Skip to main content

Cyber Security

Cyber security services for small and mid-sized businesses

The controls that stop most attacks on businesses your size, run every day by the same team that supports your users.

Priced
Per user or device
Coverage
Herts, Essex, London
Security
Built in
Since
2001

What is cyber security?

Dig IT Solutions provides managed cyber security for small and mid-sized organisations: endpoint detection and response on every device, multi-factor authentication and conditional access for Microsoft 365, email filtering against phishing and invoice fraud, patch management, tested backups and staff awareness. The service is built around the five Cyber Essentials controls, so it prepares you for certification and for cyber insurance questionnaires.

The managed security stack

Six layers, run every day

Identity, endpoints, email, cloud, network and recovery. Each layer stops a different class of attack; together they cover the ways businesses your size actually get breached.
01 Identity02 Endpoints03 Email04 Microsoft 36505 Network06 RecoveryYour businessSIX LAYERS · RUN DAILYCONCEPTUAL VIEW
  1. 01

    Identity

    MFA on every account, conditional access, admin roles separated

  2. 02

    Endpoints

    EDR on every device, automatic patching, encryption

  3. 03

    Email

    Filtering, SPF, DKIM and DMARC, link protection, awareness training

  4. 04

    Microsoft 365 and cloud

    Secure configuration, sharing controls, audit logging, independent backup

  5. 05

    Network

    Business firewalls, segmented Wi-Fi, secure remote access

  6. 06

    Recovery

    Separated, retained, tested backups and a first-hour plan

Problems we fix

The problems this service exists to solve

  1. 01

    Phishing and invoice fraud

    A convincing email asks finance to change a supplier's bank details, or a staff login is captured and used to send more phishing from your domain.

  2. 02

    Ransomware

    One infected laptop encrypts shared files and Microsoft 365 data. The question becomes whether your backups were separate, recent and restorable.

  3. 03

    Insurance and client questionnaires

    Your cyber insurer or a larger customer wants evidence of MFA, EDR, patching and backups, and nobody is sure what the honest answer is.

  4. 04

    Leavers and shared passwords

    Former staff can still sign in, admin passwords are in a spreadsheet, and personal devices hold company data with no control.

Scope

What is included

Written into the agreement, not implied. Anything outside this list is scoped and quoted as a project so your monthly cost stays predictable.
  • 01

    Managed endpoint detection and response (EDR)

    Modern protection on every laptop, desktop and server that detects suspicious behaviour, not just known malware, and can isolate a device from the network the moment it is compromised.

  • 02

    Identity and access control

    MFA enforced for everyone, conditional access policies that block risky sign-ins, admin roles separated from daily accounts, and legacy authentication switched off.

  • 03

    Email security

    Filtering for phishing, spoofing and malicious attachments, SPF, DKIM and DMARC configured for your domain, and link protection to reduce the impact of the email that gets through.

  • 04

    Patch and vulnerability management

    Operating systems, browsers and common applications kept current automatically, with reporting on anything that fails so it does not quietly become an open door.

  • 05

    Backup and recovery

    Backups for servers and Microsoft 365 that are separate from production, monitored daily and tested, because backup is the control that turns ransomware into a recovery job.

  • 06

    Security awareness for staff

    Short, practical sessions and phishing simulations so people recognise the requests that attackers actually make: urgent payments, password resets and gift cards.

  • 07

    Cyber Essentials readiness

    We align your firewalls, device configuration, updates, access control and malware protection with the five Cyber Essentials controls and help you gather the evidence for assessment.

  • 08

    Security reporting

    Plain-English reporting on protection coverage, patch status, MFA adoption and incidents, suitable for a board meeting or an insurer.

Outcomes

What changes for the business

  • Attacks that would have succeeded are blocked or contained
  • Honest, evidenced answers for insurers and client due diligence
  • A recovery position you have tested, not assumed
  • Staff who spot the email before finance pays it
Mr Plant Hire lorry and access platforms in a depot yard
Construction & Plant Hire

Proof

Mr Plant Hire: one IT partner across every depot for over 15 years

Mr Plant Hire is a plant and tool hire business established in 1981 and headquartered in Enfield, operating from multiple depots. Dig IT Solutions has provided its complete IT function for more than fifteen years, growing the network, security and cloud platform as the company expanded.

15+
years supported
Multi-depot
single managed network
M365
email, SharePoint and Teams
EDR
on every workstation

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What cyber security does a small business actually need?
The controls that stop most opportunistic attacks: multi-factor authentication on email and cloud accounts, endpoint detection and response on every device, automatic updates, email filtering, separate tested backups, and least-privilege access so staff and leavers cannot reach more than they need. These map to the five Cyber Essentials controls, which is why we use that framework as the baseline for every client.
Do you provide Cyber Essentials certification?
Certification is issued by an IASME-licensed certification body after assessment, not by an IT provider. Dig IT prepares your systems to meet the five controls, fixes the gaps, gathers the evidence and can work with the assessor during the process. Whether you go for Cyber Essentials or Cyber Essentials Plus depends on what your clients and insurers require.
Is antivirus enough?
Traditional antivirus compares files against known signatures and misses attacks that use legitimate tools or brand-new malware. Endpoint detection and response watches for the behaviour of an attack, records what happened, and can isolate a device automatically. For a business holding client data, EDR is the minimum we recommend.
How do you protect against ransomware?
In layers: MFA so stolen passwords are not enough, EDR to detect and isolate an infected device, patching to close the vulnerabilities ransomware exploits, email filtering to stop the initial delivery, restricted admin rights to limit spread, and separate backups with retention so you can restore rather than pay. We also test recovery, because a backup that has never been restored is a hope, not a plan.
Can you help with a cyber insurance questionnaire?
Yes. Insurers increasingly ask for MFA, EDR, backup separation, patch cadence and incident response arrangements. We provide accurate answers with evidence from our tooling and, where the honest answer is no, a plan and price to fix it before renewal.
What happens if we have a security incident?
Contact the helpdesk immediately. We isolate affected devices, secure accounts, assess what was accessed, restore from backup where needed and document the timeline. If personal data is involved, we help you decide whether the ICO must be notified within the 72-hour window and support you through it.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us