What Is Email Encryption? A Plain English Guide for UK Small Businesses
22 September 2026
Plain English guide to email encryption for UK small businesses: TLS versus message encryption, what Microsoft 365 includes, and what the ICO expects.
Insights
Plain English cyber security guides for UK small businesses: Cyber Essentials, phishing, email security, policies, templates and the Defence Cyber Certification.
34 articles, newest first.
22 September 2026
Plain English guide to email encryption for UK small businesses: TLS versus message encryption, what Microsoft 365 includes, and what the ICO expects.
22 September 2026
DEFCON 658, Def Stan 05-138, the Cyber Security Model and Defence Cyber Certification are four different things. Here is what each does and how they reach a subcontractor.
2 September 2026
Level 0 is three controls and six questions, and it still catches well-run firms. Here is what each control asks for, what counts as evidence, and where suppliers go wrong.
2 September 2026
MOD has asked all industry partners to hold Defence Cyber Certification Level 0 by 31 December 2026. Here is what the scheme is, what each level means, how it reaches subcontractors, and what to do first.
27 August 2026
Your customer has asked for Cyber Essentials and given you a deadline. How to read the requirement, scope it around a shop floor, and pass first time.
16 August 2026
What UK insurers now require for cyber cover in 2026: MFA, EDR, backups, patching and Cyber Essentials. A plain-English checklist for small businesses.
12 May 2026
Phishing is the most common way attackers get into a small business. These five simple habits stop the overwhelming majority before any harm is done.
9 May 2026
Your M365 Already Has Everything You Need for Cyber Essentials Compliance If you have been following our blog on Cyber Essentials Plus changes for 2026, you know that cybersecurity requirements are getting stricter every year. But here is the good news: your Microsoft 365 subscription already includ
18 April 2026
Introduction: Why Cyber Essentials Plus Matters More Than Ever If your business handles any form of digital data, and in 2026, that means every business, then Cyber Essentials Plus should be on your radar. The UK government-backed certification scheme has undergone significant updates this year, a
18 February 2026
Phishing emails are the number one way criminals break into small business systems. According to the UK government’s Cyber Security Breaches Survey, phishing was the most common type of attack identified by UK businesses, and small companies are just as much at risk as large enterprises. The good ne
9 February 2026
Moving to the cloud gives your business incredible flexibility, but it also opens the door to a new world of cloud computing security risks. These threats aren't always complex, world-ending cyber-attacks; they can be as simple as a single wrong setting. But whether it's human error or a targeted at
7 February 2026
Think of your business as a castle. Your network, data, and applications are the crown jewels locked away in the treasury. Every single device your team uses, laptops, mobiles, servers, is a potential door or window into that castle. So, what is endpoint security? It’s the art and science of putting s
3 February 2026
The best way to fend off cyber attacks is to stop thinking about them as something you react to and start thinking about how to prevent them from ever happening. It’s a mindset shift. The best defence combines solid technical controls, things like firewalls and multi-factor authentication, with thorou
30 January 2026
The fundamental difference between a penetration test and a vulnerability assessment comes down to one thing: intent. A vulnerability assessment is all about finding a broad list of potential weaknesses, whereas a penetration test actively tries to exploit a specific weakness to see if it’s a real-w
29 January 2026
Phishing is no longer just about suspicious emails with glaring spelling mistakes. Today’s cybercriminals deploy a sophisticated and ever-evolving arsenal of techniques designed to exploit human trust and bypass traditional security measures. For small to medium-sized businesses (SMBs) across the UK
5 January 2026
Data Loss Prevention (DLP) isn't just a piece of software; it's a complete strategy that combines smart technology with clear processes. Its whole purpose is to make sure your company's sensitive information doesn't get lost, leaked, or stolen. Think of it like a highly intelligent security guard fo
25 December 2025
Think of Network Access Control (NAC) as the vigilant security guard for your entire company network. Its job is simple but critical: to see and identify every single device that tries to connect, whether it's a laptop, a smartphone, or even a smart thermostat, and decide what it's allowed to do. Base
24 December 2025
At its core, Privileged Access Management (PAM) is all about controlling, monitoring, and locking down access to an organisation's most powerful digital accounts. Think of it as a security detail for your 'keys to the kingdom', those high-level accounts that can change systems, access sensitive data,
21 December 2025
Choosing the right firewall can feel a bit daunting. For most small UK businesses, it usually boils down to two main options: a Unified Threat Management (UTM) device for its all-in-one simplicity, or a Next-Generation Firewall (NGFW) if you need finer control over applications. If your team is most
14 December 2025
Let's be honest, your company’s biggest security risk isn’t your firewall. It's that well-meaning employee who clicks a single bad link. The good news is that effective cybersecurity training for employees can turn this weakness into your strongest line of defence, creating a human firewall that no
8 December 2025
Think of your password as the first key to your front door. Two-factor authentication (2FA) is like adding a second, completely different lock that needs a unique key, one that only you possess. It's a security process that adds an extra layer of defence, making sure that even if someone manages to s
28 November 2025
Think of an IT security policy as the rulebook that protects your company’s data, your reputation, and the trust you’ve built with your clients. It’s far more than a dusty document; it’s a living guide that sets clear expectations for your team, tells everyone what to do in a crisis, and proves you’
21 November 2025
Let's be honest, cybersecurity can feel like a huge, complicated puzzle. A good cybersecurity risk assessment template isn't just another document to fill out; it's your strategic map through the maze, helping you pinpoint exactly what needs protecting and how to do it efficiently. Why a Risk Assess
13 November 2025
In a business environment where security breaches are an ever-present threat, simply implementing security measures is not enough. You must consistently verify that these defences are working as intended. A proactive and methodical approach to security is no longer optional; it's a core business nec
4 November 2025
Think of dark web monitoring as your company's own private intelligence agency, scouring the internet's hidden alleyways for any mention of your stolen data. It’s a constant, vigilant search for sensitive information that shouldn’t be out in the wild. This isn't about just waiting for something bad
30 October 2025
Endpoint Detection and Response (EDR) is essentially a highly vigilant security team for all your company devices. It's designed to constantly monitor endpoints like laptops and servers for any sign of trouble, investigate potential threats as they happen, and give you the tools to shut down attacks
19 October 2025
At its core, patch management is simply the process of keeping your software up to date. It's the systematic way you find, test, and install updates, or "patches", for all the software and systems your business relies on, from laptops to servers. Think of it as a crucial, continuous maintenance routin
12 October 2025
When you hear the term 'email security solution', what comes to mind? It’s not just one thing, but a whole system of defences working together. Think of it as a digital bodyguard for your inbox, specifically designed to protect your accounts and messages from being stolen, lost, or tampered with. It
6 October 2025
Zero trust security is a strategic approach to cybersecurity that flips the old rulebook on its head. It’s built on one core idea: never trust, always verify. This model gets rid of the outdated concept of a "safe" internal network and a "dangerous" external one. Instead, it treats every single atte
3 October 2025
A solid cyber incident response plan is really just a documented strategy. It’s your playbook for what to do when something goes wrong, like a data breach or a ransomware attack. Think of it as your survival guide to minimise damage, get back up and running, and keep your customers’ trust. Why You C
30 September 2025
Preventing a ransomware attack isn't about finding one magic bullet. It's about building a layered defence that combines a well-trained team, smart technology, and a backup plan you can count on. The idea is to be proactive, spotting threats like phishing emails and locking down your network before a
25 September 2025
As UK businesses increasingly migrate to the cloud, securing digital assets has become a paramount concern. The flexibility and scalability of the cloud bring immense benefits, but they also introduce new security challenges that can leave unprepared organisations vulnerable. For small to medium-siz
22 September 2025
Network security vulnerabilities are, at their core, cracks in your defences. They're the weak spots, flaws in your software, gaps in your procedures, or even risky habits among your staff, that attackers look for and exploit. Think of them not as technical glitches, but as open invitations for cyberc
17 September 2025
Choosing the best antivirus software for businesses can feel overwhelming. With countless options available, each promising total protection, it's difficult to determine which solution truly fits your company's specific needs, size, and budget. A startup of five people has vastly different security