PassCyber
PassCyber / Guides

Buying cyber security services as a small business — without being sold fear

The market sells small businesses everything from £5 antivirus to £50,000 “security operations”. Most of it is mismatched to what a small organisation actually needs. Here's the honest shopping list, in the right order — and the questions that expose providers worth avoiding.

Reading time 6 minutes

The three things you might actually be buying

Day-to-day IT security — someone keeping devices patched, MFA enforced, backups running, email filtered. For most small businesses this is an MSP (managed service provider) on a monthly per-user fee, and it's the genuine foundation: unglamorous configuration discipline prevents the overwhelming majority of small-business incidents. Certification — independent evidence the basics are in place, usually Cyber Essentials, bought when a contract demands it or customers ask; it also forces the foundation to actually be laid, which is quietly its biggest benefit. Specialist testing and response — penetration testing, incident response retainers, monitoring. Real services, mostly mis-sold to this market: a ten-person firm with sensible controls rarely needs a £s-thousands pen test before it needs the basics evidenced.

The order that respects your budget

Foundation first (MSP or a competent internal routine), certification second (evidence, and increasingly a contractual gate), a written security policy alongside it (free — template at that link), insurance conversations informed by all of the above — and specialist testing only when your size, data, or a specific contract genuinely calls for it. Spending in that order buys risk reduction; spending in the reverse order buys reassurance theatre.

Questions that sort real providers from fear-sellers

Ask any prospective provider: Which of the five Cyber Essentials controls does your service cover, and which are left to us? (A good provider answers crisply; a fear-seller pivots to threat statistics.) Will you support us through certification, and is your own organisation certified? What exactly happens when something goes wrong at 4pm on a Friday? What does offboarding look like if we leave? And on price: monthly per-user fees for management, fixed fees for certification support, day rates for genuine specialist work — anything priced by fear (“hackers are targeting firms like yours, sign today”) is the red flag itself.

Where we sit — and where we don't

PassCyber is a certification-support specialist: readiness, remediation guidance, and done-for-you support through to a Cyber Essentials certificate at a fixed all-in price. We are not an MSP and don't sell managed IT — where you need one, we work alongside yours (we partner with MSPs) or can point you at what good looks like. That separation is deliberate: the person drafting your certification answers shouldn't be marking their own configuration homework.

The one-page version

Get the basics managed. Evidence them with certification when contracts ask — or before, since the process itself hardens you. Write the policy (free). Skip the expensive theatre until you're genuinely the size for it. And buy from providers who answer plain questions plainly — in security, straight answers are the product.

PassCyber

Start with the free readiness check

Five minutes, no sign-up to see your result: what's already solid, what would fail an assessment, and what to fix first — before you spend a pound with anyone, including us.

Take the readiness check  ·  hello@passcyber.co.uk

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd