Working Practices

What is Shadow IT, and what does it mean for cyber security within UK SMEs?

We all know that the threats to our businesses through cyber-attacks and scams changes and expands almost daily, and it is really difficult to stay abreast of when there is so much else going on in our businesses that needs our attention.  One of the fastest-growing cyber risks for SMEs is what has become known as Shadow IT, because it introduces technology that the business doesn’t know about, can’t monitor, and can’t secure.  It is more of a risk for SMEs than it is for corporates, who generally have strong policies to protect themselves, and are prepared to spend money on resources to enforce those policies.  Luxury that SMEs can’t afford.  Shadow IT can be particularly dangerous because employees often adopt apps and AI tools to work faster, without involving IT or their MSP.  It’s not that they are deliberately introducing problems into the environment but often they see the use of tools that they have been using for a long time privately, as increasing their efficiency and making their jobs easier.

What is Shadow IT?

Shadow IT is any software, cloud service, device, or AI tool used for work without the approval or oversight of the business or its IT provider.  Examples include:

  • Employees storing company files in personal Google Drive or Dropbox accounts.
  • Using ChatGPT or other AI tools with confidential customer information.
  • Free file-sharing services such as WeTransfer.
  • Personal laptops, tablets, or phones accessing company email.
  • Unsanctioned project management tools like Trello, Notion, or Monday.com.

This list is far from exhaustive.

Why SMEs are especially vulnerable

Unlike large enterprises, SMEs often have:

  • Limited IT staff.
  • Smaller security budgets.
  • Employees wearing multiple hats and choosing their own tools.
  • Less visibility into what applications is being used.

All of which makes Shadow IT easy to introduce and difficult to detect.  The biggest risks:

  1. Data leakage caused potentially by employees uploading:
  • Client financial information.
  • Legal documents.
  • HR records.
  • Intellectual property.

…into services that the company does not control.

For regulated sectors like legal and financial services, this can create significant issues.

2. Increased phishing and ransomware exposure via free and consumer apps which:

  • Don’t enforce MFA.
  • Have weak passwords.
  • Lack business-grade monitoring.

If compromised, attackers gain another doorway into cloud or company systems.  It’s also worth noting that it introduces Cyber Essentials failure points.

3. AI creates “Shadow AI” and is becoming one of its newest forms. Some examples are:

  • Staff pasting customer contracts into AI chatbots.
  • Uploading spreadsheets containing personal data.
  • Using AI browser extensions that access company emails.

Sensitive information can leave the organisation without anyone realising.

4. Compliance failures such as Cyber Essentials which requires organisations to control software, accounts, devices, and access.  Shadow IT can mean:

  • Unpatched software.
  • Unknown devices.
  • Unmanaged cloud accounts.
  • Data stored outside approved locations.

The above can jeopardise Cyber Essentials and other certifications and cyber insurance conditions.  Let’s look at a simple attack scenario:

  • Step 1 – Employee uses a personal Dropbox account to share files with a customer.
  • Step 2 – The Dropbox password is reused from another breached website.
  • Step 3 – Attackers access the Dropbox account and discover invoices, contracts, and email addresses.
  • Step 4 – They use this information to launch convincing phishing emails against customers and finance staff.

The result of this is invoice fraud or ransomware infection.  This type of attack is increasingly common because attackers exploit unmanaged services rather than well protected corporate systems.

Warning signs that Shadow IT exists

  • Employees using WhatsApp or other messaging apps for customer conversations.
  • Personal email accounts used for work documents.
  • Unknown browser extensions installed.
  • Multiple file-sharing platforms in use.
  • AI tools appearing in browser history or network logs.
  • Staff connecting personal USB devices or laptops.

How can SMEs reduce the risk and protect themselves.

ControlBenefit
Application DiscoveryIdentify every cloud app employees use
Approved software policyProvide sanctioned alternatives so staff don’t seek their own tools
Multi-factor authenticationProtect business accounts even if passwords are stolen
Protective monitoring/Managed Detection and ResponseDetect unusual logins, new applications and risky behaviour
AI usage policyDefine what information can and cannot be entered into AI tools
Employee awareness trainingExplain why convenience care create business risk

Why this matters for Cyber Essentials

Shadow IT maps directly to several Cyber Essentials control themes:

  • Asset management: You must know what software and services are in use.
  • Access control: Only authorised users should access company resources.
  • Secure configuration: Unapproved apps may not meet security standards.
  • Protective monitoring: Continuous visibility helps identify Shadow IT before it becomes a breach.

Shadow IT isn’t just employees installing software, it’s invisible cyber risk. Every unapproved app, AI tool, or cloud service creates a potential doorway into your business. If you can’t see it, you can’t secure it.  This is a particularly strong message for a UK SME audience because it ties directly into Cyber Essentials, GDPR, and the need for continuous cyber risk monitoring.

I hope this has been useful information but it’s just the tip of the iceberg.  If you want to know more then please use the contact information below, or DM me on my LinkedIn account.

Do SMEs need to be concerned about Nation State cyber-attacks?

When we talk about cyber scams and attacks on SMEs, we concentrate on threats from cyber criminals because, quite simply, they are not just the perceived threat, but often the actual threat.  However, there is another category which we tend not to connect with SMEs, but rather with the corporate and government worlds, and that is the nation state threat. With what’s happening in the world today, maybe we should be keeping a weather eye on that potential threat.

Let’s take Iran for example, research suggests that they have been far more successful at espionage and disruption than at causing strategic damage.  Since the conflict escalated (initial Israel-Iran fighting in June 2025, followed by direct US-Israeli operations against Iran in February 2026), Iran’s cyber organisations have launched thousands of attacks against Israel, the US and Western allies. However, most have been contained, short-lived, or psychological in effect rather than strategically decisive. Cyber defences have largely prevented catastrophic infrastructure failures. This suggests that there hasn’t been much to worry about, from an SME perspective.  However, there is much more to it than that.

For UK SMEs, this is one of the biggest shifts in cybersecurity over the past 2–3 years.  Nation-state actors are no longer just targeting governments and FTSE 100 companies. They’re increasingly targeting SMEs because SMEs are the easiest route into larger organisations, valuable data, and critical UK supply chains.

The UK National Cyber Security Centre (NCSC) has repeatedly warned that the most serious cyber threats facing the UK now come from Russia, China, Iran and North Korea, and that businesses of all sizes need to prepare for attacks linked to geopolitical conflict.

The Nation-State Cyber Threat Landscape for UK SMEs (2026)

A Board-level takeaway is that your business is probably collateral damage, not the primary target.  You’re the route into your larger customers.  SMEs are targeted because they are easier to compromise than large enterprises and often have trusted access into customers, suppliers, and public-sector organisations.

What SMEs worry aboutWhat nation states actually do  
Steal money with ransomwareSteal credentials, intelligence, disrupt supply chains, prepare infrastructure for future conflict, and sometimes use ransomware as cover  
‘We’re too small’‘You’re connected to someone bigger’  
Only defence companies are targetsLaw firms, accountants, manufacturers, MSPs, logistics, healthcare, charities, fintech and engineering SMEs are all regularly targeted.  

The UK Government’s Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the previous year, around 612,000 businesses.  OK, but why would a nation state target a 25-person business?

The “supply chain attack” model

Think of your SME as a trusted key into someone else’s business.

SME TypeWhy it’s attractive  
Managed Service ProvidersAccess to hundreds of customers through remote management tools  
Law firmsM&A documents, litigation, intellectual property, government contracts  
AccountantsFinancial records, payroll, tax credentials  
ManufacturersDefence supply chains, engineering drawings, OT systems  
Financial AdvisorsHigh-net-worth client information and payment systems  
Healthcare SMEsSensitive patient information and NHS connectivity

This is exactly why Cyber Essentials and the upcoming Cyber Security & Resilience Bill place greater emphasis on supply-chain security.

So which nation states pose the biggest risk to UK SMEs?

Comparison at a glance

ActorPrimary ObjectiveSME Targets  
ChinaEconomic espionageManufacturing, legal, biotech, technology, universities, MSPs  
RussiaDisruption, espionage, influenceEnergy suppliers, logistics, transport, IT providers, defence supply chain  
IranRetaliation, disruption, hacktivismUtilities, local government suppliers, legal firms, critical infrastructure suppliers  
North KoreaFinancial theftCryptocurrency, fintech, software companies, payroll providers  

Firstly China, regarded, by UK intelligence, as the most capable long-term cyber espionage threat against UK business.  They typically look at SME targets involved in:

  • Aerospace.
  • Advanced manufacturing.
  • Robotics.
  • AI.
  • Pharmaceuticals.
  • Universities.
  • Defence subcontractors.
  • Typical techniques

Why SMEs are targeted and why it matters:

A 20-person precision engineering company supplying parts into aerospace may unknowingly possess intellectual property valuable to a foreign state. This is particularly relevant to manufacturing SMEs like CNC engineering suppliers.

Russia is known for Supply Chain attacks and Disruption, their objectives:

  • Intelligence gathering.
  • Political disruption.
  • Critical infrastructure preparation.
  • Supply-chain compromise.

They may target:

  • MSPs.
  • Logistics firms.
  • Energy suppliers.
  • Transport providers.
  • Engineering consultancies.

The war in Ukraine has shown Russia routinely targets organisations supporting infrastructure rather than infrastructure alone.

Back to Iran, an increasing threat to UK Businesses.

Following escalating conflict involving Iran, Israel and the US, UK authorities warned businesses to prepare for Iran-linked cyber activity, including attacks against smaller organisations connected to essential services.  A recent UK example is a small UK gas-fired power plant that was temporarily shut down by suspected Iran-linked hackers, prompting government action to strengthen supply-chain cyber regulation.

They are known for:

  • Website defacement.
  • Credential theft.
  • Ransomware.
  • Industrial control system attacks.
  • Destructive malware.

Energy contractors, water suppliers, engineering companies, local authority suppliers and MSPs supporting infrastructure, are all targets.

North Korea is a little different as it is suspected that cybercrime funds the state, and unlike China and Russia, North Korea often attacks businesses primarily for money.

Fintech, cryptocurrency firms, payroll providers, software companies and defence contractors, are the main targets.

What do we need to on guard against and to look out for.  It is assessed that the most likely Nation-State attack paths into an SME are often related to:

Microsoft 365 is a common battlefield for SMEs.  Microsoft 365 identities are now the most commonly targeted asset because compromising M365 gives attackers:

  • Email.
  • OneDrive.
  • SharePoint.
  • Teams.
  • Contacts.
  • MFA reset opportunities.

Next comes AI which has changed Nation-State attacks.  For example, AI-powered phishing is now industrialised.  Before AI:

  • Poor grammar.
  • Obvious phishing.

But now:

  • Perfect English.
  • Company branding copied.
  • Deepfake voice messages.
  • Fake Teams meetings.
  • Fake invoices.

Attackers now impersonate CEOs, Solicitors, Bank staff, IT support and suppliers. NCSC has warned AI is increasing the sophistication and scale of attacks.

Nation state threats influence how Cyber Essentials maps to nation-state tactics and why v3.3 matters. The executive declaration requiring continuous assessment reflects the reality that attackers exploit newly introduced weaknesses throughout the year, not just during annual certification.

For UK SME Leaders the conversation has changed.  Cybersecurity is no longer just about avoiding ransomware. Nation-state activity means SME directors should think about the NCSC’s message that hostile-state cyber activity is increasing alongside geopolitical tensions, and SMEs are increasingly part of that threat landscape rather than outside it. I hope this helps somewhat in understanding just how much the threat landscape has changed and how much it is affected by world events. 

HOW CAN SMEs MONITOR COMPLIANCE TO CYBER ESSENTIALS EASILY

I put up a post earlier this week about cyber essentials, how effective it is and how it should be viewed.  There have been some interesting posts recently on this subject and the main argument was that it should be viewed as a base line standard, not a total panacea. Adherence to it provides a good platform on which to stand your protections and provides a basic understanding of the issues involved, which many SMEs don’t fully grasp.

Cyber threats don’t just target enterprises anymore and SMEs are increasingly in the crosshairs, often without the resources to defend themselves effectively.  But it remains important to keep in mind that for many UK SMEs, cybersecurity is no longer just about protection, it’s about winning business. It’s important to think in terms of simplicity rather than complexity.  Cyber security doesn’t have to be complicated or expensive.

My post talked about what happens after a company has achieved compliance to CE? The requirement now is to certify that they will maintain that compliance throughout the 12-month period of the certification. That is why H2 has researched a service that can be provided to SMEs at a reasonable cost, that helps simplify that journey by providing an all-in-one cybersecurity platform with continuous monitoring aligned to Cyber Essentials requirements. It helps identify security gaps, strengthen your cyber posture, and keep your business on track for compliance, while protecting your users, devices, email, and cloud environment.

We did think however that perhaps a more detailed view might be worth publishing, and here it is.

NCSC has published v3.3 (Danzell) requirements effective from April 2026, which further tighten areas such as MFA and cloud-service requirements. Organisations that have only just adapted to last years changes (Willow) should already be reviewing the next revision to avoid another compliance scramble when renewal comes around. 

What changed in the Danzell question set?

The five Cyber Essentials control areas remain the same:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Security Update Management

However, Danzell asks more detailed and specific questions about how these controls are implemented and evidenced. 

Key themes covered by the Danzell questions

Multi-Factor Authentication (MFA)

The questionnaire now requires organisations to identify all cloud services in use and confirm MFA is enabled where available. Missing MFA on supported cloud services can result in an automatic failure. 

Typical questions include:

  • What cloud services are used?
  • Is MFA enabled for all users?
  • Are administrator accounts protected by MFA?
  • What authentication methods are used?

Cloud Service Scope

Danzell explicitly brings cloud services into scope, including:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Slack
  • Zoom
  • Cloud storage platforms

Organisations must declare these services and demonstrate appropriate security controls. 

Typical questions include:

  • Which cloud services store or process business data?
  • How are accounts managed?
  • How is access removed when users leave?

User Access Control

The questionnaire places greater emphasis on:

  • Administrative accounts
  • Privileged access management
  • Account lifecycle management

Typically, questions include:

  • Are administrator accounts separate from standard user accounts?
  • How are privileged accounts controlled?
  • How are unused accounts identified and removed?

Industry discussions indicate auditors are applying the separate-admin-account requirement strictly. 

Security Update Management

Danzell asks for clearer evidence regarding:

  • Operating system patching
  • Application patching
  • Firmware updates
  • Patch deployment timescales

Applicants need to be able to identify:

  • How are vulnerabilities identified?
  • Are high-risk vulnerabilities patched within 14 days?
  • How is firmware kept up to date?

The 14-day patching requirement is now a critical assessment point. 

Password and Authentication Controls

Questions now focus on:

  • Minimum password length
  • Password managers
  • Common-password blocking
  • Password less technologies and passkeys when used

Cyber Essentials v3.3 introduced a minimum 12-character password requirement in many scenarios. 

The effects of these changes will differ from company to company of course, many will already have much of this covered and some won’t.  Many will require guidance and assistance in making sure that they are prepared to what is now required, and that guidance will need to focus on how they need to change to meet the requirement.

But arguably the biggest operational issue is that CE now requires Owners/CEOs/Boards to certify that they will maintain the standard through its 12-month lifecycle, and not just at the point of certification.  That means monitoring their estate to maintain compliance, constantly, which in turn means having the means and resource to do it.  Not easy for many SMEs and they will be worried about cost.

The obvious answer though is a managed service.  SMEs often outsource their IT environment and see benefits in terms of cost and operational efficiency.  The same can be said for Cyber Security and monitoring, but the mindset tends to be different.  There is still the thought that their IT outsourcing company has this covered, or that cyber is a bit of black art and it will be expensive.

How does the H2 Service Help?

So, what does this service do that is so special?  Well, it will audit the 5 Cyber Essentials control areas, in some detail but it goes further.  Managing cyber security internally is a challenge.   With one out of two SMEs experiencing attacks, it’s clear that modern security requires continuous attention, as does cyber essentials compliance.  Threats can change daily and software needs continual updates.  Users need protection without friction and policies need to be enforced consistently.  Alerts need to be monitored, recognised and acted upon in real time.

Trying to manage all this internally means adding complexity, workload and risk.  Security should not compete with running a business and that is where a managed services makes a difference; by taking full operational ownership of cybersecurity, not just offering advice or tools.

Example of Multi Factor Authentication Detection

The service manages:

  1. Protecting user accounts and access, identifying who has admin privilege so that it can be revoked where it isn’t needed.
  2. Secure end points and devices, identifies operating system versions, anti-malware configurations, updates and alerts.
  3. Enforces security policies.
  4. Identifies cloud configurations and connections.
  5. Reduces risk from 3rd parties and shadow IT apps, identifying where 2FA is missing.
  6. Monitors threats and suspicious activity.
  7. It can monitor email boxes looking for phishing and ransomware, although that element is not strictly necessary for CE compliance.
Example of a client dashboard
Example of Cloud Share Data Detection

An added bonus is that it comes with phishing simulations to help train staff, and a comprehensive, automated, cyber awareness training package.

The system is powered by Agentic AI, although it has a human element, with the AI taking away the number crunching and hard work, leaving the human to identify what is, and what is not, real.  Using AI in this way enables us to keep the costs low, something very important to SMEs.

Small to Medium Businesses – Scammed or Hacked?

This is something that I’ve alluded to in the past, in other articles and blogs.  What is the likelihood of an SME suffering and Scam as opposed to a more technical hack.  There is a lot of evidence to suggest that, for most SMEs, the probability of suffering a scam/social engineering attack is significantly higher than experiencing a sophisticated technical hacking attack.

A useful rule of thumb from cyber insurance claims, law enforcement reporting, and incident response firms is:

  • 70–90% of financially damaging incidents affecting SMEs involve people being manipulated (phishing, invoice fraud, CEO fraud, business email compromise, fake suppliers, fake tech support, payment diversion, etc.).
  • 10–30% involve primarily technical exploitation (ransomware through unpatched systems, web application attacks, malware exploiting vulnerabilities, credential stuffing, etc.). 

But you can argue that ransomware is often a hybrid of the two, starting often with phishing for credentials, obtaining a login, and then inserting malware.

The exact percentages vary by industry and geography, but the pattern is remarkably consistent.

Why scams are more common

  1. Humans are easier to compromise than systems

A criminal can send 10,000 phishing emails in minutes at almost no cost.

Convincing one employee to:

  • Click a link
  • Approve a payment
  • Share credentials
  • Change bank account details

is often easier than discovering and exploiting a software vulnerability.

  •  SMEs usually have weaker business processes than technology

Many SMEs now use cloud services from companies like Microsoft⁠, Google Workspace⁠, and  Amazon Web Services⁠, which has improved their security.

However, they often lack:

  • Payment verification procedures
  • Supplier validation processes
  • Security awareness training
  • Segregation of financial duties
  • Generally inadequate security policies

      Criminals exploit these business-process weaknesses.

  • Criminals follow the money

A fake invoice scam may generate £20,000–£100,000 with little technical effort, whereas a sophisticated network intrusion might require:

  • Research
  • Malware development
  • Vulnerability exploitation
  • Persistence mechanisms

From an attacker’s perspective, scams often provide a better return on      investment.

  • Business Email Compromise (BEC) is extremely effective

One of the largest causes of SME losses is BEC:

  • Attacker gains access to an email account (often through phishing)
  • Watches conversations
  • Sends realistic payment instructions
  • Diverts funds

Technically, the breach may be simple, but the financial loss comes from deception rather than hacking.

Why technical attacks still matter

Technical attacks tend to receive more media attention because they can be highly disruptive.

Some examples are:

  • Ransomware
  • Server compromise
  • Website defacement
  • Data theft
  • Supply-chain attacks

Although less frequent than scams, a successful technical attack can have larger operational consequences:

  • Business downtime
  • Regulatory penalties
  • Customer notification costs
  • Recovery expenses

What an SME should prioritise

Most, if not all SMEs, will have a limited security budget, and therefore they need to identify the highest-return controls to mitigate their risk. These can include:

  • Multi-factor authentication (MFA) on all email and cloud accounts.
  • Staff training on phishing and payment fraud.
  • Verification procedures for bank account changes and large payments.
  • Strong backups and ransomware recovery testing.
  • Endpoint protection and automatic patching.
  • Monitoring for suspicious login activity.

These measures reduce both scam risk and many technical attack paths.  It’s aways worth remembering that scammers and hacker alike will take the path of least resistance.  The more difficult you make it for them, the more likely they are to look elsewhere.

A practical estimate

For a typical 20–250 person SME and for illustrative purposes, the distribution of financially damaging incidents based on common industry observations is 80 to 20 in favour of scams.

This is not a universal statistic, but it reflects what many cyber insurers, incident responders, and fraud investigators observe in practice, that is that SMEs are generally more likely to lose money because someone was tricked than because a hacker defeated sophisticated technical defences. The most damaging incidents often combine both, such as a phishing email that steals credentials and then enables fraud or ransomware.

Cyber Essentials – How has it changed?

I think these days, pretty much everyone is aware of the UK government-backed Cyber Essentials scheme and those who have undertaken certification or are considering it, will, in the last 12 months, have been subject to the introduction of the “Willow” question set (v3.2), which became the standard for certifications from 28 April 2025. It didn’t fundamentally change the five Cyber Essentials controls, but it did make several requirements more explicit and raised expectations around asset management, authentication, remote working, and vulnerability remediation. 

For most organisations, the Willow update was not a complete overhaul. The real shift is that Cyber Essentials is becoming:

  • More focused on asset visibility
  • More aligned with modern cloud environments
  • More accepting of passwordless security
  • More rigorous about vulnerability management
  • More realistic about hybrid and remote working

If your organisation already has mature inventory management, MFA, vulnerability remediation, and cloud governance processes, the changes are relatively straightforward. If not, these areas are where most compliance effort will now be concentrated. 

Key implications for organisations

Asset management is now much harder to ignore

A significant practical change was a stronger emphasis on maintaining a complete inventory of:

  • Devices
  • Software
  • Cloud services
  • Network equipment
  • BYOD assets used for work

Organisations now need a much better visibility of what is connected to their environment. For many SMEs, this means formalising asset registers rather than relying on informal spreadsheets or staff knowledge. 

The Implication being that certification becomes more difficult if you cannot prove what systems are in scope. This may mean investing in discovery and asset-management processes.

Firmware is now explicitly in scope

The definition of software has been expanded to include firmware on devices such as:

  • Firewalls
  • Routers
  • Network appliances

Previously, some organisations focused almost entirely on operating systems and applications. Now, neglected network-device firmware can become a compliance issue.  The implication being that patch management programmes need to include infrastructure devices, not just laptops and servers.

“Patches” became broader “vulnerability fixes”

Cyber Essentials no longer focuses only on installing vendor patches.

The new language recognises that vulnerabilities may be fixed through:

  • Configuration changes
  • Registry edits
  • Vendor scripts
  • Other remediation methods

The expectation is that vulnerabilities rated CVSS 7.0+ are addressed regardless of how the vendor delivers the fix.  Again, there is an implication that organisations need a vulnerability-management mindset rather than a simple patching mindset.

Passwordless authentication is now recognised

The Willow update formally acknowledges modern authentication methods such as:

  • Passkeys
  • Biometrics
  • Security keys
  • Authenticator push notifications

These can satisfy MFA requirements where implemented correctly. 

This is good news for organisations moving away from passwords. It aligns Cyber Essentials more closely with modern identity-security strategies and NCSC guidance on passkeys.  Frustratingly though, I worked with a client recently to obtain CE and the assessor didn’t know what a passphrase was and it had to be explained to him.

Remote working is treated more broadly

The terminology changed from “home working” to “home and remote working.”

That sounds minor, but it reflects a wider scope including:

  • Hotels
  • Cafés
  • Shared workspaces
  • Other untrusted networks

I’ve blogged about this quite a bit and security controls need to work wherever employees connect from, not just from a home office.  Does a VPN suffice, maybe but maybe not.

Greater scrutiny of Bring Your Own Device (BYOD)

Now organisations are expected to have:

  • Clear BYOD policies
  • Device security controls
  • User responsibilities documented
  • Appropriate protection such as encryption and screen locking

Informal BYOD arrangements can be riskier from both a compliance and security perspective.

V3.3 (“Danzell”)

As if that wasn’t enough NCSC has published v3.3 (“Danzell”) requirements effective from April 2026, which further tighten areas such as MFA and cloud-service requirements. Organisations that have only just adapted to Willow should already be reviewing the next revision to avoid another compliance scramble next renewal cycle. 

What changed in the Danzell question set?

The five Cyber Essentials control areas remain the same:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Security Update Management

However, Danzell asks more detailed and specific questions about how these controls are implemented and evidenced. 

Key themes covered by the Danzell questions

Multi-Factor Authentication (MFA)

The questionnaire now requires organisations to identify all cloud services in use and confirm MFA is enabled where available. Missing MFA on supported cloud services can result in an automatic failure. 

Typical questions include:

  • What cloud services are used?
  • Is MFA enabled for all users?
  • Are administrator accounts protected by MFA?
  • What authentication methods are used?

Cloud Service Scope

Danzell explicitly brings cloud services into scope, including:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Slack
  • Zoom
  • Cloud storage platforms

Organisations must declare these services and demonstrate appropriate security controls. 

Typical questions include:

  • Which cloud services store or process business data?
  • How are accounts managed?
  • How is access removed when users leave?

User Access Control

The questionnaire places greater emphasis on:

  • Administrative accounts
  • Privileged access management
  • Account lifecycle management

Typically questions include:

  • Are administrator accounts separate from standard user accounts?
  • How are privileged accounts controlled?
  • How are unused accounts identified and removed?

Industry discussions indicate auditors are applying the separate-admin-account requirement strictly. 

Security Update Management

Danzell asks for clearer evidence regarding:

  • Operating system patching
  • Application patching
  • Firmware updates
  • Patch deployment timescales

Applicants need to be able to identify:

  • How are vulnerabilities are identified?
  • Are high-risk vulnerabilities patched within 14 days?
  • How is firmware kept up to date?

The 14-day patching requirement is now a critical assessment point. 

Password and Authentication Controls

Questions now focus on:

  • Minimum password length
  • Password managers
  • Common-password blocking
  • Passwordless technologies and passkeys where used

Cyber Essentials v3.3 introduced a minimum 12-character password requirement in many scenarios. 

Structure of the questionnaire

The Danzell question set generally requires organisations to provide:

  • Asset inventories
  • Cloud service inventories
  • User account information
  • Details of security policies
  • Evidence of patch management processes
  • Details of MFA deployment
  • Administrative account controls

Assessors may ask follow-up questions if answers are unclear or inconsistent. 

What, typically, is the effect on SMEs?

This will change from company to company of course, many will already have much of this covered and some won’t.  Many will require guidance and assistance in making sure that they are prepared to what is now required, and that guidance will need to focus on how they need to change to meet the requirement.

But arguably the biggest operational issue is that CE now requires Owners/CEOs/Boards to certify that they will maintain the standard through its 12-month lifecycle, and not just at the point of certification.  That means monitoring their estate to maintain compliance, constantly, which in turn means having the means and resource to do it.  Not easy for many SMEs and they will be worried about cost.

The obvious answer though is a managed service.  SMEs often outsource their IT environment and see benefits in terms of cost and operational efficiency.  The same can be said for Cyber Security and monitoring, but the mindset tends to be different.  There is still the thought that their IT outsourcing company has this covered, or that cyber is a bit of black art and it will be expensive.

Let’s face it, the majority of SMEs aren’t going to try and hire cyber expertise full time, it would be expensive and unnecessary.  Having a managed service spreads cost and makes it affordable.  If you have a service that offers:

  • Continuous monitoring of endpoints, servers, and some cloud environments
  • Monitoring patching, including CVEs issued by vendors and comparing them against your estate
  • Vulnerability assessment
  • Rapid detection of ransomware, malware, insider threats, and advanced attacks
  • Expert-led response
  • Phishing simulations
  • Cyber awareness training programme
  • Dark web monitoring

Then you are a long way towards meeting the requirement for continuous monitoring and assessment, and if you can do this for £15-£18 per user per month, then it can be very affordable.

Stop Treating Cyber Security as an Overhead – Calculate the Cost of Doing Nothing

Cyber security is often seen as a cost centre, not a value driver.  That’s not just a problem for SMEs but that attitude is still often sound at a corporate level.  Within SMEs it’s not too rate to find it positioned as an insurance or compliance spend, not as something that enables trust, customer retention or business continuity.  Often there is no ownership at the top, no board pressure until something goes wrong.  If no one owns the risk, it stays floating below the surface.

We need to flip the mindset.  Cyber security needs to feel like it’s part of the core business and should be framed as:

  • Protecting revenue not systems.
  • Protecting customers not servers.
  • Protecting the ability to operate.

Cyber incidents must be seen as business stopping events, not just technical inconveniences.  Once that is recognised at the top, it tends to be moved into core business territory very quickly.

Measuring ROI (Return on Investment) in cyber security solutions is tricky because unlike traditional investments, the “return” often comes in the form of avoided losses, reduced risk, and improved resilience rather than direct revenue, and is often seen as proving a negative which produces a circular argument.  In the blue corner we have the bean counters saying we don’t need to spend much because we’ve never been attacked, and in the red corner we have the techies telling management that you haven’t been attacked because we have spent on protections.  There is often no meeting of minds until we frame it in business terms. There are well-established approaches.

Here’s how ROI in cybersecurity is typically measured:

Define the Investment (Costs)

This includes all direct and indirect costs of the cybersecurity solution:

  • Technology costs: licenses, hardware, software, cloud services.
  • Implementation costs: setup, integration, migration.
  • Operational costs: monitoring, maintenance, upgrades.
  • Personnel costs: training, staff time, additional headcount.
  • Third-party services: managed security providers, audits, compliance checks.

Estimate the Return (Benefits)

Returns are usually risk reductions and operational gains, such as:

  • Avoided breach costs:
    • Average cost of a data breach (detection, remediation, legal fees, fines, customer churn, downtime).
    • Likelihood (probability) of an attack succeeding without the solution.
  • Operational efficiency:
    • Fewer false positives, reduced downtime, less staff time spent on manual tasks.
  • Regulatory compliance:
    • Avoidance of fines and penalties.
  • Business continuity & reputation:
    • Reduced likelihood of lost customers and brand damage.

Cybersecurity ROI Calculator Template

This can get quite complex very quickly, so SMEs need to take from it what they need and discard the rest.  Be wary though that you understand what you need and what you don’t.  The best way of doing this is to carry out a risk assessment on the assets you are trying to protect.  Until you’ve done that the ROI will be almost impossible to predict.

If you need to understand the risk assessment procedure, then this short video will guide you:

Link   Cyber Resilience for SMEs: Navigating the Digital Wild West  synthesia.io  A short video describing cyber risk management and how SMEs should consider approaching this subject.

Once you have a good grasp of cyber risk management and you understand the threats and what you may need to do to protect yourself from those threats, then you can use this framework in Excel, Google Sheets, or whatever you use. The formulas are structured so you can plug in your own assumptions and automatically calculate:

  • Annualised cyber risk exposure
  • Risk reduction from controls
  • Expected financial savings
  • Total security investment
  • ROI %

Step 1 — Define Your Baseline Risk

Annual Expected Loss (AEL):

\text{Annual Expected Loss} = \text{Probability} \times \text{Financial Impact}

Example:

  • 20% × £500,000 = £100,000 expected annual loss

At the bottom:

| Total Baseline Risk Exposure | =SUM(D2:D5) |

Now clearly you need an understanding of the threat to assess the annual probability, and you need an understanding of how long it would take you to recover from that threat becoming a reality.  You may need advice or you may feel that you have sufficient information to make that calculation yourself.

Step 2 — Add Security Controls

Now estimate how much each cybersecurity investment reduces

Step 3 — Calculate Residual Risk

For each risk scenario:

Formula

Residual Risk:

\text{Residual Risk} = \text{Baseline Risk} \times (1 – \text{Risk Reduction})

Then total:

| Total Residual Risk | =SUM(D2:D5) |

In summary

Producing an ROI in cyber security is not easy and to do it you must pull together several different but related issues, starting with a good grasp of cyber risk management.  I know that when I suggest that you should get some help and guidance, I am often accused of just trying to drum up business, and OK, maybe that has a play, but by showing the calculations and what is required to identify those calculations, what I am actually trying to do is to show you that this isn’t easy and needs thought and a bit of work to achieve a good end result, which is to give leadership a financially justifiable reason for a cyber security spend.  ROI in cyber security is less about “profit” and more about quantifying avoided losses, improved efficiency, and reduced risk relative to the cost of controls.

CYBER ESSENTIALS HAS CHANGED:  ARE YOU READY?

Cyber Essentials has changed recently and one of the most significant changes, in my opinion is the requirement for a senior executive to formally declare that security controls are continuously assessed throughout the year.  A fundamental change, not just a paperwork tweak. It shifts accountability and how organisations approach compliance.

What does this change really mean?

  1. Accountability moves to the top

Executives (often a CEO, CFO, or board-level director) are now personally attesting that controls aren’t just “point-in-time compliant” but actively maintained. This raises the stakes, false declarations could have legal, reputational, and contractual consequences.

  • End of “annual checkbox” compliance

Previously, many organisations treated Cyber Essentials as a once-a-year exercise. This change pushes toward continuous assurance, more in line with standards like ISO/IEC 27001 or frameworks such as NIST Cybersecurity Framework.

  • Increased audit and insurance implications

Cyber insurers and regulators may view this declaration as evidence of due diligence or even negligence if something goes wrong. Expect more scrutiny if a breach occurs.

  • Cultural shift toward operational security

Security becomes an ongoing business process, not an IT task. It requires coordination across the company up to and including management.

How organisations can actually deliver “continuous assessment”?

This is where many companies will struggle, because the declaration implies evidence, not intention.

  1. Continuous monitoring of key controls

Use tools that provide ongoing visibility into:

  • Patch management status
  • Vulnerability scanning
  • Endpoint protection health
  • Firewall and access control configurations

Common tooling might include:

  • Endpoint detection & response (EDR)
  • Vulnerability management platforms
  • Security configuration monitoring tools
  • Defined control testing schedule

Not everything needs real-time monitoring, but you should have:

  • Monthly or quarterly control checks
  • Automated scans (minimum of weekly vulnerability scans)
  • Regular access reviews (e.g., user permissions)
  • Centralised logging and alerting

Implement:

  • An MDR solution.
  • Alerts for control failures (e.g., antivirus disabled, patch failures)

This creates an audit trail—critical if leadership is signing a declaration.

  • Metrics and reporting to leadership

Executives need evidence to sign confidently:

  • Security dashboards
  • KPIs (e.g., patch SLAs, vulnerability remediation times)
  • Regular security reports to the board
  • Policies backed by enforcement

It’s not enough to have policies; you need:

  • Technical enforcement (e.g., blocking unpatched devices)
  • Automated compliance checks
  • Internal audits or independent checks

Periodic internal reviews or external assessments that help validate that controls are actually working.

Practical example

Instead of saying:

“We apply patches”

You now need to demonstrate:

  • All devices report patch status daily
  • Alerts trigger if patches are overdue
  • Reports show compliance over time
  • Exceptions are tracked and approved

The real challenge

The hardest part isn’t technology, it’s evidence and governance.

Many SMEs certified under Cyber Essentials don’t currently have:

  • Centralised visibility
  • Documented control testing
  • Board-level security reporting

So, this change may force investment in:

  • Better tooling
  • Clearer processes
  • Stronger governance structures

Bottom line

This declaration effectively aligns Cyber Essentials with modern security expectations: continuous control validation, not annual self-assessment.

If an organisation can’t produce evidence of ongoing monitoring and review, executives are being asked to take a significant personal risk by signing.

How can an SME meet this requirement without breaking the bank?

You don’t need an enterprise SOC or a six-figure toolchain to meet these new expectations, but you do need joined-up tooling that produces continuous evidence.

The principle: “Good enough + visible + provable”

For an executive to sign the declaration, you must:

  • Cover all five control areas
  • Be centrally visible
  • Generate reports + alerts automatically
  • Require minimal manual effort

The issue for many SMEs that a system that integrates many of the issues simply hasn’t existed in a form that is financially viable, and that doesn’t require a dedicated cyber individual on staff, until now.  Such a system does now exist, and I have put up a short video on the features section of my profile page on LinkedIn, the link is A short video on protective monitoring for SMEs.  This should help you without having to read reams of information.  You will also find a couple of articles on that particular subject.

H2 provides affordable and flexible one-off and ongoing data protection and cyber risk protection services.

To learn more about the services we provide, please click here https://www.hah2.co.uk/

Alternatively, please feel free to give us a call or drop us an email:

M: 07702 019060

E: kevin_hawkins@hah2.co.uk

TARGET PROFILING AND SOCIAL ENGINEERING

I frequently share insights on the significance of Cyber Awareness Training and its critical role in helping organisations defend against cybercrime. Cyber awareness training is a vital aspect of contemporary security strategies for everyone. It provides employees with the essential knowledge and skills needed to identify, respond to, and reduce cyber threats. This training is particularly effective in combating social engineering.  It is arguably the quickest and cheapest measure an SME can implement to shore up their defences.

While many people are now familiar with the term social engineering, they may not fully understand its meaning. In the context of cybersecurity, social engineering involves manipulating, influencing, or deceiving individuals to gain unauthorised access to IT systems or to steal personal and financial information. It employs psychological tricks to lead users into making security errors or divulging sensitive data. The most prevalent form of social engineering is phishing.

Social engineering heavily relies on the six Principles of Influence identified by Robert Cialdini, a behavioural psychologist and author of “Influence: The Psychology of Persuasion.” These six principles are: Reciprocity, Commitment and Consistency, Social Proof, Authority, Liking, and Scarcity. Simply put, what these criminals seek is information, login credentials, passwords, names, phone numbers, and more. They are profiling your organisation to identify vulnerabilities, such as who manages accounts payable or whether you have an IT support company under contract that they could impersonate. In addition to phishing, they utilise various forms including vishing (voice phishing), smishing (SMS phishing), and simply calling to ask questions.

A rising threat that criminals are increasingly adopting is help desk social engineering tactics. In these schemes, attackers call an organisation’s IT help desk while posing as a legitimate employee, trying to convince the help desk agent to reset passwords or multi-factor authentication (MFA) for a specific account.

In recent years, these techniques have been used to access single sign-on (SSO) accounts and cloud-based application suites. Multiple criminals adopted this approach in 2024, targeting academic and healthcare institutions; in these cases, attackers utilised compromised identities to extract data from cloud-based software as a service (SaaS) application or alter employee payroll information.

It is important to keep in mind that profiling isn’t about technology.  Profiling uses social engineering techniques before it starts scanning your network for vulnerabilities.

Let’s now look at a scenario which we have entitled, The Helpful IT Contractor

Reconnaissance (Profiling the Target)

An attacker spends time gathering information about a mid-sized company:

  • Reviews employee profiles on LinkedIn
  • Identifies the IT helpdesk structure
  • Finds names of recent hires and projects
  • Notes that the company recently adopted a new cloud platform

The attacker now knows enough to sound convincing.

Initial Contact (Pretexting)

The attacker calls the finance department pretending to be:

“Hi, this is Alex from IT support. We’re fixing an issue with the new system rollout.”

They:

  • Use real employee names to build trust
  • Mention the actual cloud migration project
  • Create urgency: “We need to resolve this before payroll processing today”

Exploitation Attempt

The attacker asks the employee to:

  • Confirm their login details “for verification”
  • Install a “security patch” (malware)
  • Or approve a multi-factor authentication (MFA) request

If successful, the attacker gains:

  • System access
  • Credentials for lateral movement
  • Potential access to financial systems

How This Can Be Detected

Red Flags

  • Unexpected calls asking for credentials
  • Urgency or pressure (“must be done now”)
  • Requests that bypass normal IT procedures
  • Slight inconsistencies (email domain, phone number, tone)

Technical Indicators

  • Unusual login attempts (time/location anomalies)
  • Multiple MFA push requests
  • New software installation outside standard processes

How to Stop the Attack

People Controls

  • Train staff to:
  • Never share passwords or MFA codes
    • Verify identity via official channels
    • Challenge unusual requests—even from “IT”
    • Encourage a “pause and verify” culture

Process Controls

  • Enforce strict IT support procedures:
  • No credential requests via phone/email
  • All changes logged through a ticketing system
  • Require call-back verification using known numbers
  • Implement approval workflows for sensitive actions

Technology Controls

  • Multi-factor authentication (with number matching, not just push)
  • Endpoint protection to block unauthorized installs
  • Email and call filtering systems
  • Identity monitoring (detect unusual behaviour patterns)

Example of a Successful Defence

An employee receives the call but:

  • Refuses to share credentials
  • Reports the incident to IT/security/line manager
  • IT confirms no such request exists
  • Security team blocks the attacker’s number and flags related activity

Attack stopped before any damage.

Key Takeaway

Social engineering works by exploiting trust, urgency, and human behaviour—not technical vulnerabilities.  The strongest defence is a combination of:

  • Aware people
  • Clear processes
  • Enforced technology controls

Cyber Awareness training isn’t a nice to have, it’s essential  Your staff can be a very effective first line of defence, or they can be your biggest weakness.  Such training is an iterative process; it should be done on induction and then at regulator intervals through the year.  It is not a fire and forget process.

This training doesn’t need to be costly; it can be delivered face-to-face, online, or through automated means. At H2, we offer all these options! Regardless of your choice, please consider this training an essential component of your strategy.

If you’d like more information on this topic, let’s chat!

Ransomware 101:  What Every SME Needs to Know

Ransomware is something that we tend to only hear about when it hits the news, usually referring to an attack on a major corporate organisation or a government body.  But it’s happening to a much wider range of businesses, and it tends to be a very much under-reported issue, particularly when it affects SMEs, which it does more often than you’d think. In a post last week, I referred to the attack on Knights of Old, a mid-sized transport company which was taken down in a very short space of time by a ransomware attack, from which they never recovered.  I wrote a piece a couple of months ago which highlighted the issue of under-reporting.  I won’t regurgitate it here, but if you want to read up on it, the link is Under-reported security incidents.

Overall, SMEs are particularly vulnerable because they often lack robust cybersecurity resources and recovery capabilities. A ransomware attack can have severe and often disproportionate impacts on small or medium-sized businesses:

  • Operational disruption: Critical systems and data become inaccessible, halting day-to-day business activities.
  • Financial loss: Costs may include ransom payments, recovery expenses, lost revenue, and potential regulatory fines.
  • Data loss or exposure: Sensitive customer or business data may be encrypted, stolen, or leaked.
  • Reputational damage: Loss of customer trust can lead to reduced sales and long-term brand harm.
  • Legal and compliance risks: Breaches of data protection laws (i.e. GDPR) can trigger investigations and penalties.
  • Business continuity risk: In severe cases, prolonged downtime can threaten the survival of the business.

Let’s now use a scenario to illustrate the problem.  The scenario is fictitious but has been constructed from real events.

It started like an ordinary Tuesday morning for BrightLane Logistics, a 45-person SME based just outside Manchester. They specialised in same-day delivery for local retailers, and their entire operation depended on a cloud-based booking system, a small internal server, and a handful of laptops used by dispatchers and drivers.

The Entry Point

At 9:12 AM, Sarah, a finance assistant, received what appeared to be a routine email from a known supplier. The message referenced an overdue invoice and urged her to review an attached document. The email address looked legitimate at a glance, just one letter off from the real domain.

Busy and under pressure, Sarah downloaded the attachment: “Invoice_April2026.xlsm.”

When she opened it, nothing obvious happened, just a blank spreadsheet and a prompt to “Enable Content.” She clicked.

That single action executed a hidden macro. Within seconds, a small piece of malicious code connected to a remote server and quietly installed ransomware on her machine.

Attackers do their homework.  They will have spent time profiling this company and its staff.  They will have researched them on Companies House, seen their last financial postings, and will have carried out various innocuous social engineering exercises to discover who does what within the company, and who their suppliers and customers are.  They maximise the chance of an employee clicking the link in the email.

The Spread

Because BrightLane had weak internal network segmentation and shared admin credentials across several systems, the malware didn’t stay contained. It harvested saved passwords from Sarah’s machine and moved laterally across the network.

By lunchtime:

  • The shared file server was infected
  • The dispatch system was compromised
  • Backup drives connected to the network were also encrypted

No alarms were triggered.  BrightLane had basic antivirus, but no advanced detection or monitoring tools.

The Detonation

At 2:03 PM, screens across the office flickered.

Files began changing names. Systems slowed to a crawl. Then everything locked.

A message appeared:

“Your files have been encrypted.

To regain access, pay X Bitcoin within 72 hours.

After that, your data will be permanently deleted.”

Phones started ringing immediately. Drivers couldn’t access delivery routes. Customers couldn’t place orders. The warehouse team had no visibility of scheduled shipments.  Operations ground to a halt.

The Immediate Consequences

Within hours:

  • All deliveries stopped
  • Customer service was overwhelmed
  • Financial systems were inaccessible
  • Staff were sent home early

The managing director, Tom, faced a brutal reality: the company could not operate.

They contacted their IT support provider, but it quickly became clear:

  • Backups were unusable (they had been encrypted too)
  • No incident response plan existed
  • Recovery could take weeks, if at all possible

The Decision Point

The ransom demand equated to roughly £120,000.

Paying it came with no guarantee of recovery as well as potential legal and ethical implications. Not paying meant:

  • Permanent data loss
  • Severe operational disruption
  • Potential business closure

Meanwhile, the attackers escalated pressure by threatening to leak sensitive customer data.

The Longer-Term Impact

Over the following weeks:

Financial Damage

  • Lost revenue from halted operations
  • Cost of external cybersecurity experts
  • Legal and regulatory compliance expenses

Reputational Harm

  • Customers lost trust
    • Key clients moved to competitors

Regulatory Consequences

  • A data breach investigation was triggered
    • Potential fines for failing to protect customer data

Internal Fallout

  • Staff morale dropped sharply
    • Leadership faced scrutiny over the lack of preparedness

The Aftermath

BrightLane eventually chose not to pay the ransom. They rebuilt their systems from scratch, but it took nearly a month to resume partial operations.

By then:

  • 30% of their customer base was gone
    • Cash reserves were severely depleted
    • The company had to downsize

The Lesson

The attack didn’t rely on sophisticated zero-day exploits.  This wasn’t one failure; it was a chain of small, common weaknesses, which, taken together, created a complete business shutdown:

  • One phishing email
  • One click
  • One flat network
  • One set of shared credentials
  • One poorly designed backup system

For BrightLane, the ransomware attack wasn’t just an IT issue; it became an existential business crisis.

SMEs can’t do everything, and if I were to prioritise measures that could produce the biggest risk reduction, taking into account limited budgets, I would recommend the following:

  • MFA everywhere (especially email & admin accounts)
  • Offline/immutable backups
  • Cyber Awareness training for staff and managers
  • EDR instead of basic antivirus
  • Remove shared admin credentials
  • Network segmentation (even simple VLANs)
  • Some form of managed detection and response

Don’t think it won’t happen to you.  It can and does happen to SMEs in the UK, many of whom pay up and don’t report it.  I understand why they do this, but it doesn’t help the overall problem, as it disguises the frequency and the damage done.  It’s much cheaper in the long run to take preventative action than it is to try to recover once it’s happened.

H2 provides affordable and flexible one-off and ongoing data protection and cyber risk protection services.

To learn more about the services we provide, please click here https://www.hah2.co.uk/

Alternatively, please feel free to give us a call or drop us an email:

M: 07702 019060

E: kevin_hawkins@hah2.co.uk

Trust H2 – Making sure your information is secure

Watch, Detect, Protect:  Detecting Cyber Attacks Before They Start

Imagine a small business owner who runs a 25-person company providing financial services to firms and individuals. He knows cyber threats are “a thing,” and in fact, one of his customers required basic security controls before signing a contract. And so, he took advice from his network provider, a local IT reseller, and he purchased a bundle: antivirus software, a firewall appliance, and a cloud backup service.

From his perspective, everything seems covered:

  • The antivirus dashboard shows green checkmarks.
  • The firewall has flashing lights and a web interface that he never logs into.
  • The backup system sends a weekly email saying, “Backup completed successfully.”

But here’s the reality:

He has no meaningful way to tell if any of this is actually protecting him.

A few subtle issues are happening behind the scenes:

  • The antivirus hasn’t detected anything, not because threats aren’t present, but because it’s misconfigured and only running quick scans.
  • The firewall rules were set up once by the reseller and never reviewed; several unnecessary ports are still open.
  • Backups are completing, but no one has ever tested restoring them, so they may be incomplete or unusable.
  • Staff occasionally click phishing emails, but those incidents go unnoticed because there’s no monitoring or reporting in place.
  • He doesn’t have a clear idea of what data he is holding and what that data may reasonably be classified as, i.e. highly sensitive or sensitive, or not sensitive at all.  Neither does he really have an idea who has access to what, either at a user level or worse, at an administrator level.

One day, an employee unknowingly installs malware from a phishing link. The attacker gains access to the company’s systems and quietly exfiltrates sensitive client data over several weeks.

Throughout this entire period:

  • No alerts reach any level of management in a way they understand.
  • No KPI or metric tells them, “You are under attack”, or even “your defences are being exercised.”
  • The tools continue to report “all good” because they are measuring activity (i.e., scans completed), not effectiveness (i.e., attacks prevented).
  • He assumes that “no news is good news.” In reality, he’s operating in a visibility gap:
  • He doesn’t know what “normal” vs “suspicious” looks like.
  • He has no baseline metrics (i.e., number of blocked threats, phishing simulations, patch status).
  • He lacks independent validation (like audits, vulnerability assessments, or even simple security reports translated into business terms).

So, when a client later informs him of a data breach traced back to his company, it’s a complete shock. From his perspective, he did everything right; he bought the tools. But he never had a way to measure whether those tools were correctly configured, actively working, or aligned to real threats.

This is a common SME problem: security is treated as a one-time purchase rather than an ongoing, measurable process. Without clear, understandable metrics or external validation, the owner is essentially flying blind, relying on reassuring dashboards instead of actual evidence of protection.

The question then becomes what can an SME do to protect itself from these issues.  The first problem is to recognise that they don’t have any in-house resource that can deal with these problems, and neither can they afford such a resource. At best, their IT systems are overseen by someone who has another primary function and hasn’t got much time to deal with IT issues, has no technical background, much less a cybersecurity background, and whose responsibility lies with liaising with their network provider. 

Now, let’s deal with the network provider that supplied the security tools.  These companies work to Ts&Cs that will concisely lay down what services they provide under any network maintenance contract.  Such contracts may include administration of the network, adding and taking away access rights, or they may just refer to routine maintenance and troubleshooting.  Whatever it is, an SME must have a clear understanding of what those Ts&Cs say.  You may be under the impression that they are covering things that they simply aren’t.  This is often the case with cybersecurity.  This is because they themselves don’t have a handle on how cybersecurity hangs together. They concentrate on supplying products such as firewalls and AV, and on how to install and configure such products.  They may also handle AV updates, and in that case, you need to be very clear about how they do that and how they assure you that it is done.

Be clear, I’m not denigrating these companies or the services they supply, simply pointing out that they work to strict service levels as laid down in the contract and will often not step outside of these.

To sum up, we are now at the point where we recognise that SMEs in general do not have a handle on how effective their security actually is, on where their sensitive data sits and how it’s accessed and handled.  They don’t have anyone on staff who has an understanding of cybersecurity, and there is a good chance that their network contract doesn’t include any sort of security monitoring and alerting.  The question now becomes, is there anything they can do about it?

Until quite recently, what we called protective monitoring, which is now more formally called Managed Detection and Response, along with Data Loss Prevention Systems, were very much out of reach of an SME on financial terms, and as such the majority of SMEs didn’t just not invest in them, they never really knew about them because the corporate level providers, never pitched to them because they knew they couldn’t afford it.

There are now systems on the market, AI-driven, that have managed to hit a price point that an SME can afford.  These systems may not be as comprehensive as you might find in a large company or central government department, but they do match the requirements for most SMEs.  You don’t need to understand AI; it’s built into the system and operates seamlessly.  What it does is to allow one operator to manage multiple clients at the same time, because the AI does the heavy lifting.  In this way, not only is the system itself affordable, but the managed service it supports also becomes affordable.

To maximise its cost effectiveness, it has additional capabilities such as vulnerability assessment, phishing simulations and cyber awareness training programmes, making it more attractive.  The whole package needs to emulate enterprise-grade protection without the cost and complexity of a full-blown Security Operations Centre (SOC).  Delivering it as a service reduces cost by cutting out the need for an in-house team.

In a nutshell, an SME would want this system because it delivers near enterprise-level cybersecurity protection, reduces business risk, improves compliance, and protects revenue without needing an internal cybersecurity department.  It provides peace of mind; you don’t have to worry about this, let someone else take the strain, while you focus on your business.

To help explain this easily, I have produced a very short video which you can find on the Features Section on my LinkedIn profile.   But if you don’t want to view that, what follows is an introduction to what the service offers.

  • Continuous monitoring of endpoints, servers, and some cloud environments
  • Rapid detection of ransomware, malware, insider threats, and advanced attacks
  • Expert-led response
  • Phishing simulations
  • Cyber awareness training programme
  • Dark web monitoring
  • Auditing your data, identifying what is sensitive and what isn’t; providing file-level encryption and tracking data movements around your network and where it goes when sending it to outside agencies.

In short, it provides the business benefit of reduced risk of downtime, data loss, and reputational damage.

This service comes with vulnerability assessment built into it.  Such assessments are available elsewhere as both software and a service, but they would not be integrated into an overall protection, would come at additional cost, and would need to have a level of expertise to interpret the results.

Vulnerability assessments:

  • Identify outdated software, misconfigurations, and exposed services
  • Prioritise risks based on severity
  • Provide remediation guidance

Most breaches happen because of known, unpatched vulnerabilities. Regular scanning helps prevent attacks before they happen. It is a proactive risk reduction instead of reactive damage control.

The system also offers built-in protection against human error (Phishing Simulation).

Over 80–90% of cyber breaches start with phishing. A phishing simulation programme:

  • Test employee awareness safely
  • Identifies high-risk users
  • Reinforces learning through practical scenarios

It helps reduce successful phishing attacks and reduces the likelihood of credential compromise or ransomware infection.  Such simulations are an integral part of cyber awareness training.

The system also assists in building a security culture (CBEE Awareness Training Programme).  A structured awareness programme:

  • Trains staff on cyber hygiene and data protection
  • Covers password security, social engineering, safe browsing, and more.
  • Assists compliance with regulations (GDPR, ISO 27001, Cyber Essentials, etc.)

Cybersecurity isn’t just technology, it’s behaviour. Training reduces internal risk significantly and turns employees from a security liability into a security asset.

A managed system such as this can also help with compliance & insurance requirements.  Many SMEs now face:

  • Regulatory obligations
  • Supply chain security requirements
  • Cyber insurance conditions

Having a managed service, vulnerability management, and training demonstrates due diligence and can reduce insurance premiums or improve insurability.

These last 2 points are very important to an SME:  Cost Predictability & Simplicity.  As a managed service, everything is:

  • Subscription-based
  • Centralised under one provider
  • Fully supported by trained personnel

No need to buy multiple tools, manage updates, or maintain in-house expertise.

In business terms, you are getting executive-level risk reduction with a simple value:

  • Reduced likelihood of business interruption
  • Reduced financial exposure
  • Protection of brand and customer trust
  • Clear reporting and measurable risk reduction

All through this article, I’ve talked about cost-effectiveness.  So, what does this service cost?  I’ll add the BBC caveat – other systems are available!!  We charge £15 per seat per month for the technical system and £15 per seat per month for the data leakage protection system. Discounts are available for clients who take both systems, and you get a lot for your money.  It’s a 30-day rolling contract, no long-term lock-in, simply 30 days’ notice to quit.  We also offer a totally free 14-day trial that is fully functional, so you can see the outputs from your own system, rather than look at demos with dummy data.

Scroll to top