The IT Security Framework Built for Growing Businesses

You Have IT Support
But Can You Prove You're Secure?

Most businesses rely on IT support that fixes problems after they happen. Root.12 is different. It’s a managed security framework that maps your technology estate across 12 defined areas – so when your insurer, your biggest client, or your board asks if you’re secure, you have the answer ready. With evidence to back it up.

Most IT Support Has No Security Framework. Root.12 Does.

Growing businesses and security-conscious organisations face the same problem. At some point – a cyber incident, an insurance renewal, a client due diligence questionnaire, a board risk review – someone asks whether your IT is properly managed and your security controls are in place.

Most IT support was never built to answer that. No security framework. No formal risk assessment. No documented security posture. Just a helpdesk and a hope.

What are your biggest security risks? Are your controls actually working? Could you demonstrate best practices to an underwriter?

Root.12 gives your organisation a proper cybersecurity framework – one that assesses, scores, and evidences your position across all 12 areas. A living framework that improves over time and eliminates blind spots before they become incidents.

Why We Built Root.12

Most IT support is reactive. An engineer fixes what breaks. A ticket gets closed. But nothing changes about the underlying risk.

We built Root.12 because our clients kept asking the same question: “Are we actually secure?” And the honest answer, under a traditional model, was: “We do not really know.”

Root.12 exists to change that. It gives businesses a structured way to understand their technology posture – not at a point in time, but continuously. Across 12 defined areas. With evidence you can show to your board, your insurer, and your clients.

That is what we built. And it is what every Root.12 engagement delivers.

People

Your team, access controls, security awareness, and human risk

Systems

Your infrastructure, endpoints, cloud, backup, and recovery

Governance

Your policies, compliance posture, audit readiness, and strategic alignment

12 areas. One security framework.
Zero blind spots.

Root.12 is a managed IT security framework that maps your technology estate across 12 assessment areas – four pillars, three domains. Every area is assessed, scored, and documented on a rolling basis.

Think of it as a continuous risk assessment for your entire IT environment. Security controls, infrastructure resilience, compliance posture, data management, and strategic alignment – all measured, all evidenced, all improving over time.

Imagine your next board meeting. The risk committee asks about your cybersecurity framework. Your insurers ask for evidence of security controls. A new client asks about your security posture. You answer all three from one document – because Root.12 has been building that evidence since day one.

That is proactive IT support – designed around risk management, not just keeping the lights on.

A Framework Across 12 Areas.
4 Pillars. One Complete Picture.

Security Operations Assurance Growth
People 01Human RiskAwareness & training 02User ExperienceProductivity & friction 03Policy & AwarenessWritten rules 04Automation & EfficiencyTime savings
Systems 05Threat ProtectionFirewall, AV, patching 06Infrastructure ReliabilityResilience & failover 07Data & ComplianceLocation, access, GDPR 08Scalable TechnologyGrowth-ready infra
Governance 09Security PostureScored & documented 10Service AccountabilityReporting & SLAs 11Proof of ControlEvidence & records 12Strategic AlignmentRoadmap & goals
01
PeopleSecurity
Human Risk
Awareness & training
02
PeopleOperations
User Experience
Productivity & friction
03
PeopleAssurance
Policy & Awareness
Written rules
04
PeopleGrowth
Automation & Efficiency
Time savings
05
SystemsSecurity
Threat Protection
Firewall, AV, patching
06
SystemsOperations
Infrastructure Reliability
Resilience & failover
07
SystemsAssurance
Data & Compliance
Location, access, GDPR
08
SystemsGrowth
Scalable Technology
Growth-ready infra
09
GovernanceSecurity
Security Posture
Scored & documented
10
GovernanceOperations
Service Accountability
Reporting & SLAs
11
GovernanceAssurance
Proof of Control
Evidence & records
12
GovernanceGrowth
Strategic Alignment
Roadmap & goals

Root.12 is delivered through four package levels.

Launch. Foundations. Certified. Governed. Each level applies the same Root.12 framework – the difference is depth of assurance, evidence, and governance.

What You Get With Every Root.12 Engagement

Root.12 Security Framework Assessment
A scored view of your security controls, risk posture, and infrastructure across all 12 areas. Day one visibility.
Plain-English Report
No jargon. A document you can share with your board, your insurer, or your compliance team.
M365 Secure Score Management
Included in every package. We actively improve and maintain your Microsoft security configuration.
Quarterly Security Framework Reviews
Your security posture is reviewed quarterly. Every change to your risk profile is documented, evidenced, and reported.
Evidence Library
Certificates, test results, policy sign-offs, audit logs - stored and maintained continuously, not scrambled together after an incident.
Dedicated Account Manager
One point of contact who understands your framework position and your business goals - not a rotating helpdesk queue.
Technology Roadmap
A 12-month forward plan tied to your Root.12 gaps and your business priorities. IT spend that makes sense.
Risk Reversal
Cyber Essentials and CE+ first time, or we fix it free. The only CE/CE+ guarantee in London.

How Root.12 Is Different From Standard IT Support

Standard IT supportRoot.12 security framework
No formal security framework12-area cybersecurity framework from day one
No risk assessment processContinuous risk management across all 12 areas
Security controls undocumentedEvidence library maintained continuously
Reactive - fixes downtime after the factProactive monitoring - prevents issues before they occur
No security posture visibilityScored security posture, updated quarterly
Doesn't scale with your businessScalable service aligned to your growth
Frequently Asked Questions About Root.12

Everything you need to know before booking your discovery call.

An IT security framework is a structured set of policies, controls, and processes that map how a business manages its technology risks. Unlike reactive IT support - which fixes problems after they happen - a security framework gives you ongoing visibility of your controls and evidence that they are working. Root.12 is an IT security framework built specifically for UK SMBs. It covers 12 defined areas across People, Systems, and Governance, assessed and maintained on a rolling basis.

Root.12 is Support Tree's managed IT security framework. It covers 12 areas across security, operations, assurance, and growth - giving you a scored baseline, a continuously maintained evidence library, and Cyber Essentials or CE+ certification guaranteed. It is comparable to frameworks like NIST CSF and CIS Controls, but built for UK businesses with 10 to 200 users rather than enterprise organisations.

For most UK SMBs, the choice comes down to compliance requirements and business goals. NIST and ISO 27001 are comprehensive but complex - designed for large organisations with dedicated security teams. Cyber Essentials is the UK government baseline but covers only five controls. Root.12 sits between the two: a 12-area framework that covers your full security posture, delivers CE or CE+ certification, and produces evidence you can share with insurers, clients, and regulators - without the overhead of ISO 27001.

Growing businesses and security-conscious organisations that need more than a helpdesk. Typically 10 to 200 users in compliance-sensitive sectors - financial services, legal, accountancy, and professional services. If you cannot confidently evidence your security controls to a client, an insurer, or a board - Root.12 is built for you.

We assess your business across all 12 areas over 2 to 3 days, review your security controls, and document findings. You receive a plain-English report with a score per area, a risk assessment, gap analysis, and a package recommendation.

Yes. Root.12 is a fully managed service. We manage your devices, security stack, Microsoft 365 environment, and compliance documentation. We handle the transition from your existing provider with minimal disruption to your business.

You have a scored baseline and initial risk assessment within 10 working days. Most clients see material improvements in their security posture within 90 days. Your evidence library starts building from day one - ready for your next insurance renewal or client due diligence questionnaire.

You receive a scored report across all 12 Root.12 areas, a clear explanation of your current risks, prioritised remediation actions, and a recommendation on the right ongoing package. In plain English, you leave knowing where you stand and what to do next.

stock-photo-beautiful-sunrise-at-victoria-embankment-street-in-london-uk
Trusted by London Businesses to Stay Secure and Supported

At Support Tree, we’re proud to deliver secure, dependable, and proactive IT services to London’s leading businesses.
These verified Google Reviews reflect the trust our clients place in us to keep their systems running smoothly, their data protected, and their teams productive.

Who Root.12 is not for

Root.12 is not meant to be for everybody. That is deliberate. If any of the following sounds like you, we are probably not the right fit - and we would rather be honest about that now.

You just want the cheapest IT support
Root.12 is a framework-led managed service. If price is the only factor, there are cheaper options. They will not give you this level of visibility, control, or evidence.
Your leadership team does not care about IT risk
Root.12 only works when someone at the top takes technology seriously. If the board sees IT as something to spend as little as possible on, the framework will not get the traction it needs.
You want to keep your current provider and bolt this on
Root.12 is our managed service. It is not a consultancy layer you add to somebody else's support contract. We own the framework and the delivery.
Your IT spend can't reach £750/month
Root.12 starts at £750/month from Foundations upward. Funded startups can join via Launch. If your budget can't reach the floor yet, come back when it can. We'd rather be honest now than waste your time.
You need everything fixed tomorrow
Root.12 builds a position over time. If you are already in a crisis, we can help - but the framework itself is a 12-month journey, not an emergency response.
You want a vendor relationship, not a partner
Root.12 requires a working relationship - regular reviews, honest conversations, and a shared commitment to improving your position. If you want someone to just take calls and close tickets, we are not the right fit.

Ready to See Which Root.12 Package Fits Your Business?

Compare the four Root.12 package levels and see exactly what each one delivers – from certification through to full governance.

IT Security Assessment for UK Firms That Need Evidence, Not Guesswork

When a regulator, insurer, investor or enterprise buyer asks whether your IT is properly controlled, a vague answer is not enough. You need a clear view of your technology estate, where the risks sit, which controls are already in place, and what evidence exists to prove they are working. Root.12 is built for firms that cannot rely on assumptions when security, continuity and client trust are being examined. Instead of treating IT as a helpdesk function, it turns your environment into a measured, scored and documented security position that can be explained to boards, insurers, auditors and commercial stakeholders.

Support Tree uses Root.12 to assess your IT across 12 defined areas covering people, systems and governance. The outcome is not just a technical checklist or a one-off review. It is a structured framework that identifies gaps, records evidence, prioritises remediation and gives your leadership team a practical roadmap for improvement. For regulated and audit-driven UK firms, this means your security position becomes visible, defensible and commercially useful before someone important asks difficult questions.

Security Posture Assessments for London Firms That Need Board-Level Proof

A strong security position is not only about having tools in place. It is about knowing whether those tools are configured correctly, whether responsibilities are clear, whether policies are followed, and whether the organisation can prove its controls are working. Many firms only discover the weakness of their current setup during a cyber insurance renewal, due diligence request, client security questionnaire or board risk review. Root.12 helps you move from “we think we are secure” to a documented position that shows what is working, what needs attention and what should happen next.

The assessment gives decision-makers practical visibility across the areas that matter most:

  • user access, permissions and identity controls
  • endpoint protection, patching and device management
  • Microsoft 365 security configuration and secure score improvement
  • backup, recovery and business continuity resilience
  • policies, responsibilities and security awareness
  • evidence records for insurers, auditors and client questionnaires
  • priority gaps that should be addressed first
  • longer-term improvements for security maturity and growth

This gives leadership teams a clearer way to talk about risk. Instead of reviewing isolated tickets or technical issues, they can see patterns, priorities and accountability. That makes the conversation more useful for commercial decisions, budget planning, audit preparation and ongoing governance.

Audit Readiness Assessment for UK Firms Facing Scrutiny

Audit pressure usually arrives before a business feels ready. A client may request proof of security controls before signing a contract. An insurer may ask how cyber threats, downtime and data protection are managed. A regulator may expect evidence that operational resilience is more than a written policy. Root.12 is designed for those moments. It helps firms organise the evidence, identify the gaps and build a more defensible IT position before the deadline becomes urgent.

Every engagement is designed to create outputs that can be used beyond the technical team:

  • a scored view of your current IT and security position
  • a plain-English gap report for senior stakeholders
  • evidence records that support Cyber Essentials, CE+ and insurance discussions
  • control visibility across infrastructure, access, resilience and governance
  • a prioritised remediation plan based on risk, not guesswork
  • a forward-looking roadmap aligned with business growth
  • clearer accountability for recurring reviews and reporting

 
The value is not only in finding problems. The value is in making your position explainable. When a board, insurer, auditor or buyer asks for proof, you have structured answers instead of scattered screenshots, old policies and last-minute evidence gathering.

ISO 27001 Technical Controls for London Firms Building a Defensible Security Position

ISO 27001 readiness is not achieved by writing policies alone. The technical controls behind those policies need to be understood, maintained and evidenced over time. Root.12 helps bridge the gap between everyday IT operations and the level of control visibility expected by organisations preparing for stronger governance. It gives structure to areas such as access management, asset visibility, endpoint protection, backup resilience, supplier risk, data handling, reporting and security improvement. For firms considering ISO 27001, cyber insurance renewal or enterprise client due diligence, this makes the technical side of assurance easier to organise and explain.

The framework also helps avoid the common problem of treating compliance as a separate project. Security maturity should not sit in a folder that only gets opened during an audit. It should be built into how IT is managed, reviewed and improved. Root.12 creates that operating rhythm by turning controls into a living framework: assessed, scored, documented and reviewed over time. This gives regulated and audit-driven firms a more reliable path from today’s risk position to a stronger, evidence-backed security model.

Book your Root.12 audit to understand where your security position stands today, what gaps need attention, and what evidence your firm should build next. It is the first step towards a clearer, stronger and more audit-ready IT environment.