Six Controls Carry Most of the Risk. Start There, Not With a Fourteen-Point Programme.

Most small companies get sold a security programme when what they need is a short list, in the right order, with someone accountable for it.

Six Controls Carry Most of the Risk. Start There, Not With a Fourteen-Point Programme. - Atlant Security

This page is that list, including the parts you can do yourself for nothing.

The person who would run your engagement has done this before

200+

security assessments delivered

14

countries, from startups to critical infrastructure

2013

practising since, founder-led throughout

Alexander Sverdlov, former Microsoft Security Consulting team, CISSP. Work delivered for banks, payment institutions, government bodies and critical infrastructure operators.

Security audit

See what an attacker would find

Before you buy anything, find out what is actually exposed. A scoped IT security audit answers that in days, not months.

  • Review every account, device and cloud tenant to find the gaps a real intruder would use first
  • Test your Microsoft 365 or Google Workspace against the settings that ship switched off by default
  • Rank findings by what they would actually cost you, so a small budget goes to the right five things
How the audit works
Security analyst reviewing exposure across a small business environment
Customer questionnaires

Answer the questionnaire blocking your deal

A bigger customer sent a security questionnaire and the deal now waits on it. Most answers already exist somewhere. The rest are about a fortnight of work.

  • Map each question to evidence you already hold, so you attach documents instead of writing prose
  • Close the three or four gaps that would force a "no", in the order procurement checks them
  • Keep the answers in one place so the next questionnaire takes an afternoon instead of a month
Risk assessment and evidence
What drives the cost of answering a vendor security questionnaire
Everyday defences

Close the doors attackers actually use

Almost every small-company breach starts in the same handful of places: a mailbox, an admin account, an unpatched laptop, an open port.

  • Enforce multi-factor authentication on every account, including the owner and the ones nobody remembers
  • Harden email against the invoice fraud and known weaknesses that cost small firms the most money
  • Put device protection in place that is enforced by policy rather than assumed to be running
Vulnerability management
Phishing and ransomware attacks stopped before they reach a small office network
Compliance

Get the certificate your contract demands

You rarely need a framework because it is good practice. You need it because a customer, an insurer or a regulator named one in writing, with a date.

  • Work back from the deadline in the contract, so controls land in the order the auditor checks them
  • Reuse one evidence set across SOC 2 and ISO 27001 instead of running two separate programmes
  • Get told plainly when a framework is not worth it yet, because readiness for a deal is not certification
Every framework we run
Security leadership

Borrow a CISO instead of hiring one

Under about 200 staff a full-time security hire is rarely proportionate, but having nobody accountable is exactly what the questionnaire asks about.

  • Put a named person on the org chart who answers customer and insurer questions on your behalf
  • Hold a roadmap that survives staff turnover, so security does not restart every time someone leaves
  • Scale the time up during an audit and back down afterwards, on a month-to-month basis
Virtual CISO services
Small business team working under a managed security programme
After an incident

Know your first hour

The expensive part of a small-company breach is rarely the attack. It is the two days spent deciding who is in charge and what to tell customers.

  • Decide now who can order something disconnected, and who speaks to customers and insurers
  • Rehearse the restore, because an untested backup fails on the one day it matters
  • Keep the contact list reachable when the network you normally use is the thing that is down
Incident response
Small business team reacting to a ransomware screen

Six things to fix this week, without hiring anyone

This is the list we give clients before we quote anything. None of it needs a budget or a consultant, and doing it will close more risk than most products you could buy. If you take one thing from this page, take this.

  1. 1

    Turn on multi-factor authentication for every account

    30 min

    Start with the owner, the finance mailbox and anyone holding admin rights. This single change blocks most account takeovers.

  2. 2

    Cut full admin rights down to two named people

    20 min

    Everyone else gets a normal account. Admin work happens on a separate login that is not used for email or browsing.

  3. 3

    Check every mailbox for forwarding rules nobody set up

    15 min

    A hidden rule quietly copying mail to an outsider is the usual first sign of invoice fraud, and it is invisible unless you look.

  4. 4

    Restore one real file from backup and time it

    45 min

    A backup you have never restored from is a guess. Find out now whether it works and how long it takes.

  5. 5

    List what is reachable from the internet and close the rest

    1 hour

    Old remote access left open for a supplier is one of the most common ways in. If nothing needs it, shut it.

  6. 6

    Write down who to call at 6pm on a Friday

    10 min

    One page: who decides, who calls the bank, who calls the insurer, who talks to customers. Keep a copy off the network.

And one rule worth more than any product you could buy

Any request to move money, change bank details or buy gift cards gets verified through a second channel: a phone call to a number you already had, never the number in the email. It does not matter how urgent it sounds or how convincingly it appears to come from the owner. Invoice fraud costs small companies more than ransomware does, it involves no malware at all, and a firewall cannot stop it. Write the rule down, tell the finance team it will never be treated as rude to use it, and it will pay for itself the first time it is needed.

What this costs, and why nobody will quote you online

Headcount is a poor predictor. Two fifty-person companies can differ by a factor of five. These are the things that move the number, so you can work out roughly where you sit before you call anyone.

Six free security fixes a small business can make this week: MFA, admin accounts, mail forwarding rules, a backup restore test, internet-facing services, and an out-of-hours contact
What raises and lowers the cost of a small business security engagement

We quote a fixed price in writing after a scoping call, and for assessments you read the full report before an invoice is issued. If the honest answer is that you do not need an outside firm yet, you will be told that on the call.

Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Runs every small business engagement personally, from the scoping call to the debrief your engineers attend.

Connect on LinkedIn
The person on your first call is the person who does the work. No junior bench.
No reseller agreements or vendor commissions, so a recommendation to buy is never about our margin.
Scope and price agreed in writing before anything starts.
For assessments, you read the full report before an invoice is issued.
Month to month where the work is ongoing. No annual lock-in to begin.

Thirty minutes, and you will know what to fix first

A scoping call with the person who would do the work. You leave with the three things most likely to be exposed in your environment, a straight answer on whether you need an outside firm at all, and a fixed price if you do.

Get Your Fixed Price

Or pick a time directly

Small business cybersecurity FAQ

What cybersecurity does a small business actually need?
Six things carry most of the risk: multi-factor authentication on every account, a short list of admin users, enforced device protection, a backup you have actually restored from, control of what is reachable from the internet, and a written plan for who does what during an incident. Everything else is refinement. A company under roughly 200 staff with those six in place is ahead of most of its peers.
How much does cybersecurity cost for a small business?
Scope decides it, not headcount. Two fifty-person companies can differ by a factor of five depending on how many legal entities they have, whether they still run their own servers, whether they build software, and whether a contract names a framework. A single-entity company living entirely in Microsoft 365 sits at the cheap end. We quote a fixed price in writing after a scoping call, and for assessments you pay after you have read the report.
Can I do any of this myself?
Yes, and you should start today. Turning on multi-factor authentication, reducing admin accounts, checking mailboxes for forwarding rules nobody set, and testing one real restore will close more risk than most tools you could buy. None of it costs money. The six-item list on this page is the one we give clients before we quote anything.
Is my company too small to be a target?
Targeting is mostly automated, so size rarely protects you. Attacks on small companies are usually opportunistic: a password that appears in a breach dump, an exposed remote access service, an invoice redirected after someone reads a mailbox. None of that requires anyone to have chosen your company specifically.
We already have an IT provider. Why would we need anyone else?
IT and security are different disciplines. Your IT provider builds and maintains systems and is usually measured on uptime. Security work is adversarial: it asks how those same systems would be attacked. Good IT providers welcome an independent review, and many of our engagements run alongside one rather than instead of one.
How long does it take?
A scoped audit of a small environment is typically two to three weeks from access to report. The fixes that matter most are usually done within the first few days of remediation, because they are configuration changes rather than purchases. Framework readiness takes longer and is driven by the deadline in your contract.
What do we get at the end?
A report that names the system, the exposure and the fix rather than a maturity score, a remediation plan with owners and dates, and evidence packaged the way a customer or auditor asks for it. Your engineers are invited to the debrief, not just the person who signed the order.