-
Offer
We are pleased to offer eligible organisations a complimentary, no-obligation Cyber Security Risk Assessment ("Assessment"). The purpose of the Assessment is to provide a high-level review of your organisation’s current cyber security posture, identify potential risks and vulnerabilities, and make recommendations to improve resilience against common cyber threats. Participation in this offer does not create any obligation to purchase products or services from us.
-
Eligibility
- This offer is available to business organisations only.
- One complimentary Assessment is available per organisation unless otherwise agreed in writing.
- We reserve the right to determine eligibility and to refuse, amend or withdraw the offer at our discretion.
-
Scope of the Assessment
The complimentary Cyber Security Risk Assessment is conducted in line with the principles set out within the UK Government’s Cyber Essentials scheme and is designed to help organisations understand and improve their cyber security posture.
The Assessment may include a review of one or more of the following areas:
- User access control and identity management.
- Secure configuration of devices, servers and cloud services.
- Network security, including firewalls and internet gateways.
- Security update and patch management practices.
- Malware protection controls.
- Microsoft 365 security configuration.
- Multi-factor authentication (MFA).
- Endpoint protection.
- Backup and disaster recovery arrangements.
- Security policies, procedures and user awareness.
- General cyber security risks and recommendations.
The exact scope of the Assessment will be agreed before work commences.
The Assessment is intended to identify potential risks and opportunities for improvement against recognised cyber security good practice. It is not:
- an official Cyber Essentials assessment
- a Cyber Essentials Plus assessment
- a certification audit
- a penetration test
- a vulnerability scan of every system
- or a guarantee that your organisation is compliant with Cyber Essentials or any other security standard.
-
Client Responsibilities
To enable us to carry out the Assessment effectively, the Client agrees to:
- Provide sufficient access to relevant systems, networks, cloud platforms, devices and documentation as reasonably required.
- Provide appropriate read-only administrative access wherever possible unless alternative access is agreed.
- Ensure that all access provided is authorised by the organisation.
- Make appropriate technical and business personnel available to answer reasonable questions.
- Provide complete and accurate information relevant to the Assessment.
- Inform us of any systems or environments that should be excluded from the Assessment.
Where sufficient access, information or documentation is not provided, the scope and accuracy of the Assessment may be limited. We accept no responsibility for risks, vulnerabilities or issues that could not reasonably be identified due to restricted access or incomplete information supplied by the Client.
-
Authorisation
By requesting the Assessment, the Client confirms that:
- they own, manage or have appropriate authority to authorise access to the systems being reviewed
- our activities have been authorised by the organisation
- no contractual or legal restrictions prevent the Assessment from taking place.
-
Assessment Activities
Unless expressly agreed in writing, the Assessment is intended to be non-intrusive and will not include:
- penetration testing
- exploitation of vulnerabilities
- denial-of-service testing
- password cracking
- phishing or social engineering exercises
- destructive testing
- unauthorised access attempts
- installation of software or monitoring agents
Any intrusive testing would require a separate written agreement and may incur additional charges.
-
No Changes to Systems
Unless specifically authorised in writing, we will not:
- modify configurations
- install software
- apply security updates or patches
- create, remove or amend user accounts
- change permissions
- remediate vulnerabilities
The Assessment is advisory only.
-
Findings and Recommendations
Following completion of the Assessment, we may provide a written report detailing:
- identified cyber security risks
- observations
- areas of good practice
- potential vulnerabilities
- recommendations for improvement
- suggested priorities for remediation
Where appropriate, recommendations may reference recognised cyber security good practice, including the principles of the UK Government’s Cyber Essentials scheme. The report is intended to assist the Client in improving its cyber security posture and should not be interpreted as confirmation that the organisation meets the requirements for Cyber Essentials certification or any other accreditation. Implementation of any recommendations remains entirely the responsibility of the Client unless separately agreed under a paid engagement.
-
No Warranty
The Assessment represents a snapshot of your cyber security posture at the time it is undertaken.
While reasonable skill and care will be exercised, we do not warrant or guarantee that:
- every vulnerability or security weakness will be identified
- all systems have been fully assessed
- your organisation is secure
- future cyber-attacks will be prevented
- compliance with Cyber Essentials or any other framework has been achieved.
The Assessment is based solely on the information, documentation and system access made available at the time of the review. Systems, services or controls that are inaccessible, excluded or not disclosed cannot be assessed, and we accept no liability for any findings that could not reasonably be identified due to those limitations.
-
Confidentiality
We will treat all information obtained during the Assessment as confidential and will only use such information for the purpose of carrying out the Assessment and preparing our findings, except where disclosure is required by law.
-
Data Protection
Both parties agree to comply with all applicable data protection legislation, including the UK GDPR and the Data Protection Act 2018. Where personal data is encountered during the Assessment, it will only be accessed where reasonably necessary to perform the agreed services.
-
Intellectual Property
All methodologies, reports, templates, scoring systems, documentation and recommendations produced as part of the Assessment remain our intellectual property. The Client is granted a non-exclusive licence to use the report internally within their organisation.
-
Limitation of Liability
To the fullest extent permitted by law, we shall not be liable for:
- indirect or consequential loss
- loss of profits, revenue, business or goodwill
- cyber incidents occurring before, during or after the Assessment
- security breaches arising from vulnerabilities not identified during the Assessment
- losses resulting from recommendations that are not implemented or are implemented incorrectly.
-
Offer Validity
This promotional offer may be amended, suspended or withdrawn at any time without notice. Confirmed appointments already accepted by us will not be affected.
-
Governing Law
These Terms & Conditions shall be governed by and construed in accordance with the laws of England and Wales. Any dispute arising from these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
-
Acceptance
By requesting or participating in the complimentary Cyber Security Risk Assessment, the Client confirms that they have read, understood and accepted these Terms & Conditions.