Businesses deserve straight answers about technology.

Steelwise is a technology advisory practice based in Sheffield. We help businesses make smart decisions about security, infrastructure, and AI, backed by over two decades of doing the work, not just advising on it.

Come for a coffee and tell us what's going on with your tech

Services

You know what your business needs to do. You don't always know what's technically possible, which technology fits, or who's best placed to deliver and maintain it. That's what we're here for.

Security advisory

Honest assessment of where you stand, what actually matters, and what to do next. Cyber Essentials, ISO 27001, posture reviews, incident preparedness, all prioritised by real risk, not fear. We tell you what's enough, not sell you the maximum.

Web and infrastructure advisory

Architecture decisions, platform choices, hosting strategy, reliability, performance. We don't sell hosting or software. We help you choose what's right, whether you're building something new or making sense of what you've already got.

AI advisory

Practical guidance on where AI fits in your business, and where it doesn't. Readiness assessments, risk and governance, separating genuine value from hype. Not every business needs AI right now, and we'll say so.

Coordinated delivery

When you need more than advice, we coordinate delivery through a network of specialists, not tied to any vendor or product. One relationship, one person accountable, and someone joining up security, infrastructure, and AI so you don't have to manage it all yourself.

How an engagement works, and what it costs →

How we work

We don't start with a sales pitch. We start with a conversation.

1

A coffee and a conversation

Free, face to face, no strings. Tell us what's going on with your tech, what's keeping you up at night, or what you're trying to figure out. If we can help, we'll say so. If we can't, we'll point you to someone who can.

2

A first piece of work

A defined engagement: a security review, an architecture assessment, a clear deliverable. Scoped tightly to what you actually need and quoted at a fixed price, agreed in writing before anything starts. Designed to demonstrate value before asking for commitment.

3

An ongoing relationship

For most clients, the real value is having someone to call. We become your technology person, across security, infrastructure, and AI. When you need deeper specialist work, we coordinate it through our network. One relationship, no vendor lock-in, and someone who knows your business.

Recent filings

Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.

  • Two answers now fail Cyber Essentials outright · Security

    Since April 2026, missing multi-factor authentication on any cloud service, or missing the 14-day window for high-risk updates, fails the whole Cyber Essentials assessment automatically. Here is what else changed, and why a stricter certificate is good news for the business holding one.

  • Test your backups before an attacker does · Security

    Nine in 10 organisations are confident they could recover from an attack. Fewer than one in three ransomware victims actually got all their data back. The difference is testing, and a restore test costs an afternoon.

  • Nobody knew whose job the patching was · Security Commentary

    Ask your IT provider who watches for security updates on your website, then ask yourself the same question. If the two answers do not match, you have the gap that the ICO has just reprimanded a national police unit for. Its website ran the same unpatched version for three and a half years because each side thought the other was looking.

  • The people attackers pick are not the ones you protect · Security Commentary

    Security spending goes on the accounts with technical power: administrators, IT, the server logins. New research into who actually gets compromised at the start of a ransomware attack found three quarters of victims worked in finance, sales, operations, HR, or marketing. What made them worth picking was signing authority, not system access.

  • The plugin that changed without changing · Security Infrastructure

    Seven WordPress plugins were used to create hidden administrator accounts on live sites without a single plugin file being altered. Every update check passed, every version number was correct, and the sites were still compromised. Here is why checking for updates was never going to catch it.

All filings →

Research: original analysis of public records →

About

Steelwise exists because most businesses can't get a straight answer about technology. The security industry defaults to jargon and fear. MSPs want to sell you a contract. Consultancies send juniors. What's missing is a practice that's experienced, broad, honest, and genuinely interested in your specific problem.

We're built on a partnership model: a small, trusted team backed by a network of specialists. You always get senior people who've actually done the work. No juniors, no handoffs, no learning on your time.


Carl Heaton, founder of Steelwise

Our founder, Carl, has spent over 22 years working across security, web infrastructure, data, and AI. He's served as CTO, CISO, and DPO for a web hosting company in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.

That breadth is unusual. Most advisors specialise in one lane. We deal with all of it, because that's what running a real technology business actually requires.

We're not tied to any product or vendor. We don't take commissions, and everything we deliver is yours. If you need a second opinion on what your IT provider is telling you, that's exactly the kind of conversation we're here for.

More about how we work, or read about Carl Heaton, who founded the practice.