SERVICE DETAILS
NINE WATCH
A cybersecurity plan, kept moving by someone who knows your environment.
Visibility and guidance, month after month.
What you get
A living cybersecurity plan. Regular reporting you can show your management or a customer who asks. A maturity score that moves.
NINE WATCH
Continuous visibility. Someone who stays.
01
Continuous consulting
Most companies do not have a security problem they can name. They have a dozen small things nobody is tracking: an account that was never disabled, a backup that has never been restored, a system that stopped receiving updates two years ago. Individually, none of them looks urgent. Together, they are how incidents happen.
NINE WATCH is for organisations that want to stop reacting and start anticipating. Instead of a one-off engagement, you get permanent visibility over your security posture and someone who stays with it, month after month, without needing a cybersecurity team of your own.
Who it is for
Companies with between 20 and 250 people, usually working with an external IT provider, where security has become something that matters, but nobody owns. If you have already had an audit and the report is sitting in a folder, this is the service that turns it into work that actually gets done.
Strategy and risk
We define a cybersecurity strategy that fits your organisation, not a template, and we revisit it as the business changes. Regular risk assessment identifies the actions with the greatest protective impact, so limited budget and limited time go where they count. You always know what the next three priorities are and why.
Continuous assessment
Regular Vulnerability assessments, with findings identified, prioritised and translated into specific remediation actions. Dark web monitoring flags leaked data and compromised credentials belonging to your organisation. Patching and updates are tracked, so gaps do not reopen quietly between assessments.
Controls and resilience
Periodic reviews of access and identity, privileged accounts, dormant accounts, and multi-factor authentication coverage. Verification that backups run and that recovery works when it is needed, not just that a backup job reports success. Guidance on asset inventory and on your continuity and recovery capability, so you know what you have and how quickly you could get it back.
Your point of contact
A named specialist available throughout the engagement. Security questions get answered when they come up before a decision is made, not at the next annual review. When something happens, you are not starting a conversation with a stranger.
What you get
A living cybersecurity plan, reviewed and updated rather than written once. Regular reporting you can take to your management team or show a customer who asks. And a maturity score that moves, so improvement is something you can demonstrate rather than assert.
What it does not include
NINE WATCH is strategic consulting. We specify what needs to change and validate that it worked the hands-on execution remains with your IT team or provider, and we coordinate directly with them. The service does not include 24/7 monitoring, help desk support, or incident response retainer coverage.
Where it starts
Most clients begin with a NINE DEFEND audit, which establishes the baseline that NINE WATCH then works from. If you already have a recent assessment, we can start from that.
NOT SURE WHERE TO START?
Start with the most valuable question.
A focused conversation to identify the right first move.
Book a conversation