What we do

Security and compliance

The controls themselves, and the paperwork that proves you have them. Most businesses need both, and usually discover the second one first.

What this is

Two things that are usually sold together and are genuinely different. The first is technical: stopping things happening, and noticing quickly when they do. The second is evidential: being able to show a customer, an insurer or a regulator that you take it seriously.

If a customer has just sent you a security questionnaire and you do not know how to answer it, that is the second problem, and it is the more urgent one commercially. What to do with one is a page of its own.

What is actually delivered

Endpoint detection and response on every managed device. Behavioural detection rather than signature matching, with isolation of a machine that starts acting compromised — automatically where the detection is clear-cut, and by a person where it is not, because not everything announces itself. Included as standard, not sold as a tier.

Identity protection. Multi-factor authentication properly enforced, conditional access policies that reflect how your people actually work, and administrator accounts separated from day-to-day ones. How much of this is available depends on your Microsoft licensing, and we will tell you which of it you are already paying for.

Privileged access management. Staff work without local administrator rights. This is the control that most often turns a serious incident into a minor one.

Email defence. Filtering beyond what comes built in, targeted at the phishing, impersonation and invoice-fraud attempts that actually cost money, rather than at ordinary spam. Most of what gets a business hurt arrives as an email that looks entirely reasonable, which is why this and the training above are sold and run together.

Cyber awareness training and simulated phishing. Short, regular, and measured, so you can see whether it is working rather than assuming it is. The simulations matter more than the training does: they tell you who clicks, which is the number that changes what you do next.

Password management. A managed password manager for your staff, so credentials are generated, stored and shared properly rather than reused across three sites or kept in a spreadsheet called passwords. It is available with any tier rather than being reserved for the top one, because the businesses most exposed to a reused password are rarely the ones buying the most.

Dark web monitoring. Alerting when your credentials appear in a breach or are being traded, which is usually the earliest warning you get.

Patching, tested backups and documented recovery. Unglamorous, and the three things that most often decide how bad an incident becomes.

Cyber Essentials readiness. An honest assessment of where you stand against the scheme’s requirements, what needs to change, and what it will cost, before you submit anything.

Questionnaire support. We answer what we can evidence, tell you what only you can answer, and flag the questions where a truthful answer needs work first. The first look is free; a long or complicated questionnaire, and any remediation needed before you can claim compliance honestly, is quoted as consultancy rather than absorbed.

The honest limit

Our certifications cover our systems and processes, not yours. They are a fair indication of how we will look after your environment, and they are not a substitute for you having your own. We will say so plainly to your customer if asked.

How it is charged

Through your agreement with us. The baseline controls are in the managed device charge, and the rest sits in the protection tiers — some packages include all of the above, some include part of it, and your quote says which. Readiness work for a certification, and questionnaire work beyond a first look, are quoted as projects rather than assumed.

Related

Questions people ask

A customer has sent us a security questionnaire. Can you help?
Yes, and it is one of the most common reasons businesses call us. A good deal of a typical questionnaire concerns systems we run, so we can answer those with evidence. The first look costs you nothing; a long or complicated one, and any remediation the answers turn up, is consultancy and quoted before it starts. How that works, in full.
Are you certified yourselves, or do you just help us get certified?
We hold ISO 27001, ISO 9001 and Cyber Essentials for our own systems, and you can check them independently rather than take our word for it. ISO 27001 is the audited one — an external body re-examines it every year. What we are not is a certification body. For ISO 27001 or ISO 9001 we do the technical work that makes you compliant and bring in qualified partners for the certification itself. For Cyber Essentials we can help with both the technical side and the questionnaire, and arrange the certification.
Will Cyber Essentials be enough for our insurer?
Increasingly not on its own. Insurers are asking about multi-factor authentication, backup testing and privileged access specifically. We will tell you honestly where you stand before you fill the form in.
What happens if we are breached?
Containment first: isolating what is affected so it stops spreading. Then working out how it happened, and getting you running again as quickly and as securely as we can. We will tell you what we found and what we changed. Your own incident response plan is yours — ours governs how we work, not how your business responds — and if you do not have one, that is worth a conversation before you need it rather than during.

Before you get in touch

  • How we charge What is charged per user, per device and per site, and what moves the number.
  • Service levels Response and resolution targets, and the hours they run within.
  • Certifications ISO 27001, ISO 9001 and Cyber Essentials, with the numbers to check them.

Talk to us

Twenty minutes on the phone will tell you more than any amount of reading. We will tell you honestly if we are not the right fit.

01480 570339
hello@puzzletech.co.uk

09:00 to 17:00, Monday to Friday

Send an enquiry