Now
Things you should fix this month, usually because they are both serious and cheap, including MFA gaps, dormant accounts, unpatched internet-facing systems, and backups nobody has tested.
Pillar 01 · Audit
Every business carries cyber risk. Very few can tell you how much, where it sits, or which parts of it are worth spending money on.
A cyber risk assessment answers those questions. It is a structured look at what you would lose, what could cause you to lose it, how likely that is, and what it would be worth to reduce. It is the piece of work that turns cyber security from an uncomfortable subject into a set of decisions you can make.
A cyber risk assessment identifies the things that matter to your business, the threats to them, and the weaknesses that would turn those threats into incidents. It then rates each combination by how likely it is and how much it would hurt. It is enough to make decisions on, without the depth of a full audit.
The output is a risk register that provides a prioritised list of your exposures, each with a likelihood, an impact and a recommended response. It reads as a management document, not a technical scan report.
A cyber security audit is broader and deeper. It examines your systems, controls, software and people in detail and tells you what is wrong. A risk assessment is more focused as it starts from business consequence and works backwards to the controls that would prevent it.
For most businesses, the audit is the practical first step, and the risk assessment is a part of that. The standalone assessment makes sense when you want a lighter-touch view before committing to the full piece. If you are not sure which you need, we will tell you on a call rather than sell you the larger one.
Cyber security budgets are finite and threats are not, so the only sensible approach is to spend where the risk is.
Without an assessment, decisions are based on the loudest input available, such as a vendor's pitch, a newspaper story about ransomware, or whatever the IT provider mentioned last. This is how organisations end up with an expensive tool addressing a risk they did not really carry, while an unpatched server holding the customer database sits there untouched.
There is usually a second reason too, and it is external. Someone has asked.
This is broadly how NIST and ISO 27001 approach it, applied at a scale that suits a business without a security team.
We identify your critical assets and processes: the data you hold, the systems you depend on, the services your customers rely on, and the suppliers and platforms you cannot operate without. Cloud services and third-party dependencies get counted properly, which they often are not.
For each of these assets and processes, we evaluate the realistic threats, such as ransomware, business email compromise, insider error, supplier failure, lost devices and credential theft. We keep this specific to your business, as a manufacturer's realistic threat list looks different from a solicitor's.
The vulnerabilities and control gaps that would allow each threat to succeed. This is the technical layer, and it is grounded in what we can observe, not in what a questionnaire claims.
Each risk receives a likelihood and an impact rating, and we are explicit about the reasoning behind both. Impact is expressed in business terms, including days of disruption, cost, contractual exposure, and regulatory consequence.
Every cyber assessment should end in decisions, so each risk is assigned one: treat, tolerate, transfer or terminate. Most get treated, some get tolerated with a documented reason, and some get transferred to an insurer.
A risk register that nobody acts on is just a well-organised worry. Our assessment ends with a roadmap that is sequenced, costed where we can cost it, and split by timeframe.
Things you should fix this month, usually because they are both serious and cheap, including MFA gaps, dormant accounts, unpatched internet-facing systems, and backups nobody has tested.
Work needing planning or budget over a quarter or two, such as network segmentation, endpoint replacement, formalising an incident response plan, and a training programme.
Structural changes with a longer horizon. This could include replacing an unsupported line-of-business system, moving to a better-architected cloud setup, and certification if it is not already on the list.
Everything is ordered by risk reduced per pound spent. If two items would cost the same, the one that removes more exposure goes first. It sounds obvious, but it is remarkable how rarely security recommendations arrive in this order.
We also flag which items your insurer is most likely to care about, so the roadmap does double duty at renewal.
Fourarmed came out of an insurance broker, and it shapes how we assess risk.
Insurers are in the business of pricing risk accurately, because getting it wrong costs them money. That gives them a grounded, slightly unromantic view of what causes losses, and it is often not what the security industry talks about most. The Association of British Insurers reported £197m paid out on UK cyber claims in 2024, up 230% on the previous year, with ransomware and malware accounting for 51% of claims. This is a picture of what happens, drawn from what got paid.
We assess likelihood from loss experience instead of threat headlines. A well-publicised attack technique is not necessarily one that is likely to hit you. We weight our ratings towards the things that generate claims for businesses like yours.
We also assess impact the way an underwriter would, which means quantifying business interruption. How long you would be down, what that costs per day, and what recovering would involve. This number is the one that gets budgets approved internally, and it is the one your insurer is already estimating with less information than you have.
If a board member has asked where the business is exposed and the honest answer is that nobody knows, this is the piece of work that changes that. The same applies if there is a renewal or a client questionnaire in front of you. We will scope it on a call and quote a fixed price.