The Disciplines Plate IV Cybersecurity
Cybersecurity.
Security that protects without getting in the way.
MSc-level cyber, applied with a light hand. Posture reviews, hardening, secrets management, monitoring - the kind of security that fits the scale of the business, not the anxiety of the vendor.
Return to the workshopCybersecurity doesn't have to be complicated or expensive - but it does have to be effective. I focus on practical measures that protect your business without creating friction for the people who actually have to use the systems every day.
No scare tactics. No selling you things you don't need. No framing "Cyber Essentials" as a complete security program. Just sensible controls appropriate for your size, your industry, and your real risk profile - delivered by someone who's spent two decades inside security organisations and holds an MSc in the discipline.
§ What I protect
-
I.
Infrastructure security
Secure server configuration, properly configured firewalls, intrusion detection, automated patching, vulnerability scanning. Your infrastructure hardened against the common attack vectors that actually get exploited.
-
II.
Application security
Secure coding practices, input validation, protection against SQL injection and XSS, proper authentication and session management. Applications built with security assumed from day one.
-
III.
Access control
MFA, password policies that don't drive people to post-its, role-based access, least privilege. The right people with the right access - and nobody else.
-
IV.
Data protection
Encryption at rest and in transit, secure backups, retention policies, GDPR compliance where required. Your data - and your customers' data - protected properly.
-
V.
Email security
SPF, DKIM, DMARC configured correctly. Spam filtering, phishing protection, secure gateway setup. Business email compromise is one of the most common routes in - I close it.
-
VI.
Security monitoring
Log analysis, intrusion detection, anomaly detection, alerts tuned to matter. I watch for suspicious activity and respond before incidents become breaches.
§ The approach
-
Step 1
Security assessment
Evaluate your current posture. What are you protecting? What are the realistic threats? Where are the gaps? Forms the foundation of a practical plan - not a vendor's wish list.
-
Step 2
Risk-based priorities
Not all risks are equal. I prioritise by likelihood and impact. Resources go to protecting what's actually valuable and vulnerable - not to ticking boxes nobody reads.
-
Step 3
Implementation
Deploy controls systematically - technical (firewalls, encryption), administrative (policies, procedures), physical where relevant. Layer defences for depth.
-
Step 4
Training & awareness
Your team is the first line of defence. Practical training on phishing recognition, secure password practices, reporting suspicious activity. Security becomes everyone's concern.
-
Step 5
Ongoing monitoring
Not set-and-forget. Continuous monitoring, regular updates, periodic reviews, adaptation to new threats.
-
Step 6
Incident response
If something does happen, I have a plan. Documented procedures, clear escalation paths, communication protocols. Hope for the best, prepare for the worst.
Questions, answered
We are small. Is this really necessary?
Small businesses are targeted because they are small, not in spite of it - attacks are automated and do not check the size of the company first. What is not necessary is enterprise tooling at enterprise prices; the point is security at the scale of the business.
Can you help us get Cyber Essentials?
Yes, and it is a certification this workshop holds itself. Most of the work is getting the estate into a state where the answers are true, rather than filling the questionnaire in.
What does a commission cost?
Work is quoted per commission, after a conversation. There is no day rate to quote at you and no package to fit into, because the shape of the job decides the price and nobody knows the shape yet. The first half hour is free, and it usually settles the question of whether this is a small piece of work or a large one before any money is discussed.
Who owns the code when it is finished?
You do. Outright, including the source. It is handed over with the runbooks needed to keep it running, and there is no licence to renew and no seat to pay for. Commissions, not subscriptions, is meant literally.
What happens if you are unavailable?
Everything is built to be picked up by somebody else: ordinary technologies, readable code, written runbooks and no proprietary lock-in. It is a fair question to ask a one-person workshop, and the answer has to be in the work rather than in a promise.
Do you work outside Suffolk and Cambridgeshire?
Yes. Local work gets the option of somebody in the room, which is worth more than it sounds for the first conversation and the handover. Everything after that is done remotely for most clients anyway.