You Have IT Support
But Can You Prove You're Secure?
Most businesses rely on IT support that fixes problems after they happen. Root.12 is different. It’s a managed security framework that maps your technology estate across 12 defined areas – so when your insurer, your biggest client, or your board asks if you’re secure, you have the answer ready. With evidence to back it up.
Most IT Support Has No Security Framework. Root.12 Does.
Growing businesses and security-conscious organisations face the same problem. At some point – a cyber incident, an insurance renewal, a client due diligence questionnaire, a board risk review – someone asks whether your IT is properly managed and your security controls are in place.
Most IT support was never built to answer that. No security framework. No formal risk assessment. No documented security posture. Just a helpdesk and a hope.
What are your biggest security risks? Are your controls actually working? Could you demonstrate best practices to an underwriter?
Root.12 gives your organisation a proper cybersecurity framework – one that assesses, scores, and evidences your position across all 12 areas. A living framework that improves over time and eliminates blind spots before they become incidents.
Why We Built Root.12
Most IT support is reactive. An engineer fixes what breaks. A ticket gets closed. But nothing changes about the underlying risk.
We built Root.12 because our clients kept asking the same question: “Are we actually secure?” And the honest answer, under a traditional model, was: “We do not really know.”
Root.12 exists to change that. It gives businesses a structured way to understand their technology posture – not at a point in time, but continuously. Across 12 defined areas. With evidence you can show to your board, your insurer, and your clients.
That is what we built. And it is what every Root.12 engagement delivers.
People
Your team, access controls, security awareness, and human risk
Systems
Your infrastructure, endpoints, cloud, backup, and recovery
Governance
Your policies, compliance posture, audit readiness, and strategic alignment
12 areas. One security framework.
Zero blind spots.
Root.12 is a managed IT security framework that maps your technology estate across 12 assessment areas – four pillars, three domains. Every area is assessed, scored, and documented on a rolling basis.
Think of it as a continuous risk assessment for your entire IT environment. Security controls, infrastructure resilience, compliance posture, data management, and strategic alignment – all measured, all evidenced, all improving over time.
Imagine your next board meeting. The risk committee asks about your cybersecurity framework. Your insurers ask for evidence of security controls. A new client asks about your security posture. You answer all three from one document – because Root.12 has been building that evidence since day one.
That is proactive IT support – designed around risk management, not just keeping the lights on.
A Framework Across 12 Areas.
4 Pillars. One Complete Picture.
| Security | Operations | Assurance | Growth | |
|---|---|---|---|---|
| People | 01Human RiskAwareness & training | 02User ExperienceProductivity & friction | 03Policy & AwarenessWritten rules | 04Automation & EfficiencyTime savings |
| Systems | 05Threat ProtectionFirewall, AV, patching | 06Infrastructure ReliabilityResilience & failover | 07Data & ComplianceLocation, access, GDPR | 08Scalable TechnologyGrowth-ready infra |
| Governance | 09Security PostureScored & documented | 10Service AccountabilityReporting & SLAs | 11Proof of ControlEvidence & records | 12Strategic AlignmentRoadmap & goals |
Root.12 is delivered through four package levels.
Launch. Foundations. Certified. Governed. Each level applies the same Root.12 framework – the difference is depth of assurance, evidence, and governance.
What You Get With Every Root.12 Engagement
How Root.12 Is Different From Standard IT Support
| Standard IT support | Root.12 security framework |
|---|---|
| No formal security framework | 12-area cybersecurity framework from day one |
| No risk assessment process | Continuous risk management across all 12 areas |
| Security controls undocumented | Evidence library maintained continuously |
| Reactive - fixes downtime after the fact | Proactive monitoring - prevents issues before they occur |
| No security posture visibility | Scored security posture, updated quarterly |
| Doesn't scale with your business | Scalable service aligned to your growth |
Everything you need to know before booking your discovery call.
An IT security framework is a structured set of policies, controls, and processes that map how a business manages its technology risks. Unlike reactive IT support - which fixes problems after they happen - a security framework gives you ongoing visibility of your controls and evidence that they are working. Root.12 is an IT security framework built specifically for UK SMBs. It covers 12 defined areas across People, Systems, and Governance, assessed and maintained on a rolling basis.
Root.12 is Support Tree's managed IT security framework. It covers 12 areas across security, operations, assurance, and growth - giving you a scored baseline, a continuously maintained evidence library, and Cyber Essentials or CE+ certification guaranteed. It is comparable to frameworks like NIST CSF and CIS Controls, but built for UK businesses with 10 to 200 users rather than enterprise organisations.
For most UK SMBs, the choice comes down to compliance requirements and business goals. NIST and ISO 27001 are comprehensive but complex - designed for large organisations with dedicated security teams. Cyber Essentials is the UK government baseline but covers only five controls. Root.12 sits between the two: a 12-area framework that covers your full security posture, delivers CE or CE+ certification, and produces evidence you can share with insurers, clients, and regulators - without the overhead of ISO 27001.
Growing businesses and security-conscious organisations that need more than a helpdesk. Typically 10 to 200 users in compliance-sensitive sectors - financial services, legal, accountancy, and professional services. If you cannot confidently evidence your security controls to a client, an insurer, or a board - Root.12 is built for you.
We assess your business across all 12 areas over 2 to 3 days, review your security controls, and document findings. You receive a plain-English report with a score per area, a risk assessment, gap analysis, and a package recommendation.
Yes. Root.12 is a fully managed service. We manage your devices, security stack, Microsoft 365 environment, and compliance documentation. We handle the transition from your existing provider with minimal disruption to your business.
You have a scored baseline and initial risk assessment within 10 working days. Most clients see material improvements in their security posture within 90 days. Your evidence library starts building from day one - ready for your next insurance renewal or client due diligence questionnaire.
You receive a scored report across all 12 Root.12 areas, a clear explanation of your current risks, prioritised remediation actions, and a recommendation on the right ongoing package. In plain English, you leave knowing where you stand and what to do next.
At Support Tree, we’re proud to deliver secure, dependable, and proactive IT services to London’s leading businesses.
These verified Google Reviews reflect the trust our clients place in us to keep their systems running smoothly, their data protected, and their teams productive.
Who Root.12 is not for
Root.12 is not meant to be for everybody. That is deliberate. If any of the following sounds like you, we are probably not the right fit - and we would rather be honest about that now.
Ready to See Which Root.12 Package Fits Your Business?
Compare the four Root.12 package levels and see exactly what each one delivers – from certification through to full governance.
IT Security Assessment for UK Firms That Need Evidence, Not Guesswork
When a regulator, insurer, investor or enterprise buyer asks whether your IT is properly controlled, a vague answer is not enough. You need a clear view of your technology estate, where the risks sit, which controls are already in place, and what evidence exists to prove they are working. Root.12 is built for firms that cannot rely on assumptions when security, continuity and client trust are being examined. Instead of treating IT as a helpdesk function, it turns your environment into a measured, scored and documented security position that can be explained to boards, insurers, auditors and commercial stakeholders.
Support Tree uses Root.12 to assess your IT across 12 defined areas covering people, systems and governance. The outcome is not just a technical checklist or a one-off review. It is a structured framework that identifies gaps, records evidence, prioritises remediation and gives your leadership team a practical roadmap for improvement. For regulated and audit-driven UK firms, this means your security position becomes visible, defensible and commercially useful before someone important asks difficult questions.
Security Posture Assessments for London Firms That Need Board-Level Proof
A strong security position is not only about having tools in place. It is about knowing whether those tools are configured correctly, whether responsibilities are clear, whether policies are followed, and whether the organisation can prove its controls are working. Many firms only discover the weakness of their current setup during a cyber insurance renewal, due diligence request, client security questionnaire or board risk review. Root.12 helps you move from “we think we are secure” to a documented position that shows what is working, what needs attention and what should happen next.
The assessment gives decision-makers practical visibility across the areas that matter most:
- user access, permissions and identity controls
- endpoint protection, patching and device management
- Microsoft 365 security configuration and secure score improvement
- backup, recovery and business continuity resilience
- policies, responsibilities and security awareness
- evidence records for insurers, auditors and client questionnaires
- priority gaps that should be addressed first
- longer-term improvements for security maturity and growth
This gives leadership teams a clearer way to talk about risk. Instead of reviewing isolated tickets or technical issues, they can see patterns, priorities and accountability. That makes the conversation more useful for commercial decisions, budget planning, audit preparation and ongoing governance.
Audit Readiness Assessment for UK Firms Facing Scrutiny
Audit pressure usually arrives before a business feels ready. A client may request proof of security controls before signing a contract. An insurer may ask how cyber threats, downtime and data protection are managed. A regulator may expect evidence that operational resilience is more than a written policy. Root.12 is designed for those moments. It helps firms organise the evidence, identify the gaps and build a more defensible IT position before the deadline becomes urgent.
Every engagement is designed to create outputs that can be used beyond the technical team:
- a scored view of your current IT and security position
- a plain-English gap report for senior stakeholders
- evidence records that support Cyber Essentials, CE+ and insurance discussions
- control visibility across infrastructure, access, resilience and governance
- a prioritised remediation plan based on risk, not guesswork
- a forward-looking roadmap aligned with business growth
- clearer accountability for recurring reviews and reporting
The value is not only in finding problems. The value is in making your position explainable. When a board, insurer, auditor or buyer asks for proof, you have structured answers instead of scattered screenshots, old policies and last-minute evidence gathering.
ISO 27001 Technical Controls for London Firms Building a Defensible Security Position
ISO 27001 readiness is not achieved by writing policies alone. The technical controls behind those policies need to be understood, maintained and evidenced over time. Root.12 helps bridge the gap between everyday IT operations and the level of control visibility expected by organisations preparing for stronger governance. It gives structure to areas such as access management, asset visibility, endpoint protection, backup resilience, supplier risk, data handling, reporting and security improvement. For firms considering ISO 27001, cyber insurance renewal or enterprise client due diligence, this makes the technical side of assurance easier to organise and explain.
The framework also helps avoid the common problem of treating compliance as a separate project. Security maturity should not sit in a folder that only gets opened during an audit. It should be built into how IT is managed, reviewed and improved. Root.12 creates that operating rhythm by turning controls into a living framework: assessed, scored, documented and reviewed over time. This gives regulated and audit-driven firms a more reliable path from today’s risk position to a stronger, evidence-backed security model.
Book your Root.12 audit to understand where your security position stands today, what gaps need attention, and what evidence your firm should build next. It is the first step towards a clearer, stronger and more audit-ready IT environment.