Founder of 39D · Managed IT · Cybersecurity · IT leadership Small and growing UK businesses
Cybersecurity expertise

Cybersecurity for SMEs needs to be practical, layered and continuously managed.

Smaller businesses face many of the same threats as larger organisations, but usually with fewer internal resources. The answer is a sensible set of controls that work together and can be maintained day to day.

The controls I prioritise

  • Multi-factor authentication and secure identity
  • Microsoft 365 configuration and account protection
  • Managed endpoint protection and response
  • Reliable, tested backups
  • Patch and vulnerability management
  • Staff security awareness
  • Firewall and network security
  • Cyber Essentials readiness
  • Business continuity and incident planning

Cybersecurity is an IT management responsibility

Security works best when it is built into everyday IT management. New users, leavers, devices, permissions, suppliers, backups and software changes all affect risk. That is why I treat cybersecurity as a core part of managed IT rather than a separate annual project.

Microsoft 365 security

For many SMEs, Microsoft 365 contains email, files, identities and collaboration data, making it one of the most important security environments in the business. MFA, access controls, device management, email protection and independent backup should be considered together.

Support through 39D

Through 39D, these controls can form part of an ongoing managed service rather than leaving the business to maintain them alone.