Security that someone watches
Plenty of small businesses have antivirus, a firewall and a vague sense that it's handled. The gap is usually not the tools. It's that nobody reads what the tools report. An alert at 3am is worthless if it sits in an unmonitored inbox until Thursday.
Our approach is layered and fairly ordinary: sensible defaults applied consistently, alerts triaged by a person, and the boring maintenance done on schedule. Most breaches at this end of the market don't involve anything sophisticated. They involve an unpatched machine, a reused password, or someone clicking a link in a convincing email.
What we cover
- Managed detection and response: endpoint monitoring with alerts reviewed and acted on
- Email security: filtering, impersonation protection and safe-link checking
- Multi-factor authentication: rolled out properly, including the awkward legacy apps
- Phishing simulation and staff training: short, regular, not an annual two-hour slideshow
- Patch and vulnerability management: with quarterly reporting you can show a client or insurer
- Access reviews: because ex-employees keeping live accounts is more common than anyone admits
- Cyber Essentials preparation: systems aligned to the controls, evidence assembled, assessment supported
Cyber Essentials, and why it keeps coming up
Cyber Essentials is a UK government-backed scheme covering five basic control areas: firewalls, secure configuration, access control, malware protection and patch management. It's increasingly a precondition rather than a nice-to-have. Many public sector contracts require it before you can bid, and a growing number of larger private clients ask for it during procurement. Insurers ask too, and premiums often reflect the answer.
We prepare your systems against the controls, walk you through the self-assessment, and produce the supporting evidence. Where you're aiming for Cyber Essentials Plus, which includes hands-on technical verification, we make sure the estate will pass before the assessor looks at it.
A note on honesty. No provider can promise you won't be breached, and you should be wary of any that does. What good security buys you is fewer incidents, earlier detection, and a much faster recovery when something does get through. That's the difference between a bad afternoon and a bad quarter.
Compliance and evidence
If you handle personal data you have UK GDPR obligations regardless of size, and if you work in a regulated sector or supply into one, you'll be asked to demonstrate controls rather than describe them. We keep the documentation current, covering asset registers, access lists, patch reports and backup test results, so that when the questionnaire arrives you're filling it in rather than starting from nothing.
Common questions
Do you hold Cyber Essentials yourselves?
Ask us directly and we'll give you a straight answer about our current certification status. We'd rather tell you plainly than let a logo on a website imply something inaccurate.
How often should staff have security training?
Short and frequent beats long and annual. Regular phishing simulations with brief follow-up for anyone who clicks changes behaviour far more reliably than a yearly presentation everyone forgets.
We're small. Are we really a target?
Small businesses are targeted precisely because defences are typically weaker. Most attacks aren't personal. They're automated sweeps looking for anything vulnerable, and size doesn't come into it.
What happens if we do get breached?
We contain it, work out what was accessed, restore from clean backups and document the incident. If personal data was involved there may be a duty to report to the ICO within 72 hours, and we'll help you assess that.