Fixed-Price Cyber Resilience Review

A Clear Picture of Your Cyber Risk — And a Practical Plan to Address It

£495 (or 2 payments of £275) · Written findings & a 90-day roadmap · No ongoing commitment

A defined, proportionate first engagement for SMEs that need direction on cyber risk — not an open-ended project, and not a subscription. One clear deliverable, one fixed price, delivered by Franco personally.

Most SMEs sit between two extremes: a free initial conversation that doesn't produce anything written down, and an open-ended consultancy relationship they're not ready to commit to. The Cyber Resilience Review fills that gap — a fixed-scope, fixed-price engagement that gives you a proper written assessment and a practical plan, with no assumption that anything further follows. Some clients stop there. Others use it to decide, with evidence, whether ongoing support — through specific services or a vCISO retainer — actually makes sense for them.

It is also different from running a free check or asking your existing IT provider. Automated tools identify signals and potential gaps; they can't weigh them against how your business actually works. The Review adds independent judgement, business context, prioritisation and — where it's useful — a second opinion on what you've already been told.

Is this for you?

Built for a Specific Kind of Organisation

The Review tends to suit owner-led SMEs facing one or more of the following — not every business needs it, and if any of these don't apply to you yet, that's a reasonable place to be.

No internal cyber security or risk lead — it sits alongside someone's day job, or with an outsourced IT provider.
You handle client data, card/bank payments or systems that matter operationally if they go down.
A client questionnaire, tender, insurance renewal, near miss, board or regulator concern or Cyber Essentials requirement has prompted the question.
You want independent, proportionate advice — not an enterprise-scale consultancy programme you don't need. You may just be curious to find out your cyber risk profile.

If you'd rather start with something free first, the Cyber Risk Assessment is a no-obligation self-assessment that flags potential gaps. Cyber Vitals, GET-IT's evidence-gathering scan, is included as part of the Review — see how they fit together on the Resilience Roadmap.

The offer

Two Clear Options

Both are fixed-price, both are scoped upfront — no surprises once the engagement begins.

Cyber Resilience Review
A clear picture and a practical plan
£495
Or 2 payments of £275 (£550 total) — no VAT added either way
  • Initial discovery and business-context review
  • Structured operational resilience assessment
  • External digital exposure and website-security review (includes a Cyber Vitals scan)
  • Cyber Essentials readiness perspective
  • Governance and key-control review
  • Prioritised written findings
  • Practical 90-day cyber roadmap
  • Review call to explain findings and next steps
Book a 15-Min Call →
Cyber Risk Management Policy
An optional add-on, once you've seen your findings
+£250
Added to the Review — no need to decide now
  • An organisation-specific Cyber Risk Management Policy:
  • Cyber-risk ownership and responsibilities
  • How risks will be identified, recorded and treated
  • Minimum control expectations
  • Supplier and third-party risk principles
  • Incident escalation responsibilities
  • Suggested monitoring measures and review frequency
  • Approval and annual-review framework
  • An editable version you can adopt and maintain
  • Plus two working templates:
  • Asset register template
  • MFA coverage register template
  • And a closer look at Cyber Essentials:
  • Deeper guidance on your Cyber Essentials gaps and a practical pathway to close them

We discuss this with you after your Review findings — there's nothing to arrange now.

The policy option gives you a monitoring framework and recommendations to adopt — it does not include ongoing monitoring or policy administration on our part.
GET-IT Solutions Ltd is not VAT registered; no VAT is added to these prices.

How it works

A Simple, Fixed Process

1

Discover

Initial discovery and business-context review, so the assessment reflects how your organisation actually operates.

2

Assess

Operational resilience, external digital exposure, Cyber Essentials readiness and key-control review.

3

Roadmap

Prioritised written findings and a practical 90-day roadmap — what to address, and in what order.

4

Discuss

A review call to explain the findings and talk through recommended next steps in plain language.

Deliverables

What You Receive

Written findings documentPrioritised, in plain language — not a raw scan dump.
90-day cyber roadmapA practical sequence of what to address first, second and third.
Review callFranco talks you through the findings and answers questions directly.
Cyber Risk Management Policy — £250 add-onEditable policy, plus asset and MFA coverage register templates.
What might come up

Example Categories in a 90-Day Roadmap

Every roadmap is specific to your findings — these are the kinds of areas that commonly appear.

Identity & accessWho has access to what, and whether admin rights are kept separate from everyday accounts.
Endpoint & device securityHow laptops, phones and other devices are protected and managed.
Backup & recoveryWhether you could actually recover if something went wrong.
Supplier & third-party riskWhat your IT provider and other suppliers are responsible for — and what you still own.
Governance & documentationWhether decisions and responsibilities are written down anywhere.
Incident readinessWhether there's a basic plan for what happens if something does go wrong.
Joiners & leaversHow quickly new starters get access, and how quickly it's removed when someone leaves.
Password hygiene & MFAUnique passwords, a password manager, and MFA switched on everywhere it's available.
Boundaries

What the Review Is — and Isn't

The Review gives you an independent, proportionate assessment and a practical plan. To keep that clear, it's worth being explicit about what it doesn't include. Where any of these are actually what you need, they can be discussed and scoped separately.

  • Penetration testing
  • Cyber Essentials certification
  • Legal advice
  • A guarantee of compliance
  • Remediation or implementation
  • Ongoing monitoring
  • An automatic retainer commitment

As a general rule: the Review tells you what to do and in what order — it doesn't do the doing. Anything hands-on, ongoing, or requiring an outside guarantee sits outside it by default, whether or not it's listed above.

Why now?

Cyber Risk Is a Governance Issue, Not Just an IT One

Cyber risk is increasingly a leadership and governance issue, not simply an IT task. The Cyber Security and Resilience Bill, currently progressing through Parliament, proposes stronger duties for organisations delivering essential services and for parts of their digital supply chains — it does not directly regulate every SME, accountant, insurance broker or law firm. It remains subject to Parliamentary approval and amendment, and may change before Royal Assent.

What it reflects is broader than its direct scope: a wider movement towards stronger cyber governance, documented risk ownership, supply-chain assurance and operational resilience — trends already showing up in client contracts, tender requirements and insurance renewals for businesses well outside the Bill's direct reach. You can read the Bill's progress at the UK Parliament Bills page.

The Cyber Resilience Review is not legal advice and is not a formal assessment of compliance with the Cyber Security and Resilience Bill or any other legislation.

How it fits together

Where This Sits Alongside GET-IT's Other Services

The Review establishes where you stand today. The roadmap it produces sets out priorities and sequencing. The optional policy formalises how cyber risk will be managed going forward. From there, specific services address particular weaknesses, and vCISO support provides optional continuing oversight if you want it.

The Resilience Roadmap

See how the free self-assessment, the Review and ongoing support fit together as one journey.

View the Roadmap →

Cyber Consultancy

Once priorities are set, specific services — Cyber Essentials, hardening, monitoring and more — address them individually, some through specialist partners.

Explore Cyber Consultancy →

vCISO Retainer

If ongoing oversight makes sense once you've seen the findings, GET-IT Cyber Advisory picks up where the Review leaves off.

Explore vCISO Retainer →

Ready for a Clear Picture and a Practical Plan?

Fixed price, fixed scope, delivered personally by Franco — with no assumption that anything follows.