Maple Open Tech · Services

Cyber Security Strategy

A security posture sized to your organisation: the handful of controls that stop most of what actually happens, in an order you can afford and evidence you can show.

Start a conversation See all services

Cyber Security Strategy

What a cyber security strategy engagement includes

Security advice usually arrives as a list of everything, which is indistinguishable from no advice. The useful version is short, ordered, and honest that a small organisation cannot do all of it at once.
  • An asset and access review — what you run, and who can reach it
  • Backups that have been restored, not merely scheduled
  • Identity hardening: multi-factor, least privilege, and joiner-mover-leaver
  • An incident plan short enough to follow at 3am
  • Evidence for audits and insurers, produced as you go rather than reconstructed

Talk through your project

What this looks like in practice

  • Cyber Security Strategy — illustrative

    Posture review

    Ranked findings, sized to what you can actually do

  • Cyber Security Strategy — illustrative

    Backup restore drill

    Proof it works, with the timings written down

  • Cyber Security Strategy — illustrative

    Incident runbook

    Who calls whom, in what order, at 3am

How it runs

  1. 01

    We map what exists

    Systems, accounts, data and access. Nearly every engagement finds accounts nobody could name.
  2. 02

    We rank by what stops real incidents

    Not by framework completeness. The first five items usually cover most of the risk.
  3. 03

    We fix, and we test the fix

    A backup is not a backup until it has been restored, and a plan is not a plan until it has been walked through.
  4. 04

    We leave you the evidence

    What was done, when, and how it is checked — the thing auditors and insurers actually ask for.

Questions people ask

We are small. Is this overkill?
The opposite: the point is to be honest that you cannot do everything, and to get the few things that matter done properly.
Do you do penetration testing?
We scope it and read the results with you. The report is not the outcome — the fixes and the retest are.
Will this satisfy our cyber insurer?
Usually the sticking points are multi-factor, backups and an incident plan. Those are the first three things on the list for exactly that reason.

Want to talk about sovereignty?

Tell us what you run, where it runs, and who can reach it. We will tell you honestly what moving it to Canadian infrastructure would take.