Cyber Security for Small Businesses

Business technology protected by managed cyber security

Cyber security for small businesses

Practical cyber security for small businesses

Protect devices, email, identities, cloud services and networks with proportionate controls, managed security and advice your team can understand.

Security that fits the business

Small organisations need more than basic antivirus

Cyber security works best as a set of connected protections around the technology, information and working practices your organisation relies on.

JM Restart takes a practical, layered approach. We can help identify important risks, improve everyday controls and bring suitable managed protection into the wider IT support relationship. The aim is to reduce avoidable exposure and make the response clearer when something looks wrong.

No product or configuration can remove every risk. Good security also depends on supported systems, clear responsibilities, sensible user behaviour, tested backups and decisions that are reviewed as the organisation changes.

A useful starting point

  • Review devices, accounts, email and cloud services
  • Strengthen access and multi-factor authentication
  • Protect endpoints with managed detection and response
  • Improve firewall, network and remote-access controls
  • Plan backup, recovery and incident responsibilities

Layered business protection

Secure the connected parts of your working environment

The appropriate controls depend on risk, licences, equipment and the agreed service. These areas should support one another rather than operate as isolated products.

Endpoint protection and MDR

Managed protection for covered computers using Bitdefender GravityZone Secure Plus with Managed Detection and Response.

Email security

Layered filtering, sender authentication and practical investigation to reduce email-borne risk and improve deliverability.

Identity and cloud security

Microsoft 365 hardening, multi-factor authentication, Entra ID, Conditional Access, administrative-access and tenant-security reviews.

Firewalls and networks

Firewall, VPN, router, Wi-Fi and network configuration using suitable technology such as Fortinet or DrayTek where appropriate.

Backup and recovery

Independent SaaS backup, local-backup planning, recovery priorities and test restores considered as connected resilience measures.

People and policies

Security training, working-practice reviews and clear IT policies covering passwords, access, remote working, email, data handling and staff responsibilities.

Managed protection in Bronze

Security is part of the managed IT relationship

Bronze Managed IT Support includes one Bitdefender GravityZone Secure Plus licence with MDR per managed device, together with email security for the agreed scope.

Bitdefender Secure Plus combines endpoint security with 24/7 threat monitoring, detection and response delivered through Bitdefender’s security specialists. JM Restart manages the customer relationship and wider IT context during its agreed support hours and under the service arrangements set out in the proposal.

Microsoft 365 monitoring, network monitoring and OpenText SaaS backup are also included on the standard Bronze basis. The service quotation identifies the covered devices, backup users, cloud environment and responsibilities.

Additional security options

  • Cyber Essentials and Cyber Essentials Plus preparation
  • CyberSmart Active Protect
  • CyberSmart or KnowBe4 security training
  • Authorised phishing simulations and spot checks
  • Bitdefender PHASR
  • PCI DSS readiness and penetration-testing support

Options are assessed and quoted around the organisation rather than added automatically.

MDR and EDR

Choose the response model as well as the software

Detection technology is most useful when somebody is responsible for reviewing alerts and deciding what happens next.

Endpoint Detection and Response provides tools and evidence for investigating suspicious activity. Managed Detection and Response adds specialist monitoring and response around that capability. JM Restart recommends MDR for suitable business customers because it can add security expertise beyond a traditional antivirus product.

EDR remains available in appropriate cases. The correct route depends on the customer’s risk, internal capability, devices, budget and agreed incident responsibilities.

Existing security arrangements

Support continuity without leading with legacy products

New Bronze agreements use Bitdefender as the standard managed-security platform. JM Restart can continue supporting existing Trend Micro Worry-Free Business Security Services arrangements where they remain in use.

A security review can help decide whether an existing product remains appropriate, should be reconfigured or belongs in a planned migration. A change should be based on the customer’s risk and operational needs rather than a brand change alone.

Microsoft 365 and email

Strengthen the accounts attackers often target first

Business email and cloud identities need clear access controls, secure administration and domain records that support trusted delivery.

JM Restart can help with multi-factor authentication, Entra ID, Conditional Access, administrator access, mailbox permissions and Microsoft 365 security hardening. Email work can include security services, SPF, DKIM and DMARC configuration and investigation of deliverability concerns.

We can also help customers build safer email habits through training material, authorised phishing simulations and practical spot checks. Results should be used to guide supportive follow-up training and improve working practices, not simply to catch people out.

Exact capabilities depend on the customer’s Microsoft licences and configuration. Some identity, device-management and security controls may require an appropriate Microsoft 365 plan.

Explore Microsoft 365 and cloud support →

A review can consider

  • Multi-factor authentication coverage
  • Privileged and administrator accounts
  • User onboarding and offboarding
  • Conditional Access and device requirements
  • External forwarding and mailbox permissions
  • SPF, DKIM, DMARC and email security

Cyber Essentials readiness

Turn certification questions into practical improvements

We actively encourage customers to work towards Cyber Essentials and, where appropriate, Cyber Essentials Plus certification.

JM Restart can work through the Cyber Essentials questionnaire with your team, review how people and technology operate in practice, identify gaps and help implement suitable improvements. CyberSmart and CyberSmart Active Protect can support ongoing device checks, policy management and security awareness, while custom scripts can help check and maintain agreed configuration standards across covered accounts and devices.

The formal assessment and certificate are completed through the appropriate Cyber Essentials certification route. We help make the preparation clear, accurate and useful to the business beyond assessment day.

Firewalls and routers

Review how internet-facing connections and network boundaries are protected and administered.

Secure configuration

Reduce unnecessary services, insecure defaults and avoidable exposure across covered systems.

Security update management

Understand supported software, patching responsibilities and how important updates are applied.

User access control

Give people appropriate access, protect privileged accounts and remove access when it is no longer needed.

Malware protection

Use suitable protection and working practices to reduce the likelihood and impact of malicious software.

Questionnaire and evidence

Clarify scope, work through the questionnaire, document the environment and prepare accurate answers before the formal assessment route.

People, information and assurance

Security needs to work beyond the device

Technology controls are stronger when staff understand them, access is reviewed and the organisation can explain how important information is handled.

Training and safer habits

Training materials, CyberSmart or KnowBe4 programmes, phishing awareness and authorised simulations can help staff recognise risk and practise safer decisions.

Access, data and policies

Review staff access, data storage, retention, working practices and IT policies, with practical technical improvements that can support the organisation’s wider UK GDPR responsibilities.

PCI DSS and security testing

Help reviewing PCI DSS readiness and arranging appropriately scoped penetration testing. Where independent validation or specialist accreditation is required, we will make the delivery route and responsibilities clear.

A controlled improvement route

Make the next security decision manageable

Assess

Understand devices, accounts, cloud services, networks, data and current responsibilities.

Prioritise

Separate urgent exposure from longer-term improvements and compliance objectives.

Protect

Implement the agreed controls, services and documentation in a controlled order.

Review

Revisit risks, alerts, changes and recovery plans as the organisation develops.

Common questions

Business cyber security, explained

Is cyber security included in Bronze Managed IT Support?

Yes. The standard Bronze basis includes one Bitdefender GravityZone Secure Plus licence with MDR per managed device, email security, Microsoft 365 monitoring, network monitoring and OpenText SaaS backup. The quotation confirms the covered devices, users and services.

What is the difference between MDR and antivirus?

Traditional antivirus focuses primarily on identifying and blocking malicious software. MDR adds specialist monitoring, investigation and response around security events. It still forms one layer of the wider security and recovery plan.

Can you guarantee that we will not have a cyber incident?

No responsible provider can guarantee that every incident will be prevented. JM Restart can help reduce avoidable risk, improve detection and clarify the response, while explaining the responsibilities that remain with the customer and other providers.

How do you help with Cyber Essentials?

We can work through the questionnaire with you, review the environment and working practices, help prepare accurate evidence and implement agreed improvements. CyberSmart tools can also support ongoing device checks, policies and staff awareness. Formal assessment and certification use the appropriate Cyber Essentials certification route.

Can you help with PCI DSS or penetration testing?

Yes. We can help review the technology and evidence involved in PCI DSS readiness and help scope or arrange penetration testing. The quotation will identify whether work is delivered by JM Restart or an appropriate independent specialist, and formal validation remains with the suitably qualified party where required.

Can you improve our Microsoft 365 security?

Yes. Work can include multi-factor authentication, Entra ID, Conditional Access, administrative access, mailbox permissions, email authentication and other controls supported by the customer’s licences.

What should we do if we think an account or device is compromised?

Contact JM Restart promptly using the agreed support route and explain what has been observed. Do not delete evidence or continue using a device if doing so may make the situation worse. The available response depends on the service agreement, access and incident circumstances.

Ready to understand your next security priority?

Tell us about your organisation, current protection and the concerns you want to address.