Cyber Security Services for UK Small and Medium Businesses
Cipher Knights is a Leicester-based cyber security and IT company working with small and growing UK businesses. We find the gaps, fix them in priority order, help you certify, and stay on hand when something breaks.
What cyber security services do small businesses actually need?
Most UK small businesses need four things: a vulnerability assessment to find what is exposed, Cyber Essentials to prove a baseline to customers and insurers, hardened networks and cloud accounts, and a tested plan for when something goes wrong. Cipher Knights delivers all four from Leicester, priced for SMEs.
Security work sized for a real small business
Most cyber security is sold to organisations with a security team, a budget line and a compliance department. Small businesses have none of those, which is why so much security advice goes unread. Cipher Knights exists for the other end of the market: the twelve-person accountancy practice, the family manufacturer, the dental group, the online retailer with one part-time IT contractor.
Every engagement starts with the same question — what would actually hurt this business? For an e-commerce firm it is card data and website downtime. For a healthcare practice it is patient records and an ICO notification. For a manufacturer it is a ransomware event stopping the line. We scope the work against that answer rather than against a generic checklist, so you spend money on the controls that change your risk.
- Fixed-scope, fixed-price engagements — no open-ended day rates
- Findings written for a business owner, with a technical annex for your IT provider
- Every finding ranked by real-world exploitability, not just CVSS score
- Remediation guidance you can hand straight to whoever manages your systems
Where most small businesses are actually exposed
Across the assessments we run, the same handful of issues account for the large majority of genuine risk. Almost none of them involve exotic attacks. They are unpatched internet-facing software, Microsoft 365 accounts without multi-factor authentication, flat internal networks where one infected laptop reaches every server, forgotten administrator accounts belonging to people who left, and backups that have never been restored from.
That is good news, because it means meaningful improvement is usually achievable in weeks rather than years. Our job is to tell you which five things to do first and to be specific about how to do them — not to hand you a 90-page report and an invoice.
- Internet-facing systems missing security updates
- Email and cloud accounts without multi-factor authentication
- Over-privileged and orphaned user accounts
- Flat networks with no separation between guest, staff and server traffic
- Backups that are never tested, or are reachable from the same network
- Staff who have never been shown what a modern phishing email looks like
How an engagement runs
We keep the process short and predictable. A free scoping call establishes what you run and what matters. We then send a written scope and fixed price before any work begins, so there are no surprises. Testing or review work happens on agreed dates, with a named consultant you can contact directly throughout.
You receive the report, we walk you through it on a call, and — where you want it — we help implement the fixes or work alongside your existing IT provider. Where a finding is critical we tell you the same day rather than waiting for the report.
- 1. Free consultation — 30 to 60 minutes, remote or on-site in Leicester
- 2. Written scope, timeline and fixed price for your approval
- 3. Assessment or implementation work on agreed dates
- 4. Report plus a walkthrough call in plain English
- 5. Remediation support, then a free retest of the issues we found
Working alongside your existing IT provider
A lot of our clients already have an IT support company they are happy with. We are not trying to replace them. Security assessment and day-to-day IT support are genuinely different disciplines, and there is a reason auditors prefer the two to be separate — the people who built a configuration are rarely the best people to find its flaws.
Where you want a single supplier we can take on the IT support too. Where you do not, we write our findings so that your provider can act on them without a translation layer, and we are happy to join a call with them.
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Master Services Agreement (MSA)
The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.
UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified
Cyber Security Services — your questions answered
How much does a cyber security assessment cost for a small business?
Do you only work with businesses in Leicester?
We have no IT staff at all. Can you still help?
What is the difference between a vulnerability assessment and a penetration test?
How quickly can you start?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about cyber security services?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.