Security wears several hats: keeping people out, spotting anyone who gets in, getting you running again afterward, and proving all of it to a carrier or a client. Most go unchecked until it is too late.
Monitoring and response. Who is on shift at three in the morning, and what happens after an alert fires. Open this if nothing has gone wrong yet and you want to know whether you would hear about it before Monday.
Ransomware and recovery. A copy nobody can delete, a full restore somebody has timed on your own equipment, and the order the first forty-eight hours have to run in. Open this if the question keeping you up is what Tuesday looks like after a bad Monday.
Cyber insurance readiness. The controls a carrier checks before it will renew you, and the answers on your last application that may quietly have stopped being true. Open this if a renewal or a client security questionnaire has a date against it.
The JOUST assessment. A paid written review of the whole picture, ending in a priced list of what to fix first. Open this if you cannot yet tell which of the three above is your actual problem, or if you need something a board or a carrier will read.
Sophos surveyed 2,158 leaders across seventeen countries for its State of Ransomware 2026 report and found 79 percent of attacks began with a compromised identity. Somebody signed in as your staff. So the work here is unglamorous and it comes first: multifactor on every account including the ones nobody remembers creating, administrator rights handed out for a task and taken back after, shared logins broken up so an action has a person attached, and a documented path for a departure that runs the same afternoon. Same report, worth knowing: multifactor was deployed in some form in 97 percent of the incidents rooted in stolen credentials, so switching it on is the floor and not the finish.
Whether your people spot it
Short simulated phishing runs through the year, with a few minutes of teaching attached to a click, delivered through Phin Security. The content is aimed at the fraud your firm would actually meet: a change of bank details on an invoice you are expecting, a request from a partner sent while they are on the road, a supplier portal that looks right. Clicking is treated as a training event, never as something to be embarrassed about, because a firm where people hide the click is a firm that finds out late. Your carrier will ask how often this runs, and the honest answer is worth having.
Getting it in place, as a project
Knowing what should be switched on is the easy half. Turning it on across a working business without stopping the work is the half that gets deferred for two years. This is that piece. A sequence with owners and dates, and the awkward conversation about the application that breaks when you remove local administrator rights. A pilot group before any rollout. It runs even if we do not end up managing you afterwards, and it is quoted as a project instead of being folded into a monthly fee.
What a security program costs
Two costs sit underneath any answer. Licensing is per person per month and reasonably predictable once the tools are chosen. Labor is where most of the money goes, because somebody has to read what the tools produce. Firms overspend by buying a second product to solve a problem the first one already reported and nobody looked at. Where security sits inside a managed agreement it is part of the monthly figure rather than a separate line, and the honest way to size it is an assessment first.
Common questions
We have antivirus and a firewall. Is that not cybersecurity?
They stop files and they stop traffic. Neither one stops somebody signing in with a password they bought, and that is how most of this starts. Neither one tells you it happened at two in the morning. Antivirus and a firewall are two controls out of a set that also has to cover identity, mail, backups nobody can delete, and somebody who reads the alerts.
Do we need all four of these?
Nobody buys all four. Monitoring and response, ransomware and disaster recovery and cyber insurance readiness answer different questions. Most firms need the identity and training work described above, plus whichever of the four is pressing right now. Usually that is a renewal date, or the discovery that nothing is watched overnight. If you cannot pick, that is a good reason to start with the assessment and let the findings choose.
Can you do the security work if somebody else runs our IT?
Yes, and it is a common arrangement. Your team or your existing provider keeps the day to day. We carry the security tooling and the overnight cover. It needs one thing agreed in writing before it starts: who is allowed to disconnect a machine at midnight without waiting for a meeting. See co-managed IT.
How would we know if we have already been breached?
Without monitoring in place you mostly would not, and that is the uncomfortable answer. Three checks can be run quickly: whether your company credentials have turned up in a public breach dump, whether any mailbox carries a forwarding rule nobody set, and whether sign-ins are arriving from places your staff have not been. None of the three takes long, and all of them are part of the assessment.
Do you do penetration testing?
We arrange it with a specialist firm and manage the engagement, and we do not mark our own homework by testing an environment we built. Most businesses asking for a penetration test are being asked for one by a client or a regulator. If nobody is asking, the money usually buys more as remediation than as a report telling you what an assessment would have told you for less.
Start with whatever brought you here
Fifteen minutes on the phone, about the business rather than the equipment. If one of the four is obviously your answer, we will point at it and let you get on.