Cyber security
Security sized for a real business.
Most breaches at businesses your size are not sophisticated. They are a reused password, an unpatched laptop, or someone clicking a convincing invoice. We close the ordinary gaps properly before selling you anything exotic.
What is included
Multi-factor authentication everywhere it matters
Email, remote access, finance systems and admin accounts. The single highest-value control available to a business your size, and the one most often left half-finished.
Endpoint protection and encryption
Managed protection on every device, with disk encryption enabled so a lost laptop is an inconvenience rather than a disclosure event.
Phishing simulation and staff training
Short, regular, and not designed to humiliate anyone. The goal is a team that reports suspicious email quickly, not a scoreboard.
Patching on an auditable schedule
Known vulnerabilities closed on a documented cadence, with evidence you can hand to an insurer or a client asking about your controls.
Backups proven by restore
A backup nobody has restored from is a hypothesis. We test recovery on a schedule and document how long a real restore actually takes.
A written incident plan
Who to call, what to isolate, what to preserve and who needs telling. Decided calmly in advance rather than invented at 6am.
What you should expect
- The common attack paths closed, not just monitored
- Evidence of your controls for insurers and enterprise clients
- Staff who report suspicious email instead of hiding mistakes
- A recovery time you know, because it has been measured
Common questions
- We are small. Are we actually a target?
- Most attacks are not targeted at all — they are automated and indiscriminate, which makes smaller businesses with weaker controls comparatively easy. Being small reduces attention, not exposure.
- Do we need this if we are fully on Microsoft 365?
- Microsoft secures its platform; your tenant configuration, your devices and your staff are still yours to get right. A default 365 setup leaves meaningful gaps, and closing them is usually configuration rather than new spend.
- Will security controls slow our team down?
- Badly implemented ones will, and people route around friction. We aim for controls staff barely notice — single sign-on, sensible session lengths, and MFA prompts that do not fire twenty times a day.
- Can you help with a cyber insurance questionnaire?
- Yes. Those forms ask specific questions about MFA coverage, patching cadence, backup testing and incident response. We can answer them accurately, and tell you where an honest answer would currently be no.
- What happens if we are breached?
- We work the incident plan: contain, preserve evidence, restore from tested backups, and support whatever notification obligations apply. Then a written post-incident review of what allowed it and what changed as a result.