03 / IT for business
IT security at a level a small company can actually keep up
A configuration review, MFA rollout, endpoint protection, backups, tidy access and a plan for an incident — the basics that stop the typical attacks on companies of 5 to 100 people.
Small companies fall to the same few things: an "invoice" email somebody clicked, a compromised mailbox sending out requests to change a bank account number, encrypted files on the shared drive, and a former employee who still has access to everything. None of them require a sophisticated attacker. They require an account without MFA, a backup nobody has tested, and access nobody revoked.
We start with a security review: we check the configuration of Microsoft 365, the network, workstations, backups and access, and hand over a list of risks ranked by their impact on the business — in language the owner understands, not only the IT person. Then we put the basics in place in an order that makes sense: MFA, endpoint protection, backups tested by restoring them, tidy access and offboarding, hardening of Microsoft 365 and the network. Finally, we leave a one-page incident plan and a short briefing for staff on how to recognise phishing.
We are also clear about what this is not. We do not carry out penetration tests and we do not issue certifications — if your industry or a client requires either, we will help you scope it and choose a specialised firm. Our role is to have the basics in place, documented and maintained, and under ongoing IT support, looked after every month rather than once a year.
What the service covers
Configuration security review
A baseline configuration and risk review: accounts and permissions, MFA, Microsoft 365 settings, network and firewall, workstations, backups, external access. The result is a short report with risks ranked by impact and a concrete order of work — not a list of everything that could theoretically be improved.
MFA and access control
Multi-factor authentication on every account, starting with administrators and anyone with access to finances. Permissions tied to roles, separate admin accounts, a password manager instead of a spreadsheet, and an offboarding procedure after which a departing person genuinely loses access — to mail, files, VPN and external systems.
- MFA rollout in Microsoft Entra ID
- Review of permissions and privileged accounts
- Password manager and password hygiene
- Onboarding and offboarding procedure
Endpoint protection
Windows and macOS machines with protection switched on, disks encrypted and updates applied on schedule, with no day-to-day admin rights. Settings are consistent across every workstation and written down, so a new machine gets them from day one.
Backups and recovery planning
A backup strategy for workstations, servers, Synology devices and Microsoft 365: what, how often, where and for how long — including a copy isolated from the company network so it survives an encryption attack. Restores are tested on schedule, and the recovery plan is written down and known before it is needed.
Hardening Microsoft 365 and the network
We close what is open by default: conditional access basics and legacy protocols switched off in Microsoft 365, an external sharing policy, mail protection against spoofing of your domain, and on the network — rules on MikroTik and UniFi devices, a guest network kept apart from the company one, VPN instead of open ports, and up-to-date device firmware.
- Conditional access and legacy protocols switched off
- Mail protection: SPF, DKIM, DMARC
- Firewall rules, segmentation and VPN
- Network device updates
Staff awareness and an incident plan
A short briefing for the team: how to recognise phishing, what to do with a suspicious message and where to report it without fear of blame. Plus a one-page incident response plan — who calls whom, what to disconnect first, how to restore data — so that on a bad day nobody has to improvise.
Typical situations
An employee clicked a link in an "invoice", and you do not know whether anything happened or what to check now.
Only the owner has MFA — everyone else signs in with a password a former employee also knows.
A client, an insurer or a tender requires a written security and backup policy, and today all of it lives "in the IT person's head".
There are backups, but nobody has ever restored a single file from them.
What you can count on
- A written security review: risks ranked by their impact on the business, with concrete changes and an order of work — instead of general recommendations.
- MFA on every account, protected workstations, and access tied to roles and revoked on the day someone leaves.
- Backups that restore — tested on schedule, with one copy beyond the reach of the company network and a written recovery plan.
- A one-page incident plan, and a team that knows what phishing looks like and where to report it.
Technologies
- Microsoft 365
- Microsoft Entra ID
- MikroTik
- UniFi
- Synology
Questions about this service
No — and we say so openly. We carry out a configuration and risk review: access and permissions, MFA, Microsoft 365 settings, network, workstations, backups. It catches most of the typical problems in small companies, but it does not replace a penetration test. If your industry, a client or a tender requires one, we will help you scope it and choose a specialised firm.
Yes, although it is not a certificate. After the review and rollout you hold the review report, written access and backup rules, an inventory and an incident plan — the documents that client and insurer questionnaires usually ask about. We do not issue certificates and do not promise conformity with any standard; if a formal attestation is required, we will help you prepare for it.
With the review, because without it we would be putting safeguards in blind. Then we split the work into stages by risk: MFA and backups first, because they stop the most, then access, workstations and hardening. How long it takes depends on the number of people and devices and on how much order there already is — after the review you get a schedule in writing, not an estimate from a conversation.
Yes. Under ongoing IT support for companies the security basics are maintained continuously: patching, MFA for every new account, offboarding, backup restore tests and a periodic configuration review. A one-off engagement — the review plus the basics — is possible too, and the simplest way to start is the free audit, which is a configuration and risk review.
Related services
IT support for companies
Ongoing IT support for companies with no IT department of their own: helpdesk, Microsoft 365, network, servers, backups and security under one agreement, with response times written into the SLA.
Microsoft 365 support
Administration, migration and user support for Microsoft 365: accounts, licences, mail, Teams, SharePoint and security looked after in one place — with no guessing about who has access to what.
Technical audits
Audits of code, applications, websites, QA processes and infrastructure. Instead of opinions and reassurances, a written report with priorities and an action plan.
Let's start with a security review
The free audit is a configuration and risk review: Microsoft 365, the network, workstations, backups and access. You get a short list of risks ranked by their impact on the business and a proposed order of work. It is not a penetration test, and it commits you to nothing.