Services
Cyber Security
Many businesses are purely digital. Imagine your data was lost — it happens more often than you think. Whether it is an outside attack or internal corruption, we protect your continuity.
What this covers
- Zero-trust monitoring
- Anti-virus and anti-malware
- Email and identity protection
- Security awareness training
- Incident response
A zero-trust approach
We map a team member's regular activity and get told when outlier events occur, rather than waiting to be informed after something has already gone wrong.
End-to-end protection
It takes ten years to build a business and one clever hack to corrupt all its data. Buying an attack is as easy as going to the supermarket. We would rather you did not find that out first-hand.
Anti-cyber-attack technology, anti-virus and anti-malware, and data management systems that keep things secure internally. Onsite training to reduce human error is available and recommended.
The attack is usually a login, not a virus
The mental picture most people carry — malware slipping past anti-virus — describes a shrinking share of what actually happens to businesses.
The common version is duller and worse. Someone's password is phished or reused from a breach elsewhere, an attacker signs in as them, and everything that follows is a legitimate user doing legitimate things. No malware runs. No alarm sounds, because from the system's point of view nothing wrong is occurring. Identity is the perimeter now, and the questions that matter are who signed in, from where, on what, and whether that is normal for them.
That is why anti-virus, while necessary, answers a question that is no longer the one being asked.
MFA is necessary. It is not sufficient.
Multi-factor authentication is the highest-value control most businesses can turn on, and it should have been on years ago. It is also routinely defeated now, which is worth knowing before you treat it as finished.
Attackers push repeated approval prompts until someone taps accept to make it stop. They stand in the middle of a convincing sign-in page and relay the code in real time. They steal the session token after authentication, at which point the second factor has already been satisfied.
What closes those gaps is conditional access — decisions about which devices, which locations and which risk signals are acceptable, rather than a single yes/no at the door. Phishing-resistant methods where they matter. And somebody watching for the sign-in that succeeded but should not have, which is what SIEM and monitoring is for.
The expensive incident is an invoice, not an outage
Ransomware gets the attention. Business email compromise takes the money.
The pattern is consistent: an attacker sits in a mailbox reading quietly, learns how your business talks about payments, then intervenes in a real conversation at the right moment with new bank details. Nothing is encrypted. Nothing is obviously broken. The first anyone knows is a supplier asking where their money is.
It is defended in two places at once — the identity controls above, and a process rule that no change of payment details is actioned on the strength of an email, ever, however normal it looks. The second one costs nothing and is the one most businesses skip.
Assume it will happen anyway
Every control above reduces the odds. None of them makes the number zero, and a provider who implies otherwise is selling you something.
So the other half of the work is what happens afterwards: whether you can tell what was accessed, whether you can get back to working, and who makes the decisions while everyone is upset. The evidence question depends on logs being collected before the incident, which is the whole argument for monitoring. The recovery question depends on backups that were tested. Neither can be arranged retrospectively.
Worth agreeing in advance, too: who you call at 6pm on a Friday, and what they are authorized to do without waiting for someone to wake up.
Two things that are driving this for most businesses
Insurance. Cyber policies now come with questionnaires that ask about specific controls — multi-factor authentication, endpoint detection, tested backups, admin account separation. Answering optimistically is a poor idea, because the answers are read again at claim time. If a renewal is coming, that form is a decent audit of where you actually stand.
Customers. Security questionnaires have moved down the supply chain, and businesses that never expected to be asked are now being asked. For defense contractors it is formalised as CMMC and NIST SP 800-171, and the same controls answer both.
Common questions
Do we need this if we already have anti-virus?
Anti-virus catches known threats on a device. It does not tell you when a legitimate account starts behaving unusually, which is what most real incidents look like now. The common attack is not malware slipping through — it is someone signing in with a valid password and doing ordinary things with it.
We have MFA. Are we covered?
MFA is the highest-value control most businesses can turn on and it is not the end of the exercise. Attackers defeat it by pushing repeated approval prompts until someone accepts, by relaying codes through a convincing fake sign-in page, and by stealing the session token after authentication has already succeeded. What closes those gaps is conditional access, phishing-resistant methods where they matter, and somebody watching for the sign-in that worked but should not have.
What is business email compromise?
An attacker gets into a mailbox, reads quietly until they understand how your business discusses payments, then joins a real conversation with new bank details at exactly the right moment. Nothing is encrypted and nothing looks broken, which is why it is caught late. Two defenses matter: the identity controls that stop the mailbox access, and a rule that payment details are never changed on the strength of an email. The second costs nothing and is the one most businesses do not have.
How would we know if we had been breached?
Only if something was collecting the evidence beforehand. That is the uncomfortable part — the question is decided before the incident, not after it. Sign-in logs, mailbox activity and endpoint telemetry have to exist and be watched, which is what SIEM and monitoring provides. Working it out retrospectively from an environment that was not logging anything is largely guesswork.
Our insurer sent a security questionnaire. Can you help?
Yes, and it is worth treating seriously rather than as paperwork. Those forms ask about specific controls — MFA, endpoint detection, tested backups, separated admin accounts — and the answers get read again at claim time. Going through it honestly is one of the better free audits of where a business actually stands.
The other things we do
-
Managed IT Services
We take responsibility for your systems. Unlimited helpdesk, proactive maintenance, and status monitoring, so your team stops losing hours to technology that should just work.
-
Compliance & CMMC
CMMC Level 2 readiness and Microsoft GCC High / Azure Government environments for the defense supply chain, built so evidence of every control is ready to produce.
-
Cloud Solutions
Microsoft Azure, Azure Virtual Desktop, and Microsoft 365 — designed, migrated, and run by engineers who hold the certifications for all three.
-
Backup & Disaster Recovery
Backups you have actually tested and a disaster recovery plan that has actually been rehearsed. It takes ten years to build a business and one bad day to lose its data.
-
AI Services
Practical AI inside the tools your team already uses — with the same care about where your data goes that we apply to everything else.
-
Web Development
Websites built to be fast, findable, and owned by you — treated as infrastructure to be maintained rather than a project that ends at launch.
Get in touch
Talk to us about cyber security
Tell us what you're dealing with and we'll respond as soon as possible.