The Disciplines Plate IV Cybersecurity
Cybersecurity.
Security that doesn't get in the way of the work.
Posture reviews, hardening, secrets management and monitoring, scaled to the size of the business and what it has to protect.
Return to the workshopGood security for a small business is mostly unglamorous: patched machines, MFA, sound backups and email that can't easily be spoofed. I concentrate on measures like those, chosen so the people using the systems every day barely notice them.
I won't try to frighten you into buying things you don't need, and I won't present Cyber Essentials as a complete security programme. You get controls that suit your size, your industry and the risks you face, from someone who has spent two decades inside security organisations and holds an MSc in the discipline.
§ What I protect
-
I.
Infrastructure security
Server hardening, firewall configuration, intrusion detection, automated patching and vulnerability scanning, aimed at the weaknesses attackers use most often.
-
II.
Application security
Secure coding, input validation, protection against SQL injection and XSS, and careful authentication and session handling. Security is part of the design from the start.
-
III.
Access control
MFA, password policies that don't drive people to post-its, role-based access and least privilege, so each person reaches what their job needs and nothing else.
-
IV.
Data protection
Encryption at rest and in transit, secure backups, retention policies, and GDPR compliance where it applies, for your own data and your customers'.
-
V.
Email security
SPF, DKIM and DMARC set up correctly, with spam filtering, phishing protection and a secure gateway. Business email compromise is one of the most common ways in, and I close it.
-
VI.
Security monitoring
Log analysis, intrusion and anomaly detection, and alerts tuned so they fire when something matters. I watch for suspicious activity and respond before an incident becomes a breach.
§ The approach
-
Step 1
Security assessment
I look at where you stand now: what you are protecting, which threats are realistic and where the gaps are. The plan is built from that.
-
Step 2
Risk-based priorities
Some risks matter far more than others, so I rank them by how likely they are and how much damage they would do. The budget goes to what is valuable and exposed first.
-
Step 3
Implementation
Controls go in one at a time and in order: technical ones like firewalls and encryption, written policies and procedures, and physical measures where they are relevant. Each layer covers for the others.
-
Step 4
Training & awareness
Your staff are the first line of defence, so I train them to spot phishing, handle passwords safely and report anything suspicious.
-
Step 5
Ongoing monitoring
Monitoring carries on after the work is done, with regular updates and periodic reviews as new threats appear.
-
Step 6
Incident response
If something does happen, there is a written plan: what to do, who to call and what to tell people.
Questions, answered
We are small. Is this really necessary?
Yes. Most attacks are automated and don't check how big a company is before they try. What you don't need is enterprise tooling at enterprise prices, which is why the work is sized to the business.
Can you help us get Cyber Essentials?
Yes. Old Forge holds Cyber Essentials itself. Most of the work is getting your systems to the point where every answer on the questionnaire is true. Filling it in is the easy part.
What will it cost?
The prices on this page are starting points, so you can tell in a minute whether you are in the right range. Each job is then quoted after a conversation, because the price depends on the shape of the job and nobody knows that yet. The first half hour is free, and it usually settles whether this is a small piece of work or a large one before any money is discussed.
Who owns the code when it is finished?
You do, outright, including the source. It is handed over with the runbooks needed to keep it running, and there is no licence to renew and no seat to pay for. Where this page quotes a monthly figure, that pays for hosting or ongoing support, which is optional and can be stopped without taking anything away from you. Commissions, not subscriptions, is meant literally.
What happens if you are unavailable?
Everything is built so somebody else could pick it up: common technologies, readable code, written runbooks and nothing proprietary. It is a fair question to ask of a one-person business, and the answer is in how the work is built.
Do you work outside Suffolk and Cambridgeshire?
Yes. Local work gets the option of somebody in the room, which is worth more than it sounds for the first conversation and the handover. Everything after that is done remotely for most clients anyway.