Security considerations
Practical security work for small organisations: what protects you today, what is missing, and which gaps matter most. We are not a certification body and we do not issue compliance certificates.
What we review
Baseline protections
- Account sign-in and administrator roles
- Two-factor authentication coverage
- Device encryption and update settings
- Software patching practice, including who does it
Accounts and backups
- Who holds ownership of each account and domain
- Former staff and unused accounts still active
- Backup coverage and how often a restore is tested
- Where credentials are stored and who can reach them
Written risk note
- Findings written in plain language, ranked by impact
- Likelihood and consequence set out separately
- Assumptions and limits of the review stated openly
- No assurance or certification implied by the review
Improvement list
- Actions ordered by impact against effort
- Immediate items separated from planned work
- Owner and target date recorded for each action
- A follow-up point to confirm what was completed
Devicon Ltd is an IT consultancy. We are not a software vendor, an auditor or a certification body, and nothing in this service constitutes a certification, audit opinion or statement of compliance.
What an advisory security review is not
It is worth being precise about the boundary here, because the terms used in security work are often used loosely and mean different things to different suppliers.


An advisory review is not a penetration test, not an audit and not a certification. It does not test your systems adversarially, it does not produce a certificate, and it does not state that you meet any standard or framework. What it does produce is a written account of the protections in place, the gaps we found and the order we would close them in.