For your business: IT security and email

In short: IT security and email

Antivirus is the easy part: bought in two minutes, conscience at ease. The work is everything else — the email "from your supplier" with the bank details changed at the last minute, the same password everywhere, written in the notebook beside the keyboard, the owner's mailbox doing password recovery for the bank, the invoicing software and everything else. "Who'd bother with us?" Nobody — and that's precisely the point: scams don't pick targets, they cast nets. Ten thousand identical lures go out, and the week is made on the three businesses that bite.

Managed security means something precise here: your domain's outgoing email signed and verifiable, so passing themselves off as you gets harder; antivirus that is genuinely looked after, not installed and forgotten; the extra code on the accounts that matter — email, bank, invoicing, admin access; a password manager instead of the notebook; updates done rather than postponed; and half an hour of practical training for whoever lives in the inbox. Every job closes with a written report: what was secured, and what needs keeping an eye on.

We start with a survey of machines, mailboxes and accounts, and a clear quote before any work begins: one-off jobs go by hourly rate, with the quote by email; if you want security kept alive over time, ongoing support is agreed together, tailored, in the quote. And the boundaries of the trade are honest ones: we are a lab, not a SOC — the operations room that watches networks day and night — and we sell no miracles. Formal privacy paperwork — registers, appointments, a DPO — belongs to your privacy consultant or lawyer: we do the technical side.

Quote by email, clear before we start Written report after every job On contracts: remote response within 4 working hours

What's included — Security and email

Secure email Get a quote
Antivirus and prevention Get a quote
MFA on accounts Get a quote
Password manager Get a quote
Phishing awareness Get a quote
Updates and patching Get a quote

Scams don't pick you: they cast nets. The security that stops most of it is boring

The fraud that empties small-business accounts isn't a film plot: it's a well-written email. It comes from your real supplier, inside a real thread, attached to the right invoice: one line changes — "please note our new bank details". The transfer goes out quietly, the supplier chases payment a month later, and by then the money is elsewhere. The trade name is Business Email Compromise — the company mailbox, compromised — and police reports tell the same story again and again. The counter-measure that stops most of it is organisational and costs nothing: a new IBAN is verified by phone, on the number you already have in your address book — never on the contact details written in that same email. It's a shop rule more than an IT one: decided once, known to everyone who pays invoices, and it keeps working on the days the antivirus has nothing to say.

Email is your front door: securing it means signing it and locking it. The invisible half is your domain, and the machinery has three ugly names we'll say once. The UK's National Cyber Security Centre keeps a whole guide on protecting the people you do business with by "making it difficult for cyber criminals to spoof your email address": SPF "allows you to publish IP addresses which should be trusted for your domain"; DKIM "allows you to cryptographically sign email you send to show it's from your domain"; DMARC "allows you to set a policy for how receiving email servers should handle email which doesn't pass either SPF or DKIM checks". We configure them; receiving servers do the checking. The visible half is the mailbox: filters tuned, separate addresses where they help, and particular care for the owner's — the recovery address for everything else, and the first to harden.

A password on its own no longer holds: the extra code saves you on the day it gets stolen. On the accounts that matter — email, bank, invoicing, admin access — we switch on multi-factor authentication, MFA: beyond the password, a code only you hold, so a password fished out by deception stops being enough for whoever took it. The NCSC puts it plainly: "authenticating a user to an online service using only a password is not strong enough to protect any sensitive data" — and "any implementation of MFA is still superior to reliance on passwords alone". The notebook beside the keyboard retires: in its place a password manager, an encrypted safe that remembers the passwords for you — a different one for every service, one master to memorise. And one house rule above all: the company's administrative credentials belong to the company — documented and handed to you, never held as leverage.

Antivirus and updates make no headlines, which is their whole virtue. We install the antivirus and then actually follow it — kept current, alerts read by someone: that is what managed means; where the work justifies it we step up to EDR, the layer that records what happens on a machine, without buying acronyms for sport. Updates are the hygiene of the trade: known flaws are closed by the vendors' patches, and attackers happily walk through a door left ajar for months — we keep the calendar, you get the occasional restart. Then comes the half hour that stiffens everything else: practical training, at your own desks, on your company's real cases — the odd invoice, the disguised link, the supplier who "changes IBAN" — not the eight-hour course nobody remembers. The people in the inbox every day are your first defence, not your weak link.

The law doesn't ask for a bunker: it asks for measures proportionate to the risk — which is precisely our trade. The GDPR, at Article 32, requires from anyone processing personal data "appropriate technical and organisational measures to ensure a level of security appropriate to the risk", weighing — its own words — "the state of the art, the costs of implementation": for a micro business that means its risk and its pockets, not a bank's. We do the technical side of those measures; registers, appointments, notices and any DPO stay with your privacy consultant or lawyer, and your specific case is discussed in the quote. Two honest signposts to close: when everything else has failed, the last line of defence is a copy that restores — that story lives in backup and continuity —; and security walks on a well-built network, firewall and access included: that chapter lives in the business network.

What drives the quote
Machines and peoplehow many computers, how many mailboxes, and who uses them: the surface to defend is counted before it is protected
Where your email livesyour own domain or scattered addresses, a proper provider or a legacy mailbox: domain signing and rules change the job
What's already thereactive antivirus, out-of-support systems, backlogged updates: we start from what exists and discard only what doesn't defend
Accounts that matterthe owner's email, the bank, the invoicing system, admin access: how many need the extra code switched on
Passwords to rehousefrom the notebook to a password manager: how many credentials and how many people set the patience required
One-off or over timea single hardening job by the hour, or a retainer that keeps it alive: updates and checks included

What genuinely moves the quote for this service: how many workstations and people, what is already in place, what must stay up. Agreed together before we start — and the quote, numbers included, arrives by email: one-off jobs by the hour, ongoing support priced to fit.

ElectrONIK Lab is an independent workshop: it is not an authorised service centre and is not affiliated with the manufacturers. The trademarks named here belong to their respective owners and are used only to identify the devices we work on. Your statutory consumer rights towards whoever carries out the repair are unaffected.

Frequently asked questions — Security and email

There are four of us: who would bother targeting us?
Nobody targets you, and that is exactly the point: phishing campaigns don't choose, they cast nets — the same lure to thousands of addresses, and the work is done with whoever bites. A micro business pays invoices, has a bank, and is in a hurry: that's enough to be in the net. The good news: proportionate defences — email in order, the extra code, updates done — take you out of it without upending anyone's day.
The supplier's email says the IBAN has changed. What do we do?
You don't pay: you phone the supplier, on the number already in your address book — never the contact details in that email. If the voice at the other end knows nothing about it, you have just saved the invoice. If the transfer has already gone, call your bank first, then report it to the police. We can re-secure the technical side — mailbox, rules, devices — as a one-off job, with no promises about what doesn't depend on us.
What does it cost? Is there a fixed monthly fee?
One-off work goes by hourly rate: write to us by email and a clear quote arrives before we start — the full story is on the IT support page. Ongoing support, the kind that keeps security alive over time, has no published price list: it is agreed together, in the quote, on your actual situation. Either way you know beforehand what's included and what isn't.
Do you watch our systems day and night?
No, and we say it plainly: we are a lab, not a SOC — no 24/7 monitoring, no guaranteed emergency response to an attack in progress. If an incident has already happened we step in as a one-off job: we do what can be done and tell you straight what's recoverable and what isn't. For clients on the ongoing contract the fixed commitments apply — remote take-charge within 4 working hours, on-site intervention in Brianza within 48 — not resolution times.
Does this make us "GDPR compliant"?
On the technical side, yes: Article 32 asks for measures appropriate to the risk, and secured email, the extra code, updates and copies are that kind of measure. But processing registers, appointments, notices and any DPO are formal obligations: that trade belongs to your privacy consultant or lawyer, and we won't pretend otherwise. The written report that closes each of our jobs, though, is exactly what your consultant needs: part of the work arrives already documented.

Security and email for your business, without the headaches? Let's talk.

A free consultation, a clear quote up front and a written report after every job.