Loading…
Loading…
Where we work
On site across central Scotland from our Edinburgh base, and remotely everywhere else with visits by arrangement. Same prices wherever you are, we do not price by postcode.
On site, in person
Remote coverage, visits by arrangement

Services · Tech
Fixed fee, fixed timeline. The certification more and more UK contracts and insurers now ask for, done properly rather than fudged through the questionnaire.£1,800 to £2,500

Cyber Essentials is a UK government-backed certification that shows you have five basic technical controls in place: a properly configured firewall, secure settings on your devices, control over who can access what, protection against malware, and a handle on keeping everything updated. It is deliberately not exotic. It is the set of simple things that, done properly, stop the overwhelming majority of common attacks.
There are two levels. Cyber Essentials is a self-assessment we complete and submit for you, verified externally. Cyber Essentials Plus adds a hands-on technical audit where an assessor actually checks your systems rather than taking your word for it. Which one you need usually comes down to what a contract, tender or insurer is asking for, and we will tell you straight rather than upselling.
The important word in how we do it is properly. It is entirely possible to answer the questionnaire in a way that scrapes a pass while leaving the real problems untouched, and plenty of providers do exactly that. We fix what is actually wrong first and certify the fixed version, because the certificate is meant to mean you are safer, not just that you filled a form in cleverly.
See it work
Can you spot the fake? Click the parts of this email that look wrong.
From: Microsoft 365 <>
Subject: Your password expires today
,
Our records show your password will expire. You must verify your account .
Confirm here:
You found 0 of 5 red flags
A scripted demonstration using a made-up email. In a real phishing simulation we send safe test emails to your team and report, privately, who needs a hand.
The commercial help is immediate and concrete: more and more contracts, public-sector tenders and cyber-insurance policies now require Cyber Essentials before they will deal with you at all. Without it you are quietly excluded from work you could otherwise win. With it, a growing number of doors that were shut are suddenly open, and the certificate pays for itself the first time it wins or keeps a client.
The security help is that going through it properly closes the exact holes that ordinary attacks walk through. This is not protection against a nation-state; it is protection against the automated, opportunistic attacks that make up the vast bulk of what actually hits small businesses. Getting the basics genuinely right is unglamorous and it is also where almost all of the real-world risk reduction lives.
And it gives you a clear, honest picture of where you stand. The gap assessment at the start tells you plainly what is wrong and what it will take to fix, ranked sensibly, so even before the certificate you have something valuable: an end to guessing whether you are alright, replaced by a short list of the things that actually need doing.

Illustrative cases. Tap one to see what happened and what could have been done.
The case
A facilities firm was about to be locked out of a large public-sector framework it had bid years to reach, because the tender now required Cyber Essentials and they did not have it.
What could have been done
Running the gap assessment, fixing the handful of things genuinely wrong, and certifying inside the deadline keeps them in the running for work worth many times the cost of the certificate.
The case
A marketing agency had been helped by a previous provider to 'pass' the self-assessment by wording the answers carefully, while leaving admin rights on every laptop and updates months behind, so the certificate they held did not reflect reality.
What could have been done
Telling them plainly the certificate was hollow, fixing the actual controls and recertifying honestly is the difference between paperwork and safety. Had they been breached on the old version, the gap between the form and the truth would have been a very awkward conversation with an insurer.
Tell us what is going wrong and we will come back with a fixed price in writing, after a short scoping call. No obligation, and no jargon.
£1,800 to £2,500. We agree the exact number before any work starts, so there are no open ended day rates.
Most work of this kind is live within three to four weeks. We give you a date before we begin and tell you early if anything threatens it.
Yes. We are based in Edinburgh and work on site across the Lothians, Fife and Glasgow, and remotely across the United Kingdom.
Same service, same prices, wherever you are. On site across central Scotland and remotely across the rest of the UK.
An honest, plain-English health check of how safe your business actually is, and a clear, prioritised list of what to fix first. The sensible first step before spending a penny on security.
Find out what AI your staff are already using, what business data might be leaking into it, and whether any of it is safe, before it becomes a problem. Plain-English, no hype, no obligation.
Business phone systems that follow your team anywhere. Number porting, call routing, voicemail to email, and call recording where you need it.
Predictive, progressive and preview diallers for outbound teams. Set up, tuned, and kept compliant with Ofcom rules on abandoned calls.
Every call, meeting and voice note turned into searchable text, with summaries and actions extracted automatically. Accurate on strong regional accents.
Stop missing calls. Stop quoting at midnight.