A defined, proportionate first engagement for SMEs that need direction on cyber risk — not an open-ended project, and not a subscription. One clear deliverable, one fixed price, delivered by Franco personally.
Most SMEs sit between two extremes: a free initial conversation that doesn't produce anything written down, and an open-ended consultancy relationship they're not ready to commit to. The Cyber Resilience Review fills that gap — a fixed-scope, fixed-price engagement that gives you a proper written assessment and a practical plan, with no assumption that anything further follows. Some clients stop there. Others use it to decide, with evidence, whether ongoing support — through specific services or a vCISO retainer — actually makes sense for them.
The Review tends to suit owner-led SMEs facing one or more of the following — not every business needs it, and if any of these don't apply to you yet, that's a reasonable place to be.
If you'd rather start with something free first, the Cyber Risk Assessment and Cyber Vitals scan are both no-obligation starting points — see how they fit together on the Resilience Roadmap.
Both are fixed-price, both are scoped upfront — no surprises once the engagement begins.
The policy option gives you a monitoring framework and recommendations to adopt — it does not include
ongoing monitoring or policy administration on our part.
All prices exclude VAT. GET-IT Solutions Ltd is not currently VAT registered.
Initial discovery and business-context review, so the assessment reflects how your organisation actually operates.
Operational resilience, external digital exposure, Cyber Essentials readiness and key-control review.
Prioritised written findings and a practical 90-day roadmap — what to address, and in what order.
A review call to explain the findings and talk through recommended next steps in plain language.
Every roadmap is specific to your findings — these are the kinds of areas that commonly appear.
The Review gives you an independent, proportionate assessment and a practical plan. To keep that clear, it's worth being explicit about what it doesn't include. Where any of these are actually what you need, they can be discussed and scoped separately.
Cyber risk is increasingly a leadership and governance issue, not simply an IT task. The Cyber Security and Resilience Bill, currently progressing through Parliament, proposes stronger duties for organisations delivering essential services and for parts of their digital supply chains — it does not directly regulate every SME, accountant, insurance broker or law firm. It remains subject to Parliamentary approval and amendment, and may change before Royal Assent.
What it reflects is broader than its direct scope: a wider movement towards stronger cyber governance, documented risk ownership, supply-chain assurance and operational resilience — trends already showing up in client contracts, tender requirements and insurance renewals for businesses well outside the Bill's direct reach. You can read the Bill's progress at the UK Parliament Bills page.
The Cyber Resilience Review is not legal advice and is not a formal assessment of compliance with the Cyber Security and Resilience Bill or any other legislation.
The Review establishes where you stand today. The roadmap it produces sets out priorities and sequencing. The optional policy formalises how cyber risk will be managed going forward. From there, specific services address particular weaknesses, and vCISO support provides optional continuing oversight if you want it.
See how the free scans, the Review and ongoing support fit together as one journey.
View the Roadmap →Once priorities are set, specific services — Cyber Essentials, hardening, monitoring and more — address them individually.
Explore Cyber Consultancy →If ongoing oversight makes sense once you've seen the findings, GET-IT Cyber Advisory picks up where the Review leaves off.
Explore vCISO Retainer →Fixed price, fixed scope, delivered personally by Franco — with no assumption that anything follows.