Security that makes sense when you have no IT team.
Most cybersecurity advice is written for enterprises with dedicated security staff and six-figure budgets. If that is not your situation, we built this for you.
Where does the risk actually sit?
Pick the situation that sounds most like yours.
Phishing is not a tech problem — it's a process problem.
Most successful phishing attacks succeed because there is no agreed procedure for what to do when a suspicious email arrives. Whoever is least sure simply clicks.
- Written procedure for suspicious emails
- One-hour staff awareness session (no jargon)
- Email gateway configuration review
Remote work introduced gaps that office working did not.
When staff started working from home, most businesses moved fast and skipped controls that would have been automatic in an office. Those gaps are still there.
- Remote-access configuration audit
- Multi-factor authentication setup
- Device policy for home use
Not knowing where you stand is itself a risk.
An SME security audit gives you a clear picture of what controls exist, what is missing, and what matters most given how your business actually operates — not how the textbook says it should.
- Half-day on-site or remote assessment
- Written report with prioritised actions
- No assumptions about your technical knowledge
Field Notes
What we're writing about. No news aggregation, no sponsored content.
Things people usually ask first
Honest answers to the questions we hear before almost every engagement.
Automated attacks do not distinguish by size. The phishing kits and ransomware strains that target large enterprises are the same ones hitting accountants, solicitors and retailers with ten staff. Small businesses are often more attractive because they hold real data and tend to have fewer controls in place.
Cyber Essentials (self-assessment) is the right starting point for most SMEs. Plus involves a technical verification by an external assessor and is worth pursuing if you bid for government contracts or want external confirmation of your controls. We can support either route.
A security audit reviews your controls, policies and configurations — it answers "what should be in place and what isn't." A penetration test actively attempts to exploit weaknesses — it answers "can someone actually break in given what's in place." Most SMEs benefit more from an audit first; a pen test makes most sense once basic controls exist.
A standard SME audit takes half a day on-site or via video call, with a written report delivered within three working days. Staff awareness sessions run 60 to 90 minutes. Longer engagements (Cyber Essentials support, incident response planning) vary by scope and are scoped after an initial call.
Yes. The majority of our work is now done remotely and the nature of the work — reviewing documents, configurations and policies — suits a video call well. On-site visits are available across Yorkshire and the Humber at no travel surcharge, and elsewhere by arrangement.