Cybersecurity sized for a small business

We secure small and medium businesses with the controls that actually stop common attacks: Microsoft 365 hardening, enforced MFA, patched and protected endpoints, email authentication, staff awareness training and tested backups. It starts with a free security health check and continues with fixed-price projects. No fear-driven sales.

Most UK SMB breaches are not sophisticated. They are a phished password, an unpatched machine, or a leaver whose account still works. Closing those doors is unglamorous and very effective.

Who this is for, and who it is not

A good fit if:

  • Businesses handling client data that need to demonstrate basic security competence, which is increasingly a condition of winning contracts
  • Firms pursuing Cyber Essentials or Cyber Essentials Plus certification
  • Anyone whose cyber-insurance renewal form has questions they cannot honestly answer yes to

Not the right service if:

  • You need a 24/7 security operations centre with guaranteed incident response times. That is enterprise MSSP territory and we will say so rather than fake it
  • You want a compliance certificate without changing anything. Certification bodies and attackers both notice

What you actually get

Free security health check

A structured look at your M365 or Google setup, MFA coverage, patching and backups, with a short written summary of the gaps. No obligation, genuinely.

Security audit

A fixed-price assessment of your environment covering identity, devices, email, network, backups and staff practices, with a prioritised, costed remediation plan. Vulnerability scanning is included. Where a full penetration test is warranted, we scope it with specialist testers rather than overselling our own.

Microsoft 365 hardening

MFA and conditional access, sensible sharing defaults, mailbox rules audit, admin role cleanup, and alerting on the events that matter.

Email security

SPF, DKIM and DMARC configured and monitored, so your invoices stop landing in spam and criminals cannot convincingly spoof your domain.

Cyber Essentials support

Gap analysis against the five Cyber Essentials controls, remediation, and hand-holding through certification, including Plus if your contracts demand it.

Awareness training and phishing simulation

Short, non-patronising sessions for staff plus periodic simulated phishing, because people click less when they have seen the trick before.

How it works, from enquiry to handover

  1. Free health check. Book it, give us limited read access, get a written gap summary inside a week.
  2. Fixed-price audit or project quote. You choose the depth: full audit first, or straight to fixing the known gaps.
  3. Remediation. We implement the plan with minimal disruption. Most hardening work happens without users noticing anything except an MFA prompt.
  4. Keep it that way. Optional ongoing cover: patching, monitoring, periodic re-checks and annual certification renewal, usually bundled with IT support.

What it costs

Cybersecurity pricing
EngagementPriceNotes
Security health checkFreeWritten gap summary
Security auditFixed quoteSized by users, devices and systems
M365 hardening / email securityFixed quoteTypically a small project, days not weeks
Cyber Essentials supportFixed quoteGap analysis through to certification
Ongoing security coverMonthlyUsually bundled with IT support from £30/user/month

Certification body fees for Cyber Essentials are set by the certification body and passed through at cost. All prices are in GBP. Any applicable VAT is confirmed on your written quote before payment.

What we need from you

  • Admin or audit-level access to the systems in scope, arranged securely
  • An honest picture of current practice. The audit is not a test to pass, it is a map to draw
  • Management backing for the changes. Security fails when the boss demands an MFA exemption

Honest answers to common objections

“We’re too small to be a target.”

Most attacks are automated and do not check your size. They check whether the door is open. Small firms are hit precisely because attackers assume, often correctly, that defences are weaker.

“Security tools are expensive.”

Most of what protects an SMB is configuration of licences you already pay for. Microsoft 365 in particular ships with strong controls switched off. The spend is mostly engineering time, once, at a fixed price.

“Won’t this annoy my staff?”

Done badly, yes. Done properly, it is an MFA prompt roughly once a day per device and everything else is invisible. We tune conditional access so security lands on risky sign-ins, not on everyone all the time.

Where we work

Security work is delivered remotely across the UK, with on-site assessment and training available around Aldershot, Farnborough, Farnham, Fleet, Camberley and Guildford.

On-site work centres around Aldershot, Farnborough, Farnham and Guildford; remote delivery covers the whole UK.

Frequently asked questions

Do you do penetration testing?

We run vulnerability scanning as part of audits. Where a contract or risk profile genuinely requires a full penetration test, we scope and manage it with specialist CREST-accredited testers rather than pretending to be one. You get the right test and an honest bill.

How long does Cyber Essentials take?

From a reasonable starting point, typically 4 to 8 weeks including remediation. The certificate assessment itself is quick. Closing the gaps it will find is where the time goes.

What happens if we are breached right now?

Call us. Existing clients get immediate escalation. If you are not a client, we will help if we have capacity or point you at someone who can, and afterwards help make sure there is no next time.

Is GDPR part of this?

We handle the technical side of UK GDPR: access control, encryption, retention, breach detection and response planning. For heavy legal questions we will tell you when you need a specialist solicitor rather than an engineer.

Can you just secure Microsoft 365 and stop there?

Yes. M365 hardening is our most common first engagement, it is a fixed small project, and it closes the doors most SMB breaches walk through. Many clients start there and go no further for a year.

Talk it through first?

A free 30-minute call with no obligation. Or just phone us now and you will get straight through to an engineer.