Cyber security
Cyber security that fits a business your size
Most cyber security advice is written for companies with a security team. You have a business to run and nobody whose job this is. The good news is that the handful of things that actually stop most attacks are unglamorous, well understood, and mostly already included in what you pay us each month.
No scare campaign. Just the things worth doing, in order.
What actually stops most of it
Almost every incident we see at this end of town starts one of three ways: someone's password is reused and turns up in a breach, someone clicks a convincing email, or a machine is months behind on updates. The controls below deal with all three.
Multi-factor authentication, everywhere
A stolen password on its own stops being useful. This is the single highest-value thing on the list, and it's the one insurers now ask about first. Set up properly it's a prompt on a phone, not a daily obstacle course.
Updates that actually get applied
Windows, macOS, browsers and the software people actually use. Not "there's an update available" sitting in someone's system tray for four months. On Managed and Complete we enforce this centrally, so it stops depending on whether anyone remembered.
Backups you've seen restored
A backup nobody has ever restored from is a hope, not a backup. That includes Microsoft 365 — Microsoft keeps the service running, but your mail and files are your responsibility. Daily backup of email, OneDrive and SharePoint is included with Managed and Complete, and available as an add-on on Essentials.
Staff who recognise a dodgy email
The convincing ones now reference real invoices and real names. Short, regular, non-patronising training beats an annual lecture. Staff security awareness training is included with Complete and available as an add-on on Managed — worth it if your team handles money or client data.
Nobody working as an administrator
Day-to-day accounts shouldn't be able to install anything. It's a quiet change that removes a whole category of problem, and most people never notice it happened.
Knowing what you've got
Which machines, which people, which licences, which old accounts are still switched on. You can't protect a list you don't have — and the departed-employee account is a classic way in.
What's already in your package
Every package includes MFA and sign-in security, Microsoft 365 administration and licensing, your email and domain records kept correct, and staff onboarding and secure offboarding. From Managed up you also get company computers managed with updates enforced, a maintained security baseline, daily backup of email and files, and security incident response including after hours. Complete adds staff security awareness training and an after-hours helpdesk for everyday issues.
None of it is a separate line item you get upsold after something goes wrong.
When it's about a contract, not a worry
If the reason you're reading this is a tender, a client security questionnaire or an insurer's renewal conditions, that's a different job — a programme with evidence and a deadline attached, rather than good hygiene. We run those too.
See the security & compliance programme · Security hardening as a fixed-price project
An honest word about guarantees
Nobody can promise you'll never have an incident, and you should be sceptical of anyone who does. What we can do is make the common attacks fail, make the uncommon ones survivable, and make sure that when something does happen there's a tested way back. If someone's selling you certainty, they're selling you something else.