The Assessment
Three ways information leaves a building.
An Exposure Assessment looks at all three. Most assessments look at one.
Machines
Cameras, microphones, access control, conferencing hardware, printers. Most are cloud-connected by default, streaming the inside of a building — often including audio — to a vendor's servers in another state, retained under that vendor's terms, reachable by people you have never met.
We find every device that observes or records your premises, establish what it actually captures, and follow the output to wherever it ends up.
Tools
AI services, SaaS platforms, third-party processors. Staff paste confidential material into consumer chat interfaces every day — on personal accounts, with no data processing agreement and no way to retrieve what was submitted. Most practices have no idea it is happening.
We establish what is actually in use, what those services retain, and under whose terms.
People
The channel every technical control ignores. Most breaches involve a person persuaded to do something rather than a system defeated — and voice cloning has moved that from a specialist capability to a consumer one.
We look at who holds access, how access is granted and revoked, and what an outsider could learn about your firm from public sources alone.
This is organisational, not personal. No individual is investigated, profiled, tested or surveilled.
The exposure is usually in the interaction.
Cybersecurity firms handle tools and stop at the building's edge. Physical security firms handle machines and ignore data. Neither examines how the two interact, and few examine people at all.
A camera is a machine problem until its audio reaches a vendor. A shared alarm code is a machine problem until the cleaning contractor's staff turnover makes it a people problem.
What actually happens.
Before the visit.
A short information request, most of which your office administrator can answer in twenty minutes. Answering it in advance means the time on site is spent on what only physical presence can find.
On the day.
A half-day walkthrough. Structured interviews with your office administrator, your IT provider, and any staff you nominate. Review of vendor terms and system configurations you make available. Anything critical and free to fix, we tell you before we leave.
The report.
Written findings, each rated, with a prioritised remediation list. Issued within six working days.
The debrief.
An hour, in person or by phone, walking through what was found.
Most of what an assessment finds costs nothing to fix. We have no commercial interest in those items and recommend you do them regardless.