IT Equipment Supply

Hardware specified against the work, delivered secure by default, and recorded in an asset register that will survive an audit.

Read this first

We do not sell equipment to organisations we audit.

A firm that assesses your controls and also sells you hardware has an obvious incentive problem. Ours is handled by a rule rather than a reassurance: where we deliver assurance work, equipment supply is off the table for that engagement and for twelve months after it. Where we supply equipment, we decline audit and certification work for the same period and refer it to someone else.

We hold no vendor commissions, rebates or referral fees. Equipment is supplied at cost plus a margin disclosed on the quotation, so recommending something cheaper costs us nothing. The full policy sits on our independence page.

What we supply

Categories.

End-user devices

Laptops, desktops, tablets and mobile handsets, specified to the work rather than to a catalogue tier.

Network and infrastructure

Switching, routing, wireless and on-premises server hardware, specified against your actual load and growth.

Security hardware

Firewalls, hardware authentication keys, encrypted storage and physical access control components.

Peripherals and workplace

Displays, docking, printing and conferencing equipment for offices and field operations.

We are vendor-neutral. Where you have a standing relationship with a manufacturer or a framework agreement you must buy through, we specify to it rather than against it.

How it works

Six stages, and you can stop after any of them.

01

Needs assessment

What the work actually requires, not what a vendor would like to sell. This stage regularly reduces the order.

02

Specification

A written specification you own and can take to any supplier — including one other than us.

03

Procurement

Sourcing, price comparison and order management, with the margin disclosed on the quotation.

04

Secure build

Devices delivered hardened rather than at factory defaults: encryption on, baseline configuration applied, default credentials removed.

05

Asset register

Every item recorded with serial, owner, location and lifecycle date — the register ISO/IEC 27001 Annex A expects you to hold.

06

Lifecycle and disposal

Refresh planning, and certified data-sanitised disposal with documentation you can produce to a regulator.

Why this differs

Secure by default, and audit-ready on arrival.

Hardened, not factory-default

Most equipment arrives with default credentials, no encryption and no baseline. Ours arrives configured — which is the difference between an asset and a liability on day one.

The register comes with it

Annex A of ISO/IEC 27001 expects an inventory of assets with assigned ownership. We hand you one that is already complete and in a format your auditor will accept.

Disposal is a data protection event

A discarded laptop holding personal data is a notifiable breach waiting to happen. Disposal is handled with certified data sanitisation and documentation you can produce on request.

Tell us what the work needs.

We will specify against that, and tell you honestly where you are about to over-buy.

Start a conversation