Internet Security: How to Keep Your Business Safe Online
Internet-connected businesses face a consistent and growing range of threats: phishing, ransomware, credential theft, and supply chain attacks. This guide covers the practical measures UK businesses should have in place — from firewalls to employee training — without technical jargon.
AMVIA Team
Editorial
This is a practitioner's guide, not a brochure. It covers what a UK business with 10–500 staff actually needs in place, why each control matters, and where to start if your budget is tight. If you want the controls assessed and implemented for you, our managed cybersecurity team does exactly that.
What are the biggest internet security threats to UK businesses?
The biggest threats are mundane: phishing, stolen credentials, ransomware, unpatched software, and badly configured remote access. The National Cyber Security Centre (NCSC) consistently reports that most successful attacks exploit basic failures, not advanced techniques. You are defending against opportunists who follow the path of least resistance.
That reality shapes everything below. You do not need to outspend a nation-state — you need to be a harder target than the business next door. Credentials are now the prize attackers want most.
Verizon's 2025 Data Breach Investigations Report found that "Stolen or compromised credentials were the initial attack vector in 22% of data breaches in 2024" — the single largest cause, "surpassing phishing (16%)" and software vulnerabilities (Verizon DBIR 2025). That is why identity controls like MFA matter more than any single appliance. For the UK picture on attack prevalence and cost, the government's Cyber Security Breaches Survey is the authoritative annual read.
The layered model below maps each control to the threat it actually stops:
| Control | What it stops | Where it runs |
|---|---|---|
| Business firewall | Unauthorised inbound/outbound traffic, malicious domains | Network perimeter |
| Endpoint protection (EDR) | Malware and behaviour-based threats on devices | Every laptop/desktop/phone |
| Email security | Phishing, impersonation, malicious links and attachments | Mailbox / mail flow |
| Multi-factor authentication | Account takeover from stolen passwords | Every internet-facing login |
| Patch management | Exploitation of known vulnerabilities | OS and applications |
| Staff awareness training | Human error, credential disclosure | The whole workforce |
Why does your business need a real firewall, not an ISP router?
A business-grade firewall is the foundation of internet security: it controls traffic in and out of your network, blocks unauthorised connections, and watches for suspicious activity. The consumer router your broadband ISP supplies is not a business firewall — it lacks the inspection depth and update frequency a dedicated appliance provides.
Key capabilities to look for in a business firewall:
- Deep packet inspection — inspects the content of traffic, not just source and destination
- Intrusion detection and prevention (IDS/IPS) — spots attack patterns and blocks malicious connections automatically
- DNS filtering — blocks known malicious domains before a connection is made
- Application awareness — identifies and controls specific apps, not just port numbers
Business firewall appliances from vendors like Fortinet, Sophos, and Cisco Meraki start from around £300–£800 (typical UK 2026 range) for hardware suited to a small office, plus an ongoing subscription for threat-intelligence updates. The appliance is only half the job — it needs configuring and monitoring, which is where a managed detection and response service earns its keep.
How do you protect every device that connects?
Every device on your network — laptops, desktops, mobiles — is a potential entry point. Modern Endpoint Detection and Response (EDR) goes well beyond signature antivirus: it watches device behaviour continuously, catches threats that signatures miss, and can isolate a compromised device automatically before damage spreads.
Microsoft Defender for Business — included in Microsoft 365 Business Premium at £16.90 per user/mo (microsoft.com/en-gb) — provides strong EDR for Windows estates. In genuinely cross-platform environments, products like Sophos Intercept X and CrowdStrike Falcon are also widely used. AMVIA's own managed stack is built on Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC. See how we run Microsoft Defender for Business day to day.
How do you stop phishing and email attacks?
Email is the primary delivery route for phishing and malware, and basic spam filtering is not enough. Effective business email security combines impersonation detection, real-time link and attachment scanning, and proper domain authentication so attackers cannot spoof your name to your own customers.
Business email security should include:
- Anti-phishing and impersonation protection — catches spoofed "trusted sender" attacks
- Safe Links and Safe Attachments — scans links and files in real time before the user sees them
- DMARC, DKIM, and SPF — authentication standards that stop your domain being spoofed in phishing sent to customers and partners
Microsoft Defender for Office 365 (in Business Premium and above) covers these controls; AMVIA layers the Barracuda email security suite where customers need deeper filtering. The mechanics of detection — sender reputation, impersonation analysis, and live link scanning — are explained in our phishing protection guide.
Why is multi-factor authentication the highest-value control?
Multi-factor authentication (MFA) is the single most effective control against account compromise. With MFA on, a stolen password alone is useless — the attacker also needs the second factor, typically a code from an app or a hardware token. Given that credentials are the leading breach vector, this is the highest return on effort available.
The NCSC recommends MFA on all internet-facing services. Turning it on for Microsoft 365, your VPN, and any externally accessible system should be the first thing any business does if it is not already in place. It is included in most Microsoft 365 plans and takes about an hour to configure and roll out. We walk through it in our MFA setup for Microsoft 365 guide.
How fast should you patch software?
Apply critical security patches within 14 days of release at most — ideally sooner. Attackers actively scan for known vulnerabilities, and many breaches happen weeks or months after a fix was already available but never applied. A disciplined patch process is one of the cheapest, highest-impact controls you can run.
Microsoft's Patch Tuesday ships updates monthly, and most endpoint management tools automate deployment. Operating systems and applications left unpatched beyond a month represent materially elevated risk. Treat patching as a tracked process, not an occasional chore — our vulnerability management service keeps it measured and on schedule.
How do you turn employees into a security layer?
Technology stops a large share of attacks, but employees remain the most targeted part of any organisation. Quarterly (or more frequent) phishing simulations and security awareness training measurably reduce the odds of staff clicking malicious links or handing over credentials. People are not the weak link if you train them to be the strong one.
The NCSC's free e-learning and Cyber Aware guidance gives businesses without a formal programme a solid baseline. Pair it with simulated phishing so you can see who needs support — and prove improvement over time. Cyber Essentials Plus, which AMVIA holds, formalises these basics into an audited standard.
What does AMVIA recommend?
Start with the controls that block the most common attacks for the least effort: MFA everywhere, fast patching, and proper email security. Layer in a managed firewall, EDR, and staff training as you mature. The goal is a single accountable provider running it all — not six tools nobody monitors.
That is what AMVIA delivers for 1,200+ UK businesses (rated 4.8/5): firewall, endpoint, email, and identity security managed together, monitored by our 24/7 SOC, and backed by Microsoft-certified engineers. One provider. Security-first. Microsoft-certified. You can take this as a standalone security review or as part of a broader managed SOC service.
Is Your Business Properly Protected Online?
AMVIA's security review covers firewall configuration, endpoint protection, email security, MFA status, and patch management — giving you a clear picture of where your business is exposed.
Frequently Asked Questions
The mundane ones: phishing emails harvesting credentials, ransomware following a compromised account or unpatched system, and payment fraud through hijacked email threads. Exotic attacks make headlines; ordinary businesses are breached through email and passwords, which is why the highest-value defences are unglamorous.
No. ISP routers do basic network address translation with minimal inspection, no real policy control and rarely any logging. A business firewall adds proper rules, content filtering and visibility — and for 10–500 staff it's one of the cheapest structural upgrades available relative to what it prevents.
Multi-factor authentication on every account, starting with email and admin accounts. It's the single highest-value control available: it turns a stolen password from a breach into a failed login, costs little or nothing on licences you already own, and can be rolled out in days.
Within 14 days for security updates — the benchmark Cyber Essentials sets — and faster for actively exploited vulnerabilities. Attackers weaponise disclosed flaws in days, so a monthly patch cycle leaves a standing window of exposure. Automate updates wherever the software allows it.
Related Reading
We Analysed 60,000 UK Endpoints: Hidden Cyber Risk Report
AMVIA's analysis of 60,000 UK business endpoints and the cybersecurity risks found in leased line infrastructure.
Microsoft 365 Enterprise: A Practical Performance Guide
How the enterprise security features in M365 E3 and E5 address real business security requirements.
Does Your Business Need a Leased Line?
How a dedicated internet connection improves both performance and network security for growing businesses.