IT services · Cybersecurity Services
Security work that survives contact with your actual budget.
A 200-page assessment nobody acts on is worse than nothing, because it converts a real risk into a filed document. We deliver a ranked list you can work through, starting with the items that would actually end your week.
—— Where it hurts
The problems this work actually solves.
Most SME security problems are not exotic. They are unpatched servers, shared passwords, untested backups and an ERP where everyone can see everything — and nearly all of them are fixable in weeks, not quarters.
Backups that have never been restored
The backup job runs every night and nobody has ever opened the result. When ransomware hits, that is the moment you discover the archive is empty, corrupted, or sitting on the same server that was just encrypted. By then the question is no longer technical — it is whether the company survives the month.
How we handle itWe test-restore your backups into a scratch environment as part of every assessment, and we move at least one copy off the machine it is meant to protect.
Everyone is an administrator
Access grew with the company: the first five employees got admin rights and nobody ever took them back. Ex-staff still have working logins, and the accountant's password opens the server too.
How we handle itWe inventory every account across servers, Odoo and email, map each one to a current employee, and cut rights back to what each role actually uses.
The server nobody owns
A VPS was set up years ago by a freelancer who has moved on. It runs the website, maybe the ERP too, and it has not been patched since. Nobody knows what else is installed on it or which ports are open to the internet.
How we handle itWe audit the box read-only first, document what is actually running, then patch and close it down in a scheduled window with a rollback plan.
Phishing aimed at finance
The most expensive attacks on SMEs are not hacks, they are emails: a fake invoice with changed bank details, or a message from the 'CEO' demanding an urgent transfer. One busy afternoon is all it takes.
How we handle itWe put a second factor on email and payment-adjacent systems, and help you set a simple verification rule for bank-detail changes that survives a busy afternoon.
PDPA on paper only
You have a privacy policy because a lawyer wrote one, but nobody can say which systems hold customer data, who can export it, or how you would answer a deletion request. The policy and the reality have never met.
How we handle itWe map where personal data actually lives — ERP, email, spreadsheets, backups — and turn the obligations into concrete access and retention controls.
—— Learn from other projects
Mistakes we see, and how to avoid them.
Buying tools before fixing basics
A firewall appliance and an endpoint suite get budget approval because they are visible purchases, while backups stay untested and the server stays unpatched. Attackers do not fight the expensive product — they go around it, through the basics that are still open. We rank fixes by risk, and in most SMEs the top five items cost configuration time, not licences.
Treating the report as the result
An assessment ends with a thick PDF, everyone feels a sense of progress, and the findings age quietly in a shared drive. Six months later the risk is unchanged — it is just documented now. We keep the findings list short and ranked, and quote the fix work alongside it, so closing items is the default next step rather than a separate decision.
Securing the perimeter, ignoring the ERP
The firewall is tight, but inside Odoo every user can read every customer, every price list and every salary. Most real damage at SMEs is done with a valid login, not an exploit. We treat ERP access rights as security work, not configuration trivia, and review them with the same seriousness as open ports.
One big cleanup, then silence
Security is done as a project: one intense month, then nothing for two years while patches lapse and staff changes accumulate. The posture quietly decays back to where it started. We leave you a short recurring checklist with named owners, and offer a monthly cadence for the parts you would rather hand to us.
Password rules instead of a second factor
Forced 90-day rotation and complexity rules generate sticky notes and recycled passwords, while the one control that actually stops credential theft — a second factor — stays off because it feels inconvenient. We reverse the effort: 2FA on email, VPN and admin accounts first, then saner password rules after.
—— Ways to engage
Three ways to start with us.
Security assessment
A fixed-price review of your external surface, access control, backups and patching, delivered as a ranked findings list with effort estimates. The scope is written down before we start; there is no day-rate drift.
- Test-restore of your backups, witnessed by you
- Every account mapped to a person and a need
- Findings ranked by likelihood times impact, with fix effort noted
Hardening sprint
We implement the top-ranked fixes from an assessment — ours or another firm's — and re-test each one so closure is demonstrated, not assumed. Fixed scope per sprint, agreed in writing.
- Changes made in scheduled windows with rollback plans
- Each finding re-tested and closed with evidence
- A handover note per change, so your team can maintain it
Monitoring and patching retainer
A monthly cadence that keeps the posture from decaying: patching, log review, access recertification and a periodic restore test. The scope is fixed in writing, like everything else we do.
- Security patches applied on a schedule, not when remembered
- Quarterly test-restore with a written result
- A quarterly access review against your current staff list
Your implementation partner
A partner, not a licence reseller.
We are not chasing licence volume — we design, build and stay accountable for systems that companies run their operations on. The consultant who scopes your project stays through go-live and the support that follows, and everything we commit to is written into a fixed scope per phase.
—— What done looks like
Outcomes you can verify yourself.
A restore you have watched
Your backup has been restored into a clean environment while you watched, and the steps are written down. Ransomware readiness stops being a belief and becomes a rehearsed procedure.
Accounts that match your staff list
Every login on every system maps to a current employee with the rights their role needs. Offboarding has a checklist, so the next departure does not leave a live account behind.
Findings closed with evidence
Each item from the assessment is either closed and re-tested, or consciously accepted in writing by you. Nothing sits in an unread report; the list reaches zero or every open item has an owner.
A plan for the bad day
A one-page incident runbook exists: who isolates what, who calls whom, where the backups are and how long a restore takes. The first hour of an incident follows a page instead of panic.
—— How we work
What the engagement looks like.
Assess
External surface, access control, backups, patching and the human paths. Most breaches use the boring ones.
Prioritise
Ranked by likelihood times impact, with effort noted, so you can start on Monday rather than plan for a quarter.
Harden and verify
We implement the fixes we recommend and re-test, so closure is demonstrated rather than assumed.
—— Why us
What you get that you would not elsewhere.
Ranked, not exhaustive
You get the ten things that matter, not the four hundred a scanner found.
Backups you have restored
We test-restore, because ransomware readiness is decided by whether your backup actually works.
PDPA and GDPR aware
Thailand PDPA and EU GDPR obligations mapped to concrete technical controls.
Not sure where to start? A short call sorts it.
Talk to an Odoo specialist ➜—— Why us
What working with us is actually like.
We secure systems we also run
We host and operate Odoo and web infrastructure for clients from our Thailand, USA and India offices, so our recommendations come from running production systems, not from a checklist. When we say a control is workable day to day, it is because we live with it ourselves.
Fixed written scope, per phase
The assessment is a fixed price agreed in writing before we start, and so is each hardening sprint. Security is the type of work where day-rate engagements sprawl worst; ours cannot, by construction.
The same engineer throughout
The person who assesses your systems is the person who hardens them and re-tests them. Nothing is lost in a handover between a salesperson, an auditor and a delivery team, because there is no handover.
Thai and English, natively
Findings are explained to your Bangkok accountant in Thai and to your overseas director in English, by people who work in both. Security fails at the human layer when instructions arrive in a language people only half-read.
We know where ERP data hides
As an official Odoo Partner we know which fields, exports, portal pages and the database-manager screen expose data in a default install. Generic security firms scan the perimeter; we also read the access rules inside the system that holds your margins and payroll.
We name what we do not do
We do assessment, hardening and monitoring. We do not sell formal accredited penetration tests, and we will refer you to a specialist firm when you need one. A firm that claims to do everything is guessing at something.
No resold products, no markup
We do not mark up licences — Odoo Enterprise is billed to you by Odoo directly — and we take the same line with security tooling: when a tool is genuinely needed, you buy it direct and we configure it. Our advice has no sales quota behind it.
Ranked lists, not thick reports
Our deliverable is a short list ordered by risk and effort, because a document you act on beats a document that impresses. If a finding would not change what you do on Monday, it goes in an appendix, not the list.
—— Partner tiers, explained
What an Odoo partner tier does and does not tell you.
Odoo ranks partners by certifications held and licence volume sold. A tier signals commitment to the programme — it does not tell you who will actually staff your project. Ask that question of any partner, including us.
Learning Partner
New to the programme, building their first certified consultants and reference projects. Not a red flag — everyone starts here — but ask for hands-on proof.
Official Partner
Certified consultants and active delivery. This is where we sit, enrolled through the India programme, delivering from Thailand, the USA and India.
Silver & Gold
Higher tiers earned mainly through licence sales volume and headcount of certified staff. A strong signal of scale — not automatically of fit for your project.
—— Who this is for
Built for your size, not resized for it.
Growing companies (5–100 people)
For companies of 5–100 people, security is usually one assessment and a short sprint away from materially better. The basics are cheap — they are just undone.
- You have no IT staff, and the office manager holds the passwords.
- One server or a few cloud accounts run everything, set up by someone who has left.
- A single ransomware event or redirected invoice payment would threaten the business itself.
- You need PDPA answers that a lawyer's template has not given you.
Mid-market (100–500 people)
For companies of 100–500 people, the problem is rarely awareness — it is sprawl: more systems, more admins, more ex-employees, and controls that have not kept pace.
- You have IT staff, but security is everyone's second job and nobody's first.
- Customer and auditor questionnaires now ask for controls you cannot yet evidence.
- Access has accumulated across ERP, email and servers faster than it has been revoked.
- You need a patching and review cadence that survives staff turnover, not a heroic one-off cleanup.
—— The toolkit
What this service usually touches.
—— Related
Explore what else we do.
—— FAQ
Questions teams ask about this service.
Do you do penetration testing?
We do assessment and hardening. For formal accredited penetration testing we will refer you to a specialist firm rather than pretend otherwise.
We are small. Are we really a target?
Almost all attacks are automated and indiscriminate. Being small does not make you invisible, it usually just means less monitoring.
How long does an assessment take, and what do you need from us?
Two to three weeks for most SMEs, with the scope fixed in writing before we start. We need read-only access to your servers and Odoo, an hour with whoever manages IT today, and a current staff list to check accounts against. Your team's time cost is a few hours, not a project.
Will the work disrupt our operations?
The assessment is read-only, so no. Fixes that touch production are scheduled in agreed windows with a rollback plan, and anything risky is rehearsed on a copy first. Your team signs off on the window before we touch anything live.
Do we need to buy new security products?
Usually not. In most SME engagements the top-ranked fixes are configuration, patching and access changes on things you already own. Where a tool is genuinely needed — off-site backup storage, for example — you buy it directly and we set it up; we do not resell or mark up products.
Can you secure our Odoo system specifically?
Yes, and it is often where we start, because the ERP holds the data that matters most. We review access groups, record rules, portal exposure, the database-manager page, API keys and inactive users. Odoo's defaults favour convenience; a live company system needs deliberate tightening.
We think we have been breached. Can you help right now?
Contact us and we will tell you on the first call whether we can act immediately. Our first steps are containment — isolate the machine, revoke credentials, protect the backups — before any investigation. For formal forensics or legal evidence handling we will bring in or refer a specialist rather than improvise.
Let's find out whether Odoo actually fits your business.
A short call, an honest answer. If it isn't the right system for you, we'll say so.