CYBER SECURITY
Security that's built into your IT support, not sold on top of it
Ask most businesses to walk you through their security strategy, and they cannot. They know they have antivirus, a firewall, and some other things somebody set up.
That is not a criticism; it is what happens when nobody senior owns it. What follows is what we do about that, on every client, as standard.
THE STANDARD
Sixteen controls, on every client
Not a list of recommendations - a list of things that are configured, monitored and kept that way. Every FireLight client runs on the same standard from the first month.
DEVICES
Disk encryption enforced on every company machine - BitLocker on Windows, FileVault on Mac - with the recovery key escrowed where we can retrieve it, and an alert to us if encryption is ever turned off
Standard users do not run as local administrators
Operating system patching on a managed schedule, Windows and macOS alike
Third-party application patching, because that is where most of the unpatched risk actually sits
Endpoint protection deployed and monitored, with alerts coming to us
Unsupported operating systems identified and replaced before they become a liability
IDENTITY
Multi-factor authentication enforced on every account, staff and administrators alike, with app-based approval as the default
Legacy sign-in methods blocked, so old protocols cannot be used to get around it
Administrator accounts kept separate from everyday accounts, and the number of full administrators kept to a minimum
A documented, secured emergency access account, so nobody is ever locked out of their own tenant
External sharing and guest access reviewed and set deliberately rather than left at the default
Self-service password reset, so a forgotten password is not a support ticket
Conditional access policies enforcing multi-factor authentication and blocking legacy sign-in, rather than relying on Security Defaults
EMAIL AND DATA
Mailbox forwarding and inbox rules monitored, because changing them is one of the first things an attacker does
Email authentication configured - SPF, DKIM and DMARC
Microsoft 365 backup specified and managed by us, held in an account in your name, with restores tested quarterly and the evidence kept
On the Secure level we add security awareness training for every member of staff, simulated phishing on a schedule, dark web credential monitoring, patch assurance reported against the fourteen-day Cyber Essentials rule, a review of the third-party apps and AI tools your staff have connected, and a written benchmark every quarter - the same assessment we give prospects, re-run on your tenant.
We hold Cyber Essentials Certification ourselves. We think a provider that sells a security standard should be willing to be measured against one.
SUPPLY CHAIN
Your backup is in your name, not ours
A question worth asking any IT provider: if somebody compromised your systems, how many of your clients would they reach?
For most providers, the honest answer is all of them. It is common practice for an IT company to store every client's Microsoft 365 backup in one account it owns and bills on, convenient, right up to the point where a single stolen administrator login reaches every business on its books.
Attacking the supplier to reach customers is now one of the most common patterns, and it is why new UK legislation is being written specifically around managed service providers.
We do it the other way round. We create your backup account in your name, on your invoice, and restrict it so it can only be accessed from our systems and your office. We specify it, configure it, manage it and test the restores, but it is yours; it is separate from every other client's, and nobody working through our credentials gets to all of it at once.
The same is true of your Microsoft 365 subscriptions and your tenant. We manage them; you own them.
WORTH UNDERSTANDING
Multi-factor authentication is no longer the finish line
Attackers have stopped guessing passwords. The pattern we see now starts with an ordinary-looking email - an invoice, an HR notice, a voicemail notification and moves the recipient somewhere a security control cannot follow.
One current campaign sends a Word document appearing to come from the recipient's own HR department, containing nothing but a QR code. There is no link to hover over and no text for a filter to read. Scanning it moves the user to their personal phone, away from the managed device, the web filtering, and the monitoring, where a proxy in the middle captures the password, the session cookie, and the multi-factor response together.
The result is a fully compromised Microsoft 365 account with multi-factor authentication switched on the whole way through.
Which is why the controls above aren’t a list of products. They work as a set: the device has to be known, the sign-in has to come from somewhere plausible, the session cannot live forever, the administrator account is not the everyday account, and if a mailbox rule changes, we hear about it.
YOUR PEOPLE
Your people are part of this, and they are not the problem
At the Secure level, every staff member gets short, regular security training rather than an annual lecture, plus periodic simulated phishing so you find out who clicks before someone else does.
You get a summary report; we follow up with people who haven't completed it, so you don't have to.
Where most businesses actually stand
The government's Cyber Security Breaches Survey, published in April 2026, found that 46% of businesses with ten to forty-nine staff had experienced a breach or attack. Among those affected, 69% said phishing was the most disruptive thing they faced.
The same survey found that only 12% of small businesses hold Cyber Essentials certification, only 19% have run any staff security training, only 25% have a written incident response plan, and only 15% have checked the cyber risk of their own suppliers.
We mention those numbers not to alarm anybody but to make a point about proportion. Most businesses your size are not doing this. It is not expensive or disruptive to be one of the ones that are.
