Pillar 06 · Cyber Security

Cyber Security

Endpoint, email and network protection, multi-factor sign-in everywhere, Cyber Essentials certification, and the insurer's questionnaire answered from what is actually in place.

What it is

Security for a company of 10 to 200 people is mostly discipline: every device protected, every sign-in with a second factor, every patch applied, every alert looked at by a person. The tools matter, but the habit matters more, and the habit is what we sell.

We keep it plain. No dashboards you are expected to interpret, no annual scare. A baseline that is always on, a short list of what is outstanding, and someone accountable when the insurer, the auditor or the customer asks.

Who it is for
  • Companies whose insurer, customers or auditors are asking harder questions each year.
  • Firms that want Cyber Essentials without doing the paperwork themselves.
  • Anyone who has had a near miss and would rather not have the real thing.
What is included

In plain words

  • Protection on every device, monitored, with alerts acted on
  • Email security: the phishing and impersonation that gets past the basics
  • Multi-factor sign-in and conditional access across the tenant
  • Patching, on a schedule, with the stragglers chased
  • Firewalls and network security for each site; managed WiFi and secure VPN between sites and for people on the move
  • Cyber Essentials, and Cyber Essentials Plus, run for you end to end
  • Staff awareness: short, regular, not a lecture
  • Incident response, and the insurer and customer questionnaires answered
In the portal

How it shows up day to day

Security is not a dashboard we ask you to watch. Where it matters to you, the portal shows it: which devices are protected and current, and what is outstanding, without the jargon.

See the portal →

Senior engineer

Decides the policy, handles the incident, signs the Cyber Essentials submission.

Assistant

Watches the alerts, chases the unpatched device, drafts the insurer's questionnaire from what is actually in place.

The same job, both sides. An engineer decides; the assistant does the running around.
2006
Established
20
Years, and counting
3
London-area offices
6
Regions with client sites
8
Services, one agreement

Live service numbers, measured weekly and dated, are coming to this strip. We publish nothing we have not measured.

Questions

Questions people ask

Do we need Cyber Essentials?
If a customer, a tender or an insurer asks for it, yes. It is also a sensible baseline on its own: five controls, applied properly. We run the process and the renewal each year.
Is this included in Managed IT?
The basics are: protection on every device, multi-factor sign-in, patching. Certification, network security kit and specialist tools are agreed and priced separately, so you can see them.
What happens if something gets through?
You ring us. An engineer takes it from there: contain, recover, tell you plainly what happened and what changes. Then the questionnaire from your insurer, answered honestly.
What does a typical attack on a company our size look like?
Usually an email, not a hacker in a hoodie. Someone's password is guessed or phished, the attacker signs in, and quietly adds a rule that forwards any email mentioning invoices, bank details or payroll to an outside address. Weeks later a supplier's bank details 'change'. Multi-factor sign-in stops the sign-in; watching for those rules catches the rest.
What can our own staff do?
Five habits. Never store passwords in a browser, a notepad or a personal email. Turn on multi-factor sign-in for personal accounts too. Forward any email that asks for a password to us before clicking. If a sign-in prompt appears that you did not cause, deny it. And if you think a password has leaked, ring us and say the word urgent.

Not sure where you stand?

Eight questions, sixty seconds, a first reading on the spot.