Preliminary answer / Security needs attention

Reduce practical risk.
Do the important things first.

Security is not one product. It is the coordinated protection of identities, devices, systems, data, backups and the people who use them.

The preliminary answer

What we can say before seeing the environment.

Redstone begins by identifying the business-critical systems, likely exposure and weakest operational controls. The first recommendations usually focus on identity, endpoint protection, patching, backup recoverability, network exposure and clear incident ownership.

See what Redstone would do first

Recognise the situation

This is the right starting point when…

An insurer or customer has questions

You need evidence of controls, responsibilities, backup, access and incident readiness.

Access has grown informally

Former staff, shared accounts, inconsistent MFA or excessive permissions are creating risk.

Backup confidence is low

Backups exist, but recovery, retention, isolation or ownership has not been tested.

A security event may be underway

Suspicious sign-ins, malware, lost devices or unusual activity need controlled investigation.

What Redstone would do first

A useful first engagement with a clear outcome.

The exact technical work depends on the environment. Redstone begins with a disciplined sequence that protects the business and makes the next decision clearer.

01

Step 1

Triage immediate risk

Separate an active incident from a planned improvement engagement.

02

Step 2

Map critical assets

Identify identities, data, systems, devices, backups and external exposure that matter most.

03

Step 3

Validate core controls

Review access, MFA, endpoint security, patching, recovery and administrative responsibility.

04

Step 4

Prioritise improvements

Create a practical sequence based on business impact, likelihood, effort and dependencies.

Preliminary expectations

What the first step may look like.

These details help with early planning and scheduling. Redstone confirms the actual scope after understanding impact, access, dependencies and risk.

Typical engagement

An Initial Fit and Environment Review can identify general priorities. When documented technical findings are required, a scoped technical assessment produces a prioritised report. Urgent containment, remediation and ongoing managed security are scoped separately.

Timing expectation

A focused review commonly takes 3-5 business days after access and information are available. Remediation is usually staged: urgent exposures first, foundational controls next, then longer-term standards and reporting.

Scope confirmation

The assessment boundary identifies the systems, identities, devices, evidence, testing limits and required deliverables. Remediation is defined separately after the findings are understood.

Written confirmation: your proposal or agreement states the scope, availability, responsibilities and response commitments before work begins.

Help us answer faster

A little context can shorten the first conversation.

You do not need a technical brief. If the information is available, a short checklist helps us route the request and identify the right first step.

Before the first conversation

Useful information to have, if it is available.

You can still contact Redstone without these details. They simply reduce back-and-forth and help us identify the right person and first step.

Primary business systems and sensitive information

Microsoft 365 or identity environment

Device, server and site counts

Current security, backup and firewall tools

Known insurance, customer or regulatory requirements

Recent alerts, incidents or areas of concern

Tell Us What You Need

Before you contact us

Three useful answers.

These answers are intended to help you decide whether Redstone is a sensible next conversation, not force you into a form.

Can Redstone certify that we are secure or compliant?+

No provider can responsibly promise absolute security. Redstone can assess defined controls, document evidence and help close practical gaps. Formal certification or legal interpretation may require a specialist assessor.

What if we think an attack is happening now?+

Call rather than relying only on a web form. Redstone will confirm availability and the immediate containment path; do not destroy logs or make uncontrolled changes unless necessary to protect the business.

Do we need to replace every existing security tool?+

Not automatically. We first determine whether the current tools are appropriate, configured, monitored and supported. Gaps in ownership and operation can matter as much as product choice.

Raise your technology standard

Start with a clear view of your environment.

New clients can begin with a fit and environment review: a preliminary business and technical conversation that clarifies the current situation, desired outcome and most useful next step.

Preliminary fit and environment review

Priorities aligned to business goals

A practical proposal and next steps