Security & foundations
Focused · fixed scope / retained
Security foundations · scope agreed in discussion, fixed outcome.
For a growing SME when customer security questions, unmanaged devices, shadow AI or inconsistent access start to slow sales and delivery. Scope is agreed in discussion: a focused foundations engagement producing a prioritised risk register, a managed-device and access baseline, AI governance and shadow-AI detection, and an evidence plan for Cyber Essentials Plus or customer assurance.
Typical scope
- Identity, SSO and access lifecycle
- Endpoint and device management
- Cyber Essentials Plus and ISO 27001
- Security tooling and operations
- AI governance & shadow-AI detection
Not sure whether this fits? A short call clarifies scope and timing.
Discuss Security & foundations