Security & Protection

AI made attacks cheap.
Small businesses are the soft target.

An automated attack no longer needs a person deciding you are worth the trouble. It scans everything, constantly, and a small business with a forgotten plugin and a shared password is the easiest thing on its list. We find what is exposed, fix what we can, and tell you honestly what needs somebody else.

How it actually happens

It is almost never
a hacker in a hoodie.

Three routes account for most of what we see, and not one of them requires anybody to have targeted you specifically.

Something you installed and forgot

A plugin, a theme, an extension or an add-on that quietly stopped being updated. It appears in no list of your systems, so nobody reviews it — and a scanner finds it before you do.

A password that opens more than one door

Reused across the website, the email, the payment tool and the hosting. One breach anywhere becomes a breach everywhere, and the first you hear of it is a customer asking why they got a strange email from you.

A backup nobody has ever restored

Backups that have been running for months and are empty, or that nobody has ever tried to put back. Until it has been restored, a backup is a theory.

What we do about it

Six things worth doing first

In this order. The first four are mostly a weekend of setting up and then a habit, and between them they close off most of what actually happens to businesses this size.

01

A record of what you actually run

Every site, system, subscription, plugin and integration written down in one place, with who owns it and what breaks if it goes. Most of what hurts a small business is something nobody knew was there.

02

Access and passwords

One account per person, removed the day they leave. Multi-factor on anything that matters, and a password manager so nobody has to remember or reuse anything.

03

Updates that genuinely happen

Automatic where that is safe, monitored where it is not, and checked rather than assumed. A managed install that has quietly switched its own updates off is a common and expensive surprise.

04

Backups that are tested

Off the machine, off the site, and restored on a schedule to prove they work. We have found backup jobs that had been reporting success for a fortnight while writing empty files.

05

Monitoring that tells a person

Something watching for the change nobody made on purpose — a new admin user, a modified file, a certificate about to lapse — and telling a human within the hour rather than at the end of the month.

06

A private internal network

For the work that should not be on the open web at all. Staff reach the system over a private network from wherever they are, and to everybody else it simply is not there. It costs very little and removes a whole category of attack.

What we take on,
and what we don't.

Security is the one service where being vague ends up costing somebody real money. This is the line, in writing, before you ask for it.

What we do

  • Secure the systems we build and host — updates, access, backups, certificates and monitoring, included rather than sold as a bolt-on
  • Audit what you already run and hand you a written record of it, whether or not we built any of it
  • Set access up properly: one account per person, multi-factor, a password manager, and a process for removing somebody
  • Set up and run a private network so staff can reach internal systems without those systems being exposed to the internet
  • Recover a site or system we host, from backups we have actually restored
  • Tell you plainly when something needs a specialist, an insurer or the police rather than us

What we don't do

  • Twenty-four-hour incident response. We are a small senior team, not a manned security operations centre, and we will not pretend otherwise
  • Certification. We are not a Cyber Essentials assessor and cannot award or sign off a certificate — though this work gets most businesses most of the way there
  • Your physical office network, unless we built it. Routers, firewalls and Wi-Fi that somebody else installed stay with whoever installed them
  • Penetration testing. That is a specialist discipline with its own accreditation, and we will introduce you to someone rather than improvise it
  • Any guarantee that you will not be breached. Nobody honest offers one. What we can promise is that you will know what you have, it will be up to date, and you will be able to get it back

The questions we get asked

We're only ten people. Is this really aimed at us?

Ten people is precisely who automated attacks find easiest, because the tooling does not check your size before it scans you and nobody in a business that size has this as their job. It does not have to be expensive — most of the value sits in the first four items above.

We already have IT support. Does this replace them?

No, and we will say so if that is the honest answer. Where somebody already manages your machines and network, we cover what they usually do not: the websites, the applications, the subscriptions and the data. Where the two overlap we would rather talk to them than around them.

What is the private network actually for?

Anything that should not be reachable from the open internet — an internal admin, a client database, a document store. Staff connect over a private network from wherever they are, and to everyone else the system is not visible at all. It is cheap, and it removes a whole class of attack rather than defending against it.

How does this relate to the £995 audit?

Security is one of the three things the audit looks at, alongside what you are paying for and what could be automated. You get the findings in writing with a figure or a risk against each one, and you are free to act on them yourself. The audit is the diagnosis; this page is the treatment.

Something has already happened. Can you help?

Call rather than email. If it is live we will tell you within the hour whether it is something we can help with or something that needs a specialist and your insurer — and we will say which, rather than taking the work either way.

Find out what you're
actually exposed to.

Two days, a fixed price, and a written report you own outright. If it doesn't pay for itself, you don't pay for it.