Risk audit and assessment
External and internal vulnerability scanning, configuration review, identity and access review, and a prioritised remediation plan you can budget against.
The businesses that get hurt are rarely the ones without security products. They are the ones where nobody was watching the alerts, the firewall rules had grown organically for six years, and the backup had been failing silently since March.
COREQ approaches security in the order that actually reduces risk: find out what is exposed, fix the cheap and obvious things first, then put monitoring in place so the next problem is caught while it is still small.
Final scope is confirmed after a site survey and issued in writing before work begins.
External and internal vulnerability scanning, configuration review, identity and access review, and a prioritised remediation plan you can budget against.
Modern EDR/XDR on every laptop, desktop and server — behavioural detection, isolation of compromised devices, and rollback where the platform supports it.
Log collection and correlation with round-the-clock alert triage, so genuine incidents are escalated to a human instead of sitting in a console nobody opens.
Multi-factor authentication, conditional access, phishing protection, impersonation defence and mailbox rule monitoring.
Immutable and off-site backup copies, with documented restore procedures and scheduled restore tests — the last line of defence against ransomware.
Phishing simulation and short, practical staff training, because the majority of successful intrusions still begin with someone clicking something.
We would rather scope you correctly than sell you the largest option. If a smaller package genuinely covers your requirement, that is what we will propose.
Point-in-time review
Ongoing prevention
Continuous monitoring
Every engagement follows the same six stages. You always know which stage you are in, what has been agreed, and what is outstanding.
We visit the site, understand how you actually work, and document the existing environment before proposing anything.
You receive a written scope, a design, a bill of materials and a price — with assumptions and exclusions stated plainly.
Scheduled work with an agreed programme, minimal disruption to operations, and progress visibility throughout.
Every device tested, every interface demonstrated, and defects closed before handover rather than after.
As-built drawings, device schedules, credentials and O&M documentation handed over in a structured pack.
Ongoing maintenance, monitoring and helpdesk support under an annual contract with defined response targets.
A Security Operations Centre is the function that watches security telemetry continuously and decides which alerts matter. You need one if a breach would materially disrupt your operations or expose regulated data. If your business could absorb several days offline without serious consequence, a well-managed endpoint and email security stack may be proportionate — we will say so rather than oversell.
Signature-based antivirus catches known malware. It does not catch an attacker using stolen credentials and legitimate administrative tools, which is how most serious intrusions now progress. EDR looks at behaviour rather than file signatures, which is why it detects the activity antivirus misses.
The response procedure is agreed in advance: containment steps, who is called, in what order, and what evidence must be preserved. Having that written down before an incident is most of what separates a controlled recovery from a chaotic one.
Yes. Cyber risk auditing, review and testing is one of our licensed activities and can be engaged independently of any managed service — useful when you need an objective assessment of an environment maintained by someone else.
Fixed-fee IT support that keeps your users working — remote helpdesk, scheduled preventive maintenance and on-site engineers under one annual maintenance contract.
Read moreIP surveillance designed around what you actually need to see — correct camera selection, honest storage sizing, and a system that still works two years after handover.
Read moreControl who goes where, and know who was on site — card, PIN, biometric or mobile credential, with attendance data your HR team can actually use.
Read moreTell us what you are trying to solve. We will survey the site, put a written scope and design in front of you, and price it with the assumptions stated plainly.
Fill in four details and we will come back to you within one business day.