IT for Professional Services
Identity, secure remote work and file infrastructure for teams that are never in one place.
Designed against
- ISO 27001
- GDPR
- Cyber Essentials
- SRA / professional body guidance
We build and document to these frameworks. We are not an audit firm and do not issue attestations.
- 01
The perimeter is wherever your people are
When work happens from homes, client sites and airports, an office firewall protects almost nothing. Identity becomes the control plane, and has to be configured as if it is the only defence.
- 02
Client confidentiality is a professional obligation
In regulated professions a breach is a matter for the professional body and the insurer, not only for the business. Access has to be demonstrably limited to the people on the matter.
- 03
Files sprawl across every tool anyone signed up for
Documents accumulate in personal drives, chat threads and unmanaged SaaS accounts. Nobody can answer where a client's data lives, which makes both retention and deletion impossible to honour.
Controls, not features
Each of these produces its own evidence as a by-product of running normally, so the proof exists before anyone asks for it.
- Single sign-on across every application, with multi-factor authentication enforced
- Conditional access rules based on device compliance rather than network location
- Managed devices with full-disk encryption and remote wipe
- One governed file location per matter, with retention and permissions applied there
- Joiner / mover / leaver process that removes access the same day
- Encrypted backup of collaboration platforms, which are not backed up by default
IT Infrastructure
Networks, devices and offices designed once and designed properly, instead of grown by accident.
AI Integration & Automation
ChatGPT, Claude, Gemini, Copilot and n8n, implemented properly inside the systems, permissions and data rules you already have.
Managed Services
A full IT department on a flat monthly fee, with a named engineer who knows your setup.
- 01Week 0
Assess
- 02Weeks 1 to 2
Blueprint
- 03Weeks 2 to 8
Build & Migrate
- 04Ongoing
Operate
About Professional Services
Ask Something ElseYes, with the right setup: plans that do not train on your data, single sign-on, retention settings, and permissions tidy enough that an assistant only surfaces documents a person is entitled to see. We also write a usage policy your partners can sign off.
No, and this surprises people every year. Microsoft protects the platform's availability, not your content: a deleted mailbox, ransomware syncing through OneDrive, or a leaver's cleared folders are your responsibility once retention windows pass. We add third-party backup and test restores from it.
Usually not. Backhauling all traffic through an office is slow and gives a compromised laptop a route into everything. We prefer identity-based access: each application reached individually, based on who the user is and whether their device is compliant. A VPN stays only where a legacy system needs one.
A process problem before a technical one, but the technical side matters: same-day de-provisioning across every system, an export of what they are entitled to take, and an access log covering the preceding period. Documented in advance, it is the difference between an orderly exit and a dispute.
