IAGIntelligent Access Group

Technology & digital transformation

Defensive Cybersecurity: assessment, hardening, monitoring and incident response

We help organisations reduce their security risks methodically: assessing the current situation, carrying out security tests that are explicitly authorised in writing within a defined scope, hardening systems and networks, organising access management, monitoring events and supporting the response when an incident occurs. Our work is entirely defensive.

What we offer

We start with a security assessment combining document and configuration review with team interviews: which assets matter, who can access them, how passwords and permissions are managed, the state of updates, how backups are kept and what happens when an incident occurs. The result is a report that ranks risks by priority and proposes practical measures for each, starting with quick wins.

Where needed we carry out technical security tests such as vulnerability scanning and penetration testing, only after explicit written authorisation from the owner of the systems defining the scope, the systems covered, the timing, the permitted methods and contacts. We test nothing outside that authorisation, treat findings as confidential and deliver them only to the responsible party. We then implement hardening: secure configuration of servers, devices and networks, multi-factor authentication, least-privilege access and organised patching.

We help build detection and response capability: collecting and monitoring key logs with alerts for suspicious events, a written and rehearsed incident response plan, and technical support during an incident to contain it, analyse it and restore operations. We make no promise of absolute security; no system is fully immune, and the aim is to reduce risk, detect incidents early and recover in an orderly way.

Who it is for

  • Ministries and public institutionsSystems and data of public importance that need methodical assessment, hardening and clear response plans.
  • HospitalsSensitive patient data and systems that cannot afford downtime, making protection, backups and response a priority.
  • Financial and commercial companiesHandle customer and payment data and need to reduce the risk of fraud and data leaks.
  • Organisations that have suffered an incidentNeed support to contain it, understand what happened and prevent recurrence.
  • Organisations launching new systemsWant a security review before launch, not after a problem is discovered.

Problems we address

  • Shared accounts, weak or reused passwords and broad permissions that nobody reviews.
  • Systems and devices that have not been updated for a long time.
  • No clear picture of which technical assets actually exist and who is responsible for them.
  • Phishing emails targeting staff with no training or reporting mechanism.
  • No logging or monitoring, so incidents are only discovered after damage is done.
  • No plan for what to do in an incident and no tested backups.

Tasks and deliverables

Security posture assessment
A report of risks ranked by priority, with proposed measures and the estimated effort for each.
Asset inventory
A list of key systems, servers, devices and accounts with an owner for each.
Authorised security tests
Vulnerability scanning or penetration testing within a written, approved scope, with a findings report, remediation advice and a retest after fixes.
Hardening
Secure configuration of servers, devices, networks and applications based on recognised reference guides.
Identity and access management
Organised accounts and permissions, multi-factor authentication and periodic access reviews.
Monitoring and logging
Collection of key logs, alerts for suspicious events and procedures for handling them.
Incident response plan
A written plan with roles, steps and contacts, tested in a practical exercise.
Staff awareness
Practical awareness sessions on phishing, passwords and data handling.

Who does what

What IAG does

  • Assess the security posture and prepare a prioritised remediation plan.
  • Carry out technical tests only under written authorisation and an approved scope.
  • Implement hardening and organise access management.
  • Set up monitoring and alerts and follow them up as agreed.
  • Prepare and rehearse the response plan and support containment and recovery during incidents.
  • Raise staff awareness and train the technical team.

What specialists, partners and authorities do

  • The owner of the systems issues written authorisation for tests, defines their scope and approves acceptance of residual risk.
  • The client's legal adviser is consulted on legal obligations after incidents, such as notifying competent authorities or affected individuals.
  • Competent authorities handle law enforcement and criminal investigation where applicable; we provide technical information to them through the client.
  • System vendors provide security updates and fixes for their products.

Practical example

Illustrative scenario

Security assessment and hardening plan for a mid-sized organisation

An organisation with several dozen staff, a few servers and cloud email has never had a security review.

  1. Sign an agreement defining scope, systems covered and confidentiality.
  2. Inventory assets, review configurations and permissions and interview the team.
  3. Run a vulnerability scan on the systems named in the written authorisation.
  4. Deliver a risk report and a three-phase remediation plan.
  5. Enable multi-factor authentication, organise permissions and update systems.
  6. Prepare an incident response plan and run a practical exercise with management.

This is an illustrative scenario to explain our approach, not a client reference.

How we work together

  1. Agreement and authorisation

    We define scope and objectives with you and sign the confidentiality agreement and written authorisation before any technical work.

  2. Assessment

    We inventory assets, review configurations and procedures and run the authorised tests.

  3. Prioritisation

    We present findings and agree a realistic remediation plan ranked by risk.

  4. Remediation and hardening

    We implement the agreed measures or support your team in doing so, then retest.

  5. Monitoring and readiness

    We set up monitoring and the response plan and rehearse it with you.

  6. Periodic review

    We review the situation regularly because systems and threats change.

Intended results

  • A clear picture of the most important security risks and remediation priorities.
  • Fewer known vulnerabilities and more secure configurations.
  • Better control over who can access what.
  • Greater ability to detect incidents early.
  • Organised readiness to respond and recover when an incident occurs.

What we need from you

  • Written authorisation signed by an authorised person defining the scope of any technical test.
  • A coordinator and emergency contacts.
  • Information on current systems, networks and providers.
  • Time-limited administrative access where needed, provided through agreed secure channels, not via the public website.
  • Management decisions on remediation priorities and acceptance of residual risk.
  • Staff participation in awareness sessions and exercises.

Basis for cost and timeline

Cost depends on the number of systems, sites and users, the type and depth of testing, the scope of hardening and the need for ongoing monitoring. Assessments and tests are usually priced as fixed-scope projects, hardening according to the approved remediation plan, and monitoring and incident support under an ongoing contract defining the service level. Emergency support for an active incident can be agreed after an initial assessment of the situation.

Frequently asked questions

Will you make our systems completely secure?

Nobody can. We work to reduce risk, detect incidents early and recover from them, and we tell you openly about remaining risks.

Do you test systems without permission?

No. We carry out technical tests only after explicit written authorisation from the owner of the systems, within a defined scope, timing and set of methods.

We have an incident right now. Can you help?

Contact us by phone or email, without sending sensitive data or passwords through the website. We start with an initial assessment and then agree the support needed for containment and recovery.

Do we need an in-house security team?

Not necessarily. We can cover part of the work under an ongoing contract while training your technical team on daily tasks.

How often should the assessment be repeated?

We recommend periodic reviews and a review after any major system change. The frequency is agreed according to your organisation and its risks.

Request this service

Defensive Cybersecurity: assessment, hardening, monitoring and incident response

Send us a short description; the service is already preselected in the form.

We usually reply within one business day.

Please do not send confidential documents, patient data or passwords through this form.

WhatsApp