Six Controls Carry Most of the Risk. Start There, Not With a Fourteen-Point Programme.
Most small companies get sold a security programme when what they need is a short list, in the right order, with someone accountable for it.

This page is that list, including the parts you can do yourself for nothing.
The person who would run your engagement has done this before
security assessments delivered
countries, from startups to critical infrastructure
practising since, founder-led throughout
Alexander Sverdlov, former Microsoft Security Consulting team, CISSP. Work delivered for banks, payment institutions, government bodies and critical infrastructure operators.
See what an attacker would find
Before you buy anything, find out what is actually exposed. A scoped IT security audit answers that in days, not months.
- Review every account, device and cloud tenant to find the gaps a real intruder would use first
- Test your Microsoft 365 or Google Workspace against the settings that ship switched off by default
- Rank findings by what they would actually cost you, so a small budget goes to the right five things

Answer the questionnaire blocking your deal
A bigger customer sent a security questionnaire and the deal now waits on it. Most answers already exist somewhere. The rest are about a fortnight of work.
- Map each question to evidence you already hold, so you attach documents instead of writing prose
- Close the three or four gaps that would force a "no", in the order procurement checks them
- Keep the answers in one place so the next questionnaire takes an afternoon instead of a month
Close the doors attackers actually use
Almost every small-company breach starts in the same handful of places: a mailbox, an admin account, an unpatched laptop, an open port.
- Enforce multi-factor authentication on every account, including the owner and the ones nobody remembers
- Harden email against the invoice fraud and known weaknesses that cost small firms the most money
- Put device protection in place that is enforced by policy rather than assumed to be running

Get the certificate your contract demands
You rarely need a framework because it is good practice. You need it because a customer, an insurer or a regulator named one in writing, with a date.
- Work back from the deadline in the contract, so controls land in the order the auditor checks them
- Reuse one evidence set across SOC 2 and ISO 27001 instead of running two separate programmes
- Get told plainly when a framework is not worth it yet, because readiness for a deal is not certification
Borrow a CISO instead of hiring one
Under about 200 staff a full-time security hire is rarely proportionate, but having nobody accountable is exactly what the questionnaire asks about.
- Put a named person on the org chart who answers customer and insurer questions on your behalf
- Hold a roadmap that survives staff turnover, so security does not restart every time someone leaves
- Scale the time up during an audit and back down afterwards, on a month-to-month basis

Know your first hour
The expensive part of a small-company breach is rarely the attack. It is the two days spent deciding who is in charge and what to tell customers.
- Decide now who can order something disconnected, and who speaks to customers and insurers
- Rehearse the restore, because an untested backup fails on the one day it matters
- Keep the contact list reachable when the network you normally use is the thing that is down

Six things to fix this week, without hiring anyone
This is the list we give clients before we quote anything. None of it needs a budget or a consultant, and doing it will close more risk than most products you could buy. If you take one thing from this page, take this.
- 1
Turn on multi-factor authentication for every account
30 minStart with the owner, the finance mailbox and anyone holding admin rights. This single change blocks most account takeovers.
- 2
Cut full admin rights down to two named people
20 minEveryone else gets a normal account. Admin work happens on a separate login that is not used for email or browsing.
- 3
Check every mailbox for forwarding rules nobody set up
15 minA hidden rule quietly copying mail to an outsider is the usual first sign of invoice fraud, and it is invisible unless you look.
- 4
Restore one real file from backup and time it
45 minA backup you have never restored from is a guess. Find out now whether it works and how long it takes.
- 5
List what is reachable from the internet and close the rest
1 hourOld remote access left open for a supplier is one of the most common ways in. If nothing needs it, shut it.
- 6
Write down who to call at 6pm on a Friday
10 minOne page: who decides, who calls the bank, who calls the insurer, who talks to customers. Keep a copy off the network.
And one rule worth more than any product you could buy
Any request to move money, change bank details or buy gift cards gets verified through a second channel: a phone call to a number you already had, never the number in the email. It does not matter how urgent it sounds or how convincingly it appears to come from the owner. Invoice fraud costs small companies more than ransomware does, it involves no malware at all, and a firewall cannot stop it. Write the rule down, tell the finance team it will never be treated as rude to use it, and it will pay for itself the first time it is needed.
What this costs, and why nobody will quote you online
Headcount is a poor predictor. Two fifty-person companies can differ by a factor of five. These are the things that move the number, so you can work out roughly where you sit before you call anyone.
We quote a fixed price in writing after a scoping call, and for assessments you read the full report before an invoice is issued. If the honest answer is that you do not need an outside firm yet, you will be told that on the call.

Runs every small business engagement personally, from the scoping call to the debrief your engineers attend.
Connect on LinkedInThirty minutes, and you will know what to fix first
A scoping call with the person who would do the work. You leave with the three things most likely to be exposed in your environment, a straight answer on whether you need an outside firm at all, and a fixed price if you do.
Get Your Fixed Price