Cyber security services

Find the risk. Show the evidence. Fix what matters.

Defined assessments and implementation support for businesses that need clear, practical cyber security work. Every engagement begins with agreed scope, authorisation, access requirements and safe testing boundaries.

Not sure what to request?

Explain the concern in plain English. We will identify a sensible starting point and confirm what is included before work begins.

Use the service finder
01

Assess

Cyber Security Health Check

A broad starting assessment with an evidence-backed, prioritised action plan.

Review areas

  • Accounts, MFA and privileged access
  • Patching, devices and backups
  • Sharing, recovery and exposed services

Deliverables

  • Findings register
  • Risk summary
  • Prioritised action plan
  • Client walkthrough

Best for

Businesses that need to understand their current position before commissioning deeper technical work.

Boundaries

Not certification, legal advice, emergency incident response or an unrestricted penetration test.

02

Technical security

Vulnerability & Network Security Assessments

Authorised technical review with validation, evidence and realistic remediation guidance.

Review areas

  • Internet-facing systems and services
  • Website configuration and common weaknesses
  • Devices, ports, firewall rules and segmentation
  • Patch and configuration exposure

Method

  • Written authorisation
  • Defined targets and exclusions
  • Safe discovery and validation
  • Evidence handling rules

Deliverables

  • Technical findings
  • Business impact
  • Risk priority
  • Remediation plan

Boundaries

Testing is limited to the authorised scope. High-risk exploitation, social engineering and destructive testing are excluded unless expressly agreed and suitable.

03

Cloud workspace

Microsoft 365 & Google Workspace Security Review

Reduce risk around identity, administrator access, user lifecycle and file sharing.

Review areas

  • MFA and recovery methods
  • Administrator and privileged roles
  • Starters, movers and leavers
  • External sharing and forwarding

Additional checks

  • Third-party application access
  • Audit and security settings
  • Shared accounts and ownership
  • Available logging

Deliverables

  • Access findings
  • Risk and ownership gaps
  • Configuration recommendations
  • Remediation priorities

Optional support

Approved improvements can be completed with your administrator or existing IT provider under a separate implementation scope.

04

Readiness

Incident, Essential Eight & Sensitive Data Readiness

Prepare the people, evidence, controls and decisions needed when risk becomes real.

Incident readiness

  • Roles and escalation
  • Containment and evidence checklist
  • Communication and recovery steps
  • Tabletop walkthrough

Essential Eight

  • Evidence review
  • Observed alignment and gaps
  • Implementation dependencies
  • Uplift roadmap

Sensitive data

  • Data locations and access
  • Sharing and suppliers
  • Retention and offboarding risks
  • Breach readiness

Important

Readiness services do not provide formal certification, legal opinions or privacy-law sign-off.

05

Visibility

Security Logging & Monitoring Setup

Improve visibility by identifying useful logs and configuring practical dashboards and alerts.

Inputs

  • Available systems and log sources
  • Business-critical accounts and events
  • Retention and access requirements

Setup support

  • Log source planning
  • Centralised collection guidance
  • Basic dashboards and alerts
  • Validation events

Outputs

  • Logging map
  • Alert rationale
  • Operating instructions
  • Known visibility gaps

Boundary

This is setup and readiness support, not a staffed 24/7 security operations centre or guaranteed threat detection service.

06

Improve

Remediation, Policies & Ongoing Support

Turn agreed findings into controlled improvements without losing ownership or accountability.

Remediation

  • Priority implementation plan
  • Configuration and access support
  • Vendor or IT-provider coordination
  • Progress and closeout notes

Documents

  • Access and MFA
  • Acceptable use and devices
  • Incident response
  • Backups, remote work and data handling

Ongoing support

  • Action tracking
  • Access and sharing hygiene
  • Register and policy maintenance
  • Management summaries

Related capability

Secure website development, maintenance and authorised website security review remain available as defined project work.

Authorisation is mandatory.

Lateral Cyber does not test systems without written permission. Scope, access, evidence handling, exclusions and deliverables are confirmed before technical work begins.

Discuss your requirements