SEC

Turnstone AI service

Cyber security and resilience

Reduce the likelihood and impact of common incidents, then prove the business can respond and recover.

Business outcomes

What better looks like.

  • Stronger identity and administrative controls
  • Faster containment and escalation
  • Tested backup and recovery procedures
  • A prioritised security improvement plan

Work in scope

Where we can help

  • Multi-factor authentication, privileged access and account reviews
  • Email, endpoint and cloud-security uplift
  • Essential Eight-aligned assessment and roadmap
  • Backup and restore testing
  • Incident plans, tabletop exercises and policy

Questions asked first

What would stop the business operating?

Which accounts can change or pay?

When was the last successful restore?

Who makes decisions during an incident?

A supportable path

How the work moves

  1. 01

    Identify critical services, data and plausible threats

  2. 02

    Confirm current controls with evidence

  3. 03

    Prioritise consequence and exploitability

  4. 04

    Implement and test the highest-value controls

  5. 05

    Record residual risk and rehearse response

Responsible boundaries

What we make explicit

  • An uplift review is not described as certification, penetration testing or a formal audit
  • Legal, insurance and breach-notification decisions remain with qualified advisers
  • Security claims are limited to tested scope and date

A practical next step

Discuss cyber resilience without the jargon.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.