Skip to content

Security

Cybersecurity Services

Small businesses are not breached by sophisticated attacks. They are breached through email, reused passwords and machines that were never patched — and those are the things we fix first.

The problem

The attacks that reach you are boring, not sophisticated

Nobody is writing custom malware for a twelve-person dental practice. What reaches you is a phishing email that harvests a password, a login with no second factor, and a machine missing eight months of updates. The reason it works is that it costs the attacker nothing to try it against thousands of businesses at once.

Our approach

Layers, in the order that actually reduces risk

We work through the controls that stop the attacks you will genuinely face, cheapest and highest-impact first: multi-factor authentication everywhere, email authentication so nobody can impersonate you, endpoint detection that spots ransomware behaviour, disciplined patching, and backups that survive an attacker with admin rights.

What you get

Included as standard

Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.

  • MFA enforced across email, VPN and remote access
  • SPF, DKIM and DMARC configured so your domain cannot be spoofed
  • Managed endpoint detection and response, monitored 24/7
  • Patch compliance reporting you can show an insurer
  • Immutable backups an attacker cannot delete
  • Phishing simulation and short staff training
  • Documented incident response plan before you need it
  • Evidence trail for cyber-insurance questionnaires

How we work

What actually happens

  1. 1

    Baseline

    Establish what is exposed: external footprint, email authentication, MFA coverage, patch state, backup integrity.

  2. 2

    Close the gaps

    Fix the controls in order of risk reduction per dollar. MFA and email authentication come before anything expensive.

  3. 3

    Monitor

    EDR and alerting with someone actually watching, because an alert nobody reads is not a control.

  4. 4

    Rehearse

    Test restores and walk the incident response plan. The first time you practise should not be during an incident.

Technologies

What we build on

Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.

  • Managed EDR / XDR
  • Microsoft Entra ID Conditional Access
  • SPF · DKIM · DMARC
  • Email filtering and impersonation protection
  • Immutable backup
  • Security awareness training

Questions

Cybersecurity questions

We are small. Are we really a target?

You are not targeted — you are swept up. Attacks are automated and indiscriminate, and small businesses are more likely to pay because they are less likely to have tested backups. Being small makes you a better target, not a worse one.

Will our cyber-insurance premium go down?

We cannot promise that, but insurers now decline or price up businesses that cannot demonstrate MFA, EDR and tested backups. The controls we implement are the ones the questionnaires ask about, and we produce the evidence.

Is antivirus not enough?

Traditional antivirus matches known files. Modern ransomware is usually delivered through a legitimate login using a stolen password, so there is no malicious file to match. EDR watches behaviour instead, which is what catches it.

How long does it take to get to a reasonable baseline?

MFA and email authentication can be done in days. A full baseline including EDR, patch discipline and verified backups is usually a few weeks depending on how much needs replacing.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.