Skip to main content
CY6Check Your Six

How we work

Predictable by design, because surprises are the expensive part

Most of the value in managed technology is not clever engineering. It is the same things happening on the same schedule for years, documented well enough that anybody could pick them up.

Onboarding

Your first fifteen days

  1. Day 1

    Kickoff

    We agree what success looks like, who we call for what, and how your people reach us. You leave the call knowing the support number, the escalation path and the next three dates.

    You getSupport channels live, named contacts on both sides, dates set

  2. Days 2-5

    Discovery

    We inventory what you actually run — devices, servers, cloud tenants, line-of-business software, licences, network gear and the things nobody remembered. We look for risk and for money being wasted, and we usually find both.

    You getFull asset inventory and a prioritised findings list

  3. Days 6-7

    Documentation

    Findings become a plan. You get a written roadmap, the policies your obligations require, and a clear split of what we own versus what stays with you. No surprises later about who was supposed to do what.

    You getRoadmap, security plan and a responsibility matrix you keep

  4. Days 8-14

    Deployment

    Agents, protection, backup and identity controls are rolled out in a deliberate order, mostly outside working hours. We fix the urgent findings from discovery as we go and tell you when something needs a decision.

    You getEvery covered device monitored, protected and backed up

  5. Day 15+

    Steady state

    Routine takes over: monitoring, patching, tickets, tested restores and a review each quarter. The roadmap stays current, so the next twelve months are planned rather than reactive.

    You getMonthly summary, roadmap kept current, quarterly review if you want one

Afterwards

The rhythm once you are running

Steady state is where the relationship actually lives. Here is what recurs, and how often.

  • Continuous

    Monitoring and automated response

    Agents watch every covered device and cloud tenant. Common faults are remediated automatically. Anything that needs judgement raises a ticket with a human name on it.

  • Same day

    Helpdesk

    Your people contact us directly rather than going through an internal gatekeeper. Nothing waits for a weekly IT slot.

  • Monthly

    A summary you can read in five minutes

    Tickets raised and closed, patch status, backup and restore results, anything that needs a decision. Two pages, plain English, no dashboard login required.

  • Quarterly

    Business review

    We sit down with what changed, what is ageing out, what the next twelve months cost, and what we would do next if it were our firm.

  • Annually

    Risk assessment and plan refresh

    The security plan, risk register and remediation list are brought current so they match reality rather than last year's intentions.

Scope

Six positions, watched continuously

What is under watch while all of the above is happening.

  • ENDPosition 1

    Endpoints

    Every laptop, desktop and server, monitored for failure and for attack.

  • IDNPosition 2

    Identity

    Who can sign in, from where, with what — and who no longer can.

  • EMLPosition 3

    Email

    Impersonation, payment redirection and the messages that look legitimate.

  • DATPosition 4

    Data

    Backups taken, copies held off-site, and restores proven rather than assumed.

  • NETPosition 5

    Network

    Firewalls, remote access and the boundary between your office and everything else.

  • OBLPosition 6

    Obligations

    The evidence your regulator, insurer or largest client will ask for.

Boundaries

What we will not do

Worth saying out loud, because it is how you tell one managed provider from another.

Sell you something you do not need

If your existing firewall is fine, we will say so and keep it. Our margin does not depend on replacing hardware.

Hide behind a portal

You get people and a phone number. Ticket systems are for us to track work, not for you to shout into.

Claim you are compliant

We implement controls and produce the evidence for them. Whether that satisfies your legal obligation is a call for you and your counsel, and we will not blur the two.

Questions

Everything people ask

How the work runs, who does it and what we will and will not take on. Questions about money, contracts and commitment are answered on the pricing page instead.

Do we have to replace everything we already have?

Usually the opposite. Most of what you own is probably fine and just unmanaged, set up once by somebody who has since moved on. We insist on replacing the things that are so far out of support that keeping them costs more than changing them. Everything else comes back as a list with dates against it.

We already have an IT person. Does that rule us out?

Not at all, and they are usually glad to see us. The internal person is good at the things closest to the business. Nobody enjoys being the one who has to care about patching at eleven at night. We will also tell you if the two of us would overlap, including when that means you do not need us.

How fast do you respond?

Depends how much it is hurting you. A whole office down and one slow printer are not the same event and we do not price them as though they are. The actual targets are published rather than implied.

See the response targets
Can you work with our practice-management or clinical software?

Yes, and we will talk to the vendor for you if you would rather not relay messages between two technical parties. Some firms prefer to keep that relationship themselves, which is fine.

We will also say when a vendor requirement, or something your office already does, is the actual security problem. That conversation is awkward. It is also the one worth paying for.

What is the $100,000 cybersecurity warranty?

A warranty on the security stack we deploy, included with Complete. It is not insurance and does not replace it. The conditions are published rather than buried, because a warranty you cannot read the conditions of is just a number.

Read the warranty conditions
Do you only work with regulated firms?

No. Regulated firms are where we are most useful, because the evidence side is hard to carry alone. But the real test is simpler: would a bad week offline genuinely hurt? If not, we will tell you so.

Where are you based, and do you come on site?

Most of it is remote. That is the only reason a firm of fifteen can afford cover around the clock at all. We come to you for the things that need hands: new offices, hardware, cabling, and the occasional problem that has to be looked at in person.

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967