Email security ahead of the mailbox.
Filters email before it reaches the mailbox, inspecting attachments and links and applying particular attention to attacks aimed at named individuals. Long established in larger organisations and available in forms sized for smaller ones. Sits in front of Microsoft 365 rather than inside it, which is a meaningful architectural difference.
Email security, archiving, and 365 backup in one place.
Combines email filtering, long-term archiving, and Microsoft 365 backup under one supplier. The consolidation suits businesses that would otherwise assemble three products and three renewals for closely related jobs. Archiving in particular tends to be driven by a records obligation rather than a security one.
Phishing detection that learns from what your staff report.
Improves its filtering from what staff actually report, so the people receiving the mail become part of the detection rather than only its target. Also removes a bad message from every mailbox at once when one is identified. Works best where reporting is easy and staff have been told it matters.
Email security that sits inside Microsoft 365 rather than in front.
Connects to Microsoft 365 directly instead of standing in front of it, so it can catch a bad message that has already been delivered, and can inspect internal mail between colleagues. Internal mail is where an already-compromised account does its damage, and a gateway filter never sees it. Deploys without changing mail routing.
Phishing and spear-phishing filtering for 365.
Filtering focused on phishing and the more targeted spear-phishing that names a real person and references real context. Integrates with Microsoft 365 rather than replacing its filtering. Aimed at the attack type that accounts for most small business compromises.
Detonates attachments and links before delivery.
Opens attachments and follows links in an isolated environment before the message is delivered, so what is judged is actual behaviour rather than reputation. Catches files that have never been seen before and therefore appear on no list. Adds a small delay to delivery, which is worth understanding before deploying it.
MailGuard 365
Additional filtering layer for Microsoft 365.
An additional filtering layer over Microsoft 365 for businesses that want more than the built-in protection without a full gateway platform. Straightforward to add and to remove. A reasonable option where the requirement is incremental rather than architectural.
Email encryption for regulated correspondence.
Encrypts outbound email so only the intended recipient can read it, with a recipient experience that does not demand they install anything. Driven almost entirely by regulation — healthcare, legal, and financial correspondence. The recipient experience matters more than the cryptography, because a system people route around protects nothing.
Stops others sending email that looks like it came from you.
Helps set up and maintain the DNS records that let receiving mail servers reject messages forging your domain. Without them, anyone can send email appearing to come from your company, and your customers are the ones who suffer. The setup is fiddly and easy to get wrong in ways that silently break legitimate mail, which is what tooling like this is for.
DMARC enforcement without manual DNS work.
Takes email authentication to full enforcement without the manual DNS maintenance that usually stalls it partway. Most domains that start this work never finish it, and a policy left in monitoring mode blocks nothing. Aimed at getting past that stall.
Email authentication and domain monitoring.
Covers email authentication alongside monitoring of the domains and certificates a business depends on, including lookalike domains registered to impersonate it. Broader than DMARC alone. Relevant where the brand itself is worth impersonating.
Password management with shared vaults and audit.
Stores credentials with shared vaults for teams and a record of who accessed what. The audit trail is what distinguishes business password management from the consumer kind. Also removes the spreadsheet of passwords that exists in more businesses than will admit it.
Password management staff will actually use.
Password management with an unusually good day-to-day experience, which matters more than any feature comparison — a password manager staff avoid is worse than none, because it drives credentials back into notebooks and browsers. Handles shared team credentials as well as individual ones. The adoption argument is the whole argument.
Password management with shared folders.
Long-established password management with shared folders for teams. Widely deployed and familiar to many staff already. Its security history is a matter of public record and worth reading before selecting it, which is a fair thing to say about any product holding every password a business has.
Password management and removal of local admin rights.
Pairs password management with removing local administrator rights from staff machines, allowing specific approved actions to elevate instead. Local admin is one of the highest-value things to take away and one of the most disruptive, and that tension is what this manages. Two related problems from one supplier.
Verifies who is calling before a password gets reset.
Confirms that the person asking for a password reset is who they claim to be. Attackers now phone the help desk rather than break anything, and a convincing caller has historically been enough. Closes a gap that no amount of endpoint security addresses.
Credential management built for IT documentation.
Credential storage designed to sit alongside IT documentation, so a password is recorded against the system it belongs to rather than in a separate vault with a cryptic label. Built for whoever supports the environment. The linkage to documentation is the point.
VPN and password management for distributed teams.
Business versions of the VPN and password tools from the consumer brand, aimed at distributed teams. Familiar names, which lowers the resistance to rolling them out. Covers the basics for a business without a security programme rather than replacing one.
Network access for staff working anywhere.
Provides access to internal systems for staff wherever they work, granting reach to specific resources rather than the whole network. A modern replacement for a traditional VPN appliance. Relevant where there is still something internal to reach at all.
TLS certificates and certificate lifecycle management.
Issues the certificates that make websites and services trusted, and tracks when each one expires. An expired certificate takes a site or a service offline with a browser warning that frightens customers, and it is almost always an administrative failure rather than a technical one. Certificate lifetimes keep shortening, which makes tracking them harder to do by memory.
Blocks malicious and unwanted sites at the DNS layer.
Blocks known-bad and unwanted sites at the point a device looks up an address, so the connection is never made. One of the highest-value controls relative to the effort of deploying it, because it stops a whole class of problem before anything needs detecting. Also handles the acceptable-use question some businesses have to answer.
Finds vulnerabilities across everything you run.
Scans the estate for missing patches, weak configuration, and known vulnerabilities, and reports what was found. Finding the problems is the easy half; the value only arrives when somebody works the list. Insurers and larger clients increasingly ask whether scanning like this happens at all.
Patches vulnerabilities and mitigates the ones that cannot be patched.
Finds and applies patches, and where no patch exists or one cannot yet be installed, applies a mitigation instead. That middle ground is the useful part — the awkward vulnerabilities are the ones on a system nobody dares touch. Addresses the gap between knowing about a problem and being able to fix it.
Automated penetration testing to show what is actually exploitable.
Runs automated attacks against your own environment to show what could genuinely be exploited, rather than listing everything theoretically wrong. That distinction matters, because a scanner report of four hundred findings tells nobody where to start. Produces a much shorter list with evidence attached.
Vulnerability scanning with plain-language reporting.
Vulnerability scanning that reports in language a business owner can follow rather than a security specialist. Useful where the person deciding what to fix is not technical. Legibility over depth, which is the right trade for most small businesses.
Continuous exposure checking across internal and external surfaces.
Watches continuously for what is exposed, inside the network and on the internet-facing side, rather than producing a snapshot once a quarter. Exposure changes whenever something is deployed or misconfigured, so a point-in-time scan ages quickly. Continuous is the distinguishing feature.
Finds sensitive data and scores the risk attached to it.
Locates sensitive data across the estate — card numbers, health records, personal information — and rates the risk of where it is sitting. Most businesses are genuinely surprised by where this turns up, usually in old shares and personal folders. The discovery alone frequently justifies the exercise.
Tracks and encrypts sensitive files wherever they travel.
Tracks sensitive files and encrypts them so they stay protected after leaving the business — on a USB stick, in an attachment, or on a personal device. Attaches the protection to the file rather than to the place it was stored. Relevant where data leaving is the specific worry.
Audits who changed what, and who can see what.
Records who changed what across systems and reports who can currently see what. Answers the two questions that arrive with any audit or incident and that almost nobody can answer from memory. Permissions drift quietly in every environment, and this is what makes the drift visible.
Security monitoring and alerting without a full SIEM project.
Collects security events and alerts on what matters without the lengthy implementation a traditional SIEM demands. Deliberately tuned to produce few, meaningful alerts, because a noisy system gets ignored within a fortnight. Aimed at businesses that need monitoring but would never complete a SIEM deployment.
Firewalls and threat prevention.
A long-established firewall and threat-prevention vendor with a strong reputation in larger and more demanding environments. Capable and correspondingly involved to administer. For a small office the lighter firewall vendors usually fit better, and this appears where the requirement is genuinely heavier.
HIPAA compliance workflow and documentation.
Walks a business through HIPAA and keeps the documentation that demonstrates the work was done. Specific to healthcare and the businesses that handle health data on their behalf. HIPAA is mostly documented process rather than technology, which is exactly what this manages.
Compliance Scorecard
Tracks security policy against a framework.
Tracks written security policy against a chosen framework and shows where the gaps are. Policy is usually the part that gets skipped, and it is the first thing an auditor or insurer asks to see. Turns a document nobody maintains into something with a status.
Manages compliance programmes across several frameworks.
Manages compliance against several frameworks at once and maps the overlap between them, so one control can satisfy more than one obligation. Valuable where a business faces multiple requirements from different customers or regulators. The overlap mapping is what saves the duplicated effort.
Builds and maintains a security programme and roadmap.
Builds a security programme and a prioritised roadmap from an assessment of the business, then keeps it current. Aimed at organisations with no security leadership of their own that still need a defensible plan. Produces the ordering — what to do first — which is usually the hardest part.
Compliance management with evidence collection.
Compliance management with the evidence gathering built in, so proof accumulates continuously instead of being assembled in a panic before an audit. Suits businesses facing recurring audits or customer security reviews. The evidence trail is the labour it removes.
CyberCert
Certification pathway for small business security.
A staged certification path for small businesses that need to demonstrate a security standard to customers or insurers without an enterprise programme. Gives a defined destination rather than open-ended improvement. Most relevant where a larger customer has started asking questions.