SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

Practical security baseline

Without a security team of your own, you are still expected to be defensible - by customers, insurers, investors, and regulators. We build the baseline that makes you trusted: practical controls, lightweight evidence, and a steady review rhythm.

You reach the baseline through a flexible framework - the CIS Critical Security Controls - applying only the tier that fits your risk, without the paper ISMS of a full ISO 27001 project.

Where This Fits

Who this is for

This is you

Your company

  • Usually 1-100+ people
  • No in-house security team
  • Not yet facing formal ISO 27001 or NIS2 obligations
  • Still expected to be defensible and trusted

What is pushing you

  • A customer sent a security questionnaire
  • A GDPR worry has surfaced
  • An incident gave everyone a scare
  • An investor started asking questions

How we do it

  • Instead of jumping into a full ISO 27001 project too early, we start from what you actually have today.

  • Instead of buying security tools nobody ever configures, we fix the highest-risk exposure first.

  • Instead of writing policies nobody reads or follows, we keep evidence light enough to stay current.

This baseline comes before ISO 27001, not instead of it. If certification becomes the right next step, none of this work is wasted - it becomes the foundation.

What We Fix First

The obvious gaps

Before policies, before frameworks, before anything that looks like an ISMS, we close the gaps that actually let attackers in.

  • MFA everywhere
  • Admin access tightened
  • A password manager people use
  • Endpoint protection
  • Patching that actually happens
  • Email and web protections
  • A verified backup recovery
  • Basic logging that someone reads

What Proof You Get

Evidence you walk away with

  • An asset register a customer can actually believe
  • A short security policy that fits your company
  • An access and admin review
  • A supplier list with security context
  • A backup recovery test you actually ran
  • An incident contact plan
  • Honest, defensible answers to customer security questionnaires

This is what makes the difference between "we take security seriously" and being able to prove it.

The Roadmap

Four phases

1

Know what exists

Map your devices, users, cloud accounts, business-critical apps, sensitive data, suppliers, and backups. You cannot protect what you have never listed.

2

Fix the obvious exposure

The eight highest-impact fixes: MFA, admin access, a password manager, endpoint protection, patching, email and web protections, verified backup recovery, and basic logging.

3

Create lightweight evidence

The evidence pack: asset register, short policy, access review, supplier list, incident contact plan, and customer-questionnaire answers.

4

Retainer rhythm

Quarterly risk and access review, supplier evidence updates, small technical checks, employee awareness, and roadmap upkeep so the baseline does not drift.

The Method

The CIS Controls IG1 structure

The defensible baseline is built on the CIS Critical Security Controls v8.1 - 18 control categories grouped into three Implementation Groups. For small companies we work inside IG1, essential cyber hygiene.

18 Controls · 3 Implementation Groups
  1. 01 Inventory and Control of Enterprise Assets
  2. 02 Inventory and Control of Software Assets
  3. 03 Data Protection
  4. 04 Secure Configuration of Enterprise Assets and Software
  5. 05 Account Management
  6. 06 Access Control Management
  7. 07 Continuous Vulnerability Management
  8. 08 Audit Log Management
  9. 09 Email and Web Browser Protections
  10. 10 Malware Defenses
  11. 11 Data Recovery
  12. 12 Network Infrastructure Management
  13. 13 Network Monitoring and Defense
  14. 14 Security Awareness and Skills Training
  15. 15 Service Provider Management
  16. 16 Application Software Security
  17. 17 Incident Response Management
  18. 18 Penetration Testing

The Path

IG1

Essential Cyber Hygiene

Where most small companies should start - and often all they need.

Decide together

ISO 27001

Formalise into an ISMS

Certification and customer assurance.

IG2

Go deeper technically

More controls, no certification.

IG3 is intended for high-sensitivity and regulated environments. It is not the target of this path.

CIS Critical Security Controls v8.1 contain 18 control categories grouped into three Implementation Groups. For small and medium-sized companies the focus is IG1, Essential Cyber Hygiene. Once IG1 is in place we decide jointly whether to formalise into an ISO 27001 information security management system, or to continue with IG2 for deeper technical defence. IG3 is intended for high-sensitivity and regulated environments and is out of scope here.

Once IG1 is in place and proven, we decide together what comes next: formalise into an ISO 27001 ISMS if certification or customer assurance is the goal, or continue with IG2 if the priority is deeper technical defence. IG3 is intended for high-sensitivity and regulated environments and is not the target of this path.

Start Here

How to start

The same four steps for every engagement here. You can stop after step two and owe nothing.

  1. 1

    Run the Discovery Calculator

    Free

    About four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.

  2. 2

    Send me the result

    Free

    I reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.

  3. 3

    Starter Assessment (€1,900) or Starter Month (€2,900)

    Fixed price, one-off

    The paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.

  4. 4

    Continue on a retainer

    From €950 a month

    If the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.

How this becomes a retainer

This is not a fixed project: we move at the pace and budget you can sustain, so security keeps moving forward instead of stalling between one-off pushes. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.

What is not included

This is not a full ISMS, not ISO 27001 certification, and not legal advice. We implement and advise; management owns the business risk and the final decisions.

What you get is not compliance, but a defensible security baseline that customers can trust.