Straight answers for business owners

Small business cyber security questions.

Understand what the services do, how a business protection plan is scoped and where technical protection ends and governance or certification begins.

What does 39Security do?

39Security designs, deploys and manages cyber security controls for established small businesses. Core services include Microsoft 365 backup, email filtering, MDR and EDR, managed firewalls, awareness training, vulnerability management, incident-response planning and standards readiness support.

Who are the packages designed for?

The packages are primarily designed for organisations with roughly 10–50 users and turnover around £750,000–£5 million. Scope can be adjusted for smaller teams, multi-site businesses and organisations with higher regulatory or client requirements.

How do I start a cyber security service?

Choose the protection outcome closest to your needs, build an initial business security plan and provide the organisation details required for onboarding. 39Security confirms the technical scope, responsibilities and any hardware before activation, with secure hosted payment available for agreed services.

Does Microsoft 365 include a complete independent backup?

Microsoft 365 provides resilient cloud services and retention features, but many businesses also require an independent backup with separate retention, granular recovery and managed restore testing. The correct design depends on legal, operational and recovery requirements.

What is the difference between EDR and MDR?

EDR is endpoint detection and response technology installed on managed devices. MDR adds people and process: security analysts investigate alerts, assess risk, contain threats where authorised and escalate incidents through an agreed response route.

Does 39Security issue ISO certificates?

No. 39Security provides readiness, implementation and evidence support for ISO/IEC 20000-1, ISO/IEC 27001 and ISO/IEC 42001. An independent accredited certification body performs the certification audit and issues any certificate.

Which areas does 39Security cover?

The main service area is Essex, Kent, Hertfordshire and London, with remote managed services available more widely across the United Kingdom. On-site requirements are agreed as part of the service scope.

Can 39Security work alongside our existing IT provider?

Yes. 39Security can add specialist security monitoring, backup, firewall, vulnerability and incident-response capability while the existing provider continues normal IT support. Responsibilities and escalation routes are documented during onboarding.

What does the free cyber security assessment cover?

The assessment reviews Microsoft 365, identity, endpoints, email, backups, firewalls, staff awareness, vulnerability management and incident response. It provides an immediate risk band and prioritised next actions.

What happens during a cyber incident?

The response depends on the retained service and agreed authority. Typical actions include triage, evidence preservation, account or endpoint containment, recovery coordination, stakeholder communication and a post-incident review. Emergency response is not guaranteed unless a suitable agreement is already in place.

Get a specific answer

Start with your current environment.

Use the five-minute assessment or speak to 39Security about Microsoft 365, endpoints, backup, email, firewalls or compliance readiness.

Start the assessment
Detailed cyber security guides

Answers for the decisions businesses are making now.

Go deeper into email security, Microsoft 365, ransomware, BYOD, AI governance and practical business policies.

Email security

SPF, DKIM, DMARC, BIMI, blocklists, spoofing and suspicious-domain checks.

Read the guide →

Small-business checklist

A practical leadership checklist for accounts, devices, email, backup and incident readiness.

Read the guide →

Microsoft 365 security

Identity, administrators, email, devices, monitoring and recovery.

Read the guide →

Clicked a phishing link?

What to do after a click, credential entry, MFA approval or malicious download.

Read the guide →

Ransomware

Preparation, isolation, backups, recovery and incident response.

Read the guide →

BYOD, GDPR & ICO

30 detailed questions about personal devices, privacy, security and data protection.

Read the guide →

BYOD policy template

Free editable BYOD policy plus a 30-point personal-device approval checklist.

Read the guide →

Company AI policy

30 AI governance questions plus an editable AI Usage Policy Template.

Read the guide →

Free policy templates

AI, BYOD, social media and internet usage templates for UK businesses.

Read the guide →

Cyber security costs

How to set priorities and budget for a small-business security programme.

Read the guide →