How worried should a small UK business actually be about cyber attacks?
Worried enough to do something, not worried enough to lose sleep. The honest picture: most UK SMB attacks are opportunistic, not targeted. Phishing emails, leaked passwords, weak Microsoft 365 logins. Those are the ways small businesses get hit, and they are all fixable with the basics done well: MFA on everything, properly configured Microsoft 365, awareness training, decent endpoint protection, and tested backups. If you have all five working, you are above the line that attackers move on from.
What is Cyber Essentials and do we actually need it?
Cyber Essentials is the UK government-backed baseline cyber security standard. Five technical controls: firewalls, secure configuration, access control, malware protection, patching. We hold it ourselves. For most UK SMBs you need it if you bid for public-sector work, if your PI insurance or main customers ask for it, or if you handle regulated client data. Even if no one is asking, it is a sensible bar to clear. We take clients through CE certification routinely as part of the engagement. We consider Cyber Essentials the minimum level of cyber security any UK business should have in place. Anything less than that and you are taking unnecessary risks.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is self-assessed: you answer a long questionnaire, we help you get the answers right, IASME issues the certificate. Cyber Essentials Plus is the same five controls but verified by an external assessor who actually tests your systems. Plus is the higher-credibility version. We hold Cyber Essentials. We don’t currently hold Cyber Essentials Plus on Initial IT itself. We take clients through both routinely.
How much should we be spending on cyber security?
Rough industry benchmark for UK SMBs is 1 to 3 percent of turnover on IT and cyber combined, with cyber sitting in the £15 to £25 per person per month range when you split it out. Our Elevate tier is £67/person/month all-in (helpdesk, monitoring, Microsoft tenant management is a separate £100/month per tenant, and security is built in: MFA, conditional access, awareness training, endpoint protection, dark-web monitoring). For most 10-50 person firms that’s the right level. If you are below the line on cyber, the gap usually shows up the first time you fill in an insurance or supplier questionnaire.
If we got hit by ransomware tomorrow, what happens?
Three things happen in parallel. One, we isolate the affected machines from the network within minutes so the spread stops. Two, we pull your latest clean backup and start rebuilding into a fresh environment. Three, we work through what got in (almost always a phished credential or unpatched system) and close the door. Recovery time depends entirely on backups, which is why we test them on every client every month. We have never had a client pay a ransom.
Are our Microsoft 365 files actually backed up?
Probably not the way you think. Microsoft holds your data with their own redundancy, but their retention policies don’t replace a real backup. If someone deletes a file or mailbox, you have a limited window to recover it from the recycle bin. Beyond that, gone. We add a third-party backup of Microsoft 365 (Exchange, SharePoint, OneDrive, Teams) as standard on Elevate and Fortify tiers, with point-in-time restore. If that’s not in place on your current setup, it’s the first thing we’d add.
Do we really need MFA on everything?
Yes. Multi-factor authentication is the single highest-impact control you can put in place. Most breaches we see at SMB level would have been stopped by MFA alone. We enforce it on Microsoft 365, your password manager, any business app that supports it, and admin accounts especially. Text-message MFA is better than nothing but app-based codes or hardware keys are stronger. Yes, your staff will grumble for a week. After that, no one notices.
Are you monitoring our systems 24/7?
Out of hours, our security team monitors everything across our clients. If anything happens they contact Initial IT immediately and we respond. During the working day (Mon to Fri, 9:00 to 17:30) our UK helpdesk is on the phone. That’s not the same as an enterprise SOC with eyes-on-glass 24/7/365, and we tell you that upfront. For most UK SMBs, our cover is the right level. If you genuinely need 24/7 human monitoring, that’s a larger enterprise security spend and we’ll point you in that direction honestly.
What happens if a member of staff clicks a phishing link?
First, the technical defence: Microsoft Defender and our email filtering catch most malicious links before they’re clicked. Second, the awareness layer: regular phishing simulations and short training videos mean staff are less likely to click in the first place. Third, the safety net: if a credential is phished, MFA blocks the login attempt, dark-web monitoring alerts us within hours, and we force a password reset. Tell us when it happens, don’t hide it. We’ve never blamed a member of staff for clicking, only for not telling us.
Will our cyber insurance still pay out if something goes wrong?
Only if you have done what the insurance application said you were doing. The biggest reason cyber claims get refused: the firm said they had MFA on everything when they only had it on some accounts. Or they said backups were tested when they hadn’t been tested in a year. We help you fill in the insurance application accurately and make sure the technical reality matches what you’ve declared. If your insurance has come up for renewal and they’re asking new questions, send us the questionnaire and we’ll work through it together.
Are home workers a security risk?
Not if you set them up properly. The bigger risk is staff using their own personal laptop or phone with no MFA, no encryption, and the family’s data mixed in with client files. We deploy your security baseline (MFA, encryption, endpoint protection, conditional access) to every device that accesses company data, whether it’s at the office, at home, or on a beach in Croatia. Conditional access policies let us block sign-ins from risky countries or untrusted devices automatically.
Should we upgrade Microsoft 365 to Business Premium for the security tools?
Often, yes. Microsoft 365 Business Premium includes Defender for Endpoint, Defender for Office, Intune device management, and the conditional access engine. For most SMBs it pays for itself just on the cyber controls you’d otherwise buy as add-ons. If you’re on Business Standard, we usually find the Premium upgrade is cost-neutral once you cancel the third-party tools it replaces. We’ll do the maths on your tenant before we recommend it.
Do you support solicitors, accountants, or surveyors with their regulator’s cyber requirements?
Yes. Professional services is most of our client base. We understand SRA Standards and Lexcel evidence requirements, ICAEW and ACCA expectations, RICS conduct rules, and the cyber commitments PI insurers ask for at renewal. We can sign a DPA and an NDA before any sales conversation. We can also fill in customer or regulator cyber questionnaires on your behalf as part of the engagement.
Can you fill in our customer’s cyber security questionnaire on our behalf?
Yes. We do this regularly. Most of the questionnaires (your customer’s procurement form, an insurance application, a Cyber Essentials renewal, a new supplier vetting form) ask the same 80 percent of questions, so once we know your environment well, we can complete them quickly. On Elevate and Fortify tiers this is included. On Foundations it’s billable as a small project.
What are the most common ways small UK businesses get hacked?
In rough order: phished Microsoft 365 credentials, weak or reused passwords, unpatched software, malicious email attachments, and old admin accounts that were never disabled when someone left. Almost every breach we have helped a new client recover from started with one of those five. Fixing them is not exotic, it is just basic discipline applied consistently. Which is exactly what a good managed IT and cyber service does.
Have any of your clients ever been hacked?
Yes, before they were our clients. Most of our security work starts with a firm who has just had a phishing incident, a near-miss on ransomware, or an insurance renewal that turned awkward. Since onboarding, we have not had a client suffer a successful ransomware encryption event. We have had phishing attempts blocked, accounts compromised and recovered quickly, and a couple of supply-chain near-misses spotted by our monitoring. We will tell you honestly what our incident history looks like on the call.