No jargon left unexplained. 25 common terms, explained the way we'd explain them on a phone call.
Paying for IT support only when something breaks, rather than an ongoing proactive relationship.
Copies of your data stored offsite, in the cloud, so a local disaster doesn't take your backups with it.
A UK government-backed certification proving a business has five basic technical security controls in place.
The same five controls as Cyber Essentials, but independently tested rather than self-assessed.
The full plan for getting a business back online after a major IT failure — not just having backups.
Security software on laptops and servers that watches for suspicious behaviour, not just known viruses.
A system that controls what network traffic is allowed in and out of a business's network.
UK data protection law governing how businesses must collect, store and protect personal data.
The team and ticketing system staff contact for day-to-day IT problems and requests.
An international standard for managing information security across an entire organisation, not just IT.
Outsourcing day-to-day IT — helpdesk, monitoring, security, strategy — to an external team for a fixed monthly fee.
Software that lets a business enforce security settings and remotely wipe lost or stolen phones/laptops.
Requiring a second proof of identity — usually a code or app approval — alongside a password to log in.
Keeping software and operating systems updated with security fixes, systematically rather than ad-hoc.
Hiring a specialist to deliberately try to break into your systems, to find weaknesses before a real attacker does.
A fake email, text or call designed to trick someone into handing over credentials or money.
Malware that encrypts your files and demands payment to get them back.
How much data you can afford to lose, measured in time — e.g. "no more than 1 hour of data."
How long you can afford to be down, measured in time — e.g. "back up and running within 4 hours."
Software that intelligently manages traffic across multiple internet connections at a site, for reliability and speed.
A written commitment defining how quickly a provider responds to and resolves issues.
A team (and the tools they use) watching for security threats around the clock, not just during office hours.
Phone calls carried over the internet instead of traditional phone lines.
An encrypted connection that lets remote devices securely reach internal company systems over the internet.
A security model that verifies every access request, rather than trusting anything just because it's "inside" the network.