Security Foundations Review

Get the basics right.
Know what comes next.

A rapid, Cyber Essentials-aligned review for small and growing organisations that need a clear view of immediate exposure and a practical plan to strengthen the controls every business should rely on.

Request a foundations review ↗

Who it is for

Security matters. A large internal team is not realistic.

01Responsibility sits with an owner, operations lead or generalist IT manager

02Cyber Essentials, insurance or customer assurance is approaching

03Microsoft 365 and outsourced IT have grown without a joined-up security view

04The business needs priorities before committing to more technology

What we review

Essential controls.
Business context.

The review uses Cyber Essentials as a practical baseline and extends the conversation where email, cloud services, backup and ownership materially affect the outcome.

01

Business context and critical services

02

Accounts, passwords and administrator access

03

MFA and access controls

04

Laptops, servers and mobile devices

05

Secure configuration and patching

06

Malware and endpoint protection

07

Firewalls, internet and remote access

08

Microsoft 365, email and collaboration

09

Backup coverage and recovery

10

Policies, awareness and ownership

What you receive

A plan designed to be used.

  1. 01Foundations scorecard
  2. 02Cyber Essentials readiness view
  3. 03Immediate high-risk findings
  4. 0430-day priority actions
  5. 05Practical 90-day plan
  6. 06Management readout
  7. 07Technology and specialist options

Important distinction

Readiness—not borrowed accreditation.

This is an independent Cyber Essentials-aligned readiness and improvement review. It is not formal Cyber Essentials certification. Where certification is required, Sevenpoynt can help prepare the organisation and connect the appropriate authorised route.

Need a deeper NIST-aligned review? →

The engagement

Focused enough to finish quickly.

  1. 01

    Scope

    Confirm the business, systems, people and immediate decision drivers.

  2. 02

    Discover

    Review practical evidence with the business and its IT provider where appropriate.

  3. 03

    Prioritise

    Separate urgent exposure from planned improvement and optional enhancement.

  4. 04

    Mobilise

    Agree owners, next steps and any product or specialist support genuinely required.

A practical first step

Strengthen the foundations before complexity compounds.

The review can stand alone, support Cyber Essentials readiness or become the beginning of an ongoing trusted-adviser relationship.

Start a conversation