Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Services
London · IT Services

Cyber Security

Layered protection sized for a small business — we tell you what to fix first, what can wait, and why the order matters more than the shopping list.

Response within 4 hours On-site & remote No long contracts Windows & Mac
A glowing security shield on a laptop screen, representing threat protection

Start with the order, not the shopping list

Most security advice arrives as a flat list. Endpoint protection, email filtering, multi-factor authentication, backups, training, testing, encryption — everything presented as equally urgent, nothing ranked. If you run a 20-person business with a finite budget and nobody whose actual job is security, that list is not help. It is a way of feeling permanently behind.

The useful question is narrower. What buys the most risk reduction per pound, and in what order? That has an answer, and it is fairly stable from one small business to the next, because the ways small businesses get hurt are fairly stable too. A convincing email. A password reused from a site that was breached three years ago. A laptop that stopped receiving updates and nobody noticed.

So this page is an order of operations rather than a catalogue. The spine is the five Cyber Essentials controls — a UK government-backed scheme, and a sensible skeleton whether or not you ever apply for the certificate itself. If the certificate is what you actually need, the certification process is a job of its own and it has its own page. Here we are talking about the practice, not the paperwork.

The five controls, translated into a real office

Firewalls and internet gateways. For a small office this is less about buying a box and more about what the box you already have is doing. The router your broadband provider supplied is a firewall of sorts. The questions are whether its admin password was ever changed from the printed default, whether remote management is switched off, and whether something was port-forwarded to a machine inside the office years ago and then forgotten. Hybrid working moves the boundary anyway: if half your staff sit behind a home router you do not control, the firewall that matters is the one on the laptop, backed by a properly configured remote access setup rather than a port left open for convenience.

Secure configuration. Devices and services ship configured for easy setup, not for safety. That means default accounts still enabled, features nobody uses still running, and sharing settings wider than anyone intended. In Microsoft 365 the defaults are where we find most of it — anonymous sharing links that never expire, mailbox forwarding rules staff can create for themselves, older sign-in methods still permitted alongside modern ones. None of that is exotic. It is simply nobody’s job, so it stays as it came out of the box.

User access control. Everyone gets their own named account, and administrator rights are rare and deliberate. The small-business version of this going wrong is recognisable: a shared login to the accounts package because it was simpler, one password held by four people, and a leaver from last spring whose access was never actually removed. Standard user accounts also blunt a lot of malware, because software that cannot install itself has far fewer options.

Malware protection. Modern anti-malware on every machine, including Macs, and including the laptop that lives on someone’s kitchen table. The part that gets skipped is central visibility — one place that tells you all twenty-three devices are protected and current. A licence bought once, installed by whoever set the machine up and never looked at again, is a receipt rather than a control.

Security update management. The dullest of the five, and the one that quietly does the most work. It means updates applied within a sensible window rather than deferred indefinitely, and it means retiring software that has passed its support date. Windows 10 stopped receiving free security updates in October 2025, which turned a lot of perfectly serviceable laptops into an unpatched liability more or less overnight. Old machines rarely announce themselves. They just keep working while the gap between them and current attacks widens.

Three things a checklist under-sells

The five controls are a floor, not a ceiling. Three things deserve more attention than any framework tends to give them.

Multi-factor authentication, done properly. Not switched on somewhere, but on every account that reaches your email, your files or your money — including the ones nobody thinks about, like shared mailboxes, the global admin account, the accounting platform and the remote-access login. The form matters too: an app prompt or a hardware key is meaningfully stronger than a code sent by text. And staff need to understand that an approval request they were not expecting is something to report, not an annoyance to tap away.

A backup you have actually restored from. An untested backup is a belief, not a backup, and ransomware crews go looking for backups before they encrypt anything else. Two things catch small firms out. The first is never having rehearsed a restore, so nobody knows how long it takes or what turns out to be missing. The second is assuming Microsoft holds a copy of everything — Microsoft protects the platform, while your content remains your responsibility, which is why a separate copy of your 365 tenant is a different thing from a retention setting. The wider backup and continuity work is where recovery targets get agreed and proven.

People. Every control above can be working perfectly while somebody is talked into approving a payment to a new bank account. That is not a failure of the tools, and no product fixes it alone. Short, regular security awareness training that coaches rather than catches people out changes the odds — and, more usefully, changes how quickly you find out that something went wrong.

The order we would actually work in

  1. Multi-factor authentication across email, cloud and remote access — usually the largest gain for the least money
  2. Patching and update management, plus an honest inventory of anything past its support date
  3. Remove standing administrator rights and close accounts belonging to people who have left
  4. Prove the backup by restoring something real, then fix whatever that exercise exposes
  5. Tighten the configuration of Microsoft 365, the firewall and the devices themselves
  6. Train the people, and keep training them in small doses rather than one annual session
  7. Test it independently once the basics hold, so you are checking reality rather than intentions

Steps one to four are where the risk actually falls. A business that has done those four and bought nothing else is in a better position than one that bought a security product and skipped them. That is not an argument against the later steps — it is an argument against doing them first.

Who this suits

Small and mid-sized businesses across Streatham, South London, Croydon and Surrey that hold client data, move money by email, or would lose real revenue in a day of downtime — and any firm being asked by a customer, funder or insurer to show that security is handled rather than hoped for. It fits home-workers and hybrid teams particularly well, because that is where the gap between “we have IT” and “someone checks” tends to be widest. If nobody in your business can say when a restore was last tested, or who still holds admin rights, that is your honest starting point.

When something gets through anyway

No layered defence is a promise that nothing will ever land, and a provider telling you otherwise is selling something. What good security buys you is fewer incidents, smaller ones, and earlier discovery. When something does get through, the order matters again: contain it so it stops spreading, understand what was reached before changing anything, recover from clean backups, then close the way in. Rebuilding a machine without finding the entry point simply schedules the next call. Where there is an active infection, that is malware removal and clean-up work, and it sits alongside the managed IT support that keeps patching, accounts and backups in order the rest of the year.

Not sure where you stand? Get in touch and we will start with a review of what you already have — then tell you plainly what to fix first, and what can wait.

Frequently asked questions

We have a limited budget. What should we buy first?

Multi-factor authentication on email and cloud accounts, because it is usually included with licences you already own and it blocks the most common route in. Then patching and removing local administrator rights. Then a backup you have restored from. Paid tooling comes after those, not before — buying a security product while a director's mailbox has no second factor is spending money in the wrong order.

Is a business our size actually a target?

Almost nothing aimed at a 20-person firm is personal. The bulk of it is automated — scanners looking for an exposed login, mass phishing sent to every address a crawler found on your website, credentials from an old breach tried against your Microsoft 365 tenant. You are not being singled out; you are being included. That is also the good news, because generic attacks are stopped by ordinary controls.

We already have antivirus and a firewall. Isn't that enough?

They are two of five basic controls, and they cover threats that arrive as files or network traffic. They do nothing about a member of staff typing a real password into a convincing fake login page, an account with no second factor, or a laptop three months behind on updates. A great deal of what hits small firms walks through the front door with valid credentials rather than breaking anything.

Do we need Cyber Essentials certification, or just the controls?

Different questions. The controls are worth implementing regardless — they are a sensible floor for any business. The certificate is worth paying for when someone external asks for it, usually a public-sector tender, a grant funder or a cyber insurer. Plenty of businesses start with the controls and certify later, when a contract makes it necessary. We can help with either.

Our staff use their own phones and laptops. How do we handle that?

Personal phones are usually fine for MFA prompts and email, provided the mailbox is managed and can be removed remotely without touching personal photos. Personal laptops are the harder case, because you cannot patch, encrypt or verify a machine you do not control. Where budget allows we move people onto company devices; where it does not, we limit what an unmanaged device is allowed to reach.

What actually happens if something gets through?

The sequence is contain, understand, recover, then close the gap. We isolate affected machines and accounts so nothing spreads, work out what was reached and whether personal data is involved, restore from clean backups, and fix the route in so the same thing cannot work twice. We will not attach a stopwatch to that — the honest answer depends entirely on what happened.

Case study · National health charity

100+ devices encrypted · audit evidence delivered

Facing a security audit, a national health charity needed every laptop encrypted and provably compliant — not just assumed to be. Our team deployed BitLocker and Secure Boot across 100+ devices, tightened patch compliance, and produced the evidence the auditors asked for. The charity could then show, not just claim, that its data was protected.

— Our team

Read the full case study →
What clients say

Trusted by London businesses.

“Honest and transparent — they could have charged me more, but instead showed me a simple fix. Trustworthy people.”
— Small business client, London
“One of the most ethical companies I’ve ever dealt with. A genuine pleasure to work with — highly recommended.”
— Managed IT client
“The service was flawless — no bad surprises, everything just worked. Highly recommended.”
— Business client, London
“Thank you very much for your assistance. A pleasure as always.”
— General manager, accommodation business, Chelsea SW3

Feedback from clients of our team, including our sister company PC Macgicians, who deliver much of our engineering work. Names withheld at their request.

Free · no obligation

Need help with Cyber Security?

Tell us what you need and we'll come back with a clear, no-obligation plan and price.