Loading…
Loading…
Where we work
On site across central Scotland from our Edinburgh base, and remotely everywhere else with visits by arrangement. Same prices wherever you are, we do not price by postcode.
On site, in person
Remote coverage, visits by arrangement

Services · Tech
Senior security thinking on a retainer, and the evidence to go with it. Cyber Essentials is now treated as the starting line, not the finish, and buyers increasingly want proof the controls still work.£1,200 to £4,000/month

A CISO is a Chief Information Security Officer, the senior person whose whole job is deciding how an organisation stays secure and proving it. Large companies employ one; a business of your size cannot justify the salary and does not need someone full time. A virtual CISO gives you that seniority on a retainer: scheduled, senior security thinking each month, without the six-figure hire.
The continuous compliance half is the shift the market has made. Cyber Essentials, and security in general, used to be a once-a-year scramble: certify, relax, panic again twelve months later. Buyers and insurers no longer accept that. They increasingly want evidence that your controls are working now, not that they passed an audit last spring. Keeping that evidence current, all year, is a job in itself, and it is the one this covers.
In practice you get planned senior time rather than an on-call promise we could not honestly staff. Each month we work through your risks, keep the register and policies current, own the security questionnaires that arrive with tenders and renewals, and give you reporting a board or a big customer can actually read. It is the security leadership a growing business needs, sized to a growing business.
See it work
This invoice email is a fake. Click the parts that should stop you before you pay it.
From: Thistle Office Supplies <>
Subject: Invoice INV-20482, payment due
Hello,
Please find this month's invoice attached. Also, .
Sort code 04-00-72 · Account 51873326
Please note, .
.
You found 0 of 5 red flags
A scripted demonstration using a made-up invoice email. Invoice fraud is one of the costliest scams a small business faces, because it targets a payment you were going to make anyway.
The commercial help is that it unlocks bigger customers. The larger the client, the more likely their procurement asks searching security questions before they will sign, and a confident, evidenced answer is often what separates you from a competitor who cannot give one. Having someone senior who owns those answers turns security from a blocker on winning work into a reason you win it.
The risk help is that someone is finally thinking ahead rather than reacting. Most small-business security is a series of fixes after something went wrong or a customer demanded it. A virtual CISO does the unglamorous, valuable work of looking at where you are exposed before it becomes an incident, and steering spend toward what actually matters rather than whatever was last in the news.
And it keeps you continuously ready instead of periodically panicked. When the evidence, the policies and the risk picture are kept current all year, the audit, the insurance renewal and the big customer's questionnaire stop being fire drills. You are simply ready when they land, which is calmer, cheaper, and a far better look to the people deciding whether to trust you.

Illustrative cases. Tap one to see what happened and what could have been done.
The case
A software firm kept losing days every time a prospect sent a lengthy security questionnaire, scrambling to answer questions nobody owned, and often stalling deals in the process while procurement waited.
What could have been done
Having someone senior own the security posture and keep the evidence current all year turns those questionnaires from a week of panic into a same-day return. Deals that stall on slow, uncertain answers tend to close once the answers are confident and quick.
The case
A critical system had quietly drifted out of the state its Cyber Essentials certificate claimed. Left until recertification, or worse until a big client's auditor found it, it would have been an awkward, trust-damaging conversation at exactly the wrong moment.
What could have been done
Routine monthly security work catches the drift months early, fixes it quietly and updates the evidence, so a serious problem becomes a non-event nobody outside the business ever hears about. Continuous checking beats the once-a-year scramble.
Tell us what is going wrong and we will come back with a fixed price in writing, after a short scoping call. No obligation, and no jargon.
£1,200 to £4,000/month. We agree the exact number before any work starts, so there are no open ended day rates.
Most work of this kind is live within three to four weeks. We give you a date before we begin and tell you early if anything threatens it.
Yes. We are based in Edinburgh and work on site across the Lothians, Fife and Glasgow, and remotely across the United Kingdom.
Same service, same prices, wherever you are. On site across central Scotland and remotely across the rest of the UK.
An honest, plain-English health check of how safe your business actually is, and a clear, prioritised list of what to fix first. The sensible first step before spending a penny on security.
Find out what AI your staff are already using, what business data might be leaking into it, and whether any of it is safe, before it becomes a problem. Plain-English, no hype, no obligation.
Business phone systems that follow your team anywhere. Number porting, call routing, voicemail to email, and call recording where you need it.
Predictive, progressive and preview diallers for outbound teams. Set up, tuned, and kept compliant with Ofcom rules on abandoned calls.
Every call, meeting and voice note turned into searchable text, with summaries and actions extracted automatically. Accurate on strong regional accents.
Stop missing calls. Stop quoting at midnight.