← Back to home

Insight: Cyber Security

Security is not a product. It is a set of layers.

There is no single control that secures a business. There is a sequence of them, chosen to match how that particular organisation actually operates, applied from the mail platform through to the file shares, and tuned so they hold without becoming an obstacle. The following walks through how that assessment is made and what each layer is for.

Written from implementations of the Essential Eight, SMB1001 and ISO 27001 across small, medium and enterprise organisations. Illustrative rather than tied to a named client.

Step One

Choosing the right standard, not the highest one

The most common error is reaching for the most rigorous framework available. The correct level is determined by what the organisation actually needs to satisfy: its contracts, its vendors, its regulatory exposure and its risk appetite.

Foundational

SMB1001

Small to medium organisations

A tiered, achievable standard for businesses without heavy contractual security obligations. It establishes genuine baseline hygiene without imposing the cost and administrative weight of a certification the business has no need to hold.

Risk-based

Essential Eight

Maturity levels one to three

A practical set of mitigation strategies with defined maturity levels. Level one is reasonable for most organisations; level three is aimed at those facing targeted, well-resourced adversaries and carries operational cost to match.

Certifiable

ISO 27001

Contractual and enterprise requirements

A full information security management system, appropriate where certification is required to win or retain business. Substantial ongoing commitment, and rarely justified unless something concrete depends on holding it.

The exception worth calculating

A small manufacturer with no high-security vendors or contracts gains little from Essential Eight maturity level three. But the calculation changes once cyber insurance enters it. Where a demonstrably higher security posture materially reduces premiums, the uplift can pay for itself, and that is an argument made in figures rather than in principle. It is worth running the numbers before ruling a higher level out.

Step Two

Working through the layers

Once the target is set, the infrastructure is broken down and assessed layer by layer. The first group sits below the people using the business and is rarely noticed by them, which is precisely why it goes unreviewed. The second is where staff meet the controls directly. Select any layer to see what it covers and where the gaps usually sit.

Infrastructure: the gateway, rarely seen by staff

People and data: where staff meet the controls

The incident that arrives most often is not a technical one

Invoice fraud and impersonation succeed because nothing about them looks wrong at the point of decision. There is no alert, no blocked file, no failed login, only a request that appears reasonable, acted on by someone doing their job. The defence is caution built into the process itself: a habit of verifying through a channel other than the one the request arrived on. Technology narrows the opening. Training and a verification step close most of what remains.

Why the network layer carries twice the weight

Infrastructure is the foundation cyber security is built on and the front door to the business at the same time. But it is also the operating layer: the one staff feel every day, and the source of most of what they complain about. Slow file access, unreliable connections between sites, applications blamed for problems the switching is actually causing. Getting this layer right is rarely presented as a security project, yet it determines both how far an intruder could travel and whether the business runs smoothly. It is worth addressing on either argument alone. It should be addressed on both.

If it does not make noise, it does not get managed. Until it does.

Most of what goes wrong was visible beforehand. It simply never announced itself, so nobody was asked to own it.

Step Three

Security that people will actually work with

A control that obstructs daily work does not survive contact with the business. It gets bypassed, or it gets removed, and the organisation ends up less secure than before.

It runs in the background

The strongest implementations are barely noticed. Conditional access, device compliance and application control operate quietly, and staff encounter them only when something genuinely warrants attention.

Changes are adoptable

Some alteration to how people work is unavoidable. Each one should be small, explainable and easy to absorb. A change nobody understands becomes a change nobody complies with.

Exceptions are designed, not improvised

Travel, contractors and unusual working patterns are anticipated in advance through defined exception groups with time limits, rather than handled by disabling a control for everyone the moment it becomes inconvenient.

Cost is proportionate

Licensing decides what is realistically achievable. The right answer is the strongest posture the existing licensing supports, before recommending an upgrade the business does not need.

Change is logged and reviewed

Access requests, approvals and exceptions are recorded, and those records are audited. Without that cycle, every environment drifts back toward the state it started in.

Someone owns each layer

Every control has a named owner and a review interval. Security that belongs to everyone in general belongs to nobody in particular.

The Point

Depth, matched to the business

There are many layers available, and no organisation needs all of them at maximum strength. The work is understanding what a business runs on, what it is genuinely exposed to, and what level it needs to reach in order to operate confidently, without exhausting the budget and without impeding the people doing the work.

Done well, security is not felt day to day. It simply means that the questions have already been asked, and someone is watching the answers.