Skip to content
Mon–Fri · 09:00 — 12:00 New YorkReply within 1 business daycontact@ferwyn.com
FerwynContact
FerwynToggle navigation

Cybersecurity

Audits, hardening and incident response for companies with no security team of their own. The output is a ranked list of things to do, written for the person who will actually have to do them.

What this looks like in practice

Work we have actually done, described as work rather than as capability.

Audits that end in a ranked list
Findings ordered by what they would actually cost you, with the ones you can fix this week marked. Not a hundred-page export from a scanner.
Hardening without breaking the business
Tightening a running system is a sequence, not a switch. Each step is reversible and checked against the work it might interrupt.
Access review
Who can reach what, why they still can, and which accounts belong to people who left. Usually the cheapest fix on the list.
Incident response
When something already happened: contain it, work out what was reachable, write down what we know and what we do not.

Constraints we work with

The limits that shape this kind of project. Naming them costs us nothing and tells you more than a list of technologies would.

Some systems cannot be patched
A vendor that no longer ships updates, a machine that must not reboot. Then the answer is isolation and monitoring, and we say which risk remains.
You will decide not to fix some of it
That is a legitimate business call. Our job is to make the trade-off explicit and write down who accepted it, not to press until you agree.
There is no security team to hand the report to
The findings land on someone whose main job is something else. So they are written to be acted on by that person, in order, without a glossary.
We do not certify anyone
We are not an accredited auditor and do not issue compliance certificates. If that is what you need, you need a different supplier, and we will say so early.

Where this shows up in our work

No public case study here, and there may never be one. Security work is the category clients are least willing to see written up, and publishing a sanitized version teaches a reader nothing. We would rather walk you through our approach on a real question of yours than publish a case study shaped to be publishable.

Not sure what you are exposed to?

Tell us what you run and what would hurt most if it leaked or stopped. An audit that starts from your answer beats one that starts from a generic checklist.

Start a project

We reply within 1 business day. No sales calls unless you ask for one.