(Cybersecurity)
Cybersecurity for companies that do not have a security team
Between a laptop policy nobody reads and a full security operations centre there is a practical middle. Cybersecurity work here means fixing the handful of things that account for most real incidents.
(What goes wrong, in practice)
Almost nothing starts with a clever exploit. It starts with a password reused on a site that was breached, an administrator account that outlived the administrator, a storage bucket someone opened for an afternoon in 2022, or an invoice email that looked exactly right. Close those four routes and the picture changes considerably.
This is continuous work, unlike a penetration test. A test is a photograph of one system on one day; posture is what your organisation looks like every day after that.
(What we deliver)
Cybersecurity services we provide
Most engagements open with a review, because arguing about priorities without one wastes money. What follows is drawn from your own findings list.
-
A structured look at identity, devices, cloud configuration, data, suppliers and backups, measured against the CIS benchmarks and what your own risk actually is. You get a findings list ordered by exposure removed per day of effort, with quick wins marked.
-
Single sign-on, enforced multi-factor authentication, conditional access, and a joiners-movers-leavers process that actually removes accounts. Shared logins get replaced, standing administrator rights get cut back, and privileged access becomes something granted for a task rather than held permanently.
-
Disk encryption, patch enforcement, screen locks and managed profiles through Intune or Jamf. In the cloud: public access blocked by default, least-privilege IAM, key rotation, logging switched on and kept, and configuration drift picked up rather than discovered later.
-
Logs centralised somewhere searchable, alerts on the events that matter — impossible travel, new administrators, disabled logging, mass downloads. Alongside that, a written incident plan naming who decides, who calls the regulator and who talks to customers.
-
Mapping what personal data you hold, where it sits, who can reach it and how long you keep it. Retention rules, subject access request handling, processor agreements and breach notification steps — working to GDPR as a practice, documented so a regulator can follow it.
-
Short, specific sessions for the teams most targeted — finance, HR, support — using real messages rather than generic slides. Simulated phishing runs to establish a baseline, then again later. Nobody is named or shamed; the point is the trend and the reporting habit.
(Platforms and frameworks)
- 01Microsoft Entra ID and Intune
- 02Google Workspace admin
- 03Okta and Jamf
- 04AWS IAM, GuardDuty, Security Hub
- 05Azure Defender and Sentinel
- 06CIS benchmarks
- 07CIS Controls v8
- 08GDPR and UK data-protection practice
- 091Password and HashiCorp Vault
(How we work)
How the security work is sequenced
Five stages, running as a cycle rather than a project. The first pass takes a few weeks; after that it becomes a quarterly rhythm.
-
01
Review
Interviews, a walk through your cloud and identity consoles, a look at devices, backups and supplier access. The output is a findings register with severity, effort and owner against each line, not a slide deck.
-
02
Prioritise
A session with you to sort findings into this month, this quarter and accepted risk. Accepting a risk knowingly is a legitimate answer, and writing it down is what makes it defensible later.
-
03
Fix
Implementation of the agreed items: identity tightened, hardening applied, logging turned on, backups tested by an actual restore. Each change comes with a note of what it altered, so nothing surprises your users.
-
04
Monitor
Alerting configured and tuned until it is quiet enough to be believed, with a runbook per alert type. Somebody has to know what to do at two in the morning, and it should not be improvised.
-
05
Rehearse
A tabletop exercise on a plausible scenario — ransomware on a file server, a compromised finance mailbox. Gaps found in the rehearsal are cheap; gaps found during the incident are not.
(Why Team of Keys)
How we approach security posture
Security spending drifts towards whatever is easiest to buy. The aim here is to spend it where your actual exposure is, and to leave your team able to hold the line without us.
-
01
Proportionate to what you are
A thirty-person firm does not need an enterprise security programme. It needs managed identity, encrypted devices, tested backups, patching and a plan for the phishing email that will eventually work.
-
02
Nothing that stops people working
Controls people route around are worse than no controls, because they hide the real behaviour. Changes are rolled out with the teams affected, and anything that adds friction has to justify it.
-
03
Backups proven by restore
Backups are the last line and the least tested. Part of every engagement is restoring something real and timing it, so your recovery estimate is a measurement rather than a hope.
-
04
Documented for your auditor
Policies, registers and evidence are written as the work happens. Team of Keys holds no certification itself; what you get is the material your own auditor or customer will ask to see.
-
05
Handover, not dependency
Consoles stay in your tenancy, runbooks are yours, and your IT lead is taught to run the quarterly review. Keep us on retainer because it is useful, not because nobody else can operate it.
(Related)
More in quality & security
(FAQ)
Questions, answered
A posture review for a company of twenty to a hundred people is a fixed price and takes one to two weeks. Remediation is quoted from the findings, so you see the cost per item before committing. Ongoing monitoring and quarterly reviews run as a monthly retainer sized to your estate rather than to headcount.
A penetration test examines one system deeply on one day and tells you what could be broken into. Posture work covers the whole organisation — accounts, devices, cloud, suppliers, people — and keeps covering it. Most clients need the posture work first; the test then proves the specific application holds up.
It provides most of the tools, though the defaults leave gaps. Typical findings are multi-factor authentication enforced for some users but not all, legacy authentication still enabled, no conditional access, audit logging retained for too short a period, and unmanaged personal devices reaching company mail. Fixing those uses licences you already pay for.
Ring the number in your incident plan. For retained clients we help contain it — isolating accounts and devices, preserving logs, working out what was reached — then support the notification decisions, including the seventy-two hour GDPR clock. Afterwards you get a written post-incident review with the changes that stop a repeat.
Yes, and it is a common first job. We go through the questionnaire with you, answer what is true today, and turn the gaps into a remediation plan with dates you can share honestly. Fabricating an answer to close a deal creates a contractual problem later, so we will not do it.
(Global presence)
Nine countries, one studio behind them.
Every project is designed, built and shipped from one studio.
Turn the globe, or pick a country to see what we deliver there.
NoidaDrag to turn
Studio · Noida, India · --:--
(Next step)
Start with a posture review
Tell us roughly how many people, what cloud you run on and what data you hold. You get a scope, a fixed price and a findings list you can act on.
START
