Security for a mid-sized company is mostly hygiene done consistently: who has access to what, whether you can restore, whether anyone would notice an intrusion, and what happens in the first hour if something goes wrong.
The practical programme
- Access review: accounts, admin rights, shared passwords, and the ex-employee who still has a VPN profile.
- Multi-factor authentication where it matters, rolled out without stopping the business.
- Backups that are isolated from the systems they protect, and a restore test with a date on it.
- An incident plan with names and phone numbers, rehearsed at least once.
If you need to satisfy a customer audit or an ISO 27001 questionnaire, we prepare the evidence alongside the technical work rather than as a separate paper exercise.