Cyber security · South Wales

Scary slide decks.
Real security, for real South Wales businesses.

Most cyber security sales pitches are designed to frighten you into buying everything. Ours is designed to work out what you actually need. Cyber Essentials, Cyber Essentials Plus, endpoint protection, phishing training and incident response, priced so small businesses can afford proper cover.

Free exposure review What do we do?
Free exposure review · 2h response

What are you actually exposed to?

Tell us your biggest current concern and we'll come back with a short written review of where you stand. No obligation, no sales call.

Written review · human response Free · No obligation
Start here

Four honest scenarios. Find the one that sounds like you.

Before we talk about tools, let us work out what you actually need. Cyber security is not one purchase, it is a set of decisions sized to your business.

01 · Getting certified

"Our biggest client has asked for Cyber Essentials. We do not know where to start."

We get you through certification first time. Cyber Essentials is a self-assessment verified by an auditor, and CE+ adds an on-site technical audit. Most businesses need some prep work first: we scope it honestly, fix what needs fixing, then submit. Usually 3 to 6 weeks end to end.

You want CE or CE+ · project-based
02 · Phishing protection

"Someone clicked something. We got lucky but we're worried about next time."

Phishing is now the single biggest threat to small businesses. Managed email filtering, MFA enforcement and monthly simulated phishing training turn your team from risk into defence. Priced per user, starts from a few quid each.

You want Phishing defence · from £6 per user / month
03 · Active incident

"Something is happening right now. We do not know what."

Stop reading, call 01656 521505. If you are an existing client an engineer picks up immediately. If not, we will respond within two hours during working hours. Quick first move: disconnect affected systems from the network from a different device.

You want Incident response · call now
04 · Compliance coming up

"We have an audit or tender asking cyber questions. We need to look legitimate."

Compliance-driven cyber projects are short, focused, and deliverable. We tell you what the auditor actually wants to see, build it, document it, and rehearse you for the questions. CE+ certificate on the wall helps with most UK tenders.

You want Compliance prep · fixed price
Why bother with us

Three things most cyber sales pitches will not tell you.

Cyber security is full of vendors selling fear. We would rather sell you a written plan, and the minimum set of tools to run it.

01 · Advice

We will tell you when you do not need a product.

Most cyber checklists try to sell you everything. MFA, patching and proper backup beat 80% of small business threats for almost no cost. We recommend paid tools when they genuinely move the needle.

02 · Certification

Cyber Essentials that actually passes first time.

We have walked dozens of South Wales businesses through CE and CE+. We know what the assessors look for, what trips people up, and how to get the certificate on your wall without drama.

03 · Integration

Cyber is part of your IT, not a separate thing.

Security baked into how your IT is actually run is ten times more effective than a bolt-on. Because we handle your managed IT too, every control we recommend is something we can actually maintain.

What we offer

Everything we do, priced honestly.

Pricing is typically per user or per device, but some services are project-based. For example, Cyber Essentials is a fixed project while antivirus is a monthly licence. We will give you a written breakdown, not a single vague figure.

🛡️
Cyber Essentials
CE + CE+
Full prep and submission for Cyber Essentials and Cyber Essentials Plus. We fix what needs fixing, submit your evidence, and stay with you through the technical audit.
🔒
Endpoint protection
Managed AV + EDR
Proper endpoint detection and response (not just free antivirus). Managed detection, response and rollback on every laptop and desktop.
📧
Email filtering
Anti-phishing + anti-spam
Stops phishing, spoofing and payload emails before they reach your staff. Reduces the number of times a user even has to make a decision.
🎓
Phishing training
Monthly simulations
Short monthly training modules plus simulated phishing campaigns. Your click rate tracked over time so you can see improvement.
🕵️
Dark web monitoring
Continuous alerts
We watch for your company email addresses turning up in breach dumps and compromised credential lists. If we spot one, we tell you within hours.
🔍
Vulnerability scanning
Monthly + on-demand
Automated scans of your external surface and internal network. Scored, prioritised, and paired with a plan to fix what matters first.
🚨
Incident response
Per-engagement
If something is actually happening, we deploy engineers, contain the blast radius, coordinate with your insurer, and help get you back running.
MFA rollout
Project-based
The single highest-leverage security change most businesses can make. We design the policy, handle the rollout and support your staff through the change.
What happens next

From "I am worried" to "we are covered", without the scare tactics.

Here is exactly what happens when you request an exposure review.

01
Exposure review
Within 48h
Short written review based on your answers: where you stand, what the quick wins are, what to prioritise.
02
Scoping call
If you want
We walk through the review, you ask questions, we propose a shape. No pressure to buy anything.
03
Quote
One page
Fixed-price projects, clearly-priced tooling, a sensible starting point. No "enterprise" packages.
04
Deploy
2 to 6 weeks
Tooling rolled out, policies deployed, staff trained. Weekly update while we set up, then handover.
05
Maintain
Ongoing
Monthly reports, quarterly reviews, re-certification support. Security is not a one-off purchase.
Local coverage

Protecting businesses across every South Wales postcode.

We look after the cyber security of businesses from Bridgend to Newport, Swansea to the Valleys. Click through to your area for local context.

Questions we hear a lot

Common questions about cyber security for South Wales businesses.

If yours is not here, ask it in the widget above and we will answer properly.

How much does Cyber Essentials certification cost?

The certification itself is around £320-£500 per year depending on business size, paid to IASME. Our role is helping you pass first time, which for a typical small business is around £500-£1,500 of support depending on how far off you currently are. Ongoing tooling (AV, MFA, patch management) is priced separately, typically from £6 per user per month.

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment verified by an auditor. Cyber Essentials Plus adds an on-site technical audit where we test your defences live. CE is the entry bar; CE+ is what larger buyers and public sector contracts want to see. We do both.

Do you do penetration testing?

Yes, we run targeted pen tests to validate your controls are actually doing what you think they are. Most small businesses do not need a full CREST-grade test; a scoped engagement on your key apps or external surface is usually the right move.

How do you price cyber services?

It depends what you need. Certification support is a fixed project. Tooling like endpoint protection or email filtering is per user per month (typically £3-£10 each). Incident response is quoted per engagement. We will give you a written breakdown rather than a single vague price.

We had an incident. Can you help right now?

If you are an existing client, call 01656 521505 and you will get an engineer immediately. If you are not, email hello@thornetechnology.co.uk with 'INCIDENT' in the subject and we will respond within two hours during working hours. For active ransomware, we recommend disconnecting systems from the network first and calling us from a different device.

Do you do staff awareness training?

Yes. Simulated phishing campaigns, short monthly training modules, and reporting for the board. Included in Professional and Advanced IT support tiers, or available standalone from around £3 per user per month.

Not sure where you stand? Find out for free.

A short written review of where you are exposed, what to fix first, and what it would cost. No sales call, no follow-up nag.

Get my free review →