Antivirus is the easy part: bought in two minutes, conscience at ease. The work is everything else — the email "from your supplier" with the bank details changed at the last minute, the same password everywhere, written in the notebook beside the keyboard, the owner's mailbox doing password recovery for the bank, the invoicing software and everything else. "Who'd bother with us?" Nobody — and that's precisely the point: scams don't pick targets, they cast nets. Ten thousand identical lures go out, and the week is made on the three businesses that bite.
Managed security means something precise here: your domain's outgoing email signed and verifiable, so passing themselves off as you gets harder; antivirus that is genuinely looked after, not installed and forgotten; the extra code on the accounts that matter — email, bank, invoicing, admin access; a password manager instead of the notebook; updates done rather than postponed; and half an hour of practical training for whoever lives in the inbox. Every job closes with a written report: what was secured, and what needs keeping an eye on.
We start with a survey of machines, mailboxes and accounts, and a clear quote before any work begins: one-off jobs go by hourly rate, with the quote by email; if you want security kept alive over time, ongoing support is agreed together, tailored, in the quote. And the boundaries of the trade are honest ones: we are a lab, not a SOC — the operations room that watches networks day and night — and we sell no miracles. Formal privacy paperwork — registers, appointments, a DPO — belongs to your privacy consultant or lawyer: we do the technical side.
The fraud that empties small-business accounts isn't a film plot: it's a well-written email. It comes from your real supplier, inside a real thread, attached to the right invoice: one line changes — "please note our new bank details". The transfer goes out quietly, the supplier chases payment a month later, and by then the money is elsewhere. The trade name is Business Email Compromise — the company mailbox, compromised — and police reports tell the same story again and again. The counter-measure that stops most of it is organisational and costs nothing: a new IBAN is verified by phone, on the number you already have in your address book — never on the contact details written in that same email. It's a shop rule more than an IT one: decided once, known to everyone who pays invoices, and it keeps working on the days the antivirus has nothing to say.
Email is your front door: securing it means signing it and locking it. The invisible half is your domain, and the machinery has three ugly names we'll say once. The UK's National Cyber Security Centre keeps a whole guide on protecting the people you do business with by "making it difficult for cyber criminals to spoof your email address": SPF "allows you to publish IP addresses which should be trusted for your domain"; DKIM "allows you to cryptographically sign email you send to show it's from your domain"; DMARC "allows you to set a policy for how receiving email servers should handle email which doesn't pass either SPF or DKIM checks". We configure them; receiving servers do the checking. The visible half is the mailbox: filters tuned, separate addresses where they help, and particular care for the owner's — the recovery address for everything else, and the first to harden.
A password on its own no longer holds: the extra code saves you on the day it gets stolen. On the accounts that matter — email, bank, invoicing, admin access — we switch on multi-factor authentication, MFA: beyond the password, a code only you hold, so a password fished out by deception stops being enough for whoever took it. The NCSC puts it plainly: "authenticating a user to an online service using only a password is not strong enough to protect any sensitive data" — and "any implementation of MFA is still superior to reliance on passwords alone". The notebook beside the keyboard retires: in its place a password manager, an encrypted safe that remembers the passwords for you — a different one for every service, one master to memorise. And one house rule above all: the company's administrative credentials belong to the company — documented and handed to you, never held as leverage.
Antivirus and updates make no headlines, which is their whole virtue. We install the antivirus and then actually follow it — kept current, alerts read by someone: that is what managed means; where the work justifies it we step up to EDR, the layer that records what happens on a machine, without buying acronyms for sport. Updates are the hygiene of the trade: known flaws are closed by the vendors' patches, and attackers happily walk through a door left ajar for months — we keep the calendar, you get the occasional restart. Then comes the half hour that stiffens everything else: practical training, at your own desks, on your company's real cases — the odd invoice, the disguised link, the supplier who "changes IBAN" — not the eight-hour course nobody remembers. The people in the inbox every day are your first defence, not your weak link.
The law doesn't ask for a bunker: it asks for measures proportionate to the risk — which is precisely our trade. The GDPR, at Article 32, requires from anyone processing personal data "appropriate technical and organisational measures to ensure a level of security appropriate to the risk", weighing — its own words — "the state of the art, the costs of implementation": for a micro business that means its risk and its pockets, not a bank's. We do the technical side of those measures; registers, appointments, notices and any DPO stay with your privacy consultant or lawyer, and your specific case is discussed in the quote. Two honest signposts to close: when everything else has failed, the last line of defence is a copy that restores — that story lives in backup and continuity —; and security walks on a well-built network, firewall and access included: that chapter lives in the business network.
| Machines and people | how many computers, how many mailboxes, and who uses them: the surface to defend is counted before it is protected |
|---|---|
| Where your email lives | your own domain or scattered addresses, a proper provider or a legacy mailbox: domain signing and rules change the job |
| What's already there | active antivirus, out-of-support systems, backlogged updates: we start from what exists and discard only what doesn't defend |
| Accounts that matter | the owner's email, the bank, the invoicing system, admin access: how many need the extra code switched on |
| Passwords to rehouse | from the notebook to a password manager: how many credentials and how many people set the patience required |
| One-off or over time | a single hardening job by the hour, or a retainer that keeps it alive: updates and checks included |
What genuinely moves the quote for this service: how many workstations and people, what is already in place, what must stay up. Agreed together before we start — and the quote, numbers included, arrives by email: one-off jobs by the hour, ongoing support priced to fit.
ElectrONIK Lab is an independent workshop: it is not an authorised service centre and is not affiliated with the manufacturers. The trademarks named here belong to their respective owners and are used only to identify the devices we work on. Your statutory consumer rights towards whoever carries out the repair are unaffected.
A free consultation, a clear quote up front and a written report after every job.