Start with the truth
Every engagement starts with an audit, because you cannot defend what you have not inventoried. We look at who has access to what, what is exposed to the internet, what has not been patched, whether your backups would actually survive an attacker with your admin password, and how your email is authenticated.
You get a register in plain English: the risk, the likelihood, the cost of fixing it, ranked. No 200-page PDF that nobody reads.
Then close the doors that matter
Most compromises in businesses this size come through a small number of doors: a phished credential with no MFA behind it, an unpatched internet-facing service, a shared admin password, or a backup an attacker could reach and delete.
We close those first, because that is where the actual risk lives — not in the exotic threats that make better conference talks.
Then watch
Monitoring on endpoints and infrastructure, alerts that go to a human, patch management that happens on a schedule instead of when someone remembers. And an incident response plan written on a calm day, so the bad day has a script.
What we will not do
Sell you a product you don't need. Most of what makes a business this size secure is configuration and discipline, not another licence.