. Nothing we do interrupts your team or takes anything offline.
4. Your report, within three working days
Then we book the walkthrough. If you’ve included the phishing simulation, the full team results follow after seven days.
Request your assessment
Tick the areas you’d like us to look at. You can change your mind on the call, and nothing runs until you’ve agreed it.
It takes about two minutes. We’ll come back to you within one working day.
Questions people ask
Anything else you’d like to know, just ask – we’d rather answer it now than have you wondering.
Is this just a sales pitch?
Fair question, so here’s the honest answer. We do it because businesses who see clearly what’s exposed often decide they’d rather not manage it alone – and when they want a partner, we’d like to be on the list. That’s the whole commercial logic, and we’re not going to pretend otherwise.
What it isn’t: a report engineered to frighten you, or a document that stops short of anything useful until you sign something. You get the findings, you get the recommendations, and you get them in enough detail to act on with your existing IT person if that’s what suits you. No pressure follow-up, and one call from us afterwards to ask what you thought – that’s it.
Do we have to give you access to Microsoft 365?
No. Every part of the assessment is opt-in, and saying no to one area doesn’t stop the others. The only consequence is what we can’t tell you: without a read-only role, we can’t check dormant accounts, admin rights, settings or licence waste.
If it helps, the role we’d ask for can read and cannot change anything – and you can revoke it yourself at any time.
Will any of this disrupt the team?
No. Nothing we do takes a system offline or interrupts anyone’s work. The scans run quietly in the background, and the only thing your team might notice is the simulated phishing email – which is rather the point.
Should we tell the team about the phishing test?
We’d suggest not. A heads-up gets you a flattering result rather than a true one, and a flattering result protects nobody.
Nobody gets named and shamed. The point is finding out where a bit of training would help most, and we’ll help you share the results in a way that lands as support rather than a telling-off.
What does it cost?
Nothing. There’s no charge, no tie-in, and no obligation to buy anything afterwards. The report is yours to keep whatever you decide to do next.
How long does it take?
Your report lands within three working days of us starting. If you’ve included the phishing simulation, the full team results follow after seven days – that’s how long we run it for, so you get a genuine picture rather than a single morning’s snapshot.
Not ready to fill in a form?
Perfectly reasonable. Give us a call and ask whatever you like – including “is this actually worth doing for a business our size?” We’ll tell you honestly.
Engineers in Bournemouth, not Bangalore. Real people, on the end of a phone.