Find out more

Not sure what you need?

Our discovery process can help you uncover the right way forward for your business. Simply fill in our 3-minute form and we’ll give you free, no-obligation advice unique to you.

Find out more

Security & compliance FAQs

Security and compliance can feel unclear, especially when questions start coming from customers, investors, or insurers. These FAQs cover the things small businesses ask us most often, in plain English and without unnecessary detail.

If you’re looking for quick clarity rather than theory, you’re in the right place.
Compliance System security
How do we know if we need external help?

If security questions are slowing sales, you’ve had a near miss, you’re preparing for certification, or you’re unsure whether you’re “secure enough”, external support usually pays for itself.

System security
Where should we start with security?

Start with visibility: what devices, systems, and data you have. Then focus on the basics. Don’t try to do everything at once – prioritise by risk.

Compliance
A customer wants a SOC 2 report and we don’t have one. What should we do?

Be transparent. Explain what you can provide instead and ask what they’re actually trying to assess. If multiple customers are asking, it may be worth investing. If it’s a one-off, negotiation is often possible.

Compliance System security
What do cyber insurers care about?

The basics: MFA, endpoint protection, patching, tested backups, and staff training. If you can’t demonstrate these, expect higher premiums or limited cover.

Compliance Privacy System security
How do we handle customer security questionnaires?

Create a standard set of approved responses covering your controls, policies, and processes. Most questionnaires ask similar questions, just worded differently.

Compliance System security
Can we do ISO 27001 ourselves?

Some businesses can, but many choose external support due to time and expertise constraints.

Compliance
How long does ISO 27001 take?

Typically 3–9 months for a small business, depending on your starting point and available resources. Rushing often creates problems later.

Compliance
Do we need ISO 27001 certification?

It depends. If customers, regulators, or investors are asking for it, certification can remove friction. If no one is asking, formal certification may not be necessary yet, but the framework is still useful.

Compliance
What is ISO 27001?

ISO 27001 is an international standard for managing information security risks through a structured management system. Certification means an independent auditor has verified that the system meets the standard.

Compliance
How long can we keep personal data?

Only for as long as you need it for the original purpose. Clear retention periods reduce risk and simplify compliance.

Compliance Privacy
What happens if we have a data breach?

You must assess the risk to individuals. If there’s a risk, the ICO must be notified within 72 hours. High-risk breaches also require notifying affected individuals. Everything should be documented, even if you decide not to report.

Compliance
Do we need a Data Protection Officer?

Only in specific circumstances. Most small businesses don’t legally need one, but having clear ownership of data protection responsibilities is good practice.

Compliance Privacy
Does GDPR apply to us?

If you process personal data of people in the UK or EU (customers, employees, or website visitors), then yes. Size doesn’t remove the obligation, but expectations are proportionate to your scale and risk.

System security
What should we do if we think we’ve had a breach?

Act calmly but quickly. Contain the issue if possible, preserve evidence, notify your cyber insurer early, and assess any legal reporting obligations. If you’re unsure, get expert help.

System security
How often should we review our security?

At least annually, with some areas reviewed more often. Patching should be continuous, access reviewed quarterly, and security tools checked regularly. Any major business change should also trigger a review.

System security
What security tools do we actually need?

For most small businesses: device management, endpoint protection, email security, MFA, and reliable backups. More tools aren’t better; properly configured tools, with someone paying attention, are what matter.

System security
Do we need a dedicated security person?

Not usually. Many businesses with 20–200 employees manage security with IT handling day-to-day tasks and external support for strategy, assessments, or incidents. A fractional or virtual CISO often makes more sense than a full-time hire.

System security
What causes most security incidents in small businesses?

Most incidents aren’t sophisticated attacks. They’re caused by basics being missed: phishing emails, missing MFA, unpatched systems, or poor backups. Getting the fundamentals right removes the majority of risk.

System security
How do I know if my business is “secure enough”?

There’s no such thing as perfect security. “Secure enough” means having controls that are proportionate to your size, industry, and risk. At a minimum, that usually includes MFA everywhere, managed and encrypted devices, prompt patching, tested backups, and someone actively paying attention to alerts.

If you’re being asked questions you can’t confidently answer, it’s usually time for an independent sense-check.

System security
Can you work with our existing security tools and vendors?

Absolutely. We’re vendor-agnostic and experienced in integrating with diverse technology stacks. We’ll assess your current tools, optimize their configuration, and identify gaps where additional solutions may be beneficial. Our focus is maximizing the value of your existing investments while strategically enhancing your security posture.

Privacy
How often should we conduct security assessments?

We recommend quarterly vulnerability assessments and annual penetration tests as a baseline. However, you should conduct assessments whenever you make significant infrastructure changes, deploy new applications, or experience a security incident. Organizations in regulated industries may require more frequent assessments.