Cybersecurity
Security your board will sign off on, with the evidence to prove it.
We monitor and respond around the clock, using AI to filter the noise so that our analysts see what matters, faster. We test your backups by restoring them, and we keep the verified evidence ready for the day your board or your insurer asks for it.
The questionnaire usually arrives before the incident.
A client sends a security questionnaire, or your insurer changes the renewal terms. Either way, someone has to account for controls that were never written down.
We see the same gap in almost every review. The controls are mostly in place, but the evidence is not. Auditors and insurers no longer take your word for it, and a policy you cannot prove counts for little at renewal. We help you close that gap with real-world, verified evidence, and the transparency to show it.
Systems are watched through the night.
Our analysts and our agents monitor around the clock, so an alert at night is acted on immediately rather than read in the morning.
Request a security auditServices
Four services that keep your board reassured and your auditors satisfied.
Managed security (SOC)
Detection and response, 24 hours a day, across every endpoint, mailbox and identity.
Agents correlate signals across tools before an analyst reviews them.
Backup & recovery
Servers, workstations and Microsoft 365, on the 3-2-1-0 rule: three copies, two types of backup, one held remotely, and zero errors on restore. Verification is the step most providers omit.
Automated restore testing and anomaly detection on backup jobs.
Audits & compliance
Security and compliance reviews prepared to the standard the requesting party expects.
Evidence packs and gap reports assembled automatically.
Incident response
We contain, remediate and investigate, then harden your systems so that the same route cannot be used again.
Log analysis and forensics proceed considerably faster with agents completing the first pass.
Healthcare
For practices holding patient data, the IT provider is a business associate.
That is a legal fact rather than a sales point. Once a provider can reach systems holding protected health information, the legal duties extend to that provider, and the practice remains responsible for choosing well.
We support medical practices in ophthalmology, obstetrics and gynaecology, and behavioural health, predominantly smaller practices where compliance sits with an office manager alongside a full role.
What we provide
- The same 24/7 monitoring provided to every client, applied to systems holding patient data
- Our compliance audit: user analysis, Active Directory and password policies, and user behaviour tracking
- Backups on the 3-2-1-0 rule, with restores that have been tested
- Access controls and audit logs, evidencing who accessed which record and when
- Incident response in the event of a breach
There is no such thing as a HIPAA-certified vendor, and any provider claiming otherwise deserves close examination.
A composite case
An incident closed without an explanation is an incident waiting to happen again.
A European fashion house operates its North American business from a single city: a hundred and twenty people, a flagship store, and an online business that now outsells it.
A phishing message came close to compromising the finance mailbox. The incumbent provider remediated it and closed the ticket. Nobody explained why it had succeeded, so nothing changed and the same route remained open.
We assumed responsibility for IT and security within six weeks, keeping the same laptops and the same people, with a different standard underneath. We then completed the audit head office had been requesting for a year, and passed it.
A composite case. The details are drawn from real Lenet engagements; the company and the people are invented.
Credentials
We do not publish client logos, so these are the partners who vouch for us.

The recommended starting point is an audit.
You receive a written, verified assessment of where you stand, including where you are already in good shape.