Security and identity

Security your team barely notices, and an attacker cannot ignore

Most small business compromises do not involve anything clever. They involve an account with no second factor, a leaver whose access was never removed, or a laptop nobody can lock remotely.

Security work for a business this size is mostly identity: who has an account, what that account can reach, how they prove it is them, and what happens the day they leave. Devices come next, because an account is only as protected as the laptop or phone it is signed in on.

It applies wherever your systems live. Microsoft 365, Google Workspace, Windows, Apple, or the mixed set most businesses end up with. The tools have different names in each. The questions are identical.

What actually goes wrong

The incidents small businesses get hit by are boring, repetitive, and largely preventable.

An account with no second factor

Somebody reuses a password, that password turns up in an unrelated breach, and a stranger signs in successfully. Multi-factor authentication is the control that makes a stolen password worthless on its own, it is included in what you already pay for, and it is skipped more often than any other setting.

A leaver who never really left

The laptop came back. The accounts did not. Months later nobody can say for certain what a former employee can still reach, and the answer is often the email, the file storage and the shared logins.

Everyone is an administrator

Access gets granted in a hurry and never reviewed, so over a few years everybody accumulates everything. It is not malice, it is drift, and it means one compromised account is a compromise of the whole business rather than one person's mailbox.

A mailbox rule nobody put there

One of the first things an intruder does in a business mailbox is create a quiet forwarding or delete rule, then wait for an invoice conversation. This is how a payment gets redirected, and the account owner sees nothing unusual because the messages are being moved before they read them.

Devices that were handed out, not managed

A laptop set up out of the box, holding company mail and files, with no encryption anyone verified and no way to wipe it if it goes missing. It works fine right up until it is left somewhere.

The controls that earn their place

None of this is exotic. It is the short list that stops the incidents that actually happen to businesses your size.

  • Multi-factor authentication, everywhere. On every account, and on administrator accounts first. Nothing else on this list comes close for the effort involved.
  • Access that matches the job. A periodic look at who can reach what, and the removal of the permissions people picked up for a project that finished two years ago.
  • Conditional access rules. Sign-in conditions that fit how your business actually works, so unusual access gets challenged and normal work does not.
  • Joiners and leavers as a routine. Access granted on day one, removed on the last day, mailboxes converted rather than deleted so customer mail keeps arriving.
  • Devices enrolled, not just issued. Company laptops and phones enrolled so they can be configured, checked and wiped remotely. See Microsoft 365 administration for the Intune and Autopilot side of that.
  • Encryption and patching as a standard. Disk encryption on, updates applied on a schedule rather than whenever somebody clicks the reminder.
  • Security baselines instead of one-off settings. A documented set of defaults for the tenant and the devices, so a new laptop or a new hire starts from the same known position.
  • Mail that can be trusted. SPF, DKIM and DMARC aligned, which protects your name as much as your inbox. If mail is already misbehaving, start at email going to spam.
  • A written record of the above. Who holds administrator access, where recovery details live, and what the standard is. Unexciting, and the thing that turns an incident into an inconvenience.

How we approach it

  1. Find out who can reach what

    Accounts, administrators, shared logins, devices, and anything still active that belongs to somebody who left. For most businesses this is the first full picture they have had.

  2. Close the open doors first

    Multi-factor authentication, live access for leavers, and administrator accounts that belong to a person rather than the business. These are done before anything is tidied or optimised.

  3. Set a baseline

    Agree the standard for accounts, sign-in and devices, then apply it consistently instead of settling it case by case at the moment somebody is waiting.

  4. Bring devices under management

    Enrol the laptops and phones that hold business data, so they can be configured, verified and wiped if one is lost. New devices then arrive already set up.

  5. Write it down and keep it current

    The record of who holds what and where recovery details live, kept as part of technical cleanup and reviewed rather than written once.

Who this is for

  • Businesses where multi-factor authentication was never switched on, or only on some accounts
  • Owners who cannot say with certainty which former employees still have access
  • Anyone who has had a mailbox compromised, or nearly paid a redirected invoice
  • Businesses handing out laptops and phones with no way to manage or wipe them
  • Teams where everybody has administrator rights because it was easier at the time

When this is not the right fit

  • Businesses needing a formal audit or a certification signed off. That is a specialist firm, not us, and we will say so.
  • Regulated environments with a compliance framework to satisfy. We can do the practical groundwork, but we do not attest to anything.
  • Anyone looking for incident response mid-attack. That is a different discipline and speed matters more than familiarity.
  • Businesses wanting a security product resold to them. We do not sell licences, so the recommendation is often to use what you already pay for.

What Tech True Point can help with

Usually it starts with one specific worry, then turns into a tidy-up of everything around it, because the accounts, the devices and the mail are the same problem seen from three sides.

  • Turning on multi-factor authentication without disrupting the working week
  • Identity and access reviews across Microsoft 365, Google Workspace or both
  • Conditional Access and sign-in rules that suit how your business operates
  • Joiner and leaver process, so access starts and stops when it should
  • Device compliance policies, encryption and patch standards
  • Security baselines applied consistently to a tenant and to new devices
  • Cleaning up after a compromised mailbox, including the rules left behind
  • Shared logins replaced with accounts that can be traced to a person
  • Mail authentication so your domain cannot be trivially impersonated, covered further under domains and DNS
  • Documenting administrator access and recovery details for the business, not for us

Common questions

Is this the same as website security?

No, and the difference matters when you are deciding what to spend on. Website security protects the site your customers visit: certificates, hardening, the common attacks against a public page.

This is about the accounts your staff log into and the devices they log in from. A business can have a perfectly secure website and still lose control of its email tomorrow, because those are two separate systems with two separate front doors.

We are small. Is anyone really targeting us?

Almost nothing that reaches a small business is targeted. That is the point. The common compromises are automated and indiscriminate: a password that appeared in somebody else's breach, a convincing sign-in page, a mailbox rule quietly forwarding invoices to an address nobody looks at.

None of that requires anyone to have chosen you. It requires an account without multi-factor authentication, which is free to turn on and is the single highest-value hour anyone can spend here.

Will this make everyday work harder for my team?

It should not, and if a control is making normal work painful it is usually the wrong control rather than a necessary cost. Sign-in prompts that fire on every action, for instance, train people to click through them, which is worse than not having them.

The aim is that the people who work at your business barely notice, and that the change is felt by whoever tries to get in without belonging there.

Does this only apply to Microsoft 365?

No. The same questions apply wherever your accounts live: who has an account, what can they reach, is multi-factor authentication on, and what happens on the day someone leaves. We work across Microsoft 365, Google Workspace, Windows, Apple and the mixed environments most businesses actually run.

The tooling differs. The controls do not.

What happens when someone leaves the business?

That is account lifecycle management, and it is where most small businesses are quietly exposed. Access should be removed the day someone goes, their mailbox converted rather than deleted so customer mail keeps arriving, their sessions ended, and any device they held either returned or wiped remotely.

Done as a routine it takes minutes. Done six months later, after a dispute, it is a scramble in which nobody is certain what that person could still reach.

Can you audit or certify our security?

No. We are not auditors and we hold no certifications, so anything we produced would carry no weight and we would rather say that than sell it. If you need a formal audit, or a framework like SOC 2 or HIPAA signed off, you need a specialist firm and we will tell you so.

What we do is the practical work underneath: the accounts, the access, the devices and the settings that a real assessment would look at first anyway.

Get a Quote

Not sure who can reach what

Most owners are not, and finding out is quick. Tell us where your accounts live and we will tell you what is exposed and what to do first.

Call now Request a quote