Category: Microsoft 365

  • ITDR

    What is ITDR and Why Should Small Businesses Care?

    When most people think about cyber security, they picture viruses, hackers, or someone breaking into a computer. The reality is that many cyber attacks today don’t start with a device at all. They start with a person’s identity.

    That’s where ITDR (Identity Threat Detection and Response) comes in.

    Your Identity is the New Front Door

    Think about all the systems you use every day:

    • Microsoft 365
    • Outlook
    • Teams
    • SharePoint
    • Payroll systems
    • Accounting software
    • CRM platforms

    You log in with a username, password, and hopefully multi-factor authentication (MFA).

    Your identity is effectively the digital key to your business.

    Cyber criminals know this, which is why they increasingly focus on stealing accounts rather than attacking devices directly. Microsoft describes ITDR as a way to prevent, detect and respond to identity-based cyber threats by monitoring login activity, risk signals and suspicious behaviour across user accounts.

    What Does an Identity Attack Look Like?

    Imagine this scenario.

    Sarah works in accounts. She receives what looks like a Microsoft 365 sign-in request and accidentally enters her password into a fake website.

    The attacker now has her credentials.

    Instead of deploying malware, they simply:

    ✅ Sign into Microsoft 365

    ✅ Read emails

    ✅ Access company files

    ✅ Create mailbox rules

    ✅ Send fraudulent invoices

    ✅ Attempt to access other systems

    To traditional antivirus software, nothing looks wrong.

    After all, someone logged in using a valid account.

    This is why identity attacks are becoming so effective. Cyber criminals are “logging in rather than hacking in.”

    So What Exactly Is ITDR?

    Identity Threat Detection and Response (ITDR) continuously monitors user identities and login activity to identify suspicious behaviour that could indicate a compromised account. ITDR solutions are designed to detect and respond to threats such as account takeovers, business email compromise, unauthorised logins and privilege escalation.

    In simple terms:

    ITDR watches your digital identities and raises the alarm when something doesn’t look right.

    It’s the security guard checking who is using the keys to your business.

    The Warning Signs ITDR Looks For

    Modern ITDR platforms can identify things such as:

    Impossible Travel

    A user signs in from London at 9am and New York at 9:15am.

    Unless they’ve discovered teleportation, that’s suspicious.

    Unusual Login Behaviour

    An account suddenly accesses systems it has never used before.

    MFA Abuse

    Repeated MFA requests designed to annoy a user into approving one.

    Privilege Changes

    Someone suddenly gains administrator rights without a legitimate reason.

    Business Email Compromise

    A mailbox starts sending unusual messages or creating hidden email forwarding rules.

    Microsoft notes that identity-focused security can detect sign-in anomalies, risky behaviour and attempts at lateral movement before significant damage is done.

    ITDR vs EDR: What’s the Difference?

    Many businesses already have EDR (Endpoint Detection and Response).

    EDR protects the device.

    ITDR protects the identity.

    Think of it this way:

    Security ToolProtects
    AntivirusKnown malware
    EDRComputers and devices
    ITDRUser accounts and identities

    The two work best together.

    If EDR protects the laptop and ITDR protects the user, an attacker has far fewer opportunities to gain access.

    As highlighted in Huntress documentation already held within KVS365 resources, Managed ITDR focuses on detecting identity-based threats in Microsoft 365 and Google Workspace environments, including account takeovers and unauthorised logins.

    Why Small Businesses Need ITDR

    Many small businesses believe attackers only target large organisations.

    Unfortunately, the opposite is often true.

    Small businesses generally:

    • Have fewer security controls
    • Have less dedicated IT staff
    • Are more reliant on cloud services
    • Hold valuable financial and customer data

    A compromised Microsoft 365 account can quickly lead to:

    • Fraudulent invoices
    • Stolen customer data
    • Business disruption
    • Reputational damage
    • Regulatory issues

    The impact can be significant even if only a single account is compromised.

    What Good ITDR Looks Like

    A modern ITDR service should provide:

    ✅ Continuous monitoring

    ✅ Detection of suspicious logins

    ✅ Protection against account takeover

    ✅ Monitoring of privileged accounts

    ✅ Business Email Compromise detection

    ✅ Rapid incident response

    ✅ Expert investigation of alerts

    ✅ Integration with Microsoft 365

    At KVS365, we view ITDR as an essential layer of a modern security strategy alongside Microsoft 365 Business Premium, endpoint protection, security awareness training, backup, and compliance monitoring.

    Final Thoughts

    Cyber security is no longer just about protecting computers.

    Today’s attackers are often targeting the people behind those computers.

    That’s why identity has become one of the most important areas of cyber defence.

    If EDR protects your devices, ITDR protects the keys to your business.

    And when hackers don’t sleep, protecting both is becoming essential.

  • EDR

    What is EDR and Why Should Your Business Care?

    When most people think about cybersecurity, they think about antivirus software.

    For years, antivirus has been the main line of defence against viruses, malware, and other threats. The problem is that cybercriminals have become far more sophisticated. Today’s attacks often bypass traditional antivirus completely.

    That’s where EDR comes in.

    What Does EDR Stand For?

    EDR stands for Endpoint Detection and Response.

    An “endpoint” is simply any device used to access business data, including:

    • Laptops
    • Desktop PCs
    • Servers
    • Mobile phones
    • Tablets

    EDR constantly watches these devices for suspicious activity and can react when something looks wrong. Unlike traditional antivirus, it doesn’t just look for known threats. It looks for unusual behaviour that may indicate an attack.

    Antivirus vs EDR

    Think of antivirus like a security guard checking IDs at the front door.

    If a known criminal turns up, they’re stopped immediately.

    But what happens if someone gets in using a fake ID?

    Traditional antivirus may not notice.

    EDR is more like having CCTV cameras throughout the building with intelligent monitoring. If someone starts acting suspiciously, security is alerted immediately and can take action before serious damage is done.

    Why Antivirus Alone Isn’t Enough Anymore

    Modern cyber attacks often:

    • Use stolen passwords
    • Exploit legitimate applications
    • Operate without installing traditional malware
    • Spread quietly through a network
    • Remain hidden for days or weeks

    Because these attacks don’t always look like traditional viruses, many can slip past conventional antivirus systems.

    EDR focuses on behaviour rather than just known signatures, making it far more effective at spotting modern attacks.

    What Does EDR Actually Do?

    A modern EDR solution typically performs four key functions:

    1. Monitors Devices Continuously

    EDR watches what’s happening on your devices 24 hours a day, looking for unusual behaviour.

    For example:

    • Unexpected software launches
    • Suspicious PowerShell activity
    • Unusual file encryption
    • Unauthorised access attempts

    2. Detects Threats Quickly

    If something suspicious is detected, EDR raises an alert before the issue becomes a major incident.

    3. Investigates What Happened

    EDR records information about what’s occurring on devices, helping security teams understand:

    • How the attack started
    • Which devices were affected
    • What actions were taken

    4. Responds Automatically

    Many EDR platforms can take immediate action, such as:

    • Isolating an infected device
    • Stopping malicious processes
    • Blocking further activity

    This can dramatically reduce the impact of an attack.

    A Real-World Example

    Imagine an employee receives a convincing phishing email.

    They click a link and unknowingly download malicious software.

    Traditional antivirus might not recognise the threat if it’s new.

    An EDR platform may notice that:

    • The software is behaving unusually
    • Files are suddenly being encrypted
    • Sensitive data is being accessed

    The EDR solution can then stop the process and isolate the affected device before ransomware spreads across the business. This type of behavioural protection is one of the reasons EDR has become such an important security layer.

    What is Managed EDR?

    Many businesses don’t have an in-house security team monitoring alerts around the clock.

    That’s where Managed EDR comes in.

    A Managed EDR service combines the technology with real people who monitor threats, investigate alerts, and help respond to incidents 24/7.

    This means your business benefits from enterprise-grade monitoring without needing to employ a dedicated cybersecurity team.

    Is EDR Only for Large Companies?

    Absolutely not.

    Small businesses are increasingly targeted because attackers know they often have fewer security controls in place.

    In fact, many EDR solutions are now specifically designed for SMEs and integrate with common platforms such as Microsoft 365.

    The Bottom Line

    Cybercriminals don’t sleep, and modern attacks are becoming harder to detect.

    While antivirus is still important, it is no longer enough on its own.

    EDR adds an essential layer of protection by:

    • Detecting suspicious behaviour
    • Investigating threats
    • Automatically responding to attacks
    • Helping stop ransomware before it spreads

    For businesses that rely on Microsoft 365, cloud services, and remote working, EDR has quickly become one of the most effective ways to improve cybersecurity without adding complexity for users.

    Need Help Understanding Your Current Risk?

    At KVS365, we can provide a free endpoint security assessment to help identify potential risks, security gaps, and areas where your existing protection may be improved.

    Because protecting your business isn’t just about preventing attacks. It’s about detecting them quickly and responding before they become a costly problem.

  • KVS365 Becomes a Huntress Partner | 24/7 Managed Cyber Security for Small Businesses

    At KVS365, our goal has always been simple:

    Make IT simple, secure, and reliable for small businesses.

    That’s why we’re delighted to announce that KVS365 is now an official Huntress reseller and partner, bringing industry-leading managed cyber security services to our clients. Huntress provides a managed security platform designed to detect, investigate, and respond to cyber threats around the clock, backed by a 24/7 Security Operations Centre (SOC).

    Why We’ve Added Huntress

    Cyber attacks are no longer just a problem for large organisations.

    Small businesses are increasingly being targeted because attackers know many organisations don’t have dedicated security teams monitoring their systems day and night.

    Traditional antivirus software is still important, but modern attacks often involve:

    • Stolen passwords
    • Account takeovers
    • Business email compromise
    • Ransomware
    • Unauthorised access to Microsoft 365
    • Hidden threats that avoid detection

    Huntress was built to bridge that gap by providing continuous protection, detection, and response capabilities backed by real security experts operating 24/7.

    What Does Huntress Actually Do?

    Think of Huntress as an extension of your IT and security team.

    Rather than simply alerting you that something suspicious has happened, Huntress actively monitors for threats and helps stop them before they become major problems. Huntress provides managed capabilities across endpoints, identities, and other security areas, supported by a 24/7 SOC.

    Protects Your Devices

    Every laptop, desktop, and server becomes part of a monitored environment.

    If ransomware, malware, or suspicious behaviour is detected, Huntress investigates the threat and provides guidance or response actions to contain it. Huntress Managed EDR is designed to provide continuous protection, detection, and response for endpoints.

    Protects Microsoft 365 Accounts

    Many cyber attacks now start with compromised email accounts rather than infected devices.

    Huntress monitors for:

    • Suspicious sign-ins
    • Unusual login locations
    • Account takeovers
    • Business email compromise attempts
    • Identity-based threats

    Its Managed ITDR service is designed to detect and respond to identity threats affecting Microsoft 365 and other platforms.

    24/7 Human Monitoring

    One of the biggest advantages of Huntress is that you’re not relying solely on automation.

    Their security analysts work around the clock to review activity, investigate alerts, and identify genuine threats, helping reduce the noise and false positives that many organisations struggle with.

    Faster Response to Threats

    The sooner a threat is identified, the less damage it can cause.

    Huntress combines technology with real-world security expertise to help identify, contain, and remediate threats before they disrupt your business.

    What This Means for KVS365 Clients

    Adding Huntress strengthens our security offering and helps us provide a more complete protection service for businesses that rely on Microsoft 365 and cloud services.

    By combining:

    • Microsoft 365 security
    • Device management
    • Cyber Essentials best practice
    • User awareness training
    • Huntress 24/7 threat monitoring

    we can help businesses reduce risk and gain confidence that someone is always watching for cyber threats.

    Is Huntress Right for Your Business?

    If your business relies on:

    • Microsoft 365
    • Email communication
    • Cloud services
    • Remote workers
    • Laptops and mobile devices

    then having professional monitoring and threat response in place is becoming increasingly important.

    Many small businesses assume they are “too small to be targeted”. Unfortunately, cyber criminals often see smaller organisations as easier targets.

    The good news is that enterprise-grade protection is now affordable and accessible to businesses of all sizes. Huntress was created specifically to provide advanced cybersecurity capabilities to organisations without large internal security teams.

    Want to Learn More?

    If you’d like to understand how Huntress could help protect your business, get in touch with KVS365.

    We’ll review your current setup, identify any gaps, and explain how 24/7 managed cyber protection could fit alongside your existing Microsoft 365 environment.

    Cyber threats don’t work office hours. Neither does Huntress.

    Call today to arrange your free 14 day Trial

    and get your free Managed EDR Security Assessment.

  • Stop Being Hunted. Become the Hunter.

    Why We Have Expanded Our Cyber Protection Services

    Cyber criminals no longer target only large organisations.

    In fact, many attacks are aimed directly at small businesses because they often don’t have dedicated security teams watching over their systems.

    At KVS365, we’ve always believed that cyber security should be simple, practical and accessible to smaller businesses.

    That’s why we’ve expanded our Protect and Complete packages with a new layer of managed cyber protection powered by Microsoft Security and Huntress. Huntress integrates with Microsoft Defender and provides managed monitoring and response capabilities backed by a 24/7 security operations team.

    Cyber Security Is About More Than Antivirus

    Many businesses think cyber security starts and ends with antivirus software.

    The reality is that modern attacks often involve:

    • Stolen passwords
    • Account compromise
    • Phishing emails
    • Unauthorised access
    • Misconfigured security settings
    • Human error

    Protecting against today’s threats requires more than simply blocking malware.

    It requires continuous monitoring, identity protection, security awareness and expert oversight.

    Microsoft Defender Is the Foundation

    Microsoft 365 Business Premium already provides an excellent security foundation through Microsoft Defender.

    We use Microsoft’s security tools because they are built directly into the Microsoft 365 platform that most of our customers already rely on every day.

    But even the best security tools still generate alerts that somebody needs to monitor and investigate.

    That’s where Huntress comes in.

    Microsoft Defender + Huntress

    My favourite way to explain it is:

    Microsoft Defender is the alarm system.

    Huntress is the team watching the alarms.

    Huntress works alongside Microsoft Defender to provide additional monitoring, investigation and response capabilities. Huntress states that it integrates with Microsoft Defender for Business, Defender for Endpoint and Microsoft Defender Antivirus to improve visibility, threat detection and response.

    Instead of simply generating alerts, the service helps identify threats, investigate suspicious activity and support incident response.

    What Is Included in Our Protect Package?

    Protect is designed for businesses that need more than standard IT support.

    Protect includes:

    ✅ Microsoft Defender Security

    ✅ 24/7 Threat Monitoring

    ✅ Managed Endpoint Detection & Response

    ✅ Identity Threat Monitoring

    ✅ Security Posture Monitoring

    ✅ Faster Threat Investigation

    ✅ Cyber Essentials Ready Foundations

    Protect gives small businesses access to the kind of monitoring and response capabilities that would normally only be available to larger organisations.

    Plain English

    We help watch your systems, identify threats and respond before they become business problems.

    Complete Protection for Systems and People

    Technology is only one part of cyber security.

    Many successful attacks begin with a simple mistake:

    • Clicking a phishing email
    • Reusing a password
    • Approving a malicious sign-in request
    • Sharing information with the wrong person

    That’s why our Complete package goes further.

    Complete includes everything in Protect plus:

    ✅ Security Awareness Training

    ✅ Human Risk Management

    ✅ Phishing Awareness Support

    ✅ Ongoing Security Guidance

    ✅ Named Customer Contact

    ✅ Strategic Security Reviews

    Plain English

    Complete protects your technology and helps your people make safer decisions.

    Why This Matters

    The majority of small businesses don’t have a dedicated cyber security team.

    They’re already busy running the business.

    Monitoring security dashboards and investigating alerts shouldn’t become another full-time job.

    By combining Microsoft Security with Huntress monitoring and response services, we’re helping small businesses gain access to enterprise-level cyber protection without enterprise-level complexity. Huntress describes its service as combining endpoint detection and response capabilities with continuous monitoring from a 24/7 SOC team.

    Stop Being Hunted. Become the Hunter.

    Cyber criminals work around the clock.

    Now your protection can too.

    With KVS365 Protect and Complete, your business benefits from:

    • Microsoft 365 security
    • 24/7 cyber monitoring
    • Threat detection and response
    • Identity protection
    • Security awareness training
    • Plain-English support

    Because cyber security shouldn’t be complicated.

    It should simply work.

  • 5 Microsoft 365 Mistakes Small Businesses Make (And How to Fix Them)

    Microsoft 365 is brilliant — when it’s set up properly. The problem is, most small businesses either set it up themselves in a hurry, or inherited a setup that nobody’s properly looked at since.

    The result is a system that mostly works, but has a few gaps that could cause real problems down the line.

    Here are the five mistakes we see most often — and what to do about them.

    1. MFA isn’t switched on for everyone

    Multi-factor authentication (MFA) is the single most effective thing you can do to protect your Microsoft 365 accounts. It means that even if someone gets hold of a password, they still can’t get in without a second verification — usually a code on your phone.

    Microsoft themselves say that MFA blocks over 99% of account compromise attacks.

    And yet, in a surprising number of the setups we look at, MFA either isn’t switched on at all, or it’s only switched on for some users — often because it was “too complicated” for a few people when it was first rolled out.

    The fix: Switch on MFA for every account, no exceptions. In the Microsoft 365 admin centre, go to Users → Active users → Multi-factor authentication. If you’re not sure how, this is something we can sort out quickly — it takes less than an hour for most small businesses.

    2. Old accounts are still active

    When someone leaves a business, their Microsoft 365 account should be disabled (or at minimum, have their password changed and MFA reset) immediately. In reality, this often gets forgotten — especially in small teams where there’s no dedicated IT person to handle offboarding.

    An active account belonging to an ex-employee is an open door. If they still know their password, they can still access your emails, files and systems. If their credentials have been compromised elsewhere, attackers can use them to get into your business.

    We regularly find accounts for people who left months or even years ago, still sitting there active.

    The fix: Go to Users → Active users in the Microsoft 365 admin centre and check every account. Anyone who’s no longer with you should be blocked immediately. Their emails and files can be preserved without the account staying active.

    3. You think Microsoft is backing up your data — it isn’t

    This is probably the most common and most costly misconception we come across.

    Microsoft 365 keeps your emails and files available and synced across devices, but that’s not the same as a backup. If a file gets accidentally deleted, overwritten, or encrypted by ransomware, Microsoft’s standard retention policies may not save you — especially if you don’t notice for a while.

    Microsoft’s own service agreement is clear: they recommend that customers use third-party backup solutions to protect their data. Most small businesses either don’t know this or assume it’s covered.

    The fix: Add a proper backup solution for your Microsoft 365 data — email, SharePoint, OneDrive and Teams. There are good, cost-effective options designed specifically for Microsoft 365. If you’re not sure what you have in place, that’s worth checking as a priority.

    4. You’re on the wrong licence

    Microsoft 365 comes in a range of plans — Business Basic, Business Standard, Business Premium, and various others. Each one has different features, particularly around security.

    The issue we see most often is businesses on a cheaper plan that’s missing security features they actually need — or sometimes the reverse, paying for Business Premium when Basic would do the job.

    Business Premium is where the advanced security features live — things like Microsoft Defender, Intune for device management, and the tools needed to properly meet Cyber Essentials requirements. If you’re handling client data, working towards Cyber Essentials, or have staff on multiple devices, Business Premium is usually the right choice.

    The fix: Check what licences you’re on (Billing → Your products in the admin centre) and compare them against what you actually need. If you’re not sure, this is exactly the kind of thing we review in our free IT and Security Check.

    5. Security defaults haven’t been configured

    When Microsoft 365 is first set up, it comes with a set of defaults. Some of those defaults are fine. Some of them leave your business more exposed than it needs to be.

    Common examples:

    • External email forwarding allowed — meaning anyone whose account is compromised can quietly forward all their emails to an outside address
    • Too many global admins — admin accounts have full access to everything; most businesses have far more than they need
    • Apps with excessive permissions — third-party apps that have been connected to Microsoft 365 and never reviewed
    • Audit logging switched off — meaning if something does go wrong, there’s no trail to investigate

    None of these are obvious if you don’t know what to look for. But they all create real risk.

    The fix: A proper security review of your Microsoft 365 configuration. Microsoft’s Secure Score (in the Security admin centre) gives you a starting point — it scores your setup and suggests improvements. A score below 50% is a sign there’s meaningful work to do.


    How do you know if any of these apply to you?

    The honest answer is: unless someone has specifically reviewed your setup, you probably don’t.

    Most of these issues don’t cause any visible problems day-to-day. They only become apparent when something goes wrong — an account gets compromised, a file goes missing, or an auditor asks questions.

    The best time to find them is before that happens.

    We offer a free IT and Security Check for small businesses — 30 minutes, plain English, no pressure. We’ll look at your Microsoft 365 setup and tell you honestly what’s there, what’s missing, and what (if anything) needs fixing.

    👉 Book your free IT & Security Check(opens in new window)

    Or if you’d like to find out more about how we look after Microsoft 365 for small businesses: Microsoft 365 at KVS365(opens in new window)


    Ken Strettle is the founder of KVS365, a UK-based IT consultancy helping small businesses get Microsoft 365 working properly, stay secure, and get Cyber Essentials ready. Based in Newark, working with businesses across the UK.

  • Do I Need Cyber Essentials? An Honest Guide for Small Businesses

    If you’ve heard the term “Cyber Essentials” but aren’t sure whether it applies to you, you’re not alone. It’s one of the questions I get asked most often — and the honest answer is: it depends, but probably yes.

    Here’s a plain-English guide to what Cyber Essentials actually is, who needs it, and what’s involved. No jargon. No sales pitch.

    What is Cyber Essentials?

    Cyber Essentials is a UK government-backed certification scheme that helps businesses protect themselves against the most common cyber attacks. It was introduced because the vast majority of successful cyber attacks — around 80% — exploit basic security weaknesses that are completely preventable.

    The scheme covers five core areas:

    • Firewalls — controlling what comes in and out of your network
    • Secure configuration — making sure devices and software are set up safely
    • User access control — limiting who can access what, and when
    • Malware protection — keeping malicious software out
    • Patch management — keeping software and devices up to date

    There’s also a higher level called Cyber Essentials Plus, which involves a hands-on technical audit rather than a self-assessment. Most small businesses start with the standard Cyber Essentials.

    Who actually needs it?

    The short answer: more businesses than you’d think.

    You almost certainly need it if:

    • You bid for government contracts — it’s been a requirement for central government suppliers since 2014, and increasingly required further down the supply chain
    • Your clients (especially larger ones or those in regulated sectors) are starting to ask about your security posture
    • Your cyber insurance requires it — this is becoming increasingly common as insurers tighten their requirements
    • You handle personal data and want to demonstrate good GDPR practice

    You should seriously consider it if:

    • You use Microsoft 365 for email, files and day-to-day work
    • You have staff working remotely or on multiple devices
    • You’ve had a security incident (or a near miss) and want to make sure it doesn’t happen again
    • You want to give clients confidence that their data is safe with you

    You can probably wait if:

    • You’re a sole trader with minimal client data and no plans to bid for contracts — though even then, the discipline of going through the process is genuinely useful.
    What does it actually involve?

    The standard Cyber Essentials certification is a self-assessment questionnaire. You answer questions about how your IT is set up, submit it to a certifying body, and they assess it against the standard.

    It’s not as scary as it sounds — but it does require your IT to be set up properly. Common issues we find when helping businesses prepare include:

    • Multi-factor authentication (MFA) not switched on for all users
    • Old staff accounts still active
    • Devices not being patched and updated regularly
    • Unsupported software still in use
    • Overly permissive access — people having access to more than they need

    Most of these are straightforward to fix. The questionnaire just forces you to actually check.

    How long does it take?

    For a small business that’s reasonably well set up, getting Cyber Essentials ready typically takes a few weeks. Larger or more complex organisations may take longer, particularly if there’s a lot of remediation needed first.

    The certification itself (once you submit) is usually turned around within a few days.

    How much does it cost?

    The certification fee itself is currently around £300–£500 depending on the certifying body. That’s just the assessment — it doesn’t include any IT work needed to get your systems up to standard first.

    If you need support getting ready (fixing the gaps, updating configurations, setting up MFA properly), that’s where a company like ours comes in. We help businesses get Cyber Essentials ready without the stress — and because we’re already looking after Microsoft 365 for most of our clients, it’s usually far less work than people expect.

    Does it actually make a difference?

    Yes — and not just on paper.

    The five controls Cyber Essentials requires you to have in place genuinely block the most common attack types. You’re not going to be immune to every threat, but you’ll be a much harder target than businesses that haven’t done this work.

    There’s also a reputational angle. More and more businesses — and their insurers — are asking their suppliers about security. Having Cyber Essentials certification is a simple, credible answer to that question.

    What’s the first step?

    The best starting point is understanding where you currently stand. That means looking at your Microsoft 365 configuration, your device setup, and your current security policies, and identifying any gaps before you attempt the certification.

    We offer a free IT and Security Check — 30 minutes, plain English, no obligation. We’ll look at your setup and tell you honestly what needs addressing before you’d be ready for Cyber Essentials.

    From there, we can either help you get everything in place, or point you in the right direction if you’d prefer to handle it yourselves.

    👉 Book your free IT & Security Check(opens in new window)

    Or find out more about how we help businesses get Cyber Essentials ready: Cyber Essentials at KVS365(opens in new window)


    Ken Strettle is the founder of KVS365, a UK-based IT consultancy helping small businesses get Microsoft 365 working properly, stay secure, and get Cyber Essentials ready. Based in Newark, working with businesses across the UK.