Know what's putting
your business at risk.
Beacon is a structured risk assessment for small and medium businesses. In a single day, we check your identity security and device posture, see how your team is using AI tools, scan for brand exposure and data breaches, and hand you a plain-English report — no jargon, no software to install, no ongoing subscription. Works whatever platform you're on — Microsoft 365 unlocks a few extra automated checks, but it's not a requirement.
The problem
AI tools are in your business. Do you know what they're doing with your data?
Devon and Cornwall's business landscape is 96% SME. Most of those businesses have no dedicated IT staff, but they're adopting AI tools, storing customer data in cloud services, and being asked by insurers and larger clients to demonstrate their cyber posture. The gap between "we think we're covered" and "we know we're secure" is where the risk lives.
chain
Coverage
What Beacon checks
Seven domains, checked systematically — automated wherever your existing systems allow it, backed by a structured interview everywhere else.
Identity & Access Control
MFA adoption rates, conditional access policies, admin role assignments, and stale or ex-employee accounts still active in your directory.
Data Sharing & Storage
Files and folders shared externally or via anonymous links — the most common source of accidental data leakage in SMEs using cloud file storage.
Device & Patch Compliance
OS patch status, malware protection state, and device compliance posture across managed endpoints — flagging devices that are out of date or unprotected. Depth here depends on what device management is already in place.
AI & Shadow Tool Usage
Which AI tools — ChatGPT, Copilot, Gemini, Perplexity and others — are in active use across your network, and whether sensitive data may be leaving the business through them.
Cyber Essentials Alignment
A structured gap analysis across the five Cyber Essentials controls: firewalls, secure configuration, access control, malware protection, and patch management.
GDPR Accountability
A light-touch review of data flows, third-party processors, breach readiness, and record-keeping — structured as a practical checklist, not a legal opinion.
Brand & Exposure
Whether your business email domain has appeared in known data breaches, lookalike domains registered by others, services exposed to the internet, and brand mentions flagging potential reputation issues.
Process
How a Beacon assessment works
A structured, low-disruption process — most of the work happens in the background while you get on with your day.
Pre-visit setup
We send you a short pre-visit checklist. If you're on Microsoft 365, your IT contact or admin grants read-only access ahead of time — a one-time step that takes around 10 minutes and unlocks extra automated checks. If not, we cover the same ground on the day.
Assessment day
We run the Beacon toolkit against your environment — pulling identity, data, device, and brand data automatically — while conducting a structured interview to cover GDPR and Cyber Essentials areas that can't be read from an API.
Report & recommendations
You receive a plain-English report — no audit jargon — with findings rated by severity and a prioritised list of actions. Suitable to share with insurers, supply-chain contacts, or your board.
The deliverable
A report your whole team can act on
Beacon produces a structured risk assessment report — written for business owners, not IT professionals. Every finding is rated by severity and paired with a clear, actionable recommendation.
Executive summary
Overall risk score, top three findings, and a plain-English statement of your current posture.
Domain-by-domain breakdown
A score and grade for each of the seven check areas, with the specific findings behind each score.
Prioritised action list
Critical and high-severity findings listed first, each with a specific recommendation and a link to the relevant Microsoft or NCSC guidance.
Cyber Essentials alignment
A checklist summary showing where you stand against the five CE controls — useful if you're planning certification.
Pricing
Straightforward, upfront pricing
One flat price per assessment, based on company size — no day-rate guesswork, no surprise invoice.
A full single-day assessment, sized for micro-businesses and small teams.
- All seven check domains
- Full plain-English report
- Cyber Essentials alignment summary
Our most common engagement size — more directories, devices, and data to cover.
- All seven check domains
- Full plain-English report
- Cyber Essentials alignment summary
Larger SMEs with more users and devices to assess — still delivered in a single day.
- All seven check domains
- Full plain-English report
- Cyber Essentials alignment summary
More than 250 employees or multiple sites?
This is a risk assessment, not a software subscription
Beacon is a day-rate consultancy service delivered by Selectred Datum. There is no software to license, no monthly fee, and no ongoing agent running in your environment after the assessment is complete. We come in, check things, hand you a report, and leave. You own the findings. If you want a follow-up assessment in six or twelve months to track progress, we quote for that separately.
Common questions
FAQ
Do we need Microsoft 365 to use Beacon?
No. Microsoft 365 unlocks a few extra automated checks around identity and device management, but it's not a requirement — AI tool usage, brand exposure, GDPR, and Cyber Essentials alignment are checked either way, through a mix of external checks and a structured interview. Whatever platform you're on, we flag anything that can't be checked automatically and cover it manually instead.
Is Beacon a formal audit?
No. Beacon is a structured risk assessment and gap analysis — we use the language "risk assessment" and "aligned with Cyber Essentials controls" deliberately. Formal ISO 27001 certification, Cyber Essentials certification (issued only by IASME-accredited bodies), and DORA compliance are outside our scope. The report is an indicative posture check, not a certified audit.
What access do you need to our Microsoft 365 tenant?
Read-only access via a registered Azure AD application. Your Global Admin grants admin consent before the assessment — we send the exact steps in the pre-visit pack. We never request write permissions, and access is scoped to the audit endpoints only. You can revoke it at any time after the assessment.
Can we share the report with our insurer or a client?
Yes — the report is designed to be shareable. It includes a clear disclaimer that it is an indicative risk assessment rather than a certified audit, which is the language most insurers and supply-chain contacts expect.
Get started
Book a Beacon assessment
Tell us about your business and we'll come back with availability and a quote. Most assessments are completed in a single on-site day.
Or email us directly at support@selectred.com