SEG Core — managed IT, cyber security and access control. One contractor · one number.
Home / Cyber Security

Cyber security sized for a real SME budget.

Layered protection across endpoint, email, identity and people — plus the certification and evidence your clients and insurers keep asking for.

Cyber

Where we put the layers

Most breaches at SME scale come through email, credentials or an unpatched machine. That's where the effort goes.

Threat protection

Next-generation endpoint protection, email filtering and DNS security deployed and managed — not sold and forgotten.

  • Managed endpoint protection
  • Email & phishing filtering
  • DNS and web filtering
  • Ransomware rollback

User awareness training

Short, regular training plus simulated phishing, because the control that fails most often is a person in a hurry.

  • Simulated phishing campaigns
  • Bite-sized monthly training
  • Reporting by department
  • Policy templates

Identity & access

Multi-factor authentication, conditional access and privilege control across Microsoft 365 — the single highest-value change most SMEs can make.

  • MFA rollout
  • Conditional access policies
  • Privileged account control
  • Password management

Compliance & certification

Cyber Essentials and Cyber Essentials Plus readiness, plus the evidence packs that tender and insurance questionnaires demand.

  • Cyber Essentials readiness
  • Gap analysis & remediation
  • Policy documentation
  • Insurance & tender evidence

Monitoring & response

Security alerting on managed devices and Microsoft 365, with a documented process for what happens when something fires at 3am.

  • Security event monitoring
  • Alert triage
  • Documented incident response
  • Post-incident report

Risk assessment

An honest assessment of where you're exposed, ranked by risk and cost to fix, so you can spend the budget where it counts.

  • Vulnerability assessment
  • Prioritised remediation plan
  • Board-ready summary
  • Annual re-test
How it works

How we harden a business

We work top-down: close the routes attackers actually use before spending money on anything exotic.

1

Assess

A structured review of endpoint, email, identity, backup and physical access, scored against Cyber Essentials controls.

2

Prioritise

A ranked plan — what's urgent, what's important and what can wait — with the cost of each item stated up front.

3

Remediate

MFA, patching, filtering and backup fixed first. Most SMEs close the majority of their real exposure in this phase.

4

Sustain

Ongoing monitoring, monthly training, quarterly review and an annual re-assessment as the estate changes.

Why SEG Core

What makes this different

We fix, not just report

A vulnerability report you can't action is expensive paper. We quote the remediation alongside the finding.

Certification-ready evidence

Policies, asset registers and screenshots collected as we go, so certification and tender questionnaires aren't a scramble.

Physical security counts

Access control, door entry and CCTV are part of your security posture. We design and install those too.

Plain-English reporting

A board summary anyone can read, with the technical detail attached for whoever needs it.

Right-sized tooling

SME-appropriate tools properly configured beat enterprise platforms nobody has time to run.

Insurance questions answered

We'll help you complete cyber insurance questionnaires accurately — getting one wrong can void the policy.

FAQ

Common questions

What is Cyber Essentials and do we need it?
Cyber Essentials is a UK government-backed certification covering five basic technical controls. It's increasingly mandatory for public sector contracts and supply-chain work, and many insurers now ask about it. Cyber Essentials Plus adds an independent technical audit.
We're small. Are we really a target?
Most attacks on small businesses aren't targeted — they're automated, sweeping for exposed services, reused passwords and unpatched machines. Being small doesn't make you invisible; it usually just means less has been hardened.
What's the single most valuable thing we could do?
Multi-factor authentication on every account, without exception. It blocks the overwhelming majority of credential-based attacks and costs almost nothing beyond the effort of rolling it out properly.
Do you do penetration testing?
We arrange independent penetration testing through specialist partners where it's genuinely warranted, and we handle the remediation afterwards. For most SMEs, a vulnerability assessment and proper hardening delivers more per pound spent.
What happens if we're breached?
We follow a documented incident response process: contain, assess, recover, report. Clients on a managed agreement get that process agreed and rehearsed in advance rather than invented under pressure.
Can you work alongside our existing IT provider?
Yes. Security-only engagements are common where a client is happy with their IT support but wants independent security expertise.

Let's get your IT on a proper footing.

Book a free, no-obligation IT review. We'll look at your support, security and network, and tell you plainly what's working and what isn't.

Book a free IT review Call 01727 822 833
Get in touch

Tell us what you need

Send us a few details and one of our engineers — not a call centre — will come back to you within one working day.

Visit usSEG House, 192 Watford Road, Chiswell Green, St Albans, Herts AL2 3EB
Helpdesk hoursMonday to Friday, 08:00–18:00 · out-of-hours cover available
No obligation · We never share your details · See our privacy notice