Cybersecurity
Strategic IT and Security Leadership, Without the Full-Time Hire
How vCISO and vIT Manager engagements work, when they suit a growing business, and what to expect from the service.
8 min read Read more
IT Management
What Managed IT Support Actually Means for a Growing Business
What managed IT support covers, how it differs from break-fix IT, and what to look for when choosing a provider.
8 min read Read more
Cybersecurity
How to Conduct a Cybersecurity Risk Assessment: A Practical Guide
A five-step framework for identifying assets, mapping threats, scoring risks, and building a prioritised treatment plan. Includes regulatory mapping for NIS2, ISO 27001, and UK GDPR.
16 min read Read more
Cybersecurity
Endpoint Security Guide: EDR, Patching, and Device Hardening for UK Businesses
How to move from antivirus to EDR, automate patch deployment within the Cyber Essentials 14-day window, enforce BitLocker encryption, and manage devices with Microsoft Intune.
13 min read Read more
Cybersecurity
Email Security Guide: SPF, DKIM, DMARC and BEC Controls for UK Businesses
How to configure SPF, DKIM, and DMARC, secure mailboxes with MFA, deploy Microsoft Defender for Office 365, and build process controls that block business email compromise.
15 min read Read more
Cybersecurity
How to Build a Cybersecurity Roadmap: A Practical Guide for UK Businesses
A six-step framework for building a cybersecurity programme from the ground up. Covers baseline assessment, control prioritisation, budget sequencing, and how to measure progress.
20 min read Read more
Incident Response
How to Write an Incident Response Plan: A Practical Guide for UK Businesses
The six NIST phases, playbooks for ransomware, BEC, data breaches, and account compromise, GDPR and NIS2 notification obligations, and how to test the plan with tabletop exercises.
17 min read Read more
COMPLIANCEISO 27001
ISO 27001: Certification and Implementation Guide
Cyvra guides businesses through ISO 27001 certification: the six steps, realistic timelines, costs, and what a full implementation engagement covers.
9 min read Read more
COMPLIANCENIS2
NIS2 Cybersecurity Readiness: The 10 Security Controls Your Organisation Needs
NIS2 requires 10 specific cybersecurity controls. Covers what they are, how to implement them, and incident notification before a breach forces your hand.
7 min read Read more
COMPLIANCEPCI DSS
PCI DSS Compliance Guide for UK Businesses (2025)
Understand PCI DSS v4.0 requirements for UK merchants. Learn which SAQ applies to your business, the 12 core requirements, and how to reduce your compliance scope.
12 min read Read more
COMPLIANCEEU
Cyber Resilience Act: A Compliance Guide for Manufacturers and Distributors
The EU Cyber Resilience Act requires security-by-design for connected products. Vulnerability reporting from September 2026; full compliance December 2027.
11 min read Read more
CybersecurityARCHITECTURE
Zero Trust Architecture: The Identity-First Security Model for Remote and Hybrid Organisations
Zero Trust replaces perimeter security with identity verification on every request. Five pillars, Conditional Access, NIS2 and ISO 27001 alignment.
11 min read Read more
CybersecurityMICROSOFT 365
Microsoft 365 Security Hardening: The Controls Most Organisations Miss
Most Microsoft 365 tenants run default settings built for adoption, not security. Credential attacks and phishing campaigns succeed because basic hardening controls are never...
11 min read Read more
COMPLIANCEDORA
How to Conduct a DORA Gap Analysis: A Step-by-Step Framework for FinTechs
DORA has applied since January 2025. Step-by-step gap analysis framework for FinTechs covering all five pillars and a prioritised remediation roadmap.
9 min read Read more
CybersecurityIDENTITY
Passkeys and Passwordless: The Practical Guide for IT and Security Leaders
Passkeys replace passwords with device-bound cryptographic keys that cannot be phished. This guide covers how FIDO2 works, what enterprise rollout looks like, and where legacy...
14 min read Read more
INCIDENT RESPONSE
Ransomware: What to Do Before, During and After an Attack
Ransomware appeared in 88% of SMB breaches. Covers what it does, key defences, what to do in the first 48 hours, and how to recover without paying.
8 min read Read more
INCIDENT RESPONSE
Ransomware Recovery: How to Restore Your Systems Without Reinfecting Them
Ransomware hit your organisation? Cyvra responds within hours. Six recovery steps: backup validation, eradication, GDPR notification, and hardening.
9 min read Read more
COMPLIANCENIST CSF
Implementing Cybersecurity Controls for NIST CSF 2.0 and NIS2
NIST CSF 2.0 and NIS2 share the same underlying controls. Implement them once to cover both frameworks and avoid duplicated security work.
10 min read Read more
IT MANAGEMENT
How Much Should Your Business Spend on IT? A Budget Framework for SMEs
Most SMEs spend 1-2% of revenue on IT. Benchmarks suggest 4-7% for professional services. Five categories, hardware cycles, and how to build an IT budget.
8 min read Read more
IT MANAGEMENT
How to Build an IT Service Desk Without Hiring a Full Team
IT service desk essentials for SMEs: support tiers, ticketing, SLA targets and when a managed provider makes more sense than in-house IT.
7 min read Read more
AIMICROSOFT 365
Microsoft 365 Copilot: how to implement it safely and what goes wrong when you don't
Microsoft 365 Copilot amplifies data risks before it improves productivity. Covers oversharing, DLP gaps, and what to configure before you switch it on.
9 min read Read more
AI
AI Governance for UK Organisations: A Practical Framework
How to govern AI use in your organisation: map what you are using, classify by risk, write an AI policy, meet UK GDPR obligations, and assess EU AI Act applicability.
20 min read Read more
AI
AI Implementation for UK Businesses: A Practical Framework
How to implement AI in your business: define the objective, prioritise use cases, assess data readiness, select technology, pilot, test, and measure the business result.
18 min read Read more

Not sure where your security programme stands?

We'll assess your current controls, identify gaps, and help you build a roadmap that matches your risk profile and budget.

Book a cybersecurity assessment