Everything required to hold the line.
From the first external assessment to standing managed defence, every service below exists for one purpose: keeping your clients' information exactly where they believe it is. Scoped to your practice. Priced to your risk profile. Never off the shelf.
External Security & Exposure Assessment
The engagement most client relationships begin with: a rigorous, adversary's-eye examination of how your firm looks from the outside — conducted without touching your internal systems, and delivered as a board-grade dossier under its own unique reference.
- Domain & email authentication posture. Whether your name can be borrowed to defraud your clients — the single most exploited weakness in professional services.
- Infrastructure hygiene. DNS configuration, mail routing, certificate and platform signals — 400+ technical checks across your external estate.
- Credential & breach exposure intelligence. Your staff's credentials searched across breach corpora and infostealer collections spanning multiple years of compromise data.
- Dark web presence review. Mentions, listings and artefacts associated with your firm in the places you cannot look yourself.
- Severity-ranked dossier with immediate containment actions. Findings your own team can act on the same day, plus a clear remediation direction for everything else.
The full discipline, à la carte or as a programme.
Most clients begin with the assessment and build from there. Each line below can stand alone or combine into a standing programme under our managed care.
Email & Domain Security Hardening
Enforcement of modern email authentication so no one can send as you — the definitive countermeasure to invoice fraud and client impersonation.
- Authentication policy design & enforcement
- Spoofing & impersonation prevention
- Deliverability protected throughout
Credential & Dark Web Exposure Monitoring
Standing surveillance of breach corpora, infostealer markets and dark web sources for your people and your brand — with alerts when something new surfaces.
- Staff credential exposure watch
- Brand & domain abuse monitoring
- Actionable alerting, not noise
Advanced Threat Monitoring
Endpoint and gateway telemetry watched continuously on our own sovereign infrastructure, with AI-assisted triage separating genuine threats from background noise before they reach your desk.
- Endpoint & gateway surveillance
- Intelligent event triage
- Escalation with clear next actions
Incident Response & CSIRT
A dedicated Computer Security Incident Response capability: containment playbooks rehearsed in calm weather, forensic preservation when it matters, and POPIA Section 22 notification readiness for the Regulator and affected data subjects.
- Response & containment playbooks
- Regulatory breach-notification readiness
- Tabletop rehearsal with principals
Cyber Risk & Compliance
Security obligations translated into practice: gap review against POPIA's safeguarding conditions, policy frameworks, and support for your Information Officer function.
- POPIA security-safeguard gap review
- Policy & procedure frameworks
- Information Officer support
Penetration Testing
Controlled offensive testing against your defences, scoped and authorised in writing. We attempt what an adversary would, then hand you the route they would have taken — before they take it.
- Scoped, authorised, fully documented
- External and application-facing testing
- Findings ranked by exploitability
Firewall & Endpoint Management
Default-deny perimeter policy and hardened endpoints, managed continuously rather than configured once. Every device that touches your client files brought to a known standard and kept there.
- Default-deny inbound with logging
- Endpoint hardening & ransomware controls
- Managed remotely, no downtime
Security Awareness & Phishing Resilience
Your people, trained on the attacks actually aimed at firms like yours — measured, sector-specific, and free of the generic tick-box theatre.
- Sector-specific awareness training
- Controlled phishing simulation
- Measured improvement over time
VPN Solutions
We provide VPN solutions that give your people private, encrypted access to the systems they need — from home, from a client site, or from anywhere their work takes them.
- Encrypted remote access for staff
- Secure site-to-site connectivity
- Managed, monitored and kept current
Custom Security Builds
Not every requirement fits a service line. Because we build our own infrastructure, assessment engine and AI core rather than reselling someone else's, we can engineer to your specification across any aspect of cyber security — and we regularly do.
Bespoke work begins the same way every engagement does: a confidential conversation about the problem, an honest view on whether it should be built at all, and a written scope before anyone starts. What we build for you remains configured to your environment, documented, and supported by the people who wrote it.
- Purpose-built controls — where an off-the-shelf product does not fit your workflow or your obligations
- Integration with what you already run — practice management, case, clinical or logistics systems
- Bespoke reporting and dashboards — built to the format your board, insurer or regulator expects
- Hardened environments — designed around a specific risk, jurisdiction or client mandate
Packages shaped by your obligations.
The threats, regulations and client expectations of each profession are different — so the programmes are too. Each combines assessment, hardening, monitoring and readiness into standing care for your sector.
For Law Firms
Protection engineered around privilege: correspondence integrity, matter-file confidentiality, trust-account payment security and impersonation defence for fee earners whose names are on the letterhead.
Privilege · Trust accounts · ImpersonationFor Healthcare Providers
Built for the higher duty that comes with health information — special personal information under POPIA — across practices, clinics and specialists: records confidentiality, staff credential vigilance and breach-notification readiness.
Patient records · POPIA s26 · ReadinessFor Financial & Accounting Firms
Defence for the sector fraudsters impersonate most: payment-instruction integrity, client financial-data confidentiality, and continuous exposure monitoring for the credentials that unlock everything.
Payment integrity · Client data · CredentialsOutside these sectors? Programmes are composed per practice — tell us what you hold, and we will shape the protection around it.
Scoped to your practice.
Priced to your risk profile.
No two firms carry the same exposure, so we publish no rate card. Every engagement is scoped after a confidential conversation about your practice's size, sector and regulatory posture — and quoted in writing before any work begins. Whatever the scope, it runs on the same foundation: our own purpose-built infrastructure and proprietary AI core, applied with senior-led discretion from the first call.