IT Security · Compliance

Hackers love your client data. Let's ruin that for them.

When a client asks how their data is protected, “we think it's fine” isn't an answer. We give your practice a documented, defensible one, with cyber security run as the whole job, not a side service.

Kip, the Worktopia koala, beside a padlocked shield
What you're up against

The quiet ways firms get breached.

It's rarely a hooded genius at the door. It's a reused password, a device nobody manages, a convincing invoice email. Each one is ordinary, and each one is fixable.

!The threat
A convincing invoice email
Our defence
Enforced MFA and mail filtering, so a stolen password alone gets nobody in and dodgy mail rarely lands.
!The threat
Ransomware locks the files
Our defence
Tested, isolated backups, so “restore from this morning” is a real option, not a hope.
!The threat
An unpatched laptop at home
Our defence
Every device managed through Intune and patched automatically, so home kit isn't the weak link.
!The threat
Everyone knows the Xero login
Our defence
Credentials masked through Keeper, so staff log in from managed devices and can't carry passwords home.
Our security baseline

Locked down from day one, not upsold later.

These aren't premium add-ons. They're the standing baseline on every firm we look after, in place before there's ever an incident to talk about.

Enforced MFA
Multi-factor across email, Xero and every core system, no exceptions.
Automated patching
Operating systems and apps kept current, so known holes get closed fast.
Tested backups
Isolated, regularly restored copies, so recovery is proven, not assumed.
Managed devices
Every laptop enrolled in Intune, encrypted and wipe-able if it walks.
Controlled access
You decide who gets into what, from which device, and offboarding is instant.
A posture you can show
Documented controls to put in front of a board, an insurer or a client.
Where to next

Three ways in, depending on what you're being asked for.

The frameworks share most of their controls, so work done for one counts toward the other. Start wherever the pressure is coming from.

Framework & uplift
Essential Eight
The ACSC baseline that tenders and insurers still name, with a maturity level that suits your firm. We score it, then close the gaps.
Essential Eight and uplift →
Framework & uplift
SMB1001
Built for firms your size, with tiers from Bronze to Diamond. We do the uplift and can facilitate certification with CyberCert.
SMB1001 and uplift →
Ready to adopt
IT policies
Templated policies including the clauses generic templates leave out, adopted in a few clicks and signed digitally by your staff.
See the policies →
Ongoing oversight

Know where you stand, not where you stood.

A report tells you about the day it was written. Your Compliance Portal keeps scoring your posture from the systems we already run for you, so when a control slips it shows up rather than waiting for the next review.

See your live status →
A live score per framework
Your maturity level and tier, on screen, not in a PDF from March.
Evidence with a timestamp
Every source shows when we last looked at it, so nothing quietly goes stale.
History, so you can show progress
Useful at renewal, and when a client asks what changed since last year.
Common questions

Cyber security, without the fear talk.

Aren't we too small to be a target?
Small firms are targeted precisely because attackers expect weaker defences and you hold rich client financial data. Automated attacks don't check your headcount first.
We moved to the cloud, aren't we covered?
The cloud doesn't decide who can log in, from which device, or what staff paste into a chatbot. Those controls are yours to set, and that's the work we own.
Will security get in the team's way?
Done well, staff barely notice it. Masked logins and managed devices mean people sign in and work as normal, the guardrails just sit quietly underneath.
Do we need the Essential Eight?
It's fast becoming the expected baseline for firms handling client data, and increasingly what insurers and clients ask about. We align you to a sensible maturity level and keep you there.
Do we have to be certified?
No. Certification is issued by an accredited body, never by us. We get the controls in place and keep the evidence current, so you're ready if a client or insurer asks. For SMB1001, the lower tiers rest on your director's attestation rather than an external audit.
Which framework should our firm work to?
Most firms start with the Essential Eight, because that's what tenders and insurers name. SMB1001 then gives you tiers to show progress against. The two share most of their controls, so it isn't double the work.
How do we know it's still true next quarter?
Your portal keeps checking. Controls are assessed against your live environment and stamped with when we last looked, and your maturity is snapshotted over time so you can see the direction of travel.
Related reading
The Xero login problem nobody talks about.
Read →
Related reading
The Essential Eight, explained for accounting firms.
Read →
Kip, the Worktopia mascot, holding a coffee

Know where your security stands.

Book a strategy call and we'll walk your firm's posture with you, no jargon, no scare tactics, just a clear read on where you are and what's worth doing next.