Security
Cybersecurity Services
Small businesses are not breached by sophisticated attacks. They are breached through email, reused passwords and machines that were never patched — and those are the things we fix first.
The problem
The attacks that reach you are boring, not sophisticated
Nobody is writing custom malware for a twelve-person dental practice. What reaches you is a phishing email that harvests a password, a login with no second factor, and a machine missing eight months of updates. The reason it works is that it costs the attacker nothing to try it against thousands of businesses at once.
Our approach
Layers, in the order that actually reduces risk
We work through the controls that stop the attacks you will genuinely face, cheapest and highest-impact first: multi-factor authentication everywhere, email authentication so nobody can impersonate you, endpoint detection that spots ransomware behaviour, disciplined patching, and backups that survive an attacker with admin rights.
What you get
Included as standard
Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.
- MFA enforced across email, VPN and remote access
- SPF, DKIM and DMARC configured so your domain cannot be spoofed
- Managed endpoint detection and response, monitored 24/7
- Patch compliance reporting you can show an insurer
- Immutable backups an attacker cannot delete
- Phishing simulation and short staff training
- Documented incident response plan before you need it
- Evidence trail for cyber-insurance questionnaires
How we work
What actually happens
- 1
Baseline
Establish what is exposed: external footprint, email authentication, MFA coverage, patch state, backup integrity.
- 2
Close the gaps
Fix the controls in order of risk reduction per dollar. MFA and email authentication come before anything expensive.
- 3
Monitor
EDR and alerting with someone actually watching, because an alert nobody reads is not a control.
- 4
Rehearse
Test restores and walk the incident response plan. The first time you practise should not be during an incident.
Technologies
What we build on
Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.
- Managed EDR / XDR
- Microsoft Entra ID Conditional Access
- SPF · DKIM · DMARC
- Email filtering and impersonation protection
- Immutable backup
- Security awareness training
Questions
Cybersecurity questions
We are small. Are we really a target?
You are not targeted — you are swept up. Attacks are automated and indiscriminate, and small businesses are more likely to pay because they are less likely to have tested backups. Being small makes you a better target, not a worse one.
Will our cyber-insurance premium go down?
We cannot promise that, but insurers now decline or price up businesses that cannot demonstrate MFA, EDR and tested backups. The controls we implement are the ones the questionnaires ask about, and we produce the evidence.
Is antivirus not enough?
Traditional antivirus matches known files. Modern ransomware is usually delivered through a legitimate login using a stolen password, so there is no malicious file to match. EDR watches behaviour instead, which is what catches it.
How long does it take to get to a reasonable baseline?
MFA and email authentication can be done in days. A full baseline including EDR, patch discipline and verified backups is usually a few weeks depending on how much needs replacing.
Related
Often paired with
Managed IT Services
Proactive monitoring, patching and unlimited help desk for a flat monthly fee — so problems are fixed before they reach your staff.
Learn moreBackup & Disaster Recovery
Backups that are tested on a schedule, with a recovery time you have actually seen demonstrated — not assumed.
Learn moreCompliance Support
The technical controls and evidence trail behind HIPAA, PCI DSS and cyber-insurance questionnaires.
Learn more
Ready to secure your business?
A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.