Most security advice is written either for corporate IT departments who have a security team of their own, or as marketing designed to frighten you into buying something. Neither is much help if you run a business with eleven staff and no IT department.
Cyber security has become unavoidable for businesses of every size — insurers ask about it, clients ask about it, and the threats are real enough. But the gap between “this matters” and “here is what to do on Tuesday morning” is where most businesses get stuck.
We start with what actually gets exploited
The overwhelming majority of incidents we see do not involve anything sophisticated. They involve a password that was reused on a site that got breached. An email nobody looked at twice. A machine that quietly missed updates for eight months. A backup that had not run since March and nobody noticed.
So that is where we start — not because it is easy, but because it is what actually happens. Get those right and you have dealt with most of your real risk. Everything after that is refinement, and we will tell you honestly when you have reached the point of diminishing returns.
What that looks like in practice
Depending on what we find, the work usually involves some combination of:
- Multi-factor authentication on email and cloud accounts, set up so people will actually use it
- Testing that your backups restore, rather than trusting that they ran
- Endpoint protection on every machine, with somebody actually reading what it reports
- Email filtering, so the obvious attempts never reach anyone
- Short, practical training so your team recognises a phishing email
- Updates applied on time — which for clients on a support plan is handled by our remote monitoring
None of it is dramatic. All of it is the difference between a bad afternoon and a bad month.
What we will not do
We’re not chasing certifications you’ll never use or selling you a 24-page security policy that no one will read.
We will not recommend a product to solve a problem you do not have. We will not use fear as a sales technique — if something genuinely matters we can explain why in plain terms, and if we cannot explain it, that is a good sign it does not matter as much as somebody wants you to think.
And we will not pretend that everything needs doing at once. Most businesses have a couple of things worth fixing this month and a couple worth planning for next year. Knowing which is which is most of the value.
How this is priced
There is no monthly security package here.
We look at what you have, tell you what is worth doing, and quote for the work. You see the assessment before you commit to anything beyond it.
Some of what we recommend, you will be able to do yourselves — and we will tell you which parts those are rather than quietly billing you for them. That costs us a little work and buys us clients who trust what we say, which we consider a good trade.
Where Cyber Essentials fits
Get the fundamentals right and Cyber Essentials becomes largely a matter of evidencing what you already do. Do it the other way round — chase the certificate first — and you end up with a badge sitting on top of the same weaknesses.
That said, the certificate is increasingly not optional. Insurers ask for it, public sector contracts require it outright, and larger clients put it on tender documents. When somebody asks you for it, we will get you there.
Fundamentals first, certification when it is wanted. In that order, both are straightforward.
A word about insurance
Your insurer will ask what you have in place — multi-factor authentication in particular — and will price your premium on the answers.
The part worth paying attention to is that you are held to what you declared. If the proposal form said you had MFA across the business and it turns out three accounts never had it, that is a conversation you do not want to be having at the same time as dealing with an incident.
We can go through what you have told your insurer and tell you honestly whether it matches what you actually have. That is usually a short conversation, and occasionally a very valuable one.
Honest about what you need, honest about what you don’t.