Skip to content
NJOKEYTalk to us

Security & trust

Trusted with IT
means trusted with a lot.

You’re trusting us with the tools your business runs on. We take that responsibility seriously: the right access, clear decisions and someone accountable for the work.
Only the access we need
Least privilege means limiting administrative access to what is needed for the service. We review required systems, roles and permissions during onboarding.
Ask before the big changes
Sensitive access, purchasing and higher-impact actions need the appropriate authorisation. A model recommendation does not bypass that boundary.
A clear record of the work
Administrative actions should be recorded and attributable. We retain the context needed to explain what was attempted, who authorised it and what was checked.
Care with credentials
Administrative credentials and secrets need controlled handling. We agree the credential and access arrangements for your environment rather than asking employees to share passwords in ordinary support messages.
Separation between customers
Customer environments, access and credentials must remain appropriately separated. Tenant-scoped controls are part of the internal platform; service access is agreed for each organisation.
A person when it matters
Uncertain or high-risk situations are escalated. Automation does not replace the person responsible for deciding how to proceed.
Fixed means checked
Where possible, we verify that a repair had the intended effect. If evidence is missing or a check fails, the work needs follow-up.

What the security service covers.

Practical, everyday protection across the systems we manage. Deeper or specialist work is delivered through appropriately qualified partners where it’s needed.

Security baseline & configuration

A sensible starting configuration for devices, identities and Microsoft 365 or Google Workspace, reviewed as things change.

Endpoint protection & patching

Managing endpoint protection and keeping operating systems and supported software up to date on managed devices.

Identity & MFA

MFA adoption, identity security, access reviews and investigation of suspicious sign-ins where supported.

Email & phishing

Email security configuration, phishing protection and email authentication such as SPF, DKIM and DMARC where appropriate.

Vulnerability remediation

Identifying weaknesses in the areas we manage, fixing the ones inside the agreed service and tracking the rest.

Access reviews

Checking who can reach what, and removing access that is no longer needed.

Backup posture

Reviewing whether the right things are backed up and whether recovery would actually work.

Incident coordination

A clear escalation path when something goes wrong, with account containment where authorised.

Security awareness

Coordinating practical security awareness for your team, so the human side is not ignored.

Practical security,
with clear boundaries.

We help with MFA adoption, security configuration, patches, access reviews and suspicious-activity investigation within the agreed service.

Specialist incident response, MDR or SOC coverage may require separate services. We don’t promise that every incident can be prevented or automatically resolved, and we don’t claim to run a 24/7 security operations centre.

How our technology is controlled →

Getting ready for
Cyber Essentials.

If a customer or contract needs Cyber Essentials, we help you understand what’s missing, fix the technical gaps we manage and organise the evidence an assessor asks for.

There’s a difference between helping you prepare and being certified. We help you get ready; the certificate itself is issued by a licensed assessor, not by us. The same applies to Cyber Essentials Plus and similar frameworks.

Ask us the detailed questions.

We’ll discuss access, support coverage, data handling and the controls relevant to your company before you appoint us.

IT, handled.

Let’s take IT off your plate.

Tell us what’s getting in the way of work. We’ll talk through how we can help.

Talk to Njokey