Audit
A fixed-price cyber security audit of your systems, controls, software and people. We visit the site, look at what is actually running, and give you a prioritised action plan plus a board summary.
Bristol based, working UK wide
Fourarmed Cyber Ltd, trading as Fourarmed, is a cyber security company based in Bristol and working with businesses across the UK.
We audit, certify, train and monitor, and we do it from an unusual starting point, because we came out of the insurance industry and not the IT industry.
Fourarmed was founded out of Castlemead, an insurance broker and a member of ADS Group, the UK trade body for aerospace, defence, security and space. The reason was frustration.
Castlemead had arranged cyber cover for UK businesses for years, which meant seeing the aftermath of a lot of incidents. A pattern kept repeating. A client would believe they were reasonably well protected, then something would happen, and it would become clear the protection was thinner than anyone had realised. This was not through negligence, but because the advice they had been given was either too technical to act on or too generic to be worth acting on.
The gap between "we have security" and "our security would hold" was where clients kept getting hurt.
You cannot fix that from the brokering side. Brokers can advise on cover, but they cannot audit a network or train a workforce. As a result, Castlemead built the security business that had been missing.
That is why Fourarmed does things in a particular way. Our recommendations are written to satisfy an underwriter as well as an auditor, because we know which controls hold up when tested by events. Our reports are written for boards, because the person who approves the budget is not usually someone who understands the technology. Our prices are also fixed, because open-ended security bills are one of the main reasons businesses put this off.
A fixed-price cyber security audit of your systems, controls, software and people. We visit the site, look at what is actually running, and give you a prioritised action plan plus a board summary.
Cyber Essentials and Cyber Essentials Plus certification, from gap analysis through remediation to the assessment itself. Increasingly, this is the price of entry for government work, defence supply chains and larger corporate tenders.
Ongoing network monitoring and phishing tests, plus help scoping and running penetration testing. An audit tells you where you stood in June. Monitoring tells you where you stand today.
Cyber security training that treats your staff as a control, because they are one. Interactive workshops, phishing simulations and scenario exercises, built around your business instead of a generic e-learning module.
We focus on four pillars, which are set out in full on our services page, and meant to be used in sequence, not picked from a menu.
Alongside these four pillars, we work on the areas where our clients keep encountering risk: supply chain cyber security, IoT and connected device security, and incident response planning.
Our sector strength follows Castlemead's. The full picture of how the insurance background shapes our method is in our approach.
We are a small but perfectly formed team. Here is just a snapshot of our senior leadership team, but we could not do it without our support team working hard in the background to deliver the right results.
Managing Director
Tech Lead
Marketing
Call, email, or send us a message. Every conversation starts free and without obligation, and we will give you an honest view of what you need, including where that is less than you expected.