Cyber Risk & Assurance Review
One clear picture of your cyber risk, and what to fix first.
A three-day independent deep dive into your cyber risk and evidence, so your story to clients, insurers, and the board matches reality, and you know what to fix first.

Full internal and external view of where you are strong, weak, and exposed.
Plain-English Fix-First Plan your team, MSP, or DDG can actually run.
What it is
Not another audit. A decision tool.
We sit with your team and look at the whole picture: what is exposed, how far a realistic attacker could get, how access, devices, email, suppliers, logging, backups, and incident plans are set up, and whether your policies and assurance claims match reality.
The outcome
We find what matters, explain it clearly, and show what to fix first.
The Review turns scattered tools, assumptions, policies, and technical checks into one clear business view: what is exposed, what is proven, and what should happen next.
Joined-up risk view
Identity, devices, email, suppliers, backups, logging, and policies reviewed together.
Board-ready summary
Plain-English findings for leadership, not a technical report that sits unread.
Fix-First Plan
Ranked actions with owners, effort, impact, and next steps your team can run.
Risk
Evidence
Plan
Built for decisions
Different people need the same truth in different language.
The Review is designed for boards, FDs, and IT leaders who are done with scattered tools, long reports, and vague opinions.
CEO and board
An independent view and board-ready summary so your cyber story and evidence line up.
FD and finance
A check that answers on renewals and due diligence questions match reality, with money and downtime impact called out.
IT leaders
Deep technical checks turned into one pack and a priority list you can use to win budget and cut paperwork.
Outputs
What you walk away with.
At the end, you get one independent view in plain English, a board-ready summary, and a short list of what really needs fixing first in terms of risk, money, and downtime.
A one-page posture summary that explains cyber risk in business language.
A prioritised Fix-First Plan for the next 90 days and a simple 12-month view.
An evidence pack you can repurpose for insurers, tenders, and stakeholder updates.
A clear recommendation on what now: run it internally, do targeted projects, or move into managed cyber.

You can implement the Fix-First Plan with your own team, your MSP, or with DDG.
What changes
How exposed are we? What should we do first? Who is responsible?
Everything is geared around answering those three questions clearly enough that leadership can make decisions and teams can act.
Clarity
Board, IT, finance, and operations see the same picture instead of conflicting dashboards and long reports.
Control
Findings are translated into a realistic sequence of actions, mapped to owners, impact, and effort.
Next step
You get a clear recommendation on whether to run the plan internally, use targeted projects, or move into managed cyber.
How it works
Three simple steps from uncertainty to a plan.
Typical delivery timing is agreed during kickoff based on scope and access.
Step 1
Kickoff
A 60-minute call to understand your business, pressures, existing controls, scope, data needed, and who needs to be involved.
Step 2
Review
DDG does the digging: internal and external checks, supplier and control review, posture scoring, and draft Fix-First Plan.
Step 3
Readout
A 45-minute readout with decision-makers covering posture summary, Fix-First Plan, and options for how to run it.
Why now
Most organisations have tools. Fewer have a joined-up cyber story.
The Review exists because mid-market organisations often have firewalls, policies, scans, and certifications, but still cannot answer simple leadership questions with confidence.
Vendors talk in dashboards and acronyms.
Insurers, clients, and regulators want proof you are in control.
Nobody has time for another 200-page report.
Budget is being spent, but it is unclear what has actually reduced risk.
Fit check
Is this the right move?
If you are somewhere in the middle, that is fine. A short Risk Preview call usually makes it obvious whether this Review is the right starting point.
This is for you if
You are a UK organisation with roughly 50-5,000 staff.
You have tools or Cyber Essentials but no clear joined-up plan.
You face insurance, tender, customer, or board scrutiny on cyber.
You want a clear view of risk, not a tool pitch.
You are willing to act if the case is clear and practical.
Probably not for you if
You only want the cheapest possible certificate.
You are not open to changing how you manage risk.
You want a DIY checklist you already know will not be implemented.
You only want a one-off pen test with no wider context or plan.
Review scope
What we review. No remediation in this phase.
We look across identity, infrastructure, people, and process so you see the whole risk picture, not just one tool.
Identity
Endpoints and servers
Email and web
Perimeter
Vulnerabilities and patching
Backups and recovery
Logging / SIEM
Cloud and SaaS
Suppliers
People and process
Remediation is not included in this phase. The outcome is clarity and a Fix-First Plan. If you later move into managed service, this work becomes Step 1 of that roadmap.
Investment
From GBP 2,000 + VAT, credited if you move into managed cyber.
We confirm the exact fee after the initial Risk Preview call, once scope, assumptions, and timing are clear.
The point
You are not buying a PDF. You are buying a short, independent path from uncertainty to a funded, owned, and sequenced plan.
Review investment
GBP 2k+
Starting price plus VAT. Final fee is confirmed after the Risk Preview, once scope, assumptions, and access are clear.
Managed cyber credit
Credited if you move into managed cyber.
100%
Payment
Split available
Example: 50% to start and 50% at readout.
Availability
Limited slots
Priority starts can be arranged when timelines are tight.
What removes risk from the buying decision
Pricing starts from GBP 2,000 + VAT and is confirmed once scope is agreed.
Split payments are available, for example 50% to start and 50% at readout.
100% of the agreed Review fee is credited if you proceed into managed service.
Clear scope, deliverables, assumptions, and timing are agreed up front.
Book a 30-minute Risk Preview
Ready to actually manage cyber risk, not just collect tools?
We will confirm fit, answer questions, agree terms, and schedule your kickoff. No pressure, no scare tactics.
Pricing starts from GBP 2,000 + VAT and depends on scope. If you move into managed cyber, the Review fee is fully credited.
