Fixed-Price Cyber Resilience Review

A Clear Picture of Your Cyber Risk — And a Practical Plan to Address It

£495 fixed price · Written findings & a 90-day roadmap · No ongoing commitment

A defined, proportionate first engagement for SMEs that need direction on cyber risk — not an open-ended project, and not a subscription. One clear deliverable, one fixed price, delivered by Franco personally.

Ask a question first

Most SMEs sit between two extremes: a free initial conversation that doesn't produce anything written down, and an open-ended consultancy relationship they're not ready to commit to. The Cyber Resilience Review fills that gap — a fixed-scope, fixed-price engagement that gives you a proper written assessment and a practical plan, with no assumption that anything further follows. Some clients stop there. Others use it to decide, with evidence, whether ongoing support — through specific services or a vCISO retainer — actually makes sense for them.

Is this for you?

Built for a Specific Kind of Organisation

The Review tends to suit owner-led SMEs facing one or more of the following — not every business needs it, and if any of these don't apply to you yet, that's a reasonable place to be.

No internal cyber security or risk lead — it sits alongside someone's day job, or with an outsourced IT provider.
You handle sensitive information, client money, or systems that matter operationally if they go down.
A client questionnaire, tender, insurance renewal, near miss, board concern or Cyber Essentials requirement has prompted the question.
You want independent, proportionate advice — not an enterprise-scale consultancy programme you don't need.

If you'd rather start with something free first, the Cyber Risk Assessment and Cyber Vitals scan are both no-obligation starting points — see how they fit together on the Resilience Roadmap.

The offer

Two Clear Options

Both are fixed-price, both are scoped upfront — no surprises once the engagement begins.

Cyber Resilience Review
A clear picture and a practical plan
£495
Fixed price, one-off engagement
  • Initial discovery and business-context review
  • Structured operational resilience assessment
  • External digital exposure and website-security review
  • Cyber Essentials readiness perspective
  • Governance and key-control review
  • Prioritised written findings
  • Practical 90-day cyber roadmap
  • Review call to explain findings and next steps
Review + Cyber Risk Management Policy
Everything above, formalised
£595
Fixed price, total for both
  • Everything included in the £495 Review
  • Plus an organisation-specific Cyber Risk Management Policy:
  • Cyber-risk ownership and responsibilities
  • How risks will be identified, recorded and treated
  • Minimum control expectations
  • Supplier and third-party risk principles
  • Incident escalation responsibilities
  • Suggested monitoring measures and review frequency
  • Approval and annual-review framework
  • An editable version you can adopt and maintain

The policy option gives you a monitoring framework and recommendations to adopt — it does not include ongoing monitoring or policy administration on our part.
All prices exclude VAT. GET-IT Solutions Ltd is not currently VAT registered.

How it works

A Simple, Fixed Process

1

Discover

Initial discovery and business-context review, so the assessment reflects how your organisation actually operates.

2

Assess

Operational resilience, external digital exposure, Cyber Essentials readiness and key-control review.

3

Roadmap

Prioritised written findings and a practical 90-day roadmap — what to address, and in what order.

4

Discuss

A review call to explain the findings and talk through recommended next steps in plain language.

Deliverables

What You Receive

Written findings documentPrioritised, in plain language — not a raw scan dump.
90-day cyber roadmapA practical sequence of what to address first, second and third.
Review callFranco talks you through the findings and answers questions directly.
Cyber Risk Management PolicyEditable document, on the £595 option — yours to adopt and maintain.
What might come up

Example Categories in a 90-Day Roadmap

Every roadmap is specific to your findings — these are the kinds of areas that commonly appear.

Identity & accessAccount security, admin access and authentication practices.
Endpoint & device securityHow laptops, phones and other devices are protected and managed.
Backup & recoveryWhether you could actually recover if something went wrong.
Supplier & third-party riskWhat your IT provider and other suppliers are responsible for — and what you still own.
Governance & documentationWhether decisions and responsibilities are written down anywhere.
Incident readinessWhether there's a basic plan for what happens if something does go wrong.
Boundaries

What the Review Is — and Isn't

The Review gives you an independent, proportionate assessment and a practical plan. To keep that clear, it's worth being explicit about what it doesn't include. Where any of these are actually what you need, they can be discussed and scoped separately.

  • Penetration testing
  • Cyber Essentials certification
  • Legal advice
  • A guarantee of compliance
  • Remediation or implementation
  • Ongoing monitoring
  • An automatic retainer commitment
Why now?

Cyber Risk Is a Governance Issue, Not Just an IT One

Cyber risk is increasingly a leadership and governance issue, not simply an IT task. The Cyber Security and Resilience Bill, currently progressing through Parliament, proposes stronger duties for organisations delivering essential services and for parts of their digital supply chains — it does not directly regulate every SME, accountant, insurance broker or law firm. It remains subject to Parliamentary approval and amendment, and may change before Royal Assent.

What it reflects is broader than its direct scope: a wider movement towards stronger cyber governance, documented risk ownership, supply-chain assurance and operational resilience — trends already showing up in client contracts, tender requirements and insurance renewals for businesses well outside the Bill's direct reach. You can read the Bill's progress at the UK Parliament Bills page.

The Cyber Resilience Review is not legal advice and is not a formal assessment of compliance with the Cyber Security and Resilience Bill or any other legislation.

How it fits together

Where This Sits Alongside GET-IT's Other Services

The Review establishes where you stand today. The roadmap it produces sets out priorities and sequencing. The optional policy formalises how cyber risk will be managed going forward. From there, specific services address particular weaknesses, and vCISO support provides optional continuing oversight if you want it.

The Resilience Roadmap

See how the free scans, the Review and ongoing support fit together as one journey.

View the Roadmap →

Cyber Consultancy

Once priorities are set, specific services — Cyber Essentials, hardening, monitoring and more — address them individually.

Explore Cyber Consultancy →

vCISO Retainer

If ongoing oversight makes sense once you've seen the findings, GET-IT Cyber Advisory picks up where the Review leaves off.

Explore vCISO Retainer →

Ready for a Clear Picture and a Practical Plan?

Fixed price, fixed scope, delivered personally by Franco — with no assumption that anything follows.

Ask a question first