The language around cyber security is intimidating to many small businesses, but in reality “Cyber Essentials” simply reflects the most essential preventative steps towards providing a minimum level of assurance appropriate for almost any organisation. A good IT partner helps to make the basics easy, visible and routine – so you do not have rely on luck.
The first thing you should do is secure ALL the devices that interact with your business data: laptops, phones and office PCs. For instance, that includes currently supported operating systems and automatically patched with high-quality endpoint protection. This can include setting up user accounts correctly so that staff are only given access to the systems they need, and ensuring this is done promptly when an employee leaves.
Protect against common attacks – Your IT support should have email and key systems protected by MFA, password hygiene (using a password manager is ideal) and lower phishing risk with the use of staff awareness seminars plus filtering. Remember, you do not have to conduct long training sessions; just a gentle reminder is likely all that is needed and clear instructions on the steps of reporting. For a Barracuda Partner, visit www.primesys.co.uk/partnerships/barracuda
Network security matters too. They ought to harden your Wi‑Fi, configure firewalls and guarantee distant access is safe. They should harden the settings for you (other than simply “setting up accounts”) if they use cloud toolsets like Microsoft 365 or Google Workspace.
Lastly, they need to prepare for recovery. Regular, proven backups are mandatory as well – ditto for a basic incident response plan; who do you call when things go awry, what can be cut off from the rest of your network to decrease damage/risk and get back up quickly?
If your IT partner cannot verbalise these degrees of protection in plain English, or verify that such measures are implemented then this is a big issue.
