P2 · Protect
Firewalls & practical cybersecurity
A reused password, an unpatched device, an open remote-access port or a convincing email can expose a business. We review those everyday entry points alongside your firewalls and access controls.
01Sounds familiar?
Practical cybersecurity means dealing with those likely risks first: a properly configured firewall, multi-factor authentication, timely updates, sensible permissions and staff who know what to look for. We prioritise by risk and explain each decision in plain language.
- Your firewall still has its original settings, or nobody knows what its rules do.
- Staff accounts do not use multi-factor authentication.
- Former employees or suppliers may still have access to systems.
- A client, insurer or partner has asked about your security and you are unsure how to answer.
02P2 · Firewalls & security
Who it is for
Organizations without in-house security staff
Who need sensible protection set up and maintained without a dedicated team.
Teams answering security questionnaires
From clients, insurers or partners, who need accurate answers and the controls to back them up.
Organizations after a scare
A phishing attempt, a compromised account or a near miss that showed where the gaps are.
03P2 · Firewalls & security
What we deliver
Security baseline review
A prioritised list of gaps across accounts, devices, network edge, email and backups.
Firewall configuration
Rules set deliberately, remote access locked down, changes documented and reviewed.
Account security
Multi-factor authentication, least-privilege access and a joiner/leaver checklist.
Patching & device hardening
Update schedules and secure settings for computers, servers and network equipment.
Email protection
SPF, DKIM and DMARC configured to make spoofing your domain harder.
Awareness & response
Short, practical staff guidance and a written plan for who does what if something happens.
04P2 · Firewalls & security
How it usually runs
Review the baseline
We check the common entry points and rank the gaps by likelihood and impact.
Fix the likely risks first
Quick, high-value changes such as MFA and firewall rules come before larger projects.
Document decisions
What was changed, why, and what risk remains — so you can answer questions accurately.
Review regularly
Security is maintained, not finished. We schedule periodic reviews.
What we promise — and what we don’t
- No organization can be made completely secure, and we will never claim otherwise. The goal is to reduce the likelihood and impact of an incident.
- We prioritise the risks most likely to affect you, explain what each measure does, and record the risk that remains.
- We are not a 24/7 security operations centre. If you need round-the-clock monitoring or forensic incident response, we will say so and help you find the right specialist.
- We do not claim certifications or compliance on your behalf. We can help you prepare the controls and evidence those processes ask for.
Want to know where your gaps are?
Start with a security baseline review. You will get a short, prioritised list of what to fix and why.
- Personal reply
- Written next step
- No obligation