Cyber security

Somebody has to be looking at it.

Security software that nobody reads isn’t security. We run the tools, and a security operations centre watches what they find around the clock, with our team on top of that.

Talk to us 029 2111 1202

24/7watched by a real SOC

Cyber Essentialscertified ourselves

Cardiff basedno offshore first line

What we find

A true story about a domain controller

We onboarded a client and did what we always do: put Bitdefender on every machine and read what came back off the first scan.

There was a scheduled task sitting on their domain controller. It had been there since November 2019. Every ten minutes, it ran a PowerShell command that tried to download and execute code from a domain known to be part of the Lemon Duck cryptomining botnet.

Every ten minutes. On the domain controller. Since 2019.

The only reason it wasn’t mining cryptocurrency on their server and spreading across the network was that the attacker’s address had gone offline at some point in the intervening years. They had been saved by the attacker’s infrastructure failing, not by anything anyone on the defending side had done.

Here’s the part that should worry you. The previous IT provider had been managing that environment for years. There was antivirus installed. It was scanning every day. Nobody was reading what it found.

Data nobody looks at isn’t protection. It’s a false sense of one.

What we do

Layers, and somebody watching all of them

No single product stops everything, and anyone who tells you otherwise is selling. What matters is how many places an attack has to get through, and whether a human notices when one of them lights up.

24/7

Managed detection and response

The bit that was missing in the story above.

  • Bitdefender endpoint protection and Advanced Threat Security on every machine
  • A security operations centre reading the alerts around the clock
  • Our team on top of that, who know your setup
  • Threats contained rather than logged and forgotten

Email

Stopping what arrives by email

Where almost all of it starts.

  • Check Point Advanced email security, inside Microsoft 365 rather than in front of it
  • Catches what the built in filtering lets through
  • Multi-factor authentication done properly
  • Alerts on the mail rules attackers add to a compromised mailbox to hide their tracks

Browsing

The click that gets through anyway

Because eventually somebody clicks.

  • DefensX DNS and browser protection
  • Stops the connection before the bad site loads
  • Keeps credentials out of harm’s way in the browser
  • Works wherever the laptop is, not just in the office

People

Your team, and the gaps you can’t see

The two things every audit turns up.

  • Security awareness training your staff will actually sit through
  • Vulnerability scanning and management
  • Admin rights taken back off accounts that never needed them
  • Accounts of people who left, shut down properly

Your domain name

Nobody else gets to send email as you

Your domain name is one of the few things your customers trust without thinking about it. Unless it’s set up to stop them, anybody in the world can put your company in the From line, and there’s nothing in your customer’s inbox to tell them otherwise.

Your customer’s accounts team gets an email from you. The name is right. The signature is right. The invoice looks like every other invoice they’ve had from you, because whoever sent it has seen one.

Only the bank details are different.

They pay it. The money is gone the same day.

Nobody broke into your email. Nobody needed your password. The From line on an email is just text, and anybody can type anything they like in it. The only thing that stops them is three records published against your domain, and most small businesses have one of them, half configured, put there by whoever set up their email years ago and never looked at since.

Your customer lost the money. You lost the customer.

SPF, DKIM and DMARC, set up so they actually do something

SPF lists the servers allowed to send email for you. DKIM signs what goes out, so the receiving server can prove it arrived the way you sent it. DMARC tells that server what to do when the first two fail, and reports back on everyone who has been trying it on.

Publishing the records takes ten minutes. Turning them up to the point where forgeries actually get rejected is the part that needs care, because your payroll system sends as you. So does your CRM, your booking system, your accounts package, and whatever tool somebody signed up for last year. Get that wrong and the first thing to stop arriving is your own invoices, which is why so many businesses put DMARC in on monitoring only and leave it there for good.

  • We audit what your domain publishes today, which usually isn’t what anyone remembers setting up
  • We find every legitimate sender before we tighten anything, including the ones you’d forgotten about
  • We move the policy up in stages and read the reports at each one
  • We finish at a policy that rejects forgeries rather than one that just watches them go past
  • We keep reading the reports, because senders change and a record set once goes stale

Included from Secure upwards. See what each level includes

The stack

Some of the tools we actually run

Plenty of providers won’t tell you what they use, which makes it hard to compare anything or understand what’s keeping your business safe. Here’s ours.

NinjaOne

Remote monitoring, management and access, and our backup and vulnerability management. It is how we see the state of every machine, push patches, take backups and know something has gone wrong before you ring.

Bitdefender

Endpoint protection, Advanced Threat Security and managed detection and response. A security operations centre watching the alerts around the clock, with us on top of that.

Check Point

Email security, sitting inside Microsoft 365 rather than in front of it, so it catches what gets past the built in filtering. You may know it as Avanan.

DefensX

DNS and browser protection. Stops the click before it reaches the bad site, and takes credentials out of harm's way in the browser.

Talk to us

Find out what’s already on your network

Most of what we find on day one has been sitting there for years. Tell us what you’re running and we’ll tell you what we’d look at first.

Proof

We hold the certification too

It would be a strange thing to sell and not have. We’re Cyber Essentials certified, and we take clients through it to both levels.

Cyber Essentials certified

Cyber Essentials, ours and yours

A certificate proves you met the controls on the day you were assessed. It doesn’t tell you whether a scheduled task has been running on your domain controller since 2019. Get the badge if a contract or a tender needs it, and get the monitoring because the badge doesn’t do that job.

What Cyber Essentials involves Check our certificate

We have used Saturday Cloud for a number of years now and very happy with their service. The team are always on hand to help and support and are able to get back to any queries we may have. We have recently had Cyber Security put into the setting and having Saturday Cloud to help work through this with us has been a huge help. Would recommend highly!!

Shannon Treharne Nursery Manager, The Laurels Nursery

Having worked with Saturday Cloud for over 8 years across our telecoms network, I can’t recommend them enough. They are always incredibly quick to respond and resolve any issues promptly. If you’re looking for a reliable partner for your business infrastructure, you’re in safe hands.

Sarah Evans General Manager, James Douglas / Seraph

5.0 from 20+ Google reviews

Questions

The things people ask first

What does 24/7 monitoring actually mean?

Bitdefender’s security operations centre reads the alerts from your machines around the clock, every day of the year, and acts on the ones that matter. Our team sits on top of that with the context of how your business runs. It doesn’t mean our helpdesk answers the phone at three in the morning. That’s 9am to 5pm, Monday to Friday, with out of hours cover available as an add-on.

We already have antivirus. Is that not the same thing?

No, and the story further up this page is why. Antivirus tells you what it found. Managed detection and response means somebody reads that, decides whether it matters, and does something about it. The client in that story had antivirus installed and scanning every day for years, with a live threat sitting on the domain controller the whole time.

Can somebody send email that looks like it came from us?

Yes, unless your domain is set up to stop it. The From line on an email is just text and anybody can type your company into it. Three records on your domain, SPF, DKIM and DMARC, are what let a receiving mail server throw a forgery away instead of putting it in your customer’s inbox. Most businesses we audit have SPF, no DKIM on at least one sender, and either no DMARC or a DMARC record set to watch and do nothing. It’s included from our Secure level upwards.

Can we have the security without moving our IT to you?

Yes. Co-managed security runs the same stack for businesses with their own IT person or internal team. Your people keep doing what they do and somebody is watching the alerts around the clock. The shape of it depends on what your team already covers, so it starts with a conversation rather than a number.

Will this stop us being breached?

Nobody can promise that, and you should be wary of anyone who does. At some point something will get through: a convincing email, a compromised supplier, a device that walks out of an office. What this buys you is the ability to respond properly, clear audit trails, and somebody who notices on the day rather than years later.

Is this included in your IT support, or extra?

It’s a level rather than an add-on. Our Secure level is IT support with all of this underneath it, and it’s what most of our clients are on. The prices for all three levels are on the pricing page.

What happens in the first few weeks?

We audit what’s actually there before we change anything, then tell you what we found, including the parts that are awkward. Two things always change: unlicensed software gets removed and multi-factor authentication gets switched on. After that it’s layers going on and somebody watching them.

From the blog

What we find, and what we would do about it

The situations that come up most, answered in full rather than summarised into a bullet point.

Cyber security

Will your cyber insurance actually pay out?

Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.

Read this

Everything we’ve written

Next step

Ask us what we’d look at first

Tell us how many people you have and what you’re running now. You’ll get a straight answer about where the gaps usually are and what it would cost to close them.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.