What network security actually covers
If email security guards the front door people knock on, network security is the building itself: a properly managed firewall at the perimeter (not the ISP router's factory settings); segmentation so guest WiFi, card machines, CCTV and office PCs live on separate networks โ a compromised smart kettle shouldn't be able to see your server; secure remote access via VPN or zero-trust rather than remote desktop exposed to the internet (the single most common way UK SMEs actually get breached โ we close it constantly); and monitoring that notices the strange before it becomes the catastrophic.
Right-sized, honestly
A ten-person office doesn't need an enterprise SOC โ it needs the correct small version: business-grade firewall managed and updated, three or four sensible network segments, MFA'd remote access, and someone watching the logs who'd notice a device talking to somewhere it shouldn't. That's affordable, deployable in days, and eliminates the attack paths that produce most UK SME incidents. Because we also run your connectivity and WiFi, the network gets designed secure rather than patched secure โ one team, no gaps between suppliers where problems hide.
Related: Managed IT (pillar) ยท Microsoft 365 ยท Email security ยท Cyber security
The layers, in plain English
Network security is easiest to understand as layers, each answering a different question. The firewall answers "what's allowed in and out?" โ it's the front door, and like a front door it's only useful if it's actually locked and someone maintains the lock. Segmentation answers "if something gets in, how far can it spread?" โ guest WiFi that can see your card machines, or a CCTV recorder on the same network as your accounts PC, are the classic small-business versions of leaving every internal door open. Secure remote access answers "how do staff get in from outside without leaving a window open?" โ the era of exposing things directly to the internet and hoping is over, and most real-world breaches of small firms start exactly there.
Then come the layers people forget. WiFi security answers "who can join the network at all?" โ a strong password shared with every ex-employee since 2019 is not an access policy. Email security sits slightly apart but matters more than any of it in practice, because most attacks on small businesses arrive as an email, not a network intrusion. And monitoring answers the question nobody asks until it's urgent: "how would we even know?" Most small firms that get compromised find out from a customer, a bank, or a ransom note โ not from their own systems.
What does right-sized look like? For a typical small business: a properly configured and maintained firewall, guest and operational traffic separated, remote access through modern secure methods rather than open ports, WiFi with per-person credentials where it matters, and email protection doing the heavy lifting. That's not an enterprise stack and doesn't carry an enterprise price. What it mostly requires is someone actually doing it โ most of the vulnerable networks we inherit aren't missing technology, they're missing maintenance. The firewall was fine in 2021; nobody has looked at it since.
The questions worth asking any provider, including us: who updates the firewall, and when was it last done? What happens when someone leaves โ what access dies with their exit? If the guest WiFi were compromised tomorrow, what could an attacker reach? If you don't get plain answers, you've learned something important about the provider. Ours are on this page and in the quote, in writing.
Frequently asked questions
Is our ISP router's firewall enough?
For a business, honestly no โ factory-mode routers offer minimal protection and no management. A managed business firewall is the baseline, and it's cheaper than its reputation.
What is network segmentation in plain terms?
Separate lanes for separate traffic: guests, payments, cameras and office systems each isolated, so a compromise in one can't reach the others.
Can you secure a network another company installed?
Yes โ audit, quick wins first (exposed remote access closed same-day), then the staged hardening plan with costs stated plainly.