Advanced IT Services · Transforming ICT capabilities for schools · 24/7 support across the UK

FOR BUSINESS · CYBER SECURITY

Cyber Security for Business

A cyber incident is a downtime problem, a cashflow problem and a reputation problem long before anyone calls it a technology problem. We make security something your business simply has — Cyber Essentials certification, staff who can spot a phish, backups that actually restore and a Microsoft 365 that’s locked down properly — all inside one predictable per-user monthly cost.

And we practise what we sell: AIT holds both Cyber Essentials and Cyber Essentials Plus ourselves, renewed every year. The advice you get is the advice we follow.

75engineers and specialists
24/7UK-based helpdesk
2ISO 27001 UK data centres
Est. 200025+ years of IT done properly

Cyber Essentials — Certified · Cyber Essentials Plus — Certified

The question isn’t whether you’re a target. It’s whether it matters when it happens.

Most attacks on UK businesses aren’t sophisticated and aren’t personal. They’re automated: a phished password, an intercepted invoice, a ransomware payload that encrypts the file server on a Friday night. What varies from business to business isn’t the attack — it’s the consequence. One firm loses an afternoon; another loses a fortnight of trading, a cyber-insurance argument and a customer’s trust.

If you’re the owner or MD who’d take that 6am phone call, the FD who signs the insurance renewal, or the office manager everyone turns to when email stops — this page is for you. You don’t need to become a security expert. You need a partner who treats security as part of running your IT well, not a bolt-on sold by fear: certification handled, staff trained, backups tested, cloud hardened, and the evidence to show for it. That’s what this service is.

It also pays commercial dividends beyond risk. Cyber Essentials is increasingly a condition of winning work — public-sector contracts require it, and larger customers now ask their whole supply chain for it. Insurers ask sharper questions every renewal. Getting certified stops being a cost the moment it wins you a tender you’d otherwise have been screened out of.

Cyber Essentials, guided by a team that holds it

Cyber Essentials is the UK government-backed certification that proves your business has the fundamental protections in place — firewalls, secure configuration, access control, malware protection and up-to-date software. Cyber Essentials Plus covers the same five controls but adds an independent technical audit: an assessor verifies your defences actually work, rather than taking the questionnaire’s word for it.

We hold both certifications ourselves and sit the same assessments we’ll guide you through, every year — so when we tell you what the assessor will ask, it’s because we answered it ourselves last renewal, not because we read the syllabus.

Our certification guidance runs end to end:

Gap analysis

We review your current setup against all five control areas and give you a plain-English report: what already passes, what won’t, and what fixing it will cost — ranked so you can decide, not decoded from jargon.

Remediation

Our engineers do the fixing — patching, configuration, access control, MFA rollout — as scheduled work with your team kept informed, not a disruptive big bang.

Assessment support

We prepare the submission with you and, for Cyber Essentials Plus, get your systems ready for the independent technical audit so assessment day holds no surprises.

Annual renewal

Certification lasts twelve months. We track your renewal date, re-check the controls beforehand and keep you continuously compliant — so year two is routine, not a repeat project.

Certification is the floor, not the ceiling

Cyber Essentials proves the fundamentals. These four services are how we keep your business secure between certificates — each available on its own, all included in our fully managed security service.

Security audits

An independent, fixed-scope review of your network, user accounts, patching, remote access and cloud configuration — reported in plain English and ranked by risk and cost to fix. You get a prioritised roadmap a board can act on, whether or not we do the remediation.

Phishing simulation & staff training

Your team is your biggest attack surface — and, trained well, your best defence. We run safe, simulated phishing campaigns against your own staff, follow every click with short, blame-free training, and repeat the exercise so you can watch the click rate fall. You see the trend; your people learn from a fake email instead of a real one.

Managed backup & disaster recovery

Monitored daily backups with off-site copies held in our two ISO 27001 UK data centres, recovery objectives agreed with you in writing, and scheduled test restores — because a backup you’ve never restored is a hope, not a plan. If the worst happens, you already know how long recovery takes, because we’ve rehearsed it.

Microsoft 365 security hardening

Most businesses run on Microsoft 365; few have it configured securely out of the box. We enforce multi-factor authentication everywhere, apply conditional access, lock down admin accounts, set sensible sharing defaults and switch on the alerting that catches invoice-fraud attempts early — aligned with what Cyber Essentials expects to see.

Built for the size you are — and the size you’re planning to be

Security that fits a ten-person firm suffocates a two-hundred-person one, and vice versa. We shape the service to your headcount, and reshape it as you grow — same team, same per-user pricing logic throughout.

Under 40 staff

Usually fully managed: security is built into your monthly per-user cost rather than itemised into a dozen line items. We get you to Cyber Essentials, harden Microsoft 365, run your backups and train your staff — enterprise-grade fundamentals without enterprise-grade theatre.

40–150 staff

The stakes and the attack surface both grow. We layer in phishing simulation programmes, formal recovery-time objectives, regular security reviews and — where you have your own IT staff — a co-managed split that keeps them in charge of the day-to-day.

150+ staff

Typically co-managed alongside your internal IT team: independent audits, Cyber Essentials Plus, board-level reporting and tender-ready security evidence, with our 75 engineers and 24/7 helpdesk as the depth behind your own people.

Your IT team, ours — or both

Fully managed

We run your IT end to end, and security is simply part of how it’s run — patching, backups, monitoring, certification and training all under one contract, one helpdesk and one predictable monthly cost. Most of our clients under 40 staff choose this, and it’s covered in full on our business IT support page.

Co-managed

You have an IT manager or a small internal team, and they’re good — but security is a specialism with a 24/7 problem attached. Co-managed means your people keep the day-to-day and the local knowledge, while we bring the security tooling, the certifications, the out-of-hours cover and a 75-strong bench for escalation. We back your team; we don’t replace it.

The platform behind the promises

You see the same numbers we do

Every security promise on this page would be easy to make and hard to check — which is exactly why we built Helpdesk Reporting, our own client reporting platform, and give every client a login from day one. It’s included with our service, not sold on top, and it shows you the same performance data our own service managers work from: tickets, response times, SLA performance and trends across your business.

Illustrative demo data

98.7%SLA complianceof tickets resolved within target
84%First-time fix rateresolved at first contact
under 15 minAverage first responseon priority tickets
TrackedSecurity actionspatching and backup checks logged as auditable tickets

Illustrative figures — your business sees its own numbers in Helpdesk Reporting.

And because security is a spending decision as much as a technical one, every contract includes a quarterly service review with a rolling budget roadmap — hardware refresh dates, licence renewals, certification renewals and recommended security investments mapped out ahead of time, so your FD sees IT as a planned budget line instead of a series of surprises.

Existing clients sign in through the Customer Portal.

Capability you can check, not adjectives you can’t

We won’t decorate this page with glowing quotes — you’ve no way to verify those and neither would we in your position. What you can verify: we’ve been running IT since 2000, we employ 75 engineers and specialists, our UK helpdesk answers 24/7, and we operate two ISO 27001 UK data centres of our own — where we host and manage servers for businesses like White Logistics. We hold Cyber Essentials and Cyber Essentials Plus ourselves, renewed annually, and the free IT health check below is a working sample of how we think: take the report, get a second opinion on it, and judge us on what it finds.

For the wider picture of how we work with commercial clients — support models, pricing approach and what’s included as standard — start at IT services for business or go straight to business IT support.

Business cyber security, answered

Both certify the same five control areas — firewalls, secure configuration, access control, malware protection and software updates. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent technical audit in which an assessor tests that your controls genuinely work. If customers or contracts just ask for “Cyber Essentials”, the standard certification usually satisfies them; if security is a selling point in your market, Plus carries visibly more weight. We’ll advise which fits — and we hold both, so we know the difference from the inside.

Yes — AIT is certified to both Cyber Essentials and Cyber Essentials Plus, renewed every year. We wouldn’t guide clients through an assessment we weren’t prepared to sit ourselves, and going through it annually means our advice reflects what assessors currently ask, not what they asked three years ago.

It depends entirely on the gap between where you are and where the standard needs you to be — which is why we always start with a gap analysis rather than a promise. A small business with reasonably current systems is typically measured in weeks; a business with older infrastructure or no MFA may need a remediation project first. Either way you’ll know the timeline and the cost after the gap analysis, before committing to anything.

It helps, honestly stated: many insurers ask questions that map directly onto the Cyber Essentials controls, some offer better terms for certified businesses, and certification gives you evidenced answers for the renewal questionnaire instead of hopeful ones. Whether it satisfies your specific policy is a question for your policy — but we’ll help you answer the insurer’s questionnaire accurately, which matters more than most businesses realise if a claim is ever tested.

Possibly — as a partner, not a replacement. Our co-managed model leaves your internal team running the day-to-day while we supply what’s hard to build in-house: security specialisation, 24/7 cover, certification experience, enterprise tooling and 75 engineers of escalation depth. Your IT manager gets a deeper bench and holiday cover; you avoid hiring a security specialist you only need part of.

A no-obligation review of the essentials: how your users and admin accounts are protected, whether MFA is enforced, the state of patching and backups, your Microsoft 365 configuration and your exposure to the most common attacks. You get a short written report ranked by risk, in plain English, that’s yours to keep and act on — with us or with anyone else. No scare tactics and no obligation; if your setup is in good shape, the report will say so.

LET’S TALK

Start with the free IT health check

Thirty minutes of your time, a clear written picture of your security position, and no obligation at the end of it. Tell us a little about your business and we’ll be in touch to arrange it — or call 0115 9170 197 and speak to an engineer today.

Already a client? Sign in via the Customer Portal.

Book your free IT health check