Do you need help & advice with AI & Automation or Cybersecurity?
Most business leaders brush off cybersecurity until a crisis forces their hand. The truth is, a ransomware attack can easily wipe out a quarter of a million pounds or more in recovery costs. Instead of waiting for a disaster, let’s look at how you can take control, manage your vulnerabilities, and actually sleep at night.
Key takeaways
- Budget for at least £20 per user, per month, specifically for cyber protection.
- Move beyond simple antivirus; focus on proactive tools like privilege management.
- Mandatory, ongoing staff training is your strongest line of defence against phishing.
- Stop treating compliance as a tick-box exercise and start treating it as a risk assessment.
Rethinking your attitude to risk
I see it all the time. Leaders get busy with growth and forget that their digital back door is wide open. They assume their IT provider has it handled, or worse, they think they are too small to be a target. That is exactly the mindset attackers are looking for. At Good Choice IT, we see far too many businesses in London and Surrey doing the bare minimum. You need to move from a reactive ‘it won’t happen to me’ approach to a proactive, no-nonsense strategy that assumes the threat is constant.
The bare minimum for modern security
If you are only paying for an old-school firewall or basic antivirus, you are essentially trying to lock a bank vault with a piece of string. In 2024, the landscape is much more aggressive. You need to allocate a realistic budget. If you aren’t investing around £20 per user, per month on security, you are likely missing essential layers of protection.
| Feature | Why it matters |
|---|---|
| Multi-Factor Authentication (MFA) | Prevents unauthorised access even if a password is stolen. |
| Privilege Escalation Management | Stops staff from accidentally installing malicious software. |
| Next-Gen AI Antivirus | Uses machine learning to hunt threats before they can do damage. |
| Mandatory Phishing Training | Turns your staff from a risk factor into a human firewall. |
Taking control of your digital environment
Beyond the budget, you need to tighten up how your team interacts with your systems. Human error is still the biggest cause of breaches. We hear horror stories about people using the same password for everything or keeping their work logins synced to personal social media accounts.
We need to shift towards passwordless logins and ensure every single account uses MFA. Furthermore, you should look at tools like Threat Locker or similar solutions that control privilege. Instead of letting anyone install anything, these tools force a request process. It stops unauthorised applications before they can even touch your network.
It is also high time to stop giving every employee global admin rights. Do they need access to the payroll folders? Probably not. By siloing your data, you ensure that if one account is compromised, the attacker can’t easily drift into your most sensitive files.
Why tick-box compliance isn’t enough
Many businesses treat certifications as a simple checklist. They tick the boxes for the bare necessities and then stop thinking about it. That is a dangerous game. My advice? Don’t blindly trust your IT team when they say everything is ‘covered.’ Ask them specifically about the biggest risks to your business and look for an explanation that makes sense to you.
If you are navigating this, remember that your goal is to align your IT strategy with your actual business risk. It’s not about buying the fanciest tool; it’s about knowing where your data lives, who has access to it, and how quickly you can detect a threat if it lands on your system. If you want a sanity check on your current setup, we at Good Choice IT are always here to help you cut through the noise and get straight to the solutions that matter.

