Maple Open Tech · Services
Cyber Security Strategy
A security posture sized to your organisation: the handful of controls that stop most of what actually happens, in an order you can afford and evidence you can show.

What a cyber security strategy engagement includes
Security advice usually arrives as a list of everything, which is indistinguishable from no advice. The useful version is short, ordered, and honest that a small organisation cannot do all of it at once.
- An asset and access review — what you run, and who can reach it
- Backups that have been restored, not merely scheduled
- Identity hardening: multi-factor, least privilege, and joiner-mover-leaver
- An incident plan short enough to follow at 3am
- Evidence for audits and insurers, produced as you go rather than reconstructed
What this looks like in practice

Posture review
Ranked findings, sized to what you can actually do

Backup restore drill
Proof it works, with the timings written down

Incident runbook
Who calls whom, in what order, at 3am
How it runs
01
We map what exists
Systems, accounts, data and access. Nearly every engagement finds accounts nobody could name.02
We rank by what stops real incidents
Not by framework completeness. The first five items usually cover most of the risk.03
We fix, and we test the fix
A backup is not a backup until it has been restored, and a plan is not a plan until it has been walked through.04
We leave you the evidence
What was done, when, and how it is checked — the thing auditors and insurers actually ask for.
Questions people ask
We are small. Is this overkill?
The opposite: the point is to be honest that you cannot do everything, and to get the few things that matter done properly.
Do you do penetration testing?
We scope it and read the results with you. The report is not the outcome — the fixes and the retest are.
Will this satisfy our cyber insurer?
Usually the sticking points are multi-factor, backups and an incident plan. Those are the first three things on the list for exactly that reason.
Want to talk about sovereignty?
Tell us what you run, where it runs, and who can reach it. We will tell you honestly what moving it to Canadian infrastructure would take.