Skip to main content
01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeServices › Cyber Security

Cyber security that protects your business and proves you have done the right things

We help growing businesses put the right controls around your people, devices, email, Microsoft 365 and backups, so you can reduce risk, answer insurer questions and recover faster if something goes wrong.

Andy Price of Initial IT — Cyber Security
Free interactive tool

Take the 2-minute cyber health check

Answer 11 plain-English questions, get a score out of 100 and your three highest-impact fixes.

Cyber Security Health Check

11 plain-English questions about the way your business actually works. Get a score, see where you are weakest and the three things to fix first.

Free AI webinar for business owners

See what AI can safely do for your business, and where the real risks are. A practical, plain-English session with no hard sell.

Save my seat →
Who we are

Lichfield-based managed cyber security, for small businesses up to 100 staff

Cyber security delivered from our Lichfield office to growing businesses across Staffordshire, Birmingham and the West Midlands. We’re a UK-based managed security provider with a real helpdesk team that answers the phone, knows your environment, and closes the gaps before insurers or auditors get there first. Local enough to come on-site when it matters, mature enough to handle Cyber Essentials Plus, Microsoft 365 hardening and incident response without breaking stride.

From our base in Lichfield we work with businesses in Burntwood, Tamworth, Cannock, Sutton Coldfield, Burton-upon-Trent, Walsall, Derby and Birmingham, typically in regulated sectors where cyber controls have to be evidenced and renewed annually.

Cyber Essentials Certified
Microsoft Partner
20+ Years in IT & Cyber
NCSC Cyber Essentials-aligned
UK Helpdesk · Lichfield Office
★★★★★5.0 from 70 Google reviews
What changes

What stronger cyber security gives your business

Managed cyber security for Lichfield and Midlands businesses, MFA to Cyber Essentials.

Managed cyber is not really about tools. It is about the risks that stop keeping leadership awake and the questions that stop being awkward.

Lower risk of avoidable disruption

Reduce the chance of account compromise, ransomware, phishing and data loss causing serious business interruption.

Easier insurance renewals

Have clearer answers and evidence for MFA, backups, device security, patching and incident response, without a frantic scramble the week before renewal.

More confidence with clients and suppliers

Security questionnaires stop being a project of their own when your controls are documented and managed.

Less anxiety for leadership

Cyber risk stops being a vague worry and becomes a managed process with clear responsibilities and quarterly review.

Faster recovery if something goes wrong

Backups, incident response and recovery plans are only useful if they are tested and understood before they are needed.

Evidence you can point at

Cyber Essentials, access controls, MFA rollout, patching schedule and Microsoft 365 security settings, all documented and ready.

Service

What’s included

Endpoint & email defence

Microsoft Defender for Endpoint, advanced email filtering (Mimecast/Barracuda), URL rewriting and attachment sandboxing.

Make stolen passwords less useful to attackers

Multi-factor authentication enforced across all logins. Conditional Access policies tuned to block sign-ins from risky countries and untrusted devices.

Help staff spot risks before they become incidents

Quarterly cyber-security training for the whole team, with simulated phishing campaigns to keep the muscle memory real.

Know when credentials or domains are exposed

Continuous monitoring for your domains and exec credentials appearing in breach data. Alerts before attackers act on what’s leaked.

Turn cyber basics into evidence clients and insurers recognise

We design your environment so Cyber Essentials and Cyber Essentials Plus assessments become a formality. Evidence pack ready when assessors ask.

Know what happens if something does go wrong

Documented runbooks, tested DR procedures, and a senior engineer on-call so a security incident doesn’t become an existential one.

Why it matters

What changes for the business

Sleep at night

Ransomware and breaches become our problem to prevent, not yours to fear. The constant low-level anxiety about a 3am phone call quietly disappears.

Win business faster

Pass supplier and client security questionnaires in a morning, not a fortnight. Your security documentation becomes a sales tool, not a panic trigger.

The layers

How we actually defend a business

Modern cyber security is layered. Any one control on its own can be defeated, but the layers together raise the cost of attack high enough that the attacker moves on to softer targets.

Identity

MFA on every account, conditional access policies that question logins from unusual locations or devices, password manager rolled out to the whole team, and admin privilege limited and monitored. The single biggest security control most businesses are missing.

Endpoint

Modern endpoint protection (Defender for Business or equivalent) on every laptop. Patching automated and validated. Encryption enforced. Lost device remote wipe ready to go. So when someone leaves a laptop on a train, that’s an inconvenience, not a breach.

Email and web

Anti-phishing rules tuned for your business. SPF, DKIM and DMARC configured properly so your email is harder to spoof. Web filtering on managed devices. Most attacks still start with email; we treat the inbox as the front door.

Backup and recovery

Microsoft 365 backups separate from your tenant. Endpoint snapshots. Verified restore tests so we know the backups actually work, not just that they ran. The point of a backup is to recover from one, and we test that quarterly.

Awareness and training

Quarterly phishing simulation, short focused training when people click. Not the boring annual hour-long video. Your team gets sharper at spotting AI-generated phishing, BEC and vishing attempts as the threat landscape evolves.

Detect and respond

Endpoint and identity events monitored 24/7. Out-of-hours alerts get triaged, not parked till morning. If something genuinely off happens, we have an incident response runbook, not improv.

Cyber Essentials

The standard we work to (and help you certify against)

Cyber Essentials is the UK government baseline. It’s the standard insurers, big customers and public-sector tenders increasingly ask for. We get clients certified and renewed annually.

Turn cyber basics into evidence clients and insurers recognise

The five-control baseline: firewalls, secure configuration, user access control, malware protection and patching. We map your environment to each control, fix the gaps, and walk you through the self-assessment. Most certifications take 4 to 6 weeks from kickoff to pass, depending on what we find.

Cyber Essentials Plus

The independently-tested version. An external assessor verifies the controls are actually in place by sampling devices and accounts. More work, more credibility. Often required for MoD, NHS and central government supply-chain contracts.

Beyond Cyber Essentials, we map controls to widely-recognised frameworks like NIST CSF and ISO 27001-aligned controls where the regulatory pressure justifies it (legal, finance, healthcare). We don’t sell certifications you don’t need.

Cyber insurance

What your insurer will ask for, before they pay out

The questions on the form

Cyber insurance proposal forms now run to 60+ questions. MFA on what accounts? Backups how often? Patch lag in days? Privileged access how managed? Endpoint detection and response in place? If the answers don’t line up, premiums spike or cover is refused entirely.

What we do about it

We answer every question for you with evidence. If something on the form is “no” today, we tell you what it would take to make it “yes” before renewal. Several of our clients have had double-digit premium reductions after a clean renewal cycle with us. That alone can pay for the support contract.

When it goes wrong

How we handle a real incident

Most clients never need this. The ones who do are glad we have it.

Containment first

Affected accounts and devices isolated within minutes of detection. We don’t wait for office hours to start the response. The longer an attacker has access, the worse the damage.

Communication runbook

Pre-agreed who calls who, what gets said internally, what gets said externally, when to involve insurers, when to involve the ICO. You’re not making decisions at 2am with no template.

Recovery and forensics

Clean rebuild from verified backups. Forensic snapshot preserved for the insurer and any legal process. Lessons-learned write-up for the board so the same gap doesn’t reappear.

Real customers

What clients say

★★★★★

“Good guys, knowledgeable and responsive. I changed over to Microsoft, largely because it’s safer. Lots of support whilst I learn to navigate the system. With a.i and fraudsters galore, it’s foolhardy not to take IT security seriously to secure your business and your life as a whole.”

Alex P
Alex P
16. November, 2025 · via Google
★★★★★

“Outstanding IT support and security. We’ve been with Initial IT for three years and the service has been exceptional. Andy and the team are always available, proactive and ensure our systems stay secure and running smoothly. Their expertise gives us total peace of mind, and we wouldn’t trust anyone else with our IT.”

Jo Darnley
Jo Darnley
Sharpbooks Ltd · via Google
★★★★★

“I have been thoroughly impressed with the support from Initial IT. From the outset, they have taken the time to understand our business properly and provide IT support that is practical, reliable and easy to deal with. Nothing ever feels overcomplicated.”

Louise Lithgow-Dicker
Louise Lithgow-Dicker
27. January, 2026 · via Google
See cyber projects in detail →
Industries we secure

Regulated sectors where cyber has to be evidenced

Most of our cyber security clients are in regulated professional services where the controls have to be in place, documented and renewed annually for the regulator, the PI insurer, or the next client supplier-vetting form.

Law firms & conveyancers

SRA Standards & Regulations, Lexcel evidence, CQS, conveyancing fraud controls. We support law firms across the Midlands with the cyber baseline their regulator and insurer expect, evidenced and audit-ready.

More for law firms →

Accountants & bookkeepers

ICAEW and ACCA expectations, AML controls, Making Tax Digital, secure handling of client tax and finance data. We get accountancy practices to Cyber Essentials and keep them there, year after year.

More for accountants →

Surveyors, consultancies & professional services

RICS conduct rules, ISO 27001-aligned controls where the supply chain demands them, secure remote working for fee-earners and site-based staff. Whether you’re 10 staff or 100, the security stack scales with you.

Talk to us →

Related

Microsoft 365 security hardening

Ninety percent of Microsoft 365 security value sits in a dozen settings most tenants never enable properly. If your team runs on Microsoft 365 and cyber security is the concern, our M365 consultancy covers the hardening in detail.

Microsoft 365 consultancy & hardening

FAQs

The cyber security questions buyers actually ask us

Direct answers, including pricing, what we monitor out of hours, and where our cover stops. If your question isn’t here, call 01543 524594 or email hello@initialit.co.uk and we’ll answer honestly.

How worried should a small UK business actually be about cyber attacks?

Worried enough to do something, not worried enough to lose sleep. The honest picture: most UK SMB attacks are opportunistic, not targeted. Phishing emails, leaked passwords, weak Microsoft 365 logins. Those are the ways small businesses get hit, and they are all fixable with the basics done well: MFA on everything, properly configured Microsoft 365, awareness training, decent endpoint protection, and tested backups. If you have all five working, you are above the line that attackers move on from.

What is Cyber Essentials and do we actually need it?

Cyber Essentials is the UK government-backed baseline cyber security standard. Five technical controls: firewalls, secure configuration, access control, malware protection, patching. We hold it ourselves. For most UK SMBs you need it if you bid for public-sector work, if your PI insurance or main customers ask for it, or if you handle regulated client data. Even if no one is asking, it is a sensible bar to clear. We take clients through CE certification routinely as part of the engagement. We consider Cyber Essentials the minimum level of cyber security any UK business should have in place. Anything less than that and you are taking unnecessary risks.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is self-assessed: you answer a long questionnaire, we help you get the answers right, IASME issues the certificate. Cyber Essentials Plus is the same five controls but verified by an external assessor who actually tests your systems. Plus is the higher-credibility version. We hold Cyber Essentials. We don’t currently hold Cyber Essentials Plus on Initial IT itself. We take clients through both routinely.

How much should we be spending on cyber security?

Rough industry benchmark for UK SMBs is 1 to 3 percent of turnover on IT and cyber combined, with cyber sitting in the £15 to £25 per person per month range when you split it out. Our Elevate tier is £67/person/month all-in (helpdesk, monitoring, Microsoft tenant management is a separate £100/month per tenant, and security is built in: MFA, conditional access, awareness training, endpoint protection, dark-web monitoring). For most 10-50 person firms that’s the right level. If you are below the line on cyber, the gap usually shows up the first time you fill in an insurance or supplier questionnaire.

If we got hit by ransomware tomorrow, what happens?

Three things happen in parallel. One, we isolate the affected machines from the network within minutes so the spread stops. Two, we pull your latest clean backup and start rebuilding into a fresh environment. Three, we work through what got in (almost always a phished credential or unpatched system) and close the door. Recovery time depends entirely on backups, which is why we test them on every client every month. We have never had a client pay a ransom.

Are our Microsoft 365 files actually backed up?

Probably not the way you think. Microsoft holds your data with their own redundancy, but their retention policies don’t replace a real backup. If someone deletes a file or mailbox, you have a limited window to recover it from the recycle bin. Beyond that, gone. We add a third-party backup of Microsoft 365 (Exchange, SharePoint, OneDrive, Teams) as standard on Elevate and Fortify tiers, with point-in-time restore. If that’s not in place on your current setup, it’s the first thing we’d add.

Do we really need MFA on everything?

Yes. Multi-factor authentication is the single highest-impact control you can put in place. Most breaches we see at SMB level would have been stopped by MFA alone. We enforce it on Microsoft 365, your password manager, any business app that supports it, and admin accounts especially. Text-message MFA is better than nothing but app-based codes or hardware keys are stronger. Yes, your staff will grumble for a week. After that, no one notices.

Are you monitoring our systems 24/7?

Out of hours, our security team monitors everything across our clients. If anything happens they contact Initial IT immediately and we respond. During the working day (Mon to Fri, 9:00 to 17:30) our UK helpdesk is on the phone. That’s not the same as an enterprise SOC with eyes-on-glass 24/7/365, and we tell you that upfront. For most UK SMBs, our cover is the right level. If you genuinely need 24/7 human monitoring, that’s a larger enterprise security spend and we’ll point you in that direction honestly.

What happens if a member of staff clicks a phishing link?

First, the technical defence: Microsoft Defender and our email filtering catch most malicious links before they’re clicked. Second, the awareness layer: regular phishing simulations and short training videos mean staff are less likely to click in the first place. Third, the safety net: if a credential is phished, MFA blocks the login attempt, dark-web monitoring alerts us within hours, and we force a password reset. Tell us when it happens, don’t hide it. We’ve never blamed a member of staff for clicking, only for not telling us.

Will our cyber insurance still pay out if something goes wrong?

Only if you have done what the insurance application said you were doing. The biggest reason cyber claims get refused: the firm said they had MFA on everything when they only had it on some accounts. Or they said backups were tested when they hadn’t been tested in a year. We help you fill in the insurance application accurately and make sure the technical reality matches what you’ve declared. If your insurance has come up for renewal and they’re asking new questions, send us the questionnaire and we’ll work through it together.

Are home workers a security risk?

Not if you set them up properly. The bigger risk is staff using their own personal laptop or phone with no MFA, no encryption, and the family’s data mixed in with client files. We deploy your security baseline (MFA, encryption, endpoint protection, conditional access) to every device that accesses company data, whether it’s at the office, at home, or on a beach in Croatia. Conditional access policies let us block sign-ins from risky countries or untrusted devices automatically.

Should we upgrade Microsoft 365 to Business Premium for the security tools?

Often, yes. Microsoft 365 Business Premium includes Defender for Endpoint, Defender for Office, Intune device management, and the conditional access engine. For most SMBs it pays for itself just on the cyber controls you’d otherwise buy as add-ons. If you’re on Business Standard, we usually find the Premium upgrade is cost-neutral once you cancel the third-party tools it replaces. We’ll do the maths on your tenant before we recommend it.

Do you support solicitors, accountants, or surveyors with their regulator’s cyber requirements?

Yes. Professional services is most of our client base. We understand SRA Standards and Lexcel evidence requirements, ICAEW and ACCA expectations, RICS conduct rules, and the cyber commitments PI insurers ask for at renewal. We can sign a DPA and an NDA before any sales conversation. We can also fill in customer or regulator cyber questionnaires on your behalf as part of the engagement.

Can you fill in our customer’s cyber security questionnaire on our behalf?

Yes. We do this regularly. Most of the questionnaires (your customer’s procurement form, an insurance application, a Cyber Essentials renewal, a new supplier vetting form) ask the same 80 percent of questions, so once we know your environment well, we can complete them quickly. On Elevate and Fortify tiers this is included. On Foundations it’s billable as a small project.

What are the most common ways small UK businesses get hacked?

In rough order: phished Microsoft 365 credentials, weak or reused passwords, unpatched software, malicious email attachments, and old admin accounts that were never disabled when someone left. Almost every breach we have helped a new client recover from started with one of those five. Fixing them is not exotic, it is just basic discipline applied consistently. Which is exactly what a good managed IT and cyber service does.

Have any of your clients ever been hacked?

Yes, before they were our clients. Most of our security work starts with a firm who has just had a phishing incident, a near-miss on ransomware, or an insurance renewal that turned awkward. Since onboarding, we have not had a client suffer a successful ransomware encryption event. We have had phishing attempts blocked, accounts compromised and recovered quickly, and a couple of supply-chain near-misses spotted by our monitoring. We will tell you honestly what our incident history looks like on the call.

30-min IT review

Book your 30-minute IT & cyber review

30 focused minutes with Andy or one of our senior engineers. We’ll review your current setup, the gaps that would worry an insurer or auditor, and the highest-impact moves for your business in the next 90 days.

Prefer to talk now? Call 01543 524594 or email hello@initialit.co.uk.

Accredited & award-winning

Cyber Essentials Certified Industry award winner 2025 Industry award - Initial IT Industry award winner Global Recognition Awards 2025 FSB Federation of Small Businesses Member Lichfield & Tamworth Chamber of Commerce Member

Regulated industries we protect

Law Firms Financial Services Accountants Healthcare

Last reviewed: May 2026. Initial IT reviews this page monthly to keep guidance current with UK cyber threats, NCSC advisories, and Cyber Essentials scheme changes.