A 30-Day Cyber Security Action Plan for Small Businesses
A practical four-week improvement plan that turns the mini-course into measurable cyber security actions for a small business.
Read insight →Clear advice for business owners and managers who need to make sensible security decisions without becoming security engineers.
A practical four-week improvement plan that turns the mini-course into measurable cyber security actions for a small business.
Read insight →How small businesses can prepare for cyber incidents, report problems quickly, contain damage and maintain a clear decision log.
Read insight →The essential controls small businesses should use to protect Microsoft 365, email and other cloud services from account takeover and impersonation.
Read insight →How to control who can access business systems, reduce administrator risk and remove unnecessary access when employees or suppliers leave.
Read insight →A practical guide to business backups, ransomware resilience, restore testing, recovery time and protecting backup administration.
Read insight →Understand the role of antivirus, endpoint detection and response, managed monitoring and firewalls in a layered business security strategy.
Read insight →Why supported software and regular security updates are fundamental cyber security controls for business devices, applications and network equipment.
Read insight →A practical phishing guide covering fake login pages, supplier impersonation, payment fraud, suspicious links and staff reporting.
Read insight →How to reduce account takeover risk with unique passwords, password managers, passkeys and multi-factor authentication.
Read insight →A plain-English introduction to cyber security, the risks small businesses face and the core controls that reduce the chance and impact of an attack.
Read insight →How an SME can prepare for ISO/IEC 27001 by building ownership, risk treatment and evidence into normal business operations.
Read insight →A managed firewall should include design, monitoring, policy ownership, secure remote access, configuration backup and lifecycle management.
Read insight →Layered email security combines filtering, domain protection, user reporting and payment verification to reduce phishing and impersonation risk.
Read insight →EDR provides endpoint detection technology. MDR adds people, investigation and response. Here is how to decide what an established SME needs.
Read insight →Why Microsoft 365 retention, recycle bins and platform resilience do not automatically provide the independent recovery process an SME expects.
Read insight →A practical checklist for established small businesses covering identity, Microsoft 365, backup, endpoints, email, firewalls, people and incident response.
Read insight →