General Security Issues

AI – truly intelligent or over hyped?

I have commented before on the AI discussions that appear periodically on social media and do so with some trepidation because there are so many opinions.  And I must put my hands up and say I am not an expert although I do use AI in my everyday work.  I’m not against it but it must be used intelligently and seen for what it is, not what the hype says it is.  This is particularly true of generative AI, which is the type of AI that is most known about and discussed.  Generative AI is a branch of AI that focuses on creating new content, such as text, images, audio etc, by learning patterns from vast datasets and generating output that resembles human-created work.  Of course, to generate this content, you must define clearly what outcome you are looking for.

Over the years, I’ve seen change happening because of innovation within IT, much of which has forecast the end of the workforce.  It has streamlined many processes and taken a lot of drudgery away.  I’ve been involved in mapping out working practices and designing/implementing management processes using IT.  I’ve seen the development of relational databases and search engines, both of which have done much to increase the speed and access to information that is required.  Is AI doing anything different in the workplace?  Or is it just the next somewhat inevitable step up?

I have to say though, that during the years when I was working with management information systems, whilst they did improve speed and efficiency, they never really achieved the manpower savings they were advertised to do.  One claim about AI, that it will achieve those manpower reductions seem a little excessive, in fact one forecast I read by a CEO was that it would have a devastating effect.  It makes me wonder who is going to buy these wonderful goods that are being so efficiently produced if the unemployment rate is through the roof and no one can afford to buy them?  Just a thought.

But getting back to AI itself, is it truly intelligent?  This is where a lot of misunderstanding and indeed, misinformation, can be found.  What forms of AI are there?  And what forms of AI are available now to business and the public.  There are about 7 categories of AI, not types i.e. marketed under a trade name, but categories.

TypeExists today?Purpose
Narrow AI✅ YesPerforms specific tasks
General AI (AGI)❌ NoHuman-level intelligence across many tasks
Superintelligent AI (ASI)❌ NoExceeds human intelligence
Reactive AI✅ YesNo memory, responds to inputs
Limited Memory AI✅ YesUses past information
Theory of Mind AI❌ NoUnderstands emotions and intentions
Self-Aware AI❌ NoConscious, self-aware intelligence

Categories of AI

As we sit here today, virtually all AI systems, including the most well-known such as ChatGPT, are forms of Narrow AI. They can be highly capable within their domains, but they do not possess human-like general intelligence or consciousness.  Narrow AI (and yes, I did use it to create the graphic above), is characterised by:

  • Designed for specific tasks.
  • Cannot think generally outside its training or purpose.
  • Examples:
    • ChatGPT
    • Siri and Alexa
    • Google Translate
    • Image generators
    • Recommendation systems (Netflix, Spotify)
    • Etc

I have said that I use AI, but I struggle to think of it as intelligent, but I do recognise that it is all about how you define that intelligence.  I use it mostly in my managed service, to monitor clients’ systems and keep them as safe as is possible.  Prior to moving into the SME space, I worked for some major clients, both public and private sectors and built several security operations centres.  Back then most of these were centred on SIEM systems, which used correlation engines to correlate the results gathered from several other systems, such as anti-malware, firewalls, intrusion detection systems etc.  The system would then produce results, and those results would be viewed by an analyst before pronouncing them real or a false positive, or whatever.  That was always way too expensive for an SME.  Using AI systems, that cost has now been reduced to a price point that can be attractive to an SME.  So, this is one feature where AI can be of great benefit and is proving itself way more efficient than the correlation engines of old.  Of course, this isn’t the only difference, but it is the one we’re talking about today.

One type of AI that we didn’t qualify above was what is known as Agentic AI.  This is not a separate category but rather a description of how an AI behaves, rather than how capable it is.  For example, whereas many systems that fit within Narrow AI, do so because they are designed for specific tasks.  Agentic AI can plan and achieve a goal, providing it has the right information and instructions to act upon.  This enables it to undertake research for example, so when it finds what it thinks is an issue, it can research that to produce a more definitive answer to an analyst to review.  It might learn enough so that you will trust it with low level alerts and decisions, on its own.  Whether you think that that is intelligence or not, I will leave to you.

Agentic AI allows us to use a layered model embedded in an application which we can use to support SMEs at a reasonable price point.  That layered model includes:

  • Behavioural AI/ML → detects attacks.
  • Correlation engine → connects events across identities, endpoints, email, and cloud.
  • LLMs → explain incidents and assist administrators.
  • Human MDR analysts → validate and respond to serious threats.

Briefly:

Identity-based threat detection

Rather than looking at devices in isolation, we use a system which correlates activity around people (identities).

It continuously analyses signals from:

  • Microsoft 365 or Google Workspace accounts
  • Endpoints (Windows/macOS)
  • Email
  • Cloud storage
  • Dark web monitoring
  • External attack surface

The AI combines these signals to identify suspicious patterns, such as:

  • Impossible travel logins
  • Unusual login times
  • MFA changes
  • Credential leaks
  • Suspicious file access

Instead of generating dozens of alerts, it attempts to determine whether these events are part of the same attack.

Machine learning for detection

Machine learning is used to:

  • Learn normal user behaviour
  • Detect anomalies
  • Reduce false positives
  • Prioritise high-risk incidents

Generative AI (LLMs)

The system also uses large language models for tasks such as:

  • Summarising complex security incidents
  • Explaining alerts in plain English
  • Helping administrators understand why something was flagged
  • Generating phishing simulation emails for employee training

This is different from the AI used to detect threats, it’s focused on making security information easier to understand and act on.

Automated response

When the AI determines an attack is likely, it can recommend or automate actions such as:

  • Disabling compromised accounts
  • Isolating infected endpoints
  • Blocking phishing emails
  • Forcing password resets
  • Escalating incidents to a human analyst

The platform combines AI-driven automation with human security analysts for higher-confidence incidents.

So back to where I started before I got carried away.  Is AI truly intelligent?  I have my opinion which I hope came through here, but I leave you to make up your own mind.  One thing though is for sure, AI is here to stay, and it will continue to get developed and will get better, or worse, depending upon your point of view.

CYBER SECURITY IS COMMON SENSE, ISN’T IT?

Well, yes and no.  Whilst cybersecurity is often described as “common sense,” that statement is only partly true. Common sense does help avoid some online threats, but modern cybersecurity also requires awareness of evolving risks, organisational safeguards and some technical knowledge. Cybersecurity is best understood as a combination of common sense, education, and technology.  Or as we in cybersecurity, like to say, ‘People, Process and Technology.

On one hand, many cybersecurity practices are based on common-sense principles. People are advised not to share passwords, not to click on suspicious links, and to be cautious when receiving unexpected emails or messages. These actions are like everyday safety habits, such as locking doors or being careful when speaking to strangers. As is shows in the graphic above, you don’t go out in the morning, locking your doors, but leaving your windows open.  In cyber the use of strong passwords, enabling multi-factor authentication, and keeping software up to date are practical measures that reduce the likelihood of cyberattacks.

However, cybersecurity extends far beyond everyday judgment. Cybercriminals use sophisticated techniques such as phishing, ransomware, malware, and social engineering that can deceive even experienced users. Attackers often create convincing fake websites, emails, or phone calls that appear legitimate. As technology evolves, new vulnerabilities emerge that are not obvious to the average person. Without proper training, users may not recognise these threats, regardless of how cautious they are.

In addition, organisations cannot rely solely on employees’ common sense to protect their systems. Small to medium businesses need to implement security policies, use firewalls, anti-malware as a minimum, whilst considering encryption, intrusion detection systems, and regular security audits to defend against attacks. Employees should also be receiving regular cybersecurity awareness training to help them identify threats and respond appropriately. These technical and organisational measures complement individual responsibility.

Another reason cybersecurity is not simply common sense is that many attacks exploit software vulnerabilities rather than human mistakes. Even careful users can become victims if systems are not patched or if security controls are inadequate. This highlights the importance of skilled cybersecurity professionals who continuously monitor networks, manage risks, and respond to incidents.  The issue here is that many SMEs simply don’t have the knowledge to fully understand what is, and what is not, happening on their systems.

I going to show some examples now, not to showcase my managed service so much, but to demonstrate what most people simply don’t think about.  I could have chosen any of a dozen or so, but I’ve alighted on these.  In the example below, we are showing client services that are exposed to the internet.  This is something that an SME simply wouldn’t know about or perhaps understand the significance.

Figure 1 – Issue Types

What this shows is the varied types of issues that can arise and that need constant monitoring to stay on top of. These types of issues tend to fly under the radar of most SMEs, and for that matter many bigger companies, and can be exploited by hackers and scammers, with the aim of stealing your hard earned cash.

This next example shows an account compromise as it occurs. Most organisations will not know this is happening until it’s too late. If you can get an early heads up then you stand a chance of stopping it from occurring. All the common sense in the world won’t help you detect a breach as it’s happening, that takes monitoring or an absolute ton of luck.

Figure 1 – Potential account compromise

What we’ve seen here are just two examples of where common sense will only take you so far.  It’s a horrible expression, but you really don’t know what you don’t know.

In conclusion, cybersecurity involves an element of common sense, particularly in practicing safe online behaviour.  However, common sense alone is insufficient in today’s complex digital environment. Effective cybersecurity depends on a combination of informed users, ongoing education, robust technology, and well-designed security policies. Only by integrating these elements can individuals and organisations effectively protect themselves against increasingly sophisticated cyber threats.

We’d be happy to provide more information via a demonstration of our managed capability, including the offer of a fully functional and totally free 14-day trial.

HOW CAN SMEs MONITOR COMPLIANCE TO CYBER ESSENTIALS EASILY

I put up a post earlier this week about cyber essentials, how effective it is and how it should be viewed.  There have been some interesting posts recently on this subject and the main argument was that it should be viewed as a base line standard, not a total panacea. Adherence to it provides a good platform on which to stand your protections and provides a basic understanding of the issues involved, which many SMEs don’t fully grasp.

Cyber threats don’t just target enterprises anymore and SMEs are increasingly in the crosshairs, often without the resources to defend themselves effectively.  But it remains important to keep in mind that for many UK SMEs, cybersecurity is no longer just about protection, it’s about winning business. It’s important to think in terms of simplicity rather than complexity.  Cyber security doesn’t have to be complicated or expensive.

My post talked about what happens after a company has achieved compliance to CE? The requirement now is to certify that they will maintain that compliance throughout the 12-month period of the certification. That is why H2 has researched a service that can be provided to SMEs at a reasonable cost, that helps simplify that journey by providing an all-in-one cybersecurity platform with continuous monitoring aligned to Cyber Essentials requirements. It helps identify security gaps, strengthen your cyber posture, and keep your business on track for compliance, while protecting your users, devices, email, and cloud environment.

We did think however that perhaps a more detailed view might be worth publishing, and here it is.

NCSC has published v3.3 (Danzell) requirements effective from April 2026, which further tighten areas such as MFA and cloud-service requirements. Organisations that have only just adapted to last years changes (Willow) should already be reviewing the next revision to avoid another compliance scramble when renewal comes around. 

What changed in the Danzell question set?

The five Cyber Essentials control areas remain the same:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Security Update Management

However, Danzell asks more detailed and specific questions about how these controls are implemented and evidenced. 

Key themes covered by the Danzell questions

Multi-Factor Authentication (MFA)

The questionnaire now requires organisations to identify all cloud services in use and confirm MFA is enabled where available. Missing MFA on supported cloud services can result in an automatic failure. 

Typical questions include:

  • What cloud services are used?
  • Is MFA enabled for all users?
  • Are administrator accounts protected by MFA?
  • What authentication methods are used?

Cloud Service Scope

Danzell explicitly brings cloud services into scope, including:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Slack
  • Zoom
  • Cloud storage platforms

Organisations must declare these services and demonstrate appropriate security controls. 

Typical questions include:

  • Which cloud services store or process business data?
  • How are accounts managed?
  • How is access removed when users leave?

User Access Control

The questionnaire places greater emphasis on:

  • Administrative accounts
  • Privileged access management
  • Account lifecycle management

Typically, questions include:

  • Are administrator accounts separate from standard user accounts?
  • How are privileged accounts controlled?
  • How are unused accounts identified and removed?

Industry discussions indicate auditors are applying the separate-admin-account requirement strictly. 

Security Update Management

Danzell asks for clearer evidence regarding:

  • Operating system patching
  • Application patching
  • Firmware updates
  • Patch deployment timescales

Applicants need to be able to identify:

  • How are vulnerabilities identified?
  • Are high-risk vulnerabilities patched within 14 days?
  • How is firmware kept up to date?

The 14-day patching requirement is now a critical assessment point. 

Password and Authentication Controls

Questions now focus on:

  • Minimum password length
  • Password managers
  • Common-password blocking
  • Password less technologies and passkeys when used

Cyber Essentials v3.3 introduced a minimum 12-character password requirement in many scenarios. 

The effects of these changes will differ from company to company of course, many will already have much of this covered and some won’t.  Many will require guidance and assistance in making sure that they are prepared to what is now required, and that guidance will need to focus on how they need to change to meet the requirement.

But arguably the biggest operational issue is that CE now requires Owners/CEOs/Boards to certify that they will maintain the standard through its 12-month lifecycle, and not just at the point of certification.  That means monitoring their estate to maintain compliance, constantly, which in turn means having the means and resource to do it.  Not easy for many SMEs and they will be worried about cost.

The obvious answer though is a managed service.  SMEs often outsource their IT environment and see benefits in terms of cost and operational efficiency.  The same can be said for Cyber Security and monitoring, but the mindset tends to be different.  There is still the thought that their IT outsourcing company has this covered, or that cyber is a bit of black art and it will be expensive.

How does the H2 Service Help?

So, what does this service do that is so special?  Well, it will audit the 5 Cyber Essentials control areas, in some detail but it goes further.  Managing cyber security internally is a challenge.   With one out of two SMEs experiencing attacks, it’s clear that modern security requires continuous attention, as does cyber essentials compliance.  Threats can change daily and software needs continual updates.  Users need protection without friction and policies need to be enforced consistently.  Alerts need to be monitored, recognised and acted upon in real time.

Trying to manage all this internally means adding complexity, workload and risk.  Security should not compete with running a business and that is where a managed services makes a difference; by taking full operational ownership of cybersecurity, not just offering advice or tools.

Example of Multi Factor Authentication Detection

The service manages:

  1. Protecting user accounts and access, identifying who has admin privilege so that it can be revoked where it isn’t needed.
  2. Secure end points and devices, identifies operating system versions, anti-malware configurations, updates and alerts.
  3. Enforces security policies.
  4. Identifies cloud configurations and connections.
  5. Reduces risk from 3rd parties and shadow IT apps, identifying where 2FA is missing.
  6. Monitors threats and suspicious activity.
  7. It can monitor email boxes looking for phishing and ransomware, although that element is not strictly necessary for CE compliance.
Example of a client dashboard
Example of Cloud Share Data Detection

An added bonus is that it comes with phishing simulations to help train staff, and a comprehensive, automated, cyber awareness training package.

The system is powered by Agentic AI, although it has a human element, with the AI taking away the number crunching and hard work, leaving the human to identify what is, and what is not, real.  Using AI in this way enables us to keep the costs low, something very important to SMEs.

Small to Medium Businesses – Scammed or Hacked?

This is something that I’ve alluded to in the past, in other articles and blogs.  What is the likelihood of an SME suffering and Scam as opposed to a more technical hack.  There is a lot of evidence to suggest that, for most SMEs, the probability of suffering a scam/social engineering attack is significantly higher than experiencing a sophisticated technical hacking attack.

A useful rule of thumb from cyber insurance claims, law enforcement reporting, and incident response firms is:

  • 70–90% of financially damaging incidents affecting SMEs involve people being manipulated (phishing, invoice fraud, CEO fraud, business email compromise, fake suppliers, fake tech support, payment diversion, etc.).
  • 10–30% involve primarily technical exploitation (ransomware through unpatched systems, web application attacks, malware exploiting vulnerabilities, credential stuffing, etc.). 

But you can argue that ransomware is often a hybrid of the two, starting often with phishing for credentials, obtaining a login, and then inserting malware.

The exact percentages vary by industry and geography, but the pattern is remarkably consistent.

Why scams are more common

  1. Humans are easier to compromise than systems

A criminal can send 10,000 phishing emails in minutes at almost no cost.

Convincing one employee to:

  • Click a link
  • Approve a payment
  • Share credentials
  • Change bank account details

is often easier than discovering and exploiting a software vulnerability.

  •  SMEs usually have weaker business processes than technology

Many SMEs now use cloud services from companies like Microsoft⁠, Google Workspace⁠, and  Amazon Web Services⁠, which has improved their security.

However, they often lack:

  • Payment verification procedures
  • Supplier validation processes
  • Security awareness training
  • Segregation of financial duties
  • Generally inadequate security policies

      Criminals exploit these business-process weaknesses.

  • Criminals follow the money

A fake invoice scam may generate £20,000–£100,000 with little technical effort, whereas a sophisticated network intrusion might require:

  • Research
  • Malware development
  • Vulnerability exploitation
  • Persistence mechanisms

From an attacker’s perspective, scams often provide a better return on      investment.

  • Business Email Compromise (BEC) is extremely effective

One of the largest causes of SME losses is BEC:

  • Attacker gains access to an email account (often through phishing)
  • Watches conversations
  • Sends realistic payment instructions
  • Diverts funds

Technically, the breach may be simple, but the financial loss comes from deception rather than hacking.

Why technical attacks still matter

Technical attacks tend to receive more media attention because they can be highly disruptive.

Some examples are:

  • Ransomware
  • Server compromise
  • Website defacement
  • Data theft
  • Supply-chain attacks

Although less frequent than scams, a successful technical attack can have larger operational consequences:

  • Business downtime
  • Regulatory penalties
  • Customer notification costs
  • Recovery expenses

What an SME should prioritise

Most, if not all SMEs, will have a limited security budget, and therefore they need to identify the highest-return controls to mitigate their risk. These can include:

  • Multi-factor authentication (MFA) on all email and cloud accounts.
  • Staff training on phishing and payment fraud.
  • Verification procedures for bank account changes and large payments.
  • Strong backups and ransomware recovery testing.
  • Endpoint protection and automatic patching.
  • Monitoring for suspicious login activity.

These measures reduce both scam risk and many technical attack paths.  It’s aways worth remembering that scammers and hacker alike will take the path of least resistance.  The more difficult you make it for them, the more likely they are to look elsewhere.

A practical estimate

For a typical 20–250 person SME and for illustrative purposes, the distribution of financially damaging incidents based on common industry observations is 80 to 20 in favour of scams.

This is not a universal statistic, but it reflects what many cyber insurers, incident responders, and fraud investigators observe in practice, that is that SMEs are generally more likely to lose money because someone was tricked than because a hacker defeated sophisticated technical defences. The most damaging incidents often combine both, such as a phishing email that steals credentials and then enables fraud or ransomware.

Cyber Essentials – How has it changed?

I think these days, pretty much everyone is aware of the UK government-backed Cyber Essentials scheme and those who have undertaken certification or are considering it, will, in the last 12 months, have been subject to the introduction of the “Willow” question set (v3.2), which became the standard for certifications from 28 April 2025. It didn’t fundamentally change the five Cyber Essentials controls, but it did make several requirements more explicit and raised expectations around asset management, authentication, remote working, and vulnerability remediation. 

For most organisations, the Willow update was not a complete overhaul. The real shift is that Cyber Essentials is becoming:

  • More focused on asset visibility
  • More aligned with modern cloud environments
  • More accepting of passwordless security
  • More rigorous about vulnerability management
  • More realistic about hybrid and remote working

If your organisation already has mature inventory management, MFA, vulnerability remediation, and cloud governance processes, the changes are relatively straightforward. If not, these areas are where most compliance effort will now be concentrated. 

Key implications for organisations

Asset management is now much harder to ignore

A significant practical change was a stronger emphasis on maintaining a complete inventory of:

  • Devices
  • Software
  • Cloud services
  • Network equipment
  • BYOD assets used for work

Organisations now need a much better visibility of what is connected to their environment. For many SMEs, this means formalising asset registers rather than relying on informal spreadsheets or staff knowledge. 

The Implication being that certification becomes more difficult if you cannot prove what systems are in scope. This may mean investing in discovery and asset-management processes.

Firmware is now explicitly in scope

The definition of software has been expanded to include firmware on devices such as:

  • Firewalls
  • Routers
  • Network appliances

Previously, some organisations focused almost entirely on operating systems and applications. Now, neglected network-device firmware can become a compliance issue.  The implication being that patch management programmes need to include infrastructure devices, not just laptops and servers.

“Patches” became broader “vulnerability fixes”

Cyber Essentials no longer focuses only on installing vendor patches.

The new language recognises that vulnerabilities may be fixed through:

  • Configuration changes
  • Registry edits
  • Vendor scripts
  • Other remediation methods

The expectation is that vulnerabilities rated CVSS 7.0+ are addressed regardless of how the vendor delivers the fix.  Again, there is an implication that organisations need a vulnerability-management mindset rather than a simple patching mindset.

Passwordless authentication is now recognised

The Willow update formally acknowledges modern authentication methods such as:

  • Passkeys
  • Biometrics
  • Security keys
  • Authenticator push notifications

These can satisfy MFA requirements where implemented correctly. 

This is good news for organisations moving away from passwords. It aligns Cyber Essentials more closely with modern identity-security strategies and NCSC guidance on passkeys.  Frustratingly though, I worked with a client recently to obtain CE and the assessor didn’t know what a passphrase was and it had to be explained to him.

Remote working is treated more broadly

The terminology changed from “home working” to “home and remote working.”

That sounds minor, but it reflects a wider scope including:

  • Hotels
  • Cafés
  • Shared workspaces
  • Other untrusted networks

I’ve blogged about this quite a bit and security controls need to work wherever employees connect from, not just from a home office.  Does a VPN suffice, maybe but maybe not.

Greater scrutiny of Bring Your Own Device (BYOD)

Now organisations are expected to have:

  • Clear BYOD policies
  • Device security controls
  • User responsibilities documented
  • Appropriate protection such as encryption and screen locking

Informal BYOD arrangements can be riskier from both a compliance and security perspective.

V3.3 (“Danzell”)

As if that wasn’t enough NCSC has published v3.3 (“Danzell”) requirements effective from April 2026, which further tighten areas such as MFA and cloud-service requirements. Organisations that have only just adapted to Willow should already be reviewing the next revision to avoid another compliance scramble next renewal cycle. 

What changed in the Danzell question set?

The five Cyber Essentials control areas remain the same:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Security Update Management

However, Danzell asks more detailed and specific questions about how these controls are implemented and evidenced. 

Key themes covered by the Danzell questions

Multi-Factor Authentication (MFA)

The questionnaire now requires organisations to identify all cloud services in use and confirm MFA is enabled where available. Missing MFA on supported cloud services can result in an automatic failure. 

Typical questions include:

  • What cloud services are used?
  • Is MFA enabled for all users?
  • Are administrator accounts protected by MFA?
  • What authentication methods are used?

Cloud Service Scope

Danzell explicitly brings cloud services into scope, including:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Slack
  • Zoom
  • Cloud storage platforms

Organisations must declare these services and demonstrate appropriate security controls. 

Typical questions include:

  • Which cloud services store or process business data?
  • How are accounts managed?
  • How is access removed when users leave?

User Access Control

The questionnaire places greater emphasis on:

  • Administrative accounts
  • Privileged access management
  • Account lifecycle management

Typically questions include:

  • Are administrator accounts separate from standard user accounts?
  • How are privileged accounts controlled?
  • How are unused accounts identified and removed?

Industry discussions indicate auditors are applying the separate-admin-account requirement strictly. 

Security Update Management

Danzell asks for clearer evidence regarding:

  • Operating system patching
  • Application patching
  • Firmware updates
  • Patch deployment timescales

Applicants need to be able to identify:

  • How are vulnerabilities are identified?
  • Are high-risk vulnerabilities patched within 14 days?
  • How is firmware kept up to date?

The 14-day patching requirement is now a critical assessment point. 

Password and Authentication Controls

Questions now focus on:

  • Minimum password length
  • Password managers
  • Common-password blocking
  • Passwordless technologies and passkeys where used

Cyber Essentials v3.3 introduced a minimum 12-character password requirement in many scenarios. 

Structure of the questionnaire

The Danzell question set generally requires organisations to provide:

  • Asset inventories
  • Cloud service inventories
  • User account information
  • Details of security policies
  • Evidence of patch management processes
  • Details of MFA deployment
  • Administrative account controls

Assessors may ask follow-up questions if answers are unclear or inconsistent. 

What, typically, is the effect on SMEs?

This will change from company to company of course, many will already have much of this covered and some won’t.  Many will require guidance and assistance in making sure that they are prepared to what is now required, and that guidance will need to focus on how they need to change to meet the requirement.

But arguably the biggest operational issue is that CE now requires Owners/CEOs/Boards to certify that they will maintain the standard through its 12-month lifecycle, and not just at the point of certification.  That means monitoring their estate to maintain compliance, constantly, which in turn means having the means and resource to do it.  Not easy for many SMEs and they will be worried about cost.

The obvious answer though is a managed service.  SMEs often outsource their IT environment and see benefits in terms of cost and operational efficiency.  The same can be said for Cyber Security and monitoring, but the mindset tends to be different.  There is still the thought that their IT outsourcing company has this covered, or that cyber is a bit of black art and it will be expensive.

Let’s face it, the majority of SMEs aren’t going to try and hire cyber expertise full time, it would be expensive and unnecessary.  Having a managed service spreads cost and makes it affordable.  If you have a service that offers:

  • Continuous monitoring of endpoints, servers, and some cloud environments
  • Monitoring patching, including CVEs issued by vendors and comparing them against your estate
  • Vulnerability assessment
  • Rapid detection of ransomware, malware, insider threats, and advanced attacks
  • Expert-led response
  • Phishing simulations
  • Cyber awareness training programme
  • Dark web monitoring

Then you are a long way towards meeting the requirement for continuous monitoring and assessment, and if you can do this for £15-£18 per user per month, then it can be very affordable.

Stop Treating Cyber Security as an Overhead – Calculate the Cost of Doing Nothing

Cyber security is often seen as a cost centre, not a value driver.  That’s not just a problem for SMEs but that attitude is still often sound at a corporate level.  Within SMEs it’s not too rate to find it positioned as an insurance or compliance spend, not as something that enables trust, customer retention or business continuity.  Often there is no ownership at the top, no board pressure until something goes wrong.  If no one owns the risk, it stays floating below the surface.

We need to flip the mindset.  Cyber security needs to feel like it’s part of the core business and should be framed as:

  • Protecting revenue not systems.
  • Protecting customers not servers.
  • Protecting the ability to operate.

Cyber incidents must be seen as business stopping events, not just technical inconveniences.  Once that is recognised at the top, it tends to be moved into core business territory very quickly.

Measuring ROI (Return on Investment) in cyber security solutions is tricky because unlike traditional investments, the “return” often comes in the form of avoided losses, reduced risk, and improved resilience rather than direct revenue, and is often seen as proving a negative which produces a circular argument.  In the blue corner we have the bean counters saying we don’t need to spend much because we’ve never been attacked, and in the red corner we have the techies telling management that you haven’t been attacked because we have spent on protections.  There is often no meeting of minds until we frame it in business terms. There are well-established approaches.

Here’s how ROI in cybersecurity is typically measured:

Define the Investment (Costs)

This includes all direct and indirect costs of the cybersecurity solution:

  • Technology costs: licenses, hardware, software, cloud services.
  • Implementation costs: setup, integration, migration.
  • Operational costs: monitoring, maintenance, upgrades.
  • Personnel costs: training, staff time, additional headcount.
  • Third-party services: managed security providers, audits, compliance checks.

Estimate the Return (Benefits)

Returns are usually risk reductions and operational gains, such as:

  • Avoided breach costs:
    • Average cost of a data breach (detection, remediation, legal fees, fines, customer churn, downtime).
    • Likelihood (probability) of an attack succeeding without the solution.
  • Operational efficiency:
    • Fewer false positives, reduced downtime, less staff time spent on manual tasks.
  • Regulatory compliance:
    • Avoidance of fines and penalties.
  • Business continuity & reputation:
    • Reduced likelihood of lost customers and brand damage.

Cybersecurity ROI Calculator Template

This can get quite complex very quickly, so SMEs need to take from it what they need and discard the rest.  Be wary though that you understand what you need and what you don’t.  The best way of doing this is to carry out a risk assessment on the assets you are trying to protect.  Until you’ve done that the ROI will be almost impossible to predict.

If you need to understand the risk assessment procedure, then this short video will guide you:

Link   Cyber Resilience for SMEs: Navigating the Digital Wild West  synthesia.io  A short video describing cyber risk management and how SMEs should consider approaching this subject.

Once you have a good grasp of cyber risk management and you understand the threats and what you may need to do to protect yourself from those threats, then you can use this framework in Excel, Google Sheets, or whatever you use. The formulas are structured so you can plug in your own assumptions and automatically calculate:

  • Annualised cyber risk exposure
  • Risk reduction from controls
  • Expected financial savings
  • Total security investment
  • ROI %

Step 1 — Define Your Baseline Risk

Annual Expected Loss (AEL):

\text{Annual Expected Loss} = \text{Probability} \times \text{Financial Impact}

Example:

  • 20% × £500,000 = £100,000 expected annual loss

At the bottom:

| Total Baseline Risk Exposure | =SUM(D2:D5) |

Now clearly you need an understanding of the threat to assess the annual probability, and you need an understanding of how long it would take you to recover from that threat becoming a reality.  You may need advice or you may feel that you have sufficient information to make that calculation yourself.

Step 2 — Add Security Controls

Now estimate how much each cybersecurity investment reduces

Step 3 — Calculate Residual Risk

For each risk scenario:

Formula

Residual Risk:

\text{Residual Risk} = \text{Baseline Risk} \times (1 – \text{Risk Reduction})

Then total:

| Total Residual Risk | =SUM(D2:D5) |

In summary

Producing an ROI in cyber security is not easy and to do it you must pull together several different but related issues, starting with a good grasp of cyber risk management.  I know that when I suggest that you should get some help and guidance, I am often accused of just trying to drum up business, and OK, maybe that has a play, but by showing the calculations and what is required to identify those calculations, what I am actually trying to do is to show you that this isn’t easy and needs thought and a bit of work to achieve a good end result, which is to give leadership a financially justifiable reason for a cyber security spend.  ROI in cyber security is less about “profit” and more about quantifying avoided losses, improved efficiency, and reduced risk relative to the cost of controls.

Cyber Security as Business Protection – Protect, Detect and Recover

This is another foray into cyber risk management and strategy for SMEs.  I make no apologies for covering it again because it should be a vital part of any SMEs business planning.   In a nutshell it’s the business process of identifying and addressing digital threats to protect operations, revenue, and reputation. Rather than just a technical IT task, it is a strategic function focused on ensuring business continuity and managing potential financial losses. 

A strong cybersecurity risk management strategy for SMEs should focus on reducing the highest risks first while staying practical and affordable. Most SMEs do not need enterprise-scale security programs, they need disciplined fundamentals, clear ownership, and resilience.

Core Principles

  1. Protect what matters most
  2. Customer data
  3. Financial systems
  4. Email accounts
  5. Intellectual property
  6. Operational systems
  • Assume attacks will happen
  • Focus on prevention and recovery.
  • Design for resilience, not perfect security.
  • Keep it simple and repeatable
  • Overly complex controls fail in SMEs due to limited staff and budget.

Recommended Cybersecurity Risk Management Framework

A practical SME strategy can follow five pillars inspired by the National Institute of Standards and Technology Cybersecurity Framework:

  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Alternatively, for those attempting or having achieved Cyber Essentials, one of the most effective ways to secure a business is to follow the UK government’s National Cyber Security Centre (NCSC) recommendations. These five steps are designed to be cost-effective and provide protection against the majority of common cyber-attacks. 

  • Secure your data with back-ups.
  • Protect with strong authentication (MFA).
  • Keep devices and software up to date.
  • Guard against malware.
  • Train staff on cyber awareness, phishing in particular.

But beware, the latest iteration of CE requires CEOs/MDs to sign a certification that they will ensure that the standard is maintained throughout the year and not just at point of achieving the standard.  That is a game changer which requires some form of monitoring to be put in place to ensure that the standard continues to be met.

No two businesses are the same.  They all have certain threats and vulnerabilities in common, and adherence to the NCSC guidelines and/or Cyber Essentials will set you on the right path, many of you will either have gone down that route or will be actively discussing it internally.  But there will still be differences, perhaps only nuances, that can drive a hole through your defences, and that is why you need a risk management strategy to ensure you have built robust defences.

Identify Your Risks

  1. The first stop is to create an Asset Inventory:

Document:

  • Devices
  • Servers
  • Cloud services
  • SaaS platforms
  • User accounts
  • Critical data
  • Vendors

Even a spreadsheet is enough initially.

  • Classify Critical Assets

Rank systems by business impact:

  • High: payroll, CRM, finance, production
  • Medium: internal collaboration
  • Low: public marketing systems
  • Identify Likely Threats

For SMEs, the biggest risks are usually:

  • Phishing
  • Business email compromise
  • Ransomware
  • Weak passwords
  • Insider mistakes
  • Third-party/vendor compromise
  • Unpatched software
  • Cloud misconfiguration

Protect the Business

  1. Multi-Factor Authentication (MFA)

This is one of the highest-value controls and you need MFA for:

  • Email
  • VPN
  • Admin accounts
  • Cloud apps
  • Banking systems

Use authenticator apps or hardware keys where possible.

  • Strong Identity & Access Management

You need to apply:

  • Least privilege access
  • Separate admin accounts
  • Role-based permissions
  • Immediate removal of leavers

Review access at least quarterly.

  • Endpoint Protection

Deploy modern endpoint security on all company devices:

  • Antivirus/EDR
  • Device encryption
  • Automatic updates
  • Screen lock policies

Focus first on laptops because they are commonly targeted.

  • Patch Management

Set strict update timelines:

  • Critical vulnerabilities: 24–72 hours
  • High-risk patches: within 1 week
  • Routine updates: monthly

Automate updates whenever possible but you will still need some form of monitoring patch management to ensure that you have this under control.

  • Email Security

Since email is the number one attack vector:

  • Anti-phishing filters
  • DMARC, DKIM, SPF (these require DNS entries and will need to be monitored)
  • Attachment sandboxing if affordable
  • User reporting button for suspicious emails
  • Backup Strategy

Use the 3-2-1 rule:

  • 3 copies of data
  • 2 different storage types
  • 1 offline/immutable copy – don’t rely on on-line backups, they may make restoring quicker, but they can be encrypted in a ransomware scenario, just like the rest of your systems.

Test restores regularly.  Recovery in a disaster or ransomware situation depends on this.

  • Secure Cloud Usage

For cloud platforms like Microsoft 365 or Google Workspace:

  • Disable legacy authentication
  • Enforce MFA
  • Monitor sharing permissions
  • Limit external access
  • Audit administrator activity

Detect Threats Early

  1. Centralised Logging

This is often a particularly difficult thing for SMEs because they don’t have any on staff cyber security personnel and often their IT support company doesn’t offer this service.  However, it is still important to collect logs from:

  • Email systems
  • Firewalls
  • Endpoints
  • Cloud platforms

A managed service is often the way forward.

  • Monitoring & Alerts

This is another issue that is very hard for SMEs, for the same reasons as log collection.  You need to receive alerts on:

  • Failed login spikes
  • Impossible travel logins
  • Admin privilege changes
  • Large file downloads
  • Suspicious mailbox rules

A managed service is often the only way to achieve this.

  • Vulnerability Scanning

You should aim to run monthly scans internally and externally.

Prioritise:

  • Internet-facing systems
  • Critical vulnerabilities
  • Unsupported software

There are a variety of scanning tools available to purchase however you need to have someone who can interpret the results, identify critical issues and eliminate false positives.  Once again, a managed service maybe the answer for many SMEs.

Incident Response Plan

Every SME should have a documented response process which includes:

  • Who makes decisions
  • Who contacts customers
  • Legal/compliance steps
  • Cyber insurance contacts
  • IT recovery procedures
  1. Create Playbooks For:
  • Ransomware
  • Phishing compromise
  • Lost/stolen device
  • Data breach
  • Vendor compromise

Run tabletop exercises twice yearly.

Recovery & Business Continuity

  1. Define Recovery Objectives

Set:

  • RTO (Recovery Time Objective)
  • RPO (Recovery Point Objective)

Examples are below and show the amount of time the business can survive with the loss of each system, but this will be determined by business priorities:

SystemMax DowntimeMax Data Loss
Email4 hours1 hour
Payroll24 hours4 hours
CRM8 hours2 hours
  1. Business Continuity Planning

Prepare for:

  • Cloud outages
  • Cyberattacks
  • Staff unavailability
  • Power/network failures

Document manual fallback procedures to keep the business running whilst you recover from the crisis.⸻

Governance & Leadership

  1. Assign Ownership

Even small companies need accountability:

  • Security lead
  • Executive sponsor
  • Incident coordinator

Security without ownership fails.

  • Establish Policies

Minimum essential policies:

  • Acceptable use
  • Password policy
  • Data handling
  • Remote work
  • Vendor management
  • Incident reporting

Keep them concise and enforceable and importantly, rolled out so that staff know where to find them and what they contain.

Human Risk Management

Most SME breaches involve human error.

  1. Security Awareness Training

Train employees on:

  • Phishing
  • Social engineering
  • Password hygiene
  • Safe file sharing
  • AI/deepfake scams
  • Reporting suspicious activity

Short monthly sessions work better than annual training.

Phishing Simulations

Measure:

  • Click rates
  • Reporting rates
  • Repeat offenders

Use results for coaching, not punishment.

Third-Party & Supply Chain Risk

SMEs increasingly rely on vendors.

  1. Vet Critical Suppliers

Review:

  • Security certifications
  • MFA usage
  • Breach history
  • Data protection controls

Prioritise vendors with access to:

  • Financial data
  • Customer data
  • Internal systems

Compliance Considerations

Depending on industry/location, SMEs may need alignment with:

  • International Organisation for Standardization ISO 27001
  • National Cyber Security Centre Cyber Essentials
  • GDPR/Data Protection Laws
  • PCI DSS

For UK SMEs, Cyber Essentials is an excellent baseline.

Recommended SME Security Stack

A practical modern stack often includes:

  • MFA platform
  • Endpoint detection & response (EDR)
  • Password manager
  • Secure email gateway
  • Cloud backup
  • Mobile device management (MDM)
  • Firewall with IDS/IPS
  • Security awareness platform

For those considering Cyber Essentials for the first time, or for renewal, some form of monitoring is required to ensure that that standard is maintained throughout the life cycle.

Budget Prioritisation (Highest ROI First)

For SMEs budget is always limited and must be prioritised.  This is a general guide and may change dependent upon business priorities:

  • MFA everywhere
  • Backups
  • Endpoint protection
  • Email security
  • Patch management
  • Security awareness training
  • Logging/monitoring
  • Vulnerability scanning
  • Managed security services
  • Advanced zero-trust controls

In order to decide your budget, you need to work out your priorities and again, this will depend on what the company does.  A suggested 12 month roadmap, for someone starting from scratch, is:

Months 1–3

  • Asset inventory
  • MFA rollout
  • Backup improvements
  • Patch automation
  • Security policies

Months 4–6

  • Endpoint protection
  • Vulnerability scanning
  • Staff awareness training
  • Incident response planning

Months 7–9

  • Logging and monitoring
  • Vendor risk reviews
  • Phishing simulations
  • Access reviews

Months 10–12

  • Tabletop exercises
  • Business continuity testing
  • External security assessment
  • Cyber insurance review

Metrics SMEs Should Track

I talked about measuring your security stance and your compliance.  Some useful KPIs might be:

  • MFA adoption %
  • Patch compliance %
  • Phishing click rate
  • Mean time to detect/respond
  • Backup recovery success
  • Number of critical vulnerabilities
  • Security training completion

Common SME Mistakes

Turning now to some common mistakes.  I don’t want to dwell on these too much as they are self-evident, but you should avoid:

  • Treating cybersecurity as only an IT problem
  • Buying too many disconnected tools
  • Ignoring backups
  • Giving staff admin rights
  • Failing to test recovery
  • Depending entirely on one IT provider
  • No incident response process

I hope that this provides some guidance but I’m fully aware that it contains issues that will appear as a bit of a ‘black art’ to some people.  Get advice from cyber security professionals, don’t think that because someone knows about IT, they have the nuances of security covered, they often don’t.  Remember that some cyber security solutions are procedural not technical. 

Policy, Process and then Technology

CYBER ESSENTIALS HAS CHANGED:  ARE YOU READY?

Cyber Essentials has changed recently and one of the most significant changes, in my opinion is the requirement for a senior executive to formally declare that security controls are continuously assessed throughout the year.  A fundamental change, not just a paperwork tweak. It shifts accountability and how organisations approach compliance.

What does this change really mean?

  1. Accountability moves to the top

Executives (often a CEO, CFO, or board-level director) are now personally attesting that controls aren’t just “point-in-time compliant” but actively maintained. This raises the stakes, false declarations could have legal, reputational, and contractual consequences.

  • End of “annual checkbox” compliance

Previously, many organisations treated Cyber Essentials as a once-a-year exercise. This change pushes toward continuous assurance, more in line with standards like ISO/IEC 27001 or frameworks such as NIST Cybersecurity Framework.

  • Increased audit and insurance implications

Cyber insurers and regulators may view this declaration as evidence of due diligence or even negligence if something goes wrong. Expect more scrutiny if a breach occurs.

  • Cultural shift toward operational security

Security becomes an ongoing business process, not an IT task. It requires coordination across the company up to and including management.

How organisations can actually deliver “continuous assessment”?

This is where many companies will struggle, because the declaration implies evidence, not intention.

  1. Continuous monitoring of key controls

Use tools that provide ongoing visibility into:

  • Patch management status
  • Vulnerability scanning
  • Endpoint protection health
  • Firewall and access control configurations

Common tooling might include:

  • Endpoint detection & response (EDR)
  • Vulnerability management platforms
  • Security configuration monitoring tools
  • Defined control testing schedule

Not everything needs real-time monitoring, but you should have:

  • Monthly or quarterly control checks
  • Automated scans (minimum of weekly vulnerability scans)
  • Regular access reviews (e.g., user permissions)
  • Centralised logging and alerting

Implement:

  • An MDR solution.
  • Alerts for control failures (e.g., antivirus disabled, patch failures)

This creates an audit trail—critical if leadership is signing a declaration.

  • Metrics and reporting to leadership

Executives need evidence to sign confidently:

  • Security dashboards
  • KPIs (e.g., patch SLAs, vulnerability remediation times)
  • Regular security reports to the board
  • Policies backed by enforcement

It’s not enough to have policies; you need:

  • Technical enforcement (e.g., blocking unpatched devices)
  • Automated compliance checks
  • Internal audits or independent checks

Periodic internal reviews or external assessments that help validate that controls are actually working.

Practical example

Instead of saying:

“We apply patches”

You now need to demonstrate:

  • All devices report patch status daily
  • Alerts trigger if patches are overdue
  • Reports show compliance over time
  • Exceptions are tracked and approved

The real challenge

The hardest part isn’t technology, it’s evidence and governance.

Many SMEs certified under Cyber Essentials don’t currently have:

  • Centralised visibility
  • Documented control testing
  • Board-level security reporting

So, this change may force investment in:

  • Better tooling
  • Clearer processes
  • Stronger governance structures

Bottom line

This declaration effectively aligns Cyber Essentials with modern security expectations: continuous control validation, not annual self-assessment.

If an organisation can’t produce evidence of ongoing monitoring and review, executives are being asked to take a significant personal risk by signing.

How can an SME meet this requirement without breaking the bank?

You don’t need an enterprise SOC or a six-figure toolchain to meet these new expectations, but you do need joined-up tooling that produces continuous evidence.

The principle: “Good enough + visible + provable”

For an executive to sign the declaration, you must:

  • Cover all five control areas
  • Be centrally visible
  • Generate reports + alerts automatically
  • Require minimal manual effort

The issue for many SMEs that a system that integrates many of the issues simply hasn’t existed in a form that is financially viable, and that doesn’t require a dedicated cyber individual on staff, until now.  Such a system does now exist, and I have put up a short video on the features section of my profile page on LinkedIn, the link is A short video on protective monitoring for SMEs.  This should help you without having to read reams of information.  You will also find a couple of articles on that particular subject.

H2 provides affordable and flexible one-off and ongoing data protection and cyber risk protection services.

To learn more about the services we provide, please click here https://www.hah2.co.uk/

Alternatively, please feel free to give us a call or drop us an email:

M: 07702 019060

E: kevin_hawkins@hah2.co.uk

The Breach They Didn’t See

Last week, we wrote about managed detection and response, and how it benefits SMEs, at a price they can afford.  In that article, we did use a scenario where there was an inadvertent data breach, but the article concentrated more on how breaches can be detected, rather than prevented.  This week, we want to expand on how we can detect and prevent data leaks, and if they do sneak through, there is no such thing as 100% security, then how we can encrypt your most sensitive data so that any impact of a data breach is minimised.

Company profile

A small but growing haulage and cold store company that offers haulage of fresh produce from the grower to a cold store, and then onwards to the wholesaler.  It services growers mostly in their local area, a radius of about 4 counties in all directions.  This area covers a large agricultural sector which relies heavily on getting its produce to the wholesaler promptly, with minimal time in cold storage.

Phase 1: The Quiet Entry (Weeks 0–2)

An employee in the accounts team receives what looks like a legitimate email from a known software provider asking them to “re-authenticate” their account. The link leads to a convincing fake login page.

The employee unknowingly enters their credentials.

No alarms are triggered. The company does not have multi-factor authentication (MFA) enabled on this system.

Phase 2: Undetected Access (Weeks 2–8)

Using the stolen credentials, the attacker logs into the firm’s cloud-based CRM system. Because access controls are overly broad, the compromised account can view and export large volumes of client data.

The attacker:

  • Gradually downloads customer records to avoid detection
  • Accesses archived documents containing invoicing data and financial statements
  • Sets up a forwarding rule in the employee’s email to monitor communications

There is no real-time monitoring or anomaly detection in place, so this activity goes unnoticed.

Phase 3: Data Exploitation (Weeks 6–10)

The stolen data is sold on the dark web. Some clients begin experiencing:

  • Fraudulent loan applications in their name
  • Unauthorised bank transactions
  • Phishing attempts using highly personalised information

Still, the SME remains unaware.

Phase 4: The Discovery (Week 10)

A long-standing client contacts the firm after his accountant flags suspicious activity linked to financial activity, which the accountant deems suspicious.

He says:

“The fraudster replicated your invoice template but with different bank details. The invoice matched the activity between us which only we would know.  How did they do that?”

Initially, the company assumes it’s an isolated incident. But within days, two more clients report similar issues.

Phase 5: Internal Panic & Investigation (Weeks 10–12)

The company initiates an internal review and brings in external cybersecurity consultants. They discover:

  • Unusual login activity from foreign IP addresses
  • Large volumes of data exports
  • The compromised employee account is identified

At this point, leadership realises the breach has been ongoing for weeks, possibly months.

Potential Consequences

  1.  Regulatory & Legal Impact
  • Mandatory reporting to regulators (e.g., data protection authorities)
  • Potential fines for failing to protect personal data (e.g., under GDPR-like frameworks)
  • Investigations into inadequate security controls
  • Lawsuits from affected clients
  •  Financial Losses
  • Direct costs:
    • Incident response and forensic investigations
    • Legal fees
    • Customer notification and credit monitoring services
  • Indirect costs:
    • Loss of business
    • Increased Insurance Premiums
    • Potential Compensation Payouts

 Reputational Damage

  • Loss of client trust, especially critical in ‘just in time’ delivery systems
  • Negative media coverage
  • Clients moving to competitors
  • Difficulty acquiring new customers
  •  Operational Disruption
  • Systems taken offline during the investigation
  • Staff diverted from normal operations
  • Implementation of urgent security upgrades
  •  Client Harm
  • Identity theft
  • Financial fraud
  • Emotional distress and loss of confidence
  •  Internal Consequences
  • Accountability questions for leadership
  • Potential recruitments or restructuring
  • Pressure to overhaul cybersecurity policies
  •  Long-Term Strategic Impact
  • Shift from growth to damage control
  • Mandatory compliance upgrades
  • Board-level scrutiny of risk management

Key Underlying Failures

The breach wasn’t just bad luck; it stemmed from:

  • Lack of multi-factor authentication
  • Overly broad access permissions
  • No monitoring or alerting for unusual activity
  • Limited employee phishing awareness training

Summary Note

What makes this scenario particularly dangerous is that the company didn’t discover the breach itself; the client did. That delay significantly worsened the damage, turning what might have been a contained incident into a full-scale crisis.

How can this be prevented?

I have already said that there is no such thing as 100% security, and if anyone tells you otherwise, you need to take a long, hard look at them and recognise BS when you see it.  What we are trying to do is reduce your risk to a level you find acceptable for your business.  What we call the risk appetite.  That appetite will differ between businesses depending upon what they do and what can damage them, rather than the business next door.

Most Data Loss Prevention (DLP) systems are designed for the corporate market, are expensive and have a considerable admin and maintenance overhead.  All the things that SMEs simply can’t afford and don’t have the staff to run.  We took a good look at this and did a lot of research on the market.  We came up with a solution that works in terms of cost and overhead.  It allows us to offer a managed service at a price and service level that SMEs are comfortable with.

One of the things that we come up against pretty much every time we get into discussions with a prospective client is that they aren’t quite sure what data they are holding, and where it’s stored.  Now this seems strange.  You will no doubt argue that you are very clear about what you hold and where it is.  Well, maybe, but during the 14-day free trial we offer, I am pretty sure that we will discover things that will surprise you.

How are we different?

What we are offering is a unique, comprehensive, and autonomous data security platform that can transform how organisations secure their sensitive data. Unlike legacy DLP systems that are based on an event-driven approach and require extensive ongoing rules management built for LAN perimeters, our system is different. It is based on analysing data risks and applying pre-emptive encryption that handles both external threats and insider carelessness, all in a world of no security perimeters, providing full coverage no matter where your staff are operating from, the office, home or on the move.   Moreover, our set-and-forget method requires little to no maintenance and can be up and running, securing data, in less than 3 working days.

Key principles

Perimeter-less world with hybrid cloud and on-prem usage

The local area networks and the notion of a security perimeter are no longer valid with the transition to hybrid cloud, work-from-home, and zero-trust architecture. In such a setup, sensitive files are spread across on-premise repositories (File Server, NAS) and different cloud-based repositories. These cloud-based repositories are divided between the ones that you manage (managed cloud, such as organisational OneDrive), shadow IT (such as communication apps like Slack or WhatsApp), and 3rd party portals.  We provide an answer to this new data landscape with our cross-platform discovery functionality, coupled with the data flow monitoring capabilities.

Remediate Data Risk rather than handle files

We provide a detailed breakdown of the data risk and leverage the data risk for data

flow monitoring, auditing and remediation. This approach greatly simplifies the process.

Pre-emptive vs Reactive

Most DLP solutions try to prevent a data leakage event by blocking the exfiltration of the file. This approach has a couple of shortcomings:

  • It does not help with an external threat, like ransomware stealing data.
  • It requires an initial extensive effort of setting up all the blocking rules with ongoing maintenance.

Our pre-emptive approach provides an answer for both shortcomings by encrypting files automatically.

How does it work?

It is a cloud-based management platform coupled with a lean agent for workstations

(both Windows and Mac), File Servers, NAS and Terminal Servers, and a sidecar Docker

instance for cloud-based file shares (. i.e., OneDrive).

Step 1: Data Risk Discovery and Quantification

Based on predefined privacy regulations and Personal Identifiable Data (PII) definitions, the system immediately starts scanning for sensitive data using smart patterns. It then quantifies data risk per PIl type in financial terms.

Step 2: Data Risk Monitoring and Auditing

Tracks and audits data risk in real-time by continually monitoring incoming and outgoing sensitive data flows from and to the perimeter-less organisation.

Step 3: Data Risk Remediation by Encryption

Its patented transparent encryption process automatically secures sensitive data across all endpoints, cloud apps, 3rd party portals, and shadow IT. The entire process, from initial deployment through data risk analysis to remediation by automatic encryption, takes as little as 72 hours.

The system not only pre-emptively encrypts sensitive private data in files, but it also transitions the data to a safe harbour, per all privacy regulations requirements. The solution helps organisations comply with all statutory data privacy regulations.

So, what does it do for you?

  • Sensitive File Discovery.  SMEs frequently have an incomplete picture of where sensitive data is dispersed and who has access to it. The system locates and maps sensitive data across all your systems, devices, and the cloud.
  • Data Risk Quantification

Actifile calculates the data risk for every PIl type by applying an algorithm that multiplies every PII record by its potential total damage, then aggregates that across all the files and PIl records of the organisation. The aggregation is across file types, file locations, and different silos to provide a complete data risk quantification. The quantification is always up to date, in real time.

  • Real-Time Data Flow Monitoring

The system works silently in the background, monitoring real-time data flow across your entire IT ecosystem through user activities at the endpoints. This real-time monitoring shows how much data is being exfiltrated outside the organisation or imported into it. The monitoring capability does not require any type of integration to the sending or receiving application or website.

Full Audit and Indelible Log

We automatically log all data-related events, including data ingress and egress and the creation of sensitive data. You can instantly audit back to specific dates, times, and locations. The log is never deleted, covering you in the event of a breach. You also have the option to generate alerts on specific events and to integrate the alerts to 3rd party systems, such as SOC or SIEM.

  • 3rd Party Integration and Reporting

3rd party event integration: Everything that we capture can be seamlessly integrated

into a third-party security central system (SOC or SIEM). Users can capture and correlate all events that happen within the organisation.

Online and offline reporting: Conveniently export system reports and analyses in PDF format and white label them as required.

Risk Remediation by Encryption

Automatic encryption is a fast and convenient remediation process that secures sensitive data across your entire IT ecosystem, including remote devices and the cloud.  Even if data is stolen or misplaced, the AES 256 encryption mechanism prohibits bad actors from opening or using the file.  Invisible decryption allows employees to automatically use encrypted files with no latency and without the need for a password. Your employees can work without disruption, but sensitive data remains useless to any hostile actor. Automatic decryption by channel enables users to automatically decrypt any encrypted file when it’s attached to an application. The system easily meets the demands of modern high-tech working environments. Delayed encryption gives you the flexibility to balance security with the demands of daily workflows. You can create a pragmatic, tailored approach to the management of sensitive data.

In a nutshell, this service is designed to protect your data from being stolen or inadvertently leaked by employee action.  It is a layer below intrusion detection and prevention, stopping the scenario outlined above, where a cybercriminal had infiltrated the system and was exfiltrating data without the knowledge of the organisation.  If they had been using this system, their data would have been encrypted and useless to the attacker.

What is Security Architecture, and what does it mean for SMEs?

Security architecture is the structured design of systems, policies, technologies, and processes used to protect an organisation’s IT systems, networks, and data from cyber threats.  Easy to say, not quite so easy to do.

When working on a major IT infrastructure deal, the security architect would be brought in, or at least should be brought in, very early on, usually after the first logical design has been done.  What that means is that a logical design is basically a bunch of boxes on paper that represent systems with connection arrows in between, identifying data flows.  OK, I’m being a bit simplistic, but you get the idea.  Once that’s done, the security architect has something to work with to start putting in security layers.  As the design evolves, so does the security architecture.

So now let’s look at the real world.  Most SMEs are way past this phase, with their systems having grown organically as the company grows.  SME management is focused on how well the systems work for them, whether they meet the need, can the staff operate the systems efficiently, are the systems robust, etc.  Security then tends to get bolted on, often using software and/or hardware that the company’s contracted IT provider recommends, which in turn is whatever software and/or hardware that the contractor sells.

Many SMEs had set up their system before COVID, and they were often set up using what we called the Bastion security model.  That was named after the old castle design, a big wall around it with a moat and a portcullis to protect it, or in modern terms, a protected network, accessed via secure firewalling, with some sort of access control and other protections such as anti-malware.  A good model had network segregation, but I’m afraid my experience is that network segregation was often lacking.  Just to be clear, what segregation means in this instance is a breaking up of functions within the company, i.e., finance, HR, operations, management, etc., with relevant access controls of some sort.  And of course, all this on premises.

In many cases, COVID drove a coach and horses through that model.  First, it stopped people from going into the office, and owners/managers had to quickly come up with a way of working remotely through some form of remote access.  Many at that point weren’t using cloud-based systems, and in fact, there was still some reluctance to embrace cloud tech because owners didn’t trust storing their data with what they saw as being out of their control.  It took some persuasion and education to bring many of these owners/managers around.  These days, of course, cloud storage and remote access are largely the norm, but there is still the question of exactly how secure existing systems are, having often been put together rapidly and from a position of necessity rather than choice.

A realistic cybersecurity architecture for an SME should balance security, manageability, and cost. Most SMEs are now operating in a cloud-based environment, so the architecture typically centres on identity security, endpoint protection, and cloud controls rather than heavy on-prem infrastructure.  But let’s not forget monitoring and auditing, and, depending upon your business, data encryption.

Identity Layer (Core Security Control)

Identity management is core to a secure system.  It is vital to ensure that only the right people have access to the right systems.  SMEs need to consider some form of identity management, but they might feel this is expensive and unnecessary for them.  Owners and managers need to decide their own risk appetite, i.e., what they see as an acceptable, as well as what they see as an unacceptable, risk.  But it doesn’t have to be expensive.  Many SMEs will be using MS365, for example, and will be able to get a reasonable deal on Microsoft Entra ID, formerly known as Azure AD.  I know many of my colleagues in the security world will argue that Azure had its issues in the past, but it is better now.

It will help you implement controls such as:

  • Mandatory Multi-Factor Authentication
  • Conditional access policies
  • Single Sign-On (SSO)
  • Privileged identity management
  • Automated user provisioning/deprovisioning

Endpoint Security Layer

Endpoints are the primary attack surface. This typically includes:

  • Endpoint detection and response (EDR)
  • Device management
  • Encryption

Controls it should cover include:

  • Automated patching
  • Encryption:
  • Full disk encryption comes built into Windows with BitLocker and Mac with File Vault, but it has drawbacks in that it encrypts your disk at rest, protecting your data from a stolen device, but it is unencrypted on boot up, so it isn’t much protection against an intrusion or a mistake made by an employee.
    • File-level encryption works by encrypting files that you have deemed to be sensitive and need protection.  It encrypts the files using an agent-based system and unencrypts the files when shared or accessed by someone who also has the agent and therefore the permission.  Sounds complicated, but it really isn’t, and it can be shown to you very easily.
  • Application control
  • USB restrictions
  • Remote wipe

Email and Collaboration Security

Email is still the No 1 entry point for attacks, and using cloud-based software such as MS365 or even Google Workspace, both affordable for an SME, has security features that are highly desirable if not essential.

  • Anti-phishing protection
  • Attachment sandboxing
  • URL scanning
  • DMARC, SPF, DKIM email authentication – these all refer to entries in your DNS (your network provider should be able to brief you), which help ensure email isn’t being spoofed and is coming from a trusted source.

 Network Security Layer

Even cloud-heavy SMEs still need basic network protection.

Key components:

  • Next-generation firewall
  • VPN or Zero Trust remote access
  • Network segmentation
  • DNS filtering

Good firewall segmentation would include:

  • Company devices
  • Guest WiFi
  • Servers
  • IoT devices

Cloud Security

SMEs often rely heavily on Software as a Service (SaaS) and cloud infrastructure.  Again, this needs some controls, which could include:

  • Secure configuration monitoring
  • Data leakage prevention
  • Access monitoring

Key policies may include:

  • No public file sharing by default
  • Alert on impossible travel logins
  • Monitor privileged activity

Data Protection Layer

Protect sensitive data even if systems are compromised.  Controls might include:

  • Data classification
  • Data leakage prevention
  • Full disk and file-level encryption

Policies might include:

  • Prevent the sharing of sensitive records externally
  • Block download of sensitive files on unmanaged devices
  • Monitoring where your data is and how it transits the network, alerting to movements of data outside of the norm.

 Backup and Recovery

This is critical for recovering from ransomware and other data compromises, as well as technical faults.

Best practice:

  • Immutable backups
  • Offline copies
  • Regular restore testing

Don’t forget cloud backups; that’s something that is often forgotten.  Check your Ts&Cs with your provider, don’t just assume they are backing up as you would require.

Security Monitoring

You need visibility into attacks, and security monitoring is something that many SMEs simply don’t consider, possibly because in the past, it was considered very expensive and over the top.  That is no longer the case.  There are systems now available specifically for SMEs.

Typical SME approach:

  • Centralised log collection
  • Security alerts
  • Managed detection and response

Many SMEs outsource this to an MDR provider like H2.  I know you would expect me to say this, but it really is recommended.

Security Awareness and Policies

Technology alone cannot protect the organisation.  Cyber awareness training is a subject that I bang on about all the time.  It really should be a no-brainer and is arguably the cheapest quick win an SME can make.

What you need as a minimum is:

  • Security training platform
  • Phishing simulation
  • Acceptable use policy
  • Incident reporting channel

Strangely enough, we provide all of these within our managed service.

Incident Response and Business Continuity

I have blogged about this in the past.  You need to be prepared for security incidents.  This means not just having a plan to bring your systems back online and to restore your data from backups, but also having a business continuity plan to enable you to continue your business whilst the technical work is being undertaken. Test these systems and plans and make sure they work.

Key elements include

:

  • Incident response playbooks
  • Legal and breach notification procedures
  • Disaster recovery and business continuity plans
  • Security metrics dashboard

Standards

Consider adhering to a standard such as Cyber Essentials, the Government standard, which has been taken into use by many SMEs.

Summary

Security architecture is the structured design of policies, technologies, and controls used to protect an organisation’s systems, networks, and data from threats.

It acts as a blueprint for implementing security to ensure Confidentiality, Integrity, and Availability (CIA Triad) of information.  It really is something SMEs should consider and need to take advice about.  Do not rely on your network provider, they will focus on the core services they provide and the products they have deals to supply.

Scroll to top