Insights / from the people who do the work

Guidance on IT, cyber security and compliance

Practical writing on the technology you have to be able to trust: what a standard checks, what a control does, and what we would do in your position, from the team that runs, secures, builds, and proves it every day.

Written byA named, certified team
AcrossAll four disciplines
ForOperators, not algorithms
How we write
First handFrom the work SourcedEvery figure named to its source DirectStates what changed, and what it means
Insights / Latest

Writing worth your time.

Every piece attaches to one of our four disciplines. These are the questions our clients ask, answered the way we would answer them across the table.

Latest
Cyber Security

DCC vs Cyber Essentials

Cyber Essentials is not an alternative to Defence Cyber Certification, it is part of it. How the two relate, and the order to do them in.

Cyber Security

DEFCON 658 explained

DEFCON 658 brings the Cyber Security Model into your MOD contract and makes you flow it down to subcontractors. What it requires, and what to do first.

Cyber Security

Def Stan 05-138 explained

What Defence Standard 05-138 requires, how Cyber Risk Profile levels 0 to 3 decide which controls apply to you, and how it connects to DEFCON 658 and DCC.

Governance and Audit

Technology due diligence checklist (UK)

A UK technology due diligence checklist for PE deal teams and advisers: the six areas to examine and the custom-software question most reports miss.

Managed IT

Boutique vs large MSP: which is right for a regulated SME?

Boutique or large MSP for a regulated SME? How the two compare on accountability, senior access, security depth, out-of-hours cover and price.

Cyber Security

How much does Cyber Essentials cost?

What Cyber Essentials and Cyber Essentials Plus really cost in the UK: the certification fee, the work to get ready, and how to keep the spend sensible.

Cyber Security

Cyber Essentials Requirements

The five Cyber Essentials controls explained, and why Cyber Essentials Plus requirements are the same five controls verified differently rather than a longer list.

Cyber Security

EDR vs MDR vs XDR vs SOC vs MSSP

EDR, MDR, XDR, SOC and MSSP explained: what each one does, how they differ, and which one a business of your size needs.

Software and AI

What the July 2026 Microsoft Copilot changes mean

From 1 July 2026 Microsoft bundles Copilot into Microsoft 365 Business plans and raises the standalone price. What it means for your business, and what to do.

Software and AI

How much does Microsoft Copilot cost?

Microsoft Copilot pricing after the July 2026 changes: bundled Business plans with Copilot versus the standalone licence, and how to choose what fits.

Software and AI

Is Microsoft Copilot safe for business?

Whether Microsoft Copilot is safe for business depends on your Microsoft 365 permissions and data. The risks that matter, and how to address them first.

Software and AI

Microsoft Copilot security

The Microsoft 365 controls to put in place before you switch Copilot on: oversharing, sensitivity labels, DLP, identity and conditional access.

Managed IT

How much does business backup and disaster recovery cost?

What drives business backup and disaster recovery costs: data volume, cloud versus on-premises, Microsoft 365 backup, and your recovery targets.

Governance and Audit

The NCSC Cyber Assessment Framework self-assessment, a practical guide

How the NCSC Cyber Assessment Framework self-assessment works: the four objectives A to D, and where it overlaps ISO 27001, explained plainly.

Cyber Security

Cyber Essentials or ISO 27001: which does your business actually need?

Cyber Essentials or ISO 27001? A plain comparison of cost, scope, time, and how to read the contract clause that decides which your business needs.

Cyber Security

How to prepare for Cyber Essentials Plus

The five Cyber Essentials Plus controls, what the assessor checks on the day, and the common blockers – so you pass first time, not on a resit.

Cyber Security

Cyber Essentials for defence suppliers: Def Stan 05-138, DEFCON 658 and the supply chain

DEFCON 658 requires Cyber Essentials for MOD supply chain contracts. What it means, who it applies to, and how to certify – from a certification body.

Cyber Security

How much does ISO 27001 cost?

ISO 27001 certification cost and price explained: body fees, internal effort, consultancy, plus surveillance and recertification. Indicative UK ranges.

Managed IT

How much should managed IT cost? A plain guide to UK pricing models

UK managed IT pricing explained: per-user and fixed monthly models, what drives the cost, and how it scales from small teams to organisations of 600+.

Software and AI

How to stop staff leaking data to ChatGPT and AI tools

How to stop staff leaking company data into ChatGPT and AI tools: an acceptable use policy, sanctioned tools, Microsoft 365 DLP and sensitivity labels, training.

Cyber Security

Why businesses fail Cyber Essentials Plus, and how to pass first time

Why businesses fail Cyber Essentials Plus, from unpatched systems to multi-factor authentication gaps, and how to close them before the assessment.

Insights / Explore

Read by discipline.

Everything we write maps to one of the four things we do. Follow a topic through to the service behind it.

01Run it

Managed IT

Cost, switching, Microsoft 365, and getting the most from what you already pay for.

See Managed IT
02Secure it

Cyber Security

Cyber Essentials, ISO 27001, ransomware resilience, and what defence looks like beyond a certificate.

See Cyber Security
03Build it

Software and AI

Applied AI with governance, build versus buy, and software made for how you work.

See Software and AI
04Prove it

Governance and Audit

Def Stan 05-138, the CAF, audit readiness, and the evidence regulators ask for.

See Governance and Audit

Reading is good. Talking is better.

If a piece raised a question about your own setup, ask us. Book a consultation or start with a no pressure audit.

Reading, Berkshire  /  reply within one working day