
Assessment and hardening
Where you actually stand across identity, endpoints, network and cloud, then the work to close it.

Demo

04Sector dossier
M3CA Cyber runs assessment, hardening, monitoring and the evidence work that follows.

19
Days to certification readiness
100%
Findings closed or accepted in writing
12m
Median containment time
The control cycle we build against
Select a stage to read what we build there.
Asset, identity and data-flow inventory across the whole estate
Nothing undocumented
Assurance ledger
The frameworks we work to and what we actually hand over under each one.
What we deliver

Where you actually stand across identity, endpoints, network and cloud, then the work to close it.

Detection tuned to your environment, with a named response path when something fires at 3am.

Policies, controls and artefacts assembled so an audit is a retrieval exercise rather than a scramble.

Phishing simulation and training, because the control that fails most often is a person under pressure.
Featured work
On M3CA TV
What we refuse
Reports with no remediation attached. A PDF of findings is half a job.
Compliance theatre. If a control exists only for the certificate, we will say so.
Silent risk acceptance. Anything left open is signed for by a named person.
Disciplines
Switch sector
Start
An audit date, a failed pen test, an estate nobody has mapped. We will start with what is open and work down.