Security & Protection

AI made attacks cheap.
Small businesses are the soft target.

An automated attack no longer needs a person deciding you are worth the trouble. It scans everything, constantly and a small business with a forgotten plugin and a shared password is the easiest thing on its list. We find what is exposed, fix what we can and tell you honestly what needs somebody else.

What does security help from Red 4 involve?

We find out what your business has exposed to the internet and who can get into what, fix what we can and tell you plainly what needs a specialist. It is written for owners, not IT departments — no scare tactics and no jargon.

At a glance

Covers
Websites, email, accounts, devices, data
Starts with
Finding what's exposed
Fixes
Passwords, access, updates, backups
Works with
Your existing IT support, if you have it
Leads to
Cyber Essentials, if you need it
Tone
Plain English, no scare stories

How it actually happens

It is almost never
a hacker in a hoodie.

Three routes account for most of what we see and not one of them requires anybody to have targeted you specifically.

Something you installed and forgot

A plugin, a theme, an extension or an add-on that quietly stopped being updated. It appears in no list of your systems, so nobody reviews it — and a scanner finds it before you do.

A password that opens more than one door

Reused across the website, the email, the payment tool and the hosting. One breach anywhere becomes a breach everywhere and the first you hear of it is a customer asking why they got a strange email from you.

A backup nobody has ever restored

Backups that have been running for months and are empty, or that nobody has ever tried to put back. Until it has been restored, a backup is a theory.

Outcomes

What changes for your business

  • A clear list of what was exposed and what was fixed
  • Accounts that match who actually works for you
  • Two-step sign-in on the logins that matter
  • Backups you know will restore
  • Old systems and forgotten accounts switched off
  • A plain plan for what to do if something goes wrong

What we do about it

Six things worth doing first

In this order. The first four are mostly a weekend of setting up and then a habit and between them they close off most of what actually happens to businesses this size.

01

A record of what you actually run

Every site, system, subscription, plugin and integration written down in one place, with who owns it and what breaks if it goes. Most of what hurts a small business is something nobody knew was there.

02

Access and passwords

One account per person, removed the day they leave. Multi-factor on anything that matters and a password manager so nobody has to remember or reuse anything.

03

Updates that genuinely happen

Automatic where that is safe, monitored where it is not and checked rather than assumed. A managed install that has quietly switched its own updates off is a common and expensive surprise.

04

Backups that are tested

Off the machine, off the site and restored on a schedule to prove they work. We have found backup jobs that had been reporting success for a fortnight while writing empty files.

05

Monitoring that tells a person

Something watching for the change nobody made on purpose — a new admin user, a modified file, a certificate about to lapse — and telling a human within the hour rather than at the end of the month.

06

A private internal network

For the work that should not be on the open web at all. Staff reach the system over a private network from wherever they are and to everybody else it simply is not there. It costs very little and removes a whole category of attack.

Is it right for you?

This is worth doing if…

  • Nobody in the business has security as their job
  • You are not sure who still has access to what
  • Staff share passwords or reuse them
  • Your website or systems have not been checked in years
  • A customer or contract is asking about your security
  • You would rather prevent a problem than recover from one

What we take on
and what we don't.

Security is the one service where being vague ends up costing somebody real money. This is the line, in writing, before you ask for it.

What we do

  • Secure the systems we build and host — updates, access, backups, certificates and monitoring, included rather than sold as a bolt-on
  • Audit what you already run and hand you a written record of it, whether or not we built any of it
  • Set access up properly: one account per person, multi-factor, a password manager and a process for removing somebody
  • Set up and run a private network so staff can reach internal systems without those systems being exposed to the internet
  • Recover a site or system we host, from backups we have actually restored
  • Tell you plainly when something needs a specialist, an insurer or the police rather than us

What we don't do

  • Twenty-four-hour incident response. We are a small senior team, not a manned security operations centre. We will not pretend otherwise
  • Certification. We are not a Cyber Essentials assessor and cannot award or sign off a certificate — though this work gets most businesses most of the way there
  • Your physical office network, unless we built it. Routers, firewalls and Wi-Fi that somebody else installed stay with whoever installed them
  • Penetration testing. That is a specialist discipline with its own accreditation and we will introduce you to someone rather than improvise it
  • Any guarantee that you will not be breached. Nobody honest offers one. What we can promise is that you will know what you have, it will be up to date and you will be able to get it back

The questions we get asked

We're only ten people. Is this really aimed at us?

Ten people is precisely who automated attacks find easiest, because the tooling does not check your size before it scans you and nobody in a business that size has this as their job. It does not have to be expensive — most of the value sits in the first four items above.

We already have IT support. Does this replace them?

No — and we will say so if that is the honest answer. Where somebody already manages your machines and network, we cover what they usually do not: the websites, the applications, the subscriptions and the data. Where the two overlap we would rather talk to them than around them.

What is the private network actually for?

Anything that should not be reachable from the open internet — an internal admin, a client database, a document store. Staff connect over a private network from wherever they are and to everyone else the system is not visible at all. It is cheap and it removes a whole class of attack rather than defending against it.

How does this relate to the audit?

Security is one of the three things the audit looks at, alongside what you are paying for and what could be automated. You get the findings in writing with a figure or a risk against each one and you are free to act on them yourself. The audit is the diagnosis; this page is the treatment.

Something has already happened. Can you help?

Call rather than email. If it is live we will tell you within the hour whether it is something we can help with or something that needs a specialist and your insurer — and we will say which, rather than taking the work either way.

Free website audit

Not sure where your website stands?

Get a free website health check: a written audit of your site and email domain — renewals, security, email spoofing, speed and AI visibility — read by a person before it is sent.

Get a free website audit

Find out what you're
actually exposed to.

Two days and a plain-English report you own outright, at a fixed price agreed before we start.

Support