Why It Matters To You

Smaller firms are targeted precisely because they are smaller.

There is a common assumption that attackers only go after big organisations. The opposite is true. A twenty-person professional firm holds much the same client data as a large one, with a fraction of the defences and nobody whose only job is to watch for trouble. That combination is attractive, and most attacks are not personal. They are automated, and they find you because you are reachable.

Three things tend to put professional firms in the frame. The first is the client data you hold — identity documents, financial records, case files. It is valuable to someone else, and losing it damages relationships you have spent years building.

The second is payment redirection. If your business sends or receives money on behalf of clients, an attacker who can read your email can wait quietly for the right moment and change a set of bank details. The email looks normal because it is genuinely your email. This is now one of the most common and most expensive things that happens to small firms.

The third is regulatory exposure. Your professional body, your insurer and the ICO all expect you to be able to show what you did to protect the data you hold. After an incident, “we thought it was covered” is not an answer anybody accepts.

None of that is meant to frighten you. Most of the risk is closed off by a handful of controls done properly and kept up. That is the work.

A Trunnion engineer at a desk with a client, pointing at a screen while
                    they talk through it together.
What We Manage

Eight controls, managed together.

Security fails at the joins. Antivirus from one supplier, backup from another and training from a third leaves gaps that nobody owns. We run all of it, so there is one person to ask and one place the answer comes from.

Cyber Essentials & Cyber Essentials Plus

The government-backed standard covering the controls that stop most opportunistic attacks. We get you ready, walk you through the assessment and keep you there at renewal.

Managed detection & response

Someone watching your systems out of hours, not a dashboard nobody opens. Unusual activity gets investigated and contained, then explained to you in plain English.

Email security & defence

Most attacks arrive by email. We filter what we can, flag what looks wrong and lock down the settings that let someone send mail pretending to be you.

Endpoint protection & device management

Every laptop, desktop and phone enrolled, encrypted and kept up to date. If a device is lost on a train, we can wipe it before anyone opens it.

Backup & disaster recovery

Your last line of defence. Copies held separately from your live systems, tested on a schedule, with a recovery time we have agreed with you in advance.

Security awareness training

Short, human training that respects your team’s time. Simulated phishing shows where the gaps are so you can close them, without anyone being made to feel foolish.

Vulnerability & patch management

Known weaknesses are how most breaches start. We scan for them, patch on a schedule and tell you honestly about anything we cannot quietly fix.

Access control & Compliance

The right people with the right access, and a record you can show a client, an insurer or a regulator. Multi-factor as standard and leavers removed the same day.

How We Work

Plain language, no scare tactics.

Security advice is often sold with fear. We would rather explain the risk, tell you what it would take to close it, and let you decide with the facts in front of you.

  1. We tell you where you actually stand A written picture of your current position, including the parts that are already fine. You will not be told everything is broken.
  2. We fix the cheap, high-value things first Multi-factor authentication, leaver processes, mail settings and patching close off most of the risk for very little money.
  3. We are honest about what we cannot fix Some things need a decision from you, a supplier change, or budget. We will say so rather than quietly leaving it on the list.
  4. We keep checking Security is not a project with an end date. Monitoring, patching and training carry on, and you see the results every month.
Free Security Review

Find out where you stand, at no cost.

We will look at your current setup and give you a written summary of what is protecting you, what is not, and what we would do first. It takes about an hour of your time. There is no charge and no obligation to do anything with it.

Let’s Talk

Want to know how Trunnion can help your business?

If you are not sure how exposed you are, that is the normal starting point. Ask us and we will find out with you.