Cyber Security
Cyber security for small businesses, proportionate to the business you actually are
Cyber security for small businesses means endpoint protection, email filtering, multi-factor authentication, patching discipline and staff guidance: sensible, proportionate safeguards explained plainly. No scare tactics, and no enterprise tooling you will never use.
- MFA first, always
- Cyber Essentials support
- No enterprise upsell
The five things that actually matter
For a business of five to fifty people, the great majority of real-world risk is closed by five unglamorous controls: multi-factor authentication everywhere, patching that actually happens, endpoint protection that is monitored rather than installed and forgotten, backups that have been proven to restore, and staff who know what a convincing invoice fraud looks like.
None of that is exciting and none of it requires a six-figure platform. It is also, in our experience, where nearly every small business we audit has at least two gaps. We would rather close those than sell you a dashboard.
Security work sits inside our business IT support plans, with the Complete plan adding Cyber Essentials preparation and a quarterly review.
Security is part of our business IT support.
What we put in place
- Multi-factor authentication across email and remote access, rolled out without a mutiny
- Managed endpoint protection with alerts that reach an engineer, not just a log
- Email filtering for spam, phishing and impersonation of your own domain
- Patching on a schedule for operating systems and the third-party software that gets forgotten
- Least-privilege accounts, and the removal of the admin logins belonging to people who left
- Backups held in two places with restores tested rather than assumed
- Conditional access and alerting on logins from places your staff are not
- Plain-English staff guidance, including what invoice fraud actually looks like
Cyber Essentials
Cyber Essentials is a UK government-backed certification covering five basic technical controls. It is increasingly a condition of public sector contracts and larger private tenders, and for a small business it is genuinely achievable rather than a paper exercise.
On the Complete plan we prepare you for it: gap analysis against the five controls, the remediation work, and the evidence gathering that makes the assessment straightforward rather than a scramble.
There is a full write-up in the small business guide to Cyber Essentials.
Want to know where you actually stand?
The free review includes a look at your security position, and you keep the written findings whether you work with us or not.
Get in touch
Talk to us about cyber security
A few lines is enough. We will tell you straight whether we can help, what it would cost and how quickly we can be there. No hard sell, and no follow-up sequence if you decide against it.
- We reply within one working day
- A straight answer, including when it is no
- Free process review available, before any money changes hands
Would rather just ring? 01623 354250, Mon–Fri, 9am–5:30pm.
Frequently asked questions
If the answer is not here, ask us. You will get a straight one, from someone who does the work.
Mon–Fri, 9am–5:30pm
What cyber security does a small business actually need?
Multi-factor authentication, reliable patching, monitored endpoint protection, backups with tested restores, and staff who can recognise invoice fraud. Those five close most real-world risk for a business of five to fifty people, and most of the businesses we audit have at least two gaps among them.
Do we need Cyber Essentials?
If you bid for public sector work or supply larger organisations, increasingly yes. It is turning up as a tender condition. Beyond that it is a useful forcing function, because the five controls it checks are the ones worth having anyway.
How much does Cyber Essentials cost?
The certification itself is a few hundred pounds for a small business. The real cost is the remediation work beforehand, which varies enormously depending on what state things are in. We do a gap analysis first so the number is known rather than discovered.
Is antivirus enough on its own?
No, and it has not been for years. Antivirus catches known malware. It does not stop someone entering their password into a convincing fake login page, which is how most small business breaches now start. That is what multi-factor authentication is for.
What happens if we get hit by ransomware?
The answer depends entirely on your backups. With copies held in two places and restores that have been tested, it is a bad few days of recovery. Without, it is a business-threatening event. That is why backup testing sits in the security conversation rather than beside it.
Do you provide staff security training?
We provide plain-English guidance and practical sessions rather than a compliance video nobody watches. The most useful part is usually walking through the actual fraudulent emails that have reached your business.