Cyber Essentials Certified IT Support Sheffield

Adopting a Defence-in-Depth Cybersecurity Strategy

One control failing should not mean everything fails. What layered defence looks like in an organisation that is not a bank.

Every security control fails eventually. The filter lets one through. Somebody approves a multi-factor prompt they should not have. A laptop goes missing on a train. None of that is unusual, and none of it is a disaster on its own — provided something else is standing behind it.

That is all defence in depth means. No single control has to be perfect, because none of them is asked to work alone. The phrase is borrowed from military planning and has been thoroughly overused by security vendors since, but the idea underneath it is sound, and it is achievable for a business of twenty people.

Why one good control is not enough

Take a realistic sequence. An invoice arrives from a supplier you deal with every month, with new bank details on it. It is a good forgery. The filter does not stop it because there is no attachment, no malicious link, and the sending domain is one character different from the real one.

If email filtering is the only thing standing between that message and a payment, the money goes out. If it is one layer of several, other things happen first. Your finance process requires a bank change to be confirmed by telephone on a number you already hold. The sending domain is flagged as first contact. The person reading it was shown this exact pattern in training six weeks ago.

Any one of those stops it. You do not need all three to work, which is the entire point.

The layers, roughly in the order they earn their place

Identity

Multi-factor authentication on every account, with no exception for the directors who find it inconvenient. Rules that block sign-ins from countries you do not operate in. For most small businesses this is the highest-value layer there is, and it is usually included in what you already pay Microsoft.

Email

Filtering, link checking at the moment somebody clicks rather than when the message arrives, and attachments opened somewhere safe first. Most of this comes with Microsoft 365 Business Premium and needs configuring rather than buying — we went through what Defender does and where it needs setting up separately.

Devices

Every laptop known about, encrypted, patched and running endpoint detection. The machine that causes the problem is almost always the unmanaged one, because nothing is watching it and nobody remembers it exists.

People

Short, regular awareness training and simulated phishing. Not to catch anyone out, but so that when the convincing one arrives it looks familiar rather than novel.

Backup

Independent, immutable, and proven by actually restoring from it. Every layer above reduces the chance of an incident. This is the one that caps how bad a bad day gets, and it is the one most often assumed rather than tested.

Detection

Something watching, and somebody reading what it says. An alert arriving in a mailbox nobody opens is not a control, whatever the licence says.

What it looks like when a layer fails

The point of the arrangement is that failure becomes boring. Somebody clicks something they should not have. The endpoint agent stops it running. An alert appears, the account is reset, the device is checked, and the business carries on. Nobody outside IT hears about it and there is no story to tell afterwards.

That is the ordinary outcome in a layered environment. The businesses with the fewest dramatic incidents are usually the ones that spent money on the unglamorous parts.

It also answers the questions you get asked

Cyber Essentials, insurer questionnaires and client security reviews are all asking the same thing in different words: what layers do you have, and can you show they are working. A layered setup answers those forms almost as a by-product, because each layer produces its own evidence. Cyber Essentials in particular maps closely onto the list above, which is why businesses that have done the groundwork tend to pass it without drama.

Where the gaps usually are

When we take over an environment, the gaps are consistent:

  • Multi-factor authentication applied to most people, but not to the two directors who asked to be exempted
  • Backups running nightly and never restored from, so nobody knows what would actually come back
  • Endpoint protection on every machine IT set up, and missing from the three a department bought directly
  • Alerts routed to a mailbox nobody has opened since the person who configured it left
  • Licences already being paid for that include half of this, sitting switched off

None of that is negligence. It is what happens when nobody has had a clear month to look at the whole thing at once.

Where to start

Not by buying anything. Write down what you already have and which of the layers above it covers, then check what your existing Microsoft licensing already includes. In most cases two or three layers are already paid for and half configured, and the work is finishing them rather than replacing them.

If you would like a hand with that, we are happy to go through it with you and tell you what we find.

Next step

Have a look at your setup with us

Thirty minutes, no obligation, and no scripted sales call. You'll come away knowing where you stand, whether or not you work with us.

Book a 30-minute review →