03 — Cybersecurity

Security sized for a small business.

You do not need an enterprise security programme. You need the handful of controls that stop the attacks small businesses actually face — configured properly and verified, not just purchased.

6

The layers that matter

Controls
01 Endpoint protection

Managed detection on every laptop, desktop, and server — with someone watching the alerts. Software nobody monitors is a receipt, not a control.

02 Email security & phishing defence

Email is how most breaches start. Filtering, anti-spoofing records (SPF, DKIM, DMARC), and impersonation protection for the addresses attackers copy.

03 Identity & access control

Multi-factor authentication everywhere it matters, least-privilege access, and a real offboarding process so former staff lose access the day they leave.

04 Backup & recovery

Backups that are isolated from your network, so ransomware cannot encrypt them too — and restore tests, because an untested backup is a hope, not a plan.

05 Security awareness training

Short, regular training plus simulated phishing, so your team learns to spot the message that gets past the filter.

06 Policy & compliance support

The written policies and evidence that insurers, clients, and questionnaires increasingly demand — produced once and kept current.

1–4

Getting to a defensible position

Approach
  1. Baseline

    We assess what is actually in place today against the controls that matter, and rank the gaps by real risk.

  2. Close gaps

    MFA, backups, endpoint coverage, and email authentication first — the controls that block the most common attacks.

  3. Verify

    Restore tests, access reviews, and phishing simulations to prove the controls work rather than assuming.

  4. Maintain

    Ongoing monitoring, patching, quarterly access reviews, and refreshed training as staff change.

What to expect

What good looks like here.

Security work is scoped from the baseline assessment. Most small businesses can close their highest-risk gaps in a few weeks, not a few quarters.

Baseline assessment
Fixed fee, roughly 1–2 weeks
Priority
MFA, backup, endpoint, email auth
Restore testing
Scheduled and documented
Access reviews
Quarterly
Awareness training
Ongoing, with phishing simulation
Reporting
Plain-English risk summary

No honest provider can promise you will never be breached. What we can do is close the gaps attackers rely on, and make sure you can recover quickly when something does get through.

Cybersecurity

Find out where you actually stand.

A baseline assessment tells you which risks are real and which are noise. You get the findings in writing, whether or not you continue with us.

Get in touch