CYBER SECURITY

Security that's built into your IT support, not sold on top of it

Ask most businesses to walk you through their security strategy, and they cannot. They know they have antivirus, a firewall, and some other things somebody set up.

That is not a criticism; it is what happens when nobody senior owns it. What follows is what we do about that, on every client, as standard.

THE STANDARD

Sixteen controls, on every client

Not a list of recommendations - a list of things that are configured, monitored and kept that way. Every FireLight client runs on the same standard from the first month.


DEVICES

  • Disk encryption enforced on every company machine - BitLocker on Windows, FileVault on Mac - with the recovery key escrowed where we can retrieve it, and an alert to us if encryption is ever turned off

  • Standard users do not run as local administrators

  • Operating system patching on a managed schedule, Windows and macOS alike

  • Third-party application patching, because that is where most of the unpatched risk actually sits

  • Endpoint protection deployed and monitored, with alerts coming to us

  • Unsupported operating systems identified and replaced before they become a liability

IDENTITY

  • Multi-factor authentication enforced on every account, staff and administrators alike, with app-based approval as the default

  • Legacy sign-in methods blocked, so old protocols cannot be used to get around it

  • Administrator accounts kept separate from everyday accounts, and the number of full administrators kept to a minimum

  • A documented, secured emergency access account, so nobody is ever locked out of their own tenant

  • External sharing and guest access reviewed and set deliberately rather than left at the default

  • Self-service password reset, so a forgotten password is not a support ticket

  • Conditional access policies enforcing multi-factor authentication and blocking legacy sign-in, rather than relying on Security Defaults

EMAIL AND DATA

  • Mailbox forwarding and inbox rules monitored, because changing them is one of the first things an attacker does

  • Email authentication configured - SPF, DKIM and DMARC

  • Microsoft 365 backup specified and managed by us, held in an account in your name, with restores tested quarterly and the evidence kept

On the Secure level we add security awareness training for every member of staff, simulated phishing on a schedule, dark web credential monitoring, patch assurance reported against the fourteen-day Cyber Essentials rule, a review of the third-party apps and AI tools your staff have connected, and a written benchmark every quarter - the same assessment we give prospects, re-run on your tenant.

We hold Cyber Essentials Certification ourselves. We think a provider that sells a security standard should be willing to be measured against one.

SUPPLY CHAIN

Your backup is in your name, not ours

A question worth asking any IT provider: if somebody compromised your systems, how many of your clients would they reach?

For most providers, the honest answer is all of them. It is common practice for an IT company to store every client's Microsoft 365 backup in one account it owns and bills on, convenient, right up to the point where a single stolen administrator login reaches every business on its books.

Attacking the supplier to reach customers is now one of the most common patterns, and it is why new UK legislation is being written specifically around managed service providers.

We do it the other way round. We create your backup account in your name, on your invoice, and restrict it so it can only be accessed from our systems and your office. We specify it, configure it, manage it and test the restores, but it is yours; it is separate from every other client's, and nobody working through our credentials gets to all of it at once.

The same is true of your Microsoft 365 subscriptions and your tenant. We manage them; you own them.

WORTH UNDERSTANDING

Multi-factor authentication is no longer the finish line

Attackers have stopped guessing passwords. The pattern we see now starts with an ordinary-looking email - an invoice, an HR notice, a voicemail notification and moves the recipient somewhere a security control cannot follow.

One current campaign sends a Word document appearing to come from the recipient's own HR department, containing nothing but a QR code. There is no link to hover over and no text for a filter to read. Scanning it moves the user to their personal phone, away from the managed device, the web filtering, and the monitoring, where a proxy in the middle captures the password, the session cookie, and the multi-factor response together.

The result is a fully compromised Microsoft 365 account with multi-factor authentication switched on the whole way through.

Which is why the controls above aren’t a list of products. They work as a set: the device has to be known, the sign-in has to come from somewhere plausible, the session cannot live forever, the administrator account is not the everyday account, and if a mailbox rule changes, we hear about it.

YOUR PEOPLE

Your people are part of this, and they are not the problem

At the Secure level, every staff member gets short, regular security training rather than an annual lecture, plus periodic simulated phishing so you find out who clicks before someone else does.

You get a summary report; we follow up with people who haven't completed it, so you don't have to.

Where most businesses actually stand

The government's Cyber Security Breaches Survey, published in April 2026, found that 46% of businesses with ten to forty-nine staff had experienced a breach or attack. Among those affected, 69% said phishing was the most disruptive thing they faced.

The same survey found that only 12% of small businesses hold Cyber Essentials certification, only 19% have run any staff security training, only 25% have a written incident response plan, and only 15% have checked the cyber risk of their own suppliers.

We mention those numbers not to alarm anybody but to make a point about proportion. Most businesses your size are not doing this. It is not expensive or disruptive to be one of the ones that are.