Security-led managed cyber security · York & Yorkshire

Security-led IT, watched around the clock and proven every month.

Most providers bolt security on. We start with it, run it for you, and hand you the evidence, so you stay secure, compliant and covered without taking it on trust. Managed security for Yorkshire businesses that can't afford to get it wrong.

Not sure where you stand? Take our free Cyber Essentials self-check.

Cyber Essentials certification Huntress partner NinjaOne partner Independently audited by Aikido

Bolted-on security fails quietly, until it doesn't.

Nobody is watching it. Most breaches don't start with a sophisticated attacker. They start with security that was added as an afterthought: antivirus with nobody reviewing the alerts, patches that stall for months, and no one who can tell you, in plain English, whether any of it is actually working today.
43%

of UK businesses breached in 2025/26

Just over four in ten UK businesses reported a cyber security breach or attack in the past twelve months, DSIT Cyber Security Breaches Survey 2025/2026.

39%

took no preventive action after a breach

Of businesses that experienced a breach or attack, 39% reported taking no action to prevent future incidents. Familiarity normalises risk, until the consequences escalate.

5

controls address most commodity attacks

DSIT's own research shows the five Cyber Essentials controls address the attack vectors behind the majority of incidents affecting UK SMBs. Certification is evidence of having applied them.

Source: DSIT Cyber Security Breaches Survey 2025/2026 (published April 2026).

Want to know where you sit against the five controls before you talk to us? Try our free Cyber Essentials self-check and see your gaps in about five minutes.

Security-led, not bolted-on

Most managed providers are IT-first: a helpdesk with antivirus added on top. Wolds Cyber is built the other way round. The security layer is the core, recurring service you're paying for, not an add-on to a support contract.

Patched and monitored, every day

Powered by NinjaOne RMM. Every device is monitored for health, software inventory and patch status, with operating system and third-party patches applied automatically on schedule. Problems get caught before they become outages, not after a phone call.

Watched around the clock

Powered by Huntress. 24/7 managed detection and response across endpoints and Microsoft 365 accounts, backed by a dedicated security operations centre that responds when something looks wrong, not just when someone happens to notice.

Secure, in practice, means protection that's active every day, not a policy document in a drawer.

Provable, not promised

You shouldn't have to take anyone's word for your own security, including ours. Every client gets a live, plain-English view of what's protected, what's been watched, and what's been fixed, so trust is something you can check, not something you're asked for.

What you actually get

  • A live posture dashboard: log in any time to see what's patched, what's been detected, and what's been fixed
  • A posture score you can watch trend over time, so you can prove your security is holding, not just assume it
  • Full disclosure of the vendors in your stack, including the honest fact that our detection tooling comes from established, US-based security vendors, the same as almost every managed security provider. We don't pretend otherwise
  • Where it matters most, your posture reports and assessment findings, hosted on UK infrastructure we own and control, not resold through a reseller's portal

Wolds Portal, live now

The Wolds Portal client dashboard: a security posture score of 98 (Excellent), with the Devices tile flagged amber 'Watch, 1 needs attention' alongside healthy patching, threats and EDR tiles, and a score-over-time trend

Caught live: this is a real screenshot from our own portal, not a mock-up. One device just tripped the Devices tile amber, before anyone rang to complain.

Your own self-hosted dashboard, pulling your NinjaOne and Huntress data into one plain-English view: your score, what's healthy, and how it's trending. Hosted on UK infrastructure we own, behind mandatory two-factor sign-in.

Charles Cassam, founder of Wolds Cyber Ltd

Charles Cassam

Founder, Wolds Cyber Ltd, East Yorkshire

I spent over a decade in automotive management, franchised dealer, independent garage, Bosch Car Service implementation. That background taught me how operational failures actually propagate, and how to communicate technical findings to people who need to act on them, not just read them.

A named, accountable contact

Responsive by design. The person you brief about a security concern is the person accountable for it, not a ticket queue routed through account managers. No hand-offs, no shadowing juniors.

Managed IT, if you want it

Beyond security, we can also modernise and run your day-to-day IT under the Wolds brand, with routine helpdesk tickets handled by a white-label support partner. It's a secondary service. For anything security-related, you're still talking to me directly.

Where your data actually sits

When we run an assessment or host your posture reporting, it stays on UK infrastructure we own, not a vendor's multi-tenant cloud. The detection and monitoring tools underneath, named openly above, are provided by established security vendors. You always know which is which.

From £14 per user, per month

£14/user/month

5-user minimum. Covers remote monitoring and patch management, 24/7 threat detection and response, and your own live posture dashboard in the Wolds Portal. Onboarding is quoted separately once we know your starting point.

Two lines, one relationship

We sell continuous protection and continuous compliance. Assessment is part of both, at the start and then every month after. It is not something we invoice on its own.

Compliance

Watch, Certify and Assure. Continuous control monitoring and policy management, with Cyber Essentials certification included from Certify upward and CE Plus from Assure. From £300 a year.

Compare the three tiers →

A certificate proves a day. We prove the year.

A Cyber Essentials certificate says that on the day you were assessed, five technical controls were in place. That is worth having, and we get clients through it. It is not the same as being secure in November.

Between one certificate and the next, somebody joins. Somebody leaves and keeps their login. A laptop misses three patch cycles because it lives in a van. For applications registered after 26 April 2026, the scheme itself agrees with us: miss multi-factor authentication on a cloud service, or fall behind 14 days on a critical patch, and the assessment is an automatic fail. Those are the exact things a certificate on the wall cannot tell you about, and continuous monitoring can.

So we are a security-led firm that does not sell certificates on their own. You get the certificate where you need one. You also get a dated report, every month, showing what was patched, what was blocked and what is still open.

Built for businesses with something to protect

Regulated and exposed sectors where a security failure means more than downtime, it means a breach notification, a lost contract, or a regulatory finding.

📄

Accountants

HMRC data handling obligations, client financial records

🚚

Logistics

Ransomware exposure, operational continuity, supply chain

👥

Professional Services

Candidate data, client records, GDPR, regulatory exposure

🚗

Motor Trade

Insurer-approved bodyshops, fleet SMBs, leasing brokers, dealers handling consumer finance

Common questions

Straight answers.

It means the security layer comes first, not last. Instead of a standard IT helpdesk with antivirus bolted on, the core of the service is remote monitoring and patch management through NinjaOne RMM, plus 24/7 managed detection and response through Huntress, with everything else built around that, including day-to-day IT support if you want it.
Every managed client gets remote monitoring and automatic patch management across their devices, 24/7 threat detection and response backed by the Huntress security operations centre, and a live posture dashboard showing what's been patched, what's been detected, and what's been fixed. Higher tiers add Microsoft 365 hardening, managed email security, cloud backup, and quarterly reviews. Full tier detail and pricing is on the managed security page →
Every client gets direct access to their own live posture dashboard in our client Portal: your score, what's healthy, and how it's trending. We're also upfront about what sits underneath: the monitoring and detection tooling, Huntress and NinjaOne, is provided by established, US-based security vendors, the same as almost every managed security provider in this category. We say so plainly rather than dressing it up, because provable security means being honest about the whole stack, not just the parts that sound good.
Partly, and we're specific about which part. Your posture reports and assessment findings are hosted on UK infrastructure that we own and control. The monitoring and detection tools that generate that data, Huntress and NinjaOne, are US-based platforms, as is virtually every credible tool in this category. We name them openly rather than implying otherwise.
Not necessarily. Many clients keep their existing IT provider or internal team for day-to-day support and bring us in purely for the security layer. If you would rather have one point of contact for everything, we can also provide managed IT under the Wolds brand, with routine helpdesk tickets handled by our white-label support partner and Charles remaining the named contact for anything security-related.
Cyber Essentials is usually where the relationship starts, not where it ends. It is a fixed-price, one-off certification that satisfies an insurer, a tender panel or a client doing due diligence. Many clients then move into the ongoing managed service once they have seen how we work, others keep Cyber Essentials as a standalone annual renewal. Either is fine, there is no obligation to take the managed service to get certified.

Ready to make security something you can prove?

Book a free call. We'll talk about where you stand today, what a security-led managed service would look like for your business, and whether Cyber Essentials should be the first step.

Book a call

Or see how managed security works →

Free Website Security Check

Scan your website for SSL issues, missing security headers, and DNS vulnerabilities. Instant results, no sign-up required.

Scan Your Website Free