Security
Firewall, endpoint protection, tested backups and staff who spot a fake message.
Security is not one product but several overlapping layers: firewall, endpoint protection, backups that are actually tested, and people who recognise a suspicious message.
Antivirus, EDR or monitored protection
There are three common levels of endpoint protection, and the difference between them is what they do when something gets through anyway.
- Classic antivirus compares files against known patterns. It handles old threats well and attacks that use legitimate tools such as PowerShell poorly.
- EDR (Endpoint Detection and Response) watches how processes behave and can cut a computer off the network when it spots, for example, files being encrypted en masse.
- Monitored EDR adds someone who reads the alerts and acts on them, because an alert nobody looks at stops nothing.
What we recommend first
For most small businesses the first steps are not expensive, and they close the most common ways in:
- Multi-factor authentication (MFA) on email and on anything reachable from the internet
- SPF, DKIM and DMARC records for your domain, with the DMARC policy raised step by step from p=none to p=quarantine and then p=reject, so nobody can send mail in your name
- Separate admin accounts, so everyday work happens without admin rights
- A backup that is offline or immutable, so ransomware cannot encrypt it along with everything else
Only after that does it make sense to talk about EDR and penetration testing.
Why in that order
In small businesses an attack most often starts with a stolen email password, or with a fake message that looks like it came from a supplier and carries new bank details for payment. An expensive tool on the computer does not help if the attacker logs into the mailbox with the right password. So we close the way in first, then harden what sits behind it. For companies that fall under NIS2, the same order is a sound basis for the measures the law requires.
NIS2 also requires an early warning to the competent authority within 24 hours of becoming aware of a significant incident and a notification within 72 hours, so it pays to know in advance who sends it and with what information.
Common questions
Is a free antivirus enough?
For a home computer, the Microsoft Defender built into Windows is a good baseline as long as it is on and up to date. For a business, having MFA, a working backup and one view of all computers matters more than which antivirus is installed.
How much does protection for an office cost?
It depends on the number of users, whether you use Microsoft 365 or another mail system, and what you already have. After reviewing the current setup you get a list of steps with a quote for each one.
What if we have already been attacked?
Get in touch straight away. Do not shut the computers down, disconnect them from the network instead. We then change passwords from a clean device, work out how the attacker got in, and restore data from a backup that is not infected.