But Can You Prove You're Secure?
Most businesses rely on IT support that fixes problems after they happen. Root.12 is different. It’s a managed security framework that maps your technology estate across 12 defined areas – so when your insurer, your biggest client, or your board asks if you’re secure, you have the answer ready. With evidence to back it up.
Root.12 Does.
Growing businesses and security-conscious organisations face the same problem. At some point – a cyber incident, an insurance renewal, a client due diligence questionnaire, a board risk review – someone asks whether your IT is properly managed and your security controls are in place.
Most IT support was never built to answer that. No security framework. No formal risk assessment. No documented security posture. Just a helpdesk and a hope.
What are your biggest security risks? Are your controls actually working? Could you demonstrate best practices to an underwriter?
Root.12 gives your organisation a proper cybersecurity framework – one that assesses, scores, and evidences your position across all 12 areas. A living framework that improves over time and eliminates blind spots before they become incidents.
Most IT support is reactive. An engineer fixes what breaks. A ticket gets closed. But nothing changes about the underlying risk.
We built Root.12 because our clients kept asking the same question: “Are we actually secure?” And the honest answer, under a traditional model, was: “We do not really know.”
Root.12 exists to change that. It gives businesses a structured way to understand their technology posture – not at a point in time, but continuously. Across 12 defined areas. With evidence you can show to your board, your insurer, and your clients.
That is what we built. And it is what every Root.12 engagement delivers.
Your team, access controls, security awareness, and human risk
Your infrastructure, endpoints, cloud, backup, and recovery
Your policies, compliance posture, audit readiness, and strategic alignment
Zero blind spots.
Root.12 is a managed IT security framework that maps your technology estate across 12 assessment areas – four pillars, three domains. Every area is assessed, scored, and documented on a rolling basis.
Think of it as a continuous risk assessment for your entire IT environment. Security controls, infrastructure resilience, compliance posture, data management, and strategic alignment – all measured, all evidenced, all improving over time.
Imagine your next board meeting. The risk committee asks about your cybersecurity framework. Your insurers ask for evidence of security controls. A new client asks about your security posture. You answer all three from one document – because Root.12 has been building that evidence since day one.
That is proactive IT support – designed around risk management, not just keeping the lights on.
Root.12, IT Security Audit for Regulated London Firms
4 Pillars. One Complete Picture.
| Security | Operations | Assurance | Growth | |
|---|---|---|---|---|
| People | 01Human RiskAwareness & training | 02User ExperienceProductivity & friction | 03Policy & AwarenessWritten rules | 04Automation & EfficiencyTime savings |
| Systems | 05Threat ProtectionFirewall, AV, patching | 06Infrastructure ReliabilityResilience & failover | 07Data & ComplianceLocation, access, GDPR | 08Scalable TechnologyGrowth-ready infra |
| Governance | 09Security PostureScored & documented | 10Service AccountabilityReporting & SLAs | 11Proof of ControlEvidence & records | 12Strategic AlignmentRoadmap & goals |
Launch. Foundations. Certified. Governed. Each level applies the same Root.12 framework – the difference is depth of assurance, evidence, and governance.
| Standard IT support | Root.12 security framework |
|---|---|
| No formal security framework | 12-area cybersecurity framework from day one |
| No risk assessment process | Continuous risk management across all 12 areas |
| Security controls undocumented | Evidence library maintained continuously |
| Reactive - fixes downtime after the fact | Proactive monitoring - prevents issues before they occur |
| No security posture visibility | Scored security posture, updated quarterly |
| Doesn't scale with your business | Scalable service aligned to your growth |
Everything you need to know before booking your discovery call.
It reveals where security controls are effective, where weaknesses exist and which gaps create the greatest operational, security or external assurance risk. Root.12 reviews the organisation across 12 defined areas covering people, systems and governance, then produces a scored view of the current position. Leadership teams can use the findings to prioritise remediation, guide technology investment and provide clearer evidence to insurers, clients, auditors and other stakeholders.
A standard IT health check typically focuses on system performance, configuration and immediate technical issues. Root.12 goes further by assessing control effectiveness, governance, risk and the evidence available to prove how technology is managed. The result is a structured view of security posture, documented gaps and prioritised improvements that can support audits, cyber insurance reviews, client due diligence and long-term technology planning.
An assessment is particularly valuable before a cyber insurance renewal, major client due diligence exercise, Cyber Essentials or Cyber Essentials Plus assessment, significant technology change or board-level risk review. It is also useful when leadership cannot clearly demonstrate which controls are working. Root.12 establishes a documented baseline early, giving the organisation time to address weaknesses and strengthen evidence before external scrutiny creates pressure.
It gives leadership a measurable view of the organisation’s current security position instead of relying on assumptions that controls are in place. Root.12 links each assessed area to documented findings and supporting evidence across identity, endpoints, Microsoft 365, recovery and governance. This helps decision-makers explain where controls are effective, where improvement is required and what evidence can be presented when insurers, clients, boards or auditors request assurance.
It identifies missing evidence, unclear ownership and control weaknesses before a formal review begins. Root.12 examines whether records exist for areas such as access management, endpoint security, backup testing, recovery, policies and governance, then highlights what needs attention. This allows firms to maintain evidence as part of normal technology management instead of assembling screenshots, reports and documents under deadline pressure immediately before an audit.
At Support Tree, we’re proud to deliver secure, dependable, and proactive IT services to London’s leading businesses.
These verified Google Reviews reflect the trust our clients place in us to keep their systems running smoothly, their data protected, and their teams productive.
Root.12 is not meant to be for everybody. That is deliberate. If any of the following sounds like you, we are probably not the right fit - and we would rather be honest about that now.
Compare the four Root.12 package levels and see exactly what each one delivers – from certification through to full governance.
IT Security Assessment for UK Firms That Need Evidence, Not Guesswork
When a regulator, insurer, investor or enterprise buyer asks whether your IT is properly controlled, a vague answer is not enough. You need a clear view of your technology estate, where the risks sit, which controls are already in place, and what evidence exists to prove they are working. Root.12 is built for firms that cannot rely on assumptions when security, continuity and client trust are being examined. Instead of treating IT as a helpdesk function, it turns your environment into a measured, scored and documented security position that can be explained to boards, insurers, auditors and commercial stakeholders.
Support Tree uses Root.12 to assess your IT across 12 defined areas covering people, systems and governance. The outcome is not just a technical checklist or a one-off review. It is a structured framework that identifies gaps, records evidence, prioritises remediation and gives your leadership team a practical roadmap for improvement. For regulated and audit-driven UK firms, this means your security position becomes visible, defensible and commercially useful before someone important asks difficult questions.
Security Posture Assessments for London Firms That Need Board-Level Proof
A strong security position is not only about having tools in place. It is about knowing whether those tools are configured correctly, whether responsibilities are clear, whether policies are followed, and whether the organisation can prove its controls are working. Many firms only discover the weakness of their current setup during a cyber insurance renewal, due diligence request, client security questionnaire or board risk review. Root.12 helps you move from “we think we are secure” to a documented position that shows what is working, what needs attention and what should happen next.
The assessment gives decision-makers practical visibility across the areas that matter most:
- user access, permissions and identity controls
- endpoint protection, patching and device management
- Microsoft 365 security configuration and secure score improvement
- backup, recovery and business continuity resilience
- policies, responsibilities and security awareness
- evidence records for insurers, auditors and client questionnaires
- priority gaps that should be addressed first
- longer-term improvements for security maturity and growth
This gives leadership teams a clearer way to talk about risk. Instead of reviewing isolated tickets or technical issues, they can see patterns, priorities and accountability. That makes the conversation more useful for commercial decisions, budget planning, audit preparation and ongoing governance.
Audit Readiness Assessment for UK Firms Facing Scrutiny
Audit pressure usually arrives before a business feels ready. A client may request proof of security controls before signing a contract. An insurer may ask how cyber threats, downtime and data protection are managed. A regulator may expect evidence that operational resilience is more than a written policy. Root.12 is designed for those moments. It helps firms organise the evidence, identify the gaps and build a more defensible IT position before the deadline becomes urgent.
Every engagement is designed to create outputs that can be used beyond the technical team:
- a scored view of your current IT and security position
- a plain-English gap report for senior stakeholders
- evidence records that support Cyber Essentials, CE+ and insurance discussions
- control visibility across infrastructure, access, resilience and governance
- a prioritised remediation plan based on risk, not guesswork
- a forward-looking roadmap aligned with business growth
- clearer accountability for recurring reviews and reporting
The value is not only in finding problems. The value is in making your position explainable. When a board, insurer, auditor or buyer asks for proof, you have structured answers instead of scattered screenshots, old policies and last-minute evidence gathering.
ISO 27001 Technical Controls for London Firms Building a Defensible Security Position
ISO 27001 readiness is not achieved by writing policies alone. The technical controls behind those policies need to be understood, maintained and evidenced over time. Root.12 helps bridge the gap between everyday IT operations and the level of control visibility expected by organisations preparing for stronger governance. It gives structure to areas such as access management, asset visibility, endpoint protection, backup resilience, supplier risk, data handling, reporting and security improvement. For firms considering ISO 27001, cyber insurance renewal or enterprise client due diligence, this makes the technical side of assurance easier to organise and explain.
The framework also helps avoid the common problem of treating compliance as a separate project. Security maturity should not sit in a folder that only gets opened during an audit. It should be built into how IT is managed, reviewed and improved. Root.12 creates that operating rhythm by turning controls into a living framework: assessed, scored, documented and reviewed over time. This gives regulated and audit-driven firms a more reliable path from today’s risk position to a stronger, evidence-backed security model.
Book your Root.12 audit to understand where your security position stands today, what gaps need attention, and what evidence your firm should build next. It is the first step towards a clearer, stronger and more audit-ready IT environment.