// independent cyber security consultancy — united kingdom

Security advice without the fear sales.

We help UK businesses understand their real risk, fix what actually matters, and prove it — in plain English, with no scare tactics and no products to push.

Plain English Reports your board can read
Vendor neutral We sell time and judgement, not kit
Fixed-price work Scoped up front, no meter running
UK based On-site across Yorkshire & remote nationwide
01

What we do

Practical, defensive security for small and mid-sized organisations.

S/01

Security posture assessment

A structured review of your systems, cloud tenancy, network and processes. You get a prioritised, costed action plan — what to fix first, what can wait, and what's fine as it is.

fixed price · 1–2 weeks
S/02

Cyber Essentials preparation

We get you ready for Cyber Essentials and Cyber Essentials Plus — gap analysis, remediation, evidence gathering and hand-holding through the assessment itself.

certification-ready
S/03

Microsoft 365 hardening

Conditional access, MFA done properly, mailbox rules audit, anti-phishing configuration and tenant baseline hardening — the settings that stop the most common real-world attacks on UK businesses.

most requested
S/04

Incident response & recovery

Compromised mailbox? Ransomware note? We help you contain it, understand what happened, recover safely and close the door it came through.

priority response
S/05

Staff awareness & phishing simulation

Short, non-patronising training sessions and measured phishing simulations. Your people are the control that matters most — we make them harder targets.

people-first
S/06

Ongoing advisory (vCISO)

A retained security lead without the salary: quarterly reviews, policy upkeep, supplier due diligence, and someone to phone before you sign anything.

retainer
02

How an engagement runs

Every project follows the same honest shape.

  1. 01

    Scope

    A free call to understand your setup and what's worrying you. If we're not the right fit, we'll say so and point you somewhere better.

  2. 02

    Assess

    We look at the evidence — configurations, policies, backups, the lot — rather than running a scanner and printing the output.

  3. 03

    Report

    A short written report ranked by real-world risk, with costs and effort estimates. No 90-page PDF of red boxes.

  4. 04

    Fix & verify

    We remediate with you or your IT provider, then re-test to prove the gaps are actually closed.

03

Who you're dealing with

CYBER is the security consultancy arm of a working UK managed services practice — people who run networks, phone systems and Microsoft 365 tenancies every day, not auditors with a checklist.

That matters because most security advice fails at the practical step: the recommendations are right in theory and impossible in your actual environment. We've administered the systems we're securing, so our advice survives contact with reality.

We work with owner-managed businesses, professional practices, charities and schools — organisations big enough to be a target and small enough not to have a security team.

04

Start a conversation

Tell us roughly what's on your mind — a sentence is plenty. We reply within one working day.

No mailing lists, no follow-up sequences. Your details are used to reply and nothing else.