Omegaswift
Solutions

Cyber Security

We look at your systems the way somebody attacking them would, rank what we find by what it would actually cost you, and fix it in an order you can afford. Then we set up the alerts and agree who gets called at two in the morning.

How We Help

What cyber security looks like as a piece of work.

Most Break Ins Start With Something Boring

Not an exotic flaw. An admin account belonging to somebody who left, a test server still answering on a public address, a shared password living in a spreadsheet, a laptop months behind on updates. We find these on almost every audit. They survive because no one person is accountable for looking, and the only checks happening are the ones a tool does on its own.

What The Audit Actually Covers

We scan your servers and laptops with credentials rather than from the outside only, because an unauthenticated scan misses most of what matters. Then we go through the identity setup account by account: who holds admin, who holds it permanently, which service accounts have passwords that were set years ago and never rotated. We check what of yours answers from the internet against what you believe is published. Findings come back ranked by how easily each one could be used and what sits behind it. A severity score on its own does not know which server holds your customer data.

Patching, Alerts And The 2am Call

Fixing is a cadence, not a project. Critical patches inside a short agreed window, everything else monthly in a maintenance slot the business has signed off. Multi factor and conditional access go out in phases with a pilot group first, and break glass accounts stay documented and watched. For detection we send laptop, login and firewall logs into one place and write the alerts that fit your risk rather than every alert the platform ships with. Then we agree the escalation: who gets phoned at two in the morning, what they may decide on their own, and who they call next. We schedule a walk through with your leadership team instead of filing the plan, because the first read of it should not happen during an incident.

Phishing Is A Training Problem, Not A Filter Problem

Every mail gateway lets something through, and the message that gets through is the one written well enough to. So the useful measure is not how many people clicked, it is how many told somebody, and how fast. Those two numbers move for reasons that have nothing to do with software. If clicking gets a person named in a meeting, the next one who clicks will say nothing for four days, and four days is the difference between a nuisance and a rebuild. We run short simulations that take thirty seconds to fail rather than an hour of e-learning nobody finishes, publish the report rate instead of the click rate, and thank the person who reports the real one. Finance gets a rule of its own: any change to bank details is confirmed by phoning a number you already held, never the number in the message.

Backups Are A Belief Until Somebody Restores One

Nearly every company we audit has backups. Far fewer have restored one this year, and a backup nobody has restored is a belief rather than a control. The failures are ordinary. An agent stopped reporting in March and the console still shows green for everything else. The copy sits on a share reachable with the same admin credentials an attacker would take first, so it gets encrypted alongside the original. Nobody has ever timed a full restore of the file server, so the plan says four hours and the reality is two days. So we ask the business the two questions it has never been asked: how much work may we lose, and how long may we be down. Then we rehearse against those answers with a stopwatch, and keep one copy that an attacker holding your domain admin password cannot reach or delete.

What we build

The shapes cyber security work actually takes

  • Exposure audit

    Credentialed scans rather than a look from outside, an account by account walk through of who holds admin, and a check of what answers from the internet against what you believe is published.

  • Identity and access

    Multi-factor where it matters, standing admin rights replaced by elevation when needed, leavers genuinely removed, and service accounts whose passwords were set years ago rotated and scoped down.

  • Devices and patching

    Endpoint detection on every machine rather than most, a patch cadence inside a maintenance window the business has agreed, and a written list of the machines that cannot be patched and why.

  • Detection and response

    Laptop, login and firewall logs in one place, alerts written for your risk instead of every rule the platform ships with, and an escalation that names who is phoned at two in the morning.

  • Backup and restore rehearsal

    A copy an attacker holding your admin password cannot reach, and a timed restore of something that matters, because the plan says four hours right up until somebody runs a stopwatch.

  • People and phishing

    Short simulations, the reported rate published instead of the clicked rate, and a payment change rule that is a phone call to a number you already held rather than the one in the email.

How we work

How a cyber security engagement runs

  1. 01

    Find what is exposed

    A credentialed look at servers, laptops, identity and the external footprint. What comes back is routinely different from what people expected, and that gap is often the most useful finding in the report.

  2. 02

    Rank by reach, not by score

    A critical rating on a box nobody can get to matters less than a weak login on the one everyone uses. Findings are ordered by what an attacker could actually touch, and by what sits behind it.

  3. 03

    Do the cheap and the fatal first

    Multi-factor, admin rights, leavers, and a backup copy out of reach. Unglamorous controls, sequenced so the first month removes the attacks that are automated rather than aimed at you specifically.

  4. 04

    Rehearse instead of documenting

    A timed restore and a tabletop of the two in the morning call, run in daylight with the leadership team in the room. The first read of a plan should never happen during an incident.

  5. 05

    Leave it as a routine

    A cadence with a named owner, a quarterly review, and the evidence a customer questionnaire will ask for. The measure is that your own team runs all of it without us present.

Who it is for

You probably need this if

  • A customer sent you a security questionnaire

    Two hundred questions and forty you cannot answer honestly. It is a sales blocker now, and it is also a free audit written by somebody who does not work for you.

  • Nobody can say who holds admin

    Rights granted for a project three years ago and never taken back. The list nobody maintains is the list an attacker reads first, because it is the shortest route to everything.

  • The backups have never been restored

    They run nightly, the console is green, and no one has timed bringing the file server back. That makes them a belief rather than a control you can rely on.

  • You would hear about it from somebody else

    No alerting anybody reads, so first notice would come from a customer, a bank or an extortion note. Months of quiet before that call is entirely normal.

FAQ

Questions we get asked

Where should we start?

With finding out what is actually exposed, which is usually different from what people expect. The audit looks at what faces the internet, who has access to what, which accounts still work for people who left, how staff sign in, and whether the backups would survive an attack. What comes out is ordered by real risk rather than by severity score, because a critical finding on a system nobody can reach matters less than a weak login on the one everyone uses.

Is multi-factor authentication enough?

It is the single highest-value control and it is not enough on its own. It stops the commonest attack, which is a stolen password, and does nothing about a device already compromised, an over-privileged account, or a backup an attacker can reach and delete. It should be the first thing done and never the last.

What happens if we are attacked?

What decides the outcome is what was prepared beforehand: who is called, in what order, whether the backups are reachable and recent, and whether anyone has rehearsed the restore. We help write that plan and test it. During an incident the sequence is contain, understand, restore, and then write down honestly what allowed it, which is the part most often skipped.

Do we need this if we are small?

Attacks on small businesses are not targeted, they are automated, and the automation does not check your size before trying. The controls that matter most at this size are unglamorous and cheap: multi-factor authentication everywhere, patching, least privilege, and tested backups kept where an attacker who has your credentials cannot reach them.

Our team will hate multi-factor authentication. How do you roll it out without a revolt?

By spending the first month on the awkward cases rather than the majority. Start with IT and the leadership team, because an exemption granted to a director on day one becomes the one everyone asks for. Use an authenticator app with number matching rather than codes by text, which is the weakest option and the one people find most irritating. Let a known device be remembered for a sensible period, so the prompt is weekly rather than hourly. Then go looking for the real problems before they find you: the shared login on the workshop floor, the account a supplier signs in with, the person whose phone is personal and who is entitled to say so. Every exemption gets an expiry date. The revolts we have seen came from surprise and from having nobody to ask, not from the control.

What does a penetration test actually tell us?

That a competent person, given a defined scope and a fixed number of days, found these things. That is worth having and it is narrower than most buyers assume. It does not tell you whether you would have noticed: unless you asked for that explicitly, nobody checked whether your alerts fired while the tester worked, and usually they did not. It does not cover what was out of scope, which is often the supplier portal or the company you acquired and never integrated. It does not stay true either, because your estate changed the week afterwards. Read the scope before you read the findings, insist on a retest of anything you fix, and be suspicious of a quote where the work is an automated scan with a logo on the report. A report is evidence, not a programme.

Our insurer sent a forty-page questionnaire. Can you help us fill it in?

We will help, and not by ticking boxes you cannot back. Those forms have become the nearest thing many businesses have to a security standard, and the questions are narrow for a reason: multi-factor on email and on remote access, admin accounts separated from everyday ones, endpoint detection on every machine rather than most of them, backups held out of reach and tested, patching inside a stated window. An answer that overstates any of those becomes a problem at the worst possible moment, because a claim is where the wording gets read properly for the first time. So we go through it, mark honestly what is true today, and turn the rest into a plan with dates. Insurers accept in progress with a date far more readily than people expect, and the questionnaire is also, quietly, a decent free audit.

Our biggest supplier holds our customer data. What can we actually do about it?

Less than the contract implies, and more than nothing. Start by writing down which suppliers hold what, because most companies cannot produce that list, and a risk nobody has enumerated cannot be managed. Then ask for evidence rather than assurances: their most recent independent report, how they authenticate their own staff, and how quickly they will tell you about an incident. Get that notification clock into the contract in hours, since your obligation to your own customers starts when they tell you. Scope the integration, because an API key with access to everything is your exposure regardless of how careful they are. Rehearse the answer to a breach at their end, including who tells your customers. Then accept the honest limit: you cannot audit a supplier much larger than you, so what you get is terms, evidence and a thought-through exit.

What you get

What is different once the cyber security work is done

  • A findings list ranked by what an attacker could reach, not by score alone
  • Multi factor login live, and standing admin rights taken away
  • A patching cadence with a maintenance window the business has agreed
  • A named person who gets phoned at 2am, and knows what to do next

Ready to talk about your IT?

We are happy to answer any questions you have and help you work out which of our services fit your needs.