# AMVIA - full content export > AMVIA is a UK managed service provider (MSP/MSSP) delivering business > leased lines and dedicated internet access, business broadband, VoIP, > business mobiles, cybersecurity, Microsoft 365 security, and managed IT > support to UK businesses. Phone: 0333 733 8050. > Curated link index: https://amvia.co.uk/llms.txt --- # Managed Cybersecurity for UK Businesses (from £12/User) URL: https://amvia.co.uk/cybersecurity Last updated: 2026-03 Managed cybersecurity is the practice of outsourcing 24/7 threat monitoring, detection and response to a specialist provider that runs a Security Operations Centre (SOC). For UK SMEs it bundles endpoint, email, network and identity protection into one monthly service. AMVIA runs it from a UK SOC - one provider, security-first, Microsoft-certified. This is the hub for everything AMVIA does in security. You can start with full-stack managed cybersecurity, or read on and move down into each individual service - the table below links to every layer for a UK business with 10–500 staff. ## What is managed cybersecurity? Managed cybersecurity - often sold as a managed security service (MSSP) - means a specialist provider takes ownership of monitoring, detecting and responding to threats across your environment, around the clock, from a dedicated SOC. Instead of your own team chasing alerts, the provider runs the tooling, the analysts and the response process as one service. For a UK SME, that typically combines: - Endpoint security - behavioural detection (EDR) on every laptop, desktop and server, not just signature antivirus. - Email security - anti-phishing, DMARC/DKIM/SPF and business email compromise protection. - Network security - firewall management and traffic monitoring at the perimeter. - Identity security - multi-factor authentication and monitoring for compromised credentials. - SOC monitoring - analysts who correlate every alert and act on the real ones 24/7. - Compliance support - controls that support UK GDPR and sector regulations. AMVIA delivers all of this as one accountable service. You can take it as a full stack or build up from the controls that close your biggest gaps first. ## Why do UK SMEs need managed cybersecurity? UK SMEs need managed cybersecurity because attacks are automated and indiscriminate - size is no defence. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses reported a breach or attack in the past year, with an average cost of £3,550 for the most disruptive breach. Threat actors scan millions of IP addresses at once, so a 12-person firm is hit by the same commodity attacks as a 500-person one. The difference is that smaller teams rarely have analysts watching at 3am on a Saturday - exactly when ransomware operators strike. - 43% of UK businesses experienced a cyber breach or attack in 2025 (Cyber Security Breaches Survey 2025, gov.uk). - £3,550 average cost of the most disruptive breach in 2025 (Cyber Security Breaches Survey 2025, gov.uk). - Around 85% of identified breaches involved phishing (Cyber Security Breaches Survey 2025, gov.uk). The NCSC's small business guidance is clear that monitoring and a tested response plan matter as much as prevention. That is the gap a managed SOC fills. ## What does AMVIA's managed cybersecurity include? AMVIA's managed cybersecurity covers every layer of your posture - endpoints, email, network, identity and cloud - monitored from a UK Security Operations Centre. It is a layered service: close your biggest gaps first, then add capability as your risk profile grows. | | Layer | What it does | AMVIA service | Detection & response | Analyst-led investigation and containment, not just alerts | Managed detection and response | 24/7 monitoring | Round-the-clock SOC coverage across your estate | Managed SOC service | Email | Anti-phishing, DMARC/DKIM/SPF, BEC protection | Email security | Endpoint | Behavioural EDR on every device | Endpoint security | Resilience | Containment, investigation and recovery after a breach | Incident response | Validation | Independent testing of your defences | Penetration testing Every layer runs on the same stack: Microsoft Defender for Endpoint for behavioural detection, and the Barracuda email and network security suite for the perimeter. There is no white-labelled third-party SOC behind it - AMVIA's own analysts watch your environment. ## Managed SOC vs DIY security: why in-house isn't enough The default SME approach - antivirus, a firewall, and hope - fails for three concrete reasons. Signature antivirus misses modern threats, alerts without analysts go unactioned, and attacks land out of hours. A managed SOC closes all three by pairing behavioural tooling with people who respond. | | | DIY / antivirus only | AMVIA managed cybersecurity | Detection | Known-signature malware only | Behavioural EDR catches unknown threats | Coverage | Business hours, best effort | 24/7 UK SOC, 365 days a year | Response | Alerts pile up unread | Under 1 hour for critical (P1), 2-hour target for others | Cost | £45,000–£65,000/yr for one analyst | From £5 per user per month | Accountability | Split across tools and staff | One provider, security-first A single in-house analyst costs £45,000–£65,000 per year (typical UK 2026 range) and still cannot provide 24/7 cover alone. AMVIA delivers equivalent capability at materially lower cost by spreading a UK SOC across 1,200+ UK businesses. ## How much does managed cybersecurity cost? Managed cybersecurity for UK SMEs is priced per user, typically £5–£65 per user per month depending on scope. Basic endpoint plus email security sits at the lower end; a full stack with EDR, SOC monitoring, vulnerability management and incident response sits at the top. AMVIA's managed cybersecurity starts from £5 per user per month - less than a single day of incident response from a specialist firm. The figure within that range depends on how many layers you turn on and how many users you cover. ## How AMVIA delivers managed cybersecurity AMVIA runs a Security Operations Centre from Sheffield, monitoring 1,200+ UK businesses on enterprise-grade tooling delivered at SME pricing. Onboarding starts with a security assessment, then a one-to-two-week baselining period to tune alert thresholds before live monitoring begins. - Onboarding - assess current gaps in endpoint, email, patching and access; deploy monitoring agents; baseline for 1–2 weeks. - Ongoing monitoring - 24/7 correlation of alerts from endpoint, email, network and cloud, with analyst-led response and a monthly report. - Co-managed options - for businesses with 50–200 staff that have IT resource but no security specialism, AMVIA provides the SOC and tooling while your team keeps day-to-day IT. AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner, so the engineers configuring Defender and Conditional Access are certified to do it. See Microsoft's security guidance for the platform underneath. ## Frequently asked questions Q: How much does managed cybersecurity cost for a UK SME? A: Managed security scope ranges from £5 to £65 per user per month depending on coverage, with AMVIA's entry managed-security anchor from £12 per user. Against an average most-disruptive-breach cost of £3,550 (DSIT 2025) - and far higher for serious incidents - the monthly fee is the cheap side of the equation. Q: Does my small business really need managed cybersecurity? A: The UK data says the threat doesn't skip small businesses: 43% of UK businesses experienced a breach or attack in the past 12 months, and 85% of breaches involved phishing (DSIT 2025). If you don't have in-house security expertise watching around the clock, a managed service is how you get it at SME cost. Q: What does AMVIA's managed cybersecurity actually include? A: Layered protection run as a service: endpoint protection and EDR, email security, Microsoft 365 hardening, vulnerability management, and - on Enterprise plans - 24/7 SOC monitoring with incident response. One provider owns the stack, so there's a single accountable point of contact when something needs handling. Q: Is AMVIA certified? A: Yes - AMVIA holds Cyber Essentials Plus, the audited tier of the UK's government-backed certification, and is a Microsoft Solutions Partner. We also prepare client businesses for their own Cyber Essentials certification, since the five controls it verifies are what our plans run day to day. Q: What's the difference between an MSP and an MSSP? A: An MSP runs your IT (helpdesk, infrastructure, devices); an MSSP runs your security (monitoring, detection, response). AMVIA does both under one contract - which matters, because most real incidents cross the boundary between the two and finger-pointing between separate providers costs response time. --- # Managed SOC Service for UK SMEs | 24/7 Security Operations URL: https://amvia.co.uk/cybersecurity/managed-soc-service Last updated: 2026-03 A managed SOC service gives your business a 24/7 Security Operations Centre - analysts monitoring your environment, investigating every alert, and responding to incidents - without the cost of hiring a security team. AMVIA's UK-based SOC runs on Microsoft Sentinel and Defender. One provider. Security-first. Microsoft-certified. - 1,200+ UK businesses protected - 24/7 monitoring and response - critical incident response AMVIA's managed SOC is the human layer on top of your managed cybersecurity stack. Our Sheffield-based analysts watch your Microsoft 365, endpoints, and network around the clock, so a confirmed threat gets contained while your team sleeps. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we run this for over 1,200 UK businesses. ## What is a managed SOC service? A managed SOC (Security Operations Centre) is an outsourced team of security analysts who monitor your IT environment 24/7, triage alerts, hunt for threats, and respond to incidents on your behalf. It replaces the need to build, staff, and license an in-house SOC, which typically costs £1.2–1.5 million a year to run (typical UK 2026 range). The UK threat picture makes round-the-clock cover hard to justify skipping. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses suffered a cyber breach or attack in the past year. Attacks do not keep office hours, so neither do we. ## What's included in AMVIA's managed SOC? Every managed SOC engagement combines continuous monitoring, human-led investigation, and rapid response, integrated with the tools you already run. We do not just forward alerts - we triage, contain, and report, so your IT team gets decisions, not noise. - 24/7 Security Operations Centre - UK-based analysts monitoring your environment around the clock, in real time. - Human-led threat analysis - every alert is investigated by a trained analyst, not just an automated correlation rule, so false positives are stripped out before they reach you. - Incident response - confirmed threats are contained at source, the root cause is investigated, and your team is kept informed throughout. - Threat intelligence - detection is informed by continuously updated intelligence on attack techniques targeting UK businesses. - Custom detection rules - logic tuned to your applications, environment, and risk profile, not generic out-of-the-box rules. - Regular reporting - monthly threat reports and quarterly business reviews in plain English, written for leadership, not just engineers. Our 24/7 security monitoring and managed detection and response services feed directly into the SOC, giving one accountable team across detection and response. ## What SIEM and tools does the managed SOC use? AMVIA's SOC runs on Microsoft Sentinel as the primary SIEM (Security Information and Event Management) platform, with Microsoft Defender providing endpoint and identity telemetry and the Barracuda suite covering email and network security. We centralise your security logs in one platform and manage the licensing for you. This is a fully Microsoft-aligned stack, which matters if you already run Microsoft 365. Microsoft Defender for Business supplies the endpoint signal, and Sentinel correlates it with cloud and network events. You can read Microsoft's own overview of Sentinel as a cloud-native SIEM for the platform detail. Our analysts perform proactive threat hunting on top of this telemetry - looking for persistent footholds that automated rules miss. For the underlying detection-rule engineering, see our SIEM for SMEs service. ## Why do UK SMEs need a managed SOC? Most SMEs cannot staff a 24/7 SOC, yet they face the same threats as enterprises. A managed SOC closes that gap, giving you enterprise-grade detection and response at a fraction of the cost of building it in-house. The risk of going without is no longer theoretical. The DSIT survey puts the average cost of a disruptive breach at £3,550 for businesses (DSIT Cyber Security Breaches Survey 2025). Security tools generate hundreds of alerts a day; without a team to triage them, genuine threats hide in the noise. A managed SOC turns that noise into a short list of decisions. The NCSC's guidance on mitigating ransomware attacks underlines the same point: monitoring is only useful if someone is acting on it. ## In-house SOC vs AMVIA managed SOC Building a 24/7 SOC means hiring multiple certified analysts, buying SIEM licences and threat-intelligence feeds, and funding continuous training. A managed SOC delivers the same coverage as an operating expense, priced on users and data sources monitored. | | Factor | In-house SOC | AMVIA managed SOC | 24/7 coverage | Needs 6+ analysts for shift cover | Included from day one | Typical annual cost | £1.2–1.5M (typical UK 2026 range) | OPEX, priced per user/data source | SIEM licensing | You buy and manage | Included and fully managed | Time to operational | Months to recruit and tune | Weeks via structured onboarding | Threat hunting | Depends on in-house skill | Built in, by certified analysts | Reporting | You build it | Monthly reports + quarterly reviews ## How does AMVIA's managed SOC onboarding work? Onboarding follows five stages, from discovery to continuous improvement, designed to get monitoring live in weeks rather than months. You get a structured path with clear ownership at every step, not an open-ended project. 1. Discovery - we assess your environment, identify your assets, and map your risk profile. 2. Onboarding - we deploy monitoring and configure integrations with your existing tools. 3. Monitoring - 24/7 coverage begins; analysts watch your environment continuously. 4. Detection and response - threats are detected, investigated, and contained by the SOC. 5. Continuous improvement - regular reviews sharpen detection accuracy and widen coverage. If a confirmed incident needs hands-on containment, our incident response team takes over without a handoff to a third party. ## How much does a managed SOC service cost? A managed SOC is priced on the number of users and data sources monitored, delivered as a predictable monthly cost. That compares with the £1.2–1.5 million a year (typical UK 2026 range) it typically takes to build and run an equivalent in-house SOC - analysts, SIEM licensing, intelligence feeds, and training combined. For most UK SMEs, the managed model is the only realistic way to get genuine 24/7 cover. Book a free security audit and we will scope your environment and give you a concrete figure - no obligation. ## Frequently asked questions Q: What do managed SOC analysts actually do? A: SOC analysts continuously monitor security telemetry from your endpoints, email, network, and cloud using SIEM and EDR platforms. They investigate every alert, decide whether it is a genuine threat or a false positive, and escalate confirmed incidents for containment. They also run proactive threat hunting and tune detection rules to your environment, so cover gets sharper over time. Q: What SIEM does AMVIA's managed SOC use? A: AMVIA's SOC runs on Microsoft Sentinel as the primary SIEM, with Microsoft Defender providing endpoint and identity telemetry and the Barracuda suite covering email and network security. We integrate with your existing firewalls, cloud apps, and email to centralise all logs in one platform. Licensing and maintenance are fully managed by us, removing that burden from your team. Q: How does a managed SOC reduce alert fatigue? A: Security tools generate hundreds of alerts daily, most of them benign. Our analysts triage every alert before it reaches you, filtering out false positives and escalating only confirmed threats that need a business decision. Your IT staff stop drowning in noise and focus on their core work, while genuine threats - given the £3,550 average disruptive breach cost (DSIT 2025) - get immediate attention. Q: Is a managed SOC cheaper than hiring in-house? A: Yes, for almost every SME. An in-house 24/7 SOC requires multiple certified analysts plus SIEM licensing, threat-intelligence feeds, and ongoing training - typically £1.2–1.5 million a year. A managed SOC delivers equivalent coverage as a monthly operating cost, priced on users and data sources. Given the ransomware threat UK businesses now face, the cover is no longer optional. Q: What reporting do we get from the managed SOC? A: You receive monthly threat reports summarising alerts investigated, incidents handled, containment actions taken, and trends across your environment. Quarterly business reviews with your account manager cover posture improvements, detection-rule changes, and strategic recommendations. Everything is written in clear business language with executive summaries, so leadership understands its risk without wading through jargon. Q: Is AMVIA's SOC UK-based? A: Yes. Our engineering and SOC team operates from Sheffield, so your monitoring and response are handled in the UK. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we understand UK compliance requirements, network infrastructure, and the specific challenges facing British businesses. --- # Managed Detection and Response (MDR) for UK Businesses URL: https://amvia.co.uk/cybersecurity/managed-detection-response Last updated: 2026-03 Managed detection and response (MDR) is a fully managed security service that combines continuous threat monitoring, human-led threat hunting, and rapid incident containment. AMVIA's UK-based 24/7 SOC monitors Microsoft Defender across your endpoints, identity and email, detecting and stopping attacks in minutes - one provider, security-first, Microsoft-certified. MDR exists because most UK SMEs cannot staff a security team around the clock. You get the people, process and tooling of an enterprise security operations centre as a fixed monthly service. It is the active-defence layer of our wider managed cybersecurity offering, sitting on top of prevention controls to catch what slips through. ## How does AMVIA's MDR service work? AMVIA's MDR runs as a four-stage loop: assess your environment, deploy detection, monitor and hunt 24/7, then contain confirmed threats. Microsoft Defender for Endpoint feeds telemetry to our 24/7 SOC, where UK analysts triage every signal and act on real attacks - not raw alerts. - Environment assessment - we map your endpoints, network, and Microsoft 365 estate to set the right detection coverage. - Sensor deployment - lightweight Defender agents stream telemetry from your devices and identity logs to our platform. - Threat detection and hunting - analysts monitor alerts 24/7, correlate events, and proactively hunt for indicators automated rules miss. - Response and containment - confirmed threats are isolated, accounts disabled, malware removed, and your team briefed with full incident detail. Because the detection engine is Microsoft Defender for Business - not a bolt-on third-party agent - there is no rip-and-replace. We monitor the security tooling already built into your Microsoft licences. See Microsoft's own documentation on Defender for Endpoint for how the underlying detection works. ## What's included in managed detection and response? Every AMVIA MDR engagement bundles continuous monitoring, expert management, and clear reporting into one accountable service. You are not buying a dashboard - you are buying outcomes delivered by named UK engineers who know your environment. - Proactive protection - continuous monitoring and threat detection to stop incidents before they bite. - Expert management - UK-based engineers handle configuration, tuning, updates, and live incident response. - Regular reporting - monthly reports on security posture, incidents handled, and prioritised improvements. - Dedicated support - direct access to your account team, with critical issues responded to in under one hour. For threats that reach the device, MDR pairs naturally with endpoint detection and response (EDR); when an incident is confirmed, our incident response playbooks take over. ## Why do UK SMEs need MDR? UK SMEs need MDR because attackers operate outside office hours and prevention alone is not enough. Detection without a human response is just noise. The numbers show how routine breaches have become - and how expensive the ones you miss can be. - 43% of UK businesses experienced a cyber breach or attack in the last year (DSIT Cyber Security Breaches Survey 2025). - 85% of those breaches involved phishing (DSIT 2025). - £3,550 was the average cost of the most disruptive breach to UK businesses (DSIT 2025). - 22% of breaches began with compromised credentials as the initial vector (Verizon DBIR 2025). - The global median ransomware demand fell 34% year on year to about $1.32 million (~£1.04m) in 2025 (Sophos 2025). The National Cyber Security Centre publishes ongoing guidance on these cyber threats and consistently recommends 24/7 detection and response for organisations that cannot absorb downtime. AMVIA delivers exactly that, backed by 24/7 security monitoring. ## MDR vs EDR vs SIEM: what's the difference? MDR, EDR and SIEM solve overlapping problems at different layers. EDR is the sensor on the device. SIEM is the log-correlation engine. MDR is the managed service - the analysts and process that turn both into stopped attacks. SMEs without a security team get the most value from MDR. | | Capability | EDR | SIEM | MDR (AMVIA) | Detects threats on endpoints | Yes | Partial | Yes | Correlates logs across the estate | No | Yes | Yes | 24/7 human analysts | No | No | Yes | Proactive threat hunting | No | No | Yes | Hands-on incident containment | Limited | No | Yes | In-house staff required | High | High | None For a deeper breakdown, read our MDR vs EDR comparison. ## How much does MDR cost? AMVIA prices MDR per user per month on a fixed, predictable basis - no hidden charges for alert volume or incident response actions. This puts enterprise-grade security operations within reach of a 10–500 staff business without the cost of hiring a full in-house team. Set that monthly fee against the downside: with a global median ransomware demand of about $1.32 million (~£1.04m) in 2025 (Sophos 2025) and a £3,550 average disruptive-breach cost (DSIT 2025), MDR is a fraction of the financial impact of a single undetected intrusion. We scope exact pricing to your user count and environment during a free assessment. ## Frequently asked questions Q: How does MDR differ from a standalone SIEM? A: A SIEM collects and correlates security logs but needs skilled in-house staff to write detection rules, investigate alerts, and respond. MDR wraps that capability with 24/7 human analysts, proactive threat hunting, and hands-on containment - delivering outcomes, not raw data. For SMEs without a dedicated security team, MDR is what makes SIEM data actionable. Q: What does proactive threat hunting involve? A: Our analysts do not just wait for alerts. They actively search your environment for indicators of compromise, unusual account behaviour, and signs of attacker persistence that automated rules miss - including authentication anomalies, lateral movement, and suspicious PowerShell execution. With 22% of breaches starting from compromised credentials (Verizon DBIR 2025), hunting for credential abuse before it triggers an alert is essential. Q: How quickly does AMVIA contain a confirmed threat? A: Our target is to contain confirmed threats within minutes of validation. Containment includes isolating endpoints, disabling compromised accounts, blocking malicious IPs, and terminating suspicious processes. Analysts work to pre-authorised response playbooks for ransomware, credential theft, and data exfiltration, so we can act fast during an active attack without waiting on approvals. Q: How is MDR priced for small and medium businesses? A: MDR is priced per user per month on a fixed basis with no hidden charges for alert volume or incident response actions. That makes enterprise-grade security operations accessible to SMEs without the cost of a full security team. Pricing scales cleanly with headcount, so your security spend stays predictable as you grow. Q: What data sources does AMVIA's MDR monitor? A: Our MDR ingests telemetry from endpoints, Microsoft 365 email and identity logs, firewall and network traffic, cloud applications, and server infrastructure. This cross-environment visibility lets analysts correlate events across attack surfaces and detect multi-stage attacks that single-source monitoring misses. We integrate with your existing tools, so there is no need to replace your current stack. Q: Is AMVIA accredited to run MDR? A: AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status (Modern Work, Security, and Infrastructure). Our engineering and SOC team operates from Sheffield, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare, and professional services - so MDR is delivered by people who run this for a living. --- # Cyber Incident Response Service for UK Businesses URL: https://amvia.co.uk/cybersecurity/incident-response Last updated: 2026-03 Cyber incident response is the structured process of detecting, containing, investigating and recovering from a security breach. AMVIA's UK-based managed cybersecurity team mobilises within one hour, isolates the threat, preserves forensic evidence and restores your systems - one accountable provider handling the whole crisis, security-first. ## What does AMVIA's incident response service include? Our incident response service covers the full lifecycle of a breach: rapid containment, forensic investigation, system recovery and regulatory guidance. You get a single team that stops the attack, works out what happened, gets you running again and documents everything your insurer and the regulator will ask for. - 24/7 containment - critical incidents responded to within one hour, any time of day, by analysts in our Sheffield SOC. - Forensic investigation - root-cause analysis of how the breach occurred, what was affected and which data was exposed. - System recovery - structured restoration from clean backups and verified images, validated at each stage. - Regulatory guidance - ICO notification, Action Fraud reporting and communication with affected parties. - Post-incident hardening - additional controls to stop recurrence, plus a detailed written incident report. ## How does the incident response process work? The process runs through five defined stages, from your first call to a hardened environment. Each stage preserves evidence while limiting damage, so you recover faster and keep the documentation an insurer or the ICO will require. Nothing is improvised under pressure. | | Stage | What happens | Timing | 01 Alert & triage | We assess severity and mobilise the response team | Within 1 hour | 02 Containment | Affected systems isolated, evidence preserved | Immediate | 03 Investigation | Forensic analysis of attack vector, scope and data impact | Hours–days | 04 Recovery | Restoration from clean backups, verified at each step | Days | 05 Post-incident review | Full report, root cause, hardening recommendations | Post-recovery This sits alongside our managed detection and response and 24/7 security monitoring services, so detection and response are handled by the same team. ## Why do UK SMEs need a cyber incident response plan? Because attacks are now routine, not rare. 43% of UK businesses experienced a cyber breach or attack in the past year (DSIT Cyber Security Breaches Survey 2025). An incident response plan defines roles, communication and technical steps before the crisis, so your team acts decisively instead of improvising while data leaves the building. The financial stakes are severe. The global median ransom demand was about $1.32 million (~£1.04m) in 2025, down 34% year on year (Sophos). Organisations with a tested plan consistently recover faster, and at lower cost, than those responding ad hoc. Our penetration testing service helps you find the gaps before an attacker does. ## What are your legal obligations after a data breach? Under UK GDPR you must notify the Information Commissioner's Office within 72 hours if a breach poses a risk to individuals' rights and freedoms, and affected individuals must be told if the risk is high. AMVIA manages breach assessment, ICO notification drafting and communication with affected parties, and advises on Action Fraud reporting - so you meet every deadline while still containing the attack. The National Cyber Security Centre recommends a tested response plan as a baseline control for every organisation, not just large enterprises. ## In-house vs managed incident response Most UK SMEs cannot staff a 24/7 forensic capability in-house. A managed retainer gives you that capability on demand, with a team that already knows your environment. | | Capability | In-house only | AMVIA managed IR | 24/7 availability | Rare for SMEs | Yes - Sheffield SOC | Forensic tooling & evidence handling | Costly to build | Included | ICO / Action Fraud guidance | Usually external | Included | Pre-built response playbook | Often missing | Built on onboarding | Time to mobilise | Hours–days | Within 1 hour ## How much does incident response cost? Pricing depends on whether you engage ad hoc or on a retainer. Retainer agreements typically run from £350 to £750 per month (typical UK 2026 range for an SME IR retainer) and guarantee priority response with defined SLAs, a pre-built playbook, regular plan reviews and tabletop exercises. Pre-engagement significantly cuts the time between detection and effective containment. ## Why choose AMVIA for incident response? AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status, and our engineering and support team operates from Sheffield. We manage IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. One provider, security-first, Microsoft-certified - so when an incident hits, you call one number, not five. ## Frequently asked questions Q: What is cyber incident response? A: The structured process of detecting, containing, investigating and recovering from a security breach: stop the spread, establish what happened, restore safely, and capture the evidence - including what regulators and insurers will ask for afterwards. Q: How quickly does AMVIA respond to an incident? A: Mobilisation within one hour. Speed is the whole economics of incident response: containment in the first hours is the difference between an isolated device and an estate-wide event. Q: Do we have to report a breach to the ICO? A: If personal data is involved and the breach risks people's rights, UK GDPR requires notification to the ICO within 72 hours of becoming aware. A pre-agreed incident response arrangement means that clock starts with professionals already engaged rather than with a scramble to find help. Q: Should we have an incident response plan before anything happens? A: Emphatically yes - response bought during a crisis costs more and starts slower. A pre-built playbook, tested regularly, with a provider that already knows your environment turns the worst day into a managed process. It's also increasingly a cyber-insurance expectation. --- # Phishing Simulation and Security Awareness Training URL: https://amvia.co.uk/cybersecurity/phishing-simulation-training Last updated: 2026-03 Phishing simulation training sends realistic fake phishing emails to your staff, measures who clicks, and assigns targeted security awareness training to the people who fail. AMVIA runs monthly campaigns, tracks click and reporting rates, and benchmarks your progress over time - one accountable provider, security-first, with Microsoft-certified engineers running it end to end. Your people are the control that attackers target first. Tooling like managed cybersecurity catches a lot, but a single click on a convincing email can still hand over credentials. Phishing simulation training turns that weak point into a measurable, improving defence layer - and it sits naturally alongside AMVIA's email security and phishing protection services. ## What is phishing simulation training? Phishing simulation training is a controlled programme that emails staff fake-but-realistic phishing messages, records who clicks or reports them, and delivers short awareness training to those who need it. It is repeated regularly so behaviour change is measured, not assumed. The goal is a lower click rate and a higher report rate every quarter. The UK's National Cyber Security Centre treats user awareness as a core part of defending against phishing, not an optional extra (NCSC phishing guidance). Simulations make that awareness measurable: you see exactly which teams, roles, or individuals are most exposed, and you can prove improvement to your board, your insurer, and your auditor. ## How does AMVIA run your phishing simulations? AMVIA runs simulations as a continuous, four-stage cycle rather than a one-off test. We baseline current behaviour, train the people who fail, repeat with fresh real-world templates, then report against benchmarks. Each campaign uses current attack patterns - spear phishing, CEO fraud, and credential harvesting - so the test reflects what your staff actually face. - 01 - Baseline campaign. We send a realistic simulated phish to your team to measure current click and reporting rates before any training. - 02 - Targeted training. Short awareness modules are assigned automatically to staff who clicked, focusing effort where the risk is highest. - 03 - Ongoing campaigns. Monthly simulations using current templates keep awareness live and stop results drifting back over time. - 04 - Reporting and improvement. Monthly reports track click rates, report rates, and training completion against industry benchmarks. This is the same managed model behind AMVIA's managed detection and response and 24/7 security monitoring: UK-based engineers configure, run, and report on it so your team doesn't have to. ## What's included in the service? Every AMVIA phishing simulation programme includes campaign delivery, automated training assignment, new-starter onboarding, and monthly reporting. You get a named account team and audit-ready records of who completed what and when. Training content is refreshed quarterly to track the threats currently hitting UK organisations. - Realistic, current templates - spear phishing, business email compromise, credential harvesting, and removable-media lures. - Micro-learning modules - five-to-ten-minute sessions with interactive examples and short quizzes. - Automatic new-starter enrolment - joiners get a baseline module in week one, so they aren't a gap in your defences. - Board-ready reporting - click rate, report rate, and completion tracked over time with industry benchmarks. - Audit-ready evidence - central records that support UK GDPR and ISO 27001 awareness requirements. ## Why do UK SMEs need phishing simulation training? Because phishing is the most common way UK businesses get breached, and staff are the entry point. The 2025 Cyber Security Breaches Survey found phishing was the single most prevalent attack type reported by UK businesses, identified in around 85% of breaches (gov.uk, DSIT 2025). Training the people attackers target is the highest-leverage control most SMEs can add. - 43% of UK businesses experienced a cyber breach in the past year (gov.uk, DSIT 2025). - 85% of breaches involved phishing (DSIT 2025) - making it the top reported attack vector (gov.uk). - Businesses that run regular simulations typically cut staff click rates by 60–70% within six months - a consistently reported effect of sustained simulation programmes (typical UK 2026 range). - £3,550 average cost of a disruptive breach for UK businesses A lower click rate is not a vanity metric. It directly reduces the chance of the credential theft that precedes most ransomware and business email compromise incidents. ## In-house awareness vs AMVIA managed phishing simulation Many SMEs try to run awareness internally with an annual slide deck. That ticks a box but rarely changes behaviour. A managed, measured programme is the difference between hoping staff are careful and proving they are. | | Factor | DIY annual training | AMVIA managed simulation | Frequency | Once a year, often skipped | Monthly campaigns, year-round | Targeting | Everyone, same content | Training assigned to those who fail | Templates | Static, dated | Current real-world attack patterns | Measurement | Attendance only | Click rate, report rate, completion trend | New starters | Manual, easily missed | Auto-enrolled in week one | Reporting | None | Monthly, board- and audit-ready | Who runs it | Your already-stretched IT | AMVIA's UK engineers ## How much does phishing simulation training cost? AMVIA delivers phishing simulation training on fixed monthly pricing as part of a managed security package, with no hidden fees. Exact cost depends on user count and whether it's bundled with wider services like email security and endpoint protection. For how security packages are priced overall, see our managed cybersecurity cost guide. Pricing scales per user, so a 25-seat firm and a 250-seat firm are quoted differently. We'll size it to your headcount and the controls you already run - including any Microsoft Defender for Business licensing you hold. ## Why choose AMVIA for phishing simulation training? AMVIA is a security-first managed partner, not a telecoms reseller bolting on awareness training. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, our engineering and support team operates from Sheffield, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare, and professional services. - Cyber Essentials Plus certified and a Microsoft Solutions Partner - UK-recognised security credentials. - 1,200+ UK businesses protected across regulated sectors. - Sheffield-based UK team that understands UK compliance and infrastructure. - Sub-one-hour critical-issue response, by phone, email, and portal, with named account managers. > "Client testimonial coming soon - AMVIA protects over 1,200 UK businesses." - AMVIA Client ## Frequently asked questions Q: What topics does the security awareness training cover? A: The programme covers phishing recognition, password hygiene, business email compromise, safe web browsing, removable-media risks, social engineering tactics, and data handling. Content is refreshed quarterly to reflect current threats targeting UK organisations. Because phishing is the most commonly reported breach vector for UK businesses (DSIT 2025), phishing awareness forms the core of the curriculum. Q: Does the training help with compliance requirements? A: Yes. The programme supports staff-awareness requirements under UK GDPR, ISO 27001, and sector-specific regulations, and completion is tracked centrally with audit-ready reports showing who completed which modules and when. Staff awareness is a recognised component of demonstrating due diligence and reducing the likelihood of successful social engineering. It complements, rather than replaces, your technical controls. Q: How do you measure whether the training is actually working? A: We measure click rates on phishing simulations before and after training, module completion rates, quiz scores, and how often staff report suspicious emails to IT. These are tracked over time to show measurable improvement. Organisations that combine regular simulations with targeted training typically see meaningful reductions in click rates within the first three to six months. Q: How are new starters onboarded into the programme? A: New employees are automatically enrolled in a baseline awareness module in their first week, covering phishing recognition, password security, and your reporting procedures. They then join the monthly simulation campaigns and ongoing schedule. This closes the gap that new joiners otherwise represent during onboarding, when they are least familiar with internal norms and most exposed to social engineering. Q: How long do the training modules take? A: Each module is a micro-learning session of five to ten minutes, so staff can complete it without significant disruption. Modules use interactive content, real-world examples, and short quizzes to reinforce key points. Short, frequent sessions change behaviour more reliably than a single long annual course, and they keep awareness current as attack techniques evolve. Q: Is phishing simulation training enough on its own? A: No - it is one layer. Simulations and training reduce the chance of a click, but they work best alongside technical controls like email filtering, multi-factor authentication, and endpoint detection. AMVIA combines awareness with Microsoft Defender for Business and managed monitoring so a missed click still meets technical defences. Layered controls are the NCSC's recommended approach. --- # Vulnerability Management and Scanning for SMEs URL: https://amvia.co.uk/cybersecurity/vulnerability-management Last updated: 2026-03 Vulnerability management is the continuous process of finding, risk-rating and fixing security weaknesses across your servers, endpoints and cloud before attackers exploit them. AMVIA runs weekly authenticated scans, hands you a prioritised remediation plan, and patches the critical issues for you - one accountable, security-first provider with Microsoft-certified engineers. It is the discipline that turns a one-off scan into an ongoing programme. Most breaches do not exploit clever zero-days; they exploit known weaknesses that nobody got round to patching. Managed vulnerability management closes that gap. It is a core part of our wider managed cybersecurity service, alongside penetration testing and 24/7 security monitoring. ## How does managed vulnerability management work? It works as a repeating cycle: discover everything you own, scan it for known weaknesses, rank the findings by real-world risk, fix what matters first, then scan again to prove the risk is going down. AMVIA runs that cycle for you so nothing slips between IT tickets. 1. Asset discovery - we identify every internet-facing and internal asset (servers, endpoints, cloud resources) so the scan scope reflects your real estate, not a guess. 2. Initial scan - a comprehensive scan surfaces weaknesses, misconfigurations and missing patches across the estate. 3. Prioritised remediation - findings are risk-rated and delivered as an action plan: critical issues first, with clear, step-by-step fixes. 4. Continuous scanning - scheduled weekly or monthly scans run with trend reporting, so you can see your security posture improving over time. ## What's included in AMVIA's vulnerability management service? You get the scanning technology, the people who run it, and the reporting that proves it works - managed end to end by UK-based engineers. The point is that you are not handed a 200-page scanner export and left to triage it yourself; we do the triage and the fixing. - Proactive protection - continuous monitoring and threat detection to catch weaknesses before they are exploited. - Expert management - UK-based engineers handle configuration, scanning, and remediation, so your team doesn't have to. - Regular reporting - monthly reports on security posture, issues handled, and recommended improvements. - Dedicated support - direct access to your account team for questions, changes, and escalations. ## Why do UK SMEs need vulnerability management? Because the weaknesses attackers use are almost always already known and already fixable. In 2025, 43% of UK businesses experienced a cyber breach, and 85% of those breaches involved phishing that frequently lands on unpatched, exposed systems. A single missed patch on an internet-facing server is all it takes - and exploitation of vulnerabilities is now the most common way breaches start, overtaking stolen credentials for the first time at 31% (Verizon DBIR 2026). The cost is not theoretical. The average cost of a disruptive breach for UK businesses is around £3,550 - and much ransomware still enters through unpatched software. Continuous scanning shrinks the window of exposure between a CVE being published and it being fixed on your estate. It also produces the audit-ready evidence you need for UK GDPR cybersecurity obligations and Cyber Essentials. Sources: DSIT Cyber Security Breaches Survey 2025; NCSC vulnerability management guidance. ## Vulnerability scanning vs penetration testing - what's the difference? They are complementary, not interchangeable. Scanning is automated and recurring; it tells you which known weaknesses exist across the whole estate, every week. Penetration testing is a manual, point-in-time exercise where a skilled tester tries to exploit and chain those weaknesses to prove real-world impact. | | | Vulnerability scanning | Penetration testing | Frequency | Continuous / weekly | Point-in-time (annual or per-change) | Method | Automated tooling | Manual, human-led | Coverage | Whole estate, broad | Targeted, deep | Answers | "What known weaknesses exist?" | "Can an attacker actually break in?" | Best for | Ongoing risk reduction | Validation and compliance evidence Most UK SMEs need both: continuous scanning to keep risk low day to day, and an annual penetration test to validate defences. If scanning ever surfaces an active compromise, our incident response team steps in. ## What are AMVIA's patch and remediation SLAs? We commit to defined timelines so critical risk doesn't sit open. Standard SLAs target remediation of critical vulnerabilities within 14 days and high-severity findings within 30 days. For actively exploited zero-day vulnerabilities, emergency patches or mitigations are applied within 48 hours. - Critical issue response: under one hour. - Monitoring and support: 24/7. - Reporting: monthly posture and remediation reporting, audit-ready. ## How much does managed vulnerability management cost? Pricing depends on the size of your estate - the number of internal and external assets, endpoints and cloud workloads in scope. Because cost scales with asset count and scan frequency, the honest answer is that it is quoted per environment after a short scoping call. The fastest way to a real number is a free security audit, which also doubles as your first scan. ## Why choose AMVIA for vulnerability management? - Sheffield-based, UK-focused - our engineering and support team operates from Sheffield and understands UK compliance, infrastructure and the realities facing British businesses. - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status. - 1,200+ UK businesses protected - we manage IT and security for over 1,200 UK businesses across legal, finance, healthcare and professional services. - Fast, responsive support - critical issues responded to within one hour, with helpdesk by phone, email and portal, plus dedicated account managers. ## Frequently asked questions Q: What is vulnerability management? A: The continuous process of finding, risk-rating and fixing security weaknesses across your servers, endpoints and cloud before attackers exploit them. It's the discipline behind patching: scanning on a schedule, prioritising by real risk, and proving remediation happened. Q: How quickly are vulnerabilities fixed? A: AMVIA works to defined remediation SLAs: critical vulnerabilities within 14 days, high-severity within 30 days, and emergency response within 48 hours for actively exploited zero-days. Defined timelines are the difference between a managed programme and a to-do list. Q: Isn't Windows Update enough? A: No - operating system patches are one slice. Third-party applications, firmware, network devices and cloud misconfigurations all carry vulnerabilities that Windows Update never touches, and unsupported software fails compliance schemes like Cyber Essentials outright. Managed vulnerability management covers the whole estate. Q: How does vulnerability management relate to Cyber Essentials? A: Directly - security update management is one of the five controls Cyber Essentials verifies, and it's the control businesses most commonly fail. A managed programme with defined SLAs turns certification's patching requirement into routine operations rather than an annual scramble. --- # External Attack Surface Management (EASM) | SurfaceLoop by AMVIA URL: https://amvia.co.uk/cybersecurity/attack-surface-management Last updated: 2026-08 External Attack Surface Management (EASM) continuously discovers and monitors everything your business exposes to the internet - domains, subdomains, IPs, certificates, exposed services and email authentication records - so unknown and forgotten assets stop being the way in. AMVIA delivers EASM through SurfaceLoop, our attack surface monitoring capability, which is included with Cyber Essentials Plus and managed IT plans rather than sold as a standalone product. A free one-off scan of your domain is available in our tools section. ## Why external attack surface management matters now Every business accumulates internet-facing assets faster than it retires them: marketing microsites, trial subdomains, cloud services spun up for one project, mail records nobody has reviewed since setup. Attackers enumerate all of it systematically - 43% of UK businesses experienced a breach or attack in the past 12 months, and 85% of breaches involved phishing (DSIT, Cyber Security Breaches Survey 2025), an attack that starts with what's visible and spoofable from outside. EASM turns that outside view into your own operational picture. ## The visibility layer in a security-first stack EASM is deliberately one layer, and it works best wired into the rest: vulnerability management assesses the estate SurfaceLoop discovers, penetration testing proves what's actually exploitable, and AMVIA's managed cybersecurity services act on the findings day to day. SurfaceLoop itself is honest about its boundary - it's discovery, monitoring and reporting, not a managed SOC - which is exactly why we run it inside services with engineers attached rather than selling it as a dashboard. ## Where you'll meet SurfaceLoop Three places. Cyber Essentials Plus: continuous external monitoring is included with the £400/month Plus service, because new subdomains, expiring certificates and exposed services are precisely the drift that fails renewal audits - catching them continuously is what keeps a certified estate genuinely audit-ready. Managed IT and security plans: engagements where continuous visibility is part of the service design run SurfaceLoop as standard, with findings routed straight to the engineers responsible for fixing them. The free scan: our attack surface scan gives any UK business a one-off view of its own domain - instant SPF, DKIM and DMARC checks, plus a fuller exposure report for verified domains. It's the same discipline at a single point in time; the services make it continuous. Existing SurfaceLoop subscribers: the SurfaceLoop subscription agreement continues to apply to your service unchanged. ## Frequently asked questions Q: What is external attack surface management? A: EASM is the continuous discovery and monitoring of everything your organisation exposes to the internet - domains, subdomains, IP addresses, services, certificates and email authentication records. It answers the question every attacker asks first: what can I see and reach from outside? Unknown and forgotten assets are a common way in, and EASM makes them visible before someone else finds them. Q: How is EASM different from vulnerability scanning or a pen test? A: Vulnerability scanning assesses assets you already know about; a penetration test is a point-in-time exercise against an agreed scope. EASM works the other way around - it discovers what's exposed (including assets you didn't know you had) and monitors continuously between tests. The three are complementary: EASM finds the estate, vulnerability management assesses it, and pen testing proves what's exploitable. Q: What is SurfaceLoop? A: SurfaceLoop is AMVIA's attack surface monitoring capability: asset discovery from your seed domains, continuous monitoring of domains, IPs, certificates and email authentication records, CVE-matched prioritisation, and audit-ready evidence export. It powers the continuous monitoring inside our Cyber Essentials Plus and managed IT services, and the free attack surface scan in our tools section. Q: Can I buy SurfaceLoop on its own? A: No - and that's deliberate. A monitoring feed without engineers attached is a to-do list, so we include SurfaceLoop inside services where AMVIA acts on what it finds: Cyber Essentials Plus (£400+VAT/month) and our managed IT and security plans. If you just want to see what's exposed today, the free attack surface scan gives you a one-off view of your own domain. Q: Does SurfaceLoop include incident response or a managed SOC? A: No - SurfaceLoop is the visibility layer: discovery, monitoring and reporting, not a managed SOC or incident response service. That's deliberate and honest. Where findings need acting on, AMVIA's wider managed security services - including vulnerability management and penetration testing - pick up from what SurfaceLoop surfaces. Q: Which AMVIA services include SurfaceLoop monitoring? A: Cyber Essentials Plus includes continuous external monitoring as standard, because external drift is what fails renewal audits. It also runs inside our managed IT and managed security engagements where continuous visibility is part of the service design. Ask on any service call whether your plan includes it - the answer is on the table before you sign. --- # Cyber Essentials Certification for UK Businesses | £250/Month All-In URL: https://amvia.co.uk/cybersecurity/cyber-essentials Last updated: 2026-09-01 AMVIA's Cyber Essentials certification service costs £250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, hands-on remediation of the five technical controls, questionnaire submission with official IASME assessment fees included, and annual re-certification. Initial certification typically takes 30–45 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor; Cyber Essentials Plus - the independently audited tier - is £400 + VAT per month. ## What is Cyber Essentials? Cyber Essentials is the UK government-backed certification, designed by the National Cyber Security Centre and operated through IASME, that proves your organisation has five fundamental technical controls in place: firewalls, secure configuration, user access control, malware protection and security update management. None of it is exotic - the scheme certifies disciplined execution of the basics, and the basics stop most of the commodity attacks UK SMEs actually face. With 43% of UK businesses reporting a breach or attack in the past 12 months (DSIT, Cyber Security Breaches Survey 2025), the baseline matters. ## Who needs it Three groups, in practice. Suppliers to government: certain UK central government and MoD contracts require Cyber Essentials outright, and prime contractors increasingly flow the requirement down their supply chains - for many SMEs the certificate is the difference between bidding and not bidding. The insured: UK cyber insurers increasingly ask CE-aligned questions at proposal and renewal, and basic certification through IASME includes cyber liability insurance for eligible organisations under £20 million turnover. Anyone being vetted: supplier security questionnaires now routinely ask for the certificate - you can check any company's status on the official register with our certificate checker, which is exactly what your customers do to you. ## The Cyber Essentials requirements: the five controls in practice Certification assesses five technical control areas, defined by the NCSC and assessed by IASME. The requirement is not owning tools - it is being able to answer, honestly and specifically, how each control is applied across everything in scope: - Firewalls and internet gateways - every in-scope device sits behind a correctly configured firewall; default passwords changed; no unapproved inbound services. - Secure configuration - unused accounts and software removed, default credentials gone, auto-run disabled, device locking enforced. - Access control - accounts are per-person and least-privilege; admin rights separated from daily-driver accounts; MFA where the standard requires it. - Malware protection - anti-malware (or app allow-listing/sandboxing) active and updating on every in-scope device. - Security update management - supported software only, with high and critical patches applied within 14 days of release. The self-assessment questionnaire walks the whole estate through those five areas - including home workers’ devices and cloud services, which is where most first attempts stumble. Our checklist work is exactly this: finding the answers that would fail before the assessor does. ## Cyber Essentials for government contracts If you bid for central government or MOD work, Cyber Essentials stops being optional: UK government procurement policy requires suppliers on contracts involving personal information or certain ICT services to hold certification, and many framework and defence tenders will not shortlist without it. Two practical points from running these deadlines: standard-scope certification typically runs 30–45 days end to end, so start before the tender clock forces you to - and check whether the contract specifies Cyber Essentials Plus, which adds an independent technical audit and a longer runway. ## Supply chains ask for it too The fastest-growing driver we see is not government - it is customers. Larger organisations increasingly push security requirements down their supply chain, and only 15% of UK businesses formally review the cyber risks posed by their immediate suppliers (DSIT Cyber Security Breaches Survey 2025/26) - so the ones that do tend to use certification as the filter. A current certificate on the IASME register answers the security section of most vendor questionnaires in one line, which is often worth more in won business than the certificate costs. ## What we do vs what you do | | Task | AMVIA | You | Gap analysis against the current question set | ✔ We run it | Give us access and an hour of walkthrough | Remediation - MFA, access control, patching, firewalls, software audit | ✔ Our engineers do the work | Approve changes; nominate a contact | Questionnaire completion and submission | ✔ Completed with you, submitted by us | Sign off the declarations (they're yours to make) | Official assessment fees | ✔ Included in the monthly price | Nothing extra | Keeping controls in shape between renewals | ✔ Monthly checks, drift fixed | Tell us when things change - new starters, new software, new sites | Annual re-certification | ✔ Included and scheduled | An hour, once a year ## DIY vs consultant vs AMVIA | | | DIY self-assessment | Generic consultant | AMVIA managed service | Upfront cost | Official fee only (£320–£600+VAT by size) | Typically £1,000–£5,000+ project fee plus official fees | £250+VAT/month, everything included | Who fixes the gaps | You | Usually you, from their gap report | We do | Failure risk | High if the estate has drift - most first-time DIY attempts find gaps mid-questionnaire | Lower, but remediation quality varies | Low - we don't submit until the controls genuinely pass | Year two | Start again | Another project fee | Included - the controls never lapsed The honest caveat on DIY: if you run a small, modern, well-disciplined Microsoft 365 estate with no legacy kit, self-assessment is genuinely achievable - our free readiness assessment will tell you in ten minutes whether you're close. Most businesses discover the gaps are real, and the gap between knowing and fixing is where the service earns its fee. ## Pricing, in full £250 + VAT per month covers standard scope - up to 49 employees - with the official IASME assessment fees (£320–£600+VAT by organisation size, verified August 2026) included rather than billed on top. Larger or multi-site organisations are tiered from the same floor and quoted before you commit; the full cost guide breaks down every component, including what DIY really costs once remediation is counted. Need the audited tier? Cyber Essentials Plus is £400 + VAT per month - enterprise customers, insurers and government buyers increasingly ask for it by name. ## Why a monthly service and not a project Because the certificate expires every 12 months and the controls drift the day after the assessor leaves. A one-off certification project leaves you owning that drift - new starters without MFA, patches slipping past the 14-day window, a firewall rule added in a hurry - and turns every renewal into a fresh scramble. The monthly service keeps the five controls continuously in the state the assessment expects, which is also exactly the posture your insurer and your supply chain think the certificate means. If certification matters enough to buy once, it matters enough to keep. ## Frequently asked questions Q: How much does Cyber Essentials certification cost with AMVIA? A: £250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, remediation done by our engineers, questionnaire submission with the official IASME assessment fees included, and annual re-certification. Larger organisations are tiered from the same floor and quoted before commitment. Q: How long does Cyber Essentials certification take? A: Typically 30–45 days from signup to certificate for standard scope: about a week of gap analysis, two to four weeks of remediation depending on what we find, then submission. A clean, modern estate can be faster; heavy legacy software is the usual thing that extends it - and we tell you at gap-analysis stage, not at week six. Q: What are the five Cyber Essentials controls? A: Firewalls (every device behind a correctly configured boundary or software firewall), secure configuration (default passwords changed, unused software and accounts removed), user access control (least privilege, restricted admin rights, MFA on cloud services), malware protection (anti-malware or allow-listing on every in-scope device), and security update management (supported software only, high and critical patches within 14 days). Q: Is Cyber Essentials a legal requirement? A: No - it's voluntary certification. But it's contractually required for certain UK government and MoD work, increasingly demanded down supply chains by prime contractors, and asked about by cyber insurers at proposal and renewal. For many businesses the commercial pressure makes it effectively mandatory even though no law does. Q: What's the difference between Cyber Essentials and Cyber Essentials Plus? A: Both certify the same five controls. CE is a verified self-assessment - you answer the questionnaire, a qualified assessor reviews it. CE Plus adds an independent technical audit with tests run against your actual systems, which carries more weight with enterprise buyers, insurers and government. With AMVIA, CE is £250+VAT/month and Plus is £400+VAT/month. Q: Who actually certifies us - AMVIA or IASME? A: Certification is issued through the official IASME scheme. AMVIA delivers the service - gap analysis, remediation, submission, renewals - in partnership with an IASME-accredited certification body, so the certificate you receive is the standard, register-verifiable Cyber Essentials certificate. You can confirm any certificate, including ours, with our free certificate checker. Q: What if we fail the assessment? A: Our model makes that unlikely by design: we don't submit until the gap analysis says the controls genuinely pass, because we did the remediation ourselves. If an assessment does surface something, fixing it and resubmitting is part of the service - not a new invoice. Q: Do the official IASME fees cost extra? A: No - the official assessment fees (£320+VAT for micro organisations, £440+VAT for small, rising to £600+VAT for large enterprises; verified August 2026) are included in the monthly price. There is nothing to pay on top for standard scope. Q: What does 'standard scope' mean? A: Up to 49 employees with a typical single-organisation estate - the shape most UK SMEs are. More employees, multiple legal entities or unusually complex estates are tiered from the same £250/£400 floors, with the exact price confirmed on a 15-minute call before you commit to anything. Q: Does Cyber Essentials include insurance? A: Basic Cyber Essentials certification through IASME includes cyber liability insurance (£25,000 indemnity) for eligible UK organisations with under £20 million turnover, at no extra cost. It's a useful baseline - not a substitute for a standalone cyber policy sized to your actual risk. Q: We use Microsoft 365 - does that make certification easier? A: Considerably, if it's configured properly: MFA enforcement, access control and patching are all natively manageable. Misconfigured tenants are also one of the most common gap sources - our free Microsoft 365 security baseline check shows where yours stands, and tenant hardening is part of our remediation work. Q: Do home workers count in the scope? A: Yes - devices used for business, wherever they are, are in scope, including home-worker laptops and BYOD phones accessing company data. This is one of the most commonly misunderstood scope areas and a routine gap-analysis finding; our remediation covers bringing remote devices under control. Q: What happens after we're certified? A: The service keeps running: monthly control checks, drift fixed as it appears (new starters, new software, expiring configurations), and the annual re-certification handled on schedule. That continuity is the point of the monthly model - the certificate never lapses and renewal never becomes a project. Q: Can you certify us if another IT company runs our systems? A: Yes - co-managed certification is common. We coordinate the remediation with your incumbent IT provider, or handle just the certification layer while they run day-to-day support. The responsibility split is agreed at gap-analysis stage so nobody's stepping on anyone. Q: Do you offer Cyber Essentials without the remediation? A: We don't sell certification-only, because submitting an estate we haven't verified would put our name on something we can't stand behind. If you genuinely just need the assessment, the DIY route through IASME costs £320–£600+VAT - and our free readiness assessment will tell you honestly whether you're ready for it. Q: How do I check if a company has Cyber Essentials? A: Search the official register operated by IASME on behalf of the NCSC - free, no account needed. Our certificate checker takes you straight there with the company name ready to search. Certificates expire after 12 months, so a supplier who 'has Cyber Essentials' from two years ago is not currently certified. Q: Will Cyber Essentials stop us being hacked? A: It materially reduces the risk from commodity attacks - the automated, untargeted kind that make up most of what UK SMEs face - because the five controls close the doors those attacks use. It is not a complete security programme: it doesn't cover detection, response or user training, which is where managed detection and response picks up. Q: When should we go straight to Cyber Essentials Plus? A: When a contract, insurer or customer names it specifically; when you handle data sensitive enough that self-assessment won't satisfy your stakeholders; or when you want the independent audit as genuine assurance rather than paperwork. The controls are identical - Plus proves them harder. If in doubt, start the conversation at CE and upgrade; the work transfers. Q: Is Cyber Essentials required for government contracts? A: For many, yes - UK government procurement policy requires suppliers to hold Cyber Essentials for central government contracts involving personal information or certain ICT services, and MOD contracts routinely require it (often Plus). Check the tender documents for which level, and start early: standard-scope certification typically runs 30–45 days end to end. Q: What is on the Cyber Essentials checklist? A: The five control areas: firewalls and internet gateways, secure configuration, access control, malware protection, and security update management (supported software patched within 14 days for high/critical updates) - applied across every in-scope device, including home workers and cloud services. The assessment is a self-assessment questionnaire verified by an IASME assessor; Plus adds an independent technical audit of the same controls. --- # Cyber Essentials Plus Certification | £400/Month All-In URL: https://amvia.co.uk/cybersecurity/cyber-essentials-plus Last updated: 2026-08 AMVIA's Cyber Essentials Plus service costs £400 + VAT per month, all-in for standard scope (up to 49 employees): the full Cyber Essentials service - gap analysis, hands-on remediation, submission with official fees included, annual re-certification - plus preparation for the independent technical audit, evidence collection, and continuous external attack surface monitoring. Initial certification typically takes 45–60 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor. ## What Cyber Essentials Plus is Cyber Essentials Plus certifies exactly the same five technical controls as basic Cyber Essentials - firewalls, secure configuration, user access control, malware protection and security update management. The difference is proof. Basic CE is a verified self-assessment: you declare, a qualified assessor reviews. Plus adds an independent technical audit in which an assessor tests your actual systems - sampling devices, checking patch levels, attempting to deliver test malware by email and browser, and verifying that MFA and access controls really behave the way the questionnaire claims. Same standard, harder evidence. Our CE vs CE Plus comparison covers the decision in depth. ## What the technical audit involves The assessor works from the official CE Plus test specification against a representative sample of your in-scope estate. In practice that means: patch verification - sampled devices scanned to confirm no high or critical vulnerabilities older than 14 days; malware protection tests - benign test files delivered by email and download to confirm your defences catch or block them; browser and email client checks - confirming executable content from the internet can't run without protection; account and MFA verification - admin separation and multi-factor authentication demonstrated, not just declared; and a device and mobile sample covering the estate shape you declared, home workers included. Basic CE must also be certified within three months before the Plus audit completes - which is why our delivery sequences the self-assessment first, then runs the audit on systems already proven against it. ## Who Plus is for Supply chains and enterprise buyers: where basic CE gets you past the questionnaire, Plus is increasingly what larger customers, prime contractors and certain government and MoD frameworks name specifically - the audit is what they're buying. The insured: UK cyber insurers don't generally mandate the badge, but their proposal forms ask for precisely the controls Plus independently verifies, and the NCSC reports that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than those without. Our guide to cyber insurance requirements maps the overlap in detail. Anyone whose word isn't enough: if your customers handle sensitive data, a self-declaration carries limited weight - an independent audit changes the conversation. ## What's included, in full £400 + VAT per month for standard scope (up to 49 employees) covers the complete basic CE service - gap analysis, remediation done by our engineers, submission with official IASME fees included, annual re-certification - plus everything the audit adds: preparation of every in-scope device and account, evidence collection, assessor coordination with us in the room, and remediation of anything the audit surfaces, at no extra charge. It also includes continuous external attack surface monitoring: SurfaceLoop, our attack surface monitoring capability, continuously discovers and watches your internet-facing assets - domains, subdomains, certificates, exposed services - so the drift that fails audits gets caught when it appears, not when the assessor does. Larger and multi-site organisations are tiered from the same floor and quoted on a 15-minute call before any commitment. ## CE or Plus - the honest answer If no contract, insurer or customer has named Plus, basic Cyber Essentials at £250 + VAT/month is the right starting point for most SMEs - the controls are identical, and upgrading later transfers all the work. Choose Plus from the start when a requirement already names it, when you're bidding into supply chains that demand audited evidence, or when self-assessment simply won't satisfy the people you need to convince. If you're unsure which side you're on, the 15-minute call is genuinely about fit - the pricing is already on this page either way. ## Frequently asked questions Q: How much does Cyber Essentials Plus cost with AMVIA? A: £400 + VAT per month, all-in for standard scope (up to 49 employees): the full basic CE service, audit preparation, evidence collection, the independent technical audit through our IASME-accredited certification body partner, official fees, continuous external monitoring, and annual re-certification. Larger organisations are tiered from the same floor and quoted before commitment. Q: How long does Cyber Essentials Plus take? A: Typically 45–60 days from signup for standard scope: gap analysis in week one, remediation over weeks two to five, then the basic CE self-assessment followed by the technical audit. The scheme requires basic CE to be certified within three months of the Plus audit completing, so the sequence is fixed - and we run it so the audit lands on systems already proven. Q: What does the CE Plus audit actually test? A: An independent assessor samples your real systems: vulnerability scans to verify patching, test malware delivered by email and download to verify protection, browser and email client configuration checks, MFA and admin-separation verification, and a device sample representative of your declared estate - home workers included. It tests what the questionnaire declared; our preparation makes sure the two match. Q: What's the difference between Cyber Essentials and Cyber Essentials Plus? A: Identical controls, different proof. Basic CE is a verified self-assessment; Plus adds an independent technical audit of your actual systems. Plus carries more weight with enterprise buyers, government frameworks and insurers because someone independent has tested the controls rather than reviewed a declaration. With AMVIA, CE is £250+VAT/month and Plus is £400+VAT/month. Q: Do we need basic Cyber Essentials first? A: Yes - the scheme requires a valid basic CE certificate, achieved within three months before Plus certification. It's built into our delivery: the self-assessment is completed and certified first, then the audit runs. Both are included in the £400/month; you don't buy them separately. Q: What happens if we fail the audit? A: Failing is rare on our watch because we don't book the assessor until our own checks pass - we've remediated and evidenced every in-scope system first. If the audit does surface something, fixing and re-testing is part of the service, not a new invoice. Q: What is SurfaceLoop and why is it included? A: SurfaceLoop is AMVIA's external attack surface monitoring capability - it continuously discovers and monitors your internet-facing assets: domains, subdomains, certificates, exposed services and forgotten infrastructure. It's included with Plus because external drift is exactly what fails renewal audits; catching it continuously keeps you genuinely audit-ready between annual assessments. It's a capability inside our services, not a product we sell separately. Q: Does Cyber Essentials Plus help with cyber insurance? A: Materially, though not usually as a formal mandate. UK insurers' proposal forms ask for the controls Plus verifies - MFA, patching, malware protection, secure configuration - and the NCSC reports organisations with CE controls are 92% less likely to make a claim. An independently audited certificate is stronger underwriting evidence than a self-declaration; some brokers and certification bodies also report premium benefits, though no major UK insurer publishes a fixed discount. Q: Which contracts require Cyber Essentials Plus specifically? A: Certain MoD and central government contracts name Plus, particularly where sensitive data or higher-risk services are involved, and prime contractors increasingly flow the Plus requirement down their supply chains. The pattern to watch: if a framework or customer security schedule says 'independently audited' or names Plus, basic CE won't satisfy it - check the wording before choosing your tier. Q: What does the assessor need from us on audit day? A: Very little, because we've done the preparation: access to the sampled devices and accounts, a point of contact, and a few hours of availability. We coordinate the assessor, sit in on the audit, and handle evidence requests as they come - the disruption to your team is deliberately close to zero. Q: Are home workers and BYOD in scope for the audit? A: Yes - the audit samples the estate you declared, and devices used for business are in scope wherever they sit, including home-worker laptops and BYOD accessing company data. Remote devices are one of the most common audit trip-ups, which is why bringing them under control is part of our remediation, not an exclusion. Q: Can we upgrade from basic Cyber Essentials to Plus later? A: Yes, cleanly - the controls are identical, so everything done for CE transfers. If your basic certificate is less than three months old, the audit can often run against it directly; otherwise the self-assessment is refreshed first. Existing AMVIA CE customers move to the Plus tier by stepping up from £250 to £400/month - no restart, no project fee. Q: Is the certificate we get the official one? A: Yes - the audit is conducted through our IASME-accredited certification body partner, and the certificate is the standard Cyber Essentials Plus certificate, verifiable on the official register operated by IASME on behalf of the NCSC. You can confirm it - or check any supplier's - with our free certificate checker. --- # Cyber Essentials vs Cyber Essentials Plus: Which Do You Need? URL: https://amvia.co.uk/cybersecurity/compare/cyber-essentials-vs-plus Last updated: 2026-07 Cyber Essentials and Cyber Essentials Plus verify the same five controls - the difference is proof. Basic is a verified self-assessment questionnaire (£320–£600+VAT by organisation size (official IASME fees, verified August 2026; insurance included for eligible orgs)); Plus adds an independent technical audit of your actual systems (typically from around £1,500+VAT, priced by the certification body). Choose Plus when enterprise customers, regulated supply chains or government contracts demand audited evidence - it's the tier AMVIA holds itself. ## Frequently asked questions Q: Do I need basic Cyber Essentials before Cyber Essentials Plus? A: Yes - Plus requires a current basic Cyber Essentials pass, with the technical audit completed within three months of it. In practice most businesses run the two together: pass the questionnaire, then schedule the audit immediately while the evidence is fresh. Q: What does the Cyber Essentials Plus audit actually test? A: An assessor tests a sample of your real devices and systems: vulnerability scans, malware protection checks, patch levels, and how workstations handle test payloads delivered by email and browser. It verifies the controls work in practice - not just that the questionnaire said so. Q: Which tier do government contracts require? A: It varies by contract. Cyber Essentials (either tier) is required for certain UK government contracts, and some - particularly those involving more sensitive data - specify Plus. Check the tender requirements; if you sell into the public sector repeatedly, Plus usually pays for itself in eligibility. Q: Do insurers treat the two tiers differently? A: Basic certification through IASME includes cyber liability insurance for eligible UK organisations under £20 million turnover - that benefit attaches at the basic tier. Beyond the bundled policy, insurers increasingly ask about certification at renewal, and audited evidence tends to be viewed more favourably than self-assessment. Q: Can we fail the Plus audit after passing basic? A: Yes - it happens when the questionnaire was answered optimistically. Common failure points: unsupported software still in use, missing MFA, and undeclared devices. A gap analysis before the audit day is far cheaper than a failed assessment and re-test. --- # How Much Does Cyber Essentials Cost? (2026 Fees) URL: https://amvia.co.uk/cybersecurity/cyber-essentials/cost Last updated: 2026-08 Basic Cyber Essentials certification costs £320+VAT for micro organisations (0–9 employees), £440+VAT for small (10–49), rising to £600+VAT for large enterprises - the official tiered IASME assessment fees (verified August 2026) that includes cyber liability insurance for eligible UK organisations under £20 million turnover. Cyber Essentials Plus adds an independent audit priced by the certification body, typically from around £1,500+VAT. The real first-year budget is usually dominated by remediation - retiring unsupported software, MFA rollout and access-control fixes - not the fee itself. AMVIA delivers certification as a monthly service - Cyber Essentials £250 + VAT/month, Cyber Essentials Plus £400 + VAT/month, all-in including remediation and annual re-certification. ## The fee is not the budget Every Cyber Essentials pricing conversation should start with this distinction: the certification fee is fixed and small; the remediation is variable and usually bigger. The IASME assessment fee for basic certification tiers by organisation size - from around £300+VAT for micro organisations (1–9 employees) up to around £500+VAT for large ones (2026 fees, set by IASME) - and includes cyber liability insurance for eligible UK organisations with under £20 million turnover. Cyber Essentials Plus adds an independent audit priced by the certification body performing it, typically from around £1,500+VAT. ## Where first-year budgets actually go For a typical SME, the spend that matters is closing the gap between current practice and the five controls: retiring end-of-support software (often the expensive one - licence upgrades or replacements), rolling out MFA properly, separating admin accounts, and getting patching onto a managed cadence. A business already running disciplined managed IT may spend nothing beyond the fee; one with years of drift can spend several times the fee putting the basics right. That's not a scheme problem - it's the scheme doing its job. ## How to spend less on this Two moves. First, gap-analyse before you apply - knowing exactly what will fail turns remediation into a planned project instead of an audit-day surprise, and at the Plus tier it avoids paying for a re-test. Second, make the controls somebody's day job: the five controls are precisely what a managed security service runs continuously - managed cybersecurity covers endpoint protection, patching and access control as operations, which makes annual recertification an evidence-gathering exercise rather than a scramble. AMVIA holds Cyber Essentials Plus ourselves; we prepare clients the same way we passed it. Start with what Cyber Essentials involves or talk to the team about a readiness assessment. ## What does AMVIA’s Cyber Essentials service cost? £250/month, all-in AMVIA sells Cyber Essentials as a monthly service rather than a one-off project, because certification isn’t a one-off: the certificate renews every 12 months, and the controls drift unless someone owns them. Cyber Essentials is £250 + VAT per month, all-in for standard scope: gap analysis, the remediation work itself, questionnaire submission (official assessment fees included), and annual re-certification - with initial certification typically inside 30–45 days. Cyber Essentials Plus is £400 + VAT per month, adding the independent technical audit with evidence collected by our attack-surface tooling - typically 45–60 days to initial certification. Larger or more complex organisations are tiered from those floors, quoted before you commit. The service is delivered in partnership with an IASME-accredited certification body. Why monthly beats a project quote, honestly: a one-off certification engagement leaves you owning the drift - twelve months later the renewal is a project again. The monthly service keeps the five controls continuously in the state the assessment expects, so year two’s certification is a formality instead of a scramble, and the evidence trail insurers and supply chains ask for stays current all year. It’s also why most of our certification customers broaden into managed detection and response, Microsoft 365 security management and vulnerability management - the controls are already being run; extending them is the natural next step. To size your own gaps before talking to anyone, the free readiness assessment shows which of the five themes need work. Whoever you certify with, verify the certificate afterwards: any supplier’s certification - including ours - can be checked against the official register with our Cyber Essentials certificate checker. ## Frequently asked questions Q: How much does basic Cyber Essentials cost in 2026? A: The IASME assessment fee tiers by organisation size: from around £300+VAT for micro organisations (1–9 employees), roughly £400–£450+VAT for small (10–49), and around £450–£500+VAT for medium and large organisations. The fee includes cyber liability insurance for eligible UK organisations under £20 million turnover. Q: How much does Cyber Essentials Plus cost? A: Plus pricing isn't fixed centrally - each certification body sets its own audit fee, typically from around £1,500+VAT depending on organisation size and estate complexity, on top of the basic certification you must hold first. Complex, multi-site estates cost more to audit. Q: Are there hidden costs in Cyber Essentials certification? A: Not hidden, but commonly unbudgeted: remediation. Retiring unsupported software, MFA rollout, access-control fixes and patching discipline are prerequisites for an honest pass, and for most SMEs this dwarfs the assessment fee. A gap analysis up front turns it into a known number. Q: Is Cyber Essentials worth the cost? A: For most UK SMEs, yes - on eligibility alone. It's required for certain government contracts and increasingly demanded in supplier questionnaires, so the certificate protects revenue, not just systems. The bundled insurance and the forced annual hygiene are the bonus. Q: Does the certification need renewing? A: Yes - annually, at both tiers. Budget the fee each year, and treat the controls as ongoing operations rather than an annual project: businesses running the five controls continuously find renewal routine, while those who certify-and-forget pay for remediation twice. Q: How much does AMVIA charge for Cyber Essentials certification? A: Cyber Essentials is £250 + VAT per month and Cyber Essentials Plus is £400 + VAT per month, all-in for standard scope: gap analysis, remediation, submission with official assessment fees included, and annual re-certification (Plus adds the independent technical audit). Initial certification typically takes 30–45 days for CE and 45–60 for Plus; larger organisations are tiered. Delivered in partnership with an IASME-accredited certification body. --- # Cyber Insurance Requirements UK: What Insurers Actually Ask For (2026) URL: https://amvia.co.uk/cybersecurity/cyber-insurance-requirements Last updated: 2026-08 UK cyber insurers rarely mandate Cyber Essentials by name - they require its controls: MFA, 14-day patching, firewalls, malware protection. What proposal forms ask, the £25k cover bundled with certification, and how to become insurable in ~30 days. ## Do UK insurers require Cyber Essentials? Almost never as a formal, named mandate - and any page telling you otherwise is overselling. What's verifiably true is subtler and more important: UK cyber insurers underwrite on controls, and the controls on their proposal forms map closely onto the five that Cyber Essentials certifies. Hiscox, for example, publishes eligibility criteria for its UK cyber policies built on specific technical controls rather than any certificate; US-and-UK insurtech Coalition publishes a near-identical control list. Answer those questions badly and you don't get a worse premium - you often don't get cover, or you get cover that fails at claim time because the declared controls weren't real. The direction of travel has been set for a decade. In November 2014, the Cabinet Office and the CEOs of major UK insurers signed a joint statement agreeing insurers should promote adoption of good practice, 'including Cyber Essentials'; the 2015 HM Government and Marsh report UK Cyber Security: The Role of Insurance - steering group including the ABI, Lloyd's, AIG, Allianz, Beazley and Hiscox - agreed CE would feature in SME risk assessment. A decade on, the government's own evaluation of the scheme (DSIT Cyber Essentials Impact Evaluation, July 2024) found certification affects insurance in two concrete ways: bundled cover included with certification, and some insurers offering better terms to certified organisations. ## The 92% number, and what it actually means The NCSC's 10 Years of Cyber Essentials report states that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than organisations without them. It's the strongest published statistic connecting the scheme to insurance outcomes - and it's worth reading precisely: the data comes from claims on the insurance policy bundled with certification, not the whole UK market, and it measures the controls doing their job (fewer incidents), not premiums falling. It's an argument that the five controls work, which is exactly why underwriters ask about them. ## What's on the proposal form - mapped to Cyber Essentials | | What insurers ask | Cyber Essentials control? | Notes | MFA on email, remote access and admin accounts | ✔ User access control | The single most scrutinised answer on the form; inadequate MFA is widely cited by brokers as a leading cause of declined cover and disputed claims | Critical patches applied within 14 days | ✔ Security update management | The 14-day window on insurer forms is literally the CE requirement | Firewalls at the boundary and on devices | ✔ Firewalls | Direct match | Hardened configurations, default passwords removed | ✔ Secure configuration | Direct match | Anti-malware on all endpoints | ✔ Malware protection | CE requires malware protection; many insurers now expect EDR specifically, which goes beyond CE | Tested, offline or immutable backups | ✘ Not a CE control | The biggest gap - NCSC deliberately excludes backups from CE, but ransomware underwriting all but requires them The honest conclusion: Cyber Essentials answers most of the proposal form; MFA-everywhere, EDR and tested backups are the usual extras insurers want on top. That's also, not coincidentally, the shape of a sensible SME security programme. ## The insurance included with certification Basic Cyber Essentials certification through IASME includes cyber liability insurance with a £25,000 indemnity limit at no extra cost, for eligible organisations: UK or Crown Dependencies domiciled, under £20 million annual turnover, certifying the whole organisation, and opting in during assessment. The policy is underwritten by AIG UK and administered by Sutcliffe & Co, and includes a 24/7 incident-response helpline; Sutcliffe publicly offers paid uplifts of the bundled cover to higher limits. Treat £25,000 as a floor, not a policy - a serious incident costs more (the government's 2024 Cyber Security Breaches Survey put the average cost of the most disruptive breach at £8,260, and that average hides a long expensive tail) - but it's a genuinely free layer that arrives with the certificate. ## What cover costs, and what certification does to it UK SME cyber premiums start from roughly £90–£200 a year for micro-business policies (NimbleFins, 2026) and run into the low thousands for mid-sized SMEs with meaningful cover limits; broker-published ranges of £300–£6,000 a year are typical of the segment. Market conditions are currently favourable - Howden's 2025 cyber report recorded premium rates falling through 2025 as competition increased. On discounts: brokers and certification bodies report certified organisations obtaining better pricing, but no major UK insurer publishes a fixed Cyber Essentials discount - the certificate's real, verifiable value is that it evidences the controls underwriters already require, speeds the proposal process, and reduces the risk of a declined application or a voided claim. Anyone quoting you a guaranteed '10–30% off for CE' is repeating marketing, not policy wording. ## Becoming insurable in about 30 days If you can't answer the proposal form honestly today, the path is the same one certification takes - which is why we deliver them together. AMVIA's Cyber Essentials service (£250 + VAT/month, all-in) implements the five controls hands-on - MFA rolled out, patching brought inside 14 days, firewalls and configurations baselined, malware protection verified - and typically reaches certification in 30–45 days, official fees and the bundled £25k insurance eligibility included. Where your insurer wants the extras, the same team runs EDR and backup work as part of our wider managed security services, and Cyber Essentials Plus (£400 + VAT/month) adds the independent technical audit - the strongest evidence you can hand an underwriter that the declared controls are real. Start by seeing where you stand: the free cyber insurance readiness check takes ten minutes and maps your answers to the questions insurers actually ask, and our guide to getting cyber insurance in the UK covers the buying process itself. ## Frequently asked questions Q: Is Cyber Essentials required for cyber insurance in the UK? A: Generally no - no major UK insurer publishes a blanket rule refusing cover without the certificate. But insurers underwrite on the same controls Cyber Essentials certifies: MFA, 14-day patching, firewalls, secure configuration and malware protection. In practice the certificate is the fastest recognised way to evidence those controls, and organisations that can't demonstrate them face refusal, loaded premiums or restricted cover. Q: Does Cyber Essentials come with free cyber insurance? A: Yes, for eligible organisations: basic Cyber Essentials certification through IASME includes cyber liability insurance with a £25,000 indemnity limit at no extra cost - for UK or Crown Dependencies organisations under £20 million turnover that certify the whole organisation and opt in during assessment. It's underwritten by AIG UK, administered by Sutcliffe & Co, and includes a 24/7 incident-response helpline. It's a useful floor, not a substitute for a properly sized standalone policy. Q: Will Cyber Essentials reduce my cyber insurance premium? A: It can help, but be wary of specific promises: no major UK insurer publishes a fixed CE discount, and claims of '10–30% off' trace to marketing rather than policy wording. The government's July 2024 evaluation of the scheme found some insurers do offer better terms to certified organisations, and the certificate reliably speeds underwriting and reduces refusal risk - which for many SMEs is worth more than a discount. Q: What is the 92% statistic about Cyber Essentials and insurance claims? A: The NCSC's '10 Years of Cyber Essentials' report states organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than those without. The underlying data comes from the insurance policy bundled with certification rather than the whole UK market - so read it as strong evidence the five controls prevent incidents, not as a market-wide premium promise. Q: What controls do cyber insurers require that Cyber Essentials doesn't cover? A: Two main ones. Tested, offline or immutable backups - the NCSC deliberately excludes backups from CE, but ransomware underwriting all but requires them. And EDR (endpoint detection and response) - CE requires malware protection, but many insurers now expect the more capable EDR standard specifically. Both are common additions we implement alongside certification. Q: Why do insurers care so much about MFA? A: Because credential-based attacks are the dominant entry route, and MFA is the control that blunts them. It's typically the first question on the proposal form, brokers repeatedly cite missing or partial MFA as a leading cause of refused cover and disputed claims, and 'MFA on email, remote access and admin accounts' has become the de facto minimum. It's also squarely inside Cyber Essentials' user access control requirements. Q: How much does cyber insurance cost for a UK small business? A: Entry-level policies for micro businesses start around £90–£200 a year; SMEs buying meaningful cover limits typically pay from a few hundred pounds to a few thousand, with broker-published ranges of roughly £300–£6,000 a year. Rates fell through 2025 as market competition increased (Howden, 2025), making it a comparatively good time to buy - provided your controls survive the proposal form. Q: Can my insurer refuse a claim if my security controls weren't as declared? A: Yes - the proposal form is the basis of the contract, and misrepresenting controls (MFA 'enforced' with exceptions, patching 'within 14 days' in theory) is grounds for a dispute or voided claim precisely when you need the policy. This is the strongest argument for independently verified certification: Cyber Essentials Plus has an assessor test the controls, so what you declare is what an independent party found. Q: What's the fastest route from 'not insurable' to 'insurable'? A: Implement the five CE controls plus backups and EDR - which is a 30–45 day exercise for a typical SME estate when done hands-on. AMVIA's Cyber Essentials service (£250+VAT/month) does the implementation and certification together, and the free cyber insurance readiness check will show you in ten minutes which questions you'd currently fail. --- # Penetration Testing for UK Small and Medium Businesses URL: https://amvia.co.uk/cybersecurity/penetration-testing Last updated: 2026-03 Penetration testing is an authorised, simulated cyberattack against your network, applications or staff to find exploitable weaknesses before a real attacker does. AMVIA runs internal, external and web application tests for UK businesses, then hands you a prioritised, fix-first report. Most assessments complete within five to ten business days - one accountable provider, security first. A test is only useful if it changes what you do next. We don't dump a 200-page scanner export on your IT lead. Every finding is ranked by real-world risk, mapped to a fix, and retested once you've actioned it. Penetration testing sits inside AMVIA's wider managed cybersecurity service, so the people who find the gap are the people who help you close it. At a glance: - 1,200+ UK businesses protected - 24/7 monitoring and response - Critical incident response in under one hour ## What's included in an AMVIA penetration test? An AMVIA engagement covers the four ways attackers actually get in - your perimeter, your internal network, your web applications, and your people - followed by clear reporting and a retest. We scope the right combination for your environment rather than selling every test by default. - External penetration testing: your internet-facing systems - firewalls, web applications, email gateways and VPN endpoints - probed for anything an outside attacker could reach. - Internal penetration testing: simulating an attacker who already has a foothold, testing lateral movement, privilege escalation and access to sensitive data. - Web application testing: your apps and customer portals tested against the OWASP Top 10, the industry-standard list of the most critical web application risks. - Social engineering testing: simulated phishing and pretext attacks to measure how your staff respond and where awareness training is needed. - Detailed reporting: an executive summary, technical findings, CVSS-based risk ratings and specific remediation guidance. - Remediation verification: a follow-up retest that confirms each fix actually closed the gap. ## How does the penetration testing process work? The engagement runs in five stages, agreed with you up front so there are no surprises. Scope and rules of engagement are signed off before anyone touches a system, and you get a named contact throughout. Most tests complete inside five to ten business days. 1. Scoping: we define targets, boundaries and rules of engagement with your team. 2. Reconnaissance: information gathering and vulnerability scanning to map likely attack vectors. 3. Exploitation: controlled, evidence-based exploitation of confirmed weaknesses using real attacker techniques. 4. Reporting: a prioritised report with findings, CVSS risk ratings and step-by-step remediation. 5. Debrief and remediation: a technical walkthrough with your team, remediation support, then verification testing. ## Why do UK SMEs need penetration testing? Most breaches don't exploit some exotic zero-day - they walk through a misconfiguration, an unpatched service or a reused password that nobody knew was exposed. A penetration test surfaces those gaps on your terms, in a controlled window, instead of an attacker finding them first. The numbers make the case plainly. 43% of UK businesses experienced a cyber security breach or attack in the past 12 months (Cyber Security Breaches Survey 2025, DSIT). The National Cyber Security Centre recommends penetration testing as a way to gain assurance that your security controls work as intended, not just on paper. For a UK SME, an annual test is the difference between discovering a flaw in a report and discovering it in a ransom note. ## Penetration testing vs vulnerability scanning: what's the difference? A vulnerability scan is an automated check that flags known weaknesses; a penetration test is a skilled human proving which of those weaknesses can actually be exploited and how far an attacker could get. You need both - scanning for breadth and frequency, pen testing for depth and proof. | | | Vulnerability scanning | Penetration testing | Method | Automated tool scan | Skilled tester manually exploits findings | Output | List of known weaknesses | Proven, exploitable attack paths | Frequency | Continuous or monthly | Annual, plus after major change | Question answered | "What might be weak?" | "What can an attacker actually do?" Ongoing scanning is best run as part of vulnerability management; penetration testing is the periodic, human-led validation on top. If a test does uncover an active compromise, AMVIA's incident response team can step in immediately. ## Why choose AMVIA for penetration testing? AMVIA is a UK security partner, not a telecoms reseller bolting on a scanner. Our engineering and testing team operates from Sheffield, understands UK compliance requirements, and stays accountable from scoping through to verified fix. - Sheffield-based, UK-focused: our team works from Sheffield and understands UK infrastructure, compliance and the threats British businesses actually face. - Accredited and certified: AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status. - 1,200+ UK businesses protected: we manage IT and security for over 1,200 UK businesses across legal, finance, healthcare and professional services. - Fast, responsive support: critical issues answered in under one hour, with named account managers who know your environment. Findings don't stop at a PDF. Where a test exposes a monitoring gap, AMVIA's managed detection and response service - Microsoft Defender for Endpoint watched by our in-house 24/7 SOC - keeps eyes on the systems the test flagged. ## How much does penetration testing cost? Penetration testing is priced by scope: the number of IP ranges, applications, and test types in play, and whether social engineering or a retest is included. There's no honest fixed price for a test that hasn't been scoped, so we agree the cost in writing before any work starts. Most SME engagements are a fraction of the cost of a single breach. ## Frequently asked questions Q: What is penetration testing? A: An authorised, simulated cyberattack against your network, applications or staff, run to find exploitable weaknesses before a real attacker does. Unlike automated scanning, a pen test proves what's actually exploitable - the difference between a list of theoretical issues and evidence of real risk. Q: How often should a business run a penetration test? A: At least annually, and after any significant change - new systems, office moves, major cloud migrations. Many compliance frameworks and enterprise customers expect annual testing as standard, and pairing point-in-time tests with continuous vulnerability management covers the gaps between them. Q: What's the difference between a pen test and a vulnerability scan? A: A vulnerability scan is automated and broad - it lists known weaknesses across your estate. A penetration test is human-led and deep - a tester chains weaknesses together the way a real attacker would to prove impact. You need both: scanning for coverage and frequency, testing for proof. Q: What do we get at the end of a penetration test? A: A prioritised report: what was found, how it was exploited, what the business impact would be, and what to fix first - written for both your board and your engineers. AMVIA can then run the remediation through its managed security services rather than leaving you with a PDF and a problem. --- # 24/7 Cyber Security Monitoring for UK Businesses URL: https://amvia.co.uk/cybersecurity/247-security-monitoring Last updated: 2026-03 24/7 security monitoring is the continuous, round-the-clock surveillance of your endpoints, network, email and cloud services by a Security Operations Centre (SOC) that investigates every alert as it happens. AMVIA runs this from its UK-based, in-house SOC - one provider, security-first, staffed by Microsoft-certified analysts. Attackers do not keep office hours. Most ransomware is detonated at night and over weekends precisely because that is when defenders are away from their desks. Our managed cybersecurity practice exists to close that gap: a real analyst watching your environment at 3 a.m. with the same rigour as 3 p.m. If you only want one thing from this page, it is this - threats get caught when they happen, not when someone next logs in. ## What does 24/7 security monitoring actually involve? 24/7 security monitoring means a SOC continuously ingests logs and telemetry from your endpoints, servers, firewall, Microsoft 365 and cloud apps, correlates that data, and has a human analyst triage every alert it raises. The goal is simple: confirm or dismiss each signal fast, then act. Our service covers: - Continuous threat monitoring - round-the-clock surveillance of endpoints, servers, network devices and cloud services by certified security analysts. - Human-led alert triage - every alert is investigated by an analyst, not just an automated rule, so genuine threats are separated from false positives. - Rapid containment - when a real threat is confirmed, we isolate affected systems and begin investigation inside our SLA. - Monthly threat reports - what was detected, what we did, and what to fix next. - Environment-tuned detection - rules tuned to your estate to cut noise and focus on threats that matter to you. - No rip-and-replace - we integrate with your existing Microsoft 365, firewall and endpoint tooling. The detection engine is Microsoft Defender for Endpoint (Microsoft's endpoint detection and response platform), monitored by AMVIA's own analysts. For the underlying detection capability, see our endpoint detection and response service. ## How does AMVIA's 24/7 monitoring work? Onboarding to steady-state runs in five stages. We assess your environment, deploy monitoring, tune detection to your estate, then run continuous surveillance with monthly and quarterly reviews. Most clients reach full coverage within days, not months, because we monitor the tools you already own. 1. Onboarding - we assess your environment, deploy monitoring, and configure detection rules. 2. Continuous monitoring - the SOC watches your environment 24/7, investigating every alert. 3. Threat detection - when suspicious activity appears, analysts investigate and grade severity. 4. Response and containment - confirmed threats are contained immediately, with full communication to your team. 5. Reporting and improvement - monthly reports and quarterly reviews keep tightening your posture. This sits alongside our managed SOC service and feeds directly into incident response when a confirmed threat needs full remediation. ## Why do UK SMEs need 24/7 security monitoring? Because the threat is now routine, not exceptional. 43% of UK businesses experienced a cyber breach or attack in the past year, according to the Cyber Security Breaches Survey 2025 (DSIT). Antivirus and a firewall stop known malware - they do not catch an attacker logging in with stolen credentials. That gap is exactly where breaches happen. 22% of breaches involved compromised credentials as the initial access vector (Verizon DBIR 2025) - activity that traditional antivirus cannot see because no malware is involved. Continuous monitoring layers behavioural analysis, log correlation and human judgement on top of your existing defences, so a valid-looking login from an unexpected location gets questioned instead of waved through. The UK's National Cyber Security Centre treats logging and monitoring as a baseline control, not a luxury. Ransomware makes the round-the-clock point starkly: overnight is the favoured strike window. Daytime-only monitoring leaves a 16-hour hole every weekday and the entire weekend uncovered. ## In-house monitoring vs AMVIA managed 24/7 SOC Building a true 24/7 capability in-house means hiring for three shifts, buying tooling, and writing detection content - a six-figure commitment before the first alert is triaged. A managed SOC gives you the coverage without the headcount. | | Factor | In-house, business hours | AMVIA managed 24/7 SOC | Coverage | ~8 hours, weekdays | 24/7/365, including nights and weekends | Critical-alert response | Next working day | Under 1 hour for critical (P1), 2-hour target for others | Alert triage | Often automated, unfiltered | Human analyst on every alert | Staffing burden | 4–6 analysts for shift cover | None - handled by AMVIA | Detection engine | You buy, build and tune | Microsoft Defender, tuned to your estate | Time to full coverage | Months of recruitment | Days Pair this with vulnerability management and SIEM for SMEs for a complete detect-and-respond layer. ## How much does 24/7 security monitoring cost? AMVIA's 24/7 security monitoring starts from £5 per user per month, scaling with the number of users and devices in scope. Because we monitor the Microsoft 365 and endpoint tooling you already license, there is no large upfront platform spend - you pay for analysts and detection, not duplicate software. Final pricing depends on your estate size, the systems in scope, and whether you bundle managed detection and response or incident response. We scope it in a short call and quote a fixed monthly figure - no usage surprises. ## Why choose AMVIA for 24/7 security monitoring? AMVIA monitors security for 1,200+ UK businesses across legal, finance, healthcare and professional services, from our Sheffield-based, UK-staffed SOC. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and critical incidents (P1) are responded to in under one hour, with a 2-hour target for lower-priority alerts. - UK-based, UK-focused - engineering and SOC operate from Sheffield; we understand UK compliance, infrastructure and the threats facing British SMEs. - Certified and accountable - Cyber Essentials Plus and Microsoft Solutions Partner status, verifiable, not aspirational. - Human-led - analysts triage every alert, so your team only hears about confirmed threats that need a decision. - One provider - security, Microsoft 365 and connectivity under one accountable roof. ## Frequently asked questions Q: What is 24/7 security monitoring? A: Round-the-clock surveillance of your endpoints, network, email and cloud by a Security Operations Centre that investigates every alert as it fires. Attacks don't keep office hours - the point of a SOC is that detection and response start immediately, not the next morning. Q: Do we need a SOC if we already have antivirus and a firewall? A: Tools generate alerts; a SOC acts on them. Unwatched security tooling is where breaches hide - the signal was there, nobody was looking. Monitoring closes the gap between an alert firing and a human doing something about it, which is where incident cost is decided. Q: What does 24/7 monitoring cost? A: It's included in AMVIA's Enterprise managed plans rather than sold as a standalone product, with managed security coverage ranging £5–£65 per user/month by scope. Against staffing an in-house round-the-clock capability - multiple salaried analysts - the managed model is a fraction of the cost. Q: What happens when the SOC finds something at 3am? A: Triage starts immediately: the alert is investigated, affected systems can be contained, and genuine incidents escalate to response with defined SLAs - including waking the right people when severity demands it. You hear about the incident that mattered, not the thousand alerts that didn't. --- # What Is Managed Cybersecurity? A Plain-English UK Guide URL: https://amvia.co.uk/cybersecurity/what-is-managed-cybersecurity Last updated: 2026-03 Managed cybersecurity is a service where a specialist provider takes ownership of your threat detection, monitoring and incident response, running it around the clock for a predictable monthly fee. Instead of building an in-house security team, you get enterprise-grade protection from one accountable provider. AMVIA delivers this security-first, from a UK-based SOC. It is the difference between owning a smoke alarm and paying a fire service to watch it. This guide explains exactly what is included, who needs it, what it costs against an in-house team, and how to judge whether a provider is genuinely doing the job. If you want the bigger picture first, start with our managed cybersecurity pillar, which connects every service described below. ## Why does managed cybersecurity matter now? The threat is no longer hypothetical. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (gov.uk). For larger organisations the odds are worse, not better. - 65% of medium businesses and 69% of large businesses reported breaches or attacks (DSIT Cyber Security Breaches Survey 2025/26). - 85% of breaches involved phishing, and 93% of incidents meeting the legal definition of cyber crime were phishing-based (DSIT Cyber Security Breaches Survey 2025). - Only 25% of UK businesses have a formal incident response plan (DSIT Cyber Security Breaches Survey 2025/26). That last figure is the real story. Most UK businesses are being attacked, and most have no plan for what happens when an attack lands. Managed cybersecurity exists to close that gap - to make sure someone is watching, investigating and responding when an alert fires at 3am. ## How is managed cybersecurity different from antivirus? Antivirus is a single passive layer. It matches files against a database of known threats, so it cannot catch previously unseen malware, fileless attacks that run only in memory, or social-engineering campaigns like business email compromise. There is no monitoring, no investigation, and no response - just a blocked file or a missed one. Managed cybersecurity is active and continuous. It combines several technologies - endpoint detection and response, email security, identity protection and vulnerability management - with human analysts who monitor, investigate and respond around the clock. The analyst is the part antivirus can never provide. A tool raises an alert; a person decides whether it is a real attack and acts on it. ## What is included in a managed cybersecurity service? A complete service stacks several capabilities under one provider. Each addresses a different stage of an attack - preventing it, detecting it, investigating it, and recovering from it. Below is what AMVIA includes as standard, and why each layer earns its place. ## SOC monitoring A Security Operations Centre (SOC) is a team of analysts watching your IT environment 24/7 for signs of compromise. They triage alerts, separate genuine threats from false positives, and escalate real incidents for response. Without a SOC, alerts pile up uninvestigated and breaches can sit undetected for weeks. AMVIA's managed SOC service provides that continuous human oversight from Sheffield. ## Managed detection and response (MDR) Where a SOC monitors and alerts, managed detection and response goes further: analysts actively hunt for threats, investigate suspicious behaviour, and take containment action on your behalf. When a threat is confirmed, the team can isolate a compromised device, revoke stolen credentials and guide recovery. For an SME, MDR delivers the investigative muscle of a dedicated security team without the headcount. ## Endpoint detection and response (EDR) EDR software runs on every laptop, server and mobile device, watching behaviour rather than just files and able to isolate a compromised machine from the network automatically. In a managed service, the SOC investigates every EDR alert so you do not need in-house expertise to interpret them. AMVIA monitors EDR through Microsoft Defender for Endpoint, watched by our own SOC. ## Email security Email is the primary attack vector - 85% of breaches involved phishing (DSIT Cyber Security Breaches Survey 2025). Managed email security covers Microsoft Defender for Office 365 configuration and monitoring, DMARC enforced at p=reject to stop domain spoofing, anti-impersonation policies, and phishing simulation training for staff. AMVIA manages all of these as one service. The NCSC's email security guidance backs this layered approach (ncsc.gov.uk). ## Vulnerability management Vulnerability management means regularly scanning systems for unpatched software and misconfigurations before attackers find them, then prioritising and supporting remediation. Unpatched vulnerabilities are one of the most common routes to initial access, so closing them proactively is foundational rather than optional. ## Who needs managed cybersecurity? Almost any UK business that depends on technology benefits, but it matters most for organisations in a specific band of risk and resource. The 10-to-500-employee range is the sweet spot - big enough to be a worthwhile target, too small to justify a full in-house security team. - You handle sensitive customer, financial or personal data subject to UK GDPR (ico.org.uk). - You operate in a regulated sector - financial services, healthcare, legal or education. - You have 10 to 500 staff and no dedicated security function. - You must prove security maturity to win contracts, satisfy supply chains, or obtain cyber insurance. - You have already had a breach or near-miss. Attackers increasingly target people, not just systems: impersonation was reported by 35% of businesses experiencing breaches (DSIT Cyber Security Breaches Survey 2025). Technology alone cannot fully address that without expert oversight. ## In-house vs managed cybersecurity: what does it cost? Building an in-house security function is expensive and hard to staff. A single analyst costs roughly £40,000 to £60,000 per year in salary alone (the National Careers Service puts experienced cyber security analysts at up to £60,000), and a true 24/7 SOC needs three to four analysts on shifts - pushing staffing costs well past six figures before you buy a single tool. | | Factor | In-house team | Managed service (AMVIA) | Analyst salaries | £40,000–£60,000 each per year (typical UK 2026 range) | Included | 24/7 cover | 3–4 analysts on shifts | Included as standard | Security tooling | Bought and managed by you | Included and managed | Time to operational | Months of hiring | Days | Typical cost | £150,000+ per year staffing | from £5 to £65 per user per month AMVIA's managed cybersecurity service is available from £5 to £65 per user per month for SOC monitoring, managed EDR, email security and vulnerability management. For a 50-person business that is roughly £9,000 to £15,000 per year - a fraction of the in-house equivalent, with broader coverage. For context, the average cost of the single most disruptive breach was £3,550 for UK businesses (DSIT Cyber Security Breaches Survey 2025), and far higher for larger organisations once disruption and regulatory consequences are counted. ## How do you judge SLAs and accountability? A credible managed service commits to defined response times in writing. Critical incidents - active ransomware, credential compromise, data exfiltration in progress - should get an immediate response at any hour. Lower-severity alerts have defined windows, usually measured in hours. The Service Level Agreement (SLA) is where accountability becomes contractual rather than aspirational. When you compare providers, look for SLAs that specify response times by severity, clear escalation procedures, and regular reporting. If a provider cannot tell you what happens in the first hour of a confirmed ransomware incident, that is the answer. A strong incident response capability is the part of the service you are really buying. ## Why does a UK-based SOC matter? AMVIA runs its SOC from Sheffield, staffed by UK-based analysts who understand the regulatory context - UK GDPR, NCSC guidance and sector-specific obligations - that governs how incidents must be handled here. That local knowledge matters when a breach triggers reporting duties to the ICO within 72 hours. This is the AMVIA model in one line: one provider, security-first, Microsoft-certified engineers, accountable for the whole stack. We work with more than 1,200 UK businesses, with Cyber Essentials Plus certification underpinning our own security posture. ## Frequently asked questions Q: What does a managed cybersecurity service typically cover? A: A comprehensive service includes 24/7 SOC monitoring, managed endpoint detection and response across all devices, email security with DMARC enforcement and anti-phishing policies, vulnerability scanning with patch support, and incident response when threats are confirmed. For UK SMEs this typically costs from £5 to £65 per user per month, delivering enterprise-grade capability without in-house headcount. Q: How does an MSSP differ from a standard IT support provider? A: A Managed Service Provider (MSP) handles general IT - helpdesk, devices and infrastructure. A Managed Security Service Provider (MSSP) specialises in threat detection, SOC monitoring and incident response. The distinction matters because security needs dedicated analysts and tooling, not a part-time afterthought. Some providers, including AMVIA, do both under one roof, but the security function must be genuinely staffed. Q: At what size does a business need managed cybersecurity? A: Managed cybersecurity suits organisations with 10 to 500 employees - large enough to be targeted, too small to justify a dedicated hire at £40,000–£60,000 a year (National Careers Service band). That said, any business handling sensitive client data, operating in a regulated sector, or needing to satisfy supply-chain security requirements benefits. With 43% of UK businesses breached in 2025 (DSIT Cyber Security Breaches Survey 2025), risk is not limited to large enterprises. Q: Is managed cybersecurity the same as outsourcing all my IT? A: No. You can take managed cybersecurity on its own, alongside an existing IT provider or in-house team. It is a focused security layer - monitoring, detection and response - rather than general IT support. Many businesses keep their day-to-day IT in place and add a dedicated security service over the top for round-the-clock protection. Q: What tools does AMVIA use to deliver the service? A: AMVIA's managed cybersecurity is built on Microsoft Defender for Endpoint and Microsoft Defender for Office 365, with Barracuda email and network security, all monitored by our in-house 24/7 SOC. Using Microsoft-native tooling keeps the stack tightly integrated with your existing Microsoft 365 environment rather than bolting on disconnected third-party products. Q: How quickly can a managed cybersecurity service be in place? A: Onboarding typically takes days rather than the months required to recruit and equip an in-house team. The provider deploys EDR agents, connects email and identity monitoring, and begins SOC coverage once tooling is reporting. Given that only 25% of UK businesses have a formal incident response plan (DSIT Cyber Security Breaches Survey 2025/26), getting professional cover in place quickly is usually the priority. --- # Managed Cybersecurity Service for UK Businesses URL: https://amvia.co.uk/cybersecurity/managed-cybersecurity Last updated: 2026-03 Managed cybersecurity is a fully outsourced security function: a provider monitors your endpoints, email, cloud and network around the clock, detects threats, and responds on your behalf for a fixed monthly fee. AMVIA delivers it from a Sheffield-based managed cybersecurity team - one provider, security-first, Microsoft-certified. ## What does a managed cybersecurity service include? A managed cybersecurity service bundles continuous monitoring, threat detection and incident response into one accountable contract. It replaces the in-house security team most UK SMEs cannot justify hiring. AMVIA's service covers five layers, each run by the same team so nothing falls between providers. - 24/7 security monitoring - a managed SOC service watches endpoints, email, cloud and network traffic, triages alerts and escalates confirmed threats. - Managed detection and response (MDR) - managed detection and response using Microsoft Defender for Endpoint across Windows, macOS, iOS and Android, monitored by AMVIA's in-house SOC. - Email security and phishing protection - advanced filtering, attachment sandboxing, URL rewriting and DMARC, DKIM and SPF enforcement. - Vulnerability management - continuous scanning that prioritises fixes by exposure risk. - Incident response - containment, eradication, recovery and post-incident review aligned with NCSC incident management guidance. AMVIA's security stack is built on Microsoft Defender and the Barracuda email and network suite - not a sprawl of third-party tools you have to reconcile yourself. ## How does AMVIA's managed cybersecurity work? AMVIA onboards your business in four stages, then runs your security as an ongoing managed service. The goal is layered defence deployed with minimal disruption, then watched continuously rather than checked occasionally. You get a single team accountable for the whole stack. 1. Security assessment - evaluate your current posture and benchmark it against recognised UK standards such as Cyber Essentials. 2. Security stack design - layer endpoint protection, email security, network monitoring and access controls. 3. Deployment and hardening - deploy tools, configure policies and harden systems. 4. 24/7 monitoring and response - continuous SOC monitoring, monthly reporting and quarterly security reviews. ## Why do UK SMEs need managed cybersecurity? Small and medium businesses are now the primary target for cybercrime, and most cannot staff a 24/7 security desk in-house. The financial exposure is real: the 2025 UK Cyber Security Breaches Survey puts the average cost of the most disruptive breach at £3,550 for businesses reporting a material financial outcome (DSIT, 2025). Managed cybersecurity converts that unpredictable risk into a fixed monthly cost. Unpatched software remains one of the leading causes of successful attacks, which is why continuous vulnerability management sits inside the service rather than as an afterthought. Email is still the most common entry point, so phishing defence is treated as a first-order control, not an add-on. | | Capability | In-house team | AMVIA managed cybersecurity | Coverage | Office hours, holiday gaps | 24/7, 365 days | Cost model | Salaries + tooling + training | Fixed monthly fee | Detection and response | Reactive, ticket-driven | Proactive SOC triage | Tooling | Bought and integrated by you | Microsoft Defender + Barracuda, pre-integrated | Accountability | Split across staff/vendors | One provider ## How much does managed cybersecurity cost? AMVIA prices managed cybersecurity per user, from £5 to £65 per user per month depending on the level of protection. For context, indicative monthly bands by business size - typical UK 2026 market rates - are set out below. Pricing scales with headcount and the depth of monitoring and response you need. | | Business size | Staff count | Monthly cost | Small | 10–50 | £500 | Medium | 50–150 | £1,500–£4,000 | Larger SME | 150–500 | £4,000–£9,000 For a fuller breakdown, see the guide on how much managed cybersecurity costs. ## Why choose AMVIA for managed cybersecurity? AMVIA is a security-first Microsoft partner, not a telecoms reseller bolting on security. The engineering and support team operates from Sheffield and understands UK compliance and the threats facing British businesses. One provider runs the whole stack, so there is no finger-pointing when something goes wrong. - 1,200+ UK businesses managed by AMVIA across legal, finance, healthcare and professional services. - Cyber Essentials Plus certification and Microsoft Solutions Partner status - verified credentials, not marketing badges. - One-hour response for critical incidents - active breaches, ransomware and confirmed credential compromise - 24/7. - Helpdesk access by phone, email and portal. AMVIA's detection runs on Microsoft Defender monitored by an in-house SOC, and the service is designed to support - not replace - your existing IT provider. If you need rapid containment, incident response is included rather than billed as an emergency extra. ## Frequently asked questions Q: What is managed cybersecurity? A: A fully outsourced security function: a provider monitors your endpoints, email, cloud and network around the clock, detects threats and responds on your behalf for a fixed monthly fee. You get an enterprise-grade security operation without building the in-house team. Q: How much does managed cybersecurity cost compared with hiring in-house? A: Managed coverage runs £5–£65 per user/month by scope - for a typical SME, a fraction of in-house cost, where a single security hire runs thousands per month before tooling. The DSIT 2025 average most-disruptive-breach cost of £3,550 makes the comparison against doing nothing even simpler. Q: What's included in AMVIA's managed cybersecurity service? A: Endpoint protection and EDR, email security, Microsoft 365 hardening, vulnerability management and patching discipline, with 24/7 SOC monitoring and incident response on Enterprise plans. Security is built into every AMVIA plan rather than sold as a bolt-on. Q: How quickly do you respond to a security incident? A: Monitored threats are triaged around the clock, with critical-issue remote response targeted in under an hour. The point of managed detection is that response starts when the alert fires - not when someone reads an inbox the next morning. Q: Will managed cybersecurity help us pass Cyber Essentials? A: Directly - the five controls Cyber Essentials verifies (firewalls, secure configuration, access control, malware protection, patching) are exactly what a managed service runs day to day. AMVIA holds Cyber Essentials Plus itself and prepares clients for both tiers as part of the service. --- # Phishing Protection for UK Businesses URL: https://amvia.co.uk/cybersecurity/phishing-protection Last updated: 2026-03 Phishing protection is a layered defence that stops fraudulent emails reaching staff and limits the damage when one slips through. It combines technical email filtering, security awareness training and simulated attacks. AMVIA runs all three layers as one accountable provider - security-first, Microsoft-certified - so nothing falls between vendors. It sits inside our wider managed cybersecurity service, not as a bolt-on. ## Why is phishing the threat UK SMEs must fix first? Phishing is the most common way attackers get into UK businesses, so it is the single control with the highest return on effort. According to the 2025 UK Cyber Security Breaches Survey, 85% of businesses that identified a breach pointed to phishing as the most common attack type. Fix email, and you close the door most criminals walk through. The threat is also getting cheaper to run and harder to spot. Roughly 35% of UK SMEs now cite AI-generated attacks as their top concern, and an estimated 99% of phishing volume is bulk, automated email. The UK's National Cyber Security Centre treats phishing as a primary threat for organisations of every size (NCSC phishing guidance). - Email is the cheapest, most scalable route into a business. - One click can hand over credentials, money, or both. - Most breaches start here, so most prevention budget should too - see the DCMS Cyber Security Breaches Survey 2025. ## What's included in AMVIA phishing protection? AMVIA phishing protection is built in three layers, because no single control stops every attack. Technical filtering blocks the bulk volume, training hardens the people that targeted attacks aim for, and simulation measures whether the first two are actually working. You get all three from one provider. Layer 1 - Technical email security. Microsoft Defender for Office 365 and Barracuda email protection assess every inbound message for spoofed domains, malicious links, suspicious attachments and impersonation, using machine-learning models that update as new tactics appear. Layer 2 - Security awareness training. Staff learn to recognise phishing and the exact steps to take when a message looks wrong. Technical controls alone cannot stop sophisticated spear phishing or business email compromise - people are the last line. Layer 3 - Phishing simulation. Controlled, realistic phishing simulation training tests real-world susceptibility and gives you a measurable click rate to drive down over time. ## How does AMVIA protect you from phishing? We start by finding the gaps, then close them and keep them closed. The process is a continuous loop, not a one-off install, because attacker tactics and your staff both change month to month. 1. Threat assessment - we review current email security, domain configuration (SPF, DKIM, DMARC) and recent phishing attempts. 2. Technical controls - anti-phishing filters, impersonation protection, and safe links and attachments policies. 3. Staff awareness - training paired with simulated attacks so learning is tested, not assumed. 4. Ongoing defence - continuous monitoring by our in-house 24/7 SOC, regular simulations and policy updates. Critical issues are responded to within one hour by a UK-based team, and our managed detection and response service catches the threats that get past the inbox. ## Technical controls alone vs layered phishing protection Buying a spam filter is not the same as having phishing protection. Filters stop the bulk noise but miss the targeted attacks that cause real financial loss. The table shows why layering matters - and where each layer earns its place. | | Capability | Technical filter only | AMVIA layered protection | Bulk phishing blocked | High (95–99%) | High (95–99%) | Spear phishing / BEC caught | Low | Reduced via training + monitoring | Staff click rate measured | No | Yes, via simulations | Domain hardening (SPF/DKIM/DMARC) | Sometimes | Always reviewed | 24/7 response when one slips through | No | In-house SOC, 1-hour critical response | Single accountable provider | No | Yes Regular simulations move staff click rates from a typical untrained 20–30% (industry benchmark) to below 5%; AMVIA clients typically achieve sub-5% click rates within six months. ## How much does phishing protection cost? Phishing protection is usually included within a managed cybersecurity package rather than priced as a single line item, because the layers reinforce each other. Standalone email security and simulation programmes are available where you only need one piece. Microsoft 365 Business Premium, which includes Defender for Office 365, lists at £16.90 per user per month (Microsoft 365 pricing). For a tailored quote, the fastest route is a free security audit - we assess your current exposure first, then price to it. ## Why choose AMVIA for phishing protection? AMVIA is a Sheffield-based, UK-focused security partner - not a telecoms reseller bolting on a filter. We protect 1,200+ UK businesses across legal, finance, healthcare and professional services, and run detection and response in-house rather than subcontracting it. - Cyber Essentials Plus certified. - Microsoft Solutions Partner - Modern Work, Security & Azure Infrastructure. - 1,200+ UK businesses protected. - Critical issues responded to within one hour by our in-house 24/7 SOC. ## Frequently asked questions Q: What is phishing protection? A: A layered defence: technical email filtering that stops fraudulent messages reaching staff, security awareness training for the ones that slip through, and controls that limit the damage when someone clicks. No single layer is enough - 85% of UK breaches involved phishing (DSIT 2025). Q: Doesn't Microsoft 365 already block phishing? A: It blocks a lot - and sophisticated impersonation, payload-less lures and freshly-registered domains still get through the default filters. Layering dedicated protection over Microsoft 365, plus hardening the tenant itself, is the standard defence for businesses that live in Outlook and Teams. Q: Does staff training actually work against phishing? A: As a layer, yes: trained staff who report suspicious emails become detection sensors, and simulated phishing keeps the skill honest. As the only defence, no - someone will always click eventually, which is why filtering and post-click controls carry the structural load. Q: What should we do when someone clicks a phishing link? A: Fast containment: reset the credentials, revoke active sessions, check mail rules for attacker persistence, and review what the account touched. Speed matters more than blame - a reported click handled in minutes is an incident; a hidden one handled in weeks is a breach. --- # What Is SIEM? Security Information and Event Management for SMEs URL: https://amvia.co.uk/cybersecurity/siem-for-smes Last updated: 2026-03 A SIEM (Security Information and Event Management) platform collects security logs from across your IT estate and correlates them to spot multi-stage attacks. Most UK SMEs need that detection outcome, not a tool to run themselves - which is why AMVIA delivers it as managed detection and response. One provider. Security-first. Microsoft-certified. For the wider picture, this sits inside AMVIA's managed cybersecurity services for UK SMEs - SIEM is one capability within a monitored security stack, not a product you buy in isolation. ## What is a SIEM and how does it work? A SIEM combines two jobs: collecting security logs from every system, and analysing those logs in real time to detect threats. It ingests data from endpoints, Active Directory or Entra ID, firewalls, cloud audit logs, and email security, then applies correlation rules to surface attack patterns a single tool would miss. The detection power comes from correlation - spotting patterns across sources that are invisible in isolation. A single failed login is not worth investigating. But failed logins from multiple locations, then a successful login from an unfamiliar IP, then a new inbox forwarding rule to an external address, together signal a compromised account being actively exploited. SIEM stitches these events into one actionable alert. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past twelve months. Many of those attacks span email, identity, endpoint, and cloud - exactly the kind of multi-stage activity correlation is built to catch. ## How does a SIEM detect threats, step by step? A SIEM works through four connected stages: collect, normalise, correlate, alert. Log connectors gather event data from across the estate; the platform standardises it; a correlation engine applies detection rules; and analysts investigate the alerts that result. The technology produces signals - people turn signals into decisions. - Collect - agents and connectors pull Windows Security Event logs, firewall logs, Microsoft 365 audit logs, Entra ID sign-in logs, EDR alerts, DNS queries, and email gateway logs. Even a 50-user business can generate millions of events per day. - Normalise - disparate formats are translated into a common schema so one rule works across every source. - Correlate - rules range from simple thresholds (five failed logins in a minute) to multi-stage chains (failed VPN login, then cloud login from another country, then bulk download). User and Entity Behaviour Analytics (UEBA) baselines normal activity and flags deviations. - Alert - when a rule fires, the SIEM bundles the evidence, users, devices, and timeline into one alert for an analyst to triage. ## SIEM vs SOC: what's the difference? A SIEM is technology; a SOC is people. The SIEM collects logs, applies rules, and raises alerts. A Security Operations Centre (SOC) is the team of analysts who monitor that platform, investigate the alerts, and respond to confirmed threats. The SIEM generates the noise; the SOC supplies the judgement. This matters because a SIEM with no SOC is a burglar alarm nobody is listening to. The alerts still fire, but without trained analysts they pile up unactioned and real threats get lost. Per the DSIT Cyber Security Breaches Survey 2025/26, only 25% of UK businesses have a formal incident response plan - detection without a response capability is a false sense of security, not protection. AMVIA's managed SOC service supplies that analyst layer 24/7 without you hiring specialist staff. ## Why is running a SIEM hard for SMEs? Traditional SIEM platforms - Microsoft Sentinel, Splunk, IBM QRadar, Elastic - are powerful but demand expertise and budget most SMEs do not have in-house. The result is usually a half-tuned platform raising alerts nobody investigates, which delivers no security value at all. | | Challenge | What it means for an SME | Configuration complexity | Log ingestion, rule writing, and tuning need a dedicated security engineer | Alert fatigue | A poorly tuned SIEM fires hundreds of mostly false alerts a day, burying real threats | Cost | Platforms price by data ingested - volumes (and bills) escalate as log sources grow | Ongoing maintenance | Detection rules and connectors break and need constant updating | Analyst requirement | Even a perfect SIEM produces alerts that only a trained human can resolve For most UK SMEs without dedicated security staff, operating a standalone SIEM in-house is not practical. A platform that generates hundreds of unread daily alerts just creates an audit trail proving you were warned about threats you never acted on. ## When does an SME genuinely need SIEM capability? Some SMEs do need what a SIEM provides - usually driven by compliance, insurance, or contract obligations rather than choice. The trigger is rarely "we want a SIEM"; it is "a regulator, insurer, or client requires evidence of active monitoring and log retention". - Regulatory compliance - financial services, healthcare, and legal sectors often require centralised log retention and audit trails for set periods. SIEM provides that storage and search. - Cyber insurance - insurers increasingly require evidence of security monitoring as a condition of cover. - Supply chain due diligence - larger clients and government contracts may demand proof of active monitoring. - Post-incident investigation - historical log data is essential to scope a breach and trace how an attacker got in. - Multi-source attack detection - attacks crossing email, identity, endpoint, and cloud can only be caught by correlating across sources. The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach Report, 2025). For regulated businesses handling sensitive data, the cost of SIEM capability - run directly or consumed as a service - is modest against that exposure. ## How does SIEM work with Microsoft 365? If you run Microsoft 365, you already have meaningful cross-source correlation built in. Microsoft 365 Defender correlates signals across Defender for Business (endpoint), Defender for Office 365 (email), and Entra ID Protection (identity) to detect multi-stage attacks inside the Microsoft ecosystem - a solid foundation before any dedicated SIEM. Microsoft Sentinel, Microsoft's cloud-native SIEM, extends this by ingesting Defender alerts alongside non-Microsoft sources - third-party firewalls, Linux servers, and SaaS apps - and adds custom detection rules, UEBA, automated response, and long-term retention. AMVIA deploys and manages Sentinel for clients needing full log correlation and retention. For most SME clients, AMVIA pairs M365 Defender's built-in correlation with Microsoft Defender for Business, monitored by our in-house 24/7 SOC, to deliver SIEM-grade outcomes without you running a full Sentinel deployment. ## MDR vs SIEM: what do SMEs actually need? For most UK SMEs the answer is MDR, not a standalone SIEM. A SIEM is a technology that produces alerts; managed detection and response (MDR) is a service that includes the analysts who investigate and act on those alerts, using SIEM-class detection as the underlying engine. The SME bottleneck is rarely the log platform - it is the expertise to tune rules, filter false positives, investigate alerts, and respond to confirmed threats. AMVIA's managed detection and response service supplies exactly that: cross-source detection, expert investigation of every alert, and active containment when an attack is live. You get the security outcomes SIEM enables, delivered as a service rather than a platform you must staff. Our 24/7 security monitoring means alerts are seen and acted on around the clock, not collected and forgotten. ## How much does SIEM cost for an SME? SIEM pricing is driven by data volume. Microsoft Sentinel and Splunk both charge per gigabyte ingested, so costs can run from a few hundred to several thousand pounds a month depending on log sources - before you add the analyst time to operate the platform and investigate alerts. Managed MDR services bundle technology and analyst cost into a predictable per-user or per-endpoint monthly fee. For most SMEs that is cheaper than building in-house, where a SIEM licence plus analyst salaries plus ongoing training significantly exceeds the cost of a managed service delivering equivalent or better detection. AMVIA prices monitoring per user or endpoint so the bill stays predictable as you grow - book a free security audit for a figure scoped to your environment. ## Security monitoring readiness checklist Use this to judge detection maturity. The real question is not "do we have a SIEM?" but "are suspicious events detected, investigated, and acted upon?" - Security logs collected from all key sources - endpoints, identity, email, network - Log retention meets compliance requirements - typically 12 months minimum - Alerts reviewed and investigated - not just collected - Cross-source correlation active - single-source alerts miss multi-stage attacks - Incident escalation procedure defined - who receives alerts and what they do - Microsoft 365 audit logging enabled - required for Entra ID and Exchange Online investigation The NCSC's logging and monitoring guidance is a useful reference for what good detection coverage looks like. ## Frequently asked questions Q: What does a SIEM actually do? A: Collects security logs from across your estate - endpoints, identity, email, network - and correlates them to spot multi-stage attacks no single tool sees: the login from an odd location, then a mailbox rule, then unusual file access. The pattern is the detection, and patterns need the logs in one place. Q: Does a small business really need a SIEM? A: It needs the outcome - correlated visibility with someone watching - more than the enterprise product. With 43% of UK businesses attacked in a year (DSIT 2025), the SME answer is usually a managed service running modern tooling, not a self-hosted platform with nobody to staff it. Q: What logs matter most for an SME? A: Identity first (Microsoft 365 sign-ins and changes), then endpoints, then email - those three catch most real SME incidents. Starting there gets meaningful detection quickly; more sources add depth later. Q: What's the alternative to buying our own SIEM? A: Managed detection: your logs feeding a provider's SOC, tuned and watched 24/7, priced per user instead of as a platform build. It's included in AMVIA's Enterprise plans - the same outcome as an in-house SIEM+SOC at SME economics. --- # Email Security and Phishing Protection for UK Businesses URL: https://amvia.co.uk/cybersecurity/email-security Last updated: 2026-03 Email security is the set of controls that stop phishing, malware, account takeover and spoofing reaching your inbox. It combines filtering, domain authentication (DMARC, DKIM, SPF) and staff training. AMVIA manages all three as a single security-first service for 1,200+ UK businesses - one provider, Microsoft-certified. This page sits under our managed cybersecurity pillar. If email is where your risk concentrates, start here, then book a free security audit to see exactly where your defences leak. ## How does managed email security work? Managed email security layers three defences and keeps them tuned: filtering blocks malicious mail at the gateway, authentication proves who really sent a message, and simulation training hardens your people. AMVIA runs all of it on Microsoft Defender plus the Barracuda email suite, so accountability never splits across vendors. What we manage for you: - Anti-phishing and spam filtering - machine-learning and threat-intelligence filtering blocks phishing, malicious URLs and weaponised attachments before delivery. - DMARC, DKIM and SPF - we configure and monitor all three so attackers cannot impersonate your domain. See our dedicated DMARC, DKIM and SPF setup service. - Business Email Compromise detection - behavioural analysis flags impersonation of executives and suppliers; detail on our business email compromise page. - Attachment sandboxing - suspicious files are detonated in isolation before they reach a user. - Email archiving and continuity - tamper-evident archiving and inbox access that survives a Microsoft 365 outage. - Phishing simulation training - measured campaigns that cut click rates, covered on our phishing simulation page. ## Why do UK SMEs need email security? Email is the single biggest attack surface for UK businesses, and the default Microsoft 365 filtering most firms rely on does not stop targeted attacks. Phishing was the most common breach type identified in the UK Government's 2025 survey, affecting roughly 85% of businesses that reported a breach. The numbers are blunt: - 85% of UK cyber breaches involve a phishing attack as the initial entry point (DSIT 2025) - confirmed in the Cyber Security Breaches Survey 2025. - £100,000–£150,000 typical loss from a successful Business Email Compromise (BEC) attack on a UK business (typical UK 2026 range). - overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report). - 1,200+ UK businesses protected by AMVIA's managed email security service. The NCSC's phishing guidance is clear that technical controls and user awareness have to work together - which is exactly how we build the service. ## What's the difference between in-house and managed email security? In-house email security depends on one busy admin keeping policies, DNS records and training current. Managed email security gives you a dedicated team owning all of it with a 24/7 SOC behind the alerts. The table below shows where the gap shows up. | | Capability | In-house / default M365 | AMVIA managed email security | Filtering tuning | Default settings, rarely reviewed | Defender + Barracuda, tuned and audited | DMARC/DKIM/SPF | Often missing or in monitor-only | Configured, monitored, moved to enforcement | BEC / impersonation detection | Limited | Behavioural detection on every inbound | Phishing simulation | Ad hoc or none | Quarterly campaigns with department reporting | Archiving and continuity | Manual or absent | Compliant archiving + outage continuity | Response when something slips through | Whoever is free | In-house 24/7 SOC ## What types of email attack does it stop? Email attacks split into a handful of repeatable patterns, and a layered service is built to counter each one. Filtering and sandboxing handle malware; authentication handles spoofing; behavioural detection and trained staff handle the social-engineering attacks that carry no payload at all. - Phishing - mass emails impersonating banks, HMRC or Microsoft to harvest credentials. - Spear-phishing - researched, personalised attacks aimed at finance and IT staff. - Business Email Compromise - payment-fraud impersonation that uses trust, not malware. - Malware delivery - macro documents, ZIPs and links that drop ransomware or remote-access tools. - Spoofing - mail forged to look like your own domain, which DMARC, DKIM and SPF shut down. ## How do DMARC, DKIM and SPF protect your domain? DMARC, DKIM and SPF are DNS records that let receiving servers verify mail genuinely came from your domain. SPF lists your authorised senders, DKIM signs each message cryptographically, and DMARC decides what happens to anything that fails. Together they stop attackers sending mail as you. We deploy DMARC in monitoring mode first, review the aggregate reports, clean up legitimate senders, then move to `p=quarantine` or `p=reject` - so enforcement never blocks real business mail. Microsoft's own guidance on email authentication is documented at learn.microsoft.com. ## Microsoft 365 email security vs a managed service - what's the difference? Microsoft 365 includes real protection: Business Premium ships Microsoft Defender for Office 365 Plan 2 with Safe Links, Safe Attachments and anti-phishing policies. The catch is configuration - the default settings are not the most secure settings, and Basic and Standard tiers only include Exchange Online Protection. AMVIA audits your licence, tunes Defender to a hardened baseline, and adds the Barracuda email gateway where the tier needs more - sandboxing, archiving and continuity. For deeper Microsoft hardening, see Microsoft Defender for Business. Regulated firms - for example SRA-regulated law firms - also get archiving that supports FCA, SRA and GDPR retention obligations. ## How much does managed email security cost? For businesses already on Microsoft 365 Business Premium, AMVIA's management service costs from £5 per user per month, covering Defender tuning, DMARC implementation and phishing simulations. Where a tier needs a third-party gateway, expect £3–£8 per user per month for the gateway licence on top of management. The underlying Microsoft licences are list-priced (ex VAT, annual) on microsoft.com/en-gb: Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month. Premium is usually the cheapest route to strong email security because Defender Plan 2 is bundled in. ## Frequently asked questions Q: Is Microsoft 365 email security enough on its own? A: It depends on your licence and configuration. Business Premium includes Defender for Office 365 Plan 2, which is strong once tuned, but Basic and Standard only include Exchange Online Protection. Default settings are rarely the most secure. AMVIA audits your tier and adds a Barracuda gateway only where it genuinely improves filtering. Q: What is Business Email Compromise and why is it so dangerous? A: BEC is fraud where an attacker impersonates an executive or supplier to authorise a payment or data transfer. It carries no malware, so traditional filters miss it - it exploits trust, not technology. Overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report). AMVIA adds behavioural detection that flags impersonation by sender patterns. Q: Do I really need DMARC, DKIM and SPF? A: Yes. Without all three, anyone can send email that displays your company name and domain as the sender. They are foundational protection against spoofing and impersonation and support common compliance expectations. AMVIA configures them in monitoring mode first, then moves to enforcement once every legitimate sender is verified, so no real mail is blocked. Q: Does phishing simulation training actually work? A: Yes - sending staff realistic but fake phishing emails and training those who click measurably lowers susceptibility over time. Independent research points to large reductions across a year of regular campaigns. AMVIA runs quarterly simulations and reports click rates by department so managers can target training where it is needed. Q: How quickly can AMVIA get our email security in place? A: Most engagements start with a free security audit of your current DMARC, filtering and licence position, then a phased rollout. Authentication records and Defender tuning typically go live within days; DMARC moves to full enforcement once monitoring reports confirm every legitimate sender, usually within a few weeks. Q: What certifications does AMVIA hold? A: AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - Modern Work, Security & Azure Infrastructure. Our security stack is built on Microsoft Defender and the Barracuda email and network suite, monitored by an in-house 24/7 SOC. One provider, security-first, Microsoft-certified. --- # What Is Email Security? A Guide for UK Business Owners URL: https://amvia.co.uk/cybersecurity/email-security/what-is-email-security Last updated: 2026-03 Email security is the set of technologies, policies and controls that protect email from phishing, business email compromise (BEC), malware and data loss. It matters because email is the entry point for most cyberattacks: 85% of breaches involved phishing, and 93% of incidents meeting the legal definition of cyber crime were phishing-based (DSIT Cyber Security Breaches Survey 2025). AMVIA manages it end to end - one provider, security-first. Good email security is layered, not a single product. It combines gateway filtering that blocks malicious mail before it lands, sender authentication (DMARC, DKIM and SPF) that stops domain spoofing, content inspection that detonates attachments and checks links at click-time, and trained staff who can spot what slips through. Each layer covers the gaps the others leave. This is core managed cybersecurity work, and email is where most UK businesses are weakest. ## Why is email the number one attack vector? Email is universal, trusted and built for openness - which is exactly what attackers exploit. Every mailbox is a potential door into your business. Criminals use it to deliver malware, harvest credentials with fake login pages, impersonate executives to redirect payments, and push ransomware that encrypts files within minutes of a single click. The scale is real. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past twelve months, with 65% of medium and 69% of large businesses affected in the 2025/26 edition. In the 2025 survey, impersonation was reported by 35% of businesses experiencing breaches - a direct measure of how often attackers pose as someone you trust. For SMEs without dedicated security staff, that is a constant, managed-or-not risk. ## What threats does email security defend against? Email security defends against four threat families: phishing and credential theft, business email compromise, malware and ransomware delivery, and data loss. Each works differently, so each needs a different control. Below is how they behave and what stops them. | | Threat | How it works | Primary control | Phishing | Fake links and login pages harvest credentials | Advanced filtering, anti-impersonation, phishing simulation training | Business email compromise | Impersonates execs or suppliers to redirect payment | Anti-impersonation, DMARC, payment-change verification | Malware / ransomware | Malicious attachments execute code on open | Attachment sandboxing, gateway filtering | Data loss | Sensitive data misdirected or exfiltrated by email | Data loss prevention (DLP) policies ## How dangerous is business email compromise? BEC is the most expensive email threat because it carries no malicious link or attachment for tools to catch - just a convincing message from a "trusted" sender. The average cost of the single most disruptive breach was £3,550 for UK businesses (DSIT 2025), but BEC incidents run far higher - the global median BEC loss is roughly $50,000 (Verizon DBIR 2025). Verifying any payment or bank-detail change out of band is the single highest-value habit you can teach staff. ## Why does ransomware still arrive by email? Email remains the main delivery route for malware and ransomware. Attachments disguised as invoices, delivery notes or shared documents execute code that encrypts files or hands an attacker persistent access. Signature-based antivirus misses novel payloads, which is why advanced email filtering and sandboxing - detonating attachments in isolation before delivery - matter so much. ## What are the components of effective email security? Effective email security stacks several controls so a failure in one is caught by the next: filtering at the gateway, authentication of senders, inspection of attachments and links, and archiving for compliance. No single layer is sufficient; together they make email a defended channel rather than an open door. - Advanced filtering - analyses sender reputation, domain age, headers and embedded URLs using global threat intelligence to block phishing and BEC before the inbox. - Anti-phishing and anti-impersonation - flags display-name spoofing and lookalike domains where the name matches an executive but the sending domain is external. - DMARC, DKIM and SPF - authentication standards that stop criminals sending mail that appears to come from your domain. - Attachment sandboxing - detonates files in an isolated environment to catch zero-day malware that signature detection misses. - Safe links (time-of-click) - rewrites URLs and checks them when clicked, catching links weaponised after delivery. - Email archiving - a tamper-evident record for UK GDPR retention and e-discovery. ## Why are DMARC, DKIM and SPF the foundation? These three standards stop domain spoofing. SPF lists which servers may send for you, DKIM signs outbound mail cryptographically, and DMARC tells receiving servers to reject anything that fails. Publishing DMARC at a `p=reject` policy is the standard the NCSC recommends, and it prevents criminals impersonating your business to your own customers and partners. ## Is Microsoft 365 secure enough on its own? Microsoft 365 includes baseline spam filtering, but the controls that stop modern attacks - anti-phishing policies, Safe Links, Safe Attachments and anti-impersonation rules - require deliberate configuration and ongoing tuning. Out of the box, most tenants are under-protected. Microsoft Defender for Office 365 Plan 1, included in Microsoft 365 Business Premium, adds anti-phishing, Safe Links, Safe Attachments and anti-impersonation - the essentials for most SMEs. Plan 2 adds automated investigation and response, threat hunting and attack-simulation training. For the majority of UK SMEs, Plan 1 configured and monitored properly covers core requirements. The gap is rarely the licence; it is whether anyone has switched the policies on and keeps them tuned. ## What does a managed email security service include? A managed service takes configuration, monitoring and response off your plate. Instead of standing up and babysitting these tools yourself, a provider runs them against live threat intelligence and steps in when something gets through. The DSIT survey notes only 14% of UK businesses hold a formal incident response plan - a managed service fills exactly that gap. - Configuration and ongoing management of Microsoft Defender for Office 365, with Barracuda email protection where additional gateway controls are needed - DMARC, DKIM and SPF implementation and monitoring, with the goal of reaching `p=reject` - Anti-phishing and anti-impersonation policy tuning - Safe Links and Safe Attachments activation - Regular phishing simulation campaigns to test and train staff - Incident response for compromised accounts and email-borne breaches - Monthly reporting on blocked threats and user susceptibility trends AMVIA delivers this for SMEs from our Sheffield-based team: we configure and monitor Defender for Office 365, push DMARC to `p=reject`, run phishing protection and simulation programmes, and adapt controls as threats change. One accountable provider, Microsoft-certified engineers, security first. ## Frequently asked questions Q: What threats does email security protect against? A: Email security addresses phishing, business email compromise, malware and ransomware delivered via attachments, credential theft through fake login pages, and accidental data loss from misdirected mail. With 85% of UK breaches involving phishing in 2025, email is the single most important channel to secure. A strong approach layers filtering, authentication, sandboxing and staff awareness so one failure is caught by the next. Q: Is Microsoft 365 secure enough without extra email protection? A: Microsoft 365 ships with basic spam filtering, but anti-phishing policies, Safe Links, Safe Attachments and anti-impersonation rules all require manual activation and ongoing tuning. Left at defaults, tenants stay exposed to sophisticated phishing and impersonation. Microsoft Defender for Office 365 Plan 1, included in Business Premium, closes these gaps once a provider configures and monitors it properly. Q: How does email security differ from endpoint security? A: Email security inspects messages before they reach users - filtering content, authenticating senders and sandboxing attachments at the gateway. Endpoint security protects the device itself if a threat gets through, using behavioural detection and isolation. Both are essential: with 43% of UK businesses breached or attacked in 2025, relying on a single layer leaves dangerous gaps. Q: What is DMARC and do I need it? A: DMARC is an email authentication policy that stops criminals sending mail that appears to come from your domain. Working with SPF and DKIM, it tells receiving servers to reject messages that fail authentication. Yes - every business needs it. The NCSC recommends publishing DMARC at a `p=reject` policy to protect your customers and partners from spoofed mail using your brand. Q: How much does business email compromise cost? A: The average cost of the single most disruptive breach was £3,550 for UK businesses (DSIT 2025), but BEC runs far higher - the global median BEC loss is roughly $50,000 (Verizon DBIR 2025). Because BEC carries no malicious link or attachment, verifying payment and bank-detail changes out of band is the most effective control. Q: Can email security stop ransomware? A: It stops most of it. Email is the primary delivery route for ransomware, usually via attachments disguised as invoices or delivery notes. Attachment sandboxing detonates files in isolation before delivery, and time-of-click link checking catches URLs weaponised after sending - both block payloads that signature-based antivirus misses. Combined with staff training, this removes the most common ransomware entry point. --- # How to Protect Your Business from Phishing Attacks URL: https://amvia.co.uk/cybersecurity/email-security/protect-business-from-phishing Last updated: 2026-03 To protect your business from phishing, layer technical, process and human controls so that when one fails the others catch what gets through: email authentication (DMARC, SPF, DKIM), inbound filtering, multi-factor authentication, payment verification and staff training. AMVIA runs all of these as one managed email security service from its UK security operations centre. ## Why is phishing the top threat to UK businesses? Phishing is the single most common way criminals breach UK organisations, and the numbers are not improving. It exploits people, not just technology, which is why no firewall alone stops it. The defence is overlapping layers that each cover another's blind spot - managed end to end by AMVIA's cybersecurity team. In the past 12 months, 43% of UK businesses experienced a cybersecurity breach or attack - approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025). Among larger firms the figures climb: 65% of medium and 69% of large businesses reported breaches or attacks (DSIT 2025/26). In the 2025 edition, 85% of breached businesses reported phishing (DSIT 2025). Phishing is not a niche risk - it is the primary attack vector every UK business has to plan for, which is why it anchors our managed email security service. ## What are the main types of phishing attacks? Phishing is no longer just dodgy emails. Attackers now run multi-channel campaigns across email, SMS, voice and QR codes, and tailor the most damaging attacks to named individuals. Recognising each variant is the first step to defending against it. - Mass phishing - high-volume generic emails impersonating Royal Mail, HMRC, Microsoft or banks. Profitable even if one in a thousand recipients clicks. - Spear phishing - targeted emails using the victim's role, projects or colleagues to bypass suspicion. Far more effective than mass phishing. - Business email compromise (BEC) - the most financially damaging form: an attacker impersonates an executive, supplier or solicitor to trigger a payment or data transfer. Often contains no link or attachment, so technical filters struggle. See our dedicated business email compromise page. - Smishing and vishing - fraudulent SMS messages and phone calls, increasingly paired with email in the same campaign. - Quishing - malicious QR codes that hide the destination URL, defeating the "check the link" instinct users have learned for email. ## Which technical controls stop phishing? Technical controls are your first and most scalable line of defence: if a phishing email never reaches the inbox, no one can click it. The four that matter most are email authentication, filtering, Microsoft Defender for Office 365 and multi-factor authentication - configured together, not in isolation. Email authentication (DMARC, DKIM, SPF). SPF lists which servers may send mail for your domain; DKIM cryptographically signs outbound mail; DMARC ties them together and tells receiving servers to monitor, quarantine or reject failures. Publishing DMARC at `p=reject` stops criminals spoofing your domain to phish your customers and suppliers. The NCSC recommends DMARC for all UK organisations. We set this up on the DMARC, DKIM and SPF setup page. Inbound filtering. Modern filtering uses machine learning to catch phishing that signature tools miss, blocking malicious senders and scanning attachments before delivery. Microsoft Defender for Office 365. Adds anti-phishing policies, Safe Links (checks URLs at click time, catching time-delayed threats), Safe Attachments (detonates suspicious files in a sandbox) and anti-impersonation protection. Plan 1 covers the essentials for most SMEs; Plan 2 adds threat hunting and automated response. Multi-factor authentication (MFA). If credentials are stolen, MFA stops the attacker using them. Yet only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26) - so enforcing it closes one of the largest remaining gaps. The NCSC lists MFA among its top recommendations for organisations of every size. ## What process controls prevent business email compromise? Process controls catch the attacks that slip past technology - especially BEC, where the email looks legitimate and carries no payload. Two simple, enforced procedures stop most invoice fraud and payment-diversion attempts before money leaves the account. - Payment and supplier-change verification. Require that any change to supplier bank details, or any emailed payment request, is confirmed verbally using a phone number from your own records - never a number in the email. Document it, enforce it without exception. - Frictionless suspicious-email reporting. In Microsoft 365 the Report Message add-in enables one-click reporting to your security team. Every reported email is intelligence: if one employee got it, others probably did too. - A tested incident response plan. A basic plan defines who to call, how to contain (reset passwords, revoke sessions, isolate devices) and how to communicate. AMVIA helps clients build and test these as part of incident response. ## How does staff training reduce phishing risk? Training is the human layer - and it is the difference between a reported phishing email and a six-figure wire fraud. Effective programmes change behaviour, not just knowledge, by testing staff with realistic simulations and coaching at the point of failure. Regular simulated phishing campaigns send safe but realistic emails and measure who clicks, who enters credentials and who reports correctly. Employees who interact get immediate, targeted training - far more effective than an annual classroom session. Pair that with security awareness training covering email, SMS, voice and QR-code attacks, refreshed at least annually. AMVIA delivers monthly campaigns through its phishing simulation training programme with reporting on how susceptibility falls over time. ## In-house vs managed phishing protection - which is right? Most UK SMEs do not have the in-house time or specialist tooling to run layered phishing defence continuously. The table below compares running it yourself against a single managed provider. | | Capability | In-house / DIY | AMVIA managed email security | DMARC, DKIM, SPF | Configured once, rarely monitored | Configured to `p=reject` and monitored continuously | Microsoft Defender for Office 365 | Default policies, often untuned | Policies tuned, Safe Links/Attachments enforced | Phishing simulations | Ad hoc or none | Monthly campaigns with trend reporting | Threat monitoring | Business hours, best effort | 24/7 UK security operations centre | Incident response | Improvised under pressure | Documented, tested playbooks | Accountability | Split across vendors | One provider, security-first This is the AMVIA model: one accountable provider, security comes first, and the work is done by Microsoft-certified engineers - backed by our Cyber Essentials Plus certification. ## How much does phishing protection cost? Phishing protection is one of the most cost-effective security investments a UK business can make. The average cost of the single most disruptive breach is £3,550 for UK businesses (DSIT 2025), and materially higher for medium and large organisations. Layered protection combines tooling you may already own (Microsoft Defender for Office 365 is included in Microsoft 365 Business Premium at £16.90 per user/month, ex VAT - microsoft.com/en-gb) with managed configuration, monitoring and training. The cost of getting it right is a small fraction of the cost of a single successful business email compromise. ## Phishing prevention checklist for UK SMEs - DMARC published at `p=reject` for all company domains - SPF and DKIM configured for every sending source - Microsoft Defender for Office 365 anti-phishing policies enabled - Safe Links and Safe Attachments activated - MFA enforced on all user accounts - Written payment-verification policy requiring verbal confirmation - One-click suspicious-email reporting in place - Monthly phishing simulation campaigns - Annual security awareness training for all staff - Documented, tested incident response plan - Regular review of authentication reports and filtering effectiveness ## Frequently asked questions Q: What technical controls should a business deploy against phishing? A: Layer email gateway filtering with anti-impersonation policies, DMARC at `p=reject` to block domain spoofing, Safe Links for point-of-click URL scanning, Safe Attachments for sandbox detonation, and MFA on every account. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26), so enforcing MFA alone closes one of the largest gaps in most organisations' defences. Q: How do phishing simulation campaigns reduce risk? A: Simulations send realistic but harmless phishing emails and track who clicks, who enters credentials and who reports correctly. Employees who interact receive immediate, contextual training at the point of failure - far more effective than annual classroom sessions. Run consistently over successive campaigns, click rates fall, directly lowering exposure to the phishing behind 85% of breaches (DSIT 2025). Q: Why is a layered approach necessary to stop phishing? A: No single control catches every variant. Gateway filters block known threats but miss novel attacks; DMARC stops spoofing but not lookalike domains; MFA neutralises stolen credentials but not malware. Business email compromise often contains no links at all. Combining filtering, authentication, endpoint protection, payment verification and training means each layer compensates for the others' blind spots. Q: Does Microsoft 365 protect against phishing on its own? A: Microsoft Defender for Office 365 provides strong anti-phishing, Safe Links and Safe Attachments protection, but default policies are rarely tuned and need monitoring to stay effective. It also does not cover process controls like payment verification or the human layer of staff training. Defender is a core component of layered protection, not a complete defence by itself. Q: How quickly can phishing protection be put in place? A: Core technical controls - DMARC monitoring, Defender policy tuning and MFA enforcement - can typically be deployed within days for a Microsoft 365 environment. Phishing simulation and awareness training then run continuously to build resilience over time. AMVIA starts with a free security audit to identify the gaps that matter most first. --- # What Is Business Email Compromise (BEC)? UK SME Guide URL: https://amvia.co.uk/cybersecurity/email-security/business-email-compromise Last updated: 2026-03 Business email compromise (BEC) is a targeted fraud where an attacker impersonates a trusted executive, supplier or solicitor to trick staff into transferring money or data. There is no malware to detect - it exploits human trust. AMVIA blocks it with managed Microsoft-led email security: one provider, security-first, Microsoft-certified. BEC is the most financially damaging end of the phishing spectrum and the costliest email threat facing UK SMEs today. This page explains how the attacks work, why standard filters miss them, and the technical and procedural controls that stop them - backed by AMVIA's managed cybersecurity team and specialist email security service. ## What is business email compromise? Business email compromise is a social-engineering attack in which a criminal poses as someone the victim trusts - usually a senior leader, supplier or legal representative - and requests an urgent payment or change of bank details. Unlike mass phishing, BEC is highly targeted and often follows weeks of reconnaissance into the target organisation. Verizon's DBIR 2025 puts global BEC losses at around $6.3 billion, with a median loss of roughly $50,000 per incident (global figures). According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a breach or attack in the past 12 months - around 612,000 businesses - with impersonation reported by 35% of those experiencing breaches. For a small firm, a single successful BEC attack can be catastrophic. ## What are the common types of BEC attack? BEC takes several forms, but all share one trait: a believable impersonation that pressures staff to move money fast. The five patterns below account for the overwhelming majority of UK incidents, and each targets a specific business process - payments, payroll or supplier onboarding. | | BEC variant | How it works | Primary target | CEO fraud | Attacker poses as a senior leader demanding an urgent, confidential transfer that bypasses approval | Finance team | Invoice redirection (mandate fraud) | Spoofed supplier email claims bank details have changed; payments divert to the criminal | Accounts payable | Supplier impersonation | Lookalike domain (e.g. amvia-invoices.com) sends convincing invoices mirroring real branding | Accounts payable | Payroll diversion | Attacker impersonates an employee to change payroll bank details before the next run | HR / payroll | Solicitor impersonation | Criminal poses as a legal representative citing deadlines on a property or M&A transaction | Finance / directors CEO fraud exploits deference to leadership and is most effective when the real CEO is travelling - information attackers harvest from social media and out-of-office replies. Invoice redirection is dangerous because it can arrive during a genuine payment cycle, looking entirely routine. ## Why are BEC attacks so effective? BEC works because it exploits human trust, not technical vulnerabilities. The emails carry no malicious links or attachments for filters to catch, come from plausible addresses, and are timed to coincide with real business events such as a supplier invoice falling due or the CEO being away. - Attackers research LinkedIn, Companies House records and company websites to map hierarchies and identify targets - Emails are crafted to match the writing style, tone and formatting of the person being impersonated - Urgency and authority discourage staff from following normal verification steps - Many attacks run over weeks, with preliminary emails building credibility before the fraudulent request - Requests are often timed for late Friday or just before a bank holiday, when staff are rushed The DSIT Cyber Security Breaches Survey 2025 found 85% of breaches involved phishing, the broad category BEC sits within. BEC is the most targeted and dangerous end of that spectrum, where an attacker invests real effort into a single high-value deception. Pairing email security with phishing protection closes the gap that generic filtering leaves open. ## What do real-world BEC attacks look like? Real UK incidents follow a predictable shape: a believable sender, a plausible reason and the absence of a second verification step. Two scenarios reported to Action Fraud illustrate how routine these frauds appear to the staff who fall for them. A UK professional services firm of forty staff received an email appearing to come from the managing director, requesting an urgent transfer of £28,000 to a new supplier. It referenced a genuine project and used the MD's usual sign-off. The finance manager paid it. The MD's account had not been hacked - the attacker had registered a lookalike domain and studied the firm's email patterns for two weeks. In a second case, a property management company received notice from what looked like its maintenance contractor that bank details had changed. The accounts team updated the record without a phone call. Three months of payments - totalling over £15,000 - were diverted before the genuine contractor queried the missing funds. ## How do you prevent business email compromise? BEC prevention is layered: technical controls stop domain spoofing, identity controls stop account takeover, and procedural controls stop fraudulent payments leaving your account. No single measure is sufficient - together they remove the gaps each attack relies on. - Email authentication. Publish DMARC, DKIM and SPF records. A DMARC policy at `p=reject` is the standard recommended by the NCSC and stops criminals spoofing your domain against customers and partners. - Anti-impersonation filtering. Microsoft Defender for Business flags emails where a display name matches a known executive but the sending domain does not, and detects lookalike domains before messages reach inboxes. - Multi-factor authentication. Enforced multi-factor authentication on every account - especially finance, HR and leadership - sharply reduces the account takeover that lets attackers send BEC from a genuine address. - Multi-step payment verification. No email-only payment instruction should be actioned without calling the requester on a number held on file - never one supplied in the email. This single control stops most BEC that reaches the payment stage. - Staff training. Regular training and simulated BEC exercises teach finance, HR and PA staff to spot urgency, secrecy and process-bypass requests, and to report them correctly. - Supplier change controls. Any request to change supplier bank details must be verified through a pre-agreed channel, enforced consistently regardless of who appears to be asking. The DSIT Cyber Security Breaches Survey 2025/26 found only 25% of UK businesses have a formal incident response plan - so most have no defined process for what happens after a suspicious email is reported. A managed incident response capability closes that gap. ## In-house controls vs AMVIA managed email security Most SMEs can configure some of these controls, but maintaining them - and monitoring for the impersonation patterns that change weekly - is where in-house effort breaks down. The comparison below shows where a managed service earns its place. | | Capability | Typical in-house setup | AMVIA managed email security | DMARC at p=reject | Often left at p=none or unmonitored | Configured, enforced and monitored | Anti-impersonation rules | Default Microsoft 365 settings | Tuned Defender impersonation policies | Lookalike domain detection | Rarely configured | Active monitoring and alerting | MFA enforcement | Partial, gaps for execs | Enforced across all accounts | Threat monitoring | Business hours, reactive | 24/7 in-house SOC, proactive | Incident response | Usually no documented plan | Defined response and recovery ## What should you do if you suspect a BEC attack? Act immediately. Contact your bank to request a recall of any transferred funds - speed is critical, as money is often moved through several accounts within hours. Report the incident to Action Fraud and the NCSC, and preserve all relevant emails as evidence. If an email account has been compromised, reset the password at once, revoke all active sessions, and review recent sent items and mailbox rules for attacker activity. AMVIA's managed detection and response team handles this containment for clients around the clock. ## How much does managed email security cost? AMVIA's managed email security is priced per user and built on Microsoft 365 licensing, so cost scales with headcount rather than a large upfront outlay. Microsoft Business Premium - which includes Defender for Office 365 anti-impersonation protection - lists at £16.90 per user per month (microsoft.com/en-gb, ex VAT, annual). For comparison, Microsoft 365 licence list prices are Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month (ex VAT, annual). AMVIA layers configuration, DMARC enforcement, monitoring and staff awareness on top of the Premium licence as a managed service. Set against a global median BEC loss of roughly $50,000 per incident (Verizon DBIR 2025), the protection pays for itself many times over. ## How AMVIA helps UK businesses prevent BEC AMVIA deploys Microsoft Defender for Office 365 to detect BEC patterns - lookalike domain spoofing, internal executive impersonation and unusual sending behaviour. We configure DMARC at `p=reject` to stop your domain being used in outbound fraud, enforce MFA across every account, and provide ongoing monitoring, alerting and staff awareness support. That is the AMVIA model: one provider, security-first, Microsoft-certified engineers running it for you. With 65% of medium and 69% of large businesses reporting breaches or attacks (DSIT 2025/26), proactive BEC protection is not optional - it is a business necessity. ## Frequently asked questions Q: How can I spot a BEC email before authorising a payment? A: Examine the full sender address for lookalike domains such as amv1a.co.uk instead of amvia.co.uk, and be wary of any payment request citing unusual urgency or secrecy. Always verify by phoning the requester on a number already held on file - never a number given in the email. Overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), making this step indispensable. Q: What is invoice redirection fraud? A: Invoice redirection, also called mandate fraud, is a BEC variant where criminals impersonate a supplier and ask you to update their bank details. Future payments then divert to the attacker's account. A written policy requiring telephone confirmation of any bank-detail change - using a pre-agreed number - stops the vast majority before funds leave your account. Q: Why do standard email filters miss BEC messages? A: BEC emails usually contain no malicious links or attachments, so conventional filters have nothing to flag. The threat is the social engineering - a convincing impersonation of a CEO or supplier. Anti-impersonation rules in Microsoft Defender for Office 365 and DMARC at p=reject catch domain-spoofing, but the average cost of the most disruptive breach is £3,550 (DSIT 2025), and a single BEC attack can far exceed that. Q: Does multi-factor authentication stop BEC? A: MFA does not stop every BEC attack, but it removes one of the most dangerous routes. If an attacker steals a password, MFA blocks them from logging in and sending fraud from a genuine, trusted address - which makes detection far harder. Enforced MFA on finance, HR and leadership accounts is a non-negotiable baseline control. Q: Is BEC covered by cyber insurance? A: Many cyber and crime policies cover BEC losses, but cover varies and insurers increasingly require specific controls - enforced MFA, DMARC and documented payment verification - before they pay out. Check your policy wording, and treat the technical and procedural controls on this page as both fraud prevention and a condition of cover. Q: Who in my business is most at risk from BEC? A: Finance, HR and senior PA staff are the most common targets because they control payments, payroll and executive diaries. Attackers also target directors directly through solicitor and M&A impersonation. Prioritise MFA, training and payment-verification controls for these roles first, then extend them across the business. --- # What Is DMARC and Why Does It Matter for UK Businesses? URL: https://amvia.co.uk/cybersecurity/email-security/what-is-dmarc Last updated: 2026-03 DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication protocol that lets you tell receiving mail servers to reject messages that fake your domain. It builds on SPF and DKIM to stop criminals spoofing yourcompany.co.uk - and managing it well is the kind of security-first job AMVIA does for UK SMEs every week. ## What does DMARC actually do? DMARC stops anyone from sending email that looks like it came from your domain. Without it, a criminal can send an invoice or payment request that appears to come from yourcompany.co.uk, and the recipient's mail server has no reliable way to tell it apart from the real thing. DMARC fixes that. It works by checking two things receiving servers cannot otherwise enforce: that the visible "From" domain *aligns* with the domain SPF or DKIM authenticated, and what to do - deliver, quarantine, or reject - when a message fails. Domain spoofing is a primary enabler of phishing, and phishing is the dominant attack route against UK businesses, so closing this gap matters. DMARC is one of the core controls in any serious managed cybersecurity and email security programme. The NCSC recommends DMARC for all UK organisations and mandates it for government email domains. ## How do SPF, DKIM and DMARC work together? DMARC does not work alone - it ties together two older standards. SPF checks which servers are allowed to send for your domain. DKIM cryptographically signs each message. DMARC adds alignment and an enforcement instruction on top, turning two partial checks into a single, enforceable policy. - SPF (Sender Policy Framework) - a DNS record listing the mail servers authorised to send for your domain. Receiving servers check the sending IP against that list. SPF only validates the envelope sender (Return-Path), not the "From" address the recipient sees. - DKIM (DomainKeys Identified Mail) - adds a cryptographic signature using a private key on your mail server, verified against a public key in your DNS. It proves the message came from an authorised server and was not altered in transit. - DMARC - requires the visible "From" domain to align with the SPF- or DKIM-authenticated domain, then tells the receiving server whether to deliver, quarantine, or reject failures. | | Standard | What it checks | What it cannot do alone | SPF | Authorised sending IPs (envelope sender) | Cannot protect the visible "From" header | DKIM | Message signature and integrity | Cannot enforce a policy on failures | DMARC | Alignment + enforcement action | Needs SPF and/or DKIM beneath it Without alignment, an attacker can pass SPF using a domain they control while spoofing a different domain in the header the recipient actually reads. DMARC is what closes that loophole. ## What are the three DMARC policy levels? DMARC is published as a DNS TXT record with three policy settings, adopted progressively as you gain confidence in your configuration. You start in monitor mode, tighten to quarantine, then enforce with reject - the only level that fully blocks spoofing. | | Policy | What happens to failing mail | When to use it | `p=none` (monitor) | Delivered normally; aggregate/forensic reports sent | Initial deployment - discover every legitimate sender | `p=quarantine` | Delivered to spam/junk | Intermediate test step before full enforcement | `p=reject` | Rejected outright, never delivered | Final state - full protection against spoofing The NCSC recommends every UK organisation aim to reach `p=reject`. Until you get there, your domain still offers attackers an open door. ## Why do UK businesses need DMARC? Because email is still the primary attack vector, and an unprotected domain is a weapon criminals can point at your own customers, suppliers and staff. Without DMARC at `p=reject`, fraudulent invoices, payment-redirect requests, and business email compromise (BEC) all become easier to pull off in your name. The numbers make the case. 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025), and 85% of breaches experienced by UK businesses involved phishing (DSIT 2025). 65% of medium and 69% of large businesses were affected (DSIT 2025/26). The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025). There is a deliverability upside too. Google and Microsoft treat DMARC compliance as a positive spam-filtering signal, so genuine mail from a `p=reject` domain is more likely to land in the inbox. Google and Yahoo introduced requirements in 2024 mandating that bulk senders implement DMARC, confirming the industry-wide shift to enforcement. Pairing DMARC with phishing protection covers both the inbound and the impersonation side of email risk. ## How do you implement DMARC step by step? Implementation is a phased process, not a single switch. Rushing straight to `p=reject` will block legitimate mail. The safe path audits every sender first, then tightens enforcement in stages over roughly four to eight weeks. 1. Audit your sending sources - list every system that sends as your domain: Microsoft 365 or Google Workspace, marketing tools (Mailchimp, HubSpot), CRMs (Salesforce, Dynamics 365), transactional services, and helpdesk systems. Miss one and its mail will fail once you enforce. 2. Configure SPF and DKIM - publish an SPF record covering all authorised servers and enable DKIM signing on your primary platform and every third-party sender, usually via a CNAME or TXT record. 3. Publish DMARC at `p=none` - add the record with a reporting address and monitor aggregate reports for four to eight weeks to confirm legitimate sources pass. 4. Move to `p=quarantine` - once monitoring is clean, tighten to quarantine for a further two to four weeks and resolve any legitimate mail caught incorrectly. 5. Enforce with `p=reject` - switch to reject so spoofed mail is blocked. Keep reviewing reports as your sending services change. ## How should you monitor DMARC over time? DMARC is not set-and-forget. Your sending landscape shifts - new marketing tools, a changed CRM, a service a staff member signs up for - and each change can create an SPF or DKIM gap that breaks legitimate mail under `p=reject` or goes unseen under a weaker policy. Ongoing report review is what keeps enforcement safe. This is where managed monitoring earns its keep. Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26), so DMARC reports often become the first early-warning signal of an email-based attack on a domain. Reviewed regularly, they flag both misconfigurations and active spoofing attempts before they cause damage - which is why DMARC sits naturally alongside incident response. ## How does AMVIA implement and manage DMARC? AMVIA configures DMARC, SPF and DKIM for UK SMEs, manages the phased progression from `p=none` through `p=quarantine` to `p=reject`, and monitors aggregate reports so your domain stays protected as your business evolves. One provider, security-first, Microsoft-certified engineers - no hand-offs between vendors. Typical implementation is four to eight weeks for straightforward setups, longer where multiple marketing platforms, CRMs or third-party senders are involved. It runs as part of our managed email filtering and email security service, and complements Microsoft Defender for Business for organisations standardising on Microsoft 365. Contact AMVIA on 0333 733 8050 to discuss DMARC implementation for your business. ## Frequently asked questions Q: What roles do SPF, DKIM and DMARC each play? A: SPF publishes a DNS record listing the mail servers authorised to send from your domain. DKIM attaches a cryptographic signature proving the message was not altered in transit. DMARC ties both together by enforcing domain alignment and instructing receiving servers to quarantine or reject failures. Without DMARC, failed SPF or DKIM checks may still be delivered. Q: Why progress DMARC to p=reject rather than leaving it at p=none? A: At `p=none`, DMARC only monitors - fraudulent emails spoofing your domain are still delivered. Moving to `p=reject` instructs receiving servers to block them outright. Since 85% of breaches experienced by UK businesses involved phishing (DSIT 2025), and domain spoofing enables many of those attacks, `p=reject` is the only policy that actively protects your customers and partners. Q: Will DMARC block legitimate emails from third-party services? A: It can, if those services are not in your SPF record or set up with DKIM before enforcement begins. That is why implementation is phased: four to eight weeks at `p=none` to audit all legitimate senders - marketing platforms, CRM tools, helpdesk systems - then `p=quarantine` for testing, and finally `p=reject` once every authorised sender passes cleanly. Q: How long does DMARC take to implement? A: For a business with a straightforward email setup, expect four to eight weeks to move safely from `p=none` to `p=reject`. Organisations using several marketing platforms, multiple CRMs, or many third-party sending services need longer, because every one of those senders must be authenticated through SPF and DKIM before enforcement is applied. Q: Is DMARC required for UK businesses? A: DMARC is not law, but the NCSC recommends it for all UK organisations and mandates it for government domains. Google and Yahoo have required bulk senders to use DMARC since 2024, and a growing number of cyber insurance policies expect email authentication. In practice, any UK business sending email to customers should treat DMARC as essential. Q: Does DMARC improve email deliverability? A: Yes. Google and Microsoft treat DMARC compliance as a positive signal in spam filtering, so genuine mail from a domain enforcing `p=reject` is more likely to reach the inbox than mail from a domain without DMARC. Authentication gives receiving servers confidence the message is genuine, which reduces the chance of legitimate email being filtered. --- # How to Set Up DMARC DKIM and SPF for Your Domain URL: https://amvia.co.uk/cybersecurity/email-security/dmarc-dkim-spf-setup Last updated: 2026-08-28 DMARC, DKIM and SPF setup means publishing three DNS records that prove email from your domain is genuine, then enforcing a policy that rejects anything spoofed. Done in the wrong order it blocks real mail, so AMVIA stages every rollout from monitoring through to p=reject - one provider, security-first, Microsoft-certified. It is the cheapest, highest-leverage control in managed cybersecurity: one afternoon of DNS work closes the door on the impersonation attacks behind most phishing. This page sits in our email security hub alongside what DMARC actually is. ## What are DMARC, DKIM and SPF? They are three DNS-based email authentication standards that work together to prove a message claiming to come from your domain was genuinely sent by an authorised server. SPF lists who can send. DKIM signs the message. DMARC enforces a policy and reports back. Without all three, anyone can spoof your domain. Phishing is the threat they exist to stop. According to the DSIT Cyber Security Breaches Survey 2025, 85% of UK cyber breaches involve phishing (DSIT 2025), and 43% of UK businesses experienced a breach or attack in the past 12 months (DSIT 2025) (gov.uk). A large share of those attacks exploit domains with no enforcement policy, where impersonation carries no technical barrier at all. | | Standard | What it checks | What it cannot do alone | SPF | Is the sending server on your authorised list? | Only checks the envelope sender, not the visible From address; breaks on forwarding | DKIM | Is the message cryptographically signed and unmodified? | Says nothing about what to do when a check fails | DMARC | Do SPF/DKIM pass *and* align with the visible From domain? | Needs at least one of SPF or DKIM passing to act ## How does each standard work? Each tackles a different gap. SPF publishes the IP addresses and mail servers allowed to send for your domain. DKIM attaches a cryptographic signature using a private key, with the public key in DNS. DMARC ties the two together, checks domain alignment, and tells receivers what to do when authentication fails. - SPF (Sender Policy Framework) - a DNS TXT record listing authorised senders. Simplest to deploy, but it only validates the SMTP envelope sender, not the From address users see, and it fails when mail is forwarded. - DKIM (DomainKeys Identified Mail) - signs every outbound message with a private key; receivers verify it against the published public key. It survives forwarding and proves the body was not altered in transit. - DMARC (Domain-based Message Authentication, Reporting and Conformance) - sets the policy (p=none, p=quarantine or p=reject), enforces alignment between the authenticated domain and the visible From domain, and emails you aggregate reports showing every server sending as your domain. The alignment check is the part attackers cannot beat. They can pass SPF using their own domain, but they cannot make that domain align with *your* From address - so a DMARC record at p=reject discards the spoof before it reaches your customer. ## Why do UK SMEs need email authentication? Because your domain is an attack surface whether you protect it or not. An unauthenticated domain lets criminals send invoices, payment-redirection requests and credential-harvesting links that land in your clients' inboxes wearing your name. The cost of getting impersonated is borne by everyone you email. The financial stakes are real: the average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025). Yet preparation lags - only 25% of UK businesses have a formal incident response plan (DSIT 2025/26). Email authentication is one of the few preventive controls that materially lowers the odds of ever needing that plan, which is why it pairs naturally with anti-phishing protection. There is now a compliance driver too. Google and Microsoft require DMARC for bulk senders, and the NCSC actively promotes DMARC through its Mail Check service (ncsc.gov.uk). For UK businesses, authentication has moved from best practice to baseline expectation. ## How do you set up DMARC, DKIM and SPF safely? You stage it. The single biggest mistake is jumping to enforcement before you know every legitimate sender, which blocks real mail. AMVIA runs a defined sequence - audit, publish, monitor, then advance - so enforcement only arrives once the data proves it is safe. 1. Audit every sender. List everything that mails as your domain: Microsoft 365 or Google Workspace plus CRM, marketing, invoicing, helpdesk and booking tools. A missed sender fails authentication once you enforce. 2. Publish SPF. Create one TXT record covering all legitimate sources. Watch the 10 DNS lookup limit - too many third-party includes makes SPF fail for *all* mail. AMVIA flattens to direct IPs and consolidates includes to stay under it. 3. Configure DKIM. Enable signing on your platform. For Microsoft 365 we generate the key pair and publish the public key in Exchange Online (learn.microsoft.com); third-party senders are signed wherever supported. 4. Deploy DMARC at p=none. Monitoring mode collects aggregate reports without touching delivery, so you see reality before you act. 5. Review reports for 30–60 days. Authenticate every legitimate sender that is failing before you go further. Skipping this window is the top cause of blocked mail. 6. Advance to enforcement. Move to p=quarantine, then p=reject. AMVIA typically holds quarantine for two to four weeks, watching reports at each step to confirm nothing legitimate is caught. ## What do the DMARC policy modes mean? The policy tells receiving servers what to do with mail that fails authentication. You move through them in order so you never enforce blind. | | Policy | Effect on failing mail | When to use it | `p=none` | Delivered as normal; only reported | Start here - monitor and discover all senders | `p=quarantine` | Routed to spam/junk | Once senders are authenticated, as a safety stage | `p=reject` | Discarded outright | The goal - full protection against spoofing ## How does AMVIA manage email authentication? AMVIA configures SPF, DKIM and DMARC for UK businesses as part of its managed email security service, then keeps it current. The build starts with a full sender audit and runs through monitoring to enforcement on a defined timeline. DMARC is included in our managed service or available as a standalone engagement. DMARC is not set-and-forget. New tools start sending as your domain; attackers generate failed-authentication reports worth investigating. We monitor those reports continuously, fold the work into our wider Microsoft Defender for Business and email controls, and act on spoofing attempts as they appear. NCSC records 49,248 security certifications issued in 2025 (NCSC) - proof that authentication baselines are now mainstream, not optional. ## Email authentication checklist - SPF record published and validated for your domain - DKIM signing enabled for Microsoft 365 (or your mail platform) - DMARC record deployed at minimum p=none to collect reports - All third-party senders identified and authenticated before enforcement - DMARC policy advanced to p=quarantine, then p=reject - DMARC applied to every domain you own, including parked and inactive ones ## Frequently asked questions Q: Do I need all three - SPF, DKIM and DMARC? A: Yes. SPF and DKIM provide the authentication, but without DMARC there is no enforcement policy and no reporting, so a failed check has no consequence. DMARC also needs at least one of SPF or DKIM passing before it can apply a policy. The three together give the most complete protection against domain spoofing. Q: Will setting up DMARC break my existing email? A: Not if it is staged. Start at p=none, review aggregate reports, and authenticate every legitimate sender before moving to quarantine or reject. That monitoring window surfaces the CRM, marketing and invoicing tools that mail as your domain. Rushing straight to p=reject without the audit is the single most common cause of blocked legitimate mail. Q: How long does DMARC, DKIM and SPF setup take? A: For a clean Microsoft 365 environment with few third-party senders, AMVIA can publish SPF and DKIM in one session and reach DMARC quarantine within a few weeks once reports are reviewed. Environments with many senders - marketing platforms, CRM, helpdesk, invoicing - usually need six to eight weeks to reach full enforcement safely. Q: What is the SPF 10 DNS lookup limit? A: SPF allows a maximum of 10 DNS lookups when evaluating a record. Each `include` for a third-party sender consumes lookups, so businesses with several services can exceed the cap, at which point SPF fails for all mail. AMVIA stays under the limit by using direct IP addresses where possible and consolidating include mechanisms. Q: Does Microsoft 365 do this automatically? A: No. Microsoft 365 enables a default SPF entry and supports DKIM and DMARC, but DKIM signing is not switched on for your custom domain by default, and there is no DMARC record until you publish one. Without explicit configuration your domain is still spoofable. AMVIA enables and aligns all three for the domains you actually send from. Q: What does p=reject actually do? A: p=reject instructs receiving mail servers to discard any message that fails SPF and DKIM and does not align with your From domain - it never reaches the inbox or the spam folder. It is the end state of a DMARC rollout and the only policy that fully blocks impersonation. You reach it only after monitoring confirms every legitimate sender passes. --- # Business Email Filtering and Anti-Spam Service URL: https://amvia.co.uk/cybersecurity/email-security/email-filtering Last updated: 2026-03 Email filtering inspects every inbound message at the gateway and blocks spam, phishing, malware and spoofed senders before they reach a user's inbox. AMVIA runs filtering as a fully managed service on the Barracuda platform, tuned by UK engineers and layered on top of Microsoft 365 - one provider, security-first. Email is still the front door for most attacks on UK SMEs, which is why filtering sits at the centre of our managed cybersecurity programme and our wider email security stack. This page explains what the service blocks, how we deploy it, and how it compares to relying on Microsoft 365 defaults alone. ## What does an email filtering service include? A managed email filtering service routes your inbound mail through a dedicated filtering gateway before delivery, applies layered detection, and gives you engineers who own the configuration. You get protection without the day-to-day administration falling on your internal team. - Proactive protection - continuous monitoring and threat detection that stops malicious mail before it lands in an inbox. - Expert management - UK-based engineers handle configuration, policy updates and incident response, so your team doesn't have to. - Regular reporting - monthly reports on filtering volumes, incidents handled and recommended improvements. - Dedicated support - direct access to your account team for changes, releases and escalations, with critical issues responded to within one hour. ## How does email filtering work? Filtering works by sitting in front of your mail flow as the first MX hop. Every inbound message is scored on sender reputation, content and authentication (SPF, DKIM and DMARC) before it is allowed through, quarantined or rejected. Deployment is a four-step process with zero downtime. 1. Email flow analysis - we map your current routing, measure spam and threat volumes, and review existing rules. 2. Filter deployment - rules for spam, phishing, malware and spoofing are configured for your domain and industry. 3. MX cutover - routing is switched to pass through our filtering platform with no lost mail during the change. 4. Ongoing tuning - we review quarantine reports, adjust sensitivity and whitelist legitimate senders to keep false positives near zero. Sender authentication is the backbone of accurate filtering. If your records are not configured correctly, spoofed mail slips through - see our guide to DMARC, DKIM and SPF setup for the records that make filtering reliable. ## Why do UK SMEs need email filtering? UK businesses face a constant stream of email-borne attacks, and phishing is the most common entry point. Filtering removes the bulk of that volume before a human ever has to make a judgement call - which is the single highest-leverage email control most SMEs can deploy. - 43% of UK businesses experienced a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025, DSIT). - 85% of businesses identifying a breach pointed to phishing as the threat type (Cyber Security Breaches Survey 2025, DSIT). - £3,550 average cost of the most disruptive breach for UK businesses. The NCSC ranks phishing among the most damaging threats to UK organisations and recommends layered technical controls, including mail filtering and authentication, in its phishing guidance. Filtering paired with user awareness through phishing protection closes the gap that defaults leave open. ## Microsoft 365 filtering vs managed gateway filtering Microsoft 365 ships with Exchange Online Protection (EOP), a capable baseline - but the default policies are deliberately permissive, and tuning them is a job in itself. A managed gateway adds stricter attachment handling, better quarantine control and an engineer who owns the outcome. | | Capability | Microsoft 365 EOP (default) | AMVIA managed filtering | Spam and bulk mail | Baseline scoring | Tuned reputation + content scoring | Attachment policy | Standard blocks | Stricter rules incl. password-protected archives | Quarantine management | Self-service, lightly tuned | Daily digests + engineer tuning | SPF/DKIM/DMARC enforcement | Available, not configured for you | Configured and monitored for you | Who owns false positives | Your internal admin | AMVIA engineers Microsoft documents EOP's baseline scope in its Exchange Online Protection overview. Where you run Microsoft 365, filtering complements Microsoft Defender for Business rather than replacing it. ## How quickly is email filtering deployed? For most Microsoft 365 environments, filtering is live within one to two business days. There is no downtime and no disruption to mail flow - the MX cutover is staged so messages keep flowing throughout. Detection then improves over the first few weeks as we tune against your real traffic. If you have already had an incident, pair filtering with managed detection and response so a missed message is caught and contained quickly rather than discovered late. ## Why choose AMVIA for email filtering? AMVIA is a security-first managed provider, not a telecoms reseller bolting on a filter. Our engineering and support team operates from Sheffield, understands UK compliance requirements, and runs filtering as part of a single accountable security stack. - Sheffield-based, UK-focused - engineering and support delivered from the UK. - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status. - 1,200+ UK businesses protected - across legal, finance, healthcare and professional services. - Fast, responsive support - critical issues responded to within one hour, by phone, email and portal, with dedicated account managers. ## Frequently asked questions Q: What is managed email filtering? A: Gateway inspection of every inbound message - blocking spam, phishing, malware and spoofed senders before they reach an inbox - run as a managed service with policies tuned to your business rather than left on vendor defaults. Q: Why do we need filtering beyond the built-in spam filter? A: Default filters optimise for not annoying you; attackers optimise for beating defaults. Impersonation, lookalike domains and novel payloads are exactly what tuned, managed filtering plus authentication enforcement (SPF, DKIM, DMARC) exists to catch - and misconfigured DMARC is still the norm in UK SMEs. Q: Will filtering block legitimate email? A: Any filter can false-positive - the difference in a managed service is that quarantine is reviewed, release is quick, and policies are tuned from real traffic instead of set-and-forgotten. The goal is aggressive on threats, invisible on business mail. Q: How does email filtering fit with the rest of our security? A: Email is the front door - the average most-disruptive breach costs UK businesses £3,550 (DSIT 2025) and 85% of breaches involve phishing. Filtering cuts the volume that reaches humans, awareness training handles the residue, and endpoint protection catches what survives both. Layers, deliberately. --- # Advanced Email Threat Protection for UK SMEs URL: https://amvia.co.uk/cybersecurity/email-security/advanced-email-threat-protection Last updated: 2026-03 Advanced email threat protection is a security layer that defends against sophisticated phishing, malicious attachments, impersonation and zero-day email attacks that standard spam filters let through. It adds real-time link scanning, attachment sandboxing and machine-learning analysis. AMVIA configures and runs it for you on Microsoft Defender and Barracuda - one provider, security-first, Microsoft-certified. Email is still the way most attackers get in. If you only have the spam filter that ships with your mailbox, you are catching yesterday's threats and missing the targeted ones aimed squarely at your finance and leadership inboxes. This page explains what advanced protection adds, how AMVIA deploys it, and what it costs - and links back to our managed cybersecurity pillar and the wider business email security hub. ## What is advanced email threat protection? Advanced email threat protection extends basic filtering with four capabilities standard tools lack: attachment sandboxing (detonating files in isolation before delivery), click-time URL rewriting, impersonation and display-name detection, and machine-learning phishing analysis. Where basic filtering relies on known signatures and reputation lists, advanced protection inspects behaviour - so it catches attacks no one has seen before. The practical difference is what reaches your users: - Basic filtering blocks known spam and previously-reported malware by signature and sender reputation. - Advanced protection opens attachments in a sandbox, checks every link at the moment it is clicked, flags emails that impersonate your CEO or suppliers, and scores message intent with ML. - Managed advanced protection adds a human team that tunes the policies, reviews what was blocked, and responds when something gets through. ## What is included in AMVIA's service? AMVIA delivers advanced email threat protection as a fully managed service: we design the threat policies, deploy them with zero downtime, monitor what is blocked, and report monthly. You get a single accountable provider for email security rather than a console you have to learn and babysit. - Proactive protection: continuous monitoring and threat detection on Microsoft Defender for Office 365 and the Barracuda email security suite. - Expert management: UK-based, Microsoft-certified engineers handle configuration, tuning and incident response. - Monthly reporting: clear reports on threats blocked, incidents handled and recommended improvements. - Dedicated support: direct access to your account team for changes and escalations, with critical issues responded to within one hour. ## How does AMVIA deploy email threat protection? Deployment is a four-step process designed to add protection without losing a single email. We audit your current mail flow first, configure policies to your industry's threat profile, then cut over and tune continuously. For a standard Microsoft 365 tenant the policy work is measured in hours, not weeks. 1. Email audit: we map your mail flow, find gaps, and review existing filtering rules. 2. Policy configuration: custom policies for phishing, spoofing, malware and impersonation, tuned to your sector. 3. Cutover: for gateway deployments we update MX records and route mail through advanced filters with zero downtime; for Microsoft 365 we enable Defender for Office 365 policies in-place. 4. Monitoring and tuning: ongoing review of blocked threats, false-positive checks and quarterly policy adjustments. ## Why do UK SMEs need advanced email threat protection? UK SMEs need it because phishing is now the dominant attack route and basic filters do not stop targeted campaigns. Government data shows email-borne attacks are the most common breach UK businesses face, and the cost of a serious incident runs into thousands of pounds plus days of disruption. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach in the last year, and around 85% of those breaches involved phishing. The same survey puts the average cost of the single most disruptive breach at £3,550 for UK businesses - and much of the ransomware behind those figures arrives by email. The NCSC's phishing guidance confirms layered technical defence plus user awareness as the recommended approach. This is exactly why advanced protection pairs with phishing protection and defends against business email compromise, the highest-value email fraud SMEs face. ## Advanced protection vs basic email filtering | | Capability | Basic email filtering | Advanced threat protection | Known spam and malware | Yes | Yes | Attachment sandboxing | No | Yes | Click-time URL scanning | No | Yes | Impersonation / CEO-fraud detection | No | Yes | Zero-day phishing (ML analysis) | No | Yes | Managed tuning and response | No | Yes (with AMVIA) Standard email filtering is a sensible baseline. Advanced protection is what stops the attacks built specifically to slip past that baseline. ## How much does advanced email threat protection cost? For most UK SMEs the most cost-effective route is Microsoft 365 Business Premium, which includes Microsoft Defender for Office 365 Plan 1 at no extra licence cost. Beyond that, you are paying for management - the policy tuning and monitoring that turns a licence into real protection. - Microsoft Defender for Office 365 Plan 1 is included in Microsoft 365 Business Premium, priced at £16.90 per user/month (ex VAT, annual). It is not included in Business Basic or Business Standard. - Businesses on lower-tier licences can add Defender for Office 365 Plan 1 standalone, or run a third-party gateway such as Barracuda. - AMVIA's managed Microsoft Defender for Business wraps the licence in configuration, monitoring and reporting. AMVIA's own managed service is quoted per environment after the email audit - get a fixed figure from our free security audit. ## Frequently asked questions Q: What is advanced email threat protection? A: A security layer above standard filtering that targets the attacks default filters miss: sophisticated phishing, malicious attachments detonated in sandboxes, CEO/supplier impersonation, and zero-day payloads. It's the difference between blocking bulk spam and blocking the email that starts a breach. Q: How is this different from normal spam filtering? A: Spam filtering sorts unwanted volume; advanced protection interrogates intent - sandboxing attachments before delivery, rewriting and checking links at click time, and analysing sender behaviour for impersonation. The two do different jobs, and businesses being targeted (rather than sprayed) need both. Q: What is business email compromise and does this stop it? A: BEC is impersonation fraud - an email that looks like your MD or a supplier asking finance to pay an invoice. Advanced protection catches the technical markers (lookalike domains, display-name spoofing, unusual sender patterns); pairing it with payment-process controls closes the loop. Q: Does this work with Microsoft 365? A: Yes - it layers over Microsoft 365 rather than replacing it, adding independent detection on top of Microsoft's own. For businesses standardised on M365, that layered model plus tenant hardening is the practical defence architecture. --- # Employee Phishing Simulation Training Programme URL: https://amvia.co.uk/cybersecurity/email-security/phishing-simulation Last updated: 2026-03 Phishing simulation training sends realistic, controlled phishing emails to your staff to measure who clicks, who submits credentials, and who reports the threat. Employees who fail receive immediate, contextual training. AMVIA runs the programme continuously so resilience improves over time - one provider, security-first, Microsoft-certified. Phishing is not an edge case. It is the single most common way UK businesses get breached, and the only durable fix is making your people harder to fool. AMVIA designs, runs, and reports on phishing simulation programmes as part of our managed cybersecurity service, so testing and training sit inside a wider security operation rather than as a one-off exercise. ## Why do UK SMEs need phishing simulation? Because people, not firewalls, are where most attacks land. In 2025, 43% of UK businesses experienced a cyber breach or attack, and phishing was involved in 85% of those cases (Cyber Security Breaches Survey 2025). Technical controls stop a lot - but a convincing email still reaches a human who has to make the right call in two seconds. The cost is real and measurable: - 43% of UK businesses hit by a breach or attack in 2025 (DSIT, 2025) - 85% of those breaches involved phishing (DSIT, 2025) - £3,550 average cost of the most disruptive breach, excluding zero-cost responses (DSIT, 2025) A simulation programme turns "we told staff to be careful" into a measured, improving number you can put in front of your board, your insurer, and your auditor. It pairs naturally with technical phishing protection - controls catch the obvious, training catches what slips through. ## What's included in an AMVIA phishing simulation programme? A full lifecycle: a baseline test to see where you stand, tailored campaigns that mimic real attackers, instant training the moment someone clicks, and ongoing measurement that proves whether resilience is improving. Every cycle produces a report you can hand to leadership or a cyber insurer. - Step 1 - Baseline assessment. A first simulation goes to all participants without warning. This establishes your current click rate, credential-submission rate, and reporting rate, so improvement is measured against a real starting point. - Step 2 - Campaign design. AMVIA builds simulations tailored to your business - referencing your industry, your tools, and realistic sender names and branding, because generic templates train staff for attacks they will never receive. - Step 3 - Immediate training for clickers. Anyone who clicks a link, submits credentials, or opens an attachment gets a short (two-to-three-minute) contextual learning module then and there, while the mistake is fresh. - Step 4 - Targeted follow-up. After each cycle, AMVIA reports who clicked, who submitted credentials, and who correctly reported the email. Persistent clickers get enhanced, targeted training. - Step 5 - Ongoing simulation. The programme runs continuously - typically monthly or quarterly - with simulations of increasing sophistication, so staff are tested against evolving tactics, not last year's tricks. ## How does AMVIA run your phishing programme? In four repeating phases: setup, an initial unannounced simulation, targeted training for anyone who falls for it, then continuous testing that tracks improvement trends. The cycle repeats so the number that matters - your click rate - keeps falling. - 01 Programme setup - configure the simulation platform, import your user list, and design templates relevant to your industry. - 02 Initial simulation - a realistic phishing email goes to all staff, measuring who clicks, who reports, and who enters credentials. - 03 Targeted training - staff who fall for a simulation receive immediate, contextual training. - 04 Continuous testing - monthly simulations of rising sophistication, with improvement tracked over time. Simulation works best when it sits alongside the controls in your inbox. AMVIA combines awareness training with technical email defences - Microsoft Defender and the Barracuda email security suite - and ties both back to Microsoft Defender for Business. Training your people to recognise a phishing email is the human layer of that same defence. ## Phishing simulation vs awareness training alone | | Factor | One-off awareness training | AMVIA phishing simulation | Measures real behaviour | No - recall only | Yes - actual click and report rates | Frequency | Annual, often forgotten | Monthly or quarterly, continuous | Training trigger | Generic, scheduled | Immediate, at the moment of failure | Improvement evidence | Anecdotal | Trend reports per cycle | Insurance documentation | Rarely accepted alone | Compliance-ready reports supplied | Tailored to your industry | Rarely | Templates mirror your tools and brand ## Does phishing simulation help with cyber insurance? Yes. Most UK cyber insurers now expect evidence of security awareness training, and many specifically ask for phishing simulation. AMVIA supplies quarterly reports documenting programme scope, frequency, and improvement metrics - exactly the evidence underwriters request at renewal. That turns a renewal box-tick into a documented, defensible control. ## Why choose AMVIA for phishing simulation? Because we run security for a living, from the UK, with the certifications to back it. AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare, and professional services. - Sheffield-based, UK-focused. Our engineering and support team operates from Sheffield, with a working knowledge of UK compliance requirements and the challenges facing British businesses. - Accredited and certified. AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status - see the NCSC for what Cyber Essentials covers. - 1,200+ UK businesses protected. Security and IT managed for over 1,200 UK businesses across multiple regulated sectors. - Fast, responsive support. Critical issues responded to within one hour, with helpdesk available by phone, email, and portal. This is the human side of the security work we do under our managed detection and response service - people and technology defended together. ## How much does phishing simulation cost? Fixed monthly pricing. No lock-in contracts. AMVIA scopes the programme to your headcount and simulation frequency (monthly or quarterly), then bills a predictable monthly fee with no setup lock-in - so you can prove value before committing long-term. Speak to us for a quote tailored to your staff numbers and sector. ## Frequently asked questions Q: What is phishing simulation training? A: Phishing simulation training sends realistic, controlled phishing emails to employees to test whether they click malicious links or submit credentials. Staff who fail receive immediate training, and the programme runs continuously to measure and steadily improve your organisation's phishing resilience over time. Q: Is it ethical to send fake phishing emails to employees? A: Yes - it is a standard, widely accepted security practice. The purpose is not to catch or punish staff but to give realistic, experiential training in a safe environment. AMVIA recommends telling staff the programme exists, without revealing the timing of specific simulations, so the test stays fair and genuine. Q: How often should we run phishing simulations? A: Monthly simulations give the best improvement trajectory. Quarterly is sufficient for organisations with tighter resources. Annual testing is better than nothing but lacks the frequency needed for meaningful, lasting behaviour change - phishing tactics evolve faster than once-a-year training can keep up with. Q: What happens if an employee repeatedly fails phishing simulations? A: AMVIA's reporting identifies persistent clickers, who then receive targeted, enhanced training. A supportive conversation between manager and employee may be appropriate. The programme is never punitive - the goal is to build resilience, not to single people out for blame. Q: Can phishing simulation meet cyber insurance requirements? A: Yes. Most UK cyber insurers accept phishing simulation as evidence of security awareness training. AMVIA provides compliance-ready reports documenting programme scope, frequency, and improvement metrics - the documentation underwriters typically request when you renew or take out a cyber policy. Q: How does phishing simulation fit with technical email security? A: Simulation trains your people; technical controls filter the inbox. AMVIA combines both - Microsoft Defender and the Barracuda email security suite stop most malicious mail, while simulation hardens staff against the convincing emails that slip past filters. Together they cover the human and technical sides of the same risk. --- # How to Recognise a Phishing Email: Guide for UK Staff URL: https://amvia.co.uk/cybersecurity/email-security/how-to-recognise-phishing Last updated: 2026-03 To recognise phishing, check the real sender domain (not the display name), distrust artificial urgency, hover links to reveal the true URL, treat unexpected attachments as hostile, and never share passwords by email. AMVIA hardens this with Microsoft Defender filtering and staff simulation training - one provider, security-first. ## What are the warning signs of a phishing email? Six signals catch most phishing: a sender domain that does not match the display name, manufactured urgency, links that hover to a different URL, unexpected attachments, sloppy grammar or branding, and any request for credentials. Real attackers usually combine several. The fastest, most reliable check is the sender domain. Phishing is not a fringe risk. According to the DSIT Cyber Security Breaches Survey 2025, 85% of breaches experienced by UK businesses involved phishing (DSIT 2025), and 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months - approximately 612,000 businesses affected (DSIT 2025). Teaching every member of staff to spot these signs is one of the highest-value controls a business can buy, and it sits at the centre of a sound managed cybersecurity programme. - Spoofed sender - the display name reads "John Smith - Finance Director" but the address is an unrelated domain - Urgency - "Your account will be suspended within 24 hours" or "Immediate action required" - Bad links - the visible text says "Microsoft 365 Login" but the URL points elsewhere - Unexpected attachments - ZIP/RAR archives, macro-enabled Office files, or `.exe`/`.bat` executables - Branding errors - wrong logo, off colours, awkward non-British phrasing - Credential requests - no legitimate service asks for your password by email ## How do you check a suspicious sender address? Read the actual email address, not the display name. Attackers set the display name to a trusted brand - Microsoft, Royal Mail, a colleague - while sending from a different domain. On mobile, the address is often hidden behind the name, which is why mobile users are caught more often. Look for lookalike domains: `amv1a.co.uk` instead of `amvia.co.uk`, or `micro-soft.com` instead of `microsoft.com`. Watch for added words like `-secure`, `-support` or `-login` bolted onto a known brand to look official. If the domain is even slightly wrong, treat the whole message as hostile and verify through a channel you already trust. ## How do you spot a malicious link or attachment? Before clicking, hover over the link to reveal the real destination. A link labelled "Microsoft 365 Login" may resolve to a credential-harvesting page. Be wary of shortened URLs (`bit.ly`, `tinyurl.com`) and misleading subdomains like `microsoft.login.malicious-site.com`, where the true domain is `malicious-site.com`. If you need a service mentioned in an email, type the address into your browser or use a saved bookmark instead of clicking. For attachments, the highest-risk types are archive files, macro-enabled Office documents that ask you to "enable content", executables, and double extensions such as `invoice.pdf.exe`. If an attachment arrives unexpectedly - even from a known contact - confirm with them on a separate channel before opening, because their account may already be compromised. Microsoft documents the full attack surface in its phishing guidance. ## How is spear phishing different from mass phishing? Mass phishing blasts an identical email to thousands of recipients and relies on volume. Spear phishing targets one person, using LinkedIn, company websites and social media to reference your job title, current project or manager by name - so it slips past the obvious red flags of generic phishing. Business email compromise (BEC) is the most damaging variant: the attacker impersonates a CEO, finance director or supplier to authorise a fraudulent payment. BEC often carries no malware, no links and no attachments, making it invisible to technical filtering - the only defence is a recipient who questions the request. If your finance team is a target, pair this awareness with our business email compromise protection and broader email security controls. | | | Mass phishing | Spear phishing / BEC | Audience | Thousands, untargeted | One named individual | Personalisation | Minimal | Job title, projects, real contacts | Payload | Links / malware | Often none - pure social engineering | Filter detection | Usually caught | Frequently invisible | Primary defence | Email filtering | Trained, sceptical recipient ## What should you do with a suspicious email? Do not click, reply or open attachments. Report it through your organisation's process - in Microsoft 365 that is the Report Message button in Outlook - and forward it to the NCSC. Prompt reporting protects colleagues who received the same message and feeds national threat intelligence. - Do not click links or open attachments, and do not reply - Report it via the Report Message button in Outlook - Verify any request through a known phone number or a separately typed web address - never details in the email - Forward suspected phishing to report@phishing.gov.uk, the NCSC Suspicious Email Reporting Service (SERS) - For messages claiming to be from HMRC or your bank, go to their website directly ## What should you do if you have already clicked? Act immediately - time limits the damage. Tell your IT team or managed provider before checking whether anything "happens", change any exposed passwords from a clean device, and keep the email so it can be investigated. Speed of response is the single biggest factor in containing a successful phishing attack. Yet only 25% of UK businesses have a formal incident response plan (DSIT 2025/26), and the average cost of the most disruptive breach is £3,550 (DSIT 2025). A clear, rehearsed procedure - backed by AMVIA's incident response team and managed detection and response - turns a panic into a contained event. - Notify IT or your MSP first - do not wait - Change exposed passwords (and any reused ones) from a different device - Do not delete the email; it is evidence - Note the time you clicked and what you entered ## How does phishing simulation training help? Reading about phishing helps; practising beats it. AMVIA's phishing simulation training sends safe, realistic test emails - impersonating delivery alerts, IT notices or Microsoft 365 messages - and measures who clicks. Staff who fail get immediate, contextual coaching at the point of failure, which sticks better than annual classroom sessions. Quarterly reports break results down by department, seniority and theme, so you can target follow-up training where risk is highest. With 85% of breaches involving phishing (DSIT 2025), lowering staff susceptibility directly lowers breach risk. AMVIA pairs this human layer with Microsoft Defender and Barracuda email filtering - one accountable provider, security-first, staffed by Microsoft-certified engineers. ## Frequently asked questions Q: What are the most common signs of a phishing email? A: The clearest signals are a mismatch between the display name and the real sender domain, manufactured urgency demanding immediate action, links that reveal a different URL on hover, unexpected attachments, and any request for passwords or bank details. With 85% of UK breaches involving phishing (DSIT 2025), training every employee to spot these indicators is one of the highest-value security investments a business can make. Q: How can I tell if a sender address is fake? A: Read the address itself, not the friendly display name. Look for lookalike domains such as `amv1a.co.uk` for `amvia.co.uk`, or added words like `-secure` and `-login` attached to a known brand. On mobile the address is often hidden, so tap to expand it. If the domain is even slightly wrong, treat the message as hostile and verify through a channel you already trust. Q: What should I do if I receive a suspicious email? A: Do not click links or open attachments. Use the Report Message button in Microsoft Outlook to alert your IT team, then forward the email to report@phishing.gov.uk, the NCSC's Suspicious Email Reporting Service. Reporting quickly protects colleagues who received the same message and feeds national threat intelligence used to disrupt active phishing campaigns across the UK. Q: How does spear phishing differ from normal phishing? A: Mass phishing sends identical emails to thousands of people and relies on volume. Spear phishing targets one person using details from LinkedIn, company websites and social media - referencing your job title, projects or manager by name. These personalised messages bypass the obvious red flags, which is why they are increasingly aimed at UK finance teams and senior executives. Q: Can phishing emails get past my spam filter? A: Yes. Filtering catches most bulk phishing, but business email compromise often contains no malware, no links and no attachments, so it slips through technical controls. The average cost of a data breach for UK organisations reached £3.29 million (IBM Cost of a Data Breach 2025). A trained, sceptical recipient backed by simulation training is the only reliable defence against this filter-invisible category. Q: Does staff training actually reduce phishing risk? A: Yes. Realistic simulations with point-of-failure coaching consistently outperform annual classroom sessions, and click rates fall across successive quarterly campaigns. With 85% of breaches involving phishing (DSIT 2025), measurably reducing staff susceptibility directly reduces overall breach risk - which is why AMVIA runs varied, evolving scenarios rather than a single repeated test. --- # Microsoft Exchange Online Protection Explained URL: https://amvia.co.uk/cybersecurity/email-security/exchange-online-protection Last updated: 2026-03 Exchange Online Protection (EOP) is the email filtering layer built into every Microsoft 365 subscription. It scans all inbound and outbound mail for spam, known malware, and basic phishing automatically, with no extra licence. It is a strong baseline, but targeted attacks slip past it - which is where AMVIA's security-first configuration earns its keep. EOP is the floor, not the ceiling. Understanding exactly what it stops, and what it does not, is the difference between assuming your Microsoft 365 email is secure and knowing it is. This page sits under AMVIA's managed cybersecurity pillar and our wider email security service, where we harden Microsoft 365 against the threats EOP was never built to catch. ## What is Exchange Online Protection? Exchange Online Protection is Microsoft's cloud-based email filtering service. Every message sent to or from a Microsoft 365 mailbox passes through EOP, which inspects it for threats before delivery. It ships with all Microsoft 365 plans, from Business Basic to Enterprise E5, and needs no add-on to run. EOP is the baseline layer Microsoft applies across every Exchange Online mailbox. It processes billions of emails daily, and that scale feeds its threat intelligence. Administrators manage it through the Microsoft Defender portal, with policy controls, quarantine, and reporting. Microsoft documents the full architecture in its Exchange Online Protection overview. ## What does Exchange Online Protection actually do? EOP applies four protective functions to your mail flow: anti-spam filtering, anti-malware scanning, email authentication enforcement, and outbound filtering. Each runs automatically the moment a mailbox goes live, with no configuration required to switch on baseline protection. - Anti-spam filtering - connection filtering blocks known malicious IPs before the message arrives; content filtering uses machine-learning models trained on Microsoft's global mail data; sender reputation analysis scores domains against live databases. Mail is classed as spam, high-confidence spam, or bulk, then routed to Junk or quarantine. - Anti-malware scanning - multiple engines scan attachments for known malware: executables, malicious Office macros, and malware-laden PDFs are quarantined before delivery. Detection is signature-based with heuristics, so it is strong on known variants and weak on novel payloads. - Email authentication - EOP enforces SPF, DKIM, and DMARC on inbound mail and applies the sender's published DMARC policy. AMVIA strongly recommends publishing a DMARC record for your own domain and progressively enforcing a reject policy; our DMARC guide walks through it. - Outbound filtering - EOP monitors mail leaving your mailboxes, catching a compromised account before it spams your contacts and protecting your domain's sending reputation. An outbound-spam alert is often the first sign an account is breached. ## Where does Exchange Online Protection fall short? EOP is a solid baseline, but it is not built to stop sophisticated, targeted attacks. The gaps that matter most for UK SMEs are advanced phishing, zero-day attachments, time-of-click URL abuse, and business email compromise - all of which routinely reach the inbox. - Advanced and spear phishing - a well-crafted email using a real contact's display name from a fresh lookalike domain often passes EOP. Impersonation and behavioural detection require Microsoft Defender for Office 365. - Zero-day attachments - signature-based scanning misses novel malware. Sandboxing (Safe Attachments) is needed to detonate and inspect unknown files. - Time-of-click URLs - EOP scans links at delivery. A link that is clean on arrival and weaponised afterwards gets through; Safe Links re-scans at the moment of click. - Business email compromise - BEC carries no malware or obvious payload, so EOP has limited ability to spot it. Our business email compromise service covers the controls that do. > "Research shows a 47% rise in phishing attacks evading Microsoft native security and secure email gateways in 2025 (KnowBe4). Targeted attacks routinely bypass EOP." The NCSC's guidance on phishing attacks confirms that impersonation and credential-harvesting campaigns are now the dominant threat to UK organisations - exactly the category EOP handles least well. ## EOP vs Microsoft Defender for Office 365: what each licence gives you EOP covers spam, malware, and authentication on every plan. The jump to Microsoft Defender for Office 365 - included with Microsoft 365 Business Premium - adds Safe Attachments, Safe Links, and advanced impersonation protection. For most UK SMEs, Business Premium is the right balance of capability and cost. | | Capability | EOP (All M365 Plans) | Defender for Office 365 Plan 1 (Business Premium) | Defender for Office 365 Plan 2 (E5) | Anti-spam filtering | ✓ | ✓ | ✓ | Anti-malware scanning | ✓ | ✓ | ✓ | SPF/DKIM/DMARC enforcement | ✓ | ✓ | ✓ | Safe Attachments (sandboxing) | ✗ | ✓ | ✓ | Safe Links (time-of-click) | ✗ | ✓ | ✓ | Anti-phishing impersonation detection | Basic | Advanced | Advanced | Attack simulation training | ✗ | ✗ | ✓ | Automated investigation and response | ✗ | ✗ | ✓ | Threat Explorer (hunting) | ✗ | ✗ | ✓ Businesses on Business Basic or Business Standard have EOP only, which leaves the targeted-attack gaps above wide open. For deeper protection beyond Defender, see our advanced email threat protection service. ## How much does Exchange Online Protection cost? EOP itself costs nothing extra - it is bundled into every Microsoft 365 licence. The real cost question is the upgrade path to Defender for Office 365, which arrives with Microsoft 365 Business Premium. The licence tier you choose decides how much email security you actually get. | | Microsoft 365 plan | Price (per user/mo, ex VAT, annual) | Email security included | Business Basic | £4.60 | EOP only | Business Standard | £9.60 | EOP only | Business Premium | £16.90 | EOP + Defender for Office 365 Plan 1 Prices are Microsoft list prices, published on microsoft.com/en-gb. AMVIA reviews and optimises EOP and Defender policies as part of our Microsoft 365 security audit - default settings are rarely tuned for maximum protection. ## Configuring EOP correctly EOP runs out of the box, but its defaults are not optimal. Tightening anti-spam thresholds, configuring the anti-phishing policy, pruning the connection-filter allow list, and setting outbound-spam alerts all measurably reduce risk. These changes take an administrator who knows the Defender portal, not a one-time tick-box. - Anti-phishing policy configured - impersonation protection enabled for key executives - Safe Links and Safe Attachments policies active where Business Premium is licensed - DMARC, DKIM, and SPF configured and enforced on your domain - see our email filtering service - Outbound spam filter configured to flag compromised-account behaviour - Quarantine alerts reviewed - never relying on end users to check junk folders ## Frequently asked questions Q: What is Exchange Online Protection? A: Exchange Online Protection (EOP) is Microsoft's built-in email filtering service, included with all Microsoft 365 subscriptions. It filters inbound and outbound email for spam and known malware, and enforces email authentication standards (SPF, DKIM, DMARC). It is the baseline email security layer for every Microsoft 365 mailbox, active from the moment the account is created. Q: Is Exchange Online Protection sufficient for UK businesses? A: EOP gives solid protection against bulk spam and known malware, but it is not enough on its own against sophisticated phishing, zero-day malware, business email compromise, or time-of-click URL attacks. UK businesses handling sensitive data or carrying cyber insurance requirements should add Microsoft Defender for Office 365 (in Business Premium) or a dedicated gateway layer. Q: Does EOP protect against ransomware delivered by email? A: EOP can detect and block email-delivered ransomware that matches known signatures. Novel ransomware variants, which evolve constantly to evade signature detection, may pass it. Safe Attachments sandboxing in Defender for Office 365 gives far stronger protection by detonating and analysing attachment behaviour in an isolated environment before delivery. Q: Can I use EOP with a third-party email security gateway? A: Yes. Some businesses route mail through a third-party gateway before it reaches Exchange Online, adding a filtering layer in front of EOP. AMVIA deploys this for clients with specific requirements. EOP still filters as a second layer, giving defence in depth. We size the right architecture during a security audit rather than over-engineering by default. Q: Is EOP enabled automatically, or do I need to switch it on? A: EOP is on by default for every Microsoft 365 mailbox - no activation step is needed for baseline filtering. What is not automatic is tuning: the default anti-spam, anti-phishing, and quarantine policies are deliberately conservative. Reviewing and tightening them is where most of the practical security improvement comes from. Q: Does EOP cost extra on top of Microsoft 365? A: No. EOP is bundled into every Microsoft 365 plan at no additional charge, from Business Basic (£4.60) upward. The cost decision is whether to move to Business Premium (£16.90) for Defender for Office 365 Plan 1, which adds Safe Links, Safe Attachments, and advanced impersonation protection on top of EOP. --- # Email Archiving and Compliance for UK Businesses URL: https://amvia.co.uk/cybersecurity/email-security/email-archiving Last updated: 2026-03 Email archiving is the automated capture and tamper-proof, indexed storage of every business email - sent and received - so it can be searched, retrieved and produced for compliance, legal or regulatory purposes. AMVIA configures email archiving on Microsoft 365 with retention policies built around your exact UK obligations: one provider, security-first, Microsoft-certified. It sits at the heart of a properly run email security programme and underpins the wider managed cybersecurity service we deliver to over 1,200 UK businesses. ## What is email archiving and what does it include? Email archiving copies every message flowing through your system into immutable, searchable storage governed by retention rules. Unlike a mailbox, an archive cannot be edited or quietly deleted by a user, which is exactly what regulators and courts expect. AMVIA builds the archive on Microsoft 365. A complete archive covers: - Capture - every sent and received email journaled at gateway or server level, transparently, with no impact on delivery. - Retention - policies that match each sector's legal minimum, from three years to indefinite legal holds. - Search and eDiscovery - self-service search for staff plus Microsoft Purview eDiscovery for compliance and legal teams. - Tamper-proofing - immutable storage so records cannot be altered after capture. - Historical import - existing mail imported so coverage starts from day one, not just from go-live. Microsoft 365 includes in-place archiving for Exchange Online mailboxes - the archive appears as a separate Outlook folder, and retention policies automatically move older mail into it. In-place archiving is included with Exchange Online Plan 2, per Microsoft's documentation. ## Why do UK SMEs need email archiving? Most UK businesses are legally required to retain certain email but have no reliable way to produce it on demand. With 43% of UK businesses experiencing a cyber breach in 2025 (Cyber Security Breaches Survey 2025), a deleted or encrypted mailbox can wipe out records you are obliged to keep. An archive separates retention from the mailbox, so a ransomware event, an accidental deletion or a departing employee cannot destroy regulated records. The average cost of a disruptive breach for UK businesses is £3,550 (Cyber Security Breaches Survey 2025), and the inability to evidence compliance compounds that cost with regulatory and legal exposure. ## What are the UK email retention requirements? Retention depends on sector and email type - there is no single blanket period. The table below summarises the common UK obligations AMVIA designs archive policies around. Personal data in email must also obey UK GDPR's storage limitation principle: keep it no longer than necessary, as the ICO sets out. | | Requirement | Who it applies to | Typical retention | Companies Act 2006 | All limited companies | 3 years (private) / 6 years (public) | VAT records (HMRC) | VAT-registered businesses | 6 years | MiFID II client/transaction records | FCA-regulated investment firms | 5 years | Employment / tribunal evidence | All employers | ~6 years from the event | Sector rules (SRA, NHS records) | Law firms, healthcare | Often exceed general standards | UK GDPR storage limitation | Anyone holding personal data | No longer than justified AMVIA advises on sector-specific requirements during archiving setup. The Companies Act 2006 requires certain business records - including financial records - be retained for three years (private companies) or six years (public companies); financial instructions, purchase orders and invoices sent by email are in scope. MiFID II requires investment firms retain records of all client order and transaction communications for five years. ## Is email archiving the same as email backup? No. Backup captures point-in-time mailbox copies for restoration after deletion or data loss. Archiving captures every email as it flows, retains it in indexed, immutable storage for defined periods, and provides eDiscovery for legal and compliance needs. They solve different problems and you need both. | | | Email backup | Email archiving | Purpose | Restore lost data | Retain and produce records | Captures | Point-in-time snapshots | Every message, as it flows | Storage | Recoverable copy | Immutable, tamper-proof | Search | Limited | Full eDiscovery / legal hold | Primary driver | Disaster recovery | Compliance and litigation If your priority is recoverability after data loss, pair archiving with Microsoft 365 backup. For compliance evidence and legal hold, you need an archive. ## How does AMVIA set up your email archive? AMVIA runs a four-step setup that starts with your legal obligations, not the technology, so retention policies are correct from day one rather than retro-fitted later. 1. Compliance review - assess regulatory obligations (FCA, UK GDPR, legal hold) and design retention policies to match. 2. Archive configuration - configure the archive with retention rules, journaling and tamper-proof storage. 3. Historical import - import existing email so coverage is complete from day one. 4. Search and compliance - give staff self-service search and enable compliance officers to run eDiscovery searches and legal holds. Because we are also your Microsoft 365 managed service and GDPR-aligned cybersecurity provider, archiving is configured as part of one accountable security stack - not bolted on by a separate vendor. ## Why choose AMVIA for email archiving? AMVIA is a Sheffield-based security partner managing IT and security for over 1,200 UK businesses across legal, finance, healthcare and professional-services sectors. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and respond to critical issues within one hour. - UK-focused - engineering and support run from Sheffield, with first-hand knowledge of UK compliance. - Certified - Cyber Essentials Plus and Microsoft Solutions Partner (Modern Work, Security, Infrastructure). - Proven - 1,200+ UK businesses protected. - Responsive - critical issues answered within one hour by phone, email and portal. ## How much does email archiving cost? Cost depends on user count, retention length and whether historical import is required. For most SMEs already on Microsoft 365, in-place archiving is included with Exchange Online Plan 2, so the cost is the setup and ongoing policy management rather than new per-mailbox licensing. AMVIA scopes this against your retention obligations during the compliance review and quotes a fixed monthly price. ## Frequently asked questions Q: How long should UK businesses retain email? A: There is no single answer - it depends on sector and email type. A common baseline: six years for financial records (Companies Act for public companies; three years for private), six years for VAT records (HMRC), and five years for FCA-regulated client communications. Email containing personal data must be kept no longer than justified under UK GDPR's storage limitation principle. Q: Is email archiving the same as email backup? A: No. Backup captures point-in-time mailbox copies for restoration after accidental deletion or data loss. Archiving captures every email flowing through the system, retains it in indexed, immutable storage for set periods, and provides eDiscovery tools for compliance and legal purposes. Both serve different functions, and most regulated businesses need both. Q: Can users access the email archive themselves? A: Yes. In Microsoft 365, users open their archive mailbox directly from Outlook. Administrators grant compliance officers and legal teams access to search across all archives using Microsoft Purview eDiscovery, without needing access to each individual mailbox. Q: Does email archiving affect email performance? A: No. Archiving happens transparently in the background - a copy is captured at gateway or server level without affecting delivery speed or mailbox performance. Users typically notice no difference in day-to-day use. Q: What is a litigation hold and when should we use it? A: A litigation hold (legal hold) preserves all mailbox content - preventing deletion, modification or expiry - regardless of user actions or retention policies. Apply it as soon as actual or potential litigation involving that mailbox is known. AMVIA can implement litigation holds quickly and advise on scope. --- # Endpoint Security for UK Businesses: EDR & 24/7 Monitoring URL: https://amvia.co.uk/cybersecurity/endpoint-security Last updated: 2026-03 Endpoint security protects every device that connects to your business network - laptops, desktops, servers, and mobiles - using Endpoint Detection and Response (EDR) to spot malicious behaviour in real time and isolate compromised devices before threats spread. AMVIA runs it as a single accountable service: one provider, security-first, Microsoft-certified. This page sits under our managed cybersecurity pillar, where endpoints are one layer of a full security stack covering email, network, and 24/7 monitoring. ## What is endpoint security? Endpoint security is the protection of every device - an "endpoint" - that connects to your network. Each laptop, server, or phone is a potential entry point for attackers. Modern endpoint security uses EDR to monitor process behaviour live, contain compromised devices, and give forensic investigators a full activity trail. For UK businesses with hybrid teams, the endpoint is now the security perimeter. Office staff sit behind a corporate firewall; remote workers connect from home broadband, hotels, and public Wi-Fi the business cannot control. If one device is breached, attackers use it as a beachhead to reach other systems, steal data, or deploy ransomware. - 68% of organisations suffered an endpoint attack that compromised data (Ponemon Institute) - 99%+ threat detection rate for modern EDR vs 60–70% for traditional signature-based antivirus (independent lab testing, 2026) - 1,200+ UK business endpoints monitored by AMVIA's security operations centre ## What does AMVIA's managed endpoint security include? AMVIA's service combines Microsoft Defender for Endpoint - Microsoft's enterprise EDR platform - with our in-house 24/7 SOC. You get the detection technology and the human analysts who investigate and respond, under one contract with one provider accountable for the outcome. - EDR deployment and management - Defender for Endpoint rolled out across every device, with continuous tuning to cut false positives. - 24/7 monitoring - our security operations centre investigates alerts around the clock and escalates genuine threats, with monthly reporting. - Threat containment - analysts isolate affected devices within minutes to stop lateral movement and limit blast radius. - Patch management - automated OS and third-party patching with a 14-day remediation target for critical vulnerabilities. - Remote and mobile cover - home-worker laptops and phones are managed via Microsoft Intune, enforcing encryption, PIN policies, and selective wipe. ## How does EDR differ from traditional antivirus? Traditional antivirus compares files against a database of known malware signatures: match a known-bad file and it blocks it, miss it and the threat passes through. EDR instead watches the live behaviour of every process, catching novel ransomware, fileless attacks, and living-off-the-land techniques that signatures never see. Ransomware operators routinely modify malware to dodge signatures, fileless malware runs entirely in memory, and attackers abuse legitimate tools like PowerShell and WMI. Signature scanning is blind to all three. The NCSC's device security guidance sets out why behavioural protection and prompt patching matter for every managed device. | | Capability | Traditional antivirus | EDR (Defender for Endpoint) | Detection method | Known malware signatures | Live process behaviour | Catches novel ransomware | Limited | Yes | Detects fileless attacks | No | Yes | Automatic device isolation | No | Yes, within seconds | Forensic activity trail | No | Full timeline | Detection rate | 60–70% | 99%+ EDR does not just detect - it responds, automatically isolating the endpoint, killing malicious processes, and rolling back changes within seconds. Read our endpoint detection and response breakdown for the full technical detail. ## Managed endpoint security vs self-managed: which is right for you? EDR tools are powerful but noisy - they generate high alert volumes, many of them false positives. Without a dedicated investigation team, real threats get lost in the noise. Self-managing works for organisations with 200+ staff and a genuine in-house security function; for most SMEs the IT team is generalist and stretched. Managed endpoint security - also called Managed Detection and Response (MDR) - hands monitoring, investigation, and response to a provider. AMVIA pairs Defender for Endpoint with our managed detection and response team, delivering enterprise EDR with human-led response at lower cost than an understaffed internal rota. | | | Self-managed EDR | AMVIA managed endpoint security | Who investigates alerts | Your internal IT team | AMVIA's 24/7 SOC | Coverage hours | Office hours, best effort | 24/7/365 | Critical incident response | Whenever staff are free | One-hour guaranteed | Best suited to | 200+ staff with security team | UK SMEs without one ## How are remote and hybrid workers protected? Remote devices connect from networks the business cannot control, so they need identical protection to office machines. AMVIA's Defender for Endpoint agents report to a cloud console regardless of location, so our SOC monitors a home laptop exactly as it does an office desktop. - Encryption - full disk encryption enforced via BitLocker (Windows) and FileVault (macOS), so a lost device exposes no data. - Patching - remote machines are patched as promptly as on-site infrastructure, closing the most-exploited vulnerability class. - Monitoring and isolation - if a remote device is compromised, analysts isolate it from corporate resources within minutes, even on a home network. Pair this with 24/7 security monitoring for continuous coverage across your whole estate. ## How much does managed endpoint security cost? Managed endpoint security for UK SMEs typically costs between £8 and £20 per device per month (typical UK 2026 range), depending on scope. That usually covers the Defender for Endpoint licence, managed detection and response, SOC monitoring and alert investigation, patch management, and monthly reporting. Weigh that against a single incident. Recovery from a breach mounts up fast once downtime, remediation, and data recovery are added together - and the Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach for UK businesses at £3,550 (gov.uk). Endpoint protection is one of the highest-return security investments a UK business can make. ## How do you choose an endpoint security provider? Judge providers on four things: do they run their own SOC, what tooling do they use, what is the response SLA, and do they cover remote and mobile devices. AMVIA operates its own UK SOC, uses Microsoft Defender for Endpoint and Barracuda, guarantees one-hour response to critical endpoint incidents 24/7, and covers home and mobile devices as standard. - Own SOC - AMVIA's SOC is UK-based, not white-labelled offshore. - Enterprise tooling - Microsoft Defender for Endpoint and Barracuda, backed by Microsoft's security platform. - Accountable credentials - Cyber Essentials Plus certified and a Microsoft Solutions Partner (Modern Work, Security & Azure Infrastructure). ## Frequently asked questions Q: What does EDR actually do on my device? A: EDR runs as a lightweight agent on each endpoint, monitoring all process activity in real time. It detects behavioural patterns linked to ransomware, credential theft, and fileless attacks - even threats never seen before. When malicious activity is identified, it can automatically isolate the device from your network and kill the offending process within seconds, preventing lateral movement to other machines. Q: What is the difference between EDR and traditional antivirus? A: Antivirus relies on signature databases of known malware, so it only blocks threats it recognises. EDR monitors live process behaviour, catching novel ransomware, fileless attacks, and living-off-the-land techniques that signatures miss. Independent lab testing in 2026 shows modern EDR detects over 99% of real-world attack techniques versus 60–70% for traditional antivirus. EDR also responds automatically by isolating compromised devices. Q: Why do UK businesses need managed endpoint security? A: The Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a breach or attack in the past 12 months (gov.uk). Most SMEs lack the in-house expertise to monitor EDR alerts around the clock. A managed service provides 24/7 SOC monitoring, expert investigation, and rapid response - enterprise-grade protection at a fraction of the cost of an internal security team. Q: How do you protect remote workers' endpoints? A: Defender for Endpoint agents report to our cloud console regardless of device location, so home workers receive identical monitoring to office staff. We enforce full disk encryption via BitLocker, automated patching, and remote wipe via Microsoft Intune. If a remote device is compromised, our analysts isolate it from corporate resources within minutes - even on a home network. Q: How much does managed endpoint security cost per device? A: AMVIA's managed endpoint security typically costs between £8 and £20 per device per month, depending on scope. That covers the EDR licence, managed detection and response, SOC monitoring, patch management, and monthly reporting. Given the average most-disruptive breach costs UK organisations £3,550 (Cyber Security Breaches Survey 2025), endpoint protection is among the highest-return security investments available. Q: Does AMVIA cover company mobiles and BYOD devices? A: Yes. We extend endpoint security to company-owned and BYOD mobiles through Microsoft Intune, enforcing encryption, PIN policies, and selective wipe so business data can be removed without touching personal content. Mobiles are monitored by the same SOC and held to the same patch and compliance standards as laptops and servers. --- # What Is Endpoint Security? A Guide for UK SMEs URL: https://amvia.co.uk/cybersecurity/endpoint-security/what-is-endpoint-security Last updated: 2026-03 Endpoint security is the set of controls applied directly to the devices - laptops, desktops, phones, tablets, and servers - that connect to your business network or data. It detects, prevents, and contains threats on the device itself before they spread. With distributed working, the device is now the security boundary, which is why managed cybersecurity treats every endpoint as a front line. ## What counts as an endpoint? An endpoint is any device that connects to a business network or cloud service. For UK SMEs the highest-risk endpoints are the everyday machines staff use to open email and access company data - and since 2020, most of them now operate outside the office network entirely. - Laptops and desktops (Windows, macOS) - the primary devices for office-based and remote staff - Mobile phones and tablets (iOS, Android) - including personal devices under bring-your-own-device (BYOD) policies - Servers - on-premises physical servers and cloud virtual machines in Azure, AWS, or similar - Network-attached storage (NAS) devices holding shared files and backups - Point-of-sale terminals, specialist equipment, and industrial control systems in certain sectors The threat is concrete. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses, with 65% of medium and 69% of large businesses affected (DSIT 2025/26). Many of those breaches begin at the endpoint - a phishing email opened on a laptop, malware on a workstation, or a compromised phone. ## Traditional antivirus vs modern EDR - what's the difference? The difference is detection method. Traditional antivirus matches files against a database of known malware signatures and blocks what it recognises. Modern endpoint detection and response (EDR) watches device behaviour in real time and catches threats it has never seen before - then acts to contain them. Traditional antivirus is passive and reactive: it waits for a known threat to appear, then quarantines it. It cannot stop fileless attacks, living-off-the-land techniques that misuse legitimate tools like PowerShell, or sophisticated multi-stage intrusions. EDR continuously monitors process activity, network connections, file modifications, and registry changes, using behavioural analytics to flag malicious patterns regardless of whether the specific malware has been catalogued. When it detects a threat, it can isolate the device, terminate processes, roll back changes, and alert analysts. | | Capability | Traditional antivirus | Modern EDR | Detection method | Known signature matching | Behavioural + machine-learning analysis | Unknown / fileless threats | Misses them | Detects them | Device isolation | No | Yes, automatic | Investigation data | None | Detailed endpoint telemetry | Updating | Manual signature updates | Cloud-based, adapts in real time This is why EDR has replaced antivirus as the standard for business endpoint protection. Antivirus is a single layer of passive defence; EDR is active, intelligent, and responsive. ## How does AI-based detection work? AI-based detection establishes a baseline of normal behaviour for each device and user, then flags deviations that match attack patterns or anomalous activity. Modern EDR platforms - including Microsoft Defender for Business - train machine-learning models on billions of endpoint events to recognise malicious behaviour, not just known files. That behavioural approach is what catches never-before-seen malware: software attempting to disable security tools, encrypting files in rapid succession, or opening covert network connections gives itself away by what it does. AI detection also identifies fileless attacks running entirely in memory. This matters because the DSIT Cyber Security Breaches Survey 2025 found that 85% of breaches involved phishing, and phishing payloads are routinely engineered to slip past signature-based antivirus. ## What does managed endpoint security include? Managed endpoint security goes beyond installing EDR agents. It pairs the detection technology with people who investigate and act on what it finds - the gap most SMEs cannot fill in-house. A complete service covers deployment, monitoring, investigation, containment, and reporting. - Deployment and configuration of EDR agents on every endpoint, with policies tuned to your risk profile - Continuous monitoring of alerts by qualified analysts, separating genuine threats from false positives - Active investigation - examining the full context of an alert to gauge scope and severity - Incident containment - isolating compromised devices, terminating processes, revoking credentials - Remediation guidance - clear steps for recovery, re-imaging, and restoring data - Patch management support - keeping operating systems and applications current - Monthly reporting on endpoint status, threat volumes, and actions taken The DSIT Cyber Security Breaches Survey 2025 found that only 25% of UK businesses have a formal incident response plan. A managed detection and response service fills that gap by providing expert response capability whenever an endpoint threat appears, day or night. ## Microsoft Defender for Business and the managed layer For UK SMEs on Microsoft 365, Microsoft Defender for Business is the primary endpoint protection solution. It provides EDR, automated investigation and response, attack surface reduction rules, and network protection, managed through the Microsoft 365 Defender portal. It is included in Microsoft 365 Business Premium (£16.90 per user per month, ex VAT, annual - see Microsoft 365 pricing), making it cost-effective for businesses already on the platform. Detection technology alone is not enough - someone must investigate and act on the alerts it produces. AMVIA's in-house 24/7 SOC adds a human-led layer on top of Microsoft Defender, providing around-the-clock threat hunting and incident response by dedicated analysts. Microsoft Defender provides the detection; our analysts provide the expertise to investigate alerts, eliminate false positives, and respond to confirmed threats. One provider, security-first, Microsoft-certified. ## Why does endpoint security need 24/7 SOC monitoring? Because EDR detects threats, but a human has to investigate and respond. A 24/7 Security Operations Centre provides continuous monitoring of endpoint alerts - triaging events, investigating genuine threats, and containing incidents before they escalate. For SMEs without in-house security staff, round-the-clock coverage means threats are handled at any hour, not whenever someone next checks a dashboard. The case for speed is blunt. Ransomware can encrypt an entire network in under an hour. Stolen credentials can give an attacker persistent access they exploit days later. Without continuous monitoring, these threats persist undetected and do far more damage than if caught immediately. An alert generated at midnight that sits until morning is an open door. ## What does managed EDR cost for UK SMEs? Managed endpoint detection and response for UK SMEs typically costs between £5 and £15 per device per month, depending on provider, scope, and whether 24/7 SOC monitoring is included. For a 50-person business with 60 endpoints, that is roughly £3,600 to £10,800 per year. Set that against the alternatives. A single in-house security analyst costs roughly £40,000 to £60,000 per year - the National Careers Service puts experienced cyber security analysts at up to £60,000. The average cost of the single most disruptive breach was £3,550 for UK businesses (DSIT Cyber Security Breaches Survey 2025) - and the operational disruption, data loss, and reputational damage from a serious endpoint compromise can run far higher. ## How AMVIA secures endpoints for UK SMEs AMVIA deploys and manages Microsoft Defender for Business across all client endpoints, monitored by our in-house managed SOC for 24-hour threat hunting and human-led response. We manage patching, monitor alerts, investigate incidents, and report monthly on endpoint status. Our Sheffield-based team is available around the clock to respond to genuine threats - enterprise-grade protection at a predictable monthly cost. We hold Cyber Essentials Plus and work as a Microsoft Solutions Partner, so the people configuring your defences are certified on the platform they run. For practical hardening guidance, the NCSC's device security guidance is a sound reference for any UK business setting its baseline. ## Frequently asked questions Q: How does EDR differ from traditional antivirus software? A: Traditional antivirus matches files against a database of known malware signatures and misses novel or fileless threats entirely. EDR continuously monitors device behaviour - processes, network connections, registry changes - using AI-based analysis to detect previously unseen attacks in real time. Crucially, EDR can automatically isolate a compromised device and roll back malicious file changes, providing active containment antivirus cannot offer. Q: Should remote and hybrid workers have managed endpoint protection? A: Yes. Devices operating outside the office network are beyond the reach of perimeter firewalls and are frequently targeted. Every laptop, desktop, or mobile accessing company data needs managed EDR with continuous monitoring, regardless of location. With 43% of UK businesses experiencing a breach or attack in 2025 (DSIT Cyber Security Breaches Survey 2025), leaving remote endpoints unprotected creates a gap attackers actively exploit. Q: What happens when EDR detects a threat outside business hours? A: Without 24/7 SOC monitoring, an alert generated at midnight sits uninvestigated until staff arrive next morning - by which point ransomware can have encrypted the network. A managed Security Operations Centre triages EDR alerts around the clock, isolating compromised devices and containing incidents within minutes. Ransomware detonates outside office hours by design, so overnight response capability is no longer optional. Q: Is Microsoft Defender for Business enough on its own? A: Defender for Business is a capable EDR platform, but technology alone does not investigate alerts or respond to confirmed threats - a person must. Defender supplies detection, automated response, and attack surface reduction; a managed service adds analysts who triage alerts, remove false positives, and contain incidents. For an SME without a security team, pairing Defender with a 24/7 SOC turns good tooling into a complete defence. Q: What is the difference between EDR and MDR? A: EDR is the technology that detects and responds to threats on the endpoint. MDR - managed detection and response - wraps that technology in a human-led service: analysts who monitor alerts, investigate, and respond on your behalf, 24/7. EDR is the tool; MDR is the tool plus the experts running it. Most UK SMEs need the managed service because they lack in-house analysts. Q: How many endpoints does a typical SME need to protect? A: Count every device that touches company data: each staff laptop and desktop, work mobiles, tablets, on-premises and cloud servers, and any NAS or specialist equipment. A 50-person business commonly has 60 or more endpoints once phones and servers are included. Each one is a potential entry point, so endpoint security should cover all of them, not just office workstations. --- # Managed Endpoint Security for UK Small Businesses URL: https://amvia.co.uk/cybersecurity/endpoint-security/managed-endpoint-security Last updated: 2026-03 Managed endpoint security is a fully run service that protects every device your staff use - laptops, desktops and servers - with next-generation antivirus, patching, encryption checks and round-the-clock threat detection. AMVIA deploys Microsoft Defender for Endpoint and monitors it from our in-house 24/7 SOC, so you get one provider, security-first, with Microsoft-certified engineers. This is a core service within our managed cybersecurity practice. Endpoints are where most attacks land - a single unpatched laptop or stolen credential is often all an attacker needs. With 43% of UK businesses experiencing a cyber breach in 2025 (gov.uk Cyber Security Breaches Survey 2025), leaving devices on consumer antivirus is no longer a defensible position. ## What is managed endpoint security? Managed endpoint security means an external security team owns the protection of every device on your network - deploying agents, writing detection policies, patching software, and responding to threats - instead of leaving it to an overstretched internal IT person. It moves you from "we installed antivirus once" to continuous, monitored defence. It typically combines several layers most businesses run separately, or not at all: - Next-generation antivirus (EPP) - behavioural detection that catches malware traditional signature antivirus misses. - Endpoint detection and response - records device activity so analysts can investigate and roll back attacks. - Patch management - operating system and third-party app updates on a defined schedule. - Encryption and policy enforcement - BitLocker, firewall, password and access baselines applied consistently. - 24/7 monitoring - agents watched by a SOC, not just a dashboard nobody checks. ## What is included in AMVIA's managed endpoint security? AMVIA's service covers the full lifecycle of every endpoint: audit, deployment, configuration, monitoring and response. We run Microsoft Defender for Endpoint as the core agent - a tool defined as Microsoft's enterprise endpoint protection platform - and tune it to your environment so alerts are real, not noise. Every engagement includes: - Proactive protection - continuous monitoring and threat detection to stop incidents before they spread. - Expert management - UK-based engineers handle configuration, updates and incident response, so your team doesn't have to. - Regular reporting - monthly reports on security posture, incidents handled and recommended improvements. - Dedicated support - direct access to your account team for questions, changes and escalations. For tighter Microsoft 365 control, we pair endpoint protection with Microsoft Defender for Business and Microsoft Intune device management for policy enforcement across managed and mobile devices. ## How does AMVIA protect your endpoints? We follow a four-stage process that takes you from an unknown device estate to a fully monitored, baseline-compliant fleet. It is designed to deploy quietly, without disrupting staff, then hand you continuous protection backed by our 24/7 security monitoring team. 1. Device audit - we inventory all endpoints (laptops, desktops, servers) and assess current protection levels and patch status. 2. Agent deployment - endpoint protection agents are deployed silently across your estate with policies matched to your risk profile. 3. Policy configuration - detection rules, exclusions and response actions are tuned to your environment to minimise false positives. 4. Continuous monitoring - 24/7 monitoring with automated threat response, monthly reports and regular policy reviews. ## Why do UK SMEs need managed endpoint security? UK SMEs need managed endpoint security because devices are now the front line, attackers automate against small businesses, and most internal teams cannot watch every endpoint 24/7. Hybrid work has pushed laptops outside the office firewall, widening the attack surface that legacy antivirus was never built to defend. The numbers make the case plainly: - 43% of UK businesses experienced a cyber breach in 2025 (gov.uk Cyber Security Breaches Survey 2025). - 85% of breaches involved phishing (DSIT 2025) - and phishing payloads execute on the endpoint. - £3,550 is the average cost of a disruptive breach for UK businesses. - Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26). The NCSC's device security guidance is clear that patching, encryption and managed configuration are baseline controls - exactly what a managed service enforces consistently. ## In-house antivirus vs managed endpoint security The difference is not the software - it is who runs it, watches it, and responds when something fires at 2am. The table below sets out the practical contrast. | | Capability | DIY antivirus | AMVIA managed endpoint security | Detection | Signature-based | Behavioural + EDR via Microsoft Defender | Monitoring | None - alerts ignored | 24/7 in-house SOC | Patching | Manual / ad hoc | Scheduled, tracked, critical patches within 48h | Threat response | Internal IT, business hours | Automatic isolation + SOC investigation | Reporting | None | Monthly posture and incident reports | Remote devices | Inconsistent | Same policy, location-independent ## Why choose AMVIA for managed endpoint security? AMVIA combines accredited security credentials, a UK-based team and a 1,200-business track record. We are a security partner, not a telecoms reseller bolting on antivirus - endpoint protection is part of how we run security-first managed services for SMEs. - Sheffield-based, UK-focused - our engineering and support team operates from Sheffield and understands UK compliance, infrastructure and the threats facing British businesses. - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status (Modern Work, Security and Infrastructure). - 1,200+ UK businesses protected - across legal, finance, healthcare and professional services. - Fast, responsive support - critical issues responded to within one hour, by phone, email and portal, with dedicated account managers who know your environment. ## How much does managed endpoint security cost? AMVIA's managed endpoint security starts from £1.89 per device per month, billed per endpoint so the cost scales with your fleet rather than a fixed platform fee. Pricing depends on device count, the policy tier you need, and whether you bundle EDR, patching and reporting together. | | Service | From / device / month | Endpoint Security | from £1.89 For a tailored quote against your actual device estate, the fastest route is a short audit - covered below. ## Frequently asked questions Q: What is managed endpoint security? A: A fully run service protecting every device staff use - laptops, desktops, servers - with next-generation antivirus and EDR, deployed, tuned and watched by AMVIA rather than left as an unmonitored console. Q: How much does endpoint security cost? A: Unmanaged endpoint protection starts from £1.89 per device/month - the licence-only anchor from AMVIA's central price list. Managed coverage, where alerts are actually triaged and acted on, is priced within the managed security plans by scope. Q: What's the difference between managed and unmanaged endpoint security? A: The watching. Unmanaged means software installed and alerts unread; managed means detections triaged around the clock, devices isolated when something fires, and policies tuned as threats change. The tooling overlaps - the outcome doesn't. Q: Does endpoint security cover servers and home-working laptops? A: Yes - every device that touches business data is in scope, wherever it sits. Home-working laptops are the classic gap: outside the office network, but inside your data. Endpoint security travels with the device, which is the point. --- # Managed Firewall Service UK | Barracuda, Cisco, Zyxel, UniFi URL: https://amvia.co.uk/cybersecurity/managed-firewall Last updated: 2026-08 A managed firewall service means a provider takes ownership of your firewall estate: configuration against an agreed baseline, rule reviews, firmware and security patching, continuous monitoring, documented change management and reporting. AMVIA delivers this on Barracuda, Cisco, Zyxel and UniFi platforms - supplying new hardware or taking over supported devices you already own - under a published Firewall Management SLA, with per-site pricing banded by size: £75–£175/month for a small office (5–20 users), £175–£400 for 20–100 users, and £250–£750 per site for multi-site estates. ## What does a managed firewall service actually include? Five disciplines, applied continuously. Rule reviews: the rulebase is audited on a schedule against what the business actually uses, because firewalls rot by accumulation - every temporary exception that nobody removes widens the attack surface. Firmware and patch management: the firewall is itself software, and unpatched edge devices are one of the most actively exploited categories of kit on the internet; we test and apply vendor updates on a managed cycle. Configuration monitoring: device health and configuration state are watched continuously, and drift from the agreed baseline gets investigated. Change management: every rule change is requested, approved, documented and reversible. Reporting: you get the evidence - what changed, what was blocked, what was patched - in a form an auditor, insurer or Cyber Essentials assessor will accept. ## Firewalls and Cyber Essentials Firewalls are the first of the five technical control themes that Cyber Essentials verifies: every in-scope device protected by a correctly configured boundary or software firewall, default passwords changed, and management interfaces protected. It is also one of the easiest controls to fail through neglect rather than ignorance - the firewall was configured properly once, and then three years of undocumented changes happened. A managed firewall keeps the control permanently in the state the assessment expects, which is one less thing to remediate each renewal cycle. ## The right firewall platform, matched to the business AMVIA is a partner of both Barracuda and Zyxel. In broad terms we deploy Barracuda's security platform where businesses need deeper inspection, application control and integration with a wider security stack, and Zyxel's firewall range where the priority is dependable perimeter security and site-to-site VPN at SME-friendly cost. We also deploy and manage Cisco firewalls where a business is standardised on Cisco networking, and Ubiquiti UniFi gateways where centrally-managed perimeter security at entry-level cost is the right fit. The honest answer on which fits you depends on sites, users, traffic and what the rest of your stack looks like - that's what the audit step is for, and we'll say plainly if your existing hardware is worth keeping. ## What does a managed firewall cost? AMVIA prices managed firewalls per site, banded by the size of the business behind them: | | Customer size | AMVIA managed firewall | Premium MSSPs typically charge | Small office (5–20 users) | £75–£175 / site / month | £175–£300 | 20–100 users | £175–£400 / site / month | £400–£700 | Multi-site estates | £250–£750 / site / month | £750–£2,000+ Where you land in the band depends on device class, whether hardware is supplied or taken over, and what the rulebase looks like when we inherit it - the exact figure comes with the quotation, not the invoice. The right-hand column is why it is worth quoting this before renewing with an enterprise-badged MSSP: the work is the same five disciplines either way. ## Already have firewall hardware? You don't need to buy new kit to get management. If your existing firewalls are supported models on current firmware - or can be brought up to it - we take them under management: credentials rotated, configuration backed up, rulebase reviewed against the baseline, and the same monitoring, patching and published Firewall Management SLA applied as if we'd supplied them. Where hardware is end-of-life or unsupported, we'll tell you, because an unpatchable firewall fails the Cyber Essentials update-management control no matter who manages it. ## The firewall is the start, not the whole job A well-run firewall protects the perimeter; most incidents we see start inside it - a phished password, an unpatched laptop, a misconfigured Microsoft 365 tenant. That's why managed firewall customers usually broaden into managed IT support: one provider running the firewall, the endpoints, the patching and the helpdesk, under one SLA. If you're comparing that route, start with the managed IT hub - the firewall service slots into every tier. ## Frequently asked questions Q: What is a managed firewall service? A: A service where a provider takes ongoing ownership of your firewalls: configuration against an agreed baseline, scheduled rule reviews, firmware and security patching, continuous monitoring, documented change management and reporting. You keep the protection; the provider does the work that keeps it real. Q: Do I have to buy new hardware, or can you manage my existing firewall? A: If your existing devices are supported models that can run current firmware, we can usually take them under management - credentials rotated, configuration backed up and reviewed, then the same monitoring and SLA as hardware we supply. If the hardware is end-of-life, we'll say so, because unsupported devices fail the Cyber Essentials security-update control regardless of who manages them. Q: Which firewall vendors does AMVIA work with? A: We deploy and manage four platforms - Barracuda, Cisco, Zyxel and Ubiquiti UniFi - and are Barracuda and Zyxel partners. Broadly: Barracuda where deeper inspection and integration with a wider security stack are needed; Zyxel where dependable perimeter security and VPN at SME-friendly cost is the priority; Cisco where the network is already Cisco-standardised; UniFi for smaller sites wanting centrally-managed perimeter security at entry-level cost. The audit step determines which fits your sites and traffic. Q: Is a managed firewall enough for Cyber Essentials? A: It fully covers the first of the five technical controls - boundary firewalls and internet gateways - and contributes evidence for secure configuration and update management. The remaining controls (user access control, malware protection, and updates across the rest of the estate) still need to be met, which is where our wider managed IT and certification support comes in. Q: How much does a managed firewall service cost? A: Per site, banded by size: £75–£175/month for a small office (5–20 users), £175–£400 for 20–100 users, and £250–£750 per site for multi-site estates - depending on device class, site count and whether hardware is supplied or we take over equipment you already own. Premium MSSPs typically charge roughly double for the same bands; the exact AMVIA figure is confirmed at quotation. Q: What happens when a firewall change is needed? A: Changes go through documented change management: you request, we assess the security impact, apply with rollback available, and record it. That discipline is what keeps the rulebase clean - and it's covered by AMVIA's published Firewall Management SLA. --- # Zero Trust Security for UK Businesses | From £4.60/user URL: https://amvia.co.uk/cybersecurity/zero-trust Last updated: 2026-06 Zero trust is a security model that trusts no user or device by default - every request is verified against identity, device health and context before access is granted. It replaces perimeter trust with least-privilege access and continuous checks. AMVIA designs, deploys and manages zero trust for UK SMEs as part of one accountable managed cybersecurity service: security-first, Microsoft-certified. The old assumption - that anything inside the office network is safe - broke the moment your people started working from home, on phones, and across cloud apps. Zero trust fixes that by tying access to verified identity and device posture, not network location. Below is exactly how it works, what AMVIA runs for you, and what it costs. ## How does zero trust security work? Zero trust works by removing implicit trust from your network. Every user and device must prove who they are and that they meet your security standards on each access request - not once at the perimeter. It rests on four controls working together. - Identity-led verification - every request is authenticated and authorised against identity and context, backed by multi-factor authentication, instead of trusting a device because it sits on the network. - Least-privilege access - users and apps get only the access they genuinely need, so a stolen credential contains the blast radius rather than handing over the run of your systems. - Microsegmentation - your environment is split into controlled zones so a compromise in one area can't move laterally into the rest unchecked. - Continuous device posture - device health and risk are evaluated continuously; a device that drifts out of compliance loses access automatically until it's brought back to standard. The NCSC sets out the same model in its zero trust architecture design principles (ncsc.gov.uk). ## What's included in AMVIA's zero trust deployment? AMVIA delivers zero trust end to end - from assessment to fully managed enforcement - alongside your managed security service. We don't hand you a licence and walk away; our UK team builds the policies and operates them day to day. The rollout runs in four stages. - 01 Assess and map - we map your users, devices, applications and data flows, and pinpoint where implicit network trust currently exposes you. - 02 Identity and MFA foundation - we establish single sign-on and multi-factor authentication as the foundation every access decision is made against. - 03 Policies and segmentation - we define least-privilege access policies and segment access per application, replacing broad VPN-style network access with per-app controls. - 04 Manage and monitor - our team operates the policies, tuning access and responding to risk signals through our 24/7 managed SOC as your business changes. Device posture and conditional access are enforced through Microsoft Intune and Microsoft Defender, the tools we standardise on across our endpoint security stack. ## Why do UK SMEs need zero trust? UK SMEs need zero trust because the perimeter no longer holds and identity is now the primary attack surface. With hybrid working, cloud apps and stolen credentials, location-based security leaves the most common attack path - a compromised login - wide open. The data is blunt. - 43% of UK businesses experienced a cyber breach or attack in the last 12 months (gov.uk Cyber Security Breaches Survey 2025). - Phishing remains the single most common attack type, hitting 85% of businesses that identified a breach (gov.uk Cyber Security Breaches Survey 2025). - Only 47% of UK businesses have any two-factor authentication in place (DSIT 2025/26) - leaving the majority exposed to credential theft. Zero trust targets that first link directly: even a valid stolen credential can't roam, because each request is re-verified against identity and device health. ## Zero trust vs the traditional perimeter: what changes? The shift is from "trusted once you're inside" to "verified on every request". A VPN grants a connected device broad internal access; if that device or its credentials are compromised, the attacker often inherits wide network reach. Zero trust makes per-application decisions on every request instead. | | Dimension | Traditional perimeter / VPN | Zero trust | Trust basis | Network location ("on the network") | Verified identity + device posture | Access scope | Broad internal network access | Per-application, least-privilege | Stolen credential impact | Wide lateral movement | Contained blast radius | Remote / hybrid fit | Bolt-on, perimeter-bound | Native - access follows identity | Ongoing checks | One-time at connection | Continuous re-validation ## How much does zero trust cost? Zero trust licences start from £4.60 per user per month - the same list price as Microsoft 365 Business Basic, which carries the identity and conditional-access features the model is built on (microsoft.com/en-gb). That figure is the licence only; AMVIA's configuration and ongoing management are delivered as part of our managed security service. | | Service | From / user / month | Zero Trust licence | from £4.60 Licence only - requires AMVIA Managed Security to configure, monitor and tune the controls so zero trust actually works in practice rather than sitting unused. ## Why choose AMVIA for zero trust? AMVIA configures and runs zero trust for you with a UK security team - identity-led controls implemented to recognised standards, not a licence left for you to manage. We design the access policies, deploy MFA and segmentation, and operate the controls every day. - Certified to UK standards - AMVIA holds Cyber Essentials Plus and Microsoft Solutions Partner status (Modern Work, Security and Azure Infrastructure), so identity and access controls are implemented to recognised UK security standards. - 1,200+ UK businesses protected - we manage security for over 1,200 UK businesses across legal, finance, healthcare and professional services; zero trust slots into a proven managed practice. - Sheffield-based, UK-focused - our security engineers operate from Sheffield and understand UK compliance requirements and the realities facing British SMEs. ## Frequently asked questions Q: What is zero trust security? A: Zero trust is a security model built on "never trust, always verify". Instead of assuming anything inside the network perimeter is safe, every user, device and request is authenticated, authorised and continuously validated before access is granted. It combines strong identity, multi-factor authentication, least-privilege access and microsegmentation so one compromised account can't move freely across your systems. Q: How much does zero trust cost? A: AMVIA's zero trust licences start from £4.60 per user per month, the Microsoft 365 Business Basic list price that carries the underlying identity and conditional-access features. That covers licensing only; configuration and ongoing management are delivered through our managed security service, so the controls are set up correctly and operated day to day rather than left for your team to run alone. Q: Do I need a managed security service for zero trust? A: Yes. Zero trust is a model, not a single product you switch on - it needs identity policies, access rules and device-posture checks configured for your environment and maintained as it changes. AMVIA delivers zero trust alongside our managed security service, so licences are properly configured, monitored and tuned. The £4.60/user/month is the licence cost; managed security provides the expertise to operate it. Q: Is zero trust suitable for small businesses? A: Yes - arguably more so. Small businesses increasingly rely on cloud apps and remote working, which dissolves the traditional office perimeter older security depended on. Zero trust secures access based on identity and device health rather than location, which fits hybrid and remote teams well. With 43% of UK businesses breached in the last year and phishing involved in 85% of cases (gov.uk 2025), identity-led controls address the most common attack path directly. Q: How is zero trust different from a VPN? A: A VPN grants a device broad access to the internal network once connected - if that device or its credentials are compromised, the attacker often gains wide network access. Zero trust replaces that with per-application access decisions made on every request, based on verified identity and device posture. Users reach only the specific applications they're authorised for, with no implicit trust from being "on the network". Q: How long does a zero trust rollout take? A: Most SME deployments move in stages over a few weeks rather than a single switch-over. AMVIA starts by mapping users, devices and data flows, then lays the identity and MFA foundation before defining least-privilege policies and segmentation. We roll controls out gradually to avoid disrupting work, then manage and tune them continuously once enforcement is live. --- # Microsoft Defender for Endpoint: What UK SMEs Need to Know URL: https://amvia.co.uk/cybersecurity/endpoint-security/microsoft-defender-endpoint Last updated: 2026-08-28 Microsoft Defender for Endpoint is Microsoft's enterprise endpoint detection and response (EDR) platform. For SMEs, Microsoft Defender for Business - bundled into Microsoft 365 Business Premium - delivers equivalent protection at a fraction of the cost. Neither works on defaults. AMVIA configures and manages both as part of managed cybersecurity: one provider, security-first, Microsoft-certified. ## What is Microsoft Defender for Endpoint? Microsoft Defender for Endpoint (MDE) is Microsoft's enterprise-grade EDR platform: it detects, investigates, and responds to threats on Windows, macOS, Linux, iOS, and Android devices. It is distinct from the free Windows Defender Antivirus built into Windows, and from Microsoft Defender for Business, the SME-scoped edition. The Defender brand causes genuine confusion because three different products share the name: - Windows Defender Antivirus - consumer-grade signature-based malware protection built into Windows 10 and 11. No centralised management, no behavioural EDR. - Microsoft Defender for Endpoint - the enterprise EDR platform, licensed standalone or via Microsoft 365 E5. - Microsoft Defender for Business - a separate product for SMEs with up to 300 users, included in Microsoft 365 Business Premium. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, which makes properly configured endpoint protection a baseline control, not a luxury. ## What do the Defender for Endpoint plans include? Microsoft Defender for Endpoint ships in two tiers. Plan 1 covers prevention and basic response; Plan 2 adds full EDR, automated investigation, and threat hunting. Plan 2 is included in Microsoft 365 E5, which is why standalone MDE is primarily an enterprise choice. - Plan 1 (MDE P1): next-generation antivirus, attack surface reduction rules, device control, and manual response actions. - Plan 2 (MDE P2): everything in P1 plus endpoint detection and response with full telemetry, automated investigation and remediation, threat and vulnerability management, and proactive threat hunting. The vulnerability management module in P2 continuously assesses enrolled endpoints - flagging unpatched software, weak configurations, and known exposures - and ranks them by exploitability so teams fix what matters first. Microsoft documents the full capability set in its endpoint security guidance. ## Key MDE Plan 2 capabilities - Behavioural detection using machine learning and Microsoft's global threat intelligence - EDR with device isolation, process termination, and file quarantine - Automated investigation that analyses alert chains and recommends or executes remediation - Threat and vulnerability management for continuous posture assessment - Proactive threat hunting with advanced queries across endpoint telemetry - Integration with Microsoft Sentinel for SIEM and extended detection and response (XDR) ## Is Defender for Business the right choice for an SME? For most UK SMEs, yes. Microsoft Defender for Business - included in Microsoft 365 Business Premium for organisations with up to 300 users - provides protection equivalent to MDE Plan 2, packaged for businesses without a dedicated security team. It is one of the most cost-effective routes to enterprise-grade endpoint security available. Defender for Business includes next-generation antivirus, endpoint detection and response, attack surface reduction, automated investigation, and centralised management through the Microsoft 365 Defender portal. Its detection draws on Microsoft's cloud threat intelligence, built from telemetry across hundreds of millions of endpoints. When a new threat appears anywhere in that network, indicators reach connected endpoints within minutes - far faster than antivirus that waits for a scheduled signature update. | | Capability | Windows Defender AV | Defender for Business | Defender for Endpoint P2 | Built-in antivirus | Yes | Yes | Yes | Centralised management | No | Yes | Yes | Endpoint detection & response (EDR) | No | Yes | Yes | Attack surface reduction rules | Limited | Yes | Yes | Automated investigation | No | Yes | Yes | Threat & vulnerability management | No | Yes | Yes | Proactive threat hunting | No | No | Yes | Licensing | Free with Windows | M365 Business Premium | M365 E5 / standalone ## How much does Microsoft Defender for Business cost? Defender for Business carries no separate endpoint-security line item when you buy Microsoft 365 Business Premium, listed at £16.90 per user/month (ex VAT, annual commitment). Businesses on Business Basic (£4.60) or Standard (£9.60) do not receive Defender for Business. That makes Business Premium the most direct upgrade path for an SME that wants EDR. Standalone Defender for Business is also available as an add-on for tenants that cannot move to Premium. Whichever route fits, the cost of the licence is trivial against the downside: the average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025). ## Why does Defender need configuration beyond the defaults? Because the defaults protect the basics, not the business. Defender for Business and MDE ship with sensible starting settings, but the controls that stop real attacks - attack surface reduction, controlled folder access, network protection - are off or in audit mode until someone deliberately turns them on. Attack surface reduction (ASR) rules block common attack techniques at source: stopping Office apps from spawning executables (which kills most macro attacks), blocking credential theft from LSASS memory, and blocking executable content from email attachments. With 85% of breaches involving phishing (DSIT 2025), ASR rules that block email-borne techniques earn their keep. But many organisations leave ASR in audit-only mode indefinitely - visibility, zero protection. AMVIA configures Defender to Microsoft's recommended security baseline: - ASR rules enabled in block mode, not audit-only - Controlled folder access configured to resist ransomware encryption - Network protection enabled to block known malicious domains - Exclusions reviewed so nothing silently weakens detection ## Who investigates the alerts Defender generates? Detection is only half the job. Defender for Business raises alerts; someone has to triage them, separate noise from genuine threats, and contain what is real. Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26), so most have no structured process for the alerts their tools produce. AMVIA monitors Defender for Business alerts through AmviaIQ, investigates significant detections, and takes containment action when a threat is confirmed - turning a detection tool into a managed control. For businesses that want a heavier analyst layer, AMVIA's in-house 24/7 SOC provides a second opinion on endpoint alerts as part of managed detection and response. Where a full analyst function is needed, our managed SOC service sits on top of Defender. ## How are Defender devices deployed and managed? Centrally. Every Defender for Business and MDE device is managed through Microsoft Intune and the Microsoft 365 Defender portal - Intune handles enrolment, policy, and compliance; the Defender portal handles alerts, investigations, and endpoint health. There is no device-by-device fiddling. Enrolment can be automated with Windows Autopilot for new devices or scripted for an existing estate. Once enrolled, devices receive security baselines automatically, and Intune compliance policies can block non-compliant devices from corporate data via Conditional Access until they are remediated. AMVIA runs the full process - enrolling devices, deploying agents, applying baselines, and validating that every endpoint reports correctly - then manages it on an ongoing basis. Contact AMVIA on 0333 733 8050 to discuss Defender for Business for your business. ## Defender for Business configuration checklist - All managed endpoints enrolled in Defender for Business - ASR rules enabled in block mode - not left in audit-only - Controlled folder access configured against ransomware - Network protection enabled on every endpoint - Exclusions reviewed - no broad exclusions that weaken detection - Alerts monitored and investigated - not just collected ## Frequently asked questions Q: What's the difference between Defender for Endpoint and Defender for Business? A: Same engine, different packaging: Defender for Endpoint is the enterprise EDR platform; Defender for Business is the SME edition - bundled into Microsoft 365 Business Premium (£16.90/user/month ex VAT) with the core EDR capability but simplified management and some enterprise features trimmed. Q: Is Microsoft Defender good enough to replace our antivirus? A: For most SMEs, yes - the modern Defender stack is a genuine EDR product, not the free consumer antivirus people remember. The caveat is operational: it needs configuring past the defaults and its alerts need watching. Unmonitored EDR is a dashboard, not a defence. Q: We have Business Premium - are we already covered? A: You already own the capability; whether you're covered depends on configuration. Most tenants we audit have Defender features paid for but never enabled - policies at defaults, no alert triage. A one-day audit tells you exactly where you stand. Q: Who should watch the Defender alerts? A: Someone with security context, around the clock - attacks don't keep office hours, and 43% of UK businesses were breached or attacked in the past year (DSIT 2025). AMVIA runs Defender as a managed service: deployment, hardening and 24/7 triage on Enterprise plans. --- # What Is Next-Generation Antivirus (NGAV)? URL: https://amvia.co.uk/cybersecurity/endpoint-security/next-generation-antivirus Last updated: 2026-08-28 Next-generation antivirus (NGAV) uses machine learning, behavioural analysis, and cloud threat intelligence to detect threats based on what they do, not just what they look like. It catches novel and fileless attacks that signature-based tools miss. AMVIA deploys and manages NGAV - Microsoft Defender for Business - for UK SMEs as part of one accountable, security-first service. ## What is next-generation antivirus? NGAV is endpoint software that detects malware by behaviour and machine-learning analysis rather than by matching a file against a database of known signatures. That shift matters because attackers modify malware constantly - even a tiny change produces a new file hash that no signature will recognise. Traditional antivirus can only block threats it has already catalogued. NGAV closes that gap, which is why it sits at the core of managed cybersecurity for any UK business taking its security posture seriously. According to the Cyber Security Breaches Survey 2025, "43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and 85% of those breaches involved phishing (DSIT 2025)" - and many phishing payloads are crafted specifically to evade signature detection. ## How does NGAV differ from traditional antivirus? The difference is not incremental. Traditional antivirus is reactive - it blocks what has already been seen and catalogued. NGAV is predictive - it classifies and stops threats it has never encountered before, using machine learning, real-time behavioural monitoring, and shared cloud intelligence. Here is how the two approaches compare across the criteria that actually decide whether an attack gets through. | | Capability | Traditional antivirus | Next-generation antivirus (NGAV) | Detection method | Known malware signatures | Machine learning + behaviour | Novel / zero-day malware | Misses until catalogued | Detects on first encounter | Fileless / in-memory attacks | Not detected | Detected via memory + behaviour | Ransomware behaviour | Limited | Blocks rapid-encryption patterns | Threat-intelligence updates | Scheduled signature pushes | Cloud updates within minutes | Response capability | Block file | Block, isolate, terminate - Machine learning detection classifies an unseen file as likely malicious from its code structure, imported functions, entropy, and packing - protecting endpoints before any signature exists. - Behavioural analysis watches running processes and flags malware-like activity: rapid file encryption, LSASS credential access, or unexpected child processes. - Cloud threat intelligence aggregates data from millions of endpoints, so a threat seen anywhere becomes detectable everywhere within minutes. Microsoft details these layers in its endpoint security documentation. ## How does NGAV stop fileless attacks? Fileless malware never writes a file to disk - it runs entirely in memory using legitimate system tools like PowerShell, WMI, and mshta.exe. Signature scanning has nothing to match, so traditional antivirus is blind to it. NGAV catches these "living-off-the-land" attacks by analysing behaviour instead of files. When PowerShell downloads and executes a payload in memory, or WMI is abused to establish persistence, NGAV behavioural detection identifies the anomalous usage pattern and blocks the activity. The NCSC warns that attackers increasingly favour these techniques precisely because they evade legacy defences and are harder to investigate forensically. ## How do NGAV and EDR relate? NGAV and Endpoint Detection and Response (EDR) are related but distinct. NGAV is prevention - detecting and blocking threats before or early in execution. EDR adds a forensic and response layer: detailed telemetry of all endpoint activity, post-incident investigation, and response actions like device isolation and file quarantine. Modern products combine both in one agent. Microsoft Defender for Business - the NGAV AMVIA deploys - provides machine-learning detection, behavioural blocking, and cloud intelligence alongside EDR telemetry and automated investigation. For deeper coverage, see how EDR extends endpoint protection and how AMVIA delivers managed detection and response. ## Why do UK SMEs need NGAV? UK SMEs need NGAV because the threats most likely to hit them - phishing payloads and ransomware - are engineered to slip past signature-based tools. Defence that only recognises known malware leaves a permanent blind spot, and the cost of a single breach getting through is steep. The average cost of a data breach for UK organisations was "£3.29 million (IBM Cost of a Data Breach 2025)". Worse, only "25% of UK businesses have a formal incident response plan (DSIT 2025/26)" - meaning most have no structured way to handle what slips past automated defences. NGAV reduces how much gets through; managed monitoring handles what does. ## How is NGAV deployed and configured? NGAV only delivers full value when it is configured deliberately. Default installations - including Defender for Business - leave protective features switched off. Getting it right means turning protections on, not just installing the agent. - Attack surface reduction rules set to block mode, not audit-only. - Controlled folder access configured to shield critical directories from ransomware encryption. - Cloud-delivered protection enabled for real-time intelligence updates. - Exclusions reviewed carefully - each overly broad exclusion creates a detection blind spot. AMVIA reviews exclusions during onboarding and works with application vendors to avoid broad carve-outs wherever possible. Microsoft's own security guidance reinforces that hardening configuration is what separates real protection from a default install. ## How much does NGAV cost for UK SMEs? For UK SMEs on Microsoft 365 Business Premium, Defender for Business is included at no additional endpoint-security cost - one of the most accessible enterprise-grade NGAV products available. Business Basic and Standard tiers do not include it and would require an upgrade or standalone licensing. Microsoft 365 list prices (ex VAT, annual) are Business Basic £4.60, Business Standard £9.60, and Business Premium £16.90 per user per month, per Microsoft UK. Third-party NGAV products such as "SentinelOne, CrowdStrike Falcon, and Sophos Intercept X" are typically priced "between £3 and £8 per endpoint per month" depending on tier and volume. For most SMEs already on Business Premium, Defender for Business provides comparable protection without extra licensing - but AMVIA assesses each client's requirements before recommending a path. ## Why is NGAV alone not enough? No NGAV product detects 100% of threats. Sophisticated attackers test their techniques against major security products before launching, so novel methods will eventually evade automated detection. NGAV reduces the volume that gets through - it does not eliminate it. This is why AMVIA pairs NGAV deployment with 24/7 security monitoring and response. Alerts from Defender for Business are surfaced through AmviaIQ, investigated by AMVIA's security team, and acted on without waiting for you to raise a ticket. Monthly reports give visibility of every detection across your managed device estate, and regular configuration reviews keep protection current. This is the difference between a tool and a managed antivirus service: unmanaged NGAV generates alerts that may never be acted on; managed NGAV turns them into resolved incidents. Contact AMVIA on 0333 733 8050 to discuss NGAV protection for your business. ## Frequently asked questions Q: Should I replace my existing antivirus with NGAV? A: For most UK businesses, yes. If you are on Microsoft 365 Business Premium, Defender for Business provides NGAV capability at no additional cost, and running two endpoint security products at once can cause conflicts and performance problems. AMVIA assesses your current endpoint security during onboarding and recommends the appropriate transition path. Q: Can NGAV stop ransomware? A: NGAV provides meaningful ransomware protection through behavioural detection and attack surface reduction rules - for example, spotting rapid file-encryption patterns or blocking macro-based delivery. No technology guarantees 100% prevention, so AMVIA layers NGAV with controlled folder access, regular offline backups, and monitoring for defence in depth. Q: What is the difference between NGAV and a managed security service? A: NGAV is a technology - software on endpoints. A managed security service uses NGAV as a component, then adds alert monitoring, investigation, configuration management, and human response. NGAV without management produces alerts that may go unactioned; managed NGAV converts those alerts into investigated and resolved security incidents. Q: Does Microsoft Defender for Business count as NGAV? A: Yes. Defender for Business is a genuine NGAV product: it combines machine-learning detection, behavioural analysis, and cloud threat intelligence with EDR telemetry in a single agent. Included in Microsoft 365 Business Premium, it gives UK SMEs enterprise-grade endpoint protection without separate licensing when configured correctly. Q: What are fileless attacks and can NGAV detect them? A: Fileless attacks run in memory using legitimate tools like PowerShell, writing nothing to disk for signature scanners to find. NGAV detects them by analysing behaviour and memory activity rather than files, flagging anomalous tool usage - such as PowerShell downloading a payload - and blocking it before damage is done. Q: Is NGAV enough on its own to secure my business? A: No single tool is. NGAV reduces how many threats get through, but sophisticated attackers test against it beforehand. Effective security pairs NGAV with monitoring, investigation, and response - so the small percentage that evades automated detection is still caught and contained by people. --- # Endpoint Detection and Response (EDR) for UK Businesses URL: https://amvia.co.uk/cybersecurity/endpoint-security/edr-for-businesses Last updated: 2026-08-28 EDR for businesses is endpoint security software that detects threats by analysing device behaviour, not file signatures - catching ransomware, fileless malware, and zero-day attacks that antivirus misses. AMVIA deploys and manages Microsoft Defender for Business EDR for UK SMEs, monitored around the clock by our in-house SOC. One provider, security-first. Antivirus only stops threats it has already catalogued. EDR (Endpoint Detection and Response) watches what software actually *does* on a device, so a brand-new ransomware strain is caught the moment it starts encrypting files. That behavioural layer is now the baseline for serious managed cybersecurity, and for most UK SMEs it is already paid for inside Microsoft 365 Business Premium. ## What is EDR and how is it different from antivirus? EDR is software installed on every endpoint that continuously records process events, file changes, registry edits, memory operations, and network connections, then analyses that telemetry against detection rules, threat intelligence, and machine-learning models. Antivirus matches files to a signature database; EDR judges behaviour, so it catches threats no signature exists for yet. Traditional antivirus protects against threats it has already seen. It struggles with novel variants, polymorphic malware, and fileless attacks that never write a file to disc. EDR closes those gaps by focusing on activity rather than appearance - see our full breakdown of EDR vs antivirus for the technical detail. | | Capability | Traditional antivirus | EDR (e.g. Defender for Business) | Detection method | File signatures | Behaviour + ML analytics | Novel / zero-day malware | Often missed | Detected on behaviour | Fileless / in-memory attacks | Not detected | Detected | Historical investigation | None | Retained telemetry | Automated containment | Limited | Isolate device, kill process, roll back ## How does EDR detect and respond to threats? An EDR agent on each device captures telemetry and streams it to a central platform, where three layers run in parallel: known indicators of compromise (IOCs) are matched, behavioural analytics flag suspicious patterns, and machine-learning models surface anomalies that rules alone would miss. Confirmed threats trigger automated response. When suspicious behaviour is identified, the platform can quarantine a file, terminate a malicious process, isolate the compromised device from the network, or roll back changes made by ransomware. Because EDR retains historical telemetry, analysts can investigate an incident retrospectively rather than guessing what happened. What EDR detects that antivirus cannot: - Fileless malware - operating entirely in memory using legitimate system tools - Living-off-the-land attacks - abusing pre-installed binaries like PowerShell - Credential theft and lateral movement - harvesting credentials from memory and spreading across the network - Zero-day exploits - attacks against unpatched vulnerabilities - New ransomware variants - strains created daily, with no existing signature ## Why do UK SMEs need EDR? UK SMEs need EDR because most modern attacks are designed to defeat signature-based antivirus. According to the UK Government's Cyber Security Breaches Survey 2025, "43% of UK businesses experienced a cybersecurity breach or attack in the past twelve months" - many using fileless techniques and novel malware that only behavioural detection catches. The financial exposure is real: the average cost of a data breach for UK organisations was £3.29 million according to IBM's 2025 Cost of a Data Breach report. Yet only "25% of UK businesses have a formal incident response plan" (Cyber Security Breaches Survey 2025/26), so detections often pile up with no one to act on them. EDR without a response process is a half-measure. ## Is Microsoft Defender for Business a real EDR? Yes. For most UK SMEs, Microsoft Defender for Business is the primary EDR platform. It is included in Microsoft 365 Business Premium at no additional licence cost and delivers behavioural detection, attack surface reduction (ASR) rules, endpoint isolation, and integration with Microsoft's global threat intelligence network. Defender for Business is significantly more capable than the consumer Windows Defender built into Windows 10 and 11. ASR rules go a step further than detection - they stop specific attack techniques from executing at all, blocking attacks before EDR response is even needed. EDR tools like Defender for Business also satisfy the malware protection control required for Cyber Essentials certification. ## When does managed detection add value on top of EDR? EDR tools generate alerts; someone has to read, judge, and act on them. For businesses in regulated sectors, with elevated risk, or seeking MDR-level coverage, AMVIA layers its in-house 24/7 SOC on top of Microsoft Defender for Endpoint - reviewing every suspicious detection, giving clear remediation guidance, and taking direct containment action. This human-in-the-loop approach is what catches persistent threats - backdoors, remote access trojans, slow lateral movement - that an unattended tool would log and forget. EDR is the technology; managed detection and response is the service that makes it count. For the distinction in full, read MDR vs EDR. ## How much does managed EDR cost? For most UK SMEs, the EDR engine itself carries no extra licence cost - Microsoft Defender for Business is included in Microsoft 365 Business Premium at approximately £16.90 per user per month (Microsoft UK). The cost you are buying beyond the licence is the management: deployment, tuning, alert investigation, and response. - Microsoft Defender for Business - included in M365 Business Premium (~£16.90 per user per month) - AMVIA managed detection and response - priced per endpoint per month EDR should cover every managed endpoint - laptops, desktops, and servers - with no unmanaged device left holding network access. ## What does AMVIA's managed EDR include? AMVIA deploys and manages EDR for UK SMEs as part of its endpoint security service. We configure Microsoft Defender for Business, deploy attack surface reduction rules, monitor alerts through our SOC, investigate significant detections, and take containment action when threats are confirmed. Monthly reports give you clear visibility of protection status and incidents. Implementation checklist we work through: - EDR deployed on all managed endpoints - laptops, desktops, servers - ASR rules configured to block common attack techniques - Alerts monitored and investigated, not just collected - Automated containment configured for high-confidence detections - Coverage verified - no unmanaged devices with network access - Monthly status and detection report reviewed with you For a deeper technical view of the underlying detection technology, see endpoint detection and response. ## Frequently asked questions Q: What is EDR in simple terms? A: Endpoint security that watches behaviour instead of matching file signatures: it catches ransomware, fileless attacks and misused legitimate tools by spotting what they do, not what they look like - then gives responders the timeline and the kill switch. Q: How is EDR different from traditional antivirus? A: Antivirus asks 'is this file known-bad?'; EDR asks 'is this behaviour wrong?'. Modern attacks increasingly use no malware at all - stolen credentials and built-in admin tools - which signature-based antivirus can't see and behavioural detection can. Q: Does EDR slow down our machines? A: Modern agents are lightweight - the days of antivirus grinding laptops to a halt are over. The real operational cost of EDR isn't performance, it's attention: detections need triage, which is why most SMEs run it as a managed service rather than an unwatched console. Q: Which EDR should a UK SME choose? A: For Microsoft-centric businesses, Defender for Business (inside Business Premium at £16.90/user/month) is the pragmatic default - capability you may already license. The honest answer is that the operating model matters more than the logo: tuned and watched beats best-on-paper and ignored. --- # Endpoint Security for Remote and Hybrid Workers URL: https://amvia.co.uk/cybersecurity/endpoint-security/remote-worker-endpoint-security Last updated: 2026-03 Remote worker endpoint security protects company laptops, phones and data wherever staff connect - home broadband, public Wi-Fi or a client site - by securing the device itself rather than the network around it. AMVIA manages this with Microsoft Intune, Defender for Business and Conditional Access. One provider, security-first, Microsoft-certified. It is delivered as part of AMVIA's managed cybersecurity service and sits inside the wider endpoint security discipline. The principle is simple: when the office perimeter disappears, the device becomes the perimeter - so every laptop, phone and tablet must carry its own protection, encryption and access controls wherever it travels. ## How does remote worker endpoint security work? Remote worker endpoint security applies controls directly to the device and to every access request, not to a corporate network the device rarely touches. Each endpoint is managed, encrypted and monitored from the cloud, and access to business data is granted only when the device proves it is compliant. Three Microsoft technologies do the heavy lifting: - Microsoft Intune - manages devices over the internet: pushing security settings, patches, encryption and remote wipe without the device ever touching the office network. - Microsoft Defender for Business - endpoint detection and response (EDR) that monitors and contains threats on the device itself, wherever it connects. - Conditional Access - checks identity, device compliance and sign-in risk before granting access to Microsoft 365, blocking anything that fails. Because all three are cloud-delivered, a laptop on hotel Wi-Fi is governed by exactly the same rules as one plugged in at head office. The UK's National Cyber Security Centre recommends this device-led model in its home and remote working guidance. ## Why do UK SMEs need remote worker endpoint security? Hybrid work moved business data outside the firewall faster than most security models could follow. Devices now connect from networks no IT team controls, the attack surface has widened, and a single lost or compromised laptop can expose a whole organisation. The numbers make the risk concrete. - "43% of UK businesses experienced a cybersecurity breach or attack in the past twelve months" (DSIT Cyber Security Breaches Survey 2025). - "28% of UK employees now work in a hybrid pattern, splitting time between home and the office" (ONS, 2025). - "The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach Report, 2025)". - "Only 25% of UK businesses have a formal incident response plan" (DSIT Cyber Security Breaches Survey 2025/26). Remote workers also face risks office staff largely avoid: home routers with default passwords and stale firmware, public Wi-Fi exposed to man-in-the-middle attacks, and isolation that makes phishing easier to fall for without a colleague to sense-check a suspicious email. Device-level controls are what close that gap. ## VPN vs Zero Trust Network Access - which fits a cloud-first SME? For most Microsoft 365 businesses, a traditional VPN is no longer the right primary remote-access tool. A VPN drops the user inside the network and grants broad access; Zero Trust Network Access (ZTNA) grants access to specific apps only after verifying identity, device compliance and risk on every request. Conditional Access gives M365 customers ZTNA-style control with no extra product. | | Factor | Traditional VPN | Conditional Access (ZTNA-style) | Trust model | Implicit - on the network = trusted | Zero trust - every request verified | Access scope | Broad network access | Per-application, least privilege | Device compliance check | Usually none | Required before access granted | Performance | Routes cloud traffic through HQ | Direct to cloud, no bottleneck | Best for | Legacy on-premises apps and file servers | Microsoft 365, Teams, SharePoint, OneDrive A VPN may still be needed for specific on-premises systems that have not moved to the cloud - but it should not be the default front door for a workforce that lives in Microsoft 365. This is the zero trust principle applied to remote access. ## What does AMVIA's remote endpoint security include? AMVIA enrols every managed device in Intune, configures Defender for Business with EDR, deploys Conditional Access policies, and sets BYOD rules - then manages it all centrally so protection is identical whether your team is in the office or at home. You get a single accountable provider rather than a stack of disconnected tools. | | Capability | Unmanaged / DIY | AMVIA-managed | Device enrolment | Ad hoc, often skipped | Every endpoint in Intune | Disk encryption | Inconsistent | BitLocker enforced by policy | Threat detection | Basic antivirus | Defender for Business EDR, monitored | Access control | Password only | MFA + device-compliance Conditional Access | Lost-device response | Manual, slow | Documented remote wipe via Intune BYOD is handled two ways through Intune: full enrolment where staff consent, or Mobile Application Management (MAM) that protects only business apps and data - enforcing encryption, blocking copy-paste to personal apps, and enabling selective wipe without touching personal content. For field staff, the same controls extend to phones and tablets through mobile device management. ## How much does remote worker endpoint security cost? Most of the controls ship inside Microsoft 365 Business Premium, which lists at £16.90 per user, per month (ex VAT, annual commitment) on microsoft.com/en-gb. That single licence includes Intune, Defender for Business and Conditional Access - the full remote endpoint stack - so the technology cost is predictable and per-user. AMVIA's management fee is quoted on top of licensing and depends on device count and scope. The licence is the platform; the value is in correct configuration, monitoring and response - which is what separates a Business Premium subscription you own from an endpoint estate that is actually secured. AMVIA's hybrid-working configuration is detailed in our M365 hybrid working security guidance. ## Frequently asked questions Q: Do remote workers need a VPN? A: For most businesses on Microsoft 365, a traditional VPN is not needed for daily work. Teams, SharePoint and OneDrive are cloud services reached directly over the internet with MFA and Conditional Access. A VPN is only required for specific on-premises resources - internal databases or legacy file servers - that have not migrated to the cloud. Q: What happens if a remote worker's laptop is stolen? A: A managed laptop with BitLocker encryption keeps its data inaccessible without valid credentials. AMVIA triggers a remote wipe through Intune, revokes the user's Microsoft 365 sessions and forces a password reset so stolen credentials cannot be reused. These steps are pre-documented in AMVIA's lost-device procedure, so response is immediate rather than improvised. Q: Does home Wi-Fi create a security risk? A: With device-centric security, the home network matters far less. Defender for Business network protection blocks malicious domains regardless of the Wi-Fi in use, BitLocker protects data if the device is lost, and Conditional Access stops non-compliant devices reaching company data. Basic router hygiene - changing default passwords, using WPA3 - still helps but is not the primary control. Q: How do you secure personal (BYOD) devices? A: Through Microsoft Intune. Full enrolment applies corporate management where staff agree; Mobile Application Management protects only business apps and data on a personal device - enforcing encryption and selective wipe without affecting personal content. A written BYOD policy defines what data personal devices can reach and what happens when someone leaves. Q: Why use Microsoft tools rather than a separate security product? A: Intune, Defender for Business and Conditional Access are built into Microsoft 365 Business Premium and work together natively - one identity, one policy engine, one console. That avoids the gaps and overlap of bolting on third-party agents, keeps licensing simple, and gives AMVIA a single platform to manage and monitor across every remote endpoint. Q: Is Microsoft Defender for Business sufficient for remote workers without extra tooling? A: Defender for Business provides strong EDR, but tools do not equal protection. Alerts still need someone to triage, contain and respond to them. AMVIA's in-house team monitors Defender across your estate and acts on detections - turning the technology into an actual managed service rather than a dashboard nobody is watching. --- # Mobile Device Security for UK Businesses URL: https://amvia.co.uk/cybersecurity/endpoint-security/mobile-device-security Last updated: 2026-08-28 Mobile device security is the practice of protecting the smartphones and tablets that access your business email, Teams and files using policy, encryption and remote-wipe controls. AMVIA manages this through Microsoft Intune as part of our broader managed cybersecurity service - one provider, security-first, Microsoft-certified. ## What is mobile device security and what does it cover? Mobile device security protects the phones and tablets reaching your corporate data, enforcing screen locks, encryption, app controls and remote wipe from a single console. It spans company-owned devices under full management and personal BYOD devices under lighter application-only controls, and sits inside your wider endpoint security programme. A phone with access to Outlook, OneDrive and Teams holds the same sensitive data as a managed laptop - often with weaker controls. Treating mobiles as a first-class endpoint, not an afterthought, is the core idea. ## How does mobile device security work? It works through two layers: Mobile Device Management (MDM) for company-owned hardware and Mobile Application Management (MAM) for personal devices. Both run on Microsoft Intune, included with Microsoft 365 Business Premium (£16.90 per user/month, ex VAT, per Microsoft UK). - MDM enrols the whole device - controlling apps, OS updates, password complexity and full remote wipe. - MAM wraps only the business apps (Outlook, Teams, OneDrive), enforcing app PINs and blocking data leaking into personal apps, without touching personal content. - Conditional access then checks each device is enrolled and compliant before it reaches Microsoft 365. Without this, you have no visibility into which devices touch your data and no way to remove business data when a phone is lost or a staff member leaves. ## What are the most common mobile threats facing UK businesses? The biggest mobile threats are phishing, malicious apps, lost or stolen devices, and unsecured Wi-Fi. With 85% of breaches involving phishing (DSIT 2025), mobile is especially exposed because small screens hide sender addresses and shortened URLs, making fraudulent links harder to spot before a user taps. - Phishing and smishing - SMS, WhatsApp and email attacks that are harder to scrutinise on a phone. See our phishing protection service for layered defence. - Malicious applications - sideloaded Android apps and rogue store listings that harvest credentials. Kaspersky blocked approximately 33 million mobile malware incidents in 2024. - Lost and stolen devices - an unencrypted phone holding business email can be a reportable breach under UK GDPR. - Unsecured Wi-Fi - public networks expose credentials and session tokens to interception. ## MDM vs MAM - which do you need for company and BYOD devices? Use MDM for devices the business owns, and MAM for personal devices staff use for work. MDM gives full control and a complete wipe; MAM protects only business apps and respects personal privacy. Most UK SMEs run both side by side across a mixed fleet. | | Capability | MDM (company-owned) | MAM (personal / BYOD) | Device enrolment | Full device | App-level only | Controls OS updates & passcode | Yes | No | Manages business apps | Yes | Yes (Outlook, Teams, OneDrive) | Sees personal photos/messages | No | No | Wipe scope | Full factory reset | Selective - business data only | Best for | Corporate phones & tablets | Employee-owned devices On a MAM-enrolled BYOD device, Intune can only see the business apps it manages - never personal app data, photos, messages or browsing history. AMVIA provides clear staff privacy documentation so BYOD enrolment is transparent and adopted without friction. ## Why do UK SMEs need mobile device security? Because mobiles are now a primary attack surface and a primary breach route. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and unmanaged phones accessing corporate data widen that exposure. A lost device with unencrypted business email can trigger a notifiable breach. The ICO expects technical controls - encryption and remote wipe - to mitigate this. The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025), so a preventable loss carries real financial and reputational weight. The NCSC's device security guidance sets the baseline UK businesses are measured against. ## How does conditional access protect mobile devices? Conditional access requires a device to be enrolled in Intune and compliant before it can open Microsoft 365. A phone with no screen lock, an outdated OS, or one that has been jailbroken is blocked until it meets the standard. Pair this with conditional access policies for a consistent baseline. This is far stronger than trusting any device that presents valid credentials. It guarantees every device touching your data meets a minimum endpoint standard - whether company-owned or personal - and underpins a zero-trust posture across your mobile estate. ## How does remote wipe work and when is it used? Remote wipe removes business data from a lost, stolen or returned device - a full factory reset for company hardware, or a selective wipe of business apps only for BYOD. It is only effective with a documented procedure, so staff know exactly who to call and the wipe runs within hours, not days. AMVIA's managed service includes a documented remote-wipe procedure with out-of-hours initiation. Selective wipe is also a core part of leaver offboarding: business data is removed from a personal device on the final day of employment, leaving personal content untouched. ## How much does mobile device security cost? Mobile device security cost depends on device count and licensing. The platform itself, Microsoft Intune, is included in Microsoft 365 Business Premium at £16.90 per user/month (ex VAT, annual) per Microsoft UK - so many SMEs already own the licence and only need it configured and managed. AMVIA prices the managed layer - enrolment, policy design, compliance reporting and remote-wipe handling - on a per-device basis, scoped to your fleet. Request a free security audit for a fixed quote against your actual device numbers. ## How do you build a mobile security programme? Start by finding every device that touches business data, including unsanctioned personal phones. Then deploy MDM for company devices, MAM for BYOD, conditional access to block non-compliant devices, and a documented remote-wipe procedure. Review it regularly inside your wider security programme. Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26), so make sure mobile incidents are written into whatever response procedure you run. AMVIA configures and manages Intune MDM and MAM end to end - enrolment, policy, wipe requests and monthly compliance reporting. Call AMVIA on 0333 733 8050 to discuss your fleet. ## Mobile device security checklist - All devices accessing business data identified - including BYOD - MDM or MAM deployed - Intune enrolled for company devices, MAM for personal - Screen lock and storage encryption enforced via policy - Conditional access blocks non-compliant devices from Microsoft 365 - Remote-wipe procedure documented, with staff briefed on who to call ## Frequently asked questions Q: Why does mobile device security matter for business? A: Because phones and tablets read the same email and open the same files as laptops - with 85% of breaches involving phishing (DSIT 2025), the message reads identically on a phone, minus the desktop protections. An unmanaged mobile is an unlocked door into managed data. Q: What should a mobile security policy enforce? A: Encryption and PINs on every enrolled device, work data separated from personal, app and OS-version rules, and remote wipe for the inevitable losses. Enforced through MDM - policy documents without enforcement are wishes. Q: Can we secure personal phones without invading privacy? A: Yes - modern management containerises: business email and files live in a managed work profile that IT can control and wipe, while photos, messages and personal apps stay invisible to the company. That separation is what makes BYOD workable for both sides. Q: What's the first step if we've never managed mobiles? A: Inventory, then enrolment: find every device touching business data (there are always more than expected), enrol them into MDM - Microsoft Intune is included in many M365 plans you may already own - and switch on the baseline policies. AMVIA runs this as part of device management. --- # GDPR and Cybersecurity: What UK Businesses Must Do URL: https://amvia.co.uk/cybersecurity/compliance/gdpr-cybersecurity Last updated: 2026-03 GDPR cybersecurity means meeting UK GDPR Article 32: the legal duty to protect personal data with appropriate technical and organisational measures. A breach of that duty risks ICO investigation, fines, and reputational harm. AMVIA implements the controls - MFA, encryption, patching, email and endpoint security - under one accountable, Microsoft-certified provider. This is the compliance side of managed cybersecurity: the point where a technical failure becomes a legal one. If you handle personal data on UK customers or staff, security is not a best practice you can defer - it is written into law. ## Why is cybersecurity a legal obligation under GDPR? For any UK business handling personal data, security is a statutory duty, not an optional control. UK GDPR - the retained EU regulation as amended by the Data Protection Act 2018 - requires "appropriate technical and organisational measures" to protect personal data. A cyber failure that exposes data is therefore both an incident and a potential regulatory breach. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, with 69% of large businesses reporting breaches or attacks (DSIT 2025/26). Any of those incidents involving employee records, customer details, or financial data potentially triggered GDPR obligations, including mandatory reporting to the Information Commissioner's Office. ## What does UK GDPR Article 32 actually require? Article 32 does not list a fixed set of controls. It requires measures "appropriate to the risk," judged against the state of the art, cost, and the sensitivity of the data you process. In practice, the ICO expects you to have the baseline controls a business your size and risk profile should reasonably hold. The article names specific categories of measure: - Pseudonymisation and encryption of personal data - Ongoing confidentiality, integrity, availability, and resilience of systems - The ability to restore access to data promptly after an incident - A process to regularly test and evaluate the effectiveness of controls The NCSC Cyber Essentials scheme is widely accepted as the baseline that demonstrates Article 32 compliance for most SMEs. Its five controls - firewalls, secure configuration, access control, malware protection, and patch management - cover the attack vectors behind most reportable breaches. AMVIA holds Cyber Essentials Plus, the independently audited tier of that scheme. ## What happens after a breach? ICO enforcement explained When the ICO investigates a breach, it asks whether appropriate measures were in place beforehand: were MFA, patching, and access controls present; was the breach avoidable with affordable, proportionate controls; was it detected promptly; and was the 72-hour notification met. Inadequate controls plus a poor response produce the worst outcomes. The ICO takes a more lenient view where a business invested sensibly in security and responded transparently. Enforcement can still be substantial - and the published action itself often does more reputational damage than the fine. Notable cases reported by the ICO include: - A £20 million fine for British Airways after a breach exposed the personal and financial data of approximately 400,000 customers. - An £18.4 million fine for Marriott International after attackers accessed records of approximately 339 million guests. The ICO can fine up to £17.5 million or 4% of global annual turnover for serious violations. For SMEs the absolute figures are lower, but they can still be material against turnover. The average cost of a UK data breach was put at £3.29 million (IBM Cost of a Data Breach 2025), covering legal costs, remediation, downtime, and lost trust as well as penalties. ## What is the 72-hour breach notification rule? Under UK GDPR Article 33, where a personal data breach is likely to risk individuals' rights, the controller must notify the ICO within 72 hours of becoming *aware* - not from when the breach occurred. Because many incidents go undetected for weeks, early detection capability is directly tied to whether you can meet the deadline at all. The notification must set out the nature of the breach, the categories and approximate numbers of people and records affected, the likely consequences, and the measures taken to contain it. Where a breach poses a high risk - exposed financial data, health records, or identity-fraud risk - affected individuals must be told directly. Yet only 14% of UK businesses hold a formal incident response plan (DSIT 2025), so most would struggle to respond in time without a pre-built procedure. A defined incident response process is what makes the 72-hour clock survivable. ## What technical measures meet GDPR Article 32? For most UK SMEs, practical compliance starts with the technical controls that address the vulnerabilities the ICO most often finds in its investigations. The table below maps Article 32 expectations to the controls AMVIA configures. | | Article 32 expectation | Control required | How AMVIA implements it | Prevent unauthorised access | MFA on all accounts | MFA across Microsoft 365, VPN, and cloud apps | Protect data at rest | Device & disk encryption | BitLocker enforced on laptops, mobiles, and portable storage | Maintain system integrity | Patch management | Automated OS and application patching | Detect and contain malware | Endpoint protection | Microsoft Defender endpoint security on all devices | Reduce email-borne attacks | Email authentication & filtering | DMARC/DKIM/SPF and email security via the Barracuda suite With 85% of breaches involving phishing (DSIT 2025), credential theft remains the most common route to a reportable breach - which is why MFA and email security carry the most weight. Encryption matters too: a lost *encrypted* device may not be a reportable breach at all, because the data stays inaccessible, while an unencrypted one almost certainly is. ## What organisational measures does GDPR require? Technical controls alone do not satisfy GDPR. The ICO looks for evidence that policies exist *and are followed*, not just written. Article 32 is paired with governance: documented security policies communicated to staff, a formal breach-response procedure covering the 72-hour notification, regular data-handling training, data protection impact assessments (DPIAs) for high-risk processing, and data processing agreements with suppliers who handle data on your behalf. A documented policy backed by functioning controls is far stronger than either alone. This is where holding Cyber Essentials or IASME Cyber Assurance helps - it provides independent, documentary evidence that your "appropriate measures" are real rather than aspirational. ## How does AMVIA support GDPR security compliance? AMVIA's managed cybersecurity service implements and maintains the exact controls Article 32 expects - MFA, endpoint protection, patching, email security, and encryption - under one accountable provider. We support security certification as documentary evidence of those measures, and provide incident response support, including guidance on ICO notification obligations when an incident occurs. The alignment between Cyber Essentials and GDPR security duties is well established across UK business: 49,248 security certifications were issued in 2025 (NCSC). One provider. Security-first. Microsoft-certified - so the technical controls and the compliance evidence come from the same place. ## How much does GDPR-compliant security cost? There is no single price, because the controls scale with your data and headcount. Most SMEs already own much of what they need: encryption and Defender endpoint protection are included in Microsoft 365 Business Premium at £16.90 per user/month (ex VAT, annual), against Business Standard at £9.60 and Business Basic at £4.60. The cost is rarely the licences - it is the configuration, monitoring, and evidence. AMVIA's managed service layers configuration, 24/7 monitoring, and incident response on top of that licensing, so the Article 32 controls are not just bought but proven. Pricing depends on user count and scope; a free security audit establishes the baseline before any quote. ## Frequently asked questions Q: Does every cyber incident have to be reported to the ICO? A: No. Only breaches likely to risk individuals' rights and freedoms require ICO notification. A quickly contained incident where no data was accessed or exfiltrated may not be reportable - but the assessment must be documented either way. AMVIA advises on notification obligations as part of incident response support, so the risk decision is recorded and defensible. Q: What GDPR fines has the ICO issued for security failures? A: The ICO has issued substantial fines for security failures, including £20 million for British Airways and £18.4 million for Marriott International following major data breaches. For SMEs the figures are usually lower, but still material against turnover, and the published enforcement action causes lasting reputational damage. The ICO concentrates enforcement on organisations with clearly inadequate controls or poor responses. Q: Does Cyber Essentials prove GDPR compliance? A: Not on its own, but it goes a long way. Cyber Essentials demonstrates the baseline technical controls the ICO expects under Article 32, which is why it is widely accepted as evidence of "appropriate measures" for SMEs. GDPR also requires organisational measures - policies, training, DPIAs, and supplier agreements - so certification is necessary supporting evidence rather than a complete defence. Q: How quickly must we report a breach under GDPR? A: Within 72 hours of becoming aware of a breach that is likely to risk individuals' rights, you must notify the ICO under Article 33. The clock starts at awareness, not at the moment of the breach. Where notification is delayed, you must document the reason. High-risk breaches also require affected individuals to be told directly without undue delay. Q: What is the maximum GDPR fine in the UK? A: The ICO can fine up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious violations - including security failures under Article 32. In practice, fine levels reflect the severity, the adequacy of controls beforehand, and the quality of the response. Most SME outcomes are far lower, but enforcement is published regardless of size. Q: Which technical controls matter most for GDPR? A: MFA, encryption, patching, endpoint protection, and email security cover the vulnerabilities the ICO most often finds in breach investigations. With 85% of breaches involving phishing (DSIT 2025), MFA and email security carry the most weight, while device encryption can keep a lost laptop from becoming a reportable breach at all. These five form the core of GDPR-relevant security. --- # NIS2 Compliance for UK Businesses: What You Need to Know URL: https://amvia.co.uk/cybersecurity/compliance/nis2 Last updated: 2026-03 NIS2 is the EU's updated cybersecurity directive, in force since October 2024, mandating risk management, 24-hour incident reporting and board-level accountability across 18 sectors. UK businesses are not directly bound, but those supplying EU customers or running EU subsidiaries must meet equivalent standards. AMVIA helps UK SMEs build the controls NIS2 demands - one provider, security-first. ## What is NIS2 and why does it matter to UK firms? The Network and Information Security Directive 2 (NIS2) is the EU's expanded framework of mandatory cybersecurity requirements. Adopted in December 2022 and required in national law by October 2024, it replaces the original 2016 NIS Directive and widens both the sectors covered and the obligations imposed. Post-Brexit, EU law does not apply directly to UK entities. But NIS2's reach extends through supply chains, customer contracts and EU-based subsidiaries - so UK firms feel its effects indirectly. The threat backdrop is real on both sides of the Channel: 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and 85% of those breaches involved phishing (DSIT 2025) (Cyber Security Breaches Survey 2025, gov.uk). If you run managed cybersecurity controls already, you have a head start on NIS2's technical baseline. ## When does NIS2 affect a UK business? NIS2 reaches UK organisations in three ways: when they supply EU customers bound by the directive, when they operate subsidiaries inside an EU member state, and when they provide ICT or managed services to in-scope EU clients. In each case the requirement arrives through contracts and procurement, not through UK law. - Supplying EU customers - EU organisations must manage cybersecurity risk in their supply chains. UK suppliers will increasingly see NIS2-equivalent security clauses in procurement questionnaires, contracts and due-diligence checks. Suppliers that cannot demonstrate adequate controls risk losing the business. - Operating EU subsidiaries - A UK parent with subsidiaries in EU member states is directly subject to NIS2 through those entities, which must meet the local transposition's controls, reporting and governance rules. - MSPs and digital infrastructure - NIS2 names ICT service management, managed service providers and digital infrastructure explicitly. UK MSPs and cloud providers serving EU customers may inherit obligations through those relationships. ## Who does NIS2 cover: sectors and scope? NIS2 covers 18 sectors split into "essential" and "important" entities. Essential entities include energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration and space. Important entities include postal services, waste management, manufacturing, food production, digital providers, research and chemicals. The expansion from the original directive is substantial. The 2016 NIS Directive covered only operators of essential services and digital service providers. NIS2 pulls in managed service providers, manufacturing, food production, waste management and postal services - categories previously outside EU cybersecurity regulation. For UK technology firms serving EU clients, the inclusion of ICT service management and cloud providers is the headline change. ## What does NIS2 require organisations to do? NIS2 imposes both technical and organisational measures. Organisations must run a documented risk-management process covering security policies, incident handling, business continuity, supply chain security, vulnerability handling, effectiveness testing and cryptography. The directive treats these as a minimum baseline, not a wish list. The standout obligations are the reporting clock and personal accountability: - Incident reporting is far stricter than UK GDPR. An early warning to the national authority is due within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Those timelines only work if detection and escalation already exist - yet just 25% of UK businesses have a formal incident response plan (DSIT 2025/26). - Management accountability is explicit. Senior management can be held personally liable for failing to implement adequate measures, moving cybersecurity from a technical concern to a board-level governance duty. - Penalties are material: for essential entities, fines can reach up to 10 million euros or 2% of global annual turnover, whichever is higher, under Article 34 of the directive. ## NIS2 vs UK GDPR: how do the reporting rules compare? The reporting gap is the single most operationally demanding part of NIS2 for firms used to the UK GDPR regime. The table below sets the two side by side. | | Requirement | NIS2 | UK GDPR | Early warning to authority | Within 24 hours of awareness | Not required | Initial/full notification | Within 72 hours | Within 72 hours to the ICO | Final report | Within one month | No fixed final-report deadline | Personal management liability | Yes - explicit | Limited | Maximum financial penalty | €10m or 2% global turnover | £17.5m or 4% global turnover Meeting a 24-hour clock needs detection and triage running around the clock. AMVIA's 24/7 security monitoring and incident response processes are built to surface and escalate significant incidents inside that window. ## How does NIS2 map to UK security standards? NIS2's technical controls align closely with established UK guidance. The NCSC's five technical controls - boundary firewalls, secure configuration, access control, malware protection and patch management - form a significant subset of NIS2's requirements, and the NCSC Cyber Assessment Framework (CAF) maps to its fuller governance, risk and resilience scope (National Cyber Security Centre). Firms that hold a recognised baseline certification, keep documented incident procedures, run regular risk assessments and manage supplier security have already covered much of NIS2. The gap usually sits in governance: formal risk-management processes, board-level accountability and structured reporting. AMVIA holds Cyber Essentials Plus and applies Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus vulnerability management and patching to close the technical side. ## What practical steps prepare a UK business for NIS2? For UK firms that must show NIS2-equivalent security to EU customers or through EU subsidiaries, a structured readiness path works best. It starts with scoping exposure and ends with formal governance. - Assess exposure - identify EU customers, EU subsidiaries and any contract clauses referencing NIS2 or equivalent standards. - Implement technical controls - ensure endpoint security, access management, patching and network protection are in place and monitored. - Establish incident response - document detection, escalation and reporting that can meet the 24-hour early-warning rule. - Address supply chain security - assess key technology suppliers' security posture and record the assessment. - Formalise governance - make cybersecurity a board agenda item with documented accountability for risk decisions. This is the same groundwork that strengthens GDPR and cybersecurity compliance and complements continuous managed detection and response. ## What is the UK regulatory outlook? The UK government is reviewing its own NIS Regulations (2018) and is expected to update them to align with - though not copy - NIS2. The Cyber Security and Resilience Bill, announced in the 2024 King's Speech, is set to widen UK cybersecurity regulation and tighten incident reporting. Regardless of the exact UK timeline, the measures NIS2 requires - risk management, access control, incident response and supply chain security - are simply good practice. The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025), which makes the business case for acting now rather than waiting for a deadline. AMVIA supports NIS2 compliance by implementing the technical and organisational measures UK businesses need; call 0333 733 8050 to discuss your readiness. ## Frequently asked questions Q: Does NIS2 apply to UK businesses? A: Not directly - the UK is no longer subject to EU law post-Brexit. But UK firms supplying EU organisations bound by NIS2 may face contractual requirements to meet equivalent standards, and any UK business with an EU subsidiary is subject to NIS2 through that entity. The UK is also reviewing its own NIS Regulations and is expected to introduce similar obligations. Q: How quickly must NIS2 incidents be reported? A: NIS2 requires an early warning to the relevant national authority within 24 hours of detecting a significant incident, a fuller notification within 72 hours, and a final report within one month. These timelines are stricter than UK GDPR's 72-hour ICO notification and need robust detection and escalation already running to be achievable in practice. Q: What sectors does NIS2 cover? A: NIS2 covers 18 sectors, split into essential entities (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space) and important entities (postal services, waste, manufacturing, food, digital providers, research, chemicals). This is far broader than the original NIS Directive, which covered only essential-service operators and digital service providers. Q: What are the penalties for NIS2 non-compliance? A: For essential entities, NIS2 fines can reach up to 10 million euros or 2% of global annual turnover, whichever is higher, under Article 34 of the directive. Beyond fines, NIS2 introduces personal liability for senior management, so directors can be held accountable for failing to implement adequate security measures - a significant shift toward board-level governance of cyber risk. Q: How can AMVIA help with NIS2 readiness? A: AMVIA helps UK SMEs build the technical and organisational controls NIS2 expects: endpoint protection with Microsoft Defender for Endpoint, 24/7 monitoring through our in-house SOC, documented incident response that meets the 24-hour rule, vulnerability and patch management, and supplier-security assessments. We hold Cyber Essentials Plus and work as a single accountable provider - security-first, Microsoft-certified. Q: Is NIS2 the same as ISO 27001? A: No. NIS2 is an EU directive imposing legal obligations on in-scope organisations, while ISO 27001 is a voluntary information-security management standard. They overlap on controls - risk management, access control, incident handling - so an existing security management system covers part of NIS2, but certification alone does not satisfy NIS2's reporting and governance duties. --- # IASME Cyber Assurance Explained for UK SMEs URL: https://amvia.co.uk/cybersecurity/compliance/iasme-cyber-assurance Last updated: 2026-03 IASME Cyber Assurance is a UK cybersecurity certification built for SMEs. It covers technical controls plus governance, risk management, security policies and GDPR - going well beyond the five technical controls of Cyber Essentials. AMVIA implements the controls, writes the policies and manages the whole assessment for you. ## What is IASME Cyber Assurance? IASME Cyber Assurance is a comprehensive UK security standard for small and medium businesses, spanning 149 controls across five domains: governance and risk management, information security policies, security management, asset management and technical controls. Unlike Cyber Essentials, it tests whether you *manage* security, not just whether the technology is switched on. It also embeds GDPR data protection requirements, so one certification covers both your cybersecurity and your data protection obligations. That dual focus is why it sits a clear step above the purely technical schemes - it asks who is accountable, what the policies say, and how risk is assessed. If you want the parent picture of how this fits a wider programme, see AMVIA's managed cybersecurity pillar. Governance gaps - not single technical failures - drive a large share of UK incidents. The Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a breach or attack in the past 12 months (DSIT 2025), and many lacked the policies and risk processes IASME Cyber Assurance is designed to enforce. ## How does IASME relate to Cyber Essentials? IASME runs the Cyber Essentials scheme under licence from the NCSC and also owns the broader Cyber Assurance standard. Cyber Essentials covers five technical controls; Cyber Assurance includes all five and layers governance, policy, risk management and GDPR on top. Cyber Essentials focuses on firewalls, secure configuration, access control, malware protection and patch management - strong cover against commodity attacks, achievable at any size. There were 49,248 Cyber Essentials certifications in 2025 according to the NCSC. But it does not address security policies, business continuity, risk management or data protection. | | | Cyber Essentials | IASME Cyber Assurance | Five technical controls | Yes | Yes (included) | Security policies & governance | No | Yes | Risk management & risk register | No | Yes | GDPR data protection controls | No | Yes | Independent verification option | No | Yes | Designed for | Any size | UK SMEs A business can hold Cyber Essentials yet have no written policies, no risk process and no documented data protection approach. IASME Cyber Assurance requires all of it, giving customers, partners and regulators far greater confidence in your security maturity. ## What does the IASME Cyber Assurance standard cover? The standard spans five domains. Together they prove security is managed as an ongoing responsibility, not a one-off tick-box exercise - the gap that catches most growing SMEs. - Governance and risk management - regular risk assessments, a maintained risk register and documented incident response. Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26); IASME requires one. - Information security policies - written, communicated and enforced policies covering acceptable use, access control and data handling. - Security management - assigned responsibilities, regular effectiveness reviews and threat-landscape awareness. - Asset management - a current inventory of devices, software, data stores and cloud services, classified by sensitivity. - Technical controls - the five Cyber Essentials controls plus encryption, backup and monitoring. With 85% of breaches involving phishing (DSIT 2025, Cyber Security Breaches Survey), this section hardens email, access and endpoints. AMVIA pairs this with vulnerability management to keep controls evidenced year-round. ## How does IASME Cyber Assurance compare to ISO 27001? ISO 27001 is the international information security management standard - comprehensive, highly credible, and the global benchmark. It is also complex and costly: extensive documentation, internal audits, management reviews and surveillance audits by accredited bodies. For many SMEs that is disproportionate to their size and risk. IASME Cyber Assurance provides approximately 70% of ISO 27001 coverage, scoped and priced for SMEs, with a more proportionate assessment and lower cost. The average cost of a data breach for UK organisations was £3.29 million (IBM Cost of a Data Breach 2025) - structured security management is a cost-effective way to reduce that exposure. For firms planning ISO 27001 later, IASME Cyber Assurance is the ideal stepping stone. The policies, governance and risk processes it requires form the foundation ISO 27001 builds on, so you do not start from scratch. AMVIA delivers it as part of its managed cybersecurity service. ## How does the assessment process work? IASME Cyber Assurance is assessed via an online questionnaire reviewed by an IASME-approved assessor. The questionnaire covers all 149 controls, and answers must be backed by evidence - policies, training records, risk assessments, asset inventories and configuration documentation. An independently verified version is also available for businesses with more demanding customer or regulatory needs. In that route the assessor reviews evidence in depth and may interview staff or inspect systems directly, providing the strongest evidence of security maturity. ## How much does IASME Cyber Assurance cost? The certification fee for most SMEs falls in a typical UK 2026 range of £500 to £1,500, depending on organisation size and the level of assessor involvement. That is the assessment fee alone. Implementing missing controls, writing the required policies and preparing evidence are additional and depend on your starting position. AMVIA recommends allowing eight to twelve weeks for a business starting from scratch. A readiness assessment shows exactly where you stand and what to fix before the formal assessment, so you do not pay for a failed first attempt. ## How does AMVIA support IASME certification? AMVIA guides UK businesses through IASME Cyber Assurance as part of its managed cybersecurity service: implementing the technical controls, assisting with policy development and risk documentation, and managing the questionnaire and evidencing process. One provider, security-first, Microsoft-certified engineers. For businesses treating IASME Cyber Assurance as a stepping stone to ISO 27001, AMVIA builds the governance foundation systematically - so the investment directly supports future ISO 27001 work rather than running as a parallel project. Where a control gap is technical, AMVIA closes it with services such as penetration testing and GDPR-focused cybersecurity. ## Readiness checklist - Written information security policy documented and communicated to staff - Risk assessment conducted and documented, with a maintained risk register - Asset inventory maintained - all devices, software and cloud services recorded - Staff security awareness training evidenced - GDPR controls in place - privacy notices, consent management, breach response ## Frequently asked questions Q: Is IASME Cyber Assurance better than Cyber Essentials? A: It is broader. IASME Cyber Assurance includes the five Cyber Essentials technical controls plus governance, risk management, policies and GDPR. Whether it is "better" depends on your goal: government contracts usually specify Cyber Essentials, but to prove overall security maturity to customers and supply chains, Cyber Assurance is the more credible standard. Q: Does IASME Cyber Assurance meet government contract requirements? A: Most UK government contracts specify Cyber Essentials as the minimum. IASME Cyber Assurance includes Cyber Essentials, so it meets and exceeds that bar. However, tenders often name Cyber Essentials specifically, so confirm with the contracting authority before relying on Cyber Assurance alone. AMVIA helps you check the requirement before you certify. Q: How much does IASME Cyber Assurance cost? A: For most SMEs the assessment fee falls in a typical UK 2026 range of £500 to £1,500, set by the certifying body and varying by assessor. That is the certification fee only. Implementing missing controls, writing policies and AMVIA's preparation support are additional. Contact AMVIA for a tailored quote based on your current position. Q: How long does IASME Cyber Assurance take to achieve? A: AMVIA recommends allowing eight to twelve weeks for a business starting from scratch. The timeline covers implementing missing technical controls, developing policies, completing a formal risk assessment, building an asset inventory and gathering evidence. Businesses that already hold Cyber Essentials or have mature documentation can move considerably faster. Q: Does IASME Cyber Assurance cover GDPR? A: Yes. IASME Cyber Assurance embeds GDPR data protection requirements within its framework, so one certification addresses both cybersecurity and data protection obligations. It is not a substitute for legal advice, but it gives structured evidence - privacy notices, consent management and breach response - that supports your wider compliance position. Q: Is IASME the same as the NCSC? A: No. IASME is an independent organisation that runs the NCSC's Cyber Essentials scheme under licence and owns the separate Cyber Assurance standard. The NCSC sets the national guidance; IASME delivers the certifications and approves the assessors who review your evidence. --- # How Much Does Managed Cybersecurity Cost in the UK? URL: https://amvia.co.uk/cybersecurity/questions/how-much-does-managed-cybersecurity-cost Last updated: 2026-03 Managed cybersecurity in the UK typically costs £8–£30 per user per month (typical UK 2026 range), depending on scope. Basic endpoint protection starts from £8/user; a comprehensive managed SOC with 24/7 monitoring and incident response runs £20–£35/user (market rates as of 2026). AMVIA bundles this under one provider - security-first, Microsoft-certified - so you pay for outcomes, not overlapping tools. That headline range is the answer most buyers want, but the figure that matters is what sits inside it. The same per-user price can buy a thin antivirus subscription or a fully managed cybersecurity service with a human analyst watching your estate around the clock. Below is exactly what moves the number, tier by tier, so you can budget honestly and compare like with like. ## What drives the cost of managed cybersecurity? Price is set by six variables, not one. The biggest is service scope: detection-only tooling is cheap, but a service that investigates and contains threats on your behalf costs more because there are people behind it. Get clear on these before you compare quotes. - Number of users and endpoints - most services are priced per user or per endpoint per month. More devices means a higher total, but the per-unit rate usually falls with volume. - Service scope - basic endpoint protection is far cheaper than a package adding managed detection and response, SOC monitoring, email security, and vulnerability management. - Compliance requirements - financial services, healthcare and legal firms often need extra controls, audit support and reporting that lift the price. - Monitoring hours - business-hours cover is cheaper than 24/7. For anyone handling sensitive data, round-the-clock 24/7 security monitoring is the sensible floor. - Number of sites - multi-site businesses may need additional network security and site-specific monitoring. - Response level - some services only detect and alert. Full MDR investigates and actively contains the threat for you. The UK threat picture justifies the spend. According to the UK government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the attack type (DSIT 2025) - which is why email protection is non-negotiable at every tier. ## What do the managed cybersecurity pricing tiers actually buy? Most UK providers cluster around three tiers. The table below shows indicative monthly per-user pricing for SMEs with 20–200 users. Use it to sanity-check any quote: if a "comprehensive" price looks like a basic one, the scope has been cut somewhere - usually the 24/7 monitoring or the incident response. | | Feature | Basic Protection £8–£12/user/mo | Standard £15–£20/user/mo | Comprehensive £22–£30/user/mo | Endpoint protection (EDR) | ✓ | ✓ | ✓ | Email security | ✓ | ✓ | ✓ | Vulnerability scanning | ✗ | ✓ | ✓ | 24/7 SOC monitoring | ✗ | ✓ | ✓ | Incident response | ✗ | Basic | ✓ | Threat hunting | ✗ | ✗ | ✓ | Compliance reporting | ✗ | Basic | ✓ | Dedicated security analyst | ✗ | ✗ | ✓ *Prices are indicative for UK SMEs with 20–200 users (typical UK 2026 range). Actual pricing depends on your specific requirements.* The jump from Standard to Comprehensive is where 24/7 SOC monitoring, active incident response and threat hunting come in. For a regulated firm, that jump is not optional - it is the difference between being told you were breached and having someone stop it at 3am. ## What does a managed cybersecurity service include for the money? A service worth paying for covers detection, prevention and response across every entry point - endpoint, email and identity. AMVIA's stack is built on Microsoft Defender for Endpoint and the Barracuda email and network suite, monitored by our in-house 24/7 SOC. One provider, one bill, no tool sprawl. At AMVIA the standard inclusions are: - Endpoint detection and response via Microsoft Defender for Endpoint, monitored continuously by our SOC. - Email security and anti-phishing through the Barracuda suite - your highest-risk channel given the phishing data above. - 24/7 monitoring and managed detection - alerts triaged and acted on by analysts, not left in a dashboard. - Vulnerability scanning and patch oversight through ongoing vulnerability management. - Incident response with investigation and containment, ideally inside the monthly fee rather than billed per incident. For Microsoft-centric businesses, much of this builds on licensing you may already own. Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual commitment) per Microsoft UK, and includes Defender for Business and Intune - so a good provider extends what you have rather than selling you a parallel stack. ## Is managed cybersecurity worth the cost for a UK SME? Yes - the maths is straightforward when you weigh the subscription against the cost of a breach. The government's Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach at £3,550 (DSIT 2025), and that excludes downtime, lost trust and regulatory exposure. A year of managed protection typically costs less than a single serious incident. The NCSC is clear that small and medium businesses are routinely targeted precisely because their defences are assumed to be weaker. Managed cybersecurity closes that gap without you hiring a security team - you rent the capability per user instead. For most SMEs, the incremental cost of covering one more user is trivial against the downside of leaving them exposed. AMVIA protects 1,200+ UK businesses and holds Cyber Essentials Plus and Microsoft Solutions Partner status (Modern Work, Security, and Infrastructure). That is the practical case: a single accountable provider, security-first, staffed by Microsoft-certified engineers. ## How does AMVIA price managed cybersecurity? AMVIA prices per user per month, with the scope agreed up front so there are no per-incident surprises. We map your current Microsoft licensing first, then layer only what is missing - usually managed detection, email security and 24/7 SOC cover - so you are not paying twice for overlapping tools. We will not quote a number until we have seen your estate. A short free security audit tells us your user count, your current controls and your compliance obligations, which is everything needed to give you a real figure rather than a brochure range. Most SMEs land in the Standard-to-Comprehensive band once 24/7 monitoring is included. ## Frequently asked questions Q: What should be included in a managed cybersecurity service? A: A comprehensive managed service should include endpoint detection and response, email security with anti-phishing, 24/7 monitoring, vulnerability scanning, patch management, and incident response. 85% of businesses that experienced a breach identified phishing as the attack type (DSIT 2025), so email protection is non-negotiable. Always check whether incident response is in the monthly fee or billed per incident. Q: How do managed cybersecurity costs scale with business growth? A: Most providers use per-user-per-month pricing, so costs rise roughly linearly as you add staff. Volume discounts typically apply at 50, 100 and 250 users, and the per-user rate often falls at scale because fixed overhead spreads across more endpoints. Against an average disruptive breach cost of £3,550 (DSIT 2025), covering each new user is a sound investment. Q: Are there hidden fees in managed cybersecurity contracts? A: Watch for per-incident response charges, overage fees on alert volumes, and separate costs for onboarding or offboarding users. Some providers also bill extra for compliance reporting or audit support. AMVIA agrees scope up front and keeps incident response inside the monthly fee, so the price you sign is the price you pay. Q: Is 24/7 monitoring really necessary, or is business-hours cover enough? A: Attackers do not work office hours - many intrusions begin in the evenings or at weekends precisely to delay detection. Business-hours monitoring leaves a nightly window where a threat can spread unchecked. For any business handling sensitive or regulated data, 24/7 SOC monitoring is the sensible minimum and is the main reason Comprehensive tiers cost more. Q: Does managed cybersecurity replace cyber insurance? A: No - they do each other's jobs. Insurance pays out after an incident; managed cybersecurity reduces the chance and severity of one happening. Most insurers now require baseline controls such as MFA, EDR and patching before they will cover you, so a managed service often lowers your premium and keeps your policy valid. Q: How is managed cybersecurity different from antivirus? A: Antivirus is a single tool that blocks known malware on a device. Managed cybersecurity is a service: detection across endpoint, email and identity, plus human analysts who investigate and contain threats 24/7. Antivirus tells you something is wrong; a managed service does something about it. --- # What Is the Difference Between an MSP and an MSSP? URL: https://amvia.co.uk/cybersecurity/questions/msp-vs-mssp Last updated: 2026-03 An MSP (managed service provider) runs your day-to-day IT - helpdesk, infrastructure, devices, backups and user support. An MSSP (managed security service provider) does one thing: cybersecurity - threat monitoring, detection, incident response and compliance. AMVIA combines both under one accountable, security-first provider, so nothing falls between the two. ## What does an MSP actually do? An MSP keeps your technology running. It manages servers, networks, cloud platforms, email, end-user devices and the helpdesk, and it handles backups, patching and strategic IT planning. The goal is uptime and productivity - not threat hunting. Security is usually a side feature, not the core discipline. Most UK SMEs start with an MSP because the day-to-day pain is obvious: a laptop won't connect, email is down, a new starter needs onboarding. That work matters. But an MSP optimised for keeping the lights on is rarely staffed or tooled to detect a determined attacker - which means most "IT support" relationships leave a security gap the business owner never sees until something breaks. If you want a deeper view of the operational side, see our guide to managed IT support for UK SMEs. ## What does an MSSP actually do? An MSSP is a security specialist. It runs continuous threat monitoring, manages detection and response, handles vulnerability management and incident response, and produces the evidence you need for compliance. Where an MSP measures success in uptime, an MSSP measures it in dwell time, mean time to detect and breaches stopped. A genuine MSSP is built around a Security Operations Centre (SOC) - analysts watching telemetry around the clock, not a ticket queue checked in office hours. AMVIA's managed SOC service pairs Microsoft Defender for Endpoint with an in-house 24/7 SOC, so alerts are triaged by people, not just logged. That is the line most IT-first providers cannot cross without real security investment. ## How do MSP and MSSP services compare? The simplest way to see the difference is feature by feature. An MSP covers the breadth of IT; an MSSP covers the depth of security. The table below maps where each model is strong, weak, or only partial - and shows why "some" security inside an MSP rarely equals dedicated security. | | Feature | MSP (£30–£80/user/mo) | MSSP (£10–£30/user/mo) | IT helpdesk and support | Yes | No | Infrastructure management | Yes | No | Backup and disaster recovery | Yes | No | 24/7 security monitoring | Some | Yes | Incident response | Basic | Yes | Vulnerability management | Some | Yes | Compliance reporting | Basic | Yes | Strategic IT planning | Yes | No The price ranges look like the MSSP is cheaper, but they answer different questions. An MSP fee buys the whole IT function; an MSSP fee buys a security layer on top. Run them as two separate contracts and you pay for two sets of overhead - and you create a handover gap every time an incident touches both. ## Why are MSPs and MSSPs converging? The two models are merging. Forward-thinking MSPs are integrating security tooling and SOC capability, while MSSPs are broadening into the IT operations they need visibility over. For a buyer, that convergence is good news: you no longer have to choose between "IT" and "security" as separate purchases. The driver is risk. 43% of UK businesses experienced a cyber security breach or attack in the last 12 months (DSIT, Cyber Security Breaches Survey 2025). When security is bolted on as an afterthought, the gaps show. When one provider owns both the infrastructure and the security telemetry, detection is faster and accountability is clear. That single-provider model is what AMVIA was built around - one provider, security-first, Microsoft-certified. ## What security gaps come from using separate MSP and MSSP providers? When IT operations and security sit with different suppliers, incidents fall between responsibilities - the MSP says it's a security event, the MSSP says it's an infrastructure fault, and the clock keeps running. Split ownership also splits the audit trail, which slows every investigation. This matters because the most common attacks exploit exactly those seams. 85% of businesses experiencing breaches identified phishing as the attack type (DSIT, Cyber Security Breaches Survey 2025) - an attack that crosses email, identity and endpoint, the precise boundaries where a two-provider model loses time. The NCSC's guidance on phishing makes the same point: response speed depends on joined-up visibility. - One provider owns the full timeline from alert to containment. - No "not my job" handover during a live incident. - A single audit trail across identity, email and endpoint. - One contract, one escalation path, one accountable team. ## Is a combined MSP/MSSP provider more cost-effective? Usually, yes. A unified provider removes duplicated overhead, avoids paying twice for overlapping tooling, and cuts the integration cost of making two suppliers' systems talk to each other. The bigger saving, though, is risk reduction - faster detection means cheaper incidents. The numbers make the case. The average cost of the most disruptive breach is £3,550 (DSIT, Cyber Security Breaches Survey 2025) for a typical business, and far higher for medium-sized firms. Set that against the price of joined-up monitoring and the maths favours prevention. If you want to model your own figures, read how much managed cybersecurity costs in the UK. ## When should an SME choose an MSSP over an MSP? Choose an MSSP capability the moment your risk exposure outgrows basic IT support - when you hold regulated data, sell to enterprise customers demanding security assurance, or have already had a near miss. At that point, helpdesk-grade security is not enough; you need managed detection and response and round-the-clock monitoring. In practice, most UK SMEs don't want two suppliers. They want their IT and their security from one team that already understands their environment. That is why AMVIA delivers both - pairing managed IT with 24/7 security monitoring and a documented incident response process under a single contract. ## Frequently asked questions Q: Can one provider be both MSP and MSSP? A: Yes, and for SMEs it's usually the better model: most real incidents cross the IT/security boundary, and separate providers cost response time in handoffs and finger-pointing. AMVIA runs both under one contract - helpdesk to SOC - which is the practical meaning of 'security-first MSP'. Q: What does an MSSP cost compared with an MSP? A: Managed IT typically runs £30–£80 per user/month in the UK market; dedicated security services add roughly £10–£30 per user depending on depth. Integrated plans price the combination together - AMVIA's ladder runs £25–£60 per user with security deepening by tier. Q: How do I know if we need MSSP-level security? A: Ask what you're protecting and who's watching it now. If client data, regulatory exposure or downtime costs are real and the honest answer to 'who reads the security alerts?' is nobody - that's the gap an MSSP fills. 43% of UK businesses were attacked in a year (DSIT 2025); the threat doesn't wait for maturity. Q: What questions expose a weak 'security included' claim? A: Three: Who watches alerts at 2am, and what's their response SLA? What exactly triggers an incident escalation? Can you show the evidence trail from a past incident? Vague answers mean the 'security' is a product licence, not a service. --- # What Is MDR (Managed Detection and Response)? URL: https://amvia.co.uk/cybersecurity/questions/what-is-mdr Last updated: 2026-03 MDR - managed detection and response - is a security service where analysts monitor your endpoints, network and identity 24/7 and actively investigate and contain threats on your behalf. It goes beyond antivirus and EDR by adding human expertise: one provider, security-first, Microsoft-certified. ## What does MDR actually do? MDR pairs detection technology with a human team that hunts, triages and responds to threats around the clock. Where antivirus blocks known malware and EDR flags suspicious behaviour, MDR puts trained analysts behind the alerts - investigating, containing compromised devices and guiding remediation so an incident never becomes a breach. For most UK SMEs the gap is not tooling, it is people. You can buy a detection product, but you cannot buy the 3am analyst who isolates a ransomware host before it spreads. That is what MDR provides, and it is why it sits at the centre of managed cybersecurity for businesses without an in-house security team. - Detection - telemetry from endpoints, identity and email is continuously analysed. - Investigation - analysts confirm whether an alert is a real threat or noise. - Response - confirmed threats are contained: devices isolated, processes killed, accounts locked. - Recovery guidance - root-cause analysis and steps to stop it recurring. ## Why do UK businesses need MDR now? Attack volume and impact are both rising, and signature-based tools no longer keep pace. The UK government's Cyber Security Breaches Survey 2025 found that 21% of businesses that experienced a breach reported a negative outcome such as loss of money or data, and 7% reported temporary loss of access to files or networks - up from 4% in 2024. Ransomware is the sharpest edge of this. The average cost of the most disruptive breach is £3,550 (DSIT 2025). Detection alone does not stop these incidents - response does. The National Cyber Security Centre is explicit that organisations should plan for active incident response, not just prevention (NCSC guidance). The figures come from the Cyber Security Breaches Survey 2025, the UK's authoritative annual measure of business cyber risk. ## What is included in an MDR service? A well-built MDR service combines detection technology with a staffed security operations centre. The exact mix varies by provider, but these components define a genuine MDR offering rather than a relabelled antivirus subscription. ## Endpoint detection and response (EDR) A lightweight agent on every device captures process activity, network connections and file changes, then streams that telemetry to a managed platform for analysis. EDR is the sensor layer; on its own it still needs someone to act on what it sees - see our breakdown of endpoint detection and response. ## 24/7 threat monitoring Analysts review and triage alerts around the clock, escalating by severity. Attackers deliberately strike out of hours, so continuous 24/7 security monitoring is the difference between a contained event and a Monday-morning disaster. ## Threat hunting Proactive searching for indicators of compromise that automated rules miss. Analysts look for attacker behaviour - lateral movement, credential abuse, unusual privilege escalation - rather than waiting for a signature to fire. ## Incident containment When a threat is confirmed, analysts isolate affected devices, terminate malicious processes and lock compromised accounts, cutting dwell time and blast radius. This is the response in "detection and response". ## Forensic investigation and reporting After an incident, the team reconstructs what happened, identifies root cause and recommends fixes. Regular reporting gives you an audit trail for compliance, cyber insurance and board review. ## Antivirus vs EDR vs MDR: what's the difference? The three tiers of endpoint security differ in what they detect, who responds, and what they cost. Antivirus catches known malware. EDR adds behavioural detection but still needs a human. MDR wraps both in a 24/7 analyst team that investigates and contains threats for you. | | Capability | Antivirus (signature) | EDR (behavioural) | MDR (managed + human) | Known malware detection | Yes | Yes | Yes | Behavioural / anomaly detection | No | Yes | Yes | 24/7 human monitoring | No | No | Yes | Active threat hunting | No | No | Yes | Incident containment | No | Manual | Yes | Forensic investigation | No | Limited | Yes | Typical per-device cost /mo | £2–£5 | £5–£15 | £12–£30 MDR is not a replacement for endpoint hygiene, patching and MFA - it is the detection-and-response layer that sits on top of them. ## How does AMVIA deliver MDR? AMVIA delivers MDR using Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC. There is no third-party detection vendor in the chain: one accountable provider, Microsoft-certified engineers, security-first. That keeps your telemetry, identity and email signals in one Microsoft tenancy your team already owns. Defender for Endpoint is enterprise-grade detection built into the Microsoft stack (Microsoft Defender for Endpoint docs), and our analysts operate it as a managed service rather than handing you a console and walking away. For businesses already on Microsoft 365, pairing MDR with Microsoft Defender for Business consolidates detection and licensing in one place. If you want the full picture of how detection, a managed SOC and managed detection and response fit together, those service pages go deeper on coverage and scope. ## Frequently asked questions Q: How does MDR differ from simply running antivirus software? A: Antivirus relies on known malware signatures and cannot detect novel threats or attacker behaviour that does not involve malware files. MDR adds behavioural analysis, 24/7 human analyst monitoring, active threat hunting and incident containment. Against modern ransomware, antivirus alone is insufficient - MDR catches what signature-based tools miss. Q: What should I look for when choosing an MDR provider? A: Look for genuine 24/7 human analyst coverage rather than automated alerts, a stated mean time to respond, and whether the service includes active containment or only notification. Ask how threat hunting is done and for UK-relevant experience. The average cost of the most disruptive breach is £3,550 (DSIT 2025), so a provider that only sends alerts without acting delivers limited value. Q: Does MDR replace the need for MFA and patching? A: No. MDR is a detection-and-response layer that works best when foundational controls are already in place. Without MFA, patch management and email security, analysts get buried in preventable incidents. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26). Treat MDR as the layer that catches threats bypassing your preventive controls, not a substitute for them. Q: Does MDR make sense for a small business without an IT team? A: Yes, for most SMEs without in-house security staff. MDR gives you the same 24/7 analyst response a large enterprise has, at a per-device cost (£12–£30/mo) far below hiring even one full-time analyst. It is usually the most cost-effective way to gain real detection-and-response capability. Q: What is the difference between MDR and a managed SOC? A: A managed SOC is a security operations centre run as a service, covering your whole environment. MDR is more focused on endpoint and identity detection and response. In practice they overlap heavily, and many providers - including AMVIA - deliver MDR capability through a managed SOC. The right choice depends on the breadth of coverage you need. Q: Can MDR help with cyber insurance and compliance? A: Yes. Most cyber insurers now expect continuous monitoring and a defined response capability, and MDR provides both, plus the reporting and audit trail underwriters and auditors ask for. It supports frameworks such as Cyber Essentials Plus by demonstrating active detection and response controls. --- # How Does Managed Detection and Response (MDR) Work? URL: https://amvia.co.uk/cybersecurity/questions/how-does-mdr-work Last updated: 2026-03 MDR works by pairing endpoint detection software with a 24/7 human SOC team that monitors the alerts the software generates, investigates which ones are real, and contains threats on your behalf - usually within minutes. At AMVIA, that means Microsoft Defender for Endpoint telemetry watched around the clock by our in-house UK security analysts. MDR works by pairing endpoint detection software with a 24/7 human SOC team that monitors the alerts that software generates, investigates which ones are real, and contains threats on your behalf - usually within minutes. At AMVIA, that means Microsoft Defender for Endpoint telemetry watched around the clock by our in-house UK security analysts. Managed Detection and Response exists because the tooling on its own is not enough. An endpoint agent can flag a thousand suspicious events a week; someone still has to read them, decide which matter, and act before an attacker moves laterally. That "someone" is the part most SMEs cannot staff, and it is the part MDR replaces. If you are weighing up your wider security strategy, this question sits underneath our broader managed cybersecurity pillar - MDR is one layer of it, not the whole thing. The rest of this guide breaks down the MDR workflow step by step, shows where the technology ends and the human work begins, and explains what AMVIA actually does when an alert fires at 3am. ## What are the stages of the MDR process? MDR runs as a continuous loop: collect telemetry, detect anomalies, triage alerts, investigate confirmed threats, contain and respond, then review and harden. The technology handles collection and first-pass detection; analysts handle the judgement calls - deciding what is a genuine attack versus a noisy false positive. Here is the workflow in order: 1. Collect - lightweight agents and connectors stream logs and behavioural telemetry from endpoints, identity, and email into a central platform. 2. Detect - detection rules and behavioural analytics flag anomalies: unusual sign-ins, suspicious process execution, credential misuse, lateral movement. 3. Triage - a SOC analyst validates each meaningful alert, dismisses false positives, and grades severity. 4. Investigate - for confirmed threats, the analyst traces the root cause and the blast radius: which device, which account, what was touched. 5. Contain - the analyst isolates the affected endpoint or disables the compromised account, stopping spread. 6. Respond and harden - remediation guidance, removal of attacker persistence, and a review of what let the attack in. The reason this matters is speed. The UK's National Cyber Security Centre handled 429 total incidents in 2025, with 204 classified as nationally significant - the highest-ever number (NCSC). When incident volume rises, the gap between detection and response is where damage happens. A loop that runs 24/7 closes that gap. ## How is MDR different from just buying EDR software? EDR is the technology layer; MDR is EDR plus the people who run it. EDR collects endpoint telemetry and raises alerts, but it does not decide which alerts are real or take action - your staff do. MDR wraps a 24/7 SOC around the tooling so trained analysts triage, investigate, and contain on your behalf. Without the human layer, every alert lands on your IT team's desk to be sorted manually - a job most SMEs have neither the headcount nor the round-the-clock cover to do. The result is alert fatigue, missed signals, and slow response. This is exactly the distinction we draw out in our MDR vs EDR comparison. | | Capability | EDR (software only) | MDR (software + SOC) | Endpoint telemetry collection | Yes | Yes | Alert generation | Yes | Yes | Alert triage / false-positive filtering | Your staff | 24/7 SOC analysts | Threat investigation | Your staff | SOC analysts | Containment action | Your staff | SOC analysts (minutes) | Out-of-hours cover | No | Yes | Remediation guidance | No | Yes The data backs the case for the human layer. 43% of UK businesses experienced a breach or attack in the past year (DSIT Cyber Security Breaches Survey 2025), and many lacked the monitoring to detect it promptly. Buying the software without anyone watching it is how that happens. Our endpoint detection and response service is built on the MDR model for this reason. ## What does the SOC team actually do when a threat is detected? When a genuine threat is confirmed, the SOC analyst validates the alert, grades severity, and initiates containment - typically isolating the affected endpoint within minutes. They then investigate the root cause, assess how far the compromise spread, and provide remediation guidance to close the gap permanently. This is where MDR earns its keep. Containment speed is the single biggest factor between a contained incident and a full outbreak. Ransomware spreads fastest in the first hour after foothold. A SOC that isolates a machine in minutes denies the attacker the time they need. AMVIA's response work is run by our in-house managed SOC service - UK analysts, not an offshore queue. For confirmed incidents that need hands-on eradication and recovery, the SOC hands off to our incident response process so containment and clean-up are one continuous chain, not two separate phone calls. ## Does MDR work with our existing IT and Microsoft 365 setup? Yes. MDR deploys lightweight agents onto endpoints and connects to platforms you already run - Microsoft 365, identity providers, firewalls, and cloud services. It ingests logs and telemetry from those sources to build a single, correlated view of activity across your whole environment, rather than watching endpoints in isolation. That correlation is the point. 22% of breaches involved compromised credentials (Verizon DBIR 2025), and credential-based attacks only become obvious when you can join the dots across identity, email, and endpoint signals. A SOC watching all three at once catches the multi-stage attack that any single tool would miss. AMVIA builds MDR on the Microsoft security stack our clients already pay for - Microsoft Defender for Endpoint and Defender for Office 365, hardened and monitored by our team, with Barracuda covering email and network filtering. Microsoft's own guidance on Defender for Business is a useful primer (Microsoft Security). Because the detection runs on tooling you already license, MDR rarely means ripping anything out. It is continuous 24/7 security monitoring layered onto your current environment. ## What does AMVIA recommend? For most UK SMEs with 10–500 staff, MDR is the highest-leverage security spend available - more so than another point product. The honest reason: detection tooling is now commoditised and cheap, but the analysts who turn alerts into action are scarce and expensive. MDR lets you rent that capability 24/7 for a fraction of building an in-house SOC. What we would not do is buy EDR and assume it is sorted. Software that nobody is watching is a compliance checkbox, not a defence. If your endpoint tool has been raising alerts into an inbox no one reads, you already have the worst of both worlds - cost without coverage. One provider, security-first, Microsoft-certified engineers: that is the model AMVIA runs MDR on, so detection, response, and your Microsoft 365 estate sit with one accountable team. ## Frequently asked questions Q: How quickly does MDR respond to a threat? A: A mature MDR service contains confirmed threats within minutes, not hours. The endpoint agent flags suspicious behaviour in near real time, a SOC analyst validates it, and containment - isolating the device or disabling the account - follows immediately. The 24/7 model means that response is the same at 3am on a Sunday as it is at midday on a Tuesday. Q: Is MDR the same as a SIEM? A: No. A SIEM is a log-aggregation and correlation platform; MDR is an outcome-based service that may use a SIEM under the hood but adds the human SOC, the investigation, and the containment action. SIEM tells you something happened; MDR decides what it means and stops it. The two are complementary, not interchangeable. Q: Do small businesses really need MDR? A: Most do. 43% of UK businesses experienced a breach or attack in the past year (DSIT 2025), and smaller firms are targeted precisely because they lack monitoring. MDR gives an SME the same round-the-clock detection a large enterprise SOC provides, without the headcount cost of building one in-house. Q: What's the difference between MDR and incident response? A: MDR is the always-on detection and rapid-containment service that catches threats early. Incident response is the deeper eradication, forensics, and recovery work that follows a confirmed, significant compromise. Good MDR reduces how often you need full incident response - and when you do, the handover is seamless because the same team already holds the context. Q: Does MDR replace our IT team? A: No - it removes a job they cannot realistically do. Your IT team keeps running day-to-day systems; MDR adds 24/7 security analysts who watch for threats out of hours and take containment action your team is not staffed to deliver round the clock. It augments internal IT rather than replacing it. Q: How much business risk does MDR actually reduce? A: MDR attacks the most expensive part of a breach: dwell time. 21% of businesses that experienced a breach reported a negative outcome such as loss of money or data (DSIT 2025), and 7% reported temporary loss of access to files or networks - up from 4% in 2024. Faster detection and containment is what shrinks those numbers. --- # How Much Does MDR Cost for a UK Small Business? URL: https://amvia.co.uk/cybersecurity/questions/mdr-cost-uk Last updated: 2026-03 Managed detection and response in the UK typically runs from around £10 per endpoint per month, so a 50-endpoint business should budget from roughly £500 per month. The fee buys 24/7 human monitoring, EDR tooling and active threat containment. AMVIA delivers it from one accountable, security-first, Microsoft-certified provider. That headline figure is a starting point, not a quote. What you actually pay depends on how many devices you protect, whether monitoring is genuinely round-the-clock, and how much hands-on response is included. Below is how the numbers break down, what a fair per-endpoint fee covers, and how MDR compares to building the same capability yourself. For the wider picture, see how this sits inside managed cybersecurity as a whole. ## How much does MDR cost in the UK in 2026? Most UK SMEs pay on a per-endpoint, per-month basis. AMVIA's managed detection and response starts from £10 per endpoint per month, which scales predictably with headcount rather than springing surprise costs after an incident. The table below shows indicative monthly budgets at that rate. | | Business size | Endpoints (approx) | Indicative MDR/month | Micro (under 10 staff) | 10 | from £100 | Small (25 staff) | 25 | from £250 | Mid-sized (50 staff) | 50 | from £500 | Larger SME (100 staff) | 100 | from £1,000 These are AMVIA service figures preserved as published and not yet independently reconciled, hence the flags. Treat them as a planning baseline and get a scoped quote before budgeting. The point that matters: fixed monthly pricing turns an unpredictable risk into a known line item. ## What should a per-endpoint MDR fee include? A genuine MDR fee should cover EDR agent deployment, 24/7 SOC monitoring, alert investigation by human analysts, active threat containment and remediation guidance. If a provider quotes "MDR" but only sends you alerts to action yourself, that is monitoring, not response, and it should cost less. AMVIA's MDR is built on Microsoft Defender for Endpoint monitored by an in-house 24/7 SOC. Microsoft documents the underlying detection and response capability in its official guidance (learn.microsoft.com). A fair per-endpoint fee should include: - EDR agent rollout and tuning across every covered device - 24/7 monitoring by human analysts, not just automated triage - Alert investigation that separates real threats from noise - Active containment - isolating a compromised device, not emailing you about it - Remediation guidance and a clear post-incident report The average cost of the most disruptive breach for UK businesses was £3,550 (DSIT Cyber Security Breaches Survey 2025), so even a year of MDR can pay for itself by stopping one serious incident. For the deeper mechanics, read our explainer on managed detection and response. ## Why does MDR pricing vary so much between providers? The spread reflects four things: monitoring hours (business hours versus genuine 24/7), whether human analysts or automated triage handle alerts, the depth of response included, and the EDR technology underneath. Two quotes labelled "MDR" can describe very different services, which is why per-endpoint comparisons mislead unless you check what each fee covers. Threat volume is the reason 24/7 matters. The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant - the highest-ever number (NCSC). Attackers do not keep office hours. A cheaper business-hours-only service leaves nights and weekends - when ransomware is most often detonated - uncovered. Phishing remains the dominant entry point: 85% of businesses that identified a breach pointed to phishing as the attack type (DSIT Cyber Security Breaches Survey 2025). MDR earns its fee precisely when a phishing click slips past your filters and someone has to act in minutes. See how the technology layer alone compares in our MDR vs EDR breakdown. ## Is MDR cheaper than building an in-house SOC? For almost every business under 500 staff, yes. Running a credible 24/7 security operations centre means hiring at least five or six analysts to cover shifts, plus SIEM tooling, threat intelligence feeds and management overhead - comfortably six figures a year before a single alert is investigated. MDR spreads that cost across many customers. | | Approach | Typical annual cost | 24/7 cover | Time to stand up | In-house SOC | £250k–£400k (salaries + tooling, typical UK 2026 range) | Yes, if fully staffed | 6–12 months | MDR (50 endpoints) | from £6,000/year | Yes | Days to weeks | EDR only, self-managed | Tooling cost only | No human response | Hours The honest caveat: very large enterprises with mature security teams sometimes justify an in-house SOC. Most UK SMEs do not, and the staffing market makes it harder still. If you want the full cost picture across services, see how much managed cybersecurity costs, and for the operations layer specifically, our managed SOC service. ## What hidden costs should you check before signing? Watch for onboarding fees, minimum endpoint commitments, charges for out-of-hours incident response, and whether log retention and reporting are included or billed separately. A clean MDR contract states the per-endpoint fee, what triggers any extra charge, and the response actions the SOC is authorised to take on your behalf. Ask three questions of any provider: do humans investigate every alert, can the SOC contain a threat without waiting for your sign-off, and is the price fixed per endpoint regardless of incident volume. AMVIA's answer to all three is yes - and the EDR data that powers it is examined in our endpoint detection and response guide. ## Frequently asked questions Q: How much does MDR cost per endpoint in the UK? A: UK MDR is usually priced per endpoint per month. AMVIA's managed detection and response starts from £10 per endpoint per month, covering 24/7 SOC monitoring, EDR tooling, alert investigation and active containment. Final pricing depends on device count and the depth of response, so request a scoped quote rather than relying on a headline rate. Q: What does MDR cost for a 50-person business? A: A 50-endpoint business should budget from roughly £500 per month at a £10 per-endpoint rate. That single fixed fee buys round-the-clock human monitoring and threat response - far less than the £3,550 average cost of the most disruptive breach faced by UK businesses (DSIT Cyber Security Breaches Survey 2025). Q: Is MDR worth it for a small business? A: For most SMEs, yes. Phishing was the reported attack type in 85% of identified breaches (DSIT Cyber Security Breaches Survey 2025), and threats arrive outside office hours. MDR gives you a 24/7 SOC and active containment for a predictable monthly fee - capability that is otherwise unaffordable to build in-house below several hundred staff. Q: Does MDR pricing include incident response? A: It should, but check. A credible MDR fee covers active threat containment and remediation guidance as standard. Some providers bill out-of-hours incident response separately or cap the actions the SOC can take. Confirm that human-led containment is included before you compare per-endpoint prices, or the cheaper quote may cost far more in a crisis. Q: What is the difference between MDR and EDR pricing? A: EDR is the tooling that detects threats on devices; MDR adds the 24/7 human team that investigates and responds. EDR-only licences are cheaper but leave you to action alerts yourself. MDR costs more per endpoint because it bundles the SOC. Our MDR vs EDR comparison shows where each fits. Q: Why is 24/7 monitoring worth paying for? A: Because attackers target nights and weekends. The NCSC handled 429 incidents in 2025, 204 of them nationally significant (NCSC), and ransomware is routinely detonated outside business hours. Business-hours-only monitoring leaves the highest-risk windows uncovered, which is why genuine 24/7 SOC response is the part of an MDR fee you should not trade away. --- # What Is Threat Hunting in Cybersecurity? URL: https://amvia.co.uk/cybersecurity/questions/what-is-threat-hunting Last updated: 2026-03 Threat hunting is the proactive, hypothesis-driven search for attackers who are already inside your network but have not yet triggered an alert. Unlike automated detection, it relies on skilled analysts probing endpoint, identity and log data for hidden compromise. For most UK SMEs it arrives inside a managed SOC - one provider, security-first, Microsoft-certified. If you are new to the wider topic, start with our managed cybersecurity pillar, which sets out how detection, response and hunting fit together for a UK business with 10–500 staff. ## What does a threat hunter actually do? A threat hunter assumes a breach has already happened and goes looking for it. They form a hypothesis - for example, "a compromised account is moving sideways through finance" - then test it against live telemetry. Where automated tools wait for a known pattern, the hunter searches for the unknown. This matters because the most damaging attacks are designed to look normal. Stolen credentials, legitimate admin tools used maliciously, and slow data theft rarely fire a signature-based alert. Hunting closes that gap by adding human judgement on top of the machine layer. In practice it sits alongside endpoint detection and response rather than replacing it. - Hypothesis-led: start from attacker behaviour, not from an alert queue. - Data-driven: correlate endpoint, identity, network and log evidence. - Outcome-focused: confirm or disprove compromise, then feed findings back into detection rules. ## How does threat hunting differ from automated threat detection? Automated detection uses predefined rules and signatures to flag known threats the moment they match. Threat hunting is analyst-driven: security professionals form hypotheses about attacker behaviour and actively search for indicators of compromise the automated layer has missed. The two are complementary, not interchangeable. With 43% of UK businesses experiencing a cyber breach or attack in the past year (Cyber Security Breaches Survey 2025, DSIT), the volume alone guarantees that some intrusions slip past rule-based tools. Hunting exists to catch what detection cannot. | | Dimension | Automated detection | Threat hunting | Trigger | Known signature or rule match | Human hypothesis about behaviour | Driver | Software | Skilled analyst | Catches | Known, previously seen threats | Novel, stealthy, "living off the land" attacks | Timing | Reactive - fires after a match | Proactive - searches before an alert | Output | Alert | Confirmed compromise + new detection rules The strongest setups run both: automated detection handles scale and speed, while hunting reduces dwell time - the period an attacker stays undetected. This is the model behind managed detection and response (MDR). ## Why does threat hunting matter for UK businesses? It matters because the cost and frequency of undetected intrusions are rising. UK incident data shows attacks are both more common and more disruptive, and the breaches that hurt most are precisely the ones that evade automated alerts. Proactive hunting shortens the window in which an attacker can do damage. The national picture is stark. The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant - the highest-ever number (National Cyber Security Centre). At business level, 21% of organisations that experienced a breach reported a negative outcome such as loss of money or data, and 7% reported temporary loss of access to files or networks - up from 4% in 2024 (DSIT 2025). - Breaches cause real losses: the average cost of the most disruptive breach is £3,550 (DSIT 2025). - Dwell time is the enemy: the longer an intruder stays hidden, the higher the eventual cost - hunting drives that time down. For a sense of how this maps to your sector, our cybersecurity pillar breaks down threat patterns by industry. ## What data sources do threat hunters use? Threat hunters work across multiple evidence streams at once. They analyse endpoint telemetry - process executions, file changes and network connections - alongside SIEM log data, identity and authentication records, DNS queries, and external threat intelligence feeds. The skill is in correlating signals that look harmless in isolation. A hunter looks for anomalies a rule would ignore: a login at 03:00 from an unusual location, an admin tool launched on a finance laptop, lateral movement between systems, or a steady trickle of outbound data. Each on its own is plausible; together they describe an attack. Continuous visibility comes from pairing this with 24/7 security monitoring. Typical sources include: - Endpoint and EDR telemetry (process, file, registry, network activity) - Identity and sign-in logs (Microsoft Entra ID, conditional access events) - SIEM-aggregated logs from servers, firewalls and applications - DNS and proxy records for command-and-control patterns - Curated threat intelligence on current attacker tooling ## Do UK SMEs need threat hunting, or is it only for enterprises? SMEs need it too - but almost never build it in-house. Most access threat hunting as a component of a managed SOC or MDR service, which makes specialist skills affordable without hiring a full security team. Size does not exempt a business; small organisations are routinely targeted precisely because their defences are thinner. Building an internal hunting capability means recruiting scarce analysts, running tooling around the clock, and retaining that knowledge - rarely viable below a few hundred staff. A managed SOC service delivers the same outcome as a shared, accountable function. When a hunt confirms compromise, the same team runs incident response without a handover. ## How is threat hunting delivered in a managed SOC? In a managed SOC, hunting is a scheduled, repeatable discipline rather than an occasional exercise. Analysts run structured hunts against your telemetry, validate findings, and convert every confirmed technique into a new automated detection - so the machine layer gets smarter each cycle. The business gets enterprise-grade coverage on an SME budget. AMVIA delivers this with Microsoft Defender for Endpoint telemetry monitored by our in-house 24/7 SOC. One provider owns detection, hunting and response, so there is no finger-pointing between vendors when something is found. That single line of accountability - security-first, Microsoft-certified - is the difference between a tidy report and a contained incident. ## Frequently asked questions Q: How does threat hunting differ from automated threat detection? A: Automated detection relies on predefined rules and signatures to alert on known threat patterns. Threat hunting is analyst-driven: security professionals form hypotheses about attacker behaviour and actively search for indicators of compromise that automated systems miss. With 43% of UK businesses experiencing a breach or attack in 2025 (DSIT), hunting catches what rule-based tools cannot. Q: Do SMEs need threat hunting, or is it only for large enterprises? A: SMEs benefit from threat hunting, but almost always access it through a managed SOC or MDR service rather than building it in-house. This makes specialist skills affordable and practical at any size. Even small organisations face sophisticated threats that can evade basic detection. Q: What data sources do threat hunters use? A: Threat hunters analyse endpoint telemetry (process executions, file changes, network connections), SIEM logs, identity and authentication records, DNS queries, and threat intelligence feeds. They look for anomalies such as unusual login times, lateral movement, or data exfiltration. The average cost of the most disruptive breach is £3,550 (DSIT 2025), and hunting reduces the dwell time that drives that cost. Q: Is threat hunting the same as penetration testing? A: No. Penetration testing simulates an attacker to find exploitable weaknesses before a breach. Threat hunting assumes an attacker may already be inside and searches live telemetry for evidence of compromise. Pen testing is point-in-time and offensive; hunting is continuous and investigative. Mature programmes use both, feeding test findings into what hunters look for. Q: How does threat hunting reduce attacker dwell time? A: Dwell time is the period an intruder stays undetected. Because hunting actively searches for stealthy activity instead of waiting for an alert, it surfaces compromises earlier in the attack chain - often before data theft or ransomware deployment. Every confirmed finding is then turned into an automated detection rule, so the same technique is caught instantly next time. Q: Can AMVIA run threat hunting for my business? A: Yes. AMVIA delivers threat hunting inside its managed SOC, using Microsoft Defender for Endpoint telemetry monitored by an in-house 24/7 team. One provider owns detection, hunting and response, so findings are acted on immediately rather than handed between vendors. It is designed for UK SMEs that need enterprise-grade coverage without an internal security team. --- # What Is Spear Phishing? How It Differs from Phishing URL: https://amvia.co.uk/cybersecurity/questions/what-is-spear-phishing Last updated: 2026-03 Spear phishing is a targeted email attack aimed at one named person, using personal details - their job title, manager, supplier names, recent projects - to look legitimate. Unlike mass phishing blasted to thousands, it is hand-built for a single victim, which is why it slips past filters and trained staff alike. Defending against it needs layered controls and one accountable provider. Last updated: 27 June 2026. ## What Does Spear Phishing Mean in Plain English? Spear phishing is a precision con. The attacker researches a specific individual, then sends a message that references real people, real systems, or a real deal in progress so the request feels routine. Mass phishing plays the numbers; spear phishing plays the person. The difference matters because the defences differ. Generic phishing is mostly caught by spam filters and basic awareness. Spear phishing is written to pass both. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the cause - the single most common attack vector. Targeted variants account for a disproportionate share of the breaches that actually cause damage. To see where ordinary phishing ends and the targeted version begins, read our explainer on what phishing is, then come back here for the targeted threat. Both sit under our managed cybersecurity approach for UK SMEs. ## How Is Spear Phishing Different from Mass Phishing? The core difference is targeting and effort. Mass phishing is one template sent to thousands and costs the attacker almost nothing. Spear phishing is researched, personalised, and sent to one or a handful of people - higher effort, far higher hit rate, and much harder for filters to flag. | | Feature | Mass phishing | Spear phishing | Target | Thousands, untargeted | One named individual or small group | Personalisation | Generic ("Dear customer") | Real names, roles, suppliers, projects | Research | None | LinkedIn, company site, social media | Filter evasion | Often caught by spam filters | Frequently bypasses standard filters | Typical goal | Credential harvesting at scale | Wire fraud, data theft, account takeover | Success rate | Low per message | High per message Mass phishing is a volume business. Spear phishing is a sniper shot. That is why a single accountable provider running layered email, identity, and endpoint controls beats a stack of disconnected point products. ## Who Do Spear Phishers Actually Target? Attackers go where the money and access live: finance teams, senior executives (CEO and CFO), HR, and IT administrators. These roles can move funds, release sensitive data, or grant system access - so a single successful message can pay off immediately. Business email compromise (BEC) is the most expensive form of spear phishing, where an attacker impersonates a director or supplier to authorise a fraudulent payment. Cybercrime losses are climbing: total losses reported to the FBI's Internet Crime Complaint Center rose 33% in 2024 versus 2023 (FBI IC3 2024 Annual Report). Impersonation is common too: 35% of businesses that experienced breaches reported others impersonating their organisation in emails or online (DSIT 2025). Common spear phishing targets and why: - Finance and accounts payable - can authorise and release payments. - CEO / CFO and their EAs - high authority, often quoted in "urgent" requests. - HR - holds payroll data and can be tricked into changing bank details. - IT administrators - control accounts, MFA resets, and privileged access. If your finance or exec teams are exposed, our email security and phishing protection hardens the inbox before a fake invoice ever lands. ## How Does AI Make Spear Phishing Worse? AI has collapsed the cost and time of producing convincing targeted emails. Attackers now generate grammatically perfect, on-brand messages at scale, mimic a known person's writing style, automate reconnaissance from public data, and even clone voices for follow-up phone calls (vishing). The old advice - "look for spelling mistakes" - is dead. AI-written spear phishing reads exactly like a genuine internal email. The UK's National Cyber Security Centre is clear that organisations should assume some phishing will always reach inboxes and build layers that catch what slips through, rather than relying on staff to spot every fake. This is why detection now matters as much as prevention. Our managed detection and response service watches for the account takeover that follows a successful spear phish, so a stolen credential does not become a full breach. ## Can Email Filters Stop Spear Phishing on Their Own? No. Standard spam filters miss most spear phishing because the emails are individually crafted, sent from legitimate-looking or genuinely compromised domains, and often contain no malware or obvious links - just a plausible request. Filters are necessary but never sufficient. The realistic defence is layered, and identity is the weakest link in most UK businesses. "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)" - which means a stolen password is often the only thing standing between an attacker and a mailbox. Multi-factor authentication, conditional access, and anomaly detection close that gap. What actually reduces spear phishing risk: - Multi-factor authentication everywhere - even a phished password fails without the second factor. - Advanced email security - AI-driven anomaly detection on top of spam filtering. - Payment verification rules - out-of-band confirmation for any bank-detail or payment change. - Targeted awareness training - for finance, exec, HR, and IT roles specifically. - 24/7 detection - so a compromised account is caught in minutes, not weeks. If turning on MFA properly across your tenant is the gap, follow our guide to setting up MFA across Microsoft 365. And if you suspect an account is already compromised, our incident response team can contain it. One provider, security-first, Microsoft-certified - so prevention, detection, and response are not three different phone calls. ## Frequently asked questions Q: What is spear phishing in simple terms? A: Spear phishing is a phishing attack aimed at one specific person, built from real details about them - their name, role, colleagues, or current work - so the message looks genuine. Unlike mass phishing sent to thousands, it is personalised to a single target, which is exactly why it is harder to spot and more likely to succeed. Q: Who is most commonly targeted by spear phishing? A: Finance teams, senior executives (CEO and CFO), HR staff, and IT administrators are the most frequent targets because they control funds, sensitive data, or system access. Attackers research targets using LinkedIn, company websites, and social media before sending a tailored message that references real people or projects to lower the victim's guard. Q: How does AI make spear phishing more dangerous? A: AI lets attackers generate highly personalised, grammatically correct emails at scale. It can mimic a colleague's writing style, automate reconnaissance from public data, and even produce deepfake voice messages for follow-up phone scams. The traditional warning signs - bad grammar, odd phrasing - no longer apply, so layered technical controls matter far more than spotting typos. Q: Can email filters detect spear phishing attempts? A: Standard spam filters often miss spear phishing because the emails are individually crafted, sent from legitimate-seeming domains, and may contain no malware or suspicious links. Advanced email security with AI-powered anomaly detection improves detection, but MFA and out-of-band payment verification are essential because no filter catches every targeted message. Q: What is the difference between spear phishing and whaling? A: Whaling is a sub-type of spear phishing that targets only the most senior people - board members, the CEO, the CFO - usually to authorise large payments or release sensitive data. All whaling is spear phishing, but not all spear phishing is whaling; spear phishing also hits finance clerks, HR, and IT admins lower down the organisation. Q: How can a UK SME protect against spear phishing? A: Combine layers: enforce multi-factor authentication, deploy advanced email security with anomaly detection, set out-of-band verification for any payment or bank-detail change, train high-risk roles, and run 24/7 detection so a compromised account is caught fast. Using one accountable provider keeps prevention, detection, and response joined up rather than scattered across vendors. --- # How Much Does Email Security Cost for a Small Business? URL: https://amvia.co.uk/cybersecurity/questions/email-security-cost Last updated: 2026-03 Email security for a UK small business typically costs £1.80–£5 per user per month. Microsoft Defender for Office 365 Plan 1 starts at £1.80; AMVIA's fully managed email security - configuration, DMARC, monitoring and phishing simulation - starts from £5 per user per month on top of your Microsoft 365 licence. One provider, security-first. Last updated: 26 June 2026. Email is still where most attacks land. Phishing was identified by 85% of UK businesses that suffered a breach in the past year (Cyber Security Breaches Survey 2025, DSIT). The good news: meaningful protection is cheap relative to the cost of getting it wrong. This guide breaks down what each layer actually costs, what you get for the money, and how to size a realistic budget. For the wider picture of where email fits, see our managed cybersecurity for UK SMEs pillar. ## What does email security actually cost in 2026? Email security is priced in layers, not as a single line item. Most UK SMEs pay between £1.80 and £8 per user per month all-in, depending on whether they buy a Microsoft add-on, bundle it inside Microsoft 365 Business Premium, or hand the whole thing to a managed provider. The table below shows the realistic ranges. | | Layer | Typical cost (per user/mo, ex VAT) | What it covers | Exchange Online Protection | Included with any Microsoft 365 plan | Baseline anti-spam, anti-malware filtering | Microsoft Defender for Office 365 Plan 1 | from £1.80 | Safe Attachments, Safe Links, advanced anti-phishing | Microsoft 365 Business Premium (bundles Defender Plan 1) | £16.90 | Full M365 apps + Defender + Intune device management | AMVIA managed email security | from £5 | Setup, DMARC/DKIM/SPF, monitoring, phishing simulation | Phishing simulation training | £1–£3 (2026 market range) | Ongoing staff testing, reporting and coaching The cheapest number on the page is rarely the right answer. A licence you never configure protects nobody. The real cost question is "protection plus the time to run it" - which is where a managed layer earns its keep. ## What do you already get with Microsoft 365's built-in email security? Every Microsoft 365 plan includes Exchange Online Protection (EOP) at no extra cost. EOP gives you baseline anti-spam and anti-malware filtering on inbound and outbound mail. It is genuinely useful and blocks the bulk of commodity spam - but it is a floor, not a finished email security posture. EOP does not include the advanced anti-phishing, Safe Attachments (detonating files in a sandbox), or Safe Links (rewriting and scanning URLs at click time) that you get with Microsoft Defender for Office 365. Microsoft documents the difference between the two tiers in its Office 365 security comparison. For a business that handles invoices, payroll or client data over email, the gap between "basic filtering" and "active phishing defence" is the gap that attackers walk through. ## How much does Microsoft Defender for Office 365 cost? Microsoft Defender for Office 365 Plan 1 costs from £1.80 per user per month when bought standalone, and it is already included in Microsoft 365 Business Premium at £16.90 per user per month (Microsoft 365 UK pricing). If you are already on Business Premium, you have paid for it - the question is whether it is switched on and tuned. Plan 1 adds the three controls that matter most against modern phishing: - Safe Attachments - opens incoming files in an isolated environment before delivery, catching weaponised documents EOP misses. - Safe Links - rewrites every URL and re-checks it at the moment of click, defeating links that turn malicious after delivery. - Advanced anti-phishing - impersonation and spoof detection tuned to your domain and named users. We deploy and harden Defender as part of Microsoft Defender for Business. Buying the licence is step one; configuring policies, exclusions and alerting is where the protection actually comes from. ## What does managed email security add - and why does it cost more? AMVIA's managed email security starts from £5 per user per month on top of your Microsoft 365 licence. You are not paying for different software - Defender and the Barracuda email layer do the filtering - you are paying for the configuration, tuning, monitoring and incident response that turns licences into a defended mailbox estate. A managed layer typically includes: - Initial configuration and hardening of Defender for Office 365 policies - DMARC, DKIM and SPF set up correctly and monitored for failures - Quarantine review and false-positive management so legitimate mail still flows - Alerting into AMVIA's UK SOC when something gets through - Ongoing phishing simulation and reporting The maths is simple. The average cost of the most disruptive breach for a UK business is £3,550 (DSIT 2025) - and that figure excludes the management time, reputational damage and downtime that follow. A managed email security line of a few pounds per user is cheap insurance against a four-figure incident, before you count the hours your own team would otherwise spend. This is the "one provider, security-first" model: a single accountable team for licensing, configuration and response. ## Does DMARC, DKIM and SPF add to the cost? The DNS records themselves are free. DMARC, DKIM and SPF are open email-authentication standards published as DNS entries, so there is no licence to buy. The cost is expertise: configuring them in enforcement mode without breaking legitimate mail, then monitoring the reports over time. DMARC is one of the most cost-effective defences against domain spoofing - the technique behind most business email compromise (BEC) fraud aimed at your clients and staff. Overall IC3-reported cybercrime losses attacks increased 33% in 2025 (FBI IC3), and a domain published at `p=reject` makes it far harder for an attacker to impersonate you. The NCSC recommends DMARC for all organisations in its email security guidance. Get it set up properly via our DMARC, DKIM and SPF setup service, then leave it monitored - a misconfigured record silently bins real invoices. ## Should you budget for phishing simulation training too? Yes. No filter catches everything, so training people to spot what slips through is the second line of defence. Phishing simulation platforms typically cost £1–£3 per user per month (market rates as of 2026) and measurably cut click rates on malicious emails over time. Treat it as part of the email security budget, not an optional extra. Filters and people work together: the technology reduces volume, the training reduces the success rate of the few that land. With phishing identified by 85% of breached UK businesses (Cyber Security Breaches Survey 2025), the human layer is not soft - it is where most real incidents start or stop. Run it through our phishing simulation and training service alongside the managed filtering, and pair both with broader phishing protection. ## How should a 25-user business budget for email security? A practical all-in figure for a typical 25-user UK SME is £150–£200 per month for genuinely managed email security, assuming Microsoft 365 Business Premium is already in place. The exact number depends on how much you run in-house versus hand over. Worked example for 25 users (ex VAT, per month): - Defender for Office 365 already included in Business Premium - £0 incremental - AMVIA managed email security at £5/user - £125 - Phishing simulation at ~£2/user - £50 - DMARC/DKIM/SPF - included in the managed layer That lands around £175/month for fully managed, monitored email defence with staff testing - against a £3,550 average breach cost that a single successful phishing email can trigger. If you want the full Microsoft 365 security picture beyond email, our Microsoft 365 security pillar covers identity, devices and data alongside mail. ## Frequently asked questions Q: Is Microsoft 365's built-in email security enough on its own? A: Exchange Online Protection, included with every Microsoft 365 plan, gives baseline anti-spam and anti-malware filtering. It is not enough on its own - it lacks the Safe Attachments, Safe Links and advanced anti-phishing in Defender for Office 365. With phishing identified by 85% of breached UK businesses (DSIT 2025), the extra layer is worth the modest per-user cost. Q: How much is Microsoft Defender for Office 365 per user? A: Microsoft Defender for Office 365 Plan 1 costs from £1.80 per user per month standalone, and is bundled into Microsoft 365 Business Premium at £16.90 per user per month. If you already pay for Business Premium, you own Defender - the value then comes from configuring and monitoring it, not from buying it again. Q: Does DMARC cost anything to set up? A: The DMARC, DKIM and SPF records are free DNS entries with no licence fee. The cost is the expertise to deploy them in enforcement mode without blocking legitimate mail, then to monitor the reports. Done wrong, a record can silently reject real invoices, so most SMEs include it in a managed email security service. Q: Why does managed email security cost more than a Microsoft licence? A: A Microsoft licence is software; managed email security is the configuration, tuning, monitoring and incident response that makes the software effective. AMVIA's managed service starts from £5 per user per month on top of your licence and covers Defender hardening, DMARC, quarantine management and SOC alerting - turning a paid-for licence into an actively defended mailbox estate. Q: What is the total monthly cost for a small business? A: A typical 25-user UK SME on Microsoft 365 Business Premium can expect around £150–£200 per month for fully managed email security including phishing simulation. That works out at roughly £6–£8 per user all-in - cheap against the £3,550 average cost of the most disruptive breach (DSIT 2025). Q: Is phishing simulation training worth the extra cost? A: Yes. At £1–£3 per user per month (2026 market rates), simulation training is one of the highest-return security spends because it directly reduces the human error behind most successful phishing. No filter catches every threat, so testing and coaching staff measurably lowers click rates on the emails that get through. --- # Do Small Businesses Need Cybersecurity? URL: https://amvia.co.uk/cybersecurity/questions/do-small-businesses-need-cybersecurity Last updated: 2026-03 Yes. Small businesses need cybersecurity because they are targeted more often than large enterprises, not less. 43% of UK businesses suffered a breach or attack in 2025 (Cyber Security Breaches Survey 2025, gov.uk). SMEs hold valuable data but invest less in defence, which is exactly why attackers pick them. The good news: a handful of controls stop most attacks - and they cost far less than recovery. The reflex answer from a lot of owner-managed firms is "we're too small to be a target." That belief is the vulnerability. Attackers do not hand-pick victims by revenue. They run automated campaigns that scan thousands of businesses at once, find the ones with weak email security, unpatched devices or no monitoring, and walk in. If your business sends invoices, holds customer records or banks online, you have something worth stealing. This guide explains who is actually at risk, what an attack costs, and the minimum controls AMVIA tells UK SMEs to put in place - drawn from how we run managed cybersecurity for 1,200+ UK businesses. ## Why are small businesses targeted by cybercriminals? Small businesses are targeted because they combine valuable data with weaker defences. Attackers know SMEs rarely have dedicated security staff, often rely on basic antivirus, and may not notice a breach for weeks. That mix of value and exposure makes a 20-person firm an easier, more reliable payday than a hardened enterprise. Four practical reasons attackers favour smaller firms: - Weaker defences. Many SMEs run consumer-grade antivirus and hope for the best. There is no one watching the alerts, so intrusions go unchallenged. - Valuable data. Customer records, payment details, payroll and intellectual property all have resale, ransom or fraud value - regardless of company size. - Supply-chain access. Attackers compromise a small supplier to reach its larger clients. If you serve enterprise customers, your security is contractually their concern too. - Low detection rates. Without monitoring, the average SME can take weeks or months to spot a breach, giving attackers time to extract maximum value. The UK's National Cyber Security Centre publishes a free Small Business Guide precisely because this segment is so heavily hit. The threat is not theoretical or reserved for household names - it is automated, indiscriminate, and aimed squarely at the businesses least prepared for it. ## What are the most common cyber threats facing small businesses? Phishing is by far the most common threat. 85% of UK businesses that identified a breach in 2025 pointed to phishing as the vector (Cyber Security Breaches Survey 2025, gov.uk). Beyond phishing, SMEs face ransomware, business email compromise and credential theft - most of which begin with a single staff member clicking the wrong link. A quick read on the threats that actually hit UK SMEs: - Phishing. Fraudulent emails that harvest passwords or trick staff into transfers. The entry point for the majority of breaches - see our guide to email security. - Ransomware. Malware that encrypts your files and demands payment. Recovery without tested backups can take weeks; read what ransomware is and how it spreads. - Business email compromise (BEC). Attackers impersonate a director or supplier to redirect a genuine payment. Often invisible to antivirus because no malware is involved. - Credential theft. Stolen or reused passwords sold on criminal markets, used to log straight into mailboxes and cloud apps. The common thread is people, not technology. That is why staff awareness and email filtering matter as much as endpoint tooling - attackers go through the inbox far more often than they break through a firewall. ## What does a cyber attack actually cost a small business? The direct cost is only the start. The average cost of the most disruptive breach was £3,550 in 2025 (Cyber Security Breaches Survey 2025, gov.uk), but that figure climbs fast once you add lost trading time, data-loss recovery, customer churn and potential regulatory fines under UK GDPR. For an SME, the indirect costs usually hurt more than the ransom or fraud loss itself: - Downtime. Days offline while systems are rebuilt - staff paid, no revenue earned. - Recovery labour. Forensics, rebuilds and clean-up, often at emergency rates. - Regulatory exposure. A personal-data breach may be reportable to the ICO within 72 hours, with fines for serious failures. - Reputation. Lost contracts and customer confidence that take far longer to rebuild than the systems did. Set against that, prevention is cheap. A managed cybersecurity service for an SME typically runs £15–£25 per user per month, covering endpoint protection, email filtering and monitoring - a fraction of a single day's breach recovery. For a full breakdown, see how much managed cybersecurity costs. ## No security vs basic vs managed: what does each level deliver? The honest comparison is not "secure vs insecure" - it is how much risk each spend level actually removes. No security leaves you fully exposed. Basic DIY antivirus stops commodity malware but nothing targeted. Managed security adds the detection, response and monitoring that stop the attacks that hurt. | | Capability | No security £0/mo | Basic DIY £3–£8/user/mo | Managed security £15–£25/user/mo | Antivirus / antimalware | ✗ | ✓ | ✓ | Email filtering | ✗ | Basic | ✓ | Endpoint detection (EDR) | ✗ | ✗ | ✓ | 24/7 monitoring | ✗ | ✗ | ✓ | Incident response | ✗ | ✗ | ✓ | Compliance support | ✗ | ✗ | ✓ | Staff awareness training | ✗ | ✗ | ✓ *Pricing indicative for businesses with 10–50 users.* The gap that matters is monitoring and response. Basic antivirus is a locked door with nobody home; managed security is the locked door plus someone watching the alarm and responding when it trips. AMVIA delivers that response through Microsoft Defender for Endpoint, watched 24/7 by our in-house SOC - see managed detection and response. ## What is the minimum cybersecurity a small business should have? At minimum, every UK SME needs five controls: multi-factor authentication on every account, email filtering to block phishing, endpoint protection on every device, regular patching, and tested backups. These stop the overwhelming majority of commodity attacks - and most are cheap or already included in your Microsoft 365 licence. Yet adoption lags badly. Only 47% of UK businesses have two-factor authentication in place (Cyber Security Breaches Survey 2025/26, gov.uk), despite it being one of the most effective and lowest-cost defences available. The practical starting checklist AMVIA recommends: 1. Turn on MFA everywhere - email, banking, every cloud app. It blocks the vast majority of password-based attacks. 2. Filter email properly - catch phishing and BEC before staff ever see it. 3. Protect every endpoint - managed EDR, not just signature antivirus. 4. Patch on a schedule - most breaches exploit known, already-fixed flaws. 5. Back up and test restores - your only guaranteed recovery from ransomware. Working toward Cyber Essentials Plus is the cleanest way for an SME to evidence these controls - it is the certification AMVIA itself holds, and increasingly a requirement to win public-sector and enterprise contracts. One provider, security-first, Microsoft-certified: that is how we close these gaps without bolting together five different vendors. ## Frequently asked questions Q: Are small businesses really targeted, or is that scaremongering? A: They are genuinely targeted. 43% of UK businesses reported a breach or attack in 2025 (Cyber Security Breaches Survey 2025, gov.uk), and most attacks are automated rather than hand-picked. Criminals scan thousands of firms for weak email security or unpatched devices and exploit whichever they find - company size is irrelevant to the scanner. Q: Can a small business afford managed cybersecurity? A: Yes. Managed cybersecurity for an SME typically costs £15–£25 per user per month, covering endpoint protection, email filtering and monitoring. Set that against an average most-disruptive-breach cost of £3,550 - a figure that climbs steeply once downtime, data loss and fines are added. Prevention is consistently cheaper than recovery. Q: Isn't the antivirus built into Windows enough? A: No, not on its own. Built-in antivirus stops commodity malware but does not provide email filtering, 24/7 monitoring, incident response or staff training - the controls that stop targeted phishing, BEC and ransomware. It is a sensible base layer, not a complete defence. Managed endpoint security adds the detection and response that matter. Q: What is the single most effective control to start with? A: Multi-factor authentication. It blocks the overwhelming majority of password-based attacks and costs nothing on most Microsoft 365 plans, yet only 47% of UK businesses have it in place (Cyber Security Breaches Survey 2025/26, gov.uk). Turn it on across email, banking and every cloud app before spending on anything else. Q: Do we need cybersecurity to win bigger contracts? A: Increasingly, yes. Enterprise and public-sector buyers now ask suppliers to evidence security controls, and many require Cyber Essentials or Cyber Essentials Plus certification before signing. Strong security has shifted from a cost to a sales enabler - it removes a procurement blocker and proves you will not become the weak link in their supply chain. Q: How quickly can a small business improve its security? A: Quickly. MFA, email filtering and managed endpoint protection can be deployed across a 10–50 user business in days, not months, because they configure within existing Microsoft 365 tenancy. A free security audit maps your current gaps in about 30 minutes, so you fix the highest-risk issues first rather than guessing. --- # What Is a Cyber Breach and What Should You Do? URL: https://amvia.co.uk/cybersecurity/questions/what-is-a-cyber-breach Last updated: 2026-03 A cyber breach is any incident where an unauthorised party accesses, steals, corrupts, or disrupts your business data or systems. It is what happens when an attack succeeds. In the UK, 43% of businesses suffered a breach or attack in the past year - and the firms that recover fastest are the ones with a plan and a single accountable security provider before it happens. ## What counts as a cyber breach, exactly? A breach is the moment unauthorised access actually occurs - data is read, copied, encrypted, deleted, or systems are taken offline. It is distinct from an attempt. If a phishing email is blocked, that is a thwarted attack; if someone clicks, hands over credentials, and a criminal logs into your mailbox, that is a breach. The distinction is not academic. Breaches involving personal data trigger legal reporting duties, insurance claims, and regulatory scrutiny that mere attempts do not. According to the UK government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach or attack in the previous 12 months. Common breach types include: - Account takeover - stolen credentials used to log into email, finance, or cloud systems - Ransomware - files encrypted and held to ransom (see what is ransomware) - Data exfiltration - customer, employee, or commercial data copied out - Business email compromise - a hijacked or spoofed inbox used to redirect payments - System disruption - services knocked offline, often to extort or distract If your data or systems were touched without permission, treat it as a breach and work back to the parent topic on our managed cybersecurity pillar to understand the controls that prevent it. ## How do cyber breaches actually happen? Most breaches are not sophisticated. They exploit predictable gaps: a reused password, an unpatched server, a convincing email. The Cyber Security Breaches Survey 2025 found phishing was the most common vector, identified by 85% of businesses that suffered a breach. That single statistic should shape where you spend. The headline-grabbing nation-state attack is rare; the email that tricks an accounts clerk into resetting a password is daily. The most frequent breach paths for UK SMEs are: | | Breach path | Typical trigger | Primary control | Phishing | Staff click a malicious link or attachment | Email filtering + phishing protection and training | Credential theft | Reused or weak passwords | Multi-factor authentication everywhere | Unpatched software | Known vulnerability left open | Routine patching and vulnerability management | Misconfigured cloud | Open storage, weak M365 defaults | Hardening and configuration review | Insider error | Data sent or shared by mistake | Access controls and data loss prevention The pattern is consistent: foundational controls stop the overwhelming majority of incidents. The NCSC makes the same point - basic cyber hygiene, applied consistently, defeats most attacks before they become breaches. ## What is the difference between a cyber breach and a cyber attack? A cyber attack is any attempt to compromise your systems, including the unsuccessful ones. A cyber breach is what you have when an attack succeeds and unauthorised access, theft, or disruption actually occurs. Every breach starts as an attack; not every attack becomes a breach. This matters for three reasons. First, reporting: only a breach involving personal data starts the regulatory clock. Second, insurance: insurers distinguish blocked attempts from realised losses. Third, response: an attack you stopped needs review, while a breach needs containment, notification, and recovery. The 43% headline figure from the Cyber Security Breaches Survey 2025 covers both breaches and attacks combined - which is why your own logging needs to tell the two apart. ## What should you do immediately after a cyber breach? Move fast and in order. Contain first, then preserve evidence, then notify. The first hour shapes the cost and the recovery. Do not wipe machines, do not pay anything, and do not stay silent - get the right people involved straight away. The immediate steps, in sequence: 1. Isolate affected systems - disconnect compromised devices from the network without powering them off, to preserve forensic evidence. 2. Contact your IT or security provider - escalate to whoever owns incident response. Our incident response team works this exact runbook. 3. Change credentials - reset passwords and revoke sessions for affected and connected accounts; enforce MFA. 4. Report to Action Fraud - the UK's national reporting centre for cyber crime, at actionfraud.police.uk. 5. Notify the ICO within 72 hours - if personal data was compromised (see below). 6. Preserve logs and timeline - record what was seen, when, and by whom for insurers and regulators. For the full recovery playbook, read our guide on what to do after a cyber breach. Continuous detection through managed detection and response is what turns a six-figure incident into a contained one - because the breach is caught in minutes, not discovered in months. ## Are you legally required to report a cyber breach in the UK? If a breach involves personal data, UK GDPR requires you to notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. You must also tell affected individuals where the breach poses a high risk to their rights and freedoms. Reporting is not optional. The penalties are significant: under UK GDPR, fines can reach up to £17.5 million or 4% of annual global turnover, whichever is higher. That regulatory exposure sits on top of the direct incident cost. The Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach at £3,550, rising to £8,260 where data or money was actually lost - and those figures exclude fines, legal fees, and lost custom. ## What does a cyber breach actually cost a UK business? The measurable cost is only part of it. The Cyber Security Breaches Survey 2025 reports an average of £3,550 for the most disruptive breach, climbing to £8,260 where data or finances were lost. For most SMEs, the harder costs are downtime, lost customer trust, and the management hours consumed by clean-up. - Direct costs - incident response, recovery, replacement hardware or software - Regulatory costs - ICO fines up to £17.5 million or 4% of turnover for serious breaches - Operational costs - downtime, lost orders, staff diverted from their day jobs - Reputational costs - customers and partners who walk after a public incident Prevention is consistently cheaper than recovery. One provider that owns your security, runs Microsoft-certified controls, and monitors round the clock costs a fraction of a single serious breach. ## Frequently asked questions Q: What are the most common causes of cyber breaches in the UK? A: Phishing is the leading cause: 85% of UK businesses that suffered a breach identified it as the attack type (Cyber Security Breaches Survey 2025). Other frequent causes include stolen credentials, unpatched software, and misconfigured cloud services. Most breaches exploit basic gaps, which is why MFA and patching prevent the majority of incidents. Q: Am I legally required to report a cyber breach? A: If a breach involves personal data, UK GDPR requires notification to the ICO within 72 hours of becoming aware of it, and you must inform affected individuals where there is a high risk to their rights. Failure to report can attract fines of up to £17.5 million or 4% of annual turnover. Regulatory penalties can far exceed the direct incident cost. Q: What is the difference between a cyber breach and a cyber attack? A: A cyber attack is any attempt to compromise your systems, including unsuccessful ones. A cyber breach occurs when an attack succeeds and unauthorised access, data theft, or disruption actually happens. With 43% of UK businesses experiencing a breach or attack in 2025, the distinction matters for incident reporting, insurance claims, and regulatory duties. Q: How quickly should a cyber breach be contained? A: Aim to contain within the first hour. Isolate affected systems from the network without powering them off, reset credentials, and escalate to your security provider immediately. The speed of containment is the single biggest factor in how much a breach ultimately costs, because it limits how far an attacker can move. Q: Can a small business really be a target for a cyber breach? A: Yes. Smaller firms are frequently targeted precisely because their defences are thinner, and the Cyber Security Breaches Survey 2025 shows breaches are common across all business sizes. Attackers automate phishing and credential attacks at scale, so being small offers no protection. Foundational controls and continuous monitoring close the gap. Q: Will cyber insurance cover a breach? A: It depends on your policy and whether you met its conditions, which increasingly require MFA, patching, and documented incident response. Insurers distinguish blocked attempts from realised losses, so accurate logging matters. Keeping evidence - affected systems, timelines, and actions taken - is essential to support any claim after a breach. --- # How to Get Cyber Insurance for a UK Small Business URL: https://amvia.co.uk/cybersecurity/questions/how-to-get-cyber-insurance-uk Last updated: 2026-03 To get cyber insurance in the UK, you must prove strong security controls before you apply. Insurers now treat MFA, endpoint detection, tested backups, email security and staff training as minimum entry requirements. Get these in place first and you secure cover at sensible terms; skip them and you face higher excess, exclusions, or outright rejection. Most UK businesses approach this backwards. They get quoted, get shocked at the price or the refusal, then scramble to fix controls. The cheaper, faster route is to treat the proposal form as a security checklist and close the gaps before an underwriter ever sees you. That is exactly the work our managed cybersecurity team does for clients heading into renewal. ## What is cyber insurance and does my UK business need it? Cyber insurance covers the financial fallout of a cyber attack: incident response costs, data recovery, business interruption, legal fees, regulatory defence, and in some policies, extortion payments. For UK SMEs it is now close to essential, because the cost of a serious breach routinely exceeds what a small business can absorb from cash flow. The numbers make the case. "The average cost of the most disruptive breach is £3,550 (DSIT 2025)" for businesses overall, with medium and large organisations facing far higher figures, according to the government's Cyber Security Breaches Survey 2025. Insurance exists to stop a single incident becoming an existential event. ## What security controls do UK cyber insurers require? Underwriters now assess your security posture before they price the risk. The proposal form is effectively a controls audit, and weak answers either raise your premium or end the application. These are the controls UK insurers ask about most consistently in 2026. - Multi-factor authentication (MFA): MFA on all remote access, admin accounts and cloud services is a universal requirement. Insurers will not cover businesses without it. This matters because "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)" - meaning most applicants fail at the first hurdle. Our MFA setup for Microsoft 365 guide covers enforcement properly, not just switching it on. - Endpoint detection and response (EDR): Modern detection on every device. Traditional signature antivirus alone is no longer accepted by most insurers. See our endpoint security page for what "good" looks like. - Tested, immutable backups: Regular backups stored separately from the network, with evidence they have been restored - not just that they exist. Underwriters ask about restore testing frequency specifically. - Email security: Advanced filtering plus DMARC, SPF and DKIM authentication to blunt the most common attack vector. Our email security service covers the full stack. - Staff awareness training: Regular training and simulated phishing. Insurers know human error is the dominant risk factor, which is why phishing simulation and training carries weight on the proposal form. - Patch management cadence: A documented process for applying critical patches quickly, usually within 14 days for high-severity vulnerabilities. The NCSC's cyber insurance guidance makes the same point: insurance is a complement to good security, never a substitute for it. ## How does Cyber Essentials affect cyber insurance? Cyber Essentials is the UK government-backed certification that maps almost exactly onto what insurers want - boundary firewalls, secure configuration, access control, malware protection and patch management. Holding it tells an underwriter your baseline is sound, which is why many insurers reward it. Several UK cyber insurers offer premium discounts of 10–25% (typical UK 2026 range) for organisations holding a current certification, and some now require it as a minimum condition of cover. There is also a direct incentive built into the scheme: businesses with annual turnover under £20m that certify their whole organisation to Cyber Essentials get free cyber liability insurance included, per the Cyber Essentials scheme. AMVIA holds Cyber Essentials Plus, so we know the assessment from the inside and can get you certified before your renewal date. ## How much does cyber insurance cost with strong vs weak controls? Your security posture is the single biggest lever on price. A business with the controls above gets accepted at lower premiums, lower excess and fewer exclusions. A business without them is quoted punitively or declined. The contrast for a typical 50-user firm looks like this. | | Factor | Weak controls (high premium / rejection) | Strong controls (better terms - recommended) | Application outcome | Often rejected | Accepted | Annual premium (50 users, 2026 market rates) | £3,000–£8,000+ | £1,500–£3,000 | Excess / deductible | Higher | Lower | Coverage exclusions | Many | Fewer | Claims honoured | Risk of rejection | More likely The pattern is clear: the money you spend closing security gaps is largely recovered through lower premiums and dramatically reduced breach risk. Cover is cheaper when you are genuinely harder to attack. ## How do I apply for cyber insurance in the UK, step by step? The fastest route to good terms is to prepare before you quote. Treat the proposal form as a pre-flight checklist and you turn a stressful negotiation into a formality. Here is the order we take clients through. 1. Run a gap assessment. Map your current controls against MFA, EDR, backups, email security, training and patching. A free security audit gives you this in writing. 2. Close the critical gaps. Enforce MFA everywhere, deploy EDR, prove your backups restore, and harden email. These are non-negotiable for cover. 3. Get Cyber Essentials certified. It evidences your baseline and enables discounts or free cover. 4. Document everything. Underwriters want evidence - policies, testing logs, training records - not assertions. 5. Answer the proposal form accurately. Never overstate your posture (see the next section on why). 6. Compare quotes on cover, not just price. Check exclusions, sub-limits, and incident-response support, including whether the policy gives you access to a breach response team. If you cannot answer a proposal question confidently, that is a gap to fix - not a box to tick optimistically. Our 24/7 managed detection and response service exists partly because insurers increasingly expect round-the-clock monitoring on higher-value policies. ## Can a cyber insurance claim be rejected after a breach? Yes, and it happens. If an insurer finds you misrepresented your security on the application, or failed to maintain the controls you declared, the claim can be reduced or refused entirely. The "warranty" wording in most policies means a single false answer can void cover when you need it most. This is the core risk of the tick-box approach. If you declared MFA on all accounts but left admin accounts exposed, and the breach came through one of them, expect a fight - or a refusal. Accuracy on the proposal form, backed by controls you actually run, is what makes a policy pay out. ## Frequently asked questions Q: What do UK cyber insurers require before they'll quote? A: Evidence of controls, not promises: MFA everywhere, endpoint detection, tested backups, email security and staff training are now baseline expectations - applications without them face declined cover or loaded premiums. The proposal form is effectively a security audit. Q: How much does cyber insurance cost a UK SME? A: Typical SME premiums run £1,500–£3,000 a year for meaningful cover, scaling with turnover, sector and controls. Weak security raises the premium faster than almost anything else - the same controls that protect you also price the policy. Q: Does Cyber Essentials help with cyber insurance? A: Yes, twice over: certification evidences exactly the controls insurers ask about, and basic Cyber Essentials through IASME includes cyber liability insurance for eligible UK organisations under £20m turnover - a bundled floor of cover many SMEs don't realise they get. Q: Will insurance pay out if we get breached? A: If your application was accurate and controls were actually in place, that's what it's for. The claims that fail are the ones where the proposal form said MFA everywhere and the forensics found otherwise - which is why controls must be real, monitored and evidenced, not aspirational. --- # What Is Zero Trust Security? UK Business Guide URL: https://amvia.co.uk/cybersecurity/questions/what-is-zero-trust Last updated: 2026-03 Zero trust is a security model that replaces "trusted inside the network" with continuous verification: every user, device and request is authenticated, authorised and checked against policy before access is granted, regardless of location. For UK SMEs on Microsoft 365, AMVIA builds it with Conditional Access, MFA and Intune. One provider, security-first. The old model assumed anything inside the office firewall was safe. That assumption broke the moment your staff started working from home, opening Microsoft 365 from laptops, phones and home Wi-Fi. Zero trust fixes the gap by trusting nothing by default and verifying everything, every time. It is the model the National Cyber Security Centre recommends for modern, cloud-based working, and it underpins the managed cybersecurity services AMVIA runs for UK businesses. ## What are the core principles of zero trust? Zero trust rests on three principles, each enforced through specific controls rather than slogans. Microsoft frames them as verify explicitly, use least-privilege access, and assume breach. Together they shrink the damage an attacker can do even after they get a foothold inside your environment. - Verify explicitly - authenticate and authorise every request using all available signals: user identity, device health, location and the sensitivity of the application being accessed. - Least-privilege access - grant only the permissions a person or system needs for the task in front of them. Privileged access is time-limited and re-verified, never standing. - Assume breach - design as though an attacker is already inside. Segment resources to limit lateral movement, reduce blast radius, and support fast detection and response. These principles map directly onto Microsoft's published zero trust guidance, which is the framework AMVIA implements for clients running Microsoft 365. ## How does zero trust work in practice? In practice, zero trust is a set of always-on checks layered across identity, device and network. Each access request is evaluated in real time, and access is granted, blocked or stepped up depending on the risk it carries at that moment. Nothing is trusted permanently. The mechanics break down into four enforced controls: - Device health verification - a device must meet defined standards (disk encryption on, OS patched, antivirus active) before it can reach corporate resources. AMVIA enforces this with Microsoft Intune device compliance. - Network micro-segmentation - instead of one flat network, resources are segmented so a compromised account or device cannot freely reach everything else. - Continuous monitoring - access and behaviour are watched throughout a session, not just at login. Anomalies can trigger step-up authentication or session termination. - Conditional, risk-based access - sign-ins are scored against policy before anything is granted, using Conditional Access in Microsoft Entra ID. ## Perimeter security vs zero trust: what is the difference? The difference is where trust comes from. Perimeter security trusts you because of where you are - inside the network. Zero trust trusts you because of what you can prove right now - verified identity, a healthy device and a low-risk request. For remote and cloud working, location-based trust no longer holds up. | | Feature | Perimeter security (trust the network) | Zero trust (verify everything) | Trust based on network location | Yes | No | Continuous identity verification | No | Yes | Device compliance enforced | No | Yes | Conditional Access policies | No | Yes | Lateral movement constrained | No | Yes | Effective for remote workers | Limited | Yes | Works with cloud services (M365, etc.) | Partially | Yes Microsoft Entra ID (formerly Azure AD) with Conditional Access is the primary vehicle for implementing zero trust in a Microsoft 365 environment. ## Why does zero trust matter for UK SMEs? It matters because the perimeter most SMEs still rely on no longer reflects how they work. With 43% of UK businesses experiencing a breach or attack in the past year (Cyber Security Breaches Survey 2025), and many staff signing in from home networks and personal devices, implicit network trust is now a liability rather than a safeguard. The data also shows the gap is basic. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26), per the government's Cyber Security Breaches Survey 2025. That single control is one of the cheapest, highest-impact steps toward a zero trust posture - and most firms still have not switched it on. For a typical 10–500 staff business, zero trust is less about exotic technology and more about turning on and configuring controls you may already own. If you run Microsoft 365 Business Premium, the building blocks are already in your licence; the work is configuring them correctly and keeping them that way. ## Can a small business implement zero trust without a large IT team? Yes. Microsoft 365 Business Premium bundles the core building blocks - Conditional Access, Intune device compliance and MFA - into a single licence at £16.90 per user per month (ex VAT, annual). An MSP configures and maintains the policies, so you do not need an in-house security team to run it. AMVIA delivers this as a managed zero trust security service, identity-led and configured around your Microsoft 365 tenant, from £4.60/user. The starting point for most clients is enabling MFA everywhere and writing sensible Conditional Access policies - the two changes that move the needle fastest. ## How long does it take to adopt zero trust? Zero trust is a programme, not a one-off project. Most SMEs can deploy the foundational controls - MFA, Conditional Access and device compliance - within a few weeks. Maturing toward full micro-segmentation and continuous monitoring takes longer and is best phased. The fastest wins come from starting with the highest-risk areas: administrator accounts, finance staff and access to sensitive data. Lock those down first, then widen coverage. Pairing this with managed detection and response gives you the monitoring layer that makes "assume breach" real rather than theoretical. ## Frequently asked questions Q: What is zero trust in simple terms? A: Zero trust means never trusting a user or device by default, even inside your own network. Every request to reach data or an application must be verified - confirming who you are, that your device is healthy, and that the request is low-risk - before access is granted. Trust is earned per request, never assumed. Q: How does Conditional Access support zero trust? A: Conditional Access policies in Microsoft Entra ID evaluate each sign-in against criteria such as user location, device compliance and risk level before granting access. This enforces the "verify explicitly" principle without making users jump through hoops on every login. It is the primary enforcement mechanism for zero trust in Microsoft 365 environments. Q: What is the difference between zero trust and a VPN? A: A VPN grants broad network access once you authenticate, trusting everything inside the tunnel. Zero trust verifies every individual resource request regardless of network location. With 43% of UK businesses experiencing a breach or attack (DSIT 2025), the VPN model of implicit trust is increasingly seen as insufficient. Zero trust limits lateral movement even if an attacker gets in. Q: Does zero trust require replacing my existing systems? A: No. For most UK SMEs, zero trust is built on tools you already license - particularly Microsoft 365. The work is configuration: enabling MFA, writing Conditional Access policies and enforcing Intune device compliance. You rarely need to rip and replace; you need to switch on and tune what you already own. Q: Is MFA the same as zero trust? A: No, but it is the foundation. MFA proves identity more strongly; zero trust then layers device health, least-privilege access and continuous monitoring on top. With only 40% of UK businesses using two-factor authentication (DSIT 2025), enabling MFA is the single most valuable first step toward a zero trust posture. Q: Is zero trust suitable for businesses with hybrid or remote staff? A: Yes - it is built for exactly that. Because trust is based on verified identity and device health rather than network location, zero trust treats a laptop at home the same as one in the office. That makes it far better suited to hybrid working than perimeter security, which assumes everyone valuable sits behind the firewall. --- # What Is a Security Operations Centre (SOC)? URL: https://amvia.co.uk/cybersecurity/questions/what-is-a-soc Last updated: 2026-03 A Security Operations Centre (SOC) is a team of security analysts who monitor your IT environment 24/7, detect threats, investigate incidents, and coordinate response. A managed SOC delivers that same capability as a service - with no in-house team to build. AMVIA runs its own UK-based 24/7 SOC: one provider, security-first, Microsoft-certified. For most UK SMEs, the practical question is not "should we have a SOC?" but "do we build one or buy one?" This guide explains what a SOC does, why it matters in 2026, what it costs, and how a managed SOC compares to hiring analysts in-house. It sits under our managed cybersecurity pillar, where you can see how SOC monitoring fits the wider security stack. ## What does a SOC actually do? A SOC continuously watches every signal your IT estate produces - endpoints, firewalls, identity systems, email, and cloud platforms - and turns that noise into action. Analysts detect suspicious activity, triage it by severity, investigate genuine threats, and drive containment before an attacker can move laterally or exfiltrate data. The core day-to-day work breaks down into: - Monitoring - watching security alerts across the whole environment, around the clock. - Triage - separating real threats from the flood of false positives. - Investigation - correlating logs from firewalls, endpoints, identity, and cloud to confirm what is actually happening. - Response - isolating compromised devices, revoking access, and coordinating recovery. - Improvement - tuning detections and feeding lessons back into hardening. The point of a SOC is to shrink *dwell time* - the gap between a breach starting and someone noticing. With 43% of UK businesses reporting a breach or attack in the past 12 months (Cyber Security Breaches Survey 2025), having trained analysts reviewing alerts at 3am is the difference between a contained incident and a headline. This is the same discipline behind our managed SOC service and 24/7 security monitoring. ## Why do UK SMEs need a SOC in 2026? UK businesses face a volume of attacks that few in-house teams can watch alone. The national picture is stark, and the cost of missing an alert is rising. A SOC exists precisely because attacks do not keep office hours - and most breaches are detected far too late without continuous monitoring. The numbers that matter: - 43% of UK businesses experienced a breach or attack in the last 12 months (Cyber Security Breaches Survey 2025). - 21% of businesses that experienced a breach reported a negative outcome, such as loss of money or data (Cyber Security Breaches Survey 2025). - 7% of businesses that experienced a breach reported temporary loss of access to files or networks - up from 4% in 2024 (Cyber Security Breaches Survey 2025). - The average cost of the most disruptive breach is £3,550 (Cyber Security Breaches Survey 2025). - The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant - the highest-ever number (National Cyber Security Centre). Those headline figures understate the SME exposure, because smaller businesses are the easiest targets and the least likely to have 24/7 cover. A SOC closes that gap. If you suspect you are already exposed, our incident response team works to the same playbook the SOC uses every day. ## In-house SOC vs managed SOC: which makes sense for an SME? For almost every business under 500 staff, a managed SOC is the rational choice. Building in-house means hiring five to six analysts for genuine 24/7 cover, then licensing a SIEM, tooling, and training on top. A managed SOC delivers equivalent coverage for a predictable monthly fee. | | Factor | In-house SOC | Managed SOC (AMVIA) | 24/7 staffing | 5–6 analysts minimum | Included in the service | Typical cost | £300,000+ per year | £1,500–£5,000 per month | SIEM & tooling | Buy, license, maintain yourself | Provided and managed | Time to operational | Months of hiring and setup | Weeks | Coverage gaps | Holidays, sickness, attrition | None - team-based cover | Threat intelligence | You source it | Built in Building an in-house SOC requires a minimum of five to six analysts for round-the-clock coverage, plus SIEM licensing, tooling, and training - typically exceeding £300,000 per year. A managed SOC for a 50-user business costs roughly £1,500 to £5,000 per month, providing equivalent coverage at a fraction of the cost. That maths is why managed SOC is the default for UK SMEs - see our SOC-as-a-service page for how it is delivered. ## What is a SIEM, and why does a SOC need one? A Security Information and Event Management (SIEM) platform aggregates logs from across your entire environment - endpoints, firewalls, servers, and cloud services - and correlates events to detect patterns no single system would flag in isolation. It is the analytical backbone a SOC depends on to spot a threat as it unfolds. Without a SIEM, analysts are reading individual alerts in isolation and missing the story that connects them - a failed login here, a privilege change there, an unusual data transfer minutes later. The SIEM stitches those signals into one timeline. Early, SIEM-based detection is what stops a foothold becoming a full breach, and given the average most-disruptive breach costs £3,550 (Cyber Security Breaches Survey 2025), that early catch pays for itself. Our SIEM for SMEs page explains how we run it without enterprise complexity. ## What does AMVIA's managed SOC include? AMVIA's SOC is staffed in-house and runs 24/7, built on a Microsoft-first stack. We monitor Microsoft Defender for Endpoint across your devices, with Barracuda protecting email and network, and our analysts investigating and responding to every confirmed threat. One provider owns detection, investigation, and response end to end. What you get: - A UK-based, in-house SOC team - not an outsourced overnight desk. - 24/7 monitoring of Microsoft Defender for Endpoint, correlated through our SIEM. - Barracuda email and network protection feeding the same monitoring pipeline. - Investigation and hands-on response to confirmed incidents, not just alerts forwarded to your inbox. - Microsoft-certified engineers behind every escalation. This is the difference between a tool that pings you and a team that acts. If you want managed detection and response that wraps the SOC around your endpoints, see managed detection & response. ## Frequently asked questions Q: What does a SOC analyst actually do day-to-day? A: SOC analysts monitor security alerts from across your environment, investigate suspicious activity, triage incidents by severity, and coordinate containment and response. They correlate data from firewalls, endpoints, identity systems, and cloud platforms to separate genuine threats from false positives, so real attacks are caught early rather than discovered weeks later. Q: How much does an in-house SOC cost compared to a managed SOC? A: Building an in-house SOC means hiring five to six analysts for 24/7 cover, plus SIEM licensing, tooling, and training - typically exceeding £300,000 per year. A managed SOC for a 50-user business costs roughly £1,500 to £5,000 per month, delivering equivalent coverage for a fraction of the cost. That is why managed SOC is the practical option for UK SMEs. Q: What is the difference between a SOC and a SIEM? A: A SOC is the team of analysts; a SIEM is the platform they use. The SIEM aggregates and correlates logs from across your environment to surface threats, while the SOC investigates those findings and drives response. You need both - a SIEM without analysts just produces alerts nobody acts on. Q: Do small businesses really need a SOC? A: Yes. With 43% of UK businesses reporting a breach or attack in the last year (Cyber Security Breaches Survey 2025), SMEs are frequent targets and the least likely to have 24/7 cover. A managed SOC gives a small business enterprise-grade monitoring without the headcount, which is why it is the standard choice under 500 staff. Q: Is a managed SOC the same as MDR? A: They overlap but are not identical. A SOC is the monitoring-and-response function; Managed Detection and Response (MDR) packages that capability tightly around your endpoints with a defined detection-and-response outcome. In practice AMVIA delivers both through one in-house team rather than bolting on a separate vendor. Q: How quickly can a managed SOC be up and running? A: A managed SOC can typically be operational within weeks, compared with the months of recruitment and setup an in-house build requires. AMVIA connects monitoring to your existing Microsoft Defender and Barracuda estate, tunes detections to your environment, and starts watching - no large capital outlay and no hiring drag. --- # MDR vs EDR: Which Does Your Business Need? URL: https://amvia.co.uk/cybersecurity/compare/mdr-vs-edr Last updated: 2026-03 MDR and EDR solve the same problem differently. EDR is the detection technology that spots threats on your devices; MDR wraps that technology in a 24/7 human team that triages alerts and responds. For most UK SMEs without a dedicated security analyst, MDR is the safer choice - and it is how AMVIA delivers managed cybersecurity without the headcount. The short version: EDR gives you the tooling, MDR gives you the tooling plus the people to run it. If you already have a security operations team, EDR may be enough. If you don't, paying for detection you can't action is a false economy. The UK skills gap makes this decision more urgent than most MDs realise - 49% of UK businesses have a basic cyber security skills gap (DSIT, Cyber security skills in the UK labour market 2025). ## What is the difference between MDR and EDR? EDR (Endpoint Detection and Response) is software that monitors laptops, servers and devices for malicious behaviour and flags or contains it. MDR (Managed Detection and Response) is a service: it includes EDR technology plus a 24/7 team that investigates every alert, hunts for threats, and takes response action on your behalf. The cleanest way to think about it: EDR is a smoke alarm, MDR is a smoke alarm wired to a fire brigade that is always awake. EDR will tell you something is wrong. Whether anyone acts on that alert at 2am on a Sunday depends entirely on who is watching. That is the gap MDR closes. AMVIA's managed detection and response runs on Microsoft Defender for Endpoint, monitored by our in-house UK SOC around the clock. ## MDR vs EDR: feature comparison Both share the same detection core. The difference is everything that happens after a threat is detected - triage, investigation, response and reporting. The table below shows where standalone endpoint detection and response stops and a managed service begins. | | Capability | MDR (from £10/endpoint/month) | EDR (£3–£10/endpoint/mo) | Threat detection technology | Yes | Yes | Behavioural analysis | Yes | Yes | 24/7 human monitoring | Yes | No | Alert triage and investigation | Yes | No | Incident response | Yes | No | Threat hunting | Yes | No | Automated containment | Yes | Basic | Monthly threat reports | Yes | No | Requires in-house security staff | No | Yes *Pricing ranges are indicative for UK SMEs. Actual costs depend on endpoint count and service scope.* ## When should you choose MDR? Choose MDR if you do not have a dedicated in-house security team, need genuine 24/7 monitoring and response, want enterprise-grade protection at SME cost, or need to satisfy a cyber insurance requirement for managed detection. For the majority of UK businesses with 10–500 staff, this describes their reality. The reason is simple: detection without response is noise. EDR generates alerts continuously, and most of them need a trained analyst to separate a real intrusion from a false positive. Without that person, alerts pile up unread. Ransomware can encrypt an entire network in minutes, so the National Cyber Security Centre stresses rapid detection and response as core to limiting damage (NCSC). MDR exists precisely because most SMEs can't staff that response themselves. AMVIA pairs MDR with 24/7 security monitoring so nothing waits until Monday. ## When is standalone EDR enough? Choose EDR if you already run a security operations centre or employ a dedicated security analyst who can monitor alerts, investigate incidents and take response action around the clock. In that scenario EDR gives your team the detection tooling and they supply the expertise - you are not paying twice for monitoring you already perform. This is the right fit for larger organisations with a mature internal security function, or for businesses co-managing security alongside an in-house lead. If that is you, AMVIA's managed SOC service can layer on top of your existing EDR rather than replace it. But be honest about coverage: "we'll keep an eye on it" is not 24/7 monitoring, and attackers deliberately strike outside office hours. ## How do the costs of MDR and EDR really compare? On paper EDR looks cheaper - £3–£10 per endpoint per month versus MDR from £10 per endpoint. But the headline price ignores the analyst you need to operate EDR. Once you add salary, MDR is usually the lower total cost of ownership for an SME. For a 100-endpoint business, MDR costs approximately £800–£2,500/month. Standalone EDR costs roughly £300–£1,000/month - but to run it effectively you need a security analyst, and that role costs £45,000–£65,000/year before recruitment, training and cover for holidays. Put another way, the "cheaper" option requires hiring a full-time specialist in a market where half of UK businesses already report a skills gap (DSIT 2025). For most SMEs, MDR delivers better outcomes at a lower true cost. | | Cost factor (100 endpoints) | MDR | Standalone EDR | Software / service | £800–£2,500/month | £300–£1,000/month | Required staff | None | Analyst £45,000–£65,000/year | 24/7 cover included | Yes | No (extra headcount) | Effective total cost | Predictable monthly fee | Licence + salary + overheads ## What does AMVIA recommend? For most UK SMEs without a dedicated security analyst, we recommend MDR over standalone EDR. MDR combines EDR detection technology with 24/7 human monitoring and incident response, removing the need to hire and retain specialist staff. AMVIA's MDR starts from £10 per endpoint per month and includes threat hunting, monthly reporting and a dedicated response team. We are a security-first partner, not a box-shifter, so we will tell you plainly when standalone EDR is the better call - usually when you already have a capable internal SOC. If you don't, the maths almost always favours MDR. One provider, security-first, Microsoft-certified engineers running Microsoft Defender for Endpoint as the detection core. If you want to see how EDR compares to traditional antivirus before deciding, read our EDR vs antivirus breakdown, or review Microsoft Defender for Business as the underlying technology. ## Frequently asked questions Q: Can EDR replace MDR, or do I need both? A: EDR is a technology component; MDR is a service that includes EDR plus human expertise. If you have a dedicated in-house security analyst who can monitor alerts, investigate threats and respond around the clock, standalone EDR may suffice. For most UK SMEs without that capability, MDR provides the human layer that actually makes EDR effective. Q: Is MDR worth the extra cost over standalone EDR? A: Usually, yes. AMVIA's MDR starts from £10 per endpoint per month versus £3–£10 for EDR alone, but EDR without skilled analysts generates alerts that go unactioned. The average cost of the most disruptive breach for UK businesses is £3,550 (DSIT 2025), and 24/7 response typically stops incidents escalating to that level - making the difference easy to justify. Q: How fast does MDR respond compared to EDR alone? A: MDR providers typically aim to respond within fifteen to thirty minutes because trained analysts monitor alerts continuously. With EDR alone, response depends on when your internal team notices and investigates - which could be hours away or the next working day. For threats like ransomware that can encrypt a network within minutes, that speed difference is often the difference between a contained event and a full breach. Q: Does MDR include the EDR software, or do I buy it separately? A: Most MDR services include the EDR agent as part of the managed service, so you do not need a separate licence. AMVIA's MDR is built on Microsoft Defender for Endpoint, so businesses already on Microsoft 365 can often consolidate rather than buy a second agent. Bundled MDR removes the gap between detection and response and simplifies procurement. Q: Will MDR help with cyber insurance and compliance? A: Many UK cyber insurers now ask whether you have 24/7 managed detection and response in place before they quote or pay out. MDR supports those requirements by providing documented monitoring, investigation and incident response. It also supports good practice under frameworks promoted by the NCSC, including continuous monitoring of endpoints (NCSC, cyber threats). Q: Is AI making the MDR vs EDR decision more important? A: Yes. Attackers are using AI to scale phishing and speed up intrusion - vendor telemetry reports a 204% rise in malware campaigns (Acronis H2 2025, vendor research). Faster, higher-volume attacks reward fast human response, which is exactly what MDR adds over standalone EDR. --- # MDR vs SIEM: What's the Difference for UK Businesses? URL: https://amvia.co.uk/cybersecurity/compare/mdr-vs-siem Last updated: 2026-03 MDR vs SIEM is tool versus service. SIEM collects and correlates security logs but needs skilled analysts to run it. MDR bundles that detection technology with a 24/7 human team that investigates and responds. For most UK SMEs without a security team, MDR delivers better outcomes at lower total cost - one accountable, security-first provider. This is a buyer's guide, not a vendor pitch. If you are weighing managed detection against a log platform, the right answer usually hinges on one question: do you have the analysts to operate a SIEM around the clock? Most UK SMEs do not, which is why our managed cybersecurity practice starts almost every conversation with MDR rather than a raw SIEM deployment. ## What is the core difference between MDR and SIEM? SIEM (Security Information and Event Management) is a platform that ingests logs from across your estate and correlates them to surface alerts. MDR (Managed Detection and Response) is a service that includes the detection technology *and* a human team to investigate and act. SIEM hands you alerts; MDR hands you outcomes. Put simply, a SIEM is a sophisticated smoke detector - it tells you something is burning, but someone still has to grab the extinguisher. MDR is the smoke detector plus the on-call fire crew. The National Cyber Security Centre is clear that detection without a tested response capability leaves organisations exposed, because the damage happens in the minutes and hours after an alert fires, not at the moment of the alert itself. - SIEM = a tool you operate. You write the detection rules, tune the alerts, and run the investigations. - MDR = a service you subscribe to. The provider runs the platform, the analysts, and the response. - Overlap = both detect threats and correlate log data. The difference is who does the work after detection. ## How do MDR and SIEM compare feature by feature? Feature-for-feature, SIEM gives you raw capability and total control; MDR gives you a finished outcome. The table below maps the practical differences a UK SME actually feels - staffing, response, and total cost - rather than a tick-box specification sheet. | | Feature | MDR from £10/endpoint | SIEM £5,000–£50,000+/year | Threat detection | Yes | Yes | Log collection and correlation | Included | Yes | 24/7 human monitoring | Yes | No (you staff it) | Incident response | Yes | No (you respond) | Requires security analysts to operate | No | Yes | Total cost for a 100-person business | £800–£2,500/mo | £6,000–£12,000/mo platform + staff The decisive rows are the last three. A SIEM with no analysts behind it is a cost centre that generates alerts nobody triages. That is the most common failure mode we are called in to fix - a business bought the platform, never resourced the people, and the alerts pile up unread. Our managed detection and response service exists precisely to close that gap. ## When should a UK business choose MDR? Choose MDR when you need real detection and response but cannot justify hiring and rota-ing security analysts. It gives you the complete service - detection, investigation, and containment - for a per-endpoint fee, with no platform to babysit. For the vast majority of 10–500 staff businesses, this is the pragmatic choice. This matters because the threat picture is unforgiving for smaller firms. 43% of UK businesses identified a cyber breach or attack in the last year (DSIT Cyber Security Breaches Survey 2025), and 85% of those breaches involved phishing (DSIT 2025). Microsoft reports that 99.9% of compromised accounts had not enabled multi-factor authentication (Microsoft Security) - a reminder that the basics matter, and that someone needs to be watching when they fail. MDR puts that someone on the rota for you. Pick MDR if any of these are true: - You have no in-house security operations team, or fewer than three analysts. - 49% of UK businesses report a basic cyber security skills gap (DSIT 2025) - and you are one of them. - You need a response capability now, not a six-month platform build-out. - You want a single accountable provider rather than a stack of tools to integrate. ## When does a SIEM still make sense? A standalone SIEM earns its place when you already have a staffed security operations team, face specific regulatory log-retention requirements, or need deep forensic correlation across diverse, custom data sources. It is a genuinely powerful tool - but only in the hands of analysts who can write rules, tune alerts, and investigate findings around the clock. If you run a mature SOC with three or more analysts on rotation, a SIEM gives you customisation and data ownership that a packaged MDR service will not. Many larger organisations run both: MDR (or an in-house team) for response, and SIEM underneath as a log aggregation and long-term retention layer. For an SME building from zero, though, that is the wrong order. Start with the managed SOC service outcome first, then add SIEM tooling later if compliance or scale demands it. Our SIEM for SMEs guidance walks through exactly when that crossover happens. ## What does each option really cost a UK SME? On paper a SIEM licence can look cheaper than a managed service - until you cost the people. A SIEM platform plus one or more analysts at £45,000–£65,000 each (typical UK 2026 salary range) typically lands between £80,000 and £120,000 a year for an SME running it properly. Equivalent MDR coverage runs roughly £10,000–£30,000 a year (market rates as of 2026). The hidden cost of SIEM is not the licence; it is the salary, the recruitment, the cover for holidays and sickness, and the 24/7 rota you need so alerts do not sit unread overnight. The average cost of the most disruptive breach for affected UK businesses was £3,550 (DSIT 2025) - and that figure climbs fast when no one is watching out of hours. MDR converts an unpredictable staffing problem into a predictable per-endpoint line item, monitored by AMVIA's in-house 24/7 SOC using Microsoft Defender as the detection engine. ## The AMVIA recommendation For UK SMEs without a dedicated security operations team, MDR is the right call over a standalone SIEM. MDR delivers the monitoring and response outcomes that SIEM only promises - outcomes that, in a SIEM world, depend entirely on in-house expertise you would have to hire and retain. Larger organisations with an existing SOC can absolutely benefit from SIEM as a correlation and retention layer. But the sequence matters: get the response capability in place first, then add tooling. Buying a SIEM before you have analysts is buying a smoke detector and firing the fire brigade. One provider, security-first, Microsoft-certified - that is how we deploy 24/7 security monitoring for businesses that need cover without a headcount. ## Frequently asked questions Q: Can MDR replace SIEM entirely for a UK SME? A: For most SMEs, yes. MDR providers use their own log correlation and threat-intelligence platforms, so you rarely need a separate SIEM investment. MDR delivers the detection *and* the response that SIEM only promises. With 43% of UK businesses experiencing a breach or attack (DSIT 2025), the priority for a smaller firm should be effective response capability - which MDR provides out of the box. Q: Why is SIEM so expensive compared to MDR for small businesses? A: SIEM is a platform, not a service. It requires skilled analysts to write detection rules, tune alerts, and investigate findings. A SIEM licence alone can cost £5,000 to £50,000 a year (typical UK 2026 range), and staffing analysts adds £45,000 to £65,000 per person annually. MDR bundles the technology and the expertise into a single per-endpoint fee, typically £10,000 to £30,000 a year in total for an SME. Q: Does MDR include log collection and correlation like SIEM? A: Yes. MDR collects telemetry from endpoints, cloud services, and identity platforms, then correlates that data to identify threats - the same core function as a SIEM. The difference is that MDR also acts on what it finds: triaging alerts, investigating anomalies, and containing threats. SIEM stops at detection and alerting, leaving your team to handle the response. Q: When should a business choose SIEM over MDR? A: Choose SIEM when you already have a staffed security operations team, must meet specific regulatory log-retention requirements, or need deep forensic analysis across diverse data sources. With three or more analysts operating it around the clock, a SIEM gives you powerful customisation. Without that team, MDR delivers superior outcomes at a fraction of the total cost. Q: Is SIEM or MDR better for Cyber Essentials and compliance? A: Neither is a compliance product on its own, but MDR makes compliance easier to evidence because the monitoring and response are documented for you. AMVIA holds Cyber Essentials Plus and supports clients working toward GDPR and sector requirements. For log-retention mandates specifically, a SIEM layer may be required - your provider should map controls to the NCSC guidance and the standard you are pursuing. Q: Do I need both MDR and SIEM? A: Sometimes. Larger organisations often run MDR (or an in-house team) for response and a SIEM underneath for aggregation and long-term retention. For most SMEs that is overkill at the start. Begin with MDR to get a working response capability, then add SIEM tooling only when compliance or scale genuinely demands it. --- # EDR vs Antivirus: Why Traditional Antivirus Is No Longer Enough URL: https://amvia.co.uk/cybersecurity/compare/edr-vs-antivirus Last updated: 2026-03 Antivirus detects known malware by matching it against a signature database. EDR (Endpoint Detection and Response) watches how every endpoint behaves in real time, catching zero-day exploits, fileless attacks and living-off-the-land techniques that signatures never see. For most UK businesses today, antivirus alone is no longer enough - and AMVIA's managed cybersecurity practice treats EDR as the new baseline. The short version: antivirus answers "have I seen this exact file before?" EDR answers "is anything on this machine behaving like an attack right now?" The first question is easy for criminals to dodge. The second is much harder. ## What is the difference between EDR and antivirus? Antivirus is a known-threat blocker. It compares files against a database of malware signatures and quarantines anything that matches. EDR is a detection-and-response platform: it continuously records endpoint activity, flags suspicious behaviour, and gives you the tools to investigate and contain an incident - not just block a file. Traditional antivirus works well against commodity malware that already has a published signature. The problem is that modern attacks are built specifically to have no signature. Attackers use legitimate Windows tools like PowerShell, WMI and PsExec to operate "off the land," so there is no malicious file for antivirus to scan in the first place. EDR closes that gap by modelling behaviour. If a finance laptop suddenly starts enumerating the network, dumping credentials, or encrypting files at speed, EDR sees the pattern and acts - even though no single file is flagged as malware. That behavioural visibility is also what lets a SOC analyst reconstruct exactly what happened after the fact. ## How do EDR and antivirus compare feature by feature? EDR includes everything antivirus does and adds the capabilities that matter against modern attacks: behavioural analysis, fileless-attack detection, investigation tooling and automated response. Antivirus stops at signature matching and basic quarantine. The table below maps the two side by side, with typical UK market pricing per endpoint. | | Feature | EDR (£3–£10/endpoint/mo) | Antivirus (£1–£4/endpoint/mo) | Signature-based detection | Yes | Yes | Behavioural analysis | Yes | No | Fileless attack detection | Yes | No | Zero-day protection | Yes | No | Investigation / forensic tools | Yes | No | Automated response | Yes | Basic quarantine only | Threat-hunting capability | Yes | No | Real-time endpoint visibility | Yes | Limited The price ranges above (EDR £3–£10/endpoint/mo, antivirus £1–£4/endpoint/mo) are typical UK market rates, not a quote. The gap - roughly £2–£6 per endpoint per month - buys you the entire right-hand column. ## Why isn't antivirus enough on its own anymore? Antivirus alone is insufficient because the majority of damaging attacks now arrive through people and behaviour, not recognisable malware files. Phishing, credential theft and hands-on-keyboard intrusion all sail past signature scanners. The UK breach data makes the scale of this hard to argue with. According to the UK government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the attack type (DSIT, 2025). Phishing is how attackers get a foothold; antivirus rarely sees the follow-on activity once a user has handed over a password or run a malicious script. The 2025/26 edition found that 65% of medium-sized businesses reported a cybersecurity breach or attack in the past year, and that an estimated 612,000 UK businesses were affected by cyber breaches over the period (DSIT, 2025). The average cost of the most disruptive breach was £3,550 for businesses overall (DSIT, 2025) - and far higher once you include downtime, recovery and lost trust. Identity is the other open door. Microsoft reports that 99.9% of compromised accounts in its data had not enabled multi-factor authentication (Microsoft). Antivirus does nothing about an attacker who simply logs in with stolen credentials - but EDR feeding a monitored SOC will catch what they do next. The National Cyber Security Centre makes the same point in its small-business guidance: layered detection beats any single control. ## When should you choose EDR over antivirus? Choose EDR if your business holds sensitive data, has compliance obligations, uses cloud services, supports remote or hybrid workers, or has ever been targeted by phishing. In practice that describes almost every UK SME. Antivirus is only defensible for a fully isolated, low-risk device that touches nothing important. - Choose EDR if you want genuine protection against modern threats - especially with remote workers, sensitive client data, or Cyber Essentials / GDPR obligations. - Antivirus alone is risky if you handle personal or financial data, use Microsoft 365, support staff working from home, or operate in a regulated sector. - The cost-benefit is clear. For a 50-endpoint business, upgrading from antivirus to EDR costs roughly £100–£300 per month extra. A single ransomware incident that antivirus missed will cost many multiples of that - the £3,550 average disruptive-breach figure is a floor, not a ceiling. This is where AMVIA's endpoint detection and response service sits: EDR deployed, tuned and watched, not just installed and forgotten. ## Should you upgrade to EDR, or go straight to MDR? If you have the in-house security skills to triage alerts at 2am, EDR may be enough. If you don't - and most SMEs don't - MDR (Managed Detection and Response) is the better answer, because it wraps EDR in a 24/7 human SOC. EDR generates the signal; MDR makes sure someone acts on it. The trap with EDR is that it produces alerts you still have to investigate. A platform that flags a credential-dumping attempt at 3am is only useful if a person responds before the attacker spreads. That is why AMVIA pairs EDR with managed detection and response and round-the-clock 24/7 security monitoring from our in-house SOC. For the fuller breakdown of where detection tooling ends and managed response begins, see our MDR vs EDR comparison. ## What does AMVIA recommend? Replace traditional antivirus with EDR - and ideally with MDR, which adds 24/7 human monitoring on top. The good news for most UK SMEs is that you may already own enterprise-grade EDR without realising it. Microsoft Defender for Business is included in Microsoft 365 Business Premium (£16.90/user/mo ex VAT, Microsoft) and delivers EDR-level endpoint protection at no extra licence cost. AMVIA deploys, hardens and monitors Defender so that capability actually translates into protection. If you are not on Business Premium, AMVIA can deploy a dedicated EDR solution starting from £3 per endpoint per month - built on Microsoft Defender, monitored by our own UK SOC. One provider, security-first, Microsoft-certified: that is how we keep endpoint security simple to own and hard to beat. ## Frequently asked questions Q: What threats can EDR detect that antivirus cannot? A: EDR detects fileless attacks, living-off-the-land techniques, zero-day exploits and behavioural anomalies that signature-based antivirus misses entirely. Modern attacks increasingly abuse legitimate tools like PowerShell to avoid triggering signatures. With 85% of breached businesses identifying phishing as the attack type (DSIT, 2025), EDR's ability to spot post-compromise activity is essential. Q: Is the cost difference between EDR and antivirus justified for a small business? A: Yes. EDR costs roughly £3–£10 per endpoint per month versus £1–£4 for antivirus - an extra £2–£6 per device. For a 30-endpoint business that is about £60–£180 per month. Given the average most-disruptive breach costs £3,550 (DSIT, 2025), the upgrade pays for itself if it prevents a single incident a year. Q: Can I run EDR alongside my existing antivirus, or do I need to replace it? A: EDR usually replaces antivirus rather than running beside it. Most EDR platforms include signature-based detection as a baseline, so you keep antivirus capability while gaining behavioural analysis and investigation tools. Running two separate agents at once tends to cause conflicts, higher resource use and duplicate alerts on the same endpoint. Q: Do I need EDR if Windows already includes Microsoft Defender? A: The built-in Windows Defender antivirus gives you basic protection, but upgrading to Microsoft Defender for Business - included in Microsoft 365 Business Premium - adds full EDR capability, including behavioural detection and automated response. For organisations not on Business Premium, a standalone EDR solution delivers comparable protection. The key is having it monitored, not just enabled. Q: Does EDR replace the need for a SOC or MDR service? A: No. EDR is the sensor; it produces alerts that still need a human to investigate and contain. Without 24/7 monitoring, a 3am detection often goes unanswered until morning - long enough for ransomware to spread. MDR combines EDR with a round-the-clock SOC, which is why AMVIA recommends managed monitoring for any business without an in-house security team. Q: Will EDR help with Cyber Essentials or cyber insurance requirements? A: Increasingly, yes. Insurers and security frameworks now expect more than basic antivirus, and behavioural endpoint protection is becoming a baseline expectation for cover and for demonstrating due diligence. EDR also gives you the forensic record needed to evidence what happened during an incident - useful for both insurers and regulators such as the ICO. --- # In-House Security Team vs MSSP: Costs Benefits and Trade-Offs URL: https://amvia.co.uk/cybersecurity/compare/mssp-vs-in-house-security Last updated: 2026-03 For most UK SMEs under 500 staff, an MSSP beats building an in-house security team. An MSSP delivers 24/7 monitoring, detection and response for a predictable per-user fee, while an in-house team only becomes cost-effective at enterprise scale. AMVIA runs this for UK businesses - one provider, security-first, Microsoft-certified. This is a genuine trade-off, not a sales pitch. An in-house team gives you deep knowledge of your own systems and total control. A Managed Security Service Provider (MSSP) gives you round-the-clock coverage, broader threat experience, and a fixed cost. The right answer depends on your size, your budget, and how much risk you carry. Below we lay out the numbers, the trade-offs, and where each model genuinely wins - then link you to AMVIA's managed cybersecurity so you can see what an outsourced model actually covers. ## What is the difference between an MSSP and an in-house security team? An MSSP is an external provider that monitors, detects, and responds to threats across your environment for a contracted fee. An in-house security team does the same work using your own employees. The split is operational versus structural: an MSSP buys you a running capability today, an in-house team builds one you own and manage yourself. The hard part of security is not buying tools - it is staffing them around the clock. Threats do not keep office hours. The UK government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach in 2025 (DSIT), and 85% of businesses that experienced a breach identified phishing as the vector (DSIT 2025). Detecting that phishing-led intrusion at 2am is where the two models diverge most sharply. - MSSP: shared 24/7 SOC, multi-client threat visibility, fixed monthly cost, fast to deploy. - In-house: dedicated to your business, full strategic control, but you carry recruitment, shift cover, tooling, and retention. ## How much does an in-house security team cost versus an MSSP? Cost is the clearest dividing line. Building a minimal in-house security operations capability requires three to five analysts on rotating shifts, costing £150,000 to £325,000 per year in salaries alone (typical UK 2026 range) - before tooling, training, and recruitment costs. An MSSP delivers equivalent 24/7 monitoring and response for £10,000 to £50,000 per year (market rates as of 2026), depending on scope. The salary figure is only the visible cost. A real in-house Security Operations Centre also needs SIEM licensing, endpoint tooling, threat intelligence feeds, holiday and sickness cover for 24/7 shifts, and ongoing certification to stop your analysts going stale. The hidden recruitment problem is just as real: skilled SOC analysts are scarce and expensive to retain. | | Cost factor | In-house security team | MSSP | Staffing | £150,000–£325,000/yr salaries (3–5 analysts) | Included in fee | Tooling and licensing | Bought and managed by you | Included / pooled across clients | 24/7 shift cover | You fund nights, weekends, holidays | Built in | Time to operational | Months (hire, train, tune) | Days to weeks | Typical annual cost | £150,000+ all-in | £10,000–£50,000 | Threat visibility | Your environment only | Hundreds of environments For a deeper breakdown, see our guide on how much managed cybersecurity costs. ## Can an MSSP respond to threats as effectively as an in-house team that knows your business? Yes, and often more effectively. MSSPs handle hundreds of clients and see a broader range of attack patterns, giving their analysts experience that a small in-house team cannot replicate. That volume matters most against the fastest-moving threats - phishing and social engineering - where pattern recognition is the whole game. The threat landscape now rewards scale of experience. Reported figures suggest 82.6% of phishing emails now use AI-generated content (KnowBe4, vendor research) and a 204% rise in malware campaigns (Acronis H2 2025, vendor research). An MSSP analyst who has triaged thousands of these across many clients spots the novel variant faster than an in-house generalist seeing their first. What an MSSP buys you operationally: - Managed detection and response - analysts who investigate and contain, not just alert. - A 24/7 SOC - the managed SOC service covers the nights and weekends an in-house rota struggles to staff. - Continuous 24/7 security monitoring across endpoints, email, and identity. The National Cyber Security Centre's guidance on logging and protective monitoring makes clear that detection only works if someone is watching the logs in real time - which is exactly the gap an MSSP fills. ## Does using an MSSP mean you lose control over your security strategy? No. An MSSP handles operational security - monitoring, detection, and response - while your business retains strategic oversight. You set the policies, the risk appetite, and the compliance objectives. The MSSP executes against them and reports back; it does not decide your strategy for you. Think of it as a division of labour, not a handover. You own the "what" and the "why": which data matters most, what your regulators require, how much downtime you can tolerate. The MSSP owns the "how" and the "when": the 24/7 watch, the triage, the containment. Good MSSPs make this explicit in the contract with defined response times and escalation paths back to you. ## At what business size does building an in-house security team become viable? Most organisations find that an in-house security team only becomes cost-effective above 500 to 1,000 employees, where the security budget can sustain dedicated analysts, tooling, and continuous training. Below that threshold, the economics rarely work - and the recruitment market makes it harder still. For a 50-person firm, one full-time security hire cannot provide 24/7 cover, so you are exposed every night and weekend. For a 5,000-person enterprise, a full SOC team is justified and the per-head cost falls. The crossover sits roughly where your headcount can fund a five-person rota without that team dominating your IT budget. Below it, the average cost of the most disruptive breach at £3,550 (DSIT 2025) and the difficulty of recruiting specialist talent make an MSSP the more practical and affordable choice. If you are weighing tooling-level choices too, our MDR vs EDR comparison explains what "response" actually means. ## The AMVIA recommendation For UK SMEs under 500 employees, an MSSP is the right choice over in-house security. Building genuine 24/7 detection and response capability in-house requires specialist staff, expensive tooling, and shift patterns - costs viable only at enterprise scale. AMVIA's managed security delivers MDR, threat intelligence, and compliance support via a predictable per-user fee. We are a security partner, not a reseller bolting monitoring onto a phone contract. AMVIA serves 1,200+ UK businesses with an in-house 24/7 SOC built on Microsoft Defender and the Barracuda suite, holds Cyber Essentials Plus, and is a Microsoft Solutions Partner. One provider. Security-first. Microsoft-certified. ## Frequently asked questions Q: How much does an in-house security team cost compared to an MSSP? A: Building a minimal in-house security operations capability requires three to five analysts on rotating shifts, costing £150,000 to £325,000 per year in salaries alone (typical UK 2026 range) - before tooling, training, and recruitment costs. An MSSP delivers equivalent 24/7 monitoring and response for £10,000 to £50,000 per year (market rates as of 2026), depending on scope. Q: Can an MSSP respond to threats as effectively as an in-house team that knows our business? A: Yes, and often more effectively. MSSPs handle hundreds of clients and see a broader range of attack patterns, giving their analysts experience a small in-house team cannot replicate. With 85% of businesses that experienced a breach identifying phishing as the vector (DSIT 2025), an MSSP's volume of phishing investigations is a genuine advantage. Q: Does using an MSSP mean we lose control over our security strategy? A: No. An MSSP handles operational security - monitoring, detection, and response - while your business retains strategic oversight. You set the policies, the risk appetite, and the compliance objectives, and the provider executes against them with defined response times and escalation back to your team. Q: At what business size does building an in-house security team become viable over an MSSP? A: Most organisations find an in-house security team only becomes cost-effective above 500 to 1,000 employees, where the budget can sustain dedicated analysts, tooling, and continuous training. Below that threshold, the cost of breaches and the difficulty of recruiting specialist talent make an MSSP the more practical and affordable choice. Q: What does an MSSP actually do day to day? A: An MSSP continuously monitors your endpoints, email, and identity systems, investigates alerts, and contains confirmed threats - typically through a 24/7 SOC. It also tunes your detection rules, reports on incidents, and supports compliance objectives. The work is operational and ongoing, not a one-off audit. Q: Can we combine an MSSP with our existing IT team? A: Yes. Most UK SMEs run a hybrid model: their internal IT team handles day-to-day systems while the MSSP owns 24/7 detection and response. This is common and effective - your team keeps context on the business, the MSSP supplies the round-the-clock security watch and specialist analysts. --- # IT Support, Connectivity & Cybersecurity for UK Manufacturing URL: https://amvia.co.uk/cybersecurity/industries/manufacturing Last updated: 2026-07 Managed IT support for manufacturing is the outsourced running and securing of a manufacturer's office IT and its operational technology (OT) - the PLCs, SCADA and control systems that drive production. AMVIA secures and monitors both environments, segments the factory floor from corporate IT, and keeps the line moving. One provider. Security-first. Microsoft-certified. Manufacturers carry a risk profile no other sector quite matches: legacy machinery that cannot be patched on demand, production systems now wired to ERP and the internet, and customers who increasingly demand proof of security before they place an order. Our managed IT support for manufacturing is built around that reality - protection that respects the maintenance window. ## What does managed IT support for manufacturing cover? It covers the whole estate: office workstations and servers, cloud and ERP platforms, and the operational technology on the production floor. The goal is one accountable provider keeping IT secure, available and supported - without the changes that risk halting a line. - OT/IT network segmentation - production systems on a separate, firewalled segment so an office infection cannot reach machine controllers. - Production system backup and recovery - immutable, offsite backups of ERP, production configuration and business data, with tested restores. - 24/7 threat monitoring - continuous watch over network and endpoint activity, tuned for manufacturing, via Microsoft Defender for Endpoint monitored by AMVIA's in-house SOC. - Cyber Essentials for supply chain - certification support to meet customer and prime-contractor requirements. - ERP and Microsoft 365 security - MFA, Conditional Access and data-loss prevention protecting commercially sensitive production data. - Resilient connectivity - dedicated leased lines for factories that depend on reliable, high-throughput links to cloud and remote sites. ## Why is manufacturing the most targeted UK sector for ransomware? Attackers chase leverage, and few targets feel pressure faster than a manufacturer with a stopped line. Production downtime converts directly into lost revenue and broken delivery commitments, so the temptation to pay a ransom is acute. Manufacturing is now the most targeted UK sector for ransomware. The picture is stark: every hour of stopped production carries a heavy cost. The wider picture is documented in the government's Cyber Security Breaches Survey, which tracks attack rates across UK businesses each year. Three factors make manufacturers stand out: legacy systems with limited patching, complex supply-chain connections that create entry points, and valuable intellectual property. ## How does OT/IT convergence change manufacturing security? OT/IT convergence is the merging of operational technology (PLCs, SCADA, industrial control systems) with corporate IT networks. Traditional factory security treated OT as isolated; that separation no longer holds when production systems connect to ERP platforms, supplier portals and remote monitoring. The result is an attack surface neither standard IT tools nor legacy OT tools fully cover. The practical risk is lateral movement - ransomware landing on an office laptop, then reaching the controllers that run the line. The NCSC's guidance on operational technology makes network segmentation the primary control: keep OT and IT on separate segments, monitor and restrict the traffic between them, and treat any path into the production network as privileged. AMVIA assesses the full environment - from office workstations to floor controllers - prioritising availability alongside protection. ## How do you secure production systems without disrupting operations? Carefully, and passively. Securing OT means visibility and containment first: passive network monitoring rather than active scans of sensitive ICS devices, vulnerability assessment that does not probe fragile controllers, and change-controlled patching aligned to maintenance windows. AMVIA works around production schedules, not against them. The sequence we follow is segmentation and monitoring before any change that could affect uptime. Remote access to production gear runs through MFA-protected, dedicated access - never a general-purpose VPN. This is where security and managed cybersecurity meet operations: the controls have to protect the plant without ever being the reason it stops. ## In-house IT vs managed IT for manufacturers A single in-house technician rarely covers OT security, 24/7 monitoring and ERP hardening at once. Managed IT spreads that load across a certified team with round-the-clock cover - the difference between best-effort and accountable. | | Capability | Typical in-house setup | AMVIA managed IT | OT/IT segmentation | Often flat network | Designed, firewalled, monitored | Threat monitoring | Office hours, reactive | 24/7 SOC, Microsoft Defender | ERP & M365 security | Basic passwords | MFA, Conditional Access, DLP | Backup & recovery | Backups, rarely tested | Immutable, offsite, restore-tested | Cyber Essentials | DIY, if at all | Certification managed end to end | Cover during sickness/holiday | Single point of failure | Team-based, no gaps For a deeper comparison of the security side, see our managed detection and response service and our core managed IT support service. ## Manufacturing cybersecurity checklist These are the controls we check first on a manufacturing site, aligned to NCSC operational-technology guidance and common supply-chain requirements. - OT and IT networks segmented - production systems on a separate, firewalled segment; OT/IT traffic monitored and controlled. - Remote OT access secured - any remote access to production via MFA-protected, dedicated solutions, not a general VPN. - Asset inventory complete - every IP-connected device, including OT/ICS equipment, in an asset register. Undiscovered devices are unprotected devices. - ERP and business backups tested - regular restore testing for ERP, production databases and configuration; recovery time objectives validated. - Supply-chain requirements met - Cyber Essentials or CE+ in place where customers, primes or frameworks require it. - Patch management applied - office IT patched within 14 days; OT patching assessed for compatibility and scheduled to maintenance windows. ## How much does managed IT support for manufacturing cost? Cost depends on staff numbers, the size of the OT estate, and whether you need full management or co-management of an existing team. Most manufacturers price it per user per month, with OT monitoring and connectivity scoped separately after a site assessment. A single day of unplanned outage after a cyber attack can exceed the annual cost of managed security, which is why manufacturers tend to weigh the spend against downtime risk rather than headcount alone. We scope pricing against your actual environment - no generic per-seat quote before we have seen the floor. ## Frequently asked questions Q: What's different about IT support for manufacturers? A: The OT estate - PLCs, SCADA and control systems that run production. They can't be patched or rebooted like office laptops, often run old software by necessity, and downtime is measured in lost production, not inconvenience. Support has to treat OT and IT as one connected risk, managed differently. Q: How do we protect production systems from ransomware? A: Segmentation first: production networks separated from office IT so a phished laptop can't reach the line. Then monitoring that watches the boundary, controlled remote access for maintenance vendors, and a recovery plan tested against the question that matters - how fast can the line restart? Q: Can old machines running legacy software be secured? A: Usually, yes - not by patching them (often impossible) but by isolating them: network segmentation, strict access control, and monitoring the traffic around them. The machine stays useful; its blast radius stops being the whole factory. Q: What connectivity does a manufacturing site need? A: Resilient, not just fast: production data, warehouse systems and VoIP justify uncontended connectivity with an SLA, and a failover path so a single circuit fault never idles the line. AMVIA runs connectivity and security as one design - see our multi-site and leased-line services. --- # IT Support, Connectivity & Cybersecurity for UK Construction URL: https://amvia.co.uk/cybersecurity/industries/construction Last updated: 2026-07 Construction firms need IT that works where the work is: site connectivity (temporary circuits, bonded broadband and 4G/5G options), managed business mobiles for a workforce that lives on its phones, protection against the invoice fraud that targets big irregular payment runs, and hardened Microsoft 365 for BIM and project platforms. AMVIA delivers the full stack as one accountable provider - managed IT from £25/user/month, dedicated leased lines from £69/month - built around how construction actually operates. ## Why do construction firms get targeted by cyber criminals? Construction is now a digital business - BIM models, cloud project management, connected site kit and large supplier payment runs - and that broad attack surface is exactly what criminals exploit. Phishing and business email compromise hit firms that move big invoices between many parties, where one redirected payment can fund an entire fraud. The numbers below come from the government's Cyber Security Breaches Survey and named third-party reports. | | Cyber risk - key figure (UK-wide baseline) | Source | 43% of UK businesses identified a breach or attack in the past 12 months | DSIT Cyber Security Breaches Survey 2025 | £3.29M average UK data breach cost | IBM Cost of a Data Breach 2025 | 85% of businesses that identified a breach reported phishing | DSIT 2025 | Only 47% of UK businesses have two-factor authentication in place | DSIT 2025/26 | £990 (£1,970 excluding phishing-only cases) average annual cybercrime cost for affected businesses | DSIT 2025 | 75% of UK businesses lack a formal incident response plan | DSIT 2025/26 The National Cyber Security Centre confirms that phishing remains the most common route into a UK small or medium business, which is why email is the first place construction firms should harden (NCSC small business guide). ## How does AMVIA protect construction businesses? AMVIA wraps a construction firm in a single, security-first stack: Microsoft Defender on every endpoint, Barracuda email and network protection, and round-the-clock monitoring from our in-house UK SOC. You get one provider accountable for detection, response and Microsoft 365 hardening - not a patchwork of resellers. - Managed detection and response: 24/7 monitoring of endpoints, email and cloud, with our SOC investigating and containing threats. - Email security and anti-phishing: Barracuda filtering to stop phishing and business email compromise before invoices get redirected. - Endpoint and mobile security: Microsoft Defender protection for site laptops, tablets and phones, with encryption and remote wipe. - Cloud and Microsoft 365 security: secure configuration, conditional access and MFA across your tenant. - Phishing simulation and training: realistic simulations tuned to construction teams and finance staff. AMVIA holds Cyber Essentials Plus, the UK government-backed standard that independently tests your defences against common internet threats (gov.uk Cyber Essentials). ## In-house vs managed security for construction firms Most construction firms do not have a 24/7 security team, and site work happens long after a 9-to-5 IT desk has gone home. Managed security gives you enterprise-grade detection and a named provider to call during an incident, for a predictable monthly cost rather than the salary bill of an internal security team. | | Capability | In-house IT only | AMVIA managed security | 24/7 monitoring | Rare - office hours only | Always on, UK SOC | Threat detection and response | Manual, reactive | Microsoft Defender + analyst-led | Email / invoice fraud defence | Basic spam filter | Barracuda anti-BEC filtering | Incident response plan | Often absent | Documented and tested | Cost model | Salaries + tooling | Predictable monthly fee ## What's your construction cybersecurity checklist? Use this as a baseline. If you cannot tick every box, those are the gaps an attacker is most likely to find first. AMVIA's incident response team can close them and rehearse your response before a real attack tests it. - Multi-factor authentication on all email and project management accounts - Endpoint protection on every device, including site laptops and tablets - Email filtering with anti-phishing and business email compromise detection - Regular security awareness training for all staff - An incident response plan tested at least annually - Secure backup of project data with offline copies - A supplier and subcontractor security assessment process Construction firms in heavy manufacturing supply chains should also read our manufacturing cybersecurity guidance, as the threats overlap heavily. ## Beyond security: the full IT stack for construction firms Security protects the money; connectivity and mobiles are what the business actually runs on day to day - and in construction they have to move with the work. Buying them from separate suppliers means separate contracts, separate helpdesks and nobody accountable when a site can't get online the week the project starts. AMVIA runs the whole estate under one SLA with a <1hr critical response commitment. ## Connectivity that follows the work Head offices and depots run on dedicated leased lines from £69/month or full-fibre business broadband. Sites are different: a temporary office needs internet in days, not the weeks a fixed installation takes, which is where bonded broadband and 4G/5G-based options earn their keep - live fast, then superseded or backed up by a fixed line where the project duration justifies it. Designed together, the whole estate stays on one managed platform instead of a per-site scramble. ## A mobile-first workforce, managed Construction is the sector where business mobiles are the primary endpoint: pricing, procurement, device management, encryption and remote wipe for a fleet that lives in vans and site cabins. Managing mobiles and security together closes the gap attackers use - an unmanaged site phone with company email is an open door however hard the office is locked down. ## Phones and support under the same roof The PSTN switch-off on 31 January 2027 retires the analogue lines many site offices and older premises still use. AMVIA's business VoIP runs from £5.95/user/month and follows the team wherever the job is, while managed IT support at £25–£60/user/month puts helpdesk, patching and backups with the same team that monitors your security. One provider, one SLA - and one number to call from site. ## Frequently asked questions Q: Why is construction such a target for cyber attacks? A: Money moves in big, irregular payments between many parties - exactly what invoice fraud exploits - while project deadlines make firms more likely to pay ransoms. Add site staff on mobiles, shared project platforms and BIM data, and the attack surface is wider than most head offices assume. Q: What is invoice fraud and how do we stop it? A: A criminal impersonates a subcontractor or supplier - often from a genuinely compromised email account - and changes the bank details on a real invoice. Defences are layered: email security that catches impersonation, MFA so accounts are harder to hijack, and a payment process that verifies bank-detail changes by phone, every time. Q: How do we secure site staff and their devices? A: Treat phones and tablets as first-class endpoints: mobile device management enforcing encryption and PINs, work data separated from personal, remote wipe for the devices that inevitably go missing from vans and site cabins. The site is part of the network whether you manage it or not. Q: Do construction firms need security credentials to win bigger contracts? A: Increasingly, yes - main contractors and public-sector clients now ask for security credentials in prequalification, and Cyber Essentials appears in a growing share of tender requirements. Certification protects revenue as much as systems; AMVIA prepares construction firms for exactly that. Q: How do we get connectivity onto a new construction site quickly? A: Plan it like plant hire: order early and layer the options. A fixed circuit for a long-running site takes weeks to install, so temporary site offices typically start on bonded broadband or 4G/5G-based connectivity - live in days - with a fixed line following where the project duration justifies it. AMVIA scopes site connectivity alongside your head-office circuits so every cabin, depot and office sits on one managed estate. Q: Can AMVIA handle our mobiles, phones and IT support as well as security? A: Yes - for construction that's the point. Site crews live on mobiles, offices need phones that survive the PSTN switch-off on 31 January 2027, and someone has to support all of it. AMVIA runs business mobile fleets with device management, VoIP from £5.95/user/month, site and office connectivity, and managed IT support from £25/user/month - one provider, one SLA, one number whichever part breaks. --- # IT Support, Connectivity & Cybersecurity for Accountants URL: https://amvia.co.uk/cybersecurity/industries/accountancy Last updated: 2026-07 Accountancy practices need IT that protects client financial data and keeps cloud accounting running: managed cybersecurity (email defence, MFA, threat monitoring), hardened Microsoft 365, reliable business connectivity, VoIP and responsive IT support. AMVIA delivers the full stack as one accountable provider with one SLA - managed IT from £25/user/month, dedicated leased lines from £69/month - built around UK GDPR, ICO and HMRC Agent Services obligations. A breach in an accountancy practice is not one incident. It is dozens or hundreds of incidents at once, because every client whose payroll, bank details and returns you hold is exposed in the same event. That is why we treat practice security as a parent managed cybersecurity discipline, not a bolt-on. The UK Government's Cyber Security Breaches Survey 2025 confirms professional services remain a high-frequency target for phishing and impersonation. ## What is accountancy cybersecurity? Accountancy cybersecurity is the set of technical and procedural controls that protect a practice's client financial data across email, cloud accounting and devices. It covers phishing defence, account protection, encryption, monitoring and breach response - mapped to the data-protection duties accountants carry as controllers under UK GDPR. Accountancy practices are trusted custodians of payroll data, tax returns, bank details and financial records for many clients at once. The Information Commissioner's Office expects controllers to apply "appropriate technical and organisational measures" - encryption, access control, MFA and breach notification. AMVIA builds programmes specifically around cloud accounting software, email and client portals. ## Why do UK accountancy firms need specialist cybersecurity? Accountants are targeted precisely because of the money and authority they hold over client payments and payroll. The reputational damage compounds the financial damage - and the average data breach costs a UK business £3.29M (IBM Cost of a Data Breach 2025). - 43% of UK businesses identified a cyber breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025) - 85% of businesses that identified a breach reported phishing (DSIT 2025) - £3,550 average cost of the most disruptive breach, excluding nil-cost responses (DSIT 2025) - Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26) These are not abstract risks. A single compromised mailbox can expose every client a partner corresponds with, which is why email security and phishing protection sit at the centre of every accountancy programme we run. The NCSC ranks phishing as the most common attack route for UK small organisations. ## How does AMVIA protect accountancy practices? AMVIA wraps your email, cloud accounting and devices in a single managed service: Microsoft Defender for Endpoint monitored by our in-house 24/7 SOC, Barracuda email protection against phishing and business email compromise, and hardened configuration of the platforms accountants live in. One provider owns the whole picture. - Managed detection and response - Microsoft Defender for Endpoint, monitored by AMVIA's in-house 24/7 SOC, watching endpoints and cloud sign-ins in real time. See managed detection and response. - Email security - Barracuda filtering that stops phishing, business email compromise (BEC, where an attacker impersonates a director or client to redirect payments) and impersonation. - Cloud accounting security - MFA and access control on Xero, QuickBooks, Sage and Microsoft 365, plus review of third-party app connections. - Compliance support - GDPR and ICO readiness, with the technical evidence to back it up. We hold Cyber Essentials Plus. - Staff training - phishing simulations tuned to the lures accountants actually receive (fake HMRC, fake software renewals). - Encryption and backup - client data encrypted in transit and at rest, with tested backup and recovery. For practices standardised on Microsoft, this dovetails with our Microsoft 365 security service for accountants. ## In-house vs managed accountancy cybersecurity: which is right? For most UK practices under 500 staff, a managed service delivers stronger protection at lower total cost than hiring in-house, because 24/7 monitoring and specialist tooling are impractical to run alone. The table below sets out the practical difference. | | Capability | In-house / DIY | AMVIA managed | 24/7 threat monitoring | Office hours only | Round-the-clock in-house SOC | Email / BEC defence | Built-in spam filter | Barracuda anti-impersonation | HMRC & cloud accounting hardening | Ad hoc | Configured and monitored | Breach response | Improvised | Tested incident response plan | Cyber Essentials evidence | Manual | Managed by AMVIA | Accountable owner | You | One provider This is the core of our pitch: one provider, security-first, Microsoft-certified engineers, accountable for the whole stack rather than a patchwork of tools you manage yourself. ## What does an accountancy practice security checklist look like? A baseline accountancy practice should enforce MFA everywhere, protect every device, filter email aggressively, train staff against impersonation, and keep a tested breach plan. The list below is the minimum we deploy on day one for a UK firm. - MFA on all email, cloud accounting and HMRC Agent Services accounts - Endpoint protection on every device, including home-working laptops - Advanced anti-phishing email filtering - Regular phishing simulation training for all staff - Encrypted file sharing for client documents - GDPR-compliant data-handling procedures - A tested incident response and breach-notification plan Cyber Essentials Plus, the UK Government-backed scheme, gives a recognised baseline for these controls - and AMVIA holds it. ## Beyond security: the full IT stack for accountancy practices Security is where the risk concentrates, but it is not where a practice's IT problems end. Accountants buy the full stack - connectivity, Microsoft 365, phones and support - and buying it from four suppliers means four contracts, four helpdesks and nobody accountable when the pieces don't work together. AMVIA runs all of it under one SLA with a <1hr critical response commitment. ## Connectivity that survives January Cloud accounting is only as good as the line it runs on. Self-assessment season is the stress test: HMRC submissions, client portals and video calls all peak at once. AMVIA provides full-fibre business broadband from £29/month for smaller practices and dedicated leased lines from £69/month - uncontended, symmetrical and backed by a repair SLA - where downtime costs billable hours. ## Phones: the PSTN deadline is a fixed date The UK's analogue phone network switches off on 31 January 2027. Every practice still on traditional lines needs a migration plan, and moving early is cheaper than moving in a rush. AMVIA's business VoIP runs from £5.95/user/month with Microsoft Teams integration, so client calls land in the same environment your team already works in. ## IT support from the team that secures you AMVIA's managed IT support runs £25–£60/user/month depending on service level. The practical advantage of combining it with your security: the engineers patching your devices are the same people monitoring them for threats, so nothing falls between two suppliers. That is the "one provider, one SLA" model - and for a practice, it means one number to call at 9am on 31 January. ## Frequently asked questions Q: What cybersecurity obligations do accountancy firms have under GDPR and ICO rules? A: Accountancy firms are data controllers under UK GDPR, responsible for protecting client financial data. The ICO expects appropriate technical controls including encryption, access controls, MFA and breach-notification procedures. Failures can bring fines and professional sanctions. Cyber Essentials Plus provides a recognised baseline that supports ICO compliance. Q: How are HMRC Agent Services accounts targeted by cybercriminals? A: Attackers use phishing emails impersonating HMRC or software providers to steal credentials for Agent Services accounts. Once compromised, these accounts can be used to file fraudulent returns or reach client data. MFA is now mandatory on HMRC Agent Services accounts - firms without it face both security and compliance risk. Q: What is business email compromise and how does it affect accountancy firms? A: Business email compromise (BEC) uses email to impersonate clients, directors or suppliers and redirect payments or extract financial data. Accountancy firms are prime targets because they hold authority over client payroll and payments. Overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), making anti-impersonation email filtering essential for practices of every size. Q: How should accountancy practices secure cloud platforms like Xero and QuickBooks? A: Secure them with MFA on every account, strict access controls limiting client-data visibility to relevant staff, regular review of third-party app integrations, and monitoring for unusual logins. AMVIA configures and monitors these platforms as part of its managed cybersecurity service for UK accountancy practices. Q: Does AMVIA hold any security certifications? A: Yes. AMVIA holds Cyber Essentials Plus, the UK Government-backed scheme that independently verifies core technical controls. We are also a Microsoft Solutions Partner (Modern Work, Security, Infrastructure), so the same engineers who secure your Microsoft 365 estate run your monitoring. Q: How much does accountancy cybersecurity cost? A: Cost depends on staff numbers, devices and which platforms you run, so we price per practice after a short scoping conversation rather than quoting a blanket figure. The cheapest starting point is a free security audit that shows your current exposure before you commit to anything. Q: Can AMVIA supply our practice's connectivity and IT support as well as security? A: Yes - that's the model. AMVIA provides business connectivity (full-fibre broadband from £29/month, dedicated leased lines from £69/month), VoIP phone systems from £5.95/user/month, Microsoft 365, and managed IT support from £25/user/month, alongside managed cybersecurity. One provider, one SLA, one number to call - so when something breaks there's no circuit provider, IT company and security vendor pointing at each other. Q: Why does connectivity matter so much for accountancy practices in January? A: Self-assessment season concentrates a year of client demand into weeks: cloud accounting, HMRC submissions, client calls and document exchange all run flat out. A contended consumer broadband line failing in late January costs billable hours at the worst possible time. Practices that depend on Xero, QuickBooks or Sage should run business-grade connectivity with a defined repair SLA - and firms where downtime is unacceptable typically step up to a dedicated leased line. --- # Cybersecurity for Professional Services Firms URL: https://amvia.co.uk/cybersecurity/industries/professional-services Last updated: 2026-07-15 Managed IT for professional services gives accountancy, consultancy, architecture and surveying firms a single provider for IT support, Microsoft 365 management, email security and backup. It protects confidential client data and payment instructions against business email compromise. AMVIA runs it security-first - one provider, security-first, Microsoft-certified. ## Why do professional services firms need managed IT? Professional services firms hold confidential client records, process financial transactions and usually run lean without in-house IT. That combination makes them an attractive fraud target and a hard place to recover after an incident. Managed IT support closes the gap with continuous monitoring, certified engineers and tested backups. According to the UK government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the previous 12 months. Firms that bill against filing deadlines feel downtime hardest - an outage during a tax or audit deadline is lost revenue and a client-trust problem at once. Common attack vectors against professional services firms: - Business email compromise (BEC) - fraudulent invoice redirection and payment-instruction scams that exploit trusted client relationships - Phishing - credential theft targeting Microsoft 365 and practice-management logins - Ransomware - timed to deadlines, when firms are most likely to pay to keep working - Insider error - misdirected client data, a reportable breach under UK GDPR ## What's included in AMVIA's managed IT for professional services? AMVIA delivers a single, accountable stack: email security, Microsoft 365 management, endpoint protection, helpdesk and backup. Each layer is configured by Microsoft-certified engineers and monitored by our in-house team, so a firm with no internal IT department still gets enterprise-grade controls. AMVIA serves firms with 10-500 staff. - Email security and anti-BEC - Barracuda email filtering with DMARC, DKIM and SPF enforced, plus impersonation protection to block payment-redirection fraud - Microsoft 365 management - security configuration, conditional access, data-protection policies and licensing handled end to end - Device and endpoint security - Microsoft Defender for Endpoint on every laptop and mobile, covering office and remote staff - Unlimited UK helpdesk - phone, email and chat support that resolves day-to-day issues fast - Backup and business continuity - immutable backups of client files, mailboxes and practice-management data with tested recovery Microsoft Defender for Endpoint is Microsoft's endpoint detection and response (EDR) tool; AMVIA configures and monitors it 24/7 in-house rather than handing alerts to a third party. ## In-house IT vs managed IT for professional services firms - which is right? Most firms under 500 staff cannot justify a full in-house security team, yet still face the same threats as larger practices. Managed IT delivers the coverage of a department for a predictable per-user fee. The table below compares the two models on the factors that matter to a managing partner. | | Factor | In-house IT hire | AMVIA managed IT | Out-of-hours cover | Limited to one person's hours | 24/7 monitoring by in-house team | Security tooling | Bought and managed separately | Microsoft Defender + Barracuda included | Microsoft 365 expertise | Variable | Microsoft Solutions Partner engineers | Cost model | Salary + tools + cover | Predictable per-user monthly fee | Holiday / sickness risk | Single point of failure | Team-based continuity | Compliance support | Depends on individual | Supports UK GDPR compliance ## How does managed IT protect against business email compromise? BEC attacks impersonate a client, partner or supplier by email to redirect a payment or extract financial details - and AI-generated messages have made the impersonation harder to spot. AMVIA blocks it with layered email authentication and access controls rather than relying on staff to catch every fake. The National Cyber Security Centre recommends DMARC, DKIM and SPF to stop attackers spoofing your domain. AMVIA configures all three, enforces multi-factor authentication on Microsoft 365, and adds impersonation filtering so spoofed director and client emails are quarantined before they reach a fee earner. Payment-change requests are routed through a verification step, not a reply-to address. ## What UK GDPR obligations do professional services firms have for client data? Professional services firms are data controllers under UK GDPR and must apply appropriate technical and organisational security measures to the client data they hold. That means access control, encryption, documented breach procedures and the ability to act fast when something goes wrong. Under ICO rules, a notifiable personal data breach must be reported to the regulator within 72 hours. AMVIA's managed IT supports UK GDPR compliance with MFA, encryption, immutable backups and audit logging - the controls an ICO investigation expects to see evidenced. ## Professional services IT and security checklist Use this as a baseline. AMVIA implements and monitors every item as part of managed IT, so nothing is left to chance between busy periods. - MFA enforced on all cloud services - Microsoft 365, accounting software, practice-management systems and client portals - Email security controls active - DMARC, DKIM and SPF configured with anti-phishing filters - Client data backed up and tested, with offsite immutable copies - UK GDPR measures in place - privacy notice, data-processing register, retention policy and DPIA process - Staff security-awareness training covering phishing, BEC, password hygiene and data handling - Remote access secured with MFA through approved channels only ## How much does managed IT for professional services cost? AMVIA's managed IT for professional services starts from £30/user/month, covering helpdesk, security tooling, Microsoft 365 management and backup under one fee. Pricing scales with headcount and the licences a firm needs. Microsoft licensing sits alongside the service. Microsoft 365 Business Premium - which includes Defender for Business and Intune - lists at £16.90 per user per month (ex VAT, annual) on microsoft.com. AMVIA manages those licences so you pay list price without the admin overhead. For a firm of 25 staff, that is one predictable number against the salary, tooling and cover cost of an in-house hire. ## Frequently asked questions Q: What do professional services firms need from managed IT? A: A single provider covering IT support, Microsoft 365 management, email security and compliance-aware data handling - because accountancy, consultancy, architecture and surveying firms all run on the same stack: M365, client files, email and deadlines. One accountable contract beats three vendors pointing at each other. Q: How do we protect client confidentiality in practice? A: Access control by engagement (not everyone sees everything), MFA everywhere, email security tuned for the impersonation attacks that target firms handling money and contracts, and device management for the laptops that work from anywhere. It's the same discipline your PI insurer increasingly asks about. Q: What does managed IT cost for a professional firm? A: AMVIA's plans run from £25 per user/month (Essentials) to £60 (Enterprise, with 24/7 SOC) - with 43% of UK businesses experiencing a breach or attack in the past year (DSIT 2025), the security-inclusive tiers are where most regulated firms land. Q: Can you support us through client security questionnaires? A: Yes - supplier due-diligence questionnaires are now routine in professional services, and answering them well needs evidence: certifications (AMVIA holds Cyber Essentials Plus and prepares clients for their own), documented controls, and a provider who can speak to the technical answers. --- # IT Support, Connectivity & Cybersecurity for Law Firms URL: https://amvia.co.uk/cybersecurity/industries/law-firms Last updated: 2026-07 Law firms need IT built around SRA obligations and client confidentiality: managed cybersecurity against phishing, ransomware and conveyancing fraud; hardened Microsoft 365 for privileged communications; resilient connectivity for case management and remote hearings; and compliant phone systems. AMVIA - Cyber Essentials Plus certified, Microsoft Solutions Partner - delivers the full stack as one accountable provider: leased lines from £69/month, VoIP from £5.95/user/month, managed IT from £25/user/month. Solicitors hold legally privileged information, move client money, and store sensitive personal data that attackers target on purpose. A breach is not just a financial event: it triggers professional negligence exposure, SRA scrutiny, and reputation damage that takes years to repair. AMVIA builds the security programme around the specific risks legal practices face, then runs it for you. ## What cyber threats are UK law firms most exposed to? Law firms face three dominant threats: targeted phishing, ransomware, and business email compromise (BEC) - fraud where an attacker hijacks an email thread to redirect funds. These map directly to the legal workflow, hitting conveyancing payments, client account credentials, and privileged case files. The UK-wide baseline shows the scale of the exposure: - 43% of UK businesses identified a cyber breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025) - and law firms are prime targets for the funds and data they hold - 85% of businesses that identified a breach reported phishing (DSIT 2025) - 23% of firms had client money stolen through cyber fraud (SRA, 2025) - £3.29M average UK data breach cost (IBM Cost of a Data Breach 2025) Phishing is the entry point for most incidents. The government's Cyber Security Breaches Survey 2025 found phishing was the single most common breach type, identified by 85% of businesses that experienced a breach. For a law firm, one clicked link can expose an entire case management system. ## Why do law firms need specialist cybersecurity? Generic IT support secures laptops and email. Legal practice needs more: protection wrapped around client money movement, privileged-document handling, and a regulator that expects evidence of reasonable steps. AMVIA designs for those obligations rather than bolting them on afterwards. The SRA expects firms to take proportionate steps to protect client data and funds. The consequences of getting it wrong stretch well beyond the breach itself - regulatory sanction, indemnity premium increases, and clients who walk. The National Cyber Security Centre's guidance for small organisations sets out the baseline controls every firm should evidence, and AMVIA implements and monitors them on your behalf. ## What does AMVIA do to protect law firms? AMVIA runs a layered, managed programme built for legal sector requirements - detection, email defence, Microsoft 365 hardening, data loss prevention, and staff training - under one provider with one point of accountability. - Managed detection and response - 24/7 threat monitoring across endpoints, email and cloud using Microsoft Defender for Endpoint, watched by AMVIA's in-house UK SOC. Threats are contained before they reach client data. - Email security and BEC protection - the Barracuda email security suite stops conveyancing fraud, client impersonation and targeted phishing before it lands. We configure DMARC, DKIM and SPF so spoofed firm domains are rejected. - SRA compliance support - documented technical controls, MFA enforcement, tested backups and a response runbook that includes SRA notification steps where client money or data is compromised. - Microsoft 365 security - proper Microsoft 365 security hardening and monitoring for Teams, SharePoint and Exchange, where most privileged communication now lives. - Data loss prevention (DLP) - policies across email, cloud storage and endpoints that stop privileged files leaving the firm, accidentally or maliciously. - Legal staff security training - phishing simulations and awareness training built around conveyancing fraud, social engineering and safe client communication. ## In-house IT vs AMVIA managed security for law firms A single internal IT person rarely covers 24/7 monitoring, regulatory documentation, and incident response at once. The table below shows where managed security closes the gap. | | Capability | Typical in-house IT | AMVIA managed security | Threat monitoring | Business hours, reactive | 24/7 UK SOC, proactive | Email/BEC defence | Standard spam filter | Barracuda suite + DMARC/DKIM/SPF | Conveyancing fraud controls | Ad hoc | Verification process + encrypted financial email | SRA evidence pack | Often missing | Documented controls and reporting | Incident response | Improvised | Tested runbook with SRA notification | Microsoft 365 hardening | Default settings | Secured Teams, SharePoint, Exchange ## How does conveyancing fraud work, and how do you stop it? Conveyancing fraud - sometimes called Friday afternoon fraud - is where an attacker intercepts the email thread between a solicitor and client, then sends fraudulent bank details at the point of completion. Single losses can reach hundreds of thousands of pounds, and client money is rarely recovered. The controls that stop it are specific and testable: - DMARC, DKIM and SPF configured so your domain cannot be spoofed - Encrypted email for any financial or completion communication - Mandatory telephone verification of bank details using independently sourced numbers - Email security that flags lookalike domains and reply-thread anomalies If money or data is taken, report it to the ICO and the SRA without delay - the ICO's personal data breach guidance sets the 72-hour notification expectation for qualifying breaches. ## Law firm cybersecurity checklist Use this as the baseline for any UK legal practice. AMVIA implements, evidences and monitors every item. - MFA on all email, case management and client portal accounts - Advanced email security with BEC and impersonation detection - Endpoint protection on every solicitor device - Encrypted file transfer for client documents - Regular phishing simulations for all staff - Tested incident response plan with SRA notification procedures - Client bank-detail verification procedures for conveyancing ## How much does managed cybersecurity for law firms cost? Cost depends on headcount, the number of sites, and how much of your Microsoft 365 estate needs hardening - but it is far lower than the cost of a single conveyancing loss or an SRA enforcement event. AMVIA prices per user per month so it scales with your fee earners, and a free security audit gives you a fixed scope before you commit. AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner, so the controls you pay for are independently verified. ## Beyond security: the full IT stack for law firms The SRA holds firms accountable for protecting client data and money - but the working day runs on more than security controls. Case management, hearings, client calls and completions all depend on connectivity and phones, and when those come from three different suppliers, an outage becomes a blame exercise. AMVIA runs the whole estate under one SLA with a <1hr critical response commitment. ## Connectivity built for legal work Legal workloads are upload-heavy: document bundles, disclosure exchanges, video hearings. Contended consumer broadband handles them poorly. AMVIA provides dedicated leased lines from £69/month - symmetrical, uncontended and SLA-backed - with full-fibre broadband as a lighter-weight option or a backup path on a physically separate network. For firms doing conveyancing, a resilient pair means a carrier fault on completion day is an inconvenience rather than a crisis. ## Phones and the PSTN switch-off The UK's analogue phone network switches off on 31 January 2027, and every firm still on traditional lines needs a migration plan before then. AMVIA's business VoIP runs from £5.95/user/month with Microsoft Teams integration, keeping client calls in the same secured environment as your privileged communications. ## IT support with security built in AMVIA's managed IT support runs £25–£60/user/month depending on service level. Because the same team patches your devices and monitors them for threats, there is no gap between "IT's problem" and "security's problem" - and no gap is where conveyancing fraud lives. One provider, one SLA, one number to call. ## Frequently asked questions Q: What cyber threats are law firms most exposed to? A: Law firms face targeted phishing, ransomware, and business email compromise. The Cyber Security Breaches Survey 2025 found phishing was identified by 85% of businesses that experienced a breach. For solicitors, these attacks specifically target conveyancing funds, client account credentials, and privileged case data, and the SRA has reported rising client-money losses through email interception. Q: What does the SRA require from law firms regarding cybersecurity? A: The SRA expects firms to implement proportionate technical controls, staff training, and incident response procedures. In practice that means MFA on email and case management systems, tested backups, and a documented response plan including SRA notification where client money or data is compromised. Failure to take reasonable steps to protect client data can lead to regulatory sanction and professional negligence claims. Q: How does conveyancing fraud work and how can law firms prevent it? A: Conveyancing fraud involves attackers intercepting solicitor-client email threads, then sending fraudulent bank details at completion. Losses can reach hundreds of thousands of pounds. Essential controls include DMARC and DKIM configuration, encrypted email for financial communications, and mandatory telephone verification of bank details using independently sourced contact numbers - never the number in the email. Q: How should law firms protect legally privileged client data? A: Legally privileged data demands the highest protection standard. Firms should enforce role-based access controls on case management systems, apply data loss prevention policies across email and cloud storage, encrypt client files at rest and in transit, and keep immutable backups. Staff handling privileged material need targeted awareness training covering social engineering risks specific to legal practice. Q: Does AMVIA help with SRA and ICO breach reporting? A: Yes. AMVIA's incident response runbook includes the notification steps for both regulators, so your firm is not improvising during an incident. The ICO expects qualifying personal data breaches reported within 72 hours, and the SRA expects prompt notification where client money or confidential data is affected. We document the timeline and evidence required for both. Q: What security technology does AMVIA actually use? A: AMVIA's managed stack is built on Microsoft Defender for Endpoint, monitored 24/7 by our in-house UK SOC, plus the Barracuda email and network security suite for BEC and phishing defence. We harden your existing Microsoft 365 tenant rather than adding overlapping tools, so you get one accountable provider instead of a patchwork. Q: Does AMVIA provide IT support and connectivity for law firms, or only cybersecurity? A: The full estate. Alongside managed cybersecurity, AMVIA provides dedicated leased lines from £69/month and full-fibre broadband for case management and remote hearings, VoIP phone systems from £5.95/user/month, Microsoft 365, and managed IT support from £25/user/month with a <1hr critical response SLA. For a law firm the practical benefit is accountability: when a circuit, phone system or mailbox fails during a completion, one provider owns the fix. Q: What connectivity do law firms need for case management and remote hearings? A: Business-grade, resilient connectivity with meaningful upload speed. Case management platforms, video hearings and large document bundles all push data upstream, which contended consumer broadband handles poorly. Firms where downtime is unacceptable - conveyancing completions, court deadlines - typically run a dedicated leased line (symmetrical, uncontended, SLA-backed, from £69/month) with a backup circuit on a physically separate network so a single carrier fault can't take the firm offline. --- # Cybersecurity for Financial Services Businesses URL: https://amvia.co.uk/cybersecurity/industries/financial-services Last updated: 2026-07-09 A leased line for a financial services firm is a dedicated, uncontended fibre circuit with symmetric speeds, a contractual SLA and priority fault response. For FCA-regulated firms, it underpins operational resilience, low-latency trading access and reliable regulatory reporting. AMVIA delivers it as one provider - security-first and Microsoft-certified. Financial services runs on connectivity that cannot drop. Trading platforms, client management systems and FCA reporting infrastructure all depend on a circuit that performs to a measurable standard. A consumer-grade or contended business leased line alternative leaves resilience to chance - and the FCA expects you to prove it, not assume it. ## Why do financial services firms need a dedicated leased line? Financial services firms need a leased line because their important business services - trading, client portals, payments and reporting - cannot tolerate the variable performance of contended broadband. A dedicated circuit delivers symmetric, uncontended bandwidth with a defined SLA, giving you an auditable resilience standard the FCA can review. The numbers behind the risk are stark. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses suffered a cyber breach or attack in the last 12 months, 85% of those breaches involved phishing, and the average cost of a disruptive breach was £3,550 (gov.uk). For a regulated firm, the regulatory and reputational cost dwarfs that average. A resilient, monitored connection is the foundation that the rest of your controls sit on - which is why we pair connectivity with leased line security from day one. ## How does a leased line support FCA operational resilience compliance? A leased line supports FCA operational resilience compliance by giving you a contractual, measurable resilience standard for a named important business service. SYSC 15A (Operational Resilience) requires firms to map important business services and the technology that supports them - and to test recovery. An SLA-backed circuit with monitoring produces the evidence that mapping demands. The FCA requires firms to identify, protect against, and recover from disruptions to important business services. Connectivity is almost always a critical dependency in that map. AMVIA's monitoring provides the operational data - uptime, latency, fault response - needed to demonstrate connectivity resilience to FCA supervision and to evidence your technology risk management. ## What connectivity do trading and regulatory reporting systems require? Trading and reporting systems require low latency and guaranteed delivery. High-latency connections introduce delays between price data and execution, causing slippage and adverse fills. Regulatory submissions - MiFID II transaction reports, CASS reconciliations, capital returns - depend on a connection whose integrity and reliability can be relied on under deadline. - Low-latency trading access - uncontended fibre keeps the gap between price data and execution tight for equity, FX and derivatives platforms. - Reliable regulatory reporting - FCA-connected systems need a circuit that does not degrade when reports are due. - Data security in transit - a private, dedicated path reduces the exposure of sensitive financial data versus shared infrastructure. - Predictable VoIP and cloud headroom - symmetric upload supports recorded calls, video and cloud applications without contention. A dedicated internet access circuit gives you that uncontended path; for firms running several sites, multi-site connectivity keeps every branch on the same standard. ## What redundancy do FCA-regulated firms need? A single internet connection is a single point of failure. FCA-regulated firms with important business services that depend on connectivity should run a secondary path - a second leased line or a 4G/5G backup - with automatic failover. This keeps trading platforms, client systems and reporting infrastructure reachable when the primary circuit fails. | | Connectivity option | Resilience for FS firms | Best suited to | Single standard leased line | Uncontended fibre, SLA, priority fault fix - but one path | Single-site firms with low downtime tolerance | Leased line + 4G/5G backup | Automatic failover to a wireless secondary path | Firms needing continuity without a second fibre build | Dual leased lines (diverse) | Two independent circuits, no shared point of failure | Trading desks and firms with strict RTOs | Leased line with SD-WAN | Intelligent failover across multiple circuits and sites | Multi-office firms with branches and satellite sites Pair your primary circuit with backup connectivity for failover, or use SD-WAN to manage traffic and resilience intelligently across multiple offices. ## What does AMVIA's financial services connectivity include? AMVIA's FS connectivity is built around regulatory compliance, operational resilience and the data sensitivity of financial information. You get a dedicated circuit, proactive monitoring, a single point of accountability and security designed in - not a telecoms line bolted onto an unmanaged network. - Standard dedicated leased line - point-to-point symmetric fibre at 100Mbps, 200Mbps, 500Mbps or 1Gbps, with a defined SLA and priority fault response. Sizing depends on user count, cloud usage, trading data volumes and VoIP load. - Dual-path resilience - primary leased line plus a second leased line or 4G/5G backup with automatic failover for firms with DR obligations under SYSC 15A. - SD-WAN for multiple offices - intelligent traffic management and automated failover across a main office and satellite branches. - Proactive monitoring - uptime, latency and fault data captured to evidence resilience to FCA supervision. - Security-first delivery - Microsoft Defender and Barracuda email and network protection, managed by one accountable provider. ## How much does a leased line for financial services cost? AMVIA leased lines start from £69/month, with the final price driven by bandwidth, the distance from your premises to the nearest fibre, contract term and whether civils work is required. A dual-path or SD-WAN resilience design adds the cost of the second circuit and managed failover - modest against the regulatory cost of an outage. Installation typically takes 30–90 days, depending on distance to fibre infrastructure and any civils work. AMVIA manages the full process end to end; see our leased line installation timescales for what drives the timeline. ## FCA cybersecurity controls checklist for financial services The FCA expects firms to demonstrate sound technology and cyber risk management under SYSC 13, PS21/3 and its cyber security guidance for small firms. These are the core technical controls a leased line and a security-first network help you evidence. - Business continuity plan tested annually - including IT disaster recovery, with failover scenarios actually tested, not just documented. - Critical system RTOs defined and met - recovery time objectives for trading and client-facing systems documented and validated. - Third-party IT supplier risk assessed - all IT and cloud vendors in scope for third-party risk reviews, with due diligence and contractual controls. - Employee cyber awareness training current - at least annual training and phishing simulations for all staff with access to client data. - Penetration test completed within 12 months - by a qualified testing provider, covering internal and external attack surfaces. The NCSC's small-business and cyber-threat guidance is a practical reference for sizing these controls (ncsc.gov.uk). ## Frequently asked questions Q: Do financial services firms need a leased line? A: FCA-regulated firms with operational resilience obligations, trading platform access or strict data-security requirements benefit significantly from a dedicated leased line. The guaranteed performance, defined SLA and security advantages over broadband support operational resilience and help you document technology risk management to FCA supervision. Q: How does a leased line support FCA operational resilience compliance? A: SYSC 15A requires firms to document and test the resilience of important business services and their supporting technology. A leased line with a contractual SLA gives you a measurable, auditable connectivity standard. AMVIA's monitoring supplies the operational data needed to demonstrate that resilience to the regulator. Q: What connectivity redundancy do FCA-regulated firms need? A: Firms whose important business services depend on connectivity should run a secondary path - a second leased line or a 4G/5G backup - with automatic failover. This maintains access to trading platforms, client systems and regulatory reporting infrastructure if the primary circuit fails, supporting your DR obligations. Q: How long does it take to install a leased line? A: Leased line installation typically takes 30–90 days, depending on the distance from your premises to the nearest fibre infrastructure and whether civils work is required. AMVIA manages the full installation and provides regular progress updates throughout. Q: What breach-notification deadline applies to financial services firms? A: Under UK GDPR, firms must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it (ico.org.uk). FCA-regulated firms may also have separate regulatory notification duties, so resilient, monitored connectivity that helps you detect and contain incidents quickly is essential. Q: Is a leased line more secure than business broadband for a financial firm? A: A leased line is a private, dedicated, uncontended path, which reduces exposure compared with shared broadband infrastructure and delivers consistent performance for security tooling. It is not a security control on its own - it should sit alongside managed endpoint and email security for full protection. --- # Cybersecurity for Healthcare and Medical Practices URL: https://amvia.co.uk/cybersecurity/industries/healthcare Last updated: 2026-08-28 Healthcare cybersecurity protects patient records, clinical systems and appointment platforms from ransomware, breaches and downtime that put patient safety at risk. AMVIA manages managed cybersecurity and Microsoft 365 for GP practices, dental networks and NHS suppliers - supporting DSPT compliance with an in-house 24/7 SOC. One provider. Security-first. Microsoft-certified. ## Why is healthcare such a big cybersecurity target? Healthcare holds special category patient data and runs systems that cannot tolerate downtime - a combination criminals exploit, because a hospital under attack is more likely to pay to restore care. That pressure is exactly why clinical environments need security designed around availability, not just prevention. - Healthcare sits among the most targeted verticals for ransomware - see sector-level attack data in the DCMS Cyber Security Breaches Survey 2025. - The 2017 WannaCry attack affected a third of NHS England trusts - cancelling thousands of appointments and showing how a single outbreak cascades into patient harm. See the NCSC threat guidance. Ransomware here is not an IT inconvenience. It locks clinicians out of records, prescribing and booking - directly disrupting care. ## What does AMVIA's healthcare cybersecurity service include? AMVIA delivers security built around clinical availability, patient-data protection and regulatory evidence - from GP practices to private hospital groups and NHS supplier organisations. Every control below is run by one accountable provider, so there is no finger-pointing between your IT and security vendors when minutes matter. - Managed detection and response - Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC, with healthcare-specific playbooks that contain ransomware before clinical operations are disrupted. - Clinical device management - endpoint protection and MDM (Mobile Device Management - central control of devices and policies) across clinical workstations, nursing-station PCs and mobiles accessing patient records. - Patient-data backup and recovery - immutable offsite backups of clinical and administrative systems, with tested restore procedures to minimise disruption to care. - Secure network infrastructure - segmented networks separating clinical and administrative traffic, behind managed Barracuda firewalls with continuous monitoring. - Email and phishing defence - Microsoft Defender and the Barracuda email suite filtering the inbox attacks that start most breaches. - Data security awareness training - staff training that supports the National Data Guardian's standards and annual DSPT completion. - Rapid incident response - containment and recovery for patient-data breaches and the reporting obligations that follow. ## How does AMVIA support DSPT and patient-data compliance? The NHS Data Security and Protection Toolkit (DSPT) is an annual self-assessment that every organisation handling NHS patient data must complete. AMVIA's managed detection and response and UK GDPR security controls supply the technical evidence that turns "Standards Met" from an aspiration into a submitted result. DSPT maps to the National Data Guardian's ten data security standards. AMVIA supports DSPT compliance through gap analysis, technical remediation, and submission support - for private healthcare providers, GP practices, dental networks and NHS supplier organisations. Under UK GDPR, health data is special category data requiring stronger protection, and breaches involving patient data must be reported to the ICO within 72 hours. ## In-house IT vs managed healthcare cybersecurity - which protects patients better? For most UK practices, an internal IT person keeps systems running but cannot watch for threats overnight or carry the weight of DSPT evidence alone. Managed security adds the round-the-clock detection and documented controls that patient safety and compliance demand. | | Capability | In-house IT alone | AMVIA managed cybersecurity | Threat monitoring | Office hours only | Round-the-clock in-house SOC | Ransomware response | Reactive, after impact | Detect and contain before clinical disruption | DSPT evidence | Manual, time-consuming | Gap analysis + submission support | Patient-data backup | Often untested | Immutable offsite, tested recovery | Microsoft 365 hardening | Ad hoc | Defender + Intune, continuously managed | Accountability | Split across vendors | One provider, one number to call ## How much does healthcare cybersecurity cost? There is no flat sticker price - cost scales with sites, devices and how much DSPT support you need. The licence layer is predictable: Microsoft 365 Business Premium, which adds Defender for Business and Intune for clinical device security, lists at £16.90 per user/month (ex VAT, annual). AMVIA wraps that licensing with monitoring, backup and compliance support under a single managed contract, so a GP practice and a private hospital group each pay for the controls their risk profile actually requires. For a scoped figure, start with a free security audit. ## Healthcare cybersecurity & DSPT compliance checklist Key controls drawn from the NHS DSPT and the National Data Guardian's ten data security standards: - DSPT submission completed annually - "Standards Met" achieved and submitted before the 30 June deadline, with evidence documented for each assertion. - Staff data security training completed - every member of staff with access to patient data completes annual training. - Board-approved DSP policy in place - covering data handling, incident reporting and acceptable use of clinical systems. - Backup and recovery tested within 12 months - clinical and administrative backups restored, with recovery time objectives validated. - DPIAs completed - Data Protection Impact Assessments for new systems or significant processing changes, as required under UK GDPR. ## Frequently asked questions Q: What is the NHS Data Security and Protection Toolkit (DSPT) and who needs to complete it? A: The DSPT is an annual self-assessment every organisation handling NHS patient data must complete - including GP practices, dental networks, private healthcare providers and NHS supplier organisations. It maps to the National Data Guardian's ten data security standards, and a "Standards Met" rating requires security certification as a minimum. AMVIA helps healthcare providers reach and maintain DSPT compliance. Q: How do ransomware attacks affect patient safety in healthcare organisations? A: Ransomware locks clinical staff out of patient records, appointment systems and prescribing platforms, directly disrupting care. Healthcare is consistently among the most targeted sectors. The 2017 WannaCry attack affected a third of NHS England trusts, cancelling thousands of appointments. Rapid response, network segmentation and tested backups are essential. Q: How should healthcare organisations protect patient data under UK GDPR? A: UK GDPR requires appropriate technical and organisational measures to protect patient data, which is special category data needing stronger protection. That means encryption at rest and in transit, strict access controls, staff training and documented breach response. The ICO must be notified within 72 hours of any breach involving patient personal data. Q: How do I secure clinical workstations and devices that access patient records? A: Clinical workstations should run current endpoint protection, be managed through MDM, and enforce MFA on all clinical system access. Legacy devices on outdated operating systems - common in clinical settings - should be isolated on separate network segments with restricted internet access. AMVIA provides clinical device management as part of its healthcare cybersecurity service. Q: Can AMVIA support a GP practice and a multi-site hospital group equally? A: Yes. AMVIA serves 1,200+ UK businesses and scopes the same core controls - 24/7 SOC monitoring, immutable backup, Microsoft 365 hardening and DSPT support - to each setting. A single-site GP practice and a multi-site private group get the same security-first model sized to their risk and budget, under one accountable provider. Q: Does AMVIA replace our existing clinical software supplier? A: No. AMVIA secures the IT and Microsoft 365 environment around your clinical systems - endpoints, email, network, backup and identity. We work alongside your clinical software vendors, hardening access to those systems and supplying the DSPT evidence that integrating them safely requires. --- # Cybersecurity for UK Retail Businesses URL: https://amvia.co.uk/cybersecurity/industries/retail Last updated: 2026-06-30 Retail cybersecurity is the set of controls that protect card payments, customer data, EPOS terminals and ecommerce systems from theft, ransomware and fraud. UK retailers sit on payment card data and personal records, which makes them a constant target. AMVIA secures the whole estate from one provider - security-first, Microsoft-certified. ## What threats does a UK retail business actually face? Retailers face card-data theft, ransomware that halts tills, phishing aimed at back-office finance staff, and supply-chain compromise through software vendors. The common thread is that every store network, EPOS terminal and cloud account is an attack surface a criminal can reach - and most retailers run them without a dedicated security team. The numbers back this up. The UK government's Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a cybersecurity breach or attack in the previous 12 months (gov.uk). For retail specifically, the cost lands hard: the average retail data breach costs £3.8M globally (IBM), and 46% of retail breaches involved payment card data. - Ransomware spreading from office PCs to tills, stopping all sales - Card skimming and EPOS malware harvesting payment data - Phishing and business email compromise targeting finance teams - Supply-chain attacks through EPOS, ecommerce or accounting software - Customer-data theft triggering UK GDPR breach obligations ## Why does retail need specialist cybersecurity? Retail carries a unique mix of obligations that generic IT support does not cover. "PCI DSS compliance, GDPR requirements, and the threat of brand damage from a breach all demand proper security." A single payment-data breach can mean card-scheme fines, lost processing rights and reputational damage that outlasts the incident itself. Unlike an office, a retail estate spans tills, stockrooms, guest WiFi, cloud EPOS and an ecommerce front end - often across multiple sites. Securing that needs network segmentation, payment-system isolation and continuous monitoring, not a once-a-year audit. AMVIA runs all of it as a managed service so you get managed detection and response without hiring a SOC team. ## What's included in AMVIA's retail cybersecurity service? AMVIA protects the full retail technology stack with one accountable team. Monitoring runs 24/7, the security tooling is built on Microsoft Defender and the Barracuda email and network suite, and every engineer is Microsoft-certified. You get the controls a PCI DSS assessor expects, managed end to end. - Managed detection and response - Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC across tills, devices and cloud - PCI DSS support - technical controls and guidance to achieve and maintain compliance for card payment processing - Network security - segregate EPOS from guest WiFi and back-office IT, and protect connected store systems - Email security - block phishing and business email compromise targeting retail finance and supply chains - Cloud and ecommerce security - harden ecommerce platforms, cloud EPOS and Microsoft 365 with Defender for Business - Staff security training - practical sessions on social engineering, phishing and payment fraud ## In-house IT versus managed retail cybersecurity Most UK retailers do not have the headcount to run 24/7 security in-house. The table below shows where a managed service changes the economics. | | Capability | Typical in-house retail IT | AMVIA managed cybersecurity | Threat monitoring | Business hours, reactive | 24/7 SOC, proactive | EPOS/payment isolation | Often flat network | Segmented by design | PCI DSS readiness | Annual scramble | Continuous controls | Phishing defence | Basic spam filter | Barracuda + Defender | Incident response | Ad hoc | Defined, tested process | Cost | Salaries + tooling | Fixed monthly fee ## What does retail cybersecurity cost? Pricing depends on the number of sites, tills and users, and on whether you need PCI DSS support, ecommerce hardening or full managed IT alongside security. There is no per-store list price because a single shop and a 30-site chain carry very different attack surfaces. The fastest way to a real number is a free security audit, where AMVIA maps your estate and scopes exactly what you need. Microsoft 365 licensing, if bundled, follows Microsoft's published UK list prices - Business Premium is £16.90 per user per month ex VAT on an annual plan (microsoft.com/en-gb). ## Retail cybersecurity checklist Use this as a baseline. AMVIA delivers every item as part of a managed service, with penetration testing to prove the controls work. - PCI DSS compliant payment processing - Network segmentation separating EPOS from business and guest networks - Endpoint protection on all devices, including EPOS terminals - MFA on all admin, email and cloud platform accounts - Email filtering with anti-phishing protection - Regular security awareness training for all staff - GDPR-compliant handling of customer data ## Frequently asked questions Q: Does my retail business need to comply with PCI DSS? A: Yes - if you accept card payments in-store, online or over the phone, PCI DSS applies. Your compliance level depends on annual card transaction volume. Non-compliance can mean fines from the card schemes, higher processing fees, and unlimited liability if card data is breached. AMVIA provides the technical controls and evidence assessors look for. Q: How do ransomware attacks target retail EPOS systems? A: Ransomware often starts on an office PC or back-office server, then spreads to EPOS terminals - halting payment processing and all sales. The defence is network segmentation: keeping payment terminals on isolated segments away from general business IT. AMVIA segments retail networks and monitors them 24/7 to catch spread early. Q: What GDPR obligations do retailers have for customer data? A: Retailers processing customer personal data must comply with UK GDPR. That means a lawful basis for processing, clear privacy notices, retention limits, appropriate technical controls, and notifying the ICO of a reportable breach within 72 hours (ico.org.uk). AMVIA's monitoring shortens the detection time that breach deadlines depend on. Q: How do supply-chain attacks affect retail businesses? A: Supply-chain attacks compromise software or services used by many retailers to reach customer data and payment systems at scale. Attackers also hijack supplier email accounts to run invoice fraud against retail finance teams. Email security and vendor access controls reduce both routes - see NCSC supply-chain guidance (ncsc.gov.uk). Q: What should retail staff be trained to recognise? A: Staff should spot phishing aimed at back-office teams, social engineering for credentials, suspicious requests to change supplier bank details, physical card-skimming devices on terminals, and how to report an incident fast. AMVIA delivers practical, retail-specific training rather than generic e-learning, because front-line staff are the most-targeted layer. Q: Is AMVIA certified to handle retail security? A: AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner for Modern Work, Security and Infrastructure. The security tooling is built on Microsoft Defender and the Barracuda suite, monitored by an in-house 24/7 SOC. AMVIA supports 1,200+ UK businesses. --- # Cybersecurity for Schools and Education Providers URL: https://amvia.co.uk/cybersecurity/industries/education Last updated: 2026-08-28 Education cybersecurity protects schools, colleges, academy trusts and universities from ransomware, phishing and data breaches that target pupil records, safeguarding files and MIS platforms. It combines network segmentation, MFA, tested backups and 24/7 monitoring to meet DfE Cyber Security Standards. AMVIA delivers it as one provider - security-first and Microsoft-certified. Education is one of the most attacked sectors in the UK, and the reasons are structural: open networks, thousands of users, BYOD by default, and IT teams stretched across teaching, admin and estates. We protect managed cybersecurity for primary and secondary schools, multi-academy trusts, further education colleges and universities - without demanding a large in-house security team to run it. ## Why are UK schools and universities targeted so often? Educational institutions hold huge volumes of sensitive data - pupil records, SEND and safeguarding files, staff HR and financial data - while running open, multi-user networks on tight budgets. Attackers exploit that gap, frequently timing ransomware to coincide with term starts to maximise pressure to pay. - According to the UK Government's Cyber Security Breaches Survey 2025, phishing remains the most common breach vector, with 85% of businesses that experienced a breach identifying phishing as the attack method (DSIT, 2025). - Ransomware recovery typically takes schools weeks, not days - disruption lands on students, staff and administration at the worst possible moment. The National Cyber Security Centre publishes sector-specific guidance for schools precisely because the threat to education is sustained, not occasional. ## What are the DfE Cyber Security Standards for schools? The Department for Education's Cyber Security Standards set baseline expectations for schools and colleges receiving DfE funding. They cover network security, access controls, data management, staff training and incident response. AMVIA supports DfE Cyber Security Standards compliance through gap assessment, technical remediation and ongoing monitoring. Schools receiving DfE funding are expected to meet these standards, and many local-authority frameworks and academy-trust governance requirements now treat cyber security as a core compliance area. We work with single-site schools through to multi-campus universities to put practical, affordable controls in place - and AMVIA holds Cyber Essentials Plus, the UK Government-backed certification that demonstrates the same baseline we help schools reach. ## What's included in AMVIA's education security service? AMVIA delivers a single, accountable security service built around Microsoft technologies and the Barracuda email and network suite. One provider covers monitoring, devices, email, backup and incident response - so there is no finger-pointing between vendors when something goes wrong. - DfE Standards compliance support - gap assessment, technical remediation and evidence to meet DfE Cyber Security Standards. - Managed network security - segmented school networks with managed firewalls, DNS filtering and web content controls protecting students, staff and admin on shared infrastructure. - MIS & data backup - regular, immutable backups of Management Information Systems (SIMS, Arbor and similar), student records and admin data, with tested recovery. - Device management for BYOD and school devices - Microsoft Intune management of school-owned devices plus policies governing personal-device access, supporting BYOD and 1:1 programmes. - Microsoft 365 Education management - student and staff account lifecycle, Teams for Education and security configuration across the tenancy. - 24/7 threat monitoring - round-the-clock security monitoring from AMVIA's in-house UK SOC, with ransomware and malware contained before they spread across the institution. Detection is built on Microsoft Defender for Endpoint, monitored by our analysts as a managed detection and response service. Email - the source of most school breaches - is filtered through our Barracuda-based email security stack. ## In-house school IT vs AMVIA managed security Most school IT teams are excellent at keeping classrooms running but are not resourced to run a security operations centre. The table below shows where a managed model closes the gap. | | Capability | Typical in-house school IT | AMVIA managed | Threat monitoring | Office hours, best-effort | 24/7 in-house UK SOC | Detection technology | Basic antivirus | Microsoft Defender for Endpoint, analyst-monitored | Email defence | Standard mailbox filtering | Barracuda email security + phishing controls | MIS backup | Backups taken, rarely tested | Immutable, offsite, restore-tested | DfE Standards | Self-assessed, inconsistent | Gap assessed and remediated | Incident response | Ad hoc, learned under fire | Documented plan with ICO escalation ## What does education cybersecurity cost? There is no single price - it depends on the number of users, sites, device estate and whether you need full management or co-managed support alongside an existing team. Microsoft 365 licensing underpins most school deployments and is published openly, so you can budget the platform layer with confidence. Microsoft 365 list prices (ex VAT, annual) are: Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month, per microsoft.com/en-gb. Business Premium includes Defender for Business and Intune - the security and device controls schools need - which is why it is usually the right starting point for education. For a scoped quote, book a free security audit (linked below). ## DfE Cyber Security Standards checklist Use this as a quick self-check against the controls schools are expected to have in place. Each item maps to a DfE expectation and to UK GDPR obligations. - MFA enforced for all staff accounts - including email, MIS and cloud services, with priority on admin accounts that touch pupil data and finance. - Network segmentation in place - student, staff and admin traffic on separate segments, visitor Wi-Fi isolated from school systems. - Data Protection Impact Assessments completed - DPIAs for pupil-data processing across cloud services, learning platforms and communication tools. - Incident response plan documented - with an ICO notification procedure, trust or local-authority escalation path, and a communication plan for parents and governors. - Backup and recovery tested - MIS and key data restored from backup and recovery time objectives validated, not assumed. ## Frequently asked questions Q: Why do attackers target schools and trusts? A: Ransomware gangs know term-time pressure makes schools more likely to pay, and pupil records plus safeguarding files are exactly the data that cannot leak. With 85% of breaches involving phishing (DSIT 2025) and staff inboxes full of parent communication, the front door is email. Q: How do we protect pupil data and safeguarding records? A: Layered controls on the Microsoft 365 estate most schools already run: MFA enforced everywhere, access restricted by role, email security tuned for impersonation, and independent backup so records survive both ransomware and accidental deletion. Configuration, not new spend, does most of the work. Q: What does education cybersecurity cost on a school budget? A: Less than most trusts expect - much of the needed capability is inside Microsoft licensing already held (A-tier or Business Premium equivalents), and the gap is configuration and monitoring rather than new products. An audit of the current tenant is the cheapest first step. Q: Can you work alongside our existing IT technician or support company? A: Yes - the co-managed model fits education well: your team or incumbent keeps day-to-day control while AMVIA covers security monitoring, incident response and the specialist work a small team can't staff. The boundary is agreed explicitly up front. --- # Cybersecurity for UK Recruitment Agencies URL: https://amvia.co.uk/cybersecurity/industries/recruitment Last updated: 2026-08-28 Cybersecurity for recruitment agencies is the layered protection of the candidate and client data - CVs, passports, DBS checks, bank details - that agencies hold at scale, plus the ATS, email and devices that handle it. AMVIA delivers it as one security-first, Microsoft-certified provider built around how recruiters actually work. Recruitment is a data business before it is a people business. Every placement leaves a trail of identity documents, payroll details and client contracts sitting in your ATS, your inbox and your Microsoft 365 tenant. That is exactly the data criminals want. This page sits under our managed cybersecurity pillar and explains how AMVIA secures it. ## Why do recruitment agencies need specialist cybersecurity? Recruitment agencies hold a denser concentration of exploitable personal data than almost any other SME: passport scans, national insurance numbers, DBS certificates, bank details and full work histories. That makes a single breach both a fraud goldmine and a serious UK GDPR liability. 43% of UK businesses identified a cyber breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025), and agencies are squarely in scope. The structural risk is your workflow. Consultants live in email, move fast, and process high volumes of candidate and client messages - the ideal cover for impersonation. Your ATS and CRM concentrate years of records behind logins that are too often protected by a password alone. The UK's National Cyber Security Centre is clear that small organisations holding personal data are now routine targets, not collateral. - Dense personal and special-category data (DBS checks, ID documents) - High-volume email - perfect camouflage for phishing and BEC - Cloud ATS/CRM platforms holding records at scale - Remote and hybrid consultants on laptops and mobiles - Data-controller status under UK GDPR with hard reporting deadlines ## How does AMVIA protect a recruitment agency? AMVIA runs your security as a single accountable service: 24/7 monitoring, email defence, endpoint protection and Microsoft 365 hardening, configured around your ATS and the way your consultants work. You get one provider, security-first, with Microsoft-certified engineers - not a stack of disconnected tools you have to manage yourself. | | Layer | What it does for a recruiter | AMVIA service | Threat detection | 24/7 monitoring of endpoints, email and cloud, with real-time response | Managed Detection & Response | Email security | Stops phishing, impersonation and invoice fraud in high-volume inboxes | Email security | Devices | Protects consultant laptops and phones, including remote workers | Endpoint security | Microsoft 365 | Hardens identity, access and configuration across your tenant | Microsoft Defender for Business | Compliance | Technical controls that support UK GDPR obligations | GDPR cybersecurity | People | Phishing simulations and training for consultants and back office | Phishing simulation training Our monitored detection is built on Microsoft Defender for Endpoint, watched by AMVIA's in-house 24/7 SOC - not handed to an anonymous third party. Email and network filtering use the Barracuda suite. That is the whole stack: Microsoft and Barracuda, run by one team. ## How does business email compromise target recruitment agencies? Business email compromise (BEC) is the standout threat for recruiters because money and identity both move by email. Attackers impersonate a client to redirect an invoice, or impersonate a candidate to change the bank details on a payroll run. The volume of temp and contract email gives them cover to blend in. overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report). The defences that actually work are impersonation-aware email security plus a hard human rule: never change bank details on an email instruction alone - verify on a known phone number. AMVIA configures the first and trains your team on the second. ## What does a breach actually cost a recruitment agency? The financial exposure runs in two directions: the breach itself and the regulator. £3.29M average cost of a data breach for UK businesses (IBM Cost of a Data Breach 2025) captures the operational hit - downtime, recovery, lost placements and client churn. The regulatory hit is separate and can be larger. Under UK GDPR, the maximum fine is £17.5M (or 4% of global turnover, whichever is higher), and you must report a qualifying personal-data breach to the ICO within 72 hours of becoming aware of it. For an agency holding candidate identity documents, that clock is unforgiving - which is why tested detection and a rehearsed response plan matter more than any single tool. ## In-house tools vs a managed security partner Most agencies start with the security baked into Microsoft 365 and assume it is enough. It is a foundation, not a finished defence. The gap is monitoring and response - someone watching, 24/7, who acts when an alert fires. | | | DIY in-house | AMVIA managed | Monitoring | Office hours, best-effort | 24/7 SOC, real-time | Email/BEC defence | Default filtering | Impersonation-aware, tuned | Microsoft 365 | Often unhardened | Hardened to Microsoft baselines | GDPR readiness | Ad hoc | Documented controls, breach plan | Accountability | Spread across staff | One provider, one contract ## Recruitment agency security checklist Essential controls for a UK recruitment business, in priority order: - MFA on all email, ATS and cloud accounts (the single highest-impact control) - Impersonation-aware email security with payment-change verification - Endpoint protection on every consultant laptop and mobile - Encrypted storage and transfer of candidate documents - Role-based access limiting who can bulk-export the ATS - GDPR-compliant retention and deletion for data no longer needed - A tested incident response and 72-hour breach-notification plan AMVIA is certified to Cyber Essentials Plus and serves 1,200+ UK businesses, as one Microsoft Solutions Partner for Modern Work, Security and Infrastructure. ## Frequently asked questions Q: What GDPR obligations do recruitment agencies have for candidate data? A: Recruitment agencies are data controllers for candidate and client personal data and must comply with UK GDPR. That means a lawful basis for processing CVs and contact details, a processing register, retention and deletion policies for data no longer needed, and notifying the ICO within 72 hours of a qualifying breach. DBS checks and ID documents are special-category data with stricter handling duties. Q: How does AMVIA secure cloud-based ATS platforms? A: We secure ATS and CRM platforms with MFA on every account, role-based access that limits who can see and export candidate data, regular review of third-party integrations and sharing permissions, and monitoring for unusual bulk exports. We also check that a data processing agreement is in place with the vendor under UK GDPR and fold the platform into your 24/7 monitoring. Q: What makes recruitment databases attractive to cybercriminals? A: They hold passport copies, national insurance numbers, bank details, DBS certificates and salary data - a complete identity-fraud kit, stored at scale in cloud ATS and CRM systems. A breach affecting candidate data carries both heavy GDPR liability, with a maximum fine of £17.5M, and lasting reputational damage with candidates and client employers alike. Q: How do we stop payroll and invoice fraud by email? A: Combine technical and human controls. Impersonation-aware email security flags spoofed clients and candidates, while a non-negotiable rule prevents staff changing bank details on an email instruction alone - they verify on a known phone number. Given overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), this pairing is the most cost-effective defence a recruiter can deploy. Q: Does AMVIA support remote and hybrid recruitment teams? A: Yes. Consultants working from home or client sites are protected the same as office staff: endpoint security on every laptop and mobile, hardened Microsoft 365 identity and conditional access, and the same 24/7 SOC monitoring. Remote working widens the attack surface, so device-level protection and strong identity controls do the heavy lifting. Q: How quickly can AMVIA improve our security posture? A: We start with a free security audit that maps your current ATS, email and Microsoft 365 configuration against the controls above. Quick wins - MFA enforcement, email hardening, endpoint deployment - typically land within days, while deeper monitoring and GDPR documentation follow on an agreed plan. You see the gaps before you commit to anything. --- # Microsoft 365 Security: Audit & Hardening for UK Businesses URL: https://amvia.co.uk/microsoft-365-security Last updated: 2026-03 Microsoft 365 security is the work of configuring, hardening and monitoring the security controls inside your M365 tenant - MFA, Conditional Access, Microsoft Defender, DLP and backup - because the platform ships set for convenience, not protection. AMVIA audits, fixes and manages all of it. One provider. Security-first. Microsoft-certified. ## What is Microsoft 365 security and why does it matter? Microsoft 365 security covers the configuration, management and ongoing monitoring of the security controls built into the M365 platform. Out of the box, M365 is not secure - it ships with conservative defaults designed to avoid disrupting workflows. Securing a tenant means enforcing MFA, deploying Conditional Access, configuring Defender and adding real backup. The uncomfortable reality is that the tools are already in your licence; they are just switched off or left on baseline settings. In AMVIA's own tenant assessments, 85% of UK businesses using Microsoft 365 have at least one critical misconfiguration - most commonly missing MFA enforcement or legacy authentication left enabled. Microsoft itself reports that 99% of account compromise attacks can be blocked by enforcing MFA (Microsoft Security). If you want a single technician-led pass over your environment first, start with a Microsoft 365 security audit - it maps every gap before anyone changes a policy. ## What does AMVIA's Microsoft 365 security service include? AMVIA audits, configures and manages the security of your Microsoft 365 environment so the tools you already pay for work as hard as they should. Every engagement starts with a baseline assessment, then a prioritised remediation plan, then ongoing management - not a one-off project that drifts back to insecure within months. Core elements of the service: - Microsoft 365 security audit - full tenant review against Microsoft and NCSC baselines - Conditional Access configuration - the policy engine that gates every sign-in - Microsoft Defender for Business management - endpoint detection and response, tuned and monitored - MFA enforcement across all users - not just administrators - Data Loss Prevention (DLP) policies - rules that stop sensitive data leaving the tenant - Microsoft 365 backup and recovery - third-party point-in-time backup Microsoft does not provide For organisations that want the whole tenant run for them rather than just secured, our managed Microsoft 365 service layers day-to-day administration on top of the security baseline. ## Why is Microsoft 365's default configuration not secure? Microsoft 365 prioritises usability over security, so a fresh tenant leaves several doors open. The platform assumes you will harden it - it does not do that for you. The most common gaps are predictable, and attackers know exactly where to look. Default-tenant weaknesses we find repeatedly: - MFA not enforced - users sign in with just a username and password - Legacy authentication protocols enabled - these bypass MFA entirely - No Conditional Access policies - any device from any location can connect - Defender for Office 365 anti-phishing left on default settings - No DLP policies - sensitive files shared externally without restriction - Admin accounts unprotected by Privileged Identity Management (PIM) - No third-party backup - Microsoft's retention is not a backup This is not a Microsoft fault so much as a configuration responsibility. The UK Government's Cyber Security Breaches Survey found only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26) (gov.uk) - the single control that blocks the overwhelming majority of account takeovers. ## How do Microsoft 365 licence tiers compare on security? Your licence tier decides which security tools you can switch on. Business Basic and Standard give you almost nothing beyond basic mail filtering; Business Premium is the first tier with a genuine security stack. The table below shows what each tier actually includes. | | Tier | Price | Email security | Defender for Business | Conditional Access | Intune MDM | Microsoft 365 Business Basic | £4.60/user/month | EOP basic filtering | No | No | No | Microsoft 365 Business Standard | £9.60/user/month | EOP basic filtering | No | No | No | Microsoft 365 Business Premium | £16.90/user/month | Defender for Office 365 P1 | Yes (up to 300 devices) | Yes (Entra ID P1) | Yes - Microsoft 365 Business Basic (£4.60/user/month) - Exchange Online, Teams, SharePoint and OneDrive with Exchange Online Protection only. No advanced threat protection. Not a security baseline for most businesses. - Microsoft 365 Business Standard (£9.60/user/month) - adds the Office desktop apps but does not upgrade the security stack. Third-party email security and MDM strongly recommended. - Microsoft 365 Business Premium (£16.90/user/month) - Defender for Business, Defender for Office 365 Plan 1, Entra ID Premium P1 (Conditional Access and risk-based MFA), Microsoft Intune and basic DLP. This is the tier we recommend as a security baseline. If you are weighing the jump, Premium's Defender for Business covers endpoint detection and response for up to 300 devices, while the enterprise Defender for Endpoint Plan 2 removes the device limit and adds advanced hunting and Sentinel integration (Microsoft 365 plans). ## Does Microsoft back up your Microsoft 365 data? No - and this is one of the most misunderstood facts in M365. Microsoft provides short-term retention (a 30-day recycle bin, 14-day Teams retention), but that is not a backup. If data is permanently deleted, corrupted or lost beyond the retention window, Microsoft cannot restore it for you (Microsoft Learn). AMVIA deploys third-party M365 backup covering Exchange Online, SharePoint, OneDrive and Teams, with point-in-time recovery and retention periods of 1–5 years. Under the shared responsibility model, protecting your data is your job, not Microsoft's. ## How do you measure Microsoft 365 security posture? Microsoft Secure Score is a free tool in the M365 security portal that scores your tenant configuration against Microsoft's recommendations, with improvement actions ranked by impact and effort. It is the cleanest single number to track whether your security is getting better or quietly drifting backwards. AMVIA establishes a Secure Score baseline during the initial audit, then tracks it monthly. Most AMVIA clients improve their Microsoft Secure Score by 20–40 percentage points within the first three months - most of that from enforcing MFA, killing legacy authentication and deploying Conditional Access. ## How much does Microsoft 365 security management cost? AMVIA's Microsoft 365 security management - covering the initial audit, Conditional Access configuration, Defender management, DMARC setup, DLP policies and ongoing Secure Score monitoring - starts from £5 per user per month for tenants on Business Premium. That sits on top of your Microsoft licence cost, not instead of it. There is no per-incident surprise billing and no lock-in to a telecoms bundle: you get a single accountable provider, Microsoft-certified engineers, and a security baseline you can audit at any time. ## Frequently asked questions Q: Is Microsoft 365 secure by default? A: No. Microsoft 365 ships with conservative defaults built for usability, not protection. Most tenants lack MFA enforcement, leave legacy authentication enabled and have no Conditional Access policies. Microsoft Secure Score typically shows most businesses below 50% on a first assessment, which is why an audit before any other work is the right starting point. Q: What does Microsoft Defender for Business cover? A: Microsoft Defender for Business, included in Microsoft 365 Business Premium, provides endpoint detection and response, vulnerability management, attack surface reduction and automated investigation and remediation for up to 300 devices. It is designed for SMEs with simplified management, making it a strong fit for businesses with 10–300 staff that want enterprise-style protection without enterprise complexity. Q: What is the difference between Business Premium and Business Standard for security? A: Business Standard (£9.60/user/month) gives you the Office apps and basic email filtering but minimal security tooling. Business Premium (£16.90/user/month) adds Defender for Business, Conditional Access through Entra ID Premium P1, Microsoft Intune and Defender for Office 365. For most UK SMEs, Premium is the realistic security baseline and the tier AMVIA recommends. Q: Does Microsoft 365 include a backup? A: No. Microsoft provides short-term retention - a 30-day recycle bin and 14-day Teams retention - but this is not a backup. Once data passes the retention window or is permanently deleted, Microsoft cannot recover it. AMVIA deploys third-party M365 backup with point-in-time recovery and 1–5 year retention across Exchange, SharePoint, OneDrive and Teams. Q: How much does Microsoft 365 security management cost? A: AMVIA's M365 security management - initial audit, Conditional Access configuration, Defender management, DMARC setup, DLP policies and Secure Score monitoring - starts from £5 per user per month for tenants on Business Premium. That is on top of your Microsoft licence, with no per-incident billing and no long lock-in. Q: Why use AMVIA instead of managing M365 security in-house? A: We secure and manage Microsoft 365 for 1,200+ UK businesses whose Microsoft 365 environments are managed and secured by AMVIA. In-house teams can configure these controls, but keeping them current as Microsoft changes defaults and attackers change tactics is a full-time job. You get Microsoft-certified engineers, an auditable baseline and one accountable provider rather than a stack of disconnected tools. --- # Managed Microsoft 365 Service for UK SMEs URL: https://amvia.co.uk/microsoft-365-security/managed-m365-service Last updated: 2026-08 A managed M365 service is the outsourced administration and security of your Microsoft 365 tenant: licensing, user provisioning, security policies, backup and day-to-day support handled by a specialist team. AMVIA runs and hardens M365 for 1,200+ UK businesses - one accountable provider, security-first, backed by Microsoft Solutions Partner status for Modern Work, Security and Infrastructure (Azure). Most SMEs buy Microsoft 365 and never touch the security settings again. That gap is where breaches happen. AMVIA closes it by treating your tenant as part of your wider Microsoft 365 security posture - not a licence line on an invoice. We configure, monitor and improve your environment continuously, so your in-house team can focus on the business instead of policy admin. ## What's included in AMVIA's managed M365 service? Our managed M365 service covers the full lifecycle of your tenant: licence procurement and right-sizing, security configuration, identity and access control, backup, and ongoing support. You get a single team accountable for keeping Microsoft 365 working and secure. - Licence management - procurement, right-sizing and quarterly reviews so you only pay for what people use. - Security hardening - MFA enforcement, conditional access, legacy authentication disabled, and anti-phishing rules. We deploy Microsoft Defender for Business for endpoint protection. - Identity and access - joiner/mover/leaver processes, role-based access, and multi-factor authentication setup across every account. - Backup and recovery - third-party backup of Exchange, SharePoint, OneDrive and Teams, because Microsoft's shared-responsibility model does not cover your data retention. - Monitoring and support - 24/7 monitoring with critical issues responded to within one hour, plus a named account team. ## How does AMVIA manage your Microsoft 365 tenant? We work in four stages: review, optimise, manage and report. The first step is always a full audit of your existing configuration against Microsoft and NCSC best practice, so every later change is evidence-led rather than guesswork. 1. Tenant review - we run a Microsoft 365 security audit of your licensing, identity, sharing and security settings, scored against Microsoft Secure Score. 2. Optimisation - licences are right-sized, security baselines applied, and device policies set through Microsoft Intune device management. 3. Proactive management - we handle provisioning, licence changes, security alerts and configuration updates on your behalf. 4. Reporting - monthly reports on security posture, incidents handled and recommended improvements, reviewed with your account team. ## Why do UK SMEs need a managed M365 service? Because the default Microsoft 365 setup is not secure, and attackers know it. In 2025, 43% of UK businesses reported a cyber breach or attack, according to the Government's Cyber Security Breaches Survey 2025. The most common entry point was phishing - overwhelmingly aimed at email and identity, which both live inside Microsoft 365. A misconfigured tenant carries real cost. The average disruptive breach costs a UK business around £3,550. Identity-based attacks succeed when MFA is missing, legacy protocols stay open, or admin accounts are over-privileged - all of which a managed service fixes and keeps fixed. The National Cyber Security Centre lists exactly these controls as foundational. Managed M365 is how you maintain them without a full-time M365 specialist on payroll. ## In-house vs managed Microsoft 365: which is right? For most SMEs with 10–500 staff, a managed service delivers specialist security coverage that an internal generalist cannot match week to week. Microsoft changes M365 constantly; keeping pace is a job, not a task. The table below shows where the responsibility sits. | | Capability | In-house (typical SME) | AMVIA managed M365 | Tenant security hardening | Ad hoc, set once | Continuous, baselined | Licence optimisation | Rarely reviewed | Quarterly reviews | MFA & conditional access | Often partial | Enforced tenant-wide | Backup beyond Microsoft's retention | Frequently missing | Included | Critical issue response | Best effort | Within one hour | 24/7 monitoring | No | Yes | Microsoft Secure Score tracking | Manual or none | Reported monthly For deeper security operations beyond the tenant, AMVIA also delivers managed cybersecurity - endpoint detection, monitoring and incident response - under the same roof. ## How much does a managed M365 service cost? The cost has two parts: Microsoft's licence fees, and AMVIA's flat monthly management fee per user (shown in the pricing table on this page). Microsoft revises UK licence pricing periodically, so we don't restate figures here - check Microsoft's current UK pricing. Functionally: Business Basic covers web and email only; Business Standard adds desktop Office apps; Business Premium adds the built-in security stack - Defender for Business, Intune and conditional access - that most security-conscious SMEs need. See our Business Premium vs Standard breakdown. Licences are billed at cost as a pass-through - AMVIA does not mark them up. We right-size licences quarterly so you only pay for seats people actually use, which for many clients offsets much of the management fee. ## Is your tenant ready for Microsoft 365 Copilot? Copilot surfaces whatever a user can already access - so oversharing, stale permissions and unlabelled sensitive data become visible the day it switches on. AMVIA delivers Copilot readiness assessments and the data-governance work that safe adoption depends on: Microsoft Purview sensitivity labels, SharePoint permission hygiene, access reviews and oversharing controls. Readiness starts with the same evidence-led review as our Microsoft 365 security audit. For Copilot licensing and pricing, see Microsoft's official Copilot pages. ## Why choose AMVIA for managed Microsoft 365? AMVIA is a security partner first and a Microsoft partner second - that order matters. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status for Modern Work, Security and Infrastructure (Azure), and our engineering team operates from Sheffield with deep knowledge of UK compliance. - Security-first by default - every tenant is hardened, not just provisioned. - One accountable provider - licensing, security, backup and support from a single team. - Proven scale - we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. - Microsoft Solutions Partner - designations held for Modern Work, Security and Infrastructure (Azure), delivered by a UK-based team, not an offshore queue. - Fast response - critical issues answered within one hour by phone, email or portal. AMVIA supplies that specialist expertise as a service. One credential worth asking any prospective provider about: AMVIA is a Microsoft MSSP (managed security service provider) and a member of the Microsoft Intelligent Security Association (MISA), as well as a Microsoft Solutions Partner. In practice that means the people configuring Defender, Conditional Access and Intune for your tenant work to Microsoft’s security partner bar - not a generalist’s best guess - and it’s the same team that runs our managed IT support service day to day. ## Frequently asked questions Q: What does a managed Microsoft 365 service include? A: Outsourced administration and security of your tenant: licensing management, user provisioning and leavers, security policies, backup oversight and day-to-day admin - so M365 is run deliberately rather than accumulating settings nobody owns. Q: How much does managed Microsoft 365 cost? A: AMVIA's management fee is from £12 per user per month - management and configuration only, with no hidden extras. Microsoft licence costs are separate and billed at cost as a pass-through; check Microsoft's official UK pricing for current licence fees. Q: We already pay for Microsoft 365 - why does it need managing? A: Because the licence isn't the configuration. Most tenants run with default security settings, unused licences, and admin sprawl - the platform's strong controls (MFA enforcement, conditional access, data protection) only protect you once someone switches them on and keeps them right. Q: Can you sort out our licensing? A: Usually with savings: right-sizing tiers to what each user actually needs, reclaiming licences from leavers, and consolidating add-ons routinely offsets a chunk of the management fee. The audit that starts every engagement shows the number before you commit. Q: Do I still need backup if I have Microsoft 365? A: Yes. Microsoft's shared-responsibility model protects its infrastructure, not your data retention - accidental deletion, malicious wiping and retention gaps are your problem. We include third-party backup of Exchange, SharePoint, OneDrive and Teams as standard. Q: Can you take over our existing Microsoft 365 tenant? A: Yes - most clients come to us with an existing tenant. We start with a full configuration and security audit against Microsoft and NCSC best practice, then fix what the audit finds. No migration is required to move to managed service. Q: Is my business ready for Microsoft 365 Copilot? A: Only if your data governance is. Copilot exposes whatever users can already access, so oversharing and unlabelled sensitive data become immediate risks. AMVIA runs Copilot readiness assessments covering Purview sensitivity labels, permission hygiene and access reviews before you switch it on. Q: What is the difference between managed Microsoft 365 and managed IT support? A: Managed M365 covers your Microsoft 365 tenant - licensing, identity, security configuration, backup and M365 support. Managed IT support covers your wider estate: devices, network, servers and general helpdesk. Many AMVIA clients combine both under one contract. --- # Microsoft Defender for Business: Setup and Managed Service URL: https://amvia.co.uk/microsoft-365-security/microsoft-defender-for-business Last updated: 2026-03 Microsoft Defender for Business is Microsoft's endpoint security product for small and mid-sized firms, bundling next-generation antivirus, endpoint detection and response (EDR), firewall control and attack surface reduction into one console. AMVIA configures it, tunes the policies and monitors every alert through our in-house UK SOC, so threats are handled before they reach you. It is one of the most capable controls inside Microsoft 365 security, and it only earns its keep when someone watches it. That is the gap most SMEs miss: the licence gives you the engine, not the driver. One provider. Security-first. Microsoft-certified. ## What is Microsoft Defender for Business? Microsoft Defender for Business is a dedicated endpoint security suite built for organisations with up to 300 users. It delivers enterprise-grade protection - next-gen antivirus, EDR, threat and vulnerability management, automated investigation, and attack surface reduction - from a single cloud console, designed so smaller teams get capability previously reserved for large enterprises (Microsoft Learn). The 300-user cap is a hard product boundary. Above it, organisations move to Defender for Endpoint Plan 2. Below it, Defender for Business gives most UK SMEs the strongest endpoint control they can buy without enterprise licensing. - Next-generation antivirus - behaviour-based malware blocking, not just signatures - Endpoint detection and response (EDR) - detects, investigates and contains active attacks - Threat and vulnerability management - surfaces unpatched, exploitable weaknesses - Attack surface reduction (ASR) - rules that block common ransomware and macro attack paths - Automated investigation and remediation - self-heals routine threats without an analyst ## What's included in AMVIA's managed Defender service? AMVIA's managed Defender for Business service covers the full lifecycle: design, deployment, tuning and 24/7 monitoring. We do not just switch the licence on - we configure ASR rules, set automated remediation, investigate every EDR alert through our UK SOC, and report monthly on what we caught and fixed. - Security baseline - we assess your current endpoint posture and design Defender policies to your risk profile and compliance needs - Deployment - Defender is rolled out across endpoints via Microsoft Intune or Group Policy, with ASR rules enabled - Tuning and testing - detection sensitivity is calibrated and automated remediation validated against test scenarios - Managed monitoring - our SOC investigates alerts, contains confirmed threats and escalates within an hour for critical issues - Monthly reporting - clear posture reporting on detections handled and recommended improvements This sits alongside our broader managed cybersecurity practice, so endpoint protection is never a silo - it feeds the same monitoring and response team that watches your email, identity and network. ## Why do UK SMEs need managed Defender for Business? Endpoints are where most breaches land. 43% of UK businesses identified a cyber breach or attack in the past year, and phishing was by far the most common vector (DSIT Cyber Security Breaches Survey 2025). Defender for Business is built to stop exactly those attacks - but only if its alerts are watched. An unmonitored EDR tool is a smoke alarm with no one home. Defender will detect a ransomware precursor at 2am; whether anything happens next depends on who is watching. That is the difference between a licensed control and a managed service. - Around 85% of breached UK organisations reported phishing as an attack type - The average cost of the most disruptive breach to affected UK businesses was around £3,550 Defender for Business directly counters these: ASR rules block the macro and script paths phishing relies on, EDR catches ransomware behaviour early, and AMVIA's SOC turns a detection into a contained incident. ## Licensed vs AMVIA-managed Defender: what's the difference? The licence and the managed service are not the same purchase. Microsoft sells you the technology; AMVIA runs it. The table below shows what changes when a UK SOC sits behind the console. | | Capability | Defender licence only | AMVIA managed Defender | Antivirus + EDR engine | Included | Included | ASR rules configured to your risk | DIY | Configured and maintained | Alerts investigated 24/7 | No - your team | Yes - AMVIA UK SOC | Confirmed threats contained | Manual, in hours | Within the hour for critical issues | Monthly posture reporting | None | Included | Tuning to cut false positives | DIY | Ongoing Most SMEs do not have an analyst free at 2am. That is the value AMVIA adds - the same logic behind layering Defender with managed detection and response when risk is elevated. ## How much does Microsoft Defender for Business cost? Defender for Business is included at no extra cost in Microsoft 365 Business Premium, or available as a standalone add-on at around £2–3 per user per month (Microsoft list price, 2026) for firms on Business Basic or Standard. AMVIA's management fee sits on top of the licence and is quoted per environment after a short assessment. For most UK SMEs already paying for Microsoft 365, the cheapest path to strong endpoint security is moving to Business Premium rather than buying the add-on separately - we model both before recommending one. See our Business Premium vs Standard comparison for the licensing trade-off, or book a Microsoft 365 security audit to confirm what you already own. Microsoft's published UK list prices are Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month, ex VAT on an annual plan (Microsoft 365 UK pricing). ## Why choose AMVIA for Microsoft Defender for Business? AMVIA manages security and IT for 1,200+ UK businesses across legal, finance, healthcare and professional services. We are a security partner, not a telecoms reseller - Defender is configured by Microsoft-certified engineers and watched by our own SOC, not subcontracted out. - Cyber Essentials Plus certified and a Microsoft Solutions Partner (Modern Work, Security, Infrastructure) - Sheffield-based UK SOC - engineers who understand UK compliance and the threats facing British SMEs - Sub-one-hour response to critical issues, by phone, email and portal, with a named account team - 1,200+ UK businesses protected ## Frequently asked questions Q: What is Microsoft Defender for Business? A: Microsoft's endpoint security product for small and mid-sized firms: next-generation antivirus, endpoint detection and response (EDR), firewall control and threat analytics in one licence. It's serious capability - the honest caveat is that it needs configuring and watching to deliver it. Q: Is Defender for Business included in Microsoft 365? A: It's included in Microsoft 365 Business Premium (£16.90/user/month ex VAT on annual terms) and available standalone. If you already pay for Business Premium, you may already own strong endpoint security you haven't switched on properly - an audit tells you in a day. Q: Is Defender for Business good enough, or do we need something else? A: For most SMEs the product is genuinely competitive - the gap is usually operations, not technology: policies left on defaults, alerts nobody triages. Managed properly (configured, tuned, monitored 24/7 on Enterprise plans), Defender is the core of a credible endpoint defence. Q: Who watches the Defender alerts? A: That's the deciding question. Defender generates detections; someone must investigate and act on them. AMVIA runs Defender for Business as a managed service - deployment, policy hardening, and alert triage - so the licence you're paying for becomes protection rather than a dashboard. --- # Microsoft Intune: Managed Device Security for UK Businesses URL: https://amvia.co.uk/microsoft-365-security/microsoft-intune Last updated: 2026-03 Microsoft Intune is a cloud-based endpoint management platform that controls which devices reach your Microsoft 365 data and enforces security policies on every laptop and phone - company-owned or personal. AMVIA configures and runs Intune for you end to end: one provider, security-first, Microsoft-certified engineers. If your staff log in from home laptops, personal phones and company machines, Intune is how you stop an unpatched or unencrypted device from quietly becoming your weakest point. It is part of our wider Microsoft 365 security practice, and it works hand in glove with Conditional Access policies to block non-compliant devices before they ever touch your email or files. ## What is Microsoft Intune and what does it do? Intune is Microsoft's endpoint management service inside the Microsoft 365 cloud. It sets the minimum security standard a device must meet, pushes settings such as disk encryption and updates automatically, deploys approved apps, and lets you wipe a lost device remotely. In short: it makes every device prove it is safe before it gets your data. The platform covers Windows, macOS, iOS and Android, so a single console manages the whole estate. Microsoft documents the full capability set in its Intune technical documentation. ## What's included when AMVIA manages your Intune? We do not just switch Intune on and hand you a console. We design the policies, enrol the devices, and run the ongoing monitoring and reporting. A managed Intune deployment from AMVIA covers five core areas. - Device compliance policies - define the minimum standard (OS version, encryption, password rules) a device must meet to access company resources. Devices on outdated, unpatched operating systems fail compliance and are blocked. - Configuration profiles - push settings to devices automatically, with no user action: BitLocker full-disk encryption on Windows, and Windows Update settings that keep patching on schedule. - Application deployment - install approved apps silently, including security tools such as Microsoft Defender for Business, so every managed device is protected from day one. - Remote wipe and retirement - factory-reset a lost or stolen company device; on personal (BYOD) devices, a selective wipe removes only company data and leaves personal content untouched. - Autopilot zero-touch deployment - ship a new device straight to an employee; it configures itself, joins Microsoft Entra ID, and installs its apps on first connection. ## How does Intune work with Conditional Access? Intune reports each device's compliance state to Microsoft Entra ID. Conditional Access then checks that state at sign-in: a device that is enrolled and compliant gets in; one with an outdated OS or missing encryption is blocked automatically until the issue is fixed. The two systems together enforce a practical zero-trust posture. This is why Intune rarely stands alone. We deploy it alongside Conditional Access and MFA across Microsoft 365 so that identity, device health and access decisions are joined up rather than configured in isolation. ## Why do UK SMEs need managed device control? Most breaches start at the edge - an unpatched laptop, a personal phone with no encryption, or a device that should have been wiped months ago. Intune closes those gaps centrally instead of relying on staff to self-manage. The UK threat picture makes the case plainly. - 43% of UK businesses experienced a cyber breach in 2025 - DSIT Cyber Security Breaches Survey 2025. - £3,550 is the average cost of a disruptive breach for UK businesses - DSIT Cyber Security Breaches Survey 2025. For practical guidance on baseline device security, the NCSC's device security guidance is the UK reference standard, and Intune is the mechanism that enforces those baselines at scale. ## In-house Intune vs AMVIA-managed Intune Intune is powerful, but it is only as good as the policies behind it. The difference between a licence and a managed service is who owns the configuration, the patching and the monitoring. | | Area | Self-managed in-house | AMVIA-managed Intune | Policy design | DIY, often default settings | Designed to your risk and compliance needs | Device enrolment | Manual, per device | Autopilot zero-touch + bulk enrolment | Patch & OS updates | Ad hoc, easily missed | Enforced and monitored monthly | Lost-device response | Reactive, if noticed | Remote wipe on demand | Reporting | None or manual | Monthly fleet-health reporting | Time to value | Weeks of internal learning | Operational within 1–2 weeks ## How does AMVIA deploy Intune, and how long does it take? We run a four-stage rollout and have Intune operational within 1–2 weeks for a typical estate. The stages are: planning and design (we assess your devices and define compliance policies), tenant configuration (enrolment profiles, compliance, Conditional Access, app deployment), device enrolment (via Autopilot or manual), then ongoing management and monthly reporting. For a 50-user business with a straightforward device estate, we complete deployment and configuration in five to ten business days, including compliance policies, configuration profiles and Conditional Access integration. Autopilot setup for future device procurement is included as standard. Once live, Intune pairs naturally with Microsoft 365 backup and centralised mobile device management for phones and tablets. ## Why choose AMVIA for Microsoft Intune? Our engineering and support team operates from Sheffield, so you get UK-based engineers who understand UK compliance and infrastructure. AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status, manages IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services, and responds to critical issues in under one hour. One provider, security-first, Microsoft-certified. ## Frequently asked questions Q: What is Microsoft Intune? A: A cloud-based endpoint management platform that controls which devices can reach your Microsoft 365 data and enforces security policies on every laptop and phone - company-owned or personal. It's how you make 'only healthy, compliant devices touch our data' actually true. Q: Do we need Intune if staff use their own devices? A: That's precisely when you need it. Intune separates and protects business data on personal devices - enforcing encryption and PIN policies, and wiping the work container if the device is lost - without touching personal photos or apps. BYOD without management is unmanaged risk. Q: What happens when a laptop or phone is lost? A: With Intune enrolled: the device is locked and business data wiped remotely within minutes, and access tokens are revoked - so a lost device stays an inconvenience rather than becoming a breach (average most-disruptive breach cost: £3,550, DSIT 2025). Q: Is Intune hard to set up? A: The platform is included in many Microsoft 365 plans, but policy design is where deployments succeed or fail - too loose and it's decoration, too strict and staff revolt. AMVIA designs, deploys and manages Intune as part of its Microsoft 365 service, tuned to how your team actually works. --- # Microsoft 365 Security Audit Service URL: https://amvia.co.uk/microsoft-365-security/m365-security-audit Last updated: 2026-03 An M365 security audit is a structured review of your Microsoft 365 tenant against Microsoft and CIS security benchmarks. It checks MFA, Conditional Access, legacy authentication, sharing permissions, admin roles and Defender settings, then hands you a prioritised fix list. AMVIA runs the audit and fixes what it finds - one provider, security-first. Most tenants are configured for productivity, not defence. Default settings leave gaps that attackers know how to use, and those gaps rarely show up until something goes wrong. The audit turns "we think we're secure" into a ranked list of exactly what is wrong and what to do about it. AMVIA's part of the Microsoft 365 security practice - UK engineers who configure these tenants every day. ## What does an M365 security audit cover? An M365 security audit reviews every control that decides who gets into your tenant and what they can do once inside. We assess identity, data, devices and apps against Microsoft's own benchmarks, then score the risk of each gap so you fix the dangerous ones first. The audit examines: - Identity - MFA enforcement, Conditional Access policies, legacy authentication, and admin role assignments. - Data - external sharing settings, data loss prevention rules, and mailbox delegation. - Devices - Intune enrolment, compliance policies, and endpoint protection coverage. - Threat protection - Microsoft Defender for Business configuration, safe links, and anti-phishing policies. Weak authentication is the single most common finding. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26) (gov.uk Cyber Security Breaches Survey 2025), and most audits surface MFA gaps alongside dozens of other misconfigurations. ## How does the M365 security audit work? The audit runs in four stages over a few days, with no downtime for your staff. We start read-only, so nothing changes in your tenant until you have seen the findings and agreed what to fix. 1. Tenant access - we connect with read-only access to review configuration, policies and security settings. 2. Security assessment - we check Microsoft Secure Score, Conditional Access, MFA, DLP, sharing policies and admin configuration against best practice. 3. Risk report - you receive a prioritised report with risk ratings, plain-English explanations and specific remediation steps. 4. Remediation - we walk your team through the findings and either implement fixes directly or hand off clear instructions. Because the assessment phase is read-only, it is non-disruptive - no policies change and no users are affected until remediation is scheduled. ## Why do UK SMEs need an M365 security audit? UK SMEs need an audit because Microsoft 365 is where the business actually lives - email, files, identities and Teams - and a single compromised account can reach all of it. Breaches are common and expensive, and most start with a credential or phishing gap an audit would have caught. In the last year, 43% of UK businesses experienced a breach or attack (DSIT 2025), with the average disruptive breach costing £3,550 (gov.uk Cyber Security Breaches Survey 2025). The NCSC's small business guidance is clear that turning on MFA and removing legacy access are among the highest-value steps you can take - exactly what the audit verifies. For broader threat context, AMVIA's managed cybersecurity team monitors these tenants 24/7. Microsoft also moves the goalposts. Defaults and features change often, so a configuration that was fine six months ago may now leave a gap - which is why audits work best as a recurring control, not a one-off. ## In-house review vs an AMVIA M365 security audit A busy internal IT team can check the obvious settings, but a benchmark-driven audit catches the gaps that defaults hide. The table below shows where a managed audit earns its place. | | Factor | In-house spot-check | AMVIA M365 security audit | Benchmark used | Ad hoc / memory | Microsoft Secure Score + CIS controls | Coverage | Visible settings only | Identity, data, devices, apps, Defender | Risk ranking | Rare | Every finding rated by impact | Remediation | DIY | Engineers fix or guide, fast | Recurrence | Often forgotten | Annual + quarterly critical reviews | Evidence trail | Minimal | Report supporting compliance needs The audit also gives you documentation you can show auditors and insurers - useful when you need to evidence good practice for Cyber Essentials or cyber insurance renewals. ## How much does an M365 security audit cost? Pricing depends on tenant size and licence mix, and AMVIA quotes a fixed fee with no lock-in. The assessment is read-only and time-boxed; remediation is scoped separately once you have seen the prioritised findings, so you only pay to fix what matters. Most organisations see a Secure Score increase of 30 to 50 points (a typical range across UK tenants we audit in 2026) after implementing audit recommendations, which is a measurable, repeatable way to show your security posture improving over time. For tenants that need ongoing control, the audit pairs naturally with our M365 hardening guide and MFA setup for Microsoft 365. ## Why choose AMVIA for your M365 security audit? AMVIA audits and secures Microsoft 365 for 1,200+ UK businesses across legal, finance, healthcare and professional services. We are a security partner, not a telecoms reseller - Microsoft-certified engineers who configure these controls daily and stand behind the fix. - Cyber Essentials Plus certified and a Microsoft Solutions Partner (Modern Work, Security and Infrastructure). - 1,200+ UK businesses secured, with critical issues responded to within one hour. - UK-based engineers who understand UK compliance and the controls insurers and regulators look for. - One accountable provider for the audit, the fixes and the ongoing monitoring. ## Frequently asked questions Q: What is a Microsoft 365 security audit? A: A structured review of your tenant against Microsoft and CIS security benchmarks: MFA coverage, conditional access, legacy authentication, admin roles, mail rules, sharing settings and licence-included protections you may not have switched on. Q: What does an M365 audit usually find? A: The same handful of gaps, almost everywhere: incomplete MFA coverage, legacy protocols still enabled, over-privileged admin accounts, external sharing wide open, and Business Premium security features paid for but never configured. The fix list is usually short and high-impact. Q: How long does the audit take? A: Days, not weeks - read-only access, benchmark review, then a prioritised report your team (or ours) can action. It's deliberately the lowest-friction way to find out whether the tenant you depend on is actually configured to protect you. Q: Is the audit worth it if we have an IT provider already? A: Yes - it's an independent check of configuration, not a criticism of anyone. With 43% of UK businesses breached or attacked in the past 12 months (DSIT 2025) and M365 the front door for most of them, a benchmark review is due diligence, not a luxury. --- # What Is Microsoft 365 Security? URL: https://amvia.co.uk/microsoft-365-security/what-is-m365-security Last updated: 2026-03 M365 security means configuring the protection Microsoft builds into Microsoft 365 - it is not switched on by default. Microsoft secures the cloud platform; you secure your users, devices and data on it. The right licence tier is Business Premium, and the highest-impact controls are MFA and blocking legacy authentication. One provider, security-first, Microsoft-certified. Most UK businesses assume Microsoft 365 is secure because Microsoft is a large, trusted vendor. That assumption is where the risk starts. This guide explains what Microsoft 365 security actually involves, which licence tier gives you real protection, and the controls every tenant needs before it is safe to rely on. ## What Does Microsoft 365 Security Actually Mean? Microsoft 365 security is the deliberate configuration of the security tools Microsoft provides, not an assumption that the platform is safe by default. There are two different things at play: the capabilities Microsoft builds into M365, and the configuration your business must apply to make them effective. Confusing the two is the most expensive mistake UK SMEs make. Microsoft invests heavily in securing its cloud infrastructure. The datacentres, networks and application platforms M365 runs on are well protected against infrastructure-level threats. But that does nothing to stop the attacks that actually cause damage: phishing that steals credentials, ransomware delivered by email, business email compromise that diverts payments, and breaches caused by misconfigured sharing. With 43% of UK businesses experiencing a cybersecurity breach in 2025 (Department for Science, Innovation and Technology), and 85% of breached businesses identifying phishing as the attack type (DSIT Cyber Security Breaches Survey 2025), the threats Microsoft's infrastructure security does not address are exactly the ones most likely to hit you. Under Microsoft's shared responsibility model, configuring those controls is the customer's job, not Microsoft's. ## Which Microsoft 365 Licence Tier Includes Real Security? The security tools you have depend entirely on your licence tier. Business Basic and Standard share the same limited security feature set; only Business Premium adds the stack a UK SME actually needs - Conditional Access, Defender for Business, Intune and advanced email protection. Paying more for Standard buys Office apps, not security. | | Licence tier | Price (ex VAT) | Security included | EDR / Conditional Access | Business Basic | £4.60 /user/mo | Exchange Online Protection, Security Defaults MFA, Defender Antivirus | No | Business Standard | £9.60 /user/mo | Same as Basic + desktop Office apps | No | Business Premium | £16.90 /user/mo | Defender for Business (EDR), Conditional Access (Entra ID P1), Intune, Defender for Office 365 P1, Information Protection | Yes Prices are Microsoft list prices per user per month, annual commitment, ex VAT (Microsoft 365 UK). The jump from Standard to Premium is the only step that adds meaningful protection, which is why we recommend Business Premium for any business that needs more than the bare minimum. ## What Does Microsoft Defender for Business Add? Microsoft Defender for Business, included in Business Premium, is an endpoint detection and response (EDR) tool that goes well beyond the basic Defender Antivirus built into Windows. Where antivirus matches known signatures, EDR adds behavioural detection, automated investigation and remediation, attack surface reduction rules, and threat hunting. Defender for Business monitors activity across every enrolled device, can isolate a compromised machine from the network automatically, and gives you one dashboard showing the security status of the whole organisation. For a UK business without its own security operations centre, it delivers enterprise-grade endpoint protection that would otherwise need a far more expensive standalone EDR product and dedicated staff to run it. ## Why Isn't Microsoft 365 Secure Out of the Box? Even on Business Premium, a freshly provisioned tenant is not secured. The tools are licensed but none are configured. Conditional Access policies do not exist until you create them, Defender for Business is not yet deployed to devices, Safe Links and Safe Attachments are off, legacy authentication that bypasses MFA is still active, and admin accounts hold permanent elevated privileges. A Basic or Standard tenant in its default state is more exposed still: no enforced MFA unless Security Defaults are switched on, no EDR, no device management and no advanced email security. The common attacks against UK businesses - phishing, credential theft, business email compromise and ransomware - routinely succeed against unconfigured tenants that properly configured Business Premium would have stopped. That gap between available capability and actual configuration is where most M365 security risk sits. ## Which Security Controls Does Every M365 Tenant Need? Every M365 tenant needs the same baseline regardless of size: enforced MFA, blocked legacy authentication, deployed EDR, hardened email and protected admin accounts. These controls close the vulnerabilities attackers exploit most often, and most can be configured in days rather than months. - MFA for all users - enforced via Conditional Access on Business Premium or Security Defaults on lower tiers. MFA blocks over 99% of credential-based account compromise attacks (Microsoft). It is the single highest-impact control available. See our MFA setup guide for Microsoft 365. - Legacy authentication blocked - protocols such as IMAP, POP3 and basic SMTP do not support MFA and are used to bypass it. Blocking them via Conditional Access removes the most common MFA bypass. - Defender for Business deployed - EDR on all Windows and Mac devices, with attack surface reduction rules enabled and managed centrally. - Email security hardened - anti-phishing policies with impersonation protection for executives and domains, plus Safe Links and Safe Attachments for email and Teams. - DMARC, DKIM and SPF configured - email authentication records that stop attackers spoofing your domain to phish your clients and suppliers. - Admin accounts protected with PIM - Privileged Identity Management replacing permanent admin rights with just-in-time elevation, approval and audit logging. - Audit logging enabled - essential for incident forensics, made more critical by the fact that only 25% of UK businesses have a formal incident response plan (DSIT 2025/26). ## How Does Microsoft Secure Score Measure Your Configuration? Microsoft Secure Score is a free tool in every tenant at security.microsoft.com that scores your configuration against Microsoft's recommended actions as a percentage. The industry average sits around 50% (2025 industry benchmarking), meaning the typical organisation has implemented only half the recommended controls; a score above 70% indicates a well-hardened environment. Secure Score gives an ordered list of improvement actions with impact ratings, so it is straightforward to prioritise the changes that matter most. We use it both as a baseline assessment for new clients and as an ongoing monitoring tool, reviewing the score quarterly so new Microsoft recommendations are assessed and applied where appropriate. ## How Does M365 Security Fit a Wider Cybersecurity Strategy? Microsoft 365 security is one layer of a broader strategy, not the whole of it. M365 covers identity (Entra ID and Conditional Access), endpoint (Defender for Business), email (Defender for Office 365) and data (Purview). Those controls should sit alongside network security, staff awareness training, an incident response plan, and backup and recovery - the connective tissue of managed cybersecurity. For businesses pursuing certification, a correctly configured Business Premium tenant supports several Cyber Essentials technical requirements, including access control, malware protection and secure configuration. We advise on M365 configuration in the context of compliance requirements and the wider security picture, so the platform reinforces your strategy rather than sitting in isolation. ## How Does AMVIA Manage Microsoft 365 Security? AMVIA manages Microsoft 365 security for UK businesses as part of a managed service: licence management to keep you on a security-capable tier, initial tenant hardening, ongoing Secure Score monitoring, Conditional Access policy management, and Defender for Business monitoring and incident response. Our security stack is Microsoft Defender plus the Barracuda suite, run by Microsoft-certified engineers. If you have M365 but the security configuration has never been reviewed, a Secure Score review is the right starting point - it identifies the highest-impact improvements for your specific environment and licence tier. Contact AMVIA on 0333 733 8050 to discuss your requirements. ## Frequently asked questions Q: Is Microsoft 365 Business Standard sufficient for security? A: For most UK businesses, no. Standard lacks Conditional Access, so MFA cannot be enforced reliably, and it has no Defender for Business EDR or Intune device management. The cost of Standard over Basic buys desktop Office apps, not security. Only the step up to Business Premium adds the full security stack, which is why we recommend it. Q: We already pay for Microsoft 365 - do we need additional security products? A: On Business Premium the built-in tools cover identity, endpoint and email security for most SMEs. Additional products are warranted only for specific gaps: 24/7 managed detection layered on Defender for Business, an email gateway such as Barracuda for extra filtering, or third-party backup. We assess what Premium already provides versus what genuinely adds value per client. Q: How do we know if our Microsoft 365 tenant is currently secure? A: Microsoft Secure Score at security.microsoft.com gives an immediate view of your configuration against recommended settings, with an ordered list of fixes. A score well below the typical baseline indicates meaningful gaps. AMVIA offers a Secure Score review that maps your configuration against both Microsoft's recommendations and NCSC guidance, with a prioritised plan. Q: What is the highest-impact Microsoft 365 security control? A: Multi-factor authentication enforced through Conditional Access. Microsoft reports MFA blocks over 99% of credential-based account compromise attacks. Pairing it with a policy that blocks legacy authentication closes the most commonly exploited bypass, so the two together remove a large share of account-takeover risk for very little effort. Q: Does Microsoft 365 security help with Cyber Essentials? A: Yes. A correctly configured Business Premium tenant supports several Cyber Essentials technical requirements, including access control, malware protection and secure configuration. It does not award the certification on its own, but it removes much of the configuration work, and AMVIA holds Cyber Essentials Plus and advises clients on aligning M365 with the scheme. --- # Microsoft Secure Score: What It Means and How to Improve It URL: https://amvia.co.uk/microsoft-365-security/microsoft-secure-score Last updated: 2026-03 Microsoft Secure Score is a numerical rating of how well your Microsoft 365 tenant matches Microsoft's recommended security settings. It awards points for each control you enable across identity, devices, apps and data - a higher score means fewer exploitable gaps. AMVIA reviews, prioritises and lifts your score as one accountable, security-first provider. You can see the live score in the Microsoft Defender portal, but the number is only useful once someone reads it the way an attacker would. That is the work this page explains - and it sits inside AMVIA's wider Microsoft 365 security service for UK SMEs, anchored to our Microsoft 365 security pillar. ## What is Microsoft Secure Score? Microsoft Secure Score measures your Microsoft 365 configuration against a set of recommended security actions, awarding points for each one you complete. It is shown as a fraction - for example, 245 of a possible 410 points - and as a percentage. A higher score signals a stronger configuration; a lower score points to specific, addressable gaps. The score is available to every Microsoft 365 organisation through the Microsoft Defender portal (security.microsoft.com). It continuously assesses identity, devices, applications and data against Microsoft's recommended security practices. The total possible score varies by tenant, because it depends on which products and licences you have active - a Business Premium tenant has more available actions, and a higher ceiling, than a Business Standard one. Secure Score is not a guarantee. A score of 80% does not mean you cannot be breached; it means your settings align well with Microsoft's guidance. A handful of identity and admin-protection actions carry far more real-world weight than their point value suggests, and those should be done first regardless of the number they move. ## How is Microsoft Secure Score calculated? Secure Score awards points for completing recommended actions, each with a point value set by its assessed security impact. Actions fall into three groups - identity, device, and application/data - and each one lists what it does, the effort to implement it, and a direct link to the right configuration page. - Identity actions (usually the highest value): enforce MFA for all users, require MFA for admins, block legacy authentication, enable Entra ID Protection risk policies, and cut the number of Global Administrators. - Device actions: enrol devices in Microsoft Intune, enforce compliance policies, enable BitLocker, keep Defender for Business active, and stay patched. - Application and data actions: enable Data Loss Prevention, configure Safe Links and Safe Attachments, restrict external sharing, and turn on audit logging. Each action can be marked "planned", "risk accepted", or "resolved through third party" - so the score reflects deliberate decisions, not just unfinished work. ## What is a good Microsoft Secure Score? There is no universal "good" score, because the maximum varies by licence and tenant. As a working benchmark for UK SMEs, below 30% signals significant gaps that need urgent attention, 30–50% is typical of a tenant nobody has actively hardened, 50–70% is a reasonable baseline, and above 70% reflects an actively managed posture. | | Score band | What it usually means | Priority | Below 30% | Major controls missing | Urgent | 30–50% | Default / unreviewed tenant | High | 50–70% | Key controls in place, gaps remain | Medium | Above 70% | Actively managed posture | Maintain | Above 80% | Mature config, full Premium capability | Maintain Microsoft's data suggests the average score across its customer base is around 35–40% (2025 Microsoft data). Most UK SME tenants AMVIA audits come in between 25% and 50% on initial assessment in 2026, with MFA enforcement and device management the most common gaps. Fixing those two areas - through MFA setup in Microsoft 365 and Intune enrolment - moves the score more than any other change. ## Which Secure Score actions have the highest impact for UK SMEs? Not all actions are equal. A small set of identity and endpoint controls carries most of the real-world risk reduction, so prioritise these before chasing low-value points. The National Cyber Security Centre rates multi-factor authentication as one of the single most effective defences a business can deploy. - Require MFA for all users (very high impact). Enforcing MFA through Conditional Access is consistently the highest-impact action available. Microsoft's own research shows MFA blocks over 99.9% of automated credential attacks. This can add 10–20 points depending on tenant size. - Block legacy authentication (high impact). Basic auth on SMTP, POP3 and IMAP cannot support MFA, and attackers target it to slip past MFA you think is enforced. Blocking it typically adds 10–15 points. - Reduce Global Administrator accounts (high impact). Each admin account is a target; a compromised Global Admin owns the tenant. Keep two to four dedicated admin accounts and use Privileged Identity Management for just-in-time access. - Enrol devices in Microsoft Intune (high impact). Devices with verified encryption, patching and antivirus status feed multiple device-scoring actions. - Enable Microsoft Defender for Business (high impact). Defender must run in active mode - not passive - across all endpoints for these actions to score. - Configure Safe Links and Safe Attachments (medium impact). Defender for Office 365 (Plan 1), included in Business Premium, scans URLs in real time and sandboxes attachments. Enable these in protection mode, not audit mode. ## Which Secure Score actions can SMEs safely decline? Some actions suit large enterprises but add friction or risk for a 10–500 staff business. Secure Score's "risk accepted" option lets you formally record a reviewed decision not to implement an action, so it stops dragging your score down indefinitely without hiding the choice. - Excess Global Administrators: the right number is two to four - not one, and not ten. Use Conditional Access and PIM rather than spreading admin rights. - Unified Audit Log: always enable this - accept no risk here. - Blanket SharePoint external-sharing locks: scope restrictions to the data that needs them; the most restrictive setting can break legitimate workflows. The point is to harden against real attacks, not to optimise a number for its own sake. That judgement is exactly what a managed provider brings. ## How does AMVIA improve your Microsoft Secure Score? AMVIA starts with a full Microsoft 365 security audit that captures your current score, the actions available in your tenant, and a prioritised roadmap ordered by security impact, business risk and effort. We then implement and maintain the configuration on an ongoing basis, tracking the score month over month and adding new recommendations as Microsoft releases them - one provider, security-first, Microsoft-certified. Typical outcomes for AMVIA clients within the first 90 days: - Secure Score lifted from an average of 32% to above 65% - MFA enforced across all user accounts - Legacy authentication blocked - Device compliance policies active via Microsoft Intune - Defender for Business deployed across all endpoints - Safe Links and Safe Attachments in protection mode These changes cut the risk of credential compromise, ransomware, phishing and data loss - and they sit alongside the round-the-clock monitoring in our broader managed cybersecurity service. AMVIA holds Cyber Essentials Plus, so the controls we recommend are the ones we run ourselves. ## In-house vs AMVIA-managed Secure Score | | | In-house, ad hoc | AMVIA managed | Review cadence | When someone remembers | Monthly, reported | Action prioritisation | By point value | By real-world risk | New Microsoft recommendations | Often missed | Assessed as released | Implementation | Competing with day job | Microsoft-certified engineers | Evidence for audits | Reconstructed later | Tracked month over month ## Frequently asked questions Q: What is Microsoft Secure Score and how is it calculated? A: Microsoft Secure Score is a numerical measure of your Microsoft 365 security configuration. It awards points for completed security actions - settings, policies and features Microsoft recommends enabling - and shows the result as a fraction of the total points available for your licence tier. A higher score means more recommended controls are in place. Q: What is a good Microsoft Secure Score for a small business? A: For a Business Premium tenant, above 65% is a reasonable target showing major controls are in place, and above 75% reflects a strong, actively managed configuration. Most UK SMEs start lower on their first audit. The exact target depends on your licence, because the maximum possible score changes with the products you have active. Q: Does a high Secure Score mean my business is secure? A: No single number guarantees security. A high score means your Microsoft 365 configuration aligns with Microsoft's recommended practices, which meaningfully shrinks your attack surface. It does not cover risks outside Microsoft 365 - unmanaged devices, network security, or physical security - so treat it as one important indicator within a broader security programme. Q: Which Secure Score actions have the biggest impact? A: Enforcing MFA, blocking legacy authentication, and reducing Global Administrator accounts carry the highest combined security impact and point value for most tenants. Microsoft Intune device enrolment and Defender for Business deployment are the next tier. Prioritising these protects the accounts and endpoints attackers target first, rather than chasing low-value points. Q: How often does Secure Score update? A: Microsoft Secure Score updates continuously - most actions reflect a configuration change within 24 hours of detection. Some device-related actions can take up to 48 hours to appear. Because Microsoft adds new recommendations over time, a score that looked healthy six months ago can slip, so review it on a regular cadence. Q: Can AMVIA improve our Secure Score as part of a managed service? A: Yes. Secure Score monitoring and improvement are a standard part of AMVIA's managed Microsoft 365 service. We review the score monthly, implement recommended actions, and provide a report showing score progression and the security improvements made - so you see both the number moving and the risk it reflects coming down. --- # How to Set Up Multi-Factor Authentication (MFA) in Microsoft 365 URL: https://amvia.co.uk/microsoft-365-security/mfa-setup-microsoft-365 Last updated: 2026-03 The correct way to set up MFA in Microsoft 365 is to enforce it through a Conditional Access policy in Microsoft Entra ID, block legacy authentication at the same time, and apply phishing-resistant methods to admin accounts. AMVIA deploys this for UK SMEs as one accountable, security-first, Microsoft-certified provider. Start with our Microsoft 365 security approach. ## Why does MFA matter for Microsoft 365? Most Microsoft 365 account compromises begin with a stolen or guessed password, and MFA stops that attack cold by demanding a second proof of identity. Microsoft reports MFA blocks over 99% of account takeover attacks (Microsoft Security), which is why the NCSC lists it as a core control. - 43% of UK businesses experienced a cybersecurity breach in 2025 (Cyber Security Breaches Survey 2025). - Stolen or compromised credentials were the initial attack vector in 22% of data breaches in 2024 (Verizon DBIR 2025). - The NCSC recommends MFA on every internet-facing account, prioritising admin access first. A password-only Microsoft 365 tenant is one phishing email away from a full mailbox takeover. MFA makes a stolen password, on its own, useless to an attacker. ## How does MFA work in Microsoft 365? MFA requires two independent proofs at sign-in: something the user knows (their password) and something they hold or are (a device prompt or biometric). Microsoft 365 supports several second factors, and they are not equally secure - the method you choose changes how much protection you actually get. | | MFA method | Security level | Best for | FIDO2 hardware key (e.g. YubiKey) | Phishing-resistant | Admin and high-risk accounts | Windows Hello for Business | Phishing-resistant | Managed company devices | Microsoft Authenticator (number matching) | Strong | All standard users | TOTP authenticator code | Moderate | Users without a managed phone | SMS / phone call | Weak | Last-resort fallback only Microsoft Authenticator is the right default for most staff. Since 2023, number matching is on by default: the user types a two-digit number from the sign-in screen rather than tapping "approve", which neutralises MFA fatigue (push-bombing) attacks. SMS is the weakest option because codes can be intercepted via SIM swapping. ## What is the correct way to enable MFA - per-user or Conditional Access? Enable MFA with a Conditional Access policy in Microsoft Entra ID, not the legacy per-user MFA toggle. Per-user MFA can be silently bypassed by legacy email protocols, while Conditional Access enforces MFA at the policy level and blocks those protocols at the same time. | | | Legacy per-user MFA | Conditional Access | Where it lives | M365 user management portal | Microsoft Entra ID | Blocks legacy auth | No | Yes | Risk-based / device-aware | No | Yes | Per-app and per-location rules | No | Yes | Licence needed | Any | Entra ID P1 (in Business Premium) Legacy protocols - IMAP, POP3 and basic SMTP authentication - authenticate with a password alone and ignore per-user MFA entirely. Microsoft reports over 99% of password-spray attacks target these legacy endpoints (learn.microsoft.com). Conditional Access shuts that door. Full Conditional Access needs Entra ID P1, included in Microsoft 365 Business Premium; Business Basic and Standard tenants can use Security Defaults, which enforces MFA for all users and blocks legacy auth in a simplified, preset form. ## How should admin accounts be protected? Admin accounts are the highest-value target in any tenant - a compromised Global Administrator hands an attacker the entire organisation. They need phishing-resistant MFA (FIDO2 keys or Windows Hello for Business), not just an Authenticator prompt, plus just-in-time role activation. Phishing-resistant methods cannot be relayed through adversary-in-the-middle attacks, where a fake Microsoft sign-in page proxies the login in real time and captures the approval. Pair this with Privileged Identity Management (PIM), which limits admin role activation to time-boxed sessions with written justification and approval. Combined, these controls make admin compromise far harder. Only 25% of UK businesses have a formal incident response plan (DSIT Cyber Security Breaches Survey 2025/26) - hardening admin access is the cheapest way to avoid ever needing one. ## How do you roll out MFA without breaking the business? A safe MFA rollout is staged: communicate first, deploy the Authenticator app, test policies in report-only mode, enforce on a pilot group, then expand tenant-wide. This catches the apps that rely on legacy authentication before you block it. AMVIA runs this end to end as part of our managed Microsoft 365 service. - Communicate first - tell staff what is changing, why, and what they must do. - Deploy Microsoft Authenticator - install and register methods before enforcement. - Report-only mode - log what a new policy *would* do, with zero user impact. - Pilot group - enforce for IT and early adopters to validate the experience. - Full rollout - expand to all users with helpdesk cover on standby. - Block legacy authentication - switch it off alongside or just after enforcement. The usual snags are staff without a smartphone (use FIDO2 keys, phone-call or desktop TOTP), and service or shared accounts (handle with managed identities, app passwords, or documented Conditional Access exclusions). A short M365 security audit surfaces every legacy-auth app - old Outlook builds, scan-to-email printers, IMAP line-of-business tools - before anything gets blocked. ## How does AMVIA set up and manage MFA? AMVIA deploys and manages MFA for UK businesses as part of our Microsoft 365 security service: building Conditional Access policies, rolling out Microsoft Authenticator, auditing and blocking legacy authentication, procuring FIDO2 keys for admins, and running the helpdesk through the change. MFA is one layer of a zero trust model - verify every sign-in, trust nothing by default - which we extend with Microsoft Defender for Business. One provider. Security-first. Microsoft-certified. Call us on 0333 733 8050. ## Frequently asked questions Q: What's the right way to set up MFA in Microsoft 365? A: Enforce it through Conditional Access policies in Microsoft Entra ID - not per-user toggles - and block legacy authentication at the same time, because legacy protocols bypass MFA entirely. Policy-based enforcement is what makes coverage complete and provable. Q: Does MFA really make that much difference? A: It's the single highest-value control in the tenant: Microsoft's long-standing figure is that MFA blocks over 99% of automated account-compromise attacks. Given 43% of UK businesses were attacked in a year (DSIT 2025) and identity is the front door, it's the first thing any audit checks. Q: Why do we have to block legacy authentication? A: Because older protocols (basic auth for IMAP, POP, older Office clients) authenticate without MFA - attackers deliberately target them to walk around your policy. MFA without a legacy-auth block is a locked front door with an open side gate. Q: What about MFA fatigue attacks? A: Attackers spam push notifications until a tired user taps approve. Mitigations are built into Entra: number matching, additional context in prompts, and risk-based policies. Configuration again - the platform has the defence; someone has to switch it on. --- # Microsoft Entra ID (formerly Azure AD) for SME Security URL: https://amvia.co.uk/microsoft-365-security/microsoft-entra-id Last updated: 2026-03 Microsoft Entra ID - rebranded from Azure Active Directory (Azure AD) in 2023 - is Microsoft's cloud identity and access management service, and the directory behind every Microsoft 365 tenant. It authenticates each sign-in and controls who reaches your email, files and apps. AMVIA configures and monitors it so identity becomes a defence, not a doorway. This page is part of our Microsoft 365 security pillar. ## What is Microsoft Entra ID and what does it do? Entra ID is the identity layer for Microsoft 365. It stores your user accounts, groups, devices and app registrations, then authenticates and authorises every request to Exchange, SharePoint, Teams and connected third-party apps. If a Microsoft 365 user signs in, Entra ID is the service that decides whether to let them through. It is provisioned automatically with every Microsoft 365 subscription - you already own it. The 2023 rename from Azure AD signalled Microsoft folding the directory into a wider identity portfolio covering governance, permissions management and verification. The mechanics most SMEs rely on - accounts, groups, sign-in and conditional access - are unchanged. ## Why is Entra ID the primary target for attackers? Identity is the new perimeter. With data living in Microsoft 365 rather than behind an office firewall, attackers no longer breach a network - they sign in. Entra ID is the gatekeeper, so a single compromised account can expose mailboxes, files and any app that trusts Microsoft authentication. According to Microsoft, over 95% of identity attacks are conducted using stolen credentials (Microsoft Security), usually harvested by phishing. The 2025 UK Cyber Security Breaches Survey names phishing as the most common attack type for UK businesses, and Business Email Compromise relies on compromised Microsoft 365 accounts. A valid credential is the cheapest way in, and Entra ID is what stands between that credential and your data. ## What security features are built into Microsoft Entra ID? Entra ID ships with a layered set of identity controls. The most impactful are multi-factor authentication, risk-based protection, privileged access management and audit logging. Used together - and enforced through policy rather than left optional - they neutralise the credential-theft attacks that account for the overwhelming majority of breaches. ## Multi-Factor Authentication (MFA) MFA requires a second proof of identity - a Microsoft Authenticator push, a TOTP code or a hardware key - on top of the password. Microsoft's data shows "MFA blocks more than 99.9% of automated credential attacks" (Microsoft Security). Even a phished password fails without the second factor. Enforce MFA through Conditional Access policies, not legacy per-user settings. Conditional Access lets you require MFA from untrusted networks while easing friction on a known office connection. Our MFA setup for Microsoft 365 guide walks through the rollout. ## Entra ID Protection (risk-based access) Included with Entra ID P2, Identity Protection scores the risk of every sign-in using Microsoft's global threat intelligence. Signals include impossible travel, known-malicious IPs, anonymous browsing and password-spray patterns. On high risk it can automatically block the sign-in, force a reset or require MFA - no administrator action needed. ## Privileged Identity Management (PIM) PIM, also in Entra ID P2, removes standing Global Admin rights. Instead of permanent elevated access - a major risk if that account is phished - administrators activate a role on demand, with approval and a time limit. PIM logs every activation, which supports access-control evidence for frameworks such as Cyber Essentials and ISO 27001. ## Self-Service Password Reset and audit logging Self-Service Password Reset (SSPR) lets users recover their own passwords via pre-registered methods, cutting helpdesk load; require at least two verification methods and exclude admins from it. Entra ID also logs every authentication event - successful and failed sign-ins, MFA challenges and risk events. Sign-in logs are retained 30 days on P1 and 90 days on P2; for longer retention, export them to Microsoft Sentinel or a SIEM. ## What are the most common Entra ID weaknesses in UK SME tenants? AMVIA's Microsoft 365 security audits keep finding the same gaps. Most are configuration oversights rather than missing licences - which means they are fixable quickly once identified. The recurring six below appear in tenant after tenant. - No MFA enforcement - MFA available but not required, leaving unregistered users on password-only sign-in. - Too many Global Admins - every Global Admin is full-tenant blast radius; keep it to two to four. - Legacy authentication unblocked - basic SMTP and POP3 bypass MFA entirely and are actively exploited. - Guest account sprawl - forgotten external B2B accounts that nobody reviews or expires. - No break-glass accounts - without emergency access accounts excluded from Conditional Access, one bad policy locks out every admin. - Default settings unchanged - Security Defaults is a floor, not a finished posture; most SMEs need tailored Conditional Access. A structured Microsoft 365 security audit surfaces all six against NCSC and Microsoft baselines. ## Which Entra ID licence do UK SMEs need? For most UK SMEs, Microsoft 365 Business Premium is the right tier - it bundles Entra ID P1, which adds Conditional Access and SSPR on top of the free MFA baseline. Step up to Entra ID P2 only when you need PIM, risk-based Identity Protection or Access Reviews for governance. | | Feature | Entra ID Free | Entra ID P1 (in Business Premium) | Entra ID P2 | Basic MFA (Security Defaults) | Yes | Yes | Yes | Conditional Access | - | Yes | Yes | Self-Service Password Reset | - | Yes | Yes | Identity Protection (risk-based) | - | Limited | Yes | Privileged Identity Management | - | - | Yes | Access Reviews | - | - | Yes Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual) and includes Entra ID P1 (Microsoft 365 UK pricing). For most 10–500-staff businesses, that bundle delivers enough identity security without buying standalone licences. ## How does AMVIA secure Entra ID for UK businesses? AMVIA manages Entra ID as a living configuration, not a one-off setup. An initial hardening goes stale as people join, roles change and apps are added, so we audit, enforce and review continuously as part of our managed Microsoft 365 service. One provider, security-first, with Microsoft-certified engineers. | | Identity task | Typical SME, self-managed | AMVIA managed Entra ID | MFA | Available, inconsistently enforced | Enforced for all users via Conditional Access | Legacy auth | Often still open | Blocked tenant-wide | Admin rights | Standing Global Admins | PIM just-in-time, no permanent roles | Guest accounts | Accumulate unchecked | Reviewed with expiry policies | Sign-in logs | Rarely reviewed | Monitored 24/7 with alerting | Review cadence | Ad hoc | Quarterly configuration review Identity sits at the centre of our wider managed cybersecurity and Microsoft Defender for Business services, so a risky sign-in and a compromised endpoint are seen as one story, not two. ## Frequently asked questions Q: What is the difference between Microsoft Entra ID and Azure Active Directory? A: They are the same product. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023 as part of a wider rebranding of its identity and security portfolio. The functionality, licensing tiers and capabilities are unchanged - only the name is different, so existing Azure AD configurations continue to work exactly as before. Q: Is Microsoft Entra ID included in Microsoft 365? A: Yes. Every Microsoft 365 subscription includes Entra ID Free, which covers basic identity management and MFA via Security Defaults. Microsoft 365 Business Premium includes Entra ID P1, adding Conditional Access and Self-Service Password Reset. Entra ID P2, which adds Privileged Identity Management and risk-based Identity Protection, is available as an add-on licence. Q: What happens if an Entra ID Global Admin account is compromised? A: A compromised Global Admin gives an attacker unrestricted control of the entire Microsoft 365 tenant - every mailbox, file and setting. They can create admin accounts, disable security controls, exfiltrate data and lock out legitimate administrators. This is why you should keep Global Admins to a handful, enforce MFA on all of them, and use PIM to remove standing access. Q: How do I know if my Entra ID tenant has been compromised? A: Warning signs include sign-ins from unusual locations, new accounts or app registrations you did not create, unexpected changes to Conditional Access or MFA settings, mailbox forwarding rules, and alerts from Identity Protection. AMVIA's managed Microsoft 365 service monitors these indicators continuously so suspicious activity is caught and investigated early. Q: Does securing Entra ID help with compliance? A: Yes. Frameworks such as Cyber Essentials and ISO 27001 require multi-factor authentication, unique user accounts, least-privilege access and account management - all enforced and evidenced through Entra ID's Conditional Access, PIM and audit logs. A properly configured tenant is a substantial, demonstrable step toward meeting those control requirements. Q: Do I need Entra ID P2, or is P1 enough? A: For most UK SMEs, Entra ID P1 - included with Microsoft 365 Business Premium - is sufficient, giving you Conditional Access and SSPR. Move to P2 when you need just-in-time admin access via PIM, automated risk-based sign-in protection, or Access Reviews for tighter governance, typically driven by regulatory obligations or larger user counts. --- # Conditional Access in Microsoft 365: A Guide for UK Businesses URL: https://amvia.co.uk/microsoft-365-security/conditional-access Last updated: 2026-03 Conditional Access is the policy engine inside Microsoft Entra ID that decides, in real time, whether a sign-in is allowed, challenged with MFA, or blocked. It weighs who the user is, what device they are on, where they are, and what they are reaching for. AMVIA designs and runs these policies for UK SMEs as part of Microsoft 365 security management. ## How does Conditional Access work? Conditional Access sits between a login attempt and the resource behind it. When a user signs in, it reads a set of signals, scores the risk, and enforces an outcome. It replaces the blunt "correct password equals access" model with rules that adapt to context. A policy has three parts: - Assignments - which users, groups, and cloud apps the policy covers (all staff, just finance, just SharePoint). - Conditions - the signals it evaluates: sign-in risk, device compliance, location, and client app. - Access controls - the result: grant, grant with MFA, require a compliant device, force a password reset, or block outright. Microsoft's own guidance describes Conditional Access as the heart of its Zero Trust identity model, where every request is verified before access is granted (learn.microsoft.com). ## Why do UK SMEs need Conditional Access? Most successful breaches start with stolen credentials, and a password alone is no longer a control. Conditional Access breaks that attack chain: even with valid credentials, an attacker from an unknown device or country is challenged or blocked before reaching your data. Phishing remains the dominant route in. According to the UK government's Cyber Security Breaches Survey 2025, 85% of businesses that identified a cyber breach experienced phishing (gov.uk). Conditional Access is the layer that stops a phished credential turning into full tenant access. For GDPR, it gives you a documented, auditable access-control mechanism that supports the technical security expectations under Article 32 (ico.org.uk). It also supports Cyber Essentials and NCSC access-control guidance (ncsc.gov.uk). ## What are the essential Conditional Access policies? A small, well-scoped baseline covers most of the risk for a UK SME. AMVIA deploys and tests the following as a standard starting set, then tunes them to your user base and device estate. - Require MFA for all users - the single highest-impact policy; stops the bulk of credential attacks. Pairs naturally with a managed MFA setup for Microsoft 365. - Block legacy authentication - old protocols (IMAP, POP3, SMTP AUTH) cannot do MFA and must be closed off. Test first; some line-of-business apps still rely on them. - Require a compliant device for sensitive apps - SharePoint, OneDrive, and finance systems only reachable from devices enrolled and healthy in Microsoft Intune. - Block high-risk sign-ins - Entra ID Protection scores each sign-in; high-risk attempts are blocked automatically. - Restrict access by country - if no one should ever sign in from a given region, block it. Low maintenance, high return. These policies sit on top of identity controls in Microsoft Entra ID and work best alongside endpoint protection from Microsoft Defender for Business. ## Per-user MFA vs Conditional Access: what's the difference? Many businesses still run Microsoft's legacy per-user MFA toggle and assume they are covered. Conditional Access is a different class of control: policy-driven, context-aware, and consistent across every app. | | Capability | Legacy per-user MFA | Conditional Access | MFA enforcement | On or off per account | Triggered by risk, device, or location | Block legacy authentication | No | Yes | Device compliance checks | No | Yes (with Intune) | Risk-based blocking | No | Yes (with Entra ID Protection) | Geographic restrictions | No | Yes (named locations) | Report-only testing | No | Yes | Minimum licence | Any | Entra ID P1 The takeaway: per-user MFA is better than nothing, but Conditional Access is what an attacker actually has to defeat. ## Which Microsoft 365 licence includes Conditional Access? Conditional Access needs Microsoft Entra ID P1 as a minimum. That licence is bundled into Microsoft 365 Business Premium, M365 E3, M365 E5, and Entra ID P1 standalone. Business Basic and Business Standard do not include it without an add-on. This is the practical reason AMVIA recommends Business Premium for any UK SME with real security needs. Microsoft Business Premium lists at £16.90 per user per month (ex VAT, annual commitment), and it folds in Conditional Access, Intune, and Defender for Business in one licence (microsoft.com/en-gb). Stepping up from Business Standard at £9.60 is usually cheaper than buying Entra ID P1 separately and stitching it together. ## What mistakes do UK businesses make with Conditional Access? Conditional Access is powerful enough to lock your own people out if it is rushed. The failures we see most often are operational, not technical. - Enabling enforcement without testing - always run new policies in report-only mode first, read the sign-in logs, then enforce. - No break-glass account - every tenant needs at least two emergency admin accounts excluded from all policies, so a bad rule can be undone. - Blanket policies - requiring a compliant device just to send email creates friction with no benefit. Scope each policy to the apps and data that justify it. - Ignoring named locations - without defined office IP ranges, the engine cannot tell your Sheffield office from an overseas attacker, and staff get challenged needlessly. A standalone Microsoft 365 security audit surfaces these gaps before they cause an outage or a breach. ## How does AMVIA manage Conditional Access? Getting Conditional Access right means understanding your users, devices, apps, and compliance obligations - then building policies that are strict on attackers and quiet for staff. Misconfiguration cuts both ways: too loose and you have gaps, too tight and you have outages. AMVIA's managed Microsoft 365 service includes the full lifecycle: - Audit of your current Entra ID and sign-in configuration - A policy set designed for your business, not a copied template - Report-only testing before any policy is enforced - Ongoing monitoring of sign-in logs and policy effectiveness - Regular reviews as your team, devices, and apps change - Integration with Intune so device compliance drives access decisions This is part of the wider managed cybersecurity practice that makes identity, endpoint, and email security one accountable service rather than three disconnected tools. ## Frequently asked questions Q: What is Conditional Access in Microsoft 365? A: Conditional Access is a policy engine within Microsoft Entra ID that evaluates risk signals - user identity, device compliance, location, and sign-in behaviour - before granting or blocking access to Microsoft 365 apps. It is the primary tool for enforcing Zero Trust access controls in a Microsoft environment. Q: Does Conditional Access require MFA? A: Conditional Access can require MFA as a grant control, so users must pass a second factor before access. It can also demand MFA only under set conditions, such as signing in from outside the corporate network or an unmanaged device. This is far more flexible and harder to bypass than Microsoft's legacy per-user MFA settings. Q: Which Microsoft 365 licence includes Conditional Access? A: Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium, M365 E3, M365 E5, and Entra ID P1 standalone. It is not available in Microsoft 365 Business Basic or Business Standard without buying an additional licence. Q: Can Conditional Access block access from specific countries? A: Yes. Named locations let you define geographic regions, and policies can block sign-ins from listed countries or permit only approved ones. It is a straightforward control that removes a large volume of opportunistic international attack traffic with very little ongoing maintenance. Q: Will Conditional Access disrupt my staff? A: Configured well, Conditional Access is largely invisible to people signing in from known, managed devices on the corporate network. Sign-ins from new devices, new locations, or unusual circumstances get challenged with MFA or blocked. Deploying in report-only mode first lets you measure the impact before it ever reaches users. Q: Is Conditional Access enough on its own? A: No. Conditional Access is a critical identity layer but belongs inside a broader Microsoft 365 security strategy: endpoint protection via Defender for Business, email security, and data loss prevention. A full tenant audit checks all of these areas together rather than treating identity in isolation. --- # Microsoft 365 Copilot Readiness: Is Your Tenant Ready? URL: https://amvia.co.uk/microsoft-365-security/copilot-readiness Last updated: 2026-07-13 Microsoft 365 Copilot readiness means preparing your tenant before you switch Copilot on: eligible licences assigned, permissions and sharing cleaned up, and sensitivity labels in place - because Copilot surfaces anything the signed-in user already has access to. Get the hygiene right first and Copilot is an asset; skip it and you industrialise oversharing. AMVIA runs the readiness work as part of managed Microsoft 365 - one provider, security-first, Microsoft-certified. ## What does "Copilot-ready" actually mean? Three things, in increasing order of effort. First, licensing and apps: Copilot requires an eligible Microsoft 365 base subscription with accounts in Entra ID, and Microsoft publishes the current app and network requirements and the licence-assignment steps. Second, identity and access: accounts, groups and roles that reflect reality. Third - the one that actually takes work - permission and data hygiene across SharePoint, OneDrive and Teams. The licences are a purchase order. The hygiene is a project, and it is the part that decides whether Copilot helps you or hurts you. ## Why permissions decide whether Copilot is safe Microsoft is explicit about how Copilot handles your data: it honours your existing permissions - Copilot can only surface content the signed-in user can already access. That sounds reassuring, and for a well-governed tenant it is. The problem is what "can already access" means in a typical SME tenant after years of growth: anyone-with-the-link shares that never expired, org-wide groups nobody audits, a finance folder shared with a project team in 2022 and never unshared. Before Copilot, that oversharing was mostly invisible - finding the payroll file required knowing where to look. Copilot removes the "knowing where to look" step. Ask it the right question and it will helpfully summarise anything within reach. Nothing is breached - every item was already accessible - but the exposure becomes practical instead of theoretical. That is why readiness is a security exercise before it is an AI one. ## What to fix before enabling Copilot The order that works: audit sharing first (links, guests, group sprawl), tighten to least privilege, then put sensitivity labels on the data that must stay protected wherever it travels - labels carry encryption and access control into whatever Copilot produces. Only then assign licences, and to a pilot group first, not the whole company. A pilot surfaces the oversharing you missed while the blast radius is ten people, not two hundred. This is the same groundwork a Microsoft 365 security audit performs - Copilot has simply turned it from good practice into a prerequisite. ## How AMVIA gets you Copilot-ready We run the readiness sequence as a managed engagement: audit the tenant (sharing, permissions, labels, Conditional Access), fix what the audit finds, stage the pilot, then keep the posture governed after rollout as part of managed Microsoft 365. Security-first matters here: the same controls that make Copilot safe - least privilege, labelling, access reviews - are the controls that reduce breach impact generally. Copilot readiness is M365 security with a deadline attached. ## Frequently asked questions Q: Can Microsoft 365 Copilot see everything in my tenant? A: No - Copilot honours your existing Microsoft 365 permissions and can only surface content the signed-in user already has access to, per Microsoft's published privacy model. The practical risk is different: in most tenants users can access far more than anyone realises, through old sharing links, broad groups and stale guest access. Copilot makes that over-access easy to find, which is why permission hygiene is the core of readiness. Q: Is my Microsoft 365 licence enough for Copilot? A: Copilot is an add-on licence on top of an eligible Microsoft 365 base subscription, and accounts need to be in Entra ID. Microsoft publishes the current eligibility and app requirements - check them against your tenant rather than assuming, because requirements are updated as Copilot evolves. Q: What is oversharing and why does Copilot make it worse? A: Oversharing is content accessible to more people than intended - anyone-with-the-link shares, org-wide visibility, groups that grew beyond their purpose. Before Copilot, finding overshared content required knowing where to look; Copilot removes that step by answering questions across everything the user can reach. Nothing is technically breached, but theoretical exposure becomes practical. Cleaning up sharing before enabling Copilot is the single most important readiness task. Q: Do we need Purview sensitivity labels before Copilot? A: Labels are the mechanism that keeps protection attached to sensitive content - encryption and access controls follow the labelled data into new documents and AI-generated output. A tenant can technically run Copilot without them, but labelling your confidential data first means Copilot-era workflows inherit the protection instead of bypassing it. Q: How long does Copilot readiness take? A: It depends on the state of the tenant, which is exactly what an audit establishes. A small, well-governed tenant may only need licence checks and a pilot plan; a tenant with years of unmanaged sharing needs a permissions clean-up first. The audit gives you the honest scope before you commit to licences. --- # Microsoft 365 Backup and Data Recovery Service URL: https://amvia.co.uk/microsoft-365-security/microsoft-365-backup Last updated: 2026-03 Microsoft 365 backup is an independent, daily copy of your Exchange, SharePoint, OneDrive and Teams data, held separately from Microsoft so you can recover from accidental deletion, ransomware or malicious removal. Microsoft keeps the platform running; protecting the data inside it is your responsibility. AMVIA runs that backup for over 1,200+ UK businesses - one provider, security-first, Microsoft-certified. Microsoft operates a shared responsibility model: it guarantees the service, not your individual files. Its own services documentation recommends maintaining a regular backup of your content, because native tools like the Recycle Bin and version history are retention features, not a backup. AMVIA closes that gap, raising your Microsoft Secure Score in the process. ## What does AMVIA's Microsoft 365 backup include? Every licensed user's data across the four core Microsoft 365 workloads is backed up daily to UK-based cloud storage, with granular recovery down to a single email or file. You restore exactly what you lost - without overwriting current data or rolling back an entire mailbox. - Exchange Online - all emails, calendar items, contacts and tasks for every licensed mailbox, with point-in-time restore of individual messages, folders or whole mailboxes. - SharePoint Online - every site, document library, list and site setting, including the SharePoint sites created automatically behind Microsoft Teams. Recover a file, a library or a full site collection. - OneDrive for Business - all user content backed up independently of Microsoft's native version history, restorable at file, folder or full-drive level. - Microsoft Teams - channel posts and files, including private-channel content stored separately in SharePoint. Teams chats live in Exchange mailboxes and are covered by the Exchange backup. Pairs with our wider Microsoft Teams hardening work. ## How does the backup process work? AMVIA scopes, configures, verifies and monitors your backup as a managed service - you are not handed a console and left to run it. Backups are encrypted, automated and tested, with daily monitoring and a defined recovery path for every restore request. 1. Scope and policy - we identify what needs protecting (mailboxes, OneDrive, SharePoint, Teams) and set retention to match your compliance and business requirements. 2. Backup configuration - automated, encrypted backups run multiple times daily to UK-based cloud storage. 3. Verification - we run test restores to prove backup integrity and confirm recovery times meet your expectations. 4. Monitoring and recovery - backup jobs are checked daily, with self-service restore for users and full disaster recovery handled by our team. Critical issues are responded to within one hour. ## Why do UK SMEs need Microsoft 365 backup? Because Microsoft will not recover data you delete, that ransomware encrypts, or that falls outside the native retention window - and the legal and insurance consequences land on you, not Microsoft. Independent backup is the difference between a five-minute restore and a permanent loss. Under UK GDPR, the Information Commissioner's Office can issue fines of up to £17.5 million or 4% of global annual turnover for the most serious failures, and Article 32 specifically requires the ability to restore the availability of personal data after an incident. A documented Microsoft 365 backup is direct evidence of that control. It also matters commercially: UK cyber insurers increasingly ask whether cloud data is backed up before they will quote or pay out. Ransomware now targets cloud storage directly - the NCSC's ransomware guidance stresses offline, separately-credentialed backups as the recovery foundation. If an attack is in progress, our incident response team uses your clean restore point to get you trading again. ## Native Microsoft 365 retention vs AMVIA managed backup Retention policies and backup are different tools for different jobs. Retention preserves data for legal hold and compliance windows; it does not protect against ransomware or recover data deleted before the policy existed. The table makes the gap explicit. | | Capability | Native M365 retention | AMVIA managed backup | Protects against accidental/malicious deletion | Limited to retention window | Yes - point-in-time restore | Ransomware recovery (clean restore point) | No | Yes - separate storage and credentials | Granular item-level restore | Partial | Yes - single email or file | Data stored independently of Microsoft | No | Yes - UK-based cloud storage | Recovers data deleted before policy applied | No | Yes | Managed and monitored daily | No | Yes For a fuller picture of where backup sits in your Microsoft estate, start with an M365 security audit and tighten sign-in risk with Microsoft Defender for Business. ## How much does Microsoft 365 backup cost? AMVIA prices Microsoft 365 backup on fixed monthly per-user pricing with no lock-in contracts, so cost scales with your licensed headcount and you can leave if we ever stop earning your business. We quote against your actual user count and retention requirements rather than a generic package, and the backup runs alongside your existing Microsoft 365 licences - it does not replace them. Microsoft's own list prices are a useful anchor for your licensing: Business Basic is £4.60, Standard £9.60 and Premium £16.90 per user per month (ex VAT, annual). Backup is an additional managed service on top of whichever plan you run. For broader resilience planning, pair it with business continuity. ## Why choose AMVIA for Microsoft 365 backup? AMVIA is a UK security partner that runs Microsoft 365 backup as a monitored, accountable service - not a self-service tool you configure and forget. - Sheffield-based, UK-focused - our engineering and support team operates from Sheffield and understands UK compliance, infrastructure and the realities facing British SMEs. - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status. - 1,200+ UK businesses protected - across legal, finance, healthcare and professional services. - Fast, responsive support - critical issues are responded to within one hour, by phone, email and portal, with named account managers who know your environment. ## Frequently asked questions Q: Doesn't Microsoft back up Microsoft 365 already? A: Not in the way businesses assume. Microsoft runs resilient infrastructure and short-window recycle bins, but the shared-responsibility model puts data protection on you - deleted mailboxes, purged files and ransomware-encrypted OneDrives past the retention window are gone without an independent backup. Q: What does Microsoft 365 backup cover? A: An independent daily copy of Exchange mailboxes, SharePoint, OneDrive and Teams data, held separately from Microsoft, restorable at item level - one email, one file, one mailbox - without drama, however the data was lost. Q: What does M365 backup cost? A: A few pounds per user per month (AMVIA's service sits alongside the from-£12 managed M365 fee), against the cost of explaining to a client that their project files are unrecoverable. It's consistently the cheapest insurance in the stack. Q: How fast can we get data back? A: Item-level restores - a deleted email or file - take minutes. Whole-mailbox or site restores depend on volume but run in hours, not days, and crucially they work regardless of why the data went: accidental deletion, a malicious leaver, or ransomware. --- # Microsoft Teams Security Best Practices for UK Businesses URL: https://amvia.co.uk/microsoft-365-security/microsoft-teams-security Last updated: 2026-03 Microsoft Teams security is the set of guest access, meeting, app permission and data-sharing controls that stop a Teams tenant leaking sensitive information or being used for fraud. Teams is secure by design but permissive by default, so configuration is what decides your real exposure. AMVIA hardens it as part of one accountable, security-first, Microsoft-certified managed Microsoft 365 security service. ## Why does Microsoft Teams security matter for UK businesses? Teams is now one of the most data-rich systems most UK firms run. It carries commercially sensitive negotiations, HR matters, financial approvals and strategic plans, while every file shared lives in SharePoint and every recording in OneDrive. That concentration of data, plus heavy external collaboration, makes it a target worth securing properly. Attackers have noticed. The NCSC treats messaging and collaboration platforms as prime ground for social engineering, and phishing remains the single most common attack type reported by UK businesses in the government's Cyber Security Breaches Survey 2025. Once an attacker compromises one Microsoft 365 account, Teams chat becomes a trusted channel to impersonate colleagues and approve payments. The default settings make this worse. Guest access, external federation, anonymous meeting join and open app installation all ship switched on, prioritising ease of use over containment. Tightening them - alongside Conditional Access - is the work that turns a usable platform into a safe one. ## How do you control guest access in Microsoft Teams? Guest access lets people outside your organisation join teams and channels using any email address. It is genuinely useful for client and supplier collaboration, but uncontrolled it becomes the most common Teams data-exposure route. The fix is to limit who can invite, force MFA on guests, and review accounts on a schedule. By default a guest can read and post in channels they are added to, join meetings, and open files in those channels. They cannot create teams, invite other guests, or reach the admin centre. The problems are accumulation and scope: guests rarely get removed, and a guest invited at team level can often see every non-private channel in that team. Recommended configuration: - Restrict guest invitations to administrators and named roles, not all users. - Require MFA for guests through Conditional Access - see MFA setup for Microsoft 365. - Run Access Reviews in Microsoft Entra ID P2 so stale guests are re-confirmed or removed. - Use private channels for sensitive topics when external guests sit in a team. - Scope external federation to named partner domains, not "any organisation". See Microsoft's guest access guidance. ## How do you secure Teams meetings? External meetings are now the default for client and supplier calls, and anyone holding a meeting link can often join without challenge. Three controls close that gap: a lobby that holds external attendees until admitted, disabled anonymous join for sensitive calls, and recording policies that stop sessions being shared or kept forever. - Lobby: admit only people in your organisation (and invited guests) automatically; never auto-admit dial-in callers. - Anonymous join: disable it at tenant or policy level for internal and sensitive external meetings. - Recordings: control who can record, who recordings auto-share with, and set expiry so they do not persist indefinitely. Recordings inherit SharePoint and OneDrive access controls, so a single over-shared recording can expose a confidential discussion to every attendee, including guests. Treat recording governance as part of your wider data protection obligations under UK GDPR. ## How do you stop sensitive data leaking from Teams? Teams files are SharePoint and OneDrive files, so Teams sharing risk is SharePoint sharing risk. The strongest control is Microsoft Purview sensitivity labels, included in Microsoft 365 Business Premium, which can stamp a team as "Confidential" and automatically enforce its privacy, guest and external-sharing rules rather than relying on each owner to get it right. - Apply sensitivity labels to teams to auto-configure guest and external-sharing behaviour. - Set SharePoint external sharing to authenticated external users only - never anonymous links. - Use Microsoft Intune compliance policies with Conditional Access to block or browser-restrict Teams on unmanaged devices; see Microsoft Intune. - Turn on Data Loss Prevention to detect and block regulated data types leaving a chat. ## How do you manage third-party app permissions in Teams? Teams supports thousands of third-party apps, and each one requests permissions to read messages, open files, or act on a user's behalf. Left open, any user can install anything, which creates two real risks: over-permissioned apps reaching sensitive data, and OAuth consent phishing where a malicious app tricks staff into granting it access. Bring this under governance: - Allow only Microsoft-published apps or ones you have explicitly approved in the Teams admin centre. - Review the global app permission policy - the default lets every user add apps. - Use Entra ID App Governance to monitor consented permissions and flag unusual access patterns. This pairs naturally with endpoint and identity protection from Microsoft Defender for Business, which gives you the telemetry to spot a compromised account before it abuses an app grant. ## How does Teams phishing work, and how do you stop it? As email defences improve, attackers move to Teams. Tactics include impersonation accounts using names close to real contacts, compromised supplier tenants messaging your staff through existing federation, and malicious links pasted into chat. Defence needs both technical filtering and trained scepticism - the NCSC's phishing guidance applies to Teams as much as email. Microsoft Defender for Office 365 Safe Links can sandbox URLs inside Teams messages, but it is not always enabled for Teams by default - confirm the policy covers Teams, not just email. Defender does not read message body content the way it scans email, so user awareness remains essential: verify unexpected payment or credential requests through a known phone number, never the chat thread that made them. ## What about Teams voice security and the 2025 PSTN switch-off? Many UK firms are moving voice onto Microsoft Teams Direct Routing ahead of the 2025 PSTN switch-off, which adds voice-specific risks on top of collaboration ones. Call recordings need the same information governance as other sensitive data, SIP trunks must be configured to block toll fraud, and emergency call routing has to be verified because Teams handles it differently from a traditional line. ## How much does securing Microsoft Teams cost? The technical controls above are licensing-dependent, and the controls that matter most - Defender for Office 365 Safe Links and Purview sensitivity labels - live in Microsoft 365 Business Premium. The table below shows Microsoft's UK list prices; AMVIA's role is configuring and managing these features, not reselling licences. | | Microsoft 365 plan | Price (ex VAT, /user/mo, annual) | Teams security features included | Business Basic | £4.60 | Teams, core admin controls, MFA | Business Standard | £9.60 | Above + desktop apps | Business Premium | £16.90 | Above + Defender for Office 365, Purview sensitivity labels, Intune, Entra ID P1 Prices are Microsoft UK list prices via Microsoft 365 plans. Business Premium is the practical baseline for the Teams hardening described here. ## Default Teams vs AMVIA-hardened Teams The difference between a secure Teams tenant and an exposed one is configuration, not licensing alone. This is what changes when AMVIA takes it on. | | Area | Default Teams | AMVIA-hardened Teams | Guest invites | Any user can invite | Restricted to approved roles | Guest MFA | Not enforced | Required via Conditional Access | Guest review | Never | Quarterly Access Reviews | Anonymous meeting join | Enabled | Disabled for sensitive meetings | External app install | Any user | Approved apps only | Safe Links on Teams | Often off | Verified on | Sensitivity labels | Unused | Applied to confidential teams ## How does AMVIA secure Microsoft Teams? AMVIA configures Teams security as a standard component of its managed Microsoft 365 service: one provider, security-first, Microsoft-certified engineers. We audit current Teams settings against NCSC guidance, then own the configuration and the ongoing reviews so it does not drift. - Audit of Teams admin settings against NCSC guidance. - Guest access policy and cleanup of stale guest accounts. - Meeting and recording policy configuration for external calls. - App permission governance in the Teams admin centre. - Safe Links extended to Teams in Defender for Office 365. - Purview sensitivity labels for Teams information protection. - Quarterly review of guest accounts and app permissions. ## Frequently asked questions Q: Is Microsoft Teams secure for business use? A: Yes. Teams runs on enterprise-grade infrastructure and Microsoft certifies the platform against international standards including ISO 27001, SOC 2 and GDPR requirements. Its real-world security, though, depends on configuration. Defaults favour ease of use, so hardening guest access, meetings and app permissions is what makes Teams genuinely safe for your data. Q: Can guests in Teams access all of our files? A: No - guests only reach files in the teams and channels they are explicitly added to, not other teams or SharePoint sites. The catch is scope: a guest invited at team level can usually see every non-private channel in that team. Use private channels for sensitive material and review guest accounts quarterly to keep access tight. Q: How do I prevent sensitive information being shared externally via Teams? A: Apply Microsoft Purview sensitivity labels to teams so external sharing rules are enforced automatically, and use private channels when external guests are present. Set SharePoint external sharing to require authentication rather than anonymous links, and enable Data Loss Prevention policies to detect and block regulated content types before they leave a chat. Q: Does Microsoft Defender cover Teams messages? A: Partly. Defender for Office 365, included in Microsoft 365 Business Premium, provides Safe Links protection that sandboxes URLs in Teams messages, but it does not scan message body text the way it scans email. Stopping Teams-based social engineering needs both that technical control and user awareness training for staff. Q: How do I check if our Teams guest accounts are up to date? A: In the Microsoft Entra ID portal, review the external users section to see every guest with tenant access. Entra ID P2 includes Access Reviews, which automate periodic confirmation that each guest is still needed. AMVIA runs this review quarterly as part of its managed Microsoft 365 service so accounts never accumulate unchecked. Q: What is the most important first step to secure Teams? A: Restrict guest invitations and enforce MFA on guests through Conditional Access. Most Teams data exposure comes from unmanaged external accounts, so controlling who can invite guests and proving those guests' identity closes the largest gap first - before you move on to meeting, recording and app permission policies. --- # How to Harden Your Microsoft 365 Tenant: Complete Guide URL: https://amvia.co.uk/microsoft-365-security/m365-hardening-guide Last updated: 2026-03 Microsoft 365 is not secure by default. Hardening means deliberately changing the defaults - enabling Conditional Access and MFA, blocking legacy authentication, locking down admin roles and sharing - to close the gaps attackers routinely exploit. AMVIA hardens tenants against Microsoft 365 security baselines: one provider, security-first, Microsoft-certified. ## Why is Microsoft 365 not secure by default? Microsoft 365 ships for ease of deployment and broad compatibility, so the out-of-the-box settings favour access over security. Legacy authentication is enabled, any device with valid credentials can reach email, the most powerful admin roles are permanently assigned, and audit logging often is not retained long enough for a forensic investigation. That default posture matters because 43% of UK businesses experienced a cybersecurity breach or attack in 2025 (gov.uk Cyber Security Breaches Survey 2025). The most common Microsoft 365 attacks - password spray, legacy-protocol credential stuffing, OAuth app abuse - all exploit these defaults. Hardening, guided by AMVIA's Microsoft 365 security audit, turns those defaults off. ## How do you harden identity with Conditional Access? Identity is the highest-priority hardening domain because 85% of businesses that suffered a breach identified phishing as the attack type (gov.uk Cyber Security Breaches Survey 2025), and most Microsoft 365 compromises start with a stolen credential. Conditional Access is the policy engine in Microsoft Entra ID that decides who gets in, from which device, under what conditions. AMVIA deploys a baseline policy set for every managed client: - Require MFA for all users across all applications - Block legacy authentication protocols entirely - Require device compliance for SharePoint, Exchange Online and Teams - Apply phishing-resistant MFA to admin accounts ## Security Defaults vs Conditional Access Lower licence tiers include Security Defaults - pre-configured policies that enforce MFA and block legacy authentication. Full Conditional Access, available with Business Premium, adds the granular control most businesses need. See Microsoft's Conditional Access documentation for the policy detail. | | Capability | Security Defaults | Conditional Access | Enforce MFA | Yes | Yes | Block legacy auth | Yes | Yes | Device compliance rules | No | Yes | Location / risk-based access | No | Yes | Per-app and per-group control | No | Yes | Licence | Basic / Standard | Business Premium ## How do you protect admin accounts with PIM? Permanent Global Administrator access means a single compromised admin hands an attacker the whole tenant. Privileged Identity Management (PIM) replaces standing access with just-in-time elevation: an admin requests a role, gives a justification, sets a duration, and the role expires automatically - every activation logged. Standing admin rights are dangerous because only 14% of UK businesses held a formal incident response plan (DSIT Cyber Security Breaches Survey 2024), leaving most unable to contain a takeover quickly. AMVIA configures PIM for all admin accounts as standard, so day-to-day work runs on least privilege and elevation is the exception, not the rule. ## How should MFA be enforced across the tenant? MFA is the single highest-impact control: Microsoft reports MFA blocks over 99% of account compromise attacks (Microsoft Security). The detail that matters is *how* it is enforced. Legacy per-user MFA can be bypassed through old protocols; enforcing MFA through Conditional Access and a proper MFA setup makes it consistent across every access point. - Microsoft Authenticator with number matching - the baseline for business users, resistant to MFA-fatigue attacks - FIDO2 hardware keys or Windows Hello for Business - phishing-resistant MFA for admin accounts - No exceptions - every application, every user, enforced at policy level ## How do you harden email security in Exchange Online? Exchange Online Protection filters mail, but default policies are not tuned for targeted threats. Hardening means enabling impersonation protection for commonly-spoofed executives, switching on Safe Links and Safe Attachments, and authenticating your own domain so attackers cannot spoof it against your clients. - Anti-phishing policy with impersonation protection for key people and domains - Safe Links and Safe Attachments (Defender for Office 365, Business Premium) enabled, not left at defaults - DKIM signing enabled; DMARC published and advanced to `p=reject`; SPF reviewed - Outbound spam policies to catch a compromised account before takeover completes ## How do you harden endpoints with Defender for Business? Microsoft Defender for Business, included in Business Premium, provides endpoint detection and response - but its default configuration leaves much switched off. Hardening means turning protections on deliberately, because licensing Defender does not activate them. - Attack surface reduction (ASR) rules moved from audit-only to enforcement - Controlled folder access to blunt ransomware - Network protection to block known-malicious domains and IPs - Web content filtering for high-risk categories ## How do you control data sharing and audit logging? SharePoint external sharing defaults are usually too permissive, allowing anyone-with-the-link access. AMVIA restricts sharing to authenticated users, reviews Teams guest access, and layers Microsoft Purview Data Loss Prevention (DLP) over email, Teams, SharePoint and OneDrive. For UK businesses handling personal data, DLP is a technical control that supports UK GDPR obligations (ICO). Audit logging is essential for investigating an incident. AMVIA enables Microsoft 365 audit logs with appropriate retention and monitors security-relevant events - unusual sign-ins, admin actions, external sharing, and mailbox forwarding-rule creation - through its in-house 24/7 SOC. ## How do you track hardening progress with Secure Score? Microsoft Secure Score measures your configuration against Microsoft's recommendations in real time and lists improvement actions by impact, making prioritisation straightforward. The reported industry average sits around 50% (2025 benchmarks). AMVIA captures a baseline before hardening and tracks the score at quarterly reviews, following NCSC guidance alongside Microsoft's recommendations. ## M365 hardening checklist - Conditional Access - MFA required for all users, legacy authentication blocked - Admin accounts protected with PIM - just-in-time elevation, no permanent Global Admin - Anti-phishing policy - impersonation protection for key executives and domains - Safe Links and Safe Attachments enabled with appropriate policies - DKIM and DMARC configured, DMARC in enforcement - SharePoint external sharing restricted - no anonymous links without justification - Defender for Business - ASR rules enforced, not audit-only - Audit logging enabled with appropriate retention ## Frequently asked questions Q: Will M365 hardening break anything we currently use? A: Blocking legacy authentication is the most common cause of disruption - some older email clients, printers, scanners and line-of-business apps still use basic authentication. AMVIA identifies these dependencies before blocking legacy auth and helps you migrate or replace them. Other changes - Safe Links, anti-phishing, restricted external sharing - typically have minimal operational impact. Q: How long does M365 tenant hardening take? A: For a standard SME on Business Premium, AMVIA usually completes core hardening in one to three days, including testing and documentation. Identifying and resolving legacy-authentication dependencies can extend that. Initial hardening is followed by a quarterly review so the tenant stays secure as Microsoft adds new recommendations and your environment changes. Q: Do we need Business Premium to harden Microsoft 365? A: Not entirely. Security Defaults, available on Basic and Standard, enforce MFA and block legacy authentication, which is a meaningful improvement over nothing. But device compliance, full Conditional Access, Defender for Business and Safe Links require Business Premium. For most security-conscious SMEs, Business Premium is the right tier for hardening. Q: Does hardening Microsoft 365 support Cyber Essentials? A: Yes. A correctly hardened M365 configuration - enforced MFA, secure settings, malware protection and access control - supports Cyber Essentials and Cyber Essentials Plus compliance, the certification AMVIA itself holds. It makes the technical evidence for certification far more straightforward to demonstrate, though hardening alone is not a certificate. Q: Can we harden Microsoft 365 ourselves? A: You can, if you have the in-house Entra ID, Defender and Purview expertise and the time to test changes in report-only mode before enforcing them. The risk is locking out users or missing a legacy-auth dependency. AMVIA hardens against Secure Score and NCSC guidance during agreed maintenance windows, documents every change, and provides a before-and-after Secure Score comparison. --- # Microsoft 365 Security for Hybrid and Remote Working URL: https://amvia.co.uk/microsoft-365-security/hybrid-working-security Last updated: 2026-03 Hybrid working security is the set of identity, device and data controls that protect Microsoft 365 users wherever they work - office, home or on the move. It replaces the old trusted-network model with verification of every sign-in and every device. AMVIA configures and runs these controls as one accountable, security-first provider. The old model - trust the office network, distrust everything else - is gone. Most UK SMEs now have staff signing in to Microsoft 365 security from home broadband, personal laptops and phones, often with no VPN involved. The controls that protect them live inside the identity and device layer, not on a perimeter firewall. Get those controls right and hybrid working is safe. Leave them at default and your attack surface is wide open. ## Why has hybrid working changed the security landscape? Hybrid working dissolved the network perimeter. Phishing now lands in home inboxes, unmanaged personal devices reach SharePoint, and ransomware on a home laptop can propagate straight into cloud storage. The defensive line moved from the network edge to identity and device state - and most SMEs have not caught up. On 2025 UK data, around 60% of businesses have employees working regularly outside the corporate network, yet fewer than a third have updated their security controls to reflect this. That gap - people working everywhere, controls built for one place - is where most hybrid-working incidents begin. The fix is not more hardware; it is correctly configured Microsoft 365 controls. ## What security controls does every hybrid Microsoft 365 environment need? Six controls cover the vast majority of hybrid-working risk. None require new infrastructure - all ship inside Microsoft 365 Business Premium. The job is enabling, configuring and maintaining them so they hold up without driving users to work around security. - Multi-factor authentication (MFA): a second proof of identity so a stolen password alone cannot grant access. See our MFA setup for Microsoft 365 guide. - Conditional Access: policy that checks user, device and location on every sign-in. Detail on Conditional Access policies. - Device management with Intune: patching, encryption and compliance enforced over the internet. See Microsoft Intune device management. - Endpoint protection: detection and response on every laptop via Microsoft Defender for Business. - Collaboration security: guest, sharing and app controls for Microsoft Teams security. - Data Loss Prevention (DLP): Microsoft Purview rules that block sensitive data - card numbers, NHS numbers, passport details - from leaving sanctioned locations. ## How does multi-factor authentication protect remote workers? MFA is the single most effective control for hybrid staff. When a user signs in from outside the office, a second factor - a phone push, a one-time code or a hardware key - means a compromised password is not enough to get in. For people logging in from untrusted home and public networks, it is non-negotiable. Microsoft's own data states that "MFA blocks more than 99.9% of automated credential attacks" (learn.microsoft.com). MFA should be enforced through Conditional Access rather than legacy per-user settings, so you can require it for sign-ins outside named office IP ranges while keeping office logins low-friction. Legacy authentication protocols that cannot support MFA should be blocked outright, as attackers routinely use them as a bypass. ## Do hybrid workers need a VPN for Microsoft 365? Not for Microsoft 365 itself. The platform is built for internet-direct access over HTTPS and enforces its own identity and access controls, so a VPN is not the right primary defence for cloud apps. Conditional Access and MFA do that job better. A VPN still earns its place for reaching on-premises systems that lack modern authentication. The mistake is treating a VPN as the security control and skipping identity and device hardening. The NCSC's home and remote working guidance makes the same point: protect the account and the device, not just the tunnel (ncsc.gov.uk). For Microsoft 365, verified identity plus a compliant device is stronger than network location alone. ## In-house DIY vs AMVIA-managed hybrid security Hybrid security is not a one-time switch. Users join, devices change, policies drift, and threats evolve. The table below shows where a managed service differs from a self-run setup. | | Capability | DIY / unmanaged M365 | AMVIA-managed | Conditional Access | Often off or default | Designed to your hybrid model | Intune enrolment | Partial or none | All work devices enrolled and compliant | Defender for Business | Licensed but unconfigured | Deployed and monitored | Secure Score | Unknown | Tracked with an improvement roadmap | Sign-in / risk review | Ad hoc | Ongoing log and alert monitoring | Accountability | Split across tools | One provider, security-first ## How does hybrid working security support Cyber Essentials? The government-backed Cyber Essentials scheme puts every device that accesses your data - company-owned or personal - in scope for five technical controls: firewalls, secure configuration, security update management, malware protection and user access control (gov.uk). Hybrid working makes meeting them harder because the devices are no longer all on one network. In practice, that means company devices must satisfy all five controls, personal devices used for work are either Intune-enrolled or restricted to browser-only access, and MFA is enforced across all cloud services including Microsoft 365. AMVIA holds Cyber Essentials Plus, and our managed Microsoft 365 service is built to support your Cyber Essentials certification rather than just claim alignment with it. ## How does AMVIA secure hybrid Microsoft 365 environments? AMVIA runs hybrid Microsoft 365 security as a managed service, not a one-off project. We baseline your tenant, configure the right controls for how your people actually work, then monitor and tune them as your business changes - so security stays current without slowing teams down. The service includes: - Security baseline assessment of your Microsoft 365 tenant - Conditional Access policies designed for your hybrid working model - Intune enrolment and compliance management for all work devices - Microsoft Defender for Business deployment and monitoring - A Microsoft Secure Score improvement roadmap - Ongoing monitoring of sign-in logs, risk events and security alerts, with a quarterly tenant review We work with UK businesses from 10 to 500 staff across Sheffield, Leeds, Manchester and nationally. For the wider security picture beyond Microsoft 365, see our managed cybersecurity services. One provider. Security-first. Microsoft-certified. ## Frequently asked questions Q: Is Microsoft 365 secure enough for remote working? A: Yes, when configured. Microsoft 365 is designed for internet-direct access and includes strong security, but those capabilities are not all on by default. Provisioning accounts without enabling MFA, Conditional Access and device management leaves you exposed. With the right controls in place, Microsoft 365 is a secure platform for hybrid teams. Q: Do remote workers need a VPN if they use Microsoft 365? A: Not for Microsoft 365 itself. It is cloud-native, uses HTTPS encryption, and enforces its own identity and access controls, so a VPN is not the primary defence for cloud apps. A VPN remains useful for reaching on-premises systems that lack modern authentication, but Conditional Access and MFA protect cloud access more effectively. Q: What happens if a remote worker's device is lost or stolen? A: If the device is enrolled in Microsoft Intune, an administrator can remotely wipe company data, or fully wipe a company-owned device. For a personal device managed through app protection, only company data inside Microsoft 365 apps is removed, leaving personal data untouched. AMVIA's managed service includes remote wipe as standard. Q: How do I manage security for contractors who use their own devices? A: Conditional Access can permit registered-but-unenrolled personal devices with tighter rules - blocking downloads and requiring MFA on every sign-in. Intune app protection can apply data controls to Microsoft 365 apps without full device management. AMVIA designs a contractor access policy to match your risk tolerance. Q: Which Microsoft 365 plan do I need for hybrid working security? A: Microsoft 365 Business Premium includes the controls hybrid working needs: Conditional Access, Intune device management, Defender for Business and Purview DLP. Business Basic and Standard do not include these security capabilities, so most SMEs securing a hybrid workforce should licence Business Premium. Q: How do I protect data when staff work from home networks? A: Keep data in Microsoft's cloud rather than on local or personal storage, enforce DLP rules to block risky sharing, and require compliant, encrypted devices through Intune. Advise staff to update router firmware and use WPA3 or WPA2 encryption. Identity and device controls matter more than the home network itself. --- # Microsoft 365 Business Premium vs Standard: Which to Pick? URL: https://amvia.co.uk/microsoft-365-security/compare/m365-business-premium-vs-standard Last updated: 2026-03 Microsoft 365 Business Premium and Business Standard share the same Office apps, email, and Teams. Premium adds the security layer Standard leaves out: Defender for Business, Intune device management, and Conditional Access. For any UK business handling client or financial data, Premium is the baseline AMVIA recommends - one provider, security-first. If you are weighing the two tiers, this is the short version: Standard is a productivity suite, Premium is a productivity suite with built-in security and device management. The gap between them is not features-for-features' sake - it is the difference between hoping nothing goes wrong and being able to prove your accounts, laptops, and data are protected. For a fuller picture of how these controls fit together, see our Microsoft 365 security pillar. ## What is the difference between Business Premium and Standard? Both tiers include the desktop and web Office apps, 1TB OneDrive, Exchange email, Teams, and SharePoint. The difference is entirely security and management: Business Premium bundles enterprise-grade endpoint protection, mobile device management, and identity controls that Standard simply does not contain. You cannot configure your way around the gap - the licences are not present. | | Capability | Business Standard (£9.60/user/mo) | Business Premium (£16.90/user/mo) | Office desktop + web apps | Yes | Yes | Exchange email, Teams, SharePoint, 1TB OneDrive | Yes | Yes | Exchange Online Protection (spam/malware filtering) | Yes | Yes | Defender for Business (EDR-level endpoint protection) | No | Yes | Defender for Office 365 P1 (Safe Links / Safe Attachments) | No | Yes | Microsoft Intune (device management + remote wipe) | No | Yes | Entra ID P1 + Conditional Access | No | Yes | Self-service password reset | No | Yes | Microsoft Purview data loss prevention | Limited | Yes List prices are Microsoft's published UK figures, ex VAT on an annual commitment, per Microsoft 365 for business. The security capabilities are documented in Microsoft Learn. ## How much more does Business Premium cost than Standard? On Microsoft's UK list prices, Standard is £9.60 per user per month and Premium is £16.90 - a difference of £7.30. The source figure most buyers quote is slightly wider once partner and add-on pricing is included: "The additional £8–£10 per user per month includes Defender for Business, Intune, and Conditional Access - giving you a complete, integrated security baseline." For a 25-user business, that upgrade is roughly £200–£250 per month for integrated endpoint protection, device management, and identity security. Set that against the downside: "Given the average cost of the most disruptive breach is £3,550 (DSIT 2025)", the upgrade typically pays for itself by preventing a single incident. The UK government's annual Cyber Security Breaches Survey tracks these costs year on year. The honest framing: you are not paying £7–£10 for features, you are paying for the controls that stop an account takeover from becoming a data breach. ## What security features does Premium add that Standard lacks? Premium adds four controls that matter most for SMEs: Defender for Business for endpoint detection and response, Microsoft Intune for device management, Entra ID P1 for Conditional Access, and Defender for Office 365 for advanced email threats. Standard has none of these - it stops at basic email filtering. - Defender for Business - EDR-grade protection that detects and isolates compromised laptops, not just known malware signatures. - Microsoft Intune - enforces encryption, PIN policies, and remote wipe across company and BYOD devices. - Conditional Access - blocks risky sign-ins and enforces MFA based on user, device, and location. - Defender for Office 365 P1 - rewrites malicious links and detonates attachments before they reach the inbox. This matters because identity is the front door. The NCSC's multi-factor authentication guidance is unambiguous that MFA is one of the most effective controls available, yet "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)". Conditional Access in Premium is what makes enforcing it across the whole organisation a policy rather than a hope. Microsoft has reported that "99.9% of compromised accounts did not have MFA enabled" - the single cheapest control you can switch on. ## Which Microsoft 365 tier should a UK SME choose? AMVIA recommends Business Premium for any UK business handling client data, financial records, or operating in a regulated sector. Standard only makes sense for very small, low-risk teams that already run separate, well-managed endpoint and identity tooling - which, in practice, almost no SME does. The case for Premium gets stronger as the threat surface grows. Microsoft's platform is a constant target: "1,360 Microsoft vulnerabilities patched in 2024 - up 11% YoY", across an estate of "345m Microsoft 365 paid subscribers globally in 2025". Premium is how you keep pace with that patch and threat cadence without stitching together third-party tools. If you also want someone to run it for you, our managed Microsoft 365 service operates the security baseline day to day. ## Can you bolt security tools onto Standard instead of upgrading? You can, but it rarely saves money or effort. Buying standalone EDR, device management, and identity protection as separate products almost always costs more per user than the Premium upgrade, and you lose the shared threat intelligence that comes from running everything inside one Microsoft tenant. Integration is the point. The advantage of Premium is that endpoint, email, and identity signals feed a single console and enforce policy together. A third-party stack means more vendors, more agents on every device, and more gaps where two tools assume the other is watching. If you are comparing Microsoft's native protection against a separately managed detection service, our Defender vs MDR comparison breaks down where each fits, and our managed cybersecurity pages cover the wider security picture. ## Frequently asked questions Q: What security features does Business Premium add over Business Standard? A: Business Premium adds Defender for Business for endpoint detection and response, Microsoft Intune for device management, Entra ID P1 for Conditional Access, and Defender for Office 365 P1 for advanced email threats. Standard includes none of these - it stops at Exchange Online Protection for basic spam and malware filtering. Q: Is the extra cost of Business Premium justified for a small business? A: On Microsoft's UK list prices the upgrade is £7.30 per user per month (Standard £9.60, Premium £16.90), or £8–£10 once add-ons are included. For a 25-user business that is around £200–£250 per month for integrated endpoint, device, and identity protection - typically less than the cost of recovering from one breach. Q: Does Business Standard provide any security at all? A: Standard includes Exchange Online Protection for spam and malware filtering plus baseline anti-malware. It does not include endpoint detection and response, device management, Conditional Access, or advanced email threat protection. For most UK businesses that handle client or financial data, Standard's controls fall short of a defensible baseline. Q: Can I switch from Standard to Premium without disruption? A: Yes. Upgrading is a licence change within the same Microsoft tenant, so users keep their email, files, and Teams history. The work is in configuration - turning on Defender, enrolling devices in Intune, and rolling out Conditional Access policies in stages. AMVIA migrates businesses from Standard to Premium with minimal disruption. Q: Does Business Premium replace the need for a managed security provider? A: No. Premium gives you the right tools, but they still need configuring, monitoring, and maintaining. Conditional Access policies, Defender alerts, and Intune compliance rules all require ongoing attention. A managed provider turns the licences you are paying for into protection that is actually switched on and watched. --- # M365 Business Premium vs E5: Which Licence for UK SMEs? URL: https://amvia.co.uk/microsoft-365-security/compare/m365-business-premium-vs-e5 Last updated: 2026-09 For UK SMEs with fewer than 300 users, M365 Business Premium is the right licence - it includes Defender for Business, Intune, Entra ID P1, and Conditional Access at a price that makes E5 unnecessary. Only consider E5 if you need built-in SIEM (Sentinel), Teams Phone, Defender XDR, or advanced eDiscovery for legal or compliance obligations. E5 is an enterprise licence at enterprise cost; Business Premium is the SME security sweet spot. ## Frequently asked questions Q: What security features does Business Premium include that E5 does not? A: Business Premium includes Defender for Business, which is a simplified EDR solution designed specifically for SMEs. E5 includes the more advanced Defender for Endpoint P2, Defender for Office 365 P2, and Defender for Cloud Apps. However, for businesses under 300 users, Business Premium's security stack covers the most critical threat vectors at roughly half the per-user cost. Q: When is E5 worth the additional cost over Business Premium? A: E5 is justified when you need Teams Phone System built in, advanced eDiscovery for legal hold, Entra ID P2 with Privileged Identity Management, or Power BI Pro. The vast majority of SME organisations operate comfortably on Business Premium without requiring E5-tier features - the businesses that genuinely need E5 usually know exactly which feature is forcing the upgrade. Q: Can I add individual E5 features to Business Premium instead of upgrading fully? A: Yes. Microsoft allows add-on licences for specific capabilities such as Teams Phone, Defender for Endpoint P2, or Entra ID P2. For a 50-user business, selectively adding one or two E5 features to Business Premium is often significantly cheaper than upgrading every user to the full E5 licence at £37.50 per user per month. Q: Does Business Premium's 300-user limit affect growing businesses? A: Yes. Business Premium is capped at 300 users per tenant. Once you exceed this threshold, you must move to enterprise licensing - typically E3 plus security add-ons, or E5. With the average cost of the most disruptive breach at £3,550 (DSIT 2025), planning your licence migration early ensures no security gaps emerge during the transition. --- # Microsoft Defender vs Third-Party MDR: Best for SMEs? URL: https://amvia.co.uk/microsoft-365-security/compare/defender-vs-mdr Last updated: 2026-03 Microsoft Defender for Business is the detection tool; MDR (managed detection and response) is the 24/7 human service that watches it, investigates alerts, and contains threats for you. Defender finds the signal - MDR acts on it. For most UK SMEs without an in-house analyst, you need both, delivered by one accountable security partner. This is the core of the defender vs mdr decision: you are not choosing between two competing products. You are deciding whether the security tooling already inside your Microsoft 365 security licence runs unwatched, or whether trained analysts respond to what it finds. The tool is the easy part. The watching is where SMEs get caught out. ## What is the difference between Defender and MDR? Defender for Business is endpoint detection and response (EDR) software included in Microsoft 365 Business Premium. MDR is a managed service: a security operations centre (SOC) of analysts who use an EDR engine like Defender to monitor your estate around the clock, triage every alert, and contain attacks on your behalf. Put simply, Defender produces alerts; MDR turns those alerts into action. A modern EDR platform such as Microsoft Defender for Business will flag credential theft, suspicious sign-ins and malware - but flagging is not stopping. Managed detection and response (MDR) adds the human judgement and out-of-hours cover that decides whether an alert at 02:00 on a Sunday becomes a contained incident or a Monday-morning ransomware headline. ## Defender vs MDR: side-by-side comparison The two are layers in the same stack, not rivals. Defender is the sensor; MDR is the response team standing over it. The table below shows where each starts and stops, so you can see exactly which gap MDR is paid to close for an SME with no dedicated security staff. | | Factor | Microsoft Defender for Business | Managed Detection & Response (MDR) | What it is | EDR software inside M365 Business Premium | A 24/7 service run by analysts on top of EDR | Who operates it | Your own team configures and watches it | A provider's SOC monitors and responds | Alert triage | Automated; manual review still required | Human analysts triage every alert | Out-of-hours cover | None unless you staff it | 24/7/365 | Threat containment | Auto-quarantine of known malware only | Analysts isolate hosts, disable accounts, stop the spread | Typical cost | ~£16.90/user/mo within Business Premium | from £10/endpoint/mo on top | Best suited to | Firms with a dedicated security analyst | SMEs with no in-house security staff ## When is Microsoft Defender for Business enough on its own? Defender alone is defensible only when you have skilled people watching it during the hours attackers operate - which is all of them. If you employ a security analyst who triages alerts daily and can respond out of hours, the tooling in Business Premium may be sufficient without a managed layer on top. In practice, very few UK SMEs meet that bar. Microsoft's own research found that 99.9% of compromised accounts had not enabled multi-factor authentication (Microsoft, 2019) - a reminder that the gaps are usually in operation, not in the product. Defender will auto-quarantine known malware, but identity-based attacks, lateral movement and "living off the land" techniques generate alerts that need a person to interpret. Left unwatched, that detection capability is a smoke alarm with nobody home. ## When does an SME need MDR? You need MDR the moment detection outpaces your ability to respond - which, for a business without a 24/7 SOC, is immediately. If nobody is rostered to investigate alerts overnight, at weekends and during holidays, the time between detection and response is exactly where attackers do their damage. The UK threat picture backs this up. The government's Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a cyber breach or attack in the last year (gov.uk). IBM puts the average time to identify and contain a breach at 241 days (IBM 2025), with an average cost of £8,260 for businesses suffering a negative outcome. Choose MDR when: - You have no dedicated, in-house security analyst. - You cannot guarantee a human response to alerts outside office hours. - You already pay for Business Premium and want the Defender for Business tooling actually monitored. - You need defensible evidence of 24/7 oversight for clients, insurers or auditors. ## How much does MDR cost compared with running Defender alone? MDR is the cheaper way to get round-the-clock cover than hiring for it. Defender for Business is already included in Microsoft 365 Business Premium at roughly £16.90 per user per month (microsoft.com). Adding MDR layers human monitoring on top for a per-endpoint fee - far less than a salaried analyst. | | Option | Cost | What you actually get | Defender alone (in Business Premium) | ~£16.90/user/mo | EDR tooling, no monitoring | Defender + MDR | from £10/endpoint/mo added | Tooling plus 24/7 human monitoring and response | In-house security analyst | £45,000–£65,000/yr (typical UK 2026 range) | One person, business hours, single point of failure For any SME under roughly 200 endpoints, MDR is the lower-cost route to continuous coverage. One analyst cannot cover 168 hours a week; a SOC can. The NCSC's guidance on logging and protective monitoring (ncsc.gov.uk) treats continuous oversight as a baseline, not a luxury, which is why 24/7 security monitoring is sold as a service rather than a hire for businesses this size. ## What AMVIA recommends If you have no dedicated in-house security analyst, choose MDR - not Defender standalone. MDR uses Defender (or an equivalent EDR) as the detection layer, then adds 24/7 human monitoring and incident response on top. This maximises the Business Premium investment you already hold rather than bolting on a competing agent. AMVIA's MDR service starts from £10 per endpoint per month and is built on Microsoft Defender for Endpoint, monitored by AMVIA's in-house 24/7 SOC. It typically replaces both standalone antivirus and the cost of dedicated security staff. That is the whole point of our model: one provider, security-first, Microsoft-certified - so the tool and the team answering for it are never split across two contracts. If you are still weighing the underlying technologies, our MDR vs EDR comparison breaks down the detection layer, and our managed cybersecurity service shows how MDR fits a wider security programme. ## Frequently asked questions Q: Is Microsoft Defender for Business enough without MDR? A: Defender for Business is a capable EDR tool included in Microsoft 365 Business Premium, but it generates alerts that need skilled analysts to triage and act on. Without staff monitoring those alerts around the clock, threats can sit unaddressed for hours or days. For most SMEs, that response gap is the reason to add MDR. Q: Can an MDR provider use Microsoft Defender as its detection engine? A: Yes. Many MDR providers, including AMVIA, build their managed service on top of Microsoft Defender for Business. The SOC monitors Defender's alerts, investigates suspicious activity and takes containment actions for you. This approach gets more value from your existing Business Premium licence rather than replacing it with a competing endpoint agent. Q: How much does MDR cost versus running Defender alone? A: Defender for Business is already bundled into Microsoft 365 Business Premium at about £16.90 per user per month. Adding MDR layers 24/7 human monitoring on top for a per-endpoint fee. The realistic alternative - hiring a full-time security analyst - costs tens of thousands a year, so for SMEs under 200 endpoints MDR is markedly cheaper. Q: What happens when Defender flags a threat and nobody is watching? A: Defender may auto-quarantine known malware, but sophisticated attacks - credential theft, lateral movement, living-off-the-land techniques - produce alerts that need human judgement. Unmonitored, those alerts often go unactioned until real damage is done. MDR ensures every alert receives a human response, day or night. Q: Does MDR replace the need for Microsoft 365 Business Premium? A: No. MDR sits on top of Business Premium, not instead of it. Business Premium provides the Defender for Business tooling and identity controls; MDR provides the analysts who watch and respond. Keeping both with one provider means a single accountable party for the tool and the response. Q: Is MDR worth it for a small business under 50 staff? A: For most small UK businesses, yes. Attackers do not skip you for being small, and a sub-50-staff firm rarely has a 24/7 SOC of its own. MDR gives that business the same continuous monitoring and rapid containment a larger enterprise relies on, at a predictable per-endpoint cost. --- # What Is MFA (Multi-Factor Authentication)? Why It Matters URL: https://amvia.co.uk/microsoft-365-security/questions/what-is-mfa Last updated: 2026-03 Multi-factor authentication (MFA) is a security control that requires two or more proofs of identity before granting access: something you know (a password), something you have (a phone or hardware key), or something you are (a fingerprint). It blocks the overwhelming majority of account-takeover attacks, and it is the single highest-impact security step a UK business can take. If you only ever fix one thing about your Microsoft 365 security, make it this. A stolen password on its own becomes useless once a second factor stands between the attacker and your inbox, your files, and your finance system. ## What is multi-factor authentication, in plain terms? MFA means proving who you are in more than one way. A password alone is a single factor: anyone who knows it is "you" as far as the system is concerned. MFA adds a second, independent check that a remote attacker cannot easily steal or guess. The three recognised factor categories are: - Something you know - a password, PIN, or passphrase. - Something you have - a phone running an authenticator app, a one-time code, or a hardware security key. - Something you are - a biometric such as a fingerprint or face scan. Genuine MFA combines factors from at least two different categories. Two passwords are not MFA. A password plus a number from an authenticator app is. ## How does MFA actually work? When you sign in, you enter your password as usual. The service then asks for a second proof: it pushes a prompt to your authenticator app, asks for a six-digit code, or requests a tap on a hardware key. Only when both checks pass do you get in. The point is independence. Even if an attacker has phished or brute-forced your password, they still cannot satisfy the second factor sitting on a device in your pocket. Microsoft's own guidance is blunt: enabling MFA is the most effective action most organisations can take to protect accounts (Microsoft Security). Modern MFA also gets smarter with context. Tools like Microsoft Entra ID conditional access can decide *when* to ask for a second factor - for example, only when a sign-in comes from an unfamiliar device, an unusual country, or a risky network. ## Why does every UK business need MFA? Account compromise is the entry point for most modern breaches: phishing leads to a stolen password, the password enables the mailbox, and the mailbox is used to invoice your customers or move your money. MFA breaks that chain at the first step, which is why insurers, frameworks, and regulators now treat it as a baseline rather than a nice-to-have. The numbers make the case: - MFA blocks over 99.9% of account-compromise attacks, according to Microsoft research - yet adoption across UK businesses remains low. - Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26), leaving the majority reliant on passwords alone. Passwords leak constantly through breaches, reuse, and phishing. MFA is the control that makes a leaked password a non-event instead of a disaster. For the wider picture on protecting cloud accounts, see our managed cybersecurity approach. ## Which MFA methods are the most secure? Not all second factors are equal. Hardware security keys are phishing-resistant and effectively impossible to intercept remotely. Authenticator apps are strong and practical for most teams. SMS text codes are better than nothing but vulnerable to SIM-swap and interception, so they should be a fallback, not your default. | | MFA method | Security level | Phishing-resistant? | Best for | Hardware key (FIDO2 / WebAuthn) | Highest | Yes | Admins, finance, high-risk roles | Authenticator app (push / TOTP) | Strong | Partial | Most staff, day-to-day sign-ins | One-time code via email | Moderate | No | Low-risk fallback only | SMS text code | Weakest | No | Last-resort fallback Our practitioner recommendation: authenticator apps as the standard for everyone, hardware keys for administrators and anyone touching payments. Reserve SMS for break-glass scenarios. This pairs naturally with strong phishing protection, because phishing is exactly the attack MFA is meant to neutralise. ## Is MFA required for Cyber Essentials and cyber insurance? Yes. MFA is a requirement of the UK government-backed Cyber Essentials scheme for cloud services and administrative accounts (Cyber Essentials, gov.uk). The NCSC also names multi-factor authentication as a core control for protecting accounts (NCSC). Cyber insurers have followed suit. Most UK policies now ask whether MFA is enforced on email and remote access, and many will refuse cover or decline a claim if it was not. AMVIA holds Cyber Essentials Plus, so we configure MFA to meet that bar as a matter of routine rather than as an afterthought. ## How do you roll out MFA without disrupting staff? Start with the accounts attackers want most. A phased rollout - administrators first, then finance and email, then everyone - lets you prove the process works before it touches the whole business. Clear comms and a short enrolment window prevent the help-desk pile-up that gives MFA a bad name. Business email compromise is the threat this defends against most directly; overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), and email is almost always the first account targeted. Practical rollout steps: - Enrol every admin account in MFA before anything else. - Use conditional access so prompts appear on risky sign-ins, not every login from a trusted office device. - Enforce, rather than merely offer, MFA - optional MFA protects no one. - Provide a hardware-key or app-based fallback so a lost phone never locks anyone out. If you want this configured properly across your tenant, our Microsoft 365 MFA setup guide walks through the AMVIA approach. One provider, security-first, Microsoft-certified - so the rollout is planned, enforced, and supported rather than left half-finished. ## Frequently asked questions Q: What does MFA stand for? A: MFA stands for multi-factor authentication. It means verifying your identity with two or more independent factors - typically a password plus a code or prompt from a device you own - before you are allowed to sign in. It is sometimes called two-factor authentication (2FA) when exactly two factors are used. Q: Is MFA the same as two-factor authentication (2FA)? A: Almost. Two-factor authentication uses exactly two factors, while multi-factor authentication means two or more. In everyday business use the terms are used interchangeably. The important point is that the factors come from different categories - something you know plus something you have - not two of the same type. Q: Can MFA be bypassed by attackers? A: MFA can be targeted through phishing kits, prompt-bombing, or SIM-swap on SMS codes, but it dramatically raises the difficulty for attackers compared with passwords alone. Phishing-resistant methods such as FIDO2 hardware keys and number-matching in authenticator apps close most of these gaps, which is why we recommend them for high-risk accounts. Q: Does MFA cost extra in Microsoft 365? A: No. Multi-factor authentication is included with all Microsoft 365 business and enterprise plans at no additional licence cost. The investment is in configuration and rollout, not licensing. Conditional access policies for risk-based prompts require Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. Q: Which accounts should I protect with MFA first? A: Start with administrator accounts, then finance, then any account with access to email or remote systems. Admin accounts hold the keys to your whole tenant, and email accounts are the usual launchpad for fraud. Once those are covered, extend MFA to every user so no account is left as an easy target. Q: Is MFA enough on its own? A: MFA is the highest-impact single control, but it is not a complete security programme. Pair it with strong passwords, endpoint protection, email filtering, and staff awareness. MFA stops stolen-password attacks; layered defences handle the threats it does not, which is the model we build for clients. --- # Microsoft 365 vs Google Workspace: Which Is More Secure for SMEs? URL: https://amvia.co.uk/microsoft-365-security/questions/m365-vs-google-workspace-security Last updated: 2026-03 Microsoft 365 Business Premium gives most UK SMEs a deeper built-in security stack than Google Workspace - bundling Defender for Business (EDR), Intune device management, Conditional Access and Purview data loss prevention in one licence. Google Workspace has strong fundamentals but needs more bolt-on tools to match that depth at the same price point. The honest answer is that both platforms are secure when configured properly and exposed when they are not. What separates them for a 10–500 staff business is how much security you get inside the base subscription before you start buying extras. On that measure, Microsoft 365 Business Premium is the stronger out-of-the-box choice for firms that want one provider accountable for the whole stack. ## How do the two platforms compare on built-in security? The core difference is bundling. Microsoft 365 Business Premium ships endpoint detection and response, device management, identity-based access controls and DLP inside a single per-user licence. Google Workspace delivers solid email, phishing and infrastructure protection, but reserves its strongest controls - context-aware access, advanced DLP, endpoint management - for higher Enterprise tiers or third-party add-ons. That bundling matters because every bolt-on tool is another contract, another console and another integration gap. Security-first means fewer seams for an attacker to slip through. | | Security capability | M365 Business Premium | Google Workspace (Business tiers) | Endpoint EDR | Defender for Business - included | No native EDR; needs third-party tool | Device management (MDM) | Intune - included | Basic mobile management; advanced in Enterprise | Conditional / context access | Entra ID Conditional Access - included | Context-Aware Access in Enterprise tiers | Data loss prevention | Purview DLP - included | Limited; full DLP in higher tiers | Email phishing protection | Defender for Office 365 | Native Gmail protection (strong) | Identity & MFA | Entra ID, included | Google identity, MFA included | Price (entry security tier) | £16.90/user/mo | Varies by tier Microsoft 365 Business Premium lists at £16.90/user/month ex VAT on an annual plan, and that figure includes the full security set above - not an upsell. For a like-for-like security posture, Google Workspace usually requires a higher tier or extra licences. ## Which platform protects against phishing better? Both platforms block the bulk of malicious mail, so the deciding factor is what happens after a phishing link is clicked. Microsoft 365 Business Premium pairs Defender for Office 365 email filtering with Defender for Business EDR, so a compromised endpoint is detected and isolated. Google Workspace filters Gmail strongly but lacks native endpoint response at SME tiers. Phishing is not a fringe risk. The UK government's Cyber Security Breaches Survey 2025 found phishing was the most common attack type, cited by 85% of businesses that identified a breach. Email filtering alone does not stop a user handing over credentials - what matters is the layer that catches the device or identity afterwards. - Microsoft's advantage: filtering plus endpoint and identity response in one licence. - Google's strength: mature, machine-learning Gmail filtering at every tier. - The gap: Google Workspace Business tiers have no built-in EDR to contain a post-click compromise. For most SMEs the practical recommendation is layered protection - strong email security backed by endpoint and identity controls - which Business Premium delivers natively. ## How do access and device controls differ? Microsoft 365 wins on granularity at the SME price point. Entra ID Conditional Access, included in Business Premium, evaluates sign-in risk, device compliance, location and app sensitivity before granting access. Google Workspace offers Context-Aware Access, but its richer rules sit in Enterprise tiers, not the Business plans most SMEs buy. Device management follows the same pattern. Microsoft Intune - bundled with Premium - enforces encryption, patching and remote wipe across Windows, macOS, iOS and Android. Google's Business-tier mobile management is lighter, with advanced endpoint controls reserved for Enterprise. According to Microsoft's official security documentation, Defender for Business is built specifically for companies up to 300 employees, which is precisely the band where Google Workspace asks you to step up to Enterprise. For a UK SME, that means M365 reaches enterprise-grade controls without the enterprise price tag. ## Does the bigger ecosystem make Microsoft 365 the safer bet? Scale matters for security maturity: a larger user base means more attacks seen, more threat intelligence and faster detection signals. Microsoft 365 has nearly 450 million paid subscribers globally in 2025, and Microsoft Teams reports 320 million monthly active users, giving its security telemetry enormous reach. That ubiquity cuts both ways - widely used platforms are also heavily targeted - but it also funds one of the largest threat-intelligence operations in the industry. Other widely cited adoption figures include 93% of Fortune 100 companies using Microsoft Teams and over 400 million paid commercial seats reported for FY2025. An estimated 1.9 million UK businesses use Microsoft Teams. The takeaway is not "bigger is automatically safer". It is that Microsoft's signal volume feeds Defender's detection models, and for an SME that lacks its own SOC, that inherited intelligence is real value. ## What should a UK SME actually choose? Choose on where your business already lives and how much security you want inside the licence. If your team runs on Windows and Office, M365 Business Premium is the pragmatic, security-first pick - one provider, one bill, one accountable stack. If you are already deep in Google Workspace and disciplined about adding endpoint and access tooling, Workspace can be configured to a strong standard. Whichever way you lean, the platform is only as safe as its configuration. Run a Microsoft 365 security audit before assuming defaults protect you, and confirm endpoint coverage with Defender for Business. If you are weighing licence tiers, our Business Premium vs Standard comparison shows exactly which security features you gain by moving up. AMVIA's view: for the 10–500 staff businesses we work with, Business Premium configured properly beats a partly-built Google Workspace stack on coverage, accountability and total cost - one provider, security-first, Microsoft-certified. ## Frequently asked questions Q: Does Microsoft 365 include endpoint protection that Google Workspace lacks? A: Yes. Microsoft 365 Business Premium includes Defender for Business, a full endpoint detection and response (EDR) tool that protects Windows, macOS, iOS and Android devices. Google Workspace has no equivalent built-in EDR at its Business tiers and needs third-party tooling to match it. That bundled endpoint layer is one of M365's clearest security advantages for SMEs. Q: Is Google Workspace secure enough for a UK business? A: Google Workspace provides strong baseline security: mature phishing protection, resilient infrastructure and data loss prevention in higher tiers. It is genuinely secure when configured well. The gap is built-in device management and endpoint response at SME tiers, which Google reserves for Enterprise. Neither platform is fully secure out of the box - configuration decides the outcome more than the logo. Q: How do Conditional Access policies differ between M365 and Google Workspace? A: Entra ID Conditional Access, included in M365 Business Premium, checks sign-in risk, device compliance, location and app sensitivity before granting access. Google Workspace offers Context-Aware Access, but its more granular rules live in Enterprise tiers rather than the Business plans most SMEs buy. For detailed access control without an enterprise contract, M365 Premium is the stronger toolset. Q: Can I run Microsoft 365 and Google Workspace together? A: Yes, though it adds complexity. Some firms use Google Workspace for email while leaning on Microsoft's security stack. Running both increases admin overhead and risks gaps where security policies do not line up across platforms. For most SMEs, consolidating onto a single platform - usually M365 Business Premium - simplifies management and keeps controls consistent across every user and device. Q: How much does the security difference cost? A: Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual) and includes EDR, device management, Conditional Access and DLP in that price. To reach a comparable posture on Google Workspace, you typically need a higher tier or additional third-party tools, which can erode any headline price difference. Compare total security coverage, not just the base subscription. Q: Which platform is better for phishing protection? A: Both filter most malicious email well, so the difference is what happens after a click. M365 Business Premium combines email filtering with endpoint and identity response, so a compromised device or account is contained. Google Workspace has excellent Gmail filtering but no native EDR at Business tiers to catch a post-click compromise. For layered defence, M365 has the edge. --- # Leased Lines UK: Compare Costs & Providers (from £69/mo) URL: https://amvia.co.uk/leased-lines Last updated: 2026-08 A leased line is a private, uncontended fibre circuit running directly from your premises to the carrier network. Unlike broadband, the full contracted speed is dedicated to your business, symmetric both ways, and backed by an uptime SLA. AMVIA sources, installs and manages leased lines across every UK carrier - one accountable provider, security-first. ## What is a leased line and how does it differ from broadband? A leased line - also called Dedicated Internet Access (DIA) - gives you bandwidth no one else shares, symmetric upload and download, and a contractual uptime guarantee. Broadband is contended, asymmetric and carries no meaningful SLA. That is the whole reason businesses pay more for a line. The three differences that matter: - Dedicated capacity: Broadband shares bandwidth with neighbouring premises, so speeds drop at peak times (roughly 8–10am and 5–7pm). A leased line delivers its contracted speed at all times. - Symmetric speed: A 1 Gbps leased line gives 1 Gbps up *and* down - essential for VoIP, cloud apps and large uploads. Broadband upload is typically a fraction of download. - Guaranteed SLA: Leased lines specify uptime (typically 99.99% or 99.95%), fault response, repair times and service credits if breached. Broadband promises none of this. For the full technical breakdown, read our guide on what a leased line is and the detailed leased line vs broadband comparison. ## What does AMVIA's leased line service include? AMVIA manages the whole lifecycle - survey, carrier selection, installation and ongoing fault management - so you deal with one provider instead of an Openreach support queue. We are network-agnostic, comparing every major UK carrier by postcode. - Dedicated Internet Access (DIA): Fully uncontended, symmetric fibre from 100 Mbps to 100 Gbps across most UK commercial postcodes. - Guaranteed SLA: Typically 99.99% or 99.95% uptime, with defined fault response, repair windows and service-credit compensation. - SD-WAN and network management: Intelligently route and prioritise business-critical traffic across multiple circuits from one portal. - Multi-site connectivity: Link offices over MPLS or SD-WAN so internal traffic never touches the public internet. - Failover and resilience: Pair the primary line with broadband or 4G/5G backup for automatic switchover. - End-to-end installation management: We coordinate carrier engineers and manage the cutover from your existing connection with minimal disruption. ## Why do UK SMEs need a leased line? Once a connection carries cloud apps, VoIP and a growing headcount, contended broadband becomes a productivity tax. A leased line removes peak-time slowdown and gives you an SLA to hold a carrier to. Ofcom tracks UK fixed connectivity in its Connected Nations report, the authoritative source on national network performance. According to the source data, 39% of UK business internet connections are now fixed leased lines (Ofcom Connected Nations, 2024), and the UK broadband average download speed is just 69.4 Mbps (Ofcom Connected Nations 2024) - well below what a busy office needs. AMVIA manages connectivity for UK businesses, including multi-site leased line estates. A leased line is usually worth considering if: - You have 25 or more staff sharing one connection - You depend on cloud services (Microsoft 365, ERP, CRM) that need consistent bandwidth - You host systems clients or remote workers must reach reliably - You run VoIP and need guaranteed call quality - Your broadband slows noticeably at peak times - You need a contractual SLA for regulatory or commercial reasons ## How much does a leased line cost in the UK? Leased line pricing depends on speed, postcode and carrier. Lines start from £69/mo, with the full range shaped by distance to the nearest fibre exchange. Urban postcodes (London, Manchester, Birmingham, Sheffield) generally cost less than rural ones. Because pricing is so location-dependent, the only reliable figure is a quote for your exact address. Our UK leased line pricing map sets out the entry price for every speed tier and exactly what moves a quote away from it. | | Speed | Typical monthly cost | Best suited to | 100 Mbps | from £69/mo | Small-to-mid offices, 25–50 staff | 1 Gbps | from £129/mo | Cloud-heavy SMEs, multi-team sites | 10 Gbps | from £349/mo | Data-intensive or multi-site aggregation Installation is usually zero or a one-off £500–£1,500 connection charge (typical UK 2026 range), depending on whether fibre already reaches the building. Most carriers require a minimum 36-month term. AMVIA accesses pricing from BT Openreach, Virgin Media Business, Zayo, CityFibre and Hyperoptic, then presents the most competitive option for your postcode and speed. ## What makes a business leased line different? “Business leased line” isn’t a marketing variant - it describes what the product actually is: a dedicated, symmetric fibre circuit sold with business-grade commitments that consumer and standard business broadband simply don’t carry. Three of them matter in practice. An SLA with teeth: uptime targets (typically 99.99%) with defined fix times and service credits, not best-effort support queues. Symmetry and no contention: upload equals download and the bandwidth is yours alone, which is what keeps VoIP calls clean and cloud backups inside their windows while the office works. Accountable support: a fault on a business leased line is worked to the SLA clock around the calendar, because the circuit is monitored as infrastructure rather than sold as a subscription. If the price gap to broadband surprises you, that gap is what it buys - and the honest comparison is in our leased line vs broadband guide, with per-tier from-prices on the leased line pricing page. ## How long does leased line installation take? A new leased line typically takes 30–90 working days from order to live service, because it involves a physical survey, fibre build where none exists, and carrier coordination. AMVIA tracks every milestone and can supply a temporary 4G/5G router if you need connectivity before the line goes live. The typical timeline: - Days 1–5: Order placed; carrier desktop survey confirms availability and pricing. - Days 5–15: Physical site survey to plan the install route. - Days 15–45: Fibre installation - shorter if fibre already reaches the building. - Days 45–60: Testing, configuration and cutover from the existing connection. ## How do you keep a leased line resilient and secure? Even a 99.99% SLA cannot stop a digger cutting fibre. For business-critical sites, pair the primary line with a secondary circuit configured for automatic failover - and treat the connection as part of your security perimeter, not just plumbing. The NCSC recommends building resilience and redundancy into critical business connectivity. Common failover options: - Secondary leased line: Maximum resilience, highest cost - trading floors, healthcare, critical infrastructure. - Broadband failover: Lower cost and bandwidth, activates automatically - fine for most SMEs. - 4G/5G router failover: Fastest to deploy, no install; limited bandwidth, ideal for short outages. Because a leased line is a direct path into your network, AMVIA layers leased line security - firewalling, segmentation and monitoring - over every circuit we manage, configured through SD-WAN or a managed router so a failure never becomes a disruption. One more pattern worth knowing: a good share of our leased-line customers also take managed IT support from us. Connectivity plus IT under one provider means one SLA, one support number and no vendor finger-pointing when something between the router and the desktop misbehaves. The same logic drives our business phone and broadband bundles - calls and connectivity engineered together ahead of the 2027 switch-off. ## Frequently asked questions Q: How much does a business leased line cost in the UK? A: Leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps in well-served postcodes, with your exact price set by which carriers have fibre near your building. Installation is typically £500–£2,000 as a one-off and frequently waived on a 36-month term. Q: How long does a leased line take to install? A: Typically 30–90 working days from order to live service: desktop survey, physical site survey, any fibre build, then testing and cutover. Buildings close to existing carrier fibre land at the shorter end, and AMVIA can supply a temporary 4G/5G router if you need connectivity before the line goes live. Q: What's the difference between a leased line and business broadband? A: A leased line is dedicated and uncontended - you get the full contracted speed, symmetric in both directions, at all times, backed by an uptime SLA of typically 99.99% with service credits. Broadband is shared with neighbouring premises, asymmetric, and carries no meaningful fix-time guarantee. Q: Which leased line providers does AMVIA compare? A: AMVIA is network-agnostic: we compare BT Openreach, Virgin Media Business, CityFibre, Zayo and other carriers at your exact postcode, then present the strongest option on price, install time and SLA together. The carrier with fibre closest to your building usually wins - and that changes street by street. Q: Do I need a backup connection with a leased line? A: For business-critical sites, yes - even a 99.99% SLA can't stop a digger cutting fibre. Most SMEs pair the primary circuit with broadband or 4G/5G failover configured for automatic switchover, so a single fault never takes the business offline. Q: What speed leased line does my business need? A: For most offices of 10–30 people using cloud apps, VoIP and video calls, 100Mbps (from £69/month) is comfortable. Teams of 30–100, heavy file transfer, or sites hosting their own systems suit 1Gbps (from £129/month). 10Gbps (from £349/month) is for data-intensive operations - media, engineering, multi-site backhaul - and 100Gbps is available for the most demanding sites. Because leased lines are symmetric, upload speed matches download, which is what makes the difference for VoIP, backups and cloud working. Q: What's the difference between business FTTP and a leased line? A: FTTP (full fibre broadband) is a shared connection: speeds are asymmetric (slower upload than download), bandwidth is contended with other users, and fixes are best-efforts. A leased line is dedicated fibre to your premises only: the full speed both ways, uncontended, with a fix time guaranteed in an SLA. FTTP suits small offices where a few hours offline is an inconvenience; a leased line is for businesses where connectivity failure stops trading. Q: Is a leased line worth it for a small business? A: It depends on what downtime costs you. If your phones are VoIP, your systems are cloud-based, or you take payments online, a broadband outage stops the business - and a leased line, from £69 a month with a guaranteed fix time, often costs less than a single afternoon of lost trading. If you can work through an outage on mobile data, well-served FTTP broadband is usually the better-value choice until you grow. Q: Can I check leased line availability at my postcode? A: Yes - enter your postcode in the checker on this page and we compare what BT Openreach, Virgin Media Business, CityFibre and other carriers can deliver to your building, with indicative pricing for each speed tier. Availability and price vary street by street depending on how close each carrier’s fibre runs. --- # Business Phone & Broadband Bundles: One Bill, One SLA URL: https://amvia.co.uk/business-phone-and-broadband Last updated: 2026-08 A business phone and broadband bundle combines your connectivity and phone system under one provider and one bill: AMVIA pairs full-fibre business broadband from £29/month (or SoGEA, or a leased line from £69/month where an SLA matters) with hosted VoIP from £5.95 per user per month, with the combined figure built from those published component floors and confirmed per address and user count - no opaque bundle rate, just the two prices you can already see. With the analogue phone network retiring on 31 January 2027, bundling is usually the PSTN migration done properly: connectivity installed first, voice proven in parallel, numbers ported with no gap in service, and one team accountable for call quality end to end. ## Why phone and broadband stopped being separate purchases Two reasons, one technical and one practical. Technically, the PSTN switch-off (31 January 2027) turns every business phone line into a broadband product - after the analogue network retires, your calls travel over an internet connection whether you plan it or not, so the quality of your phone system becomes a property of your connectivity. Practically, split provision is where service quality goes to die: when calls crackle, the phone provider blames the circuit, the ISP blames the phone platform, and you're the unpaid project manager between them. A bundle isn't a discount mechanism - it's an accountability mechanism that happens to also cost less to run. ## What the bundle costs The components carry AMVIA's published floors: full-fibre business broadband from £29/month, hosted VoIP from £5.95 per user per month with UK landline and mobile calls included, and leased lines from £69/month where call volumes or uptime justify the SLA. The bundle is priced from those component floors - there is deliberately no separate bundle rate to decode - with the exact figure depending on your postcode's networks, user count, handset choices and whether call recording or Teams integration is in scope. As with every price we publish, these are honest floors on spec-dependent ranges - the number you'll actually pay arrives with the per-address quote, not after signature. ## Broadband bundle or leased line bundle? The £29 broadband tier carries a small office's calls comfortably - hosted VoIP uses roughly 100Kbps per concurrent call, so bandwidth is rarely the constraint. What moves businesses to the leased line bundle is everything around the bandwidth: an SLA with fix times when the phones are the business, symmetric capacity when heavy uploads share the wire with calls, and QoS on an uncontended circuit when call quality can't be a lottery at 2pm. The honest threshold: if an hour of dead phones has a cost you can name, bundle on a leased line; if not, bundle on broadband and spend the difference elsewhere. Our leased line vs broadband guide walks the decision in full. ## Teams Phone changes the bundle question If your business already runs on Microsoft Teams, the phone half of the bundle can be Teams Phone rather than a separate VoIP platform - real business numbers inside the app your staff already use, via Operator Connect or Direct Routing. The connectivity half of the decision doesn't change: Teams calls ride the same circuit and deserve the same QoS engineering. For businesses not standardised on Teams, the cloud phone system remains the flexible default, and the two can coexist during a transition. ## Comparing bundles honestly (including against ours) Four questions cut through any bundle brochure, ours included. Does the voice platform carry per-user pricing you can see, or a "from" price that only survives until the second user? Is the connectivity quoted across networks, or defaulted to whichever the provider resells? Who owns call quality contractually when both halves come from one place - is there an SLA, and what does it commit to? And what happens at renewal, when bundle discounts traditionally evaporate? For contrast, our review of Virgin's business broadband and phone bundles applies the same questions to a major alternative. Ask them of us and the answers are: published per-user pricing, carrier-compared circuits, one published SLA covering both, and renewal pricing that doesn't rely on you forgetting to check. ## Frequently asked questions Q: How much does a business phone and broadband bundle cost? A: From the published component floors: full-fibre broadband from £29/month plus hosted VoIP from £5.95 per user per month with UK calls included - combined and confirmed per address and user count. We deliberately don’t quote an opaque single bundle rate; compare any rival bundle on the full term: connectivity, per-user voice, handsets, and what the price does at renewal. Q: Is it better to get business phone and broadband from one provider? A: Usually, and for an unglamorous reason: VoIP call quality is a property of the connection it rides, so split provision means split accountability when quality drops. One provider means one SLA covering both, QoS engineered deliberately, and no vendor finger-pointing. The exception is when either half of an existing setup is genuinely excellent and mid-contract - we'll say so when that's the case. Q: Do I still need phone lines with a bundle? A: No - that's rather the point. The analogue network retires on 31 January 2027, and a bundle replaces phone lines with a cloud phone system running over your broadband or leased line. Your numbers port over under the regulated process, and anything else riding on old copper pairs (alarms, card machines, door entry) gets a migration plan of its own. Q: How much bandwidth do business phones need? A: Roughly 100Kbps per concurrent call - so even the £29 full-fibre tier carries a small office's calls with ease. The real engineering is prioritisation (QoS) so calls stay clean when the connection is busy, which is exactly what a properly built bundle configures and a thrown-together one doesn't. Q: Can the bundle use Microsoft Teams as the phone system? A: Yes - Teams Phone (via Operator Connect or Direct Routing) can be the voice half of the bundle, giving staff real business numbers inside Teams. It suits businesses already standardised on Microsoft 365; the hosted VoIP platform remains the default for everyone else, and both are managed by the same team here. --- # Business Fibre Broadband UK: Full Fibre from £29/Month URL: https://amvia.co.uk/business-fibre Last updated: 2026-08-13 Business fibre means full-fibre connectivity sold with business-grade service - and it covers three genuinely different products: full-fibre (FTTP) business broadband from £29/month on a shared network, SoGEA as the no-phone-line transition where fibre hasn't reached you, and dedicated leased lines from £69/month (100Mbps) with symmetric speeds and an uptime SLA. Which one you should buy depends on your postcode's networks, your user count and what an hour of downtime costs you. ## What is business fibre? Strictly, fibre broadband where the fibre runs all the way to your premises (FTTP), sold on business terms: priority support, static IP options, and contract terms built for organisations rather than households. In practice, UK providers use “business fibre” loosely enough that the same phrase covers a £29-a-month shared broadband product and a £1,999-a-month dedicated 100Gbps circuit. The differences that matter are three: contention (shared broadband slows when the street is busy; a dedicated circuit never does), symmetry (broadband uploads are a fraction of downloads; leased lines are equal both ways), and the SLA (broadband is fixed on a best-efforts basis; a leased line carries defined fix times with service credits). ## What is FTTC (fibre to the cabinet)? FTTC is what most UK businesses actually have when they say they have fibre. Fibre runs from the exchange to the green street cabinet, then copper telephone wire carries the connection the final stretch into your building. That copper final mile is the bottleneck. Speed degrades with distance from the cabinet. A business next door to one may get close to the advertised 80Mbps down and 20Mbps up; a business 500 metres away may see 40Mbps or less. FTTC still works for small teams with modest needs, but it is a transitional technology now the copper network is being retired. - Final mile: copper, and it is the limiting factor - Typical speed: up to 80Mbps down and 20Mbps up, falling with distance - Contention: shared bandwidth on a best-efforts service If your team lives in Microsoft 365, Teams calls and cloud apps, FTTC’s weak upload and variability will show. That is usually the trigger to look at FTTP or a business leased line. ## What is FTTP (fibre to the premises)? FTTP removes the copper entirely - fibre runs from the exchange directly into your building. Speed no longer depends on how far you sit from a cabinet, maximum speeds are higher, and latency is lower. Where FTTP is available it should be the default over FTTC for any business that depends on reliable performance. Speeds run from 100Mbps to 1Gbps depending on which network passes your building. FTTP is delivered over Openreach’s expanding build and over CityFibre in the towns and cities where CityFibre has laid its own infrastructure, with new build-outs published regularly by Openreach. - Final mile: fibre all the way, no copper - Typical speed: 100Mbps to 1Gbps download - Upload: far better than FTTC, still well short of a leased line - From: £29/month on business terms FTTP is still broadband, not a dedicated circuit - the bandwidth is contended, shared with others on the network. For most small teams that is fine. When it stops being fine, the answer is a leased line. ## How FTTC, FTTP and leased lines compare The three sit on a ladder. The honest way to choose is by what breaks first for you: distance from the cabinet, upload capacity, or the absence of any guarantee when something fails. | | | FTTC | FTTP | Leased line | Final mile | Copper | Fibre | Dedicated fibre | Speed | Up to 80Mbps, distance-dependent | 100Mbps to 1Gbps | 100Mbps to 100Gbps | Upload | Up to 20Mbps | A fraction of download | Equal to download | Shared with others | Yes | Yes | No | SLA | Best efforts | Best efforts | Contractual fix times | From | - | £29/month | £69/month A leased line is symmetrical and uncontended, and it carries a formal SLA - a fault becomes a breach with a clock on it rather than a best-efforts ticket. That contractual guarantee, not the headline speed, is usually what businesses are actually buying. ## Which business fibre do you actually need? The honest heuristic we use daily: a team of a dozen people doing email, SaaS and video calls is well served by full-fibre business broadband from £29/month - the money saved against a leased line pays for a lot of other IT. The calculation flips when downtime has a per-hour cost you can name, when uploads are constant (off-site backup, media, CAD, large file movement), or when the phones run over the connection and call quality is non-negotiable: that's leased line territory, from £69/month for 100Mbps, and the leased line vs broadband comparison walks the decision properly. And if full fibre hasn't reached your postcode yet, SoGEA bridges you off the retiring copper network until it does. ## Full fibre availability: the real constraint What you can buy is decided by which networks pass your building. Openreach's full-fibre build is the biggest, CityFibre serves large parts of many UK cities, and Virgin's network adds another route - and they don't overlap neatly, which is why two neighbouring postcodes can get completely different quotes. We check all of them in one pass, plus route-dependent carriers like Zayo and Colt for dedicated circuits, and tell you what's genuinely orderable at your address - including when the right answer is “wait three months for the FTTP build instead of signing a long SoGEA contract now”. ## Business fibre pricing, plainly Entry full-fibre business broadband starts at £29/month. Dedicated fibre starts at £69/month for 100Mbps and £129/month for 1Gbps, with installation typically £500–£2,000 depending on address - full tier-by-tier floors are on the leased line pricing page. Every AMVIA price is a published from-price on a spec-dependent range: the exact figure is quoted per postcode, because that is honestly how the economics of fibre work. ## Frequently asked questions Q: What is the difference between business fibre and home fibre? A: Often the same physical network, different service wrap: business products add priority UK support, static IP availability, business contract terms and (on dedicated circuits) an SLA with defined fix times. What business fibre doesn't automatically mean is a dedicated line - a £29/month business FTTP service is still a shared network, just with business-grade service around it. Q: How much does business fibre cost in the UK? A: Full-fibre business broadband from £29/month; dedicated leased lines from £69/month (100Mbps), £129/month (1Gbps) and £349/month (10Gbps) on 36-month terms in well-served areas, plus typical installation of £500–£2,000 on dedicated circuits. All figures are published from-price floors - exact pricing is per postcode. Q: Is full fibre business broadband worth it over FTTC? A: Where FTTP is available, almost always: it's faster, more consistent, unaffected by line length, and it's the network the UK is migrating to as copper retires. FTTC and SoGEA remain sensible only where the fibre build hasn't reached you - and SoGEA specifically exists to get you off the analogue phone network before January 2027 while you wait. Q: When does a business need a leased line instead of fibre broadband? A: When downtime has a nameable hourly cost, when uploads matter as much as downloads (backup, media, CAD), when the phone system runs over the connection, or when compliance demands an SLA. Below those thresholds, business fibre broadband plus a 4G backup is usually the better spend - and we'll say so. Q: Can I get business fibre at my address? A: It depends which networks pass your building - Openreach, CityFibre and Virgin coverage differ street by street. We check all of them (plus route-dependent carriers for dedicated circuits) in one postcode check and come back within 24 hours with what's orderable and at what price. Q: Does AMVIA install and manage the fibre? A: Yes - order, engineer visit, router configuration and ongoing UK-based support are all handled by our Sheffield team. Dedicated circuits include the site survey and carry our published SLA; and if you want connectivity, VoIP and managed IT under one provider, that's the model most of our customers end up on. Q: Is FTTP broadband the same as fibre optic broadband? A: FTTP is genuinely all-fibre from exchange to premises. FTTC is also often marketed as “fibre optic broadband” but has a copper final mile that caps speed and varies with distance. When you evaluate a product, check specifically whether it is FTTP (fibre all the way) or FTTC (fibre to the cabinet, copper from cabinet to building) - the label “fibre” alone does not tell you. Q: What upload speeds can I get on FTTP business broadband? A: Business FTTP runs in tiers from 100Mbps up to 1Gbps download, depending on the infrastructure at your postcode. Upload is typically 50–100Mbps on higher business tiers - much faster than FTTC’s 20Mbps ceiling, but lower than a leased line’s symmetrical rate. If you push large files, run cloud backups or host services, upload is usually the figure that matters most. Q: Is FTTC being switched off? A: Openreach plans to stop new FTTC installations in areas where FTTP is available, and many existing FTTC products will migrate to FTTP as the full-fibre rollout completes. Businesses on FTTC in FTTP-covered areas should plan their migration now; most providers offer like-for-like migrations with no installation disruption. Openreach publishes its build and stop-sell programme, so you can check your area in advance. Q: Can I get FTTP in a rural location? A: Rural FTTP availability is improving but remains patchy. Openreach’s rural rollout, partly funded by the government’s Project Gigabit programme, is extending coverage well beyond towns and cities. Availability has expanded considerably over the past 18 months, so check your postcode - full fibre may now reach addresses where it previously did not. Q: Does business fibre come with a static IP address? A: Business broadband (FTTC or FTTP) typically includes a static IP as standard or as a low-cost add-on, and a leased line includes one as standard. Consumer broadband usually does not. A static IP matters for VPNs, hosted services, remote access and security systems that need a fixed, known address - so confirm it is included before you sign. --- # Business Ethernet: Dedicated Circuits from £69/Month URL: https://amvia.co.uk/leased-lines/business-ethernet Last updated: 2026-08 Business ethernet is a dedicated, symmetric, uncontended data circuit delivered into your premises over fibre - in UK procurement it is the same product as an ethernet leased line or dedicated internet access. AMVIA delivers business ethernet from £69/month for 100Mbps and £129/month for 1Gbps on 36-month terms in well-served areas, SLA-backed (typically 99.99% uptime), quoted per address across Openreach, CityFibre, Virgin and route-dependent carriers. ## Ethernet, leased line, DIA: one product, three names If you're comparing quotes that variously say “business ethernet”, “ethernet leased line” and “dedicated internet access”, compare specifications, not names - they describe the same thing: a point-to-point or internet-connected fibre circuit reserved for your business, symmetric at every tier, uncontended by definition, and sold with an SLA. The vocabulary varies by carrier heritage; the engineering doesn't. Our dedicated internet access page covers the internet-facing product in depth, and the pricing page publishes the per-tier floors most providers hide behind quote forms. ## Specification checklist for procurement Six lines that belong on any ethernet RFQ, in the order they decide the outcome: bearer and service speed (specify both - 200Mbps on a 1Gb bearer beats 200Mbps on a 200Mb bearer for anyone growing); contention (must be 1:1 - anything else is broadband wearing a suit); symmetry (upload equals download, stated); SLA (uptime target, fix time, and the service credits that make both mean something); diversity options (second circuit on a separate route, or 4G/5G backup, if downtime is existential); and excess construction charges (confirmed by survey before signature, never after). A quote that goes quiet on any of these is telling you something. ## What about EFM and EoFTTC? Ethernet in the First Mile (bonded copper pairs) and Ethernet over FTTC had their era when full fibre was scarce: real SLAs at sub-fibre prices. In 2026 that era is closing - copper is being retired, speeds are capped, and the price gap to true fibre ethernet has narrowed to the point where we rarely recommend either except as a stopgap on genuinely hard-to-reach sites. If a provider leads with EFM in 2026, ask them why - and then ask us to check which fibre routes actually reach your postcode. ## Pricing From £69/month for 100Mbps, £129/month for 1Gbps, £349/month for 10Gbps and £1,999/month for 100Gbps on 36-month terms in well-served areas; installation typically £500–£2,000 depending on the civil works your address needs, confirmed by survey. Every figure is a published floor on a spec-dependent range - the exact number is a per-address fact, and we return it within 24 hours, carrier-compared. ## Frequently asked questions Q: Is business ethernet the same as a leased line? A: Yes. Business ethernet, ethernet leased line, dedicated leased line and dedicated internet access all describe the same product: a fibre circuit reserved for one business, symmetric and uncontended, with an SLA. The name varies by seller; the specification is what to compare. Q: How much does business ethernet cost? A: From £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps on 36-month terms in well-served areas, with installation typically £500–£2,000 depending on address. Prices are per-postcode floors - carrier competition on your street decides how close to them you land. Q: What is a bearer, and why does it matter? A: The bearer is the physical capacity of the circuit; the service speed is what you pay to use. A 200Mbps service on a 1Gb bearer upgrades to 500Mbps or 1Gbps by configuration change - the same upgrade on a 200Mb bearer means new installation. Growing businesses should almost always buy the bigger bearer. Q: Is EFM still worth buying in 2026? A: Rarely. EFM runs over copper pairs that are being retired, its speeds are capped far below fibre, and fibre ethernet prices have fallen to the point where the saving seldom justifies the ceiling. It survives as a stopgap for genuinely hard-to-reach sites - and even there, checking every fibre route first is the right move. Q: How long does an ethernet circuit take to install? A: It depends on the route: premises near existing carrier fibre can be weeks; sites needing new construction, wayleaves or road crossings take longer. The survey stage tells you honestly before you commit, and we manage the carrier throughout - including escalations when a build slips. --- # Dark Fibre for UK Businesses: Unlit Fibre, Your Equipment URL: https://amvia.co.uk/leased-lines/dark-fibre Last updated: 2026-08 Dark fibre is unlit optical fibre leased as the physical strand: the provider supplies the glass between two points and you supply the equipment that lights it, so capacity is limited only by your optics. It is priced per route (distance, carrier and scarcity - not bandwidth), typically on multi-year terms, and it genuinely suits data-centre interconnect, large campuses and organisations with in-house optical skills. For most businesses, a lit ethernet circuit - 10Gbps from £349/month - delivers the capacity without the engineering obligations, and Ethernet First Mile (EFM), the old copper-bonding alternative, is now a legacy footnote. ## What dark fibre actually is Every fibre service you can buy is the same physical thing - glass strands in the ground - differing only in who lights them. On a leased line, the carrier lights the fibre and sells you a service at a speed. On dark fibre, nobody lights it until you do: you lease the strand itself, put optical equipment on both ends, and the capacity is whatever your optics can drive - 10Gb today, 100Gb by swapping transceivers, multiple wavelengths if you run DWDM. That's the whole product. The power and the obligations both follow directly from it. ## How dark fibre is priced in the UK Per route, not per megabit. The carrier prices the strand on distance, the route's construction cost, term length and - bluntly - scarcity, since spare strands between two useful points are a finite resource. That's why no honest provider publishes a dark fibre rate card, and why AMVIA quotes dark fibre per route - bespoke to the endpoints, with multi-year terms the norm. The discipline that keeps the decision honest: always price the equivalent lit service alongside. If your requirement is 10Gbps between two sites, the number to beat is a managed 10Gbps circuit from £349/month - dark fibre wins that comparison at scale and with growth, and loses it for a single steady-state link more often than the marketing admits. ## Dark fibre vs a lit leased line Three trade-offs decide it. Capacity economics: lit services charge again each time you upgrade; dark fibre absorbs growth by changing your own optics - decisive when you can already see the growth curve. Control: with dark fibre nothing of the provider's sits in your transmission path - attractive for encryption and latency reasons, if you have the team to own it. Responsibility: when a lit circuit fails, the carrier's SLA clock runs; when dark fibre fails, diagnosing whether it's your optics or the strand is your first job. Our business ethernet page covers the lit product line this gets compared against, and the pricing page publishes the lit floors. ## Where EFM fits (historically) Ethernet First Mile deserves a paragraph because procurement documents still mention it: EFM delivered ethernet over bonded copper pairs - a clever answer to fibre scarcity that gave real SLAs at sub-fibre prices in the 2010s. With full fibre now widespread and the copper network being retired, EFM is a legacy product: speed-capped, on borrowed infrastructure, and rarely quotable for new supply. If EFM is the only thing reachable at a site, that's a signal to check the fibre build timeline - and in the meantime SoGEA or 4G/5G usually bridges better than new copper commitments. ## The honest recommendation Ask two questions. Do you have - or want to build - the optical engineering capability to own a transmission layer? And can you already see growth that makes re-buying lit bandwidth expensive? Two yeses: dark fibre is a genuinely good product, and we'll route-check it properly. Anything else: take the lit circuit, keep the SLA, and spend the difference on the parts of your IT that actually differentiate you. We make the same margin either way, which is what lets us tell you straight. ## Frequently asked questions Q: What is dark fibre? A: Optical fibre leased as the unlit physical strand: the provider supplies the glass between two points, you supply and run the equipment that lights it. Capacity is set by your optics rather than a service tier - which is both the entire appeal and the entire obligation. Q: How much does dark fibre cost in the UK? A: It's priced per route - distance, construction cost, term and strand scarcity - not per megabit, so there is no honest rate card and every quote is bespoke, typically on multi-year terms with annual charges. The benchmark to hold any dark fibre quote against is the equivalent lit service: a managed 10Gbps circuit from £349/month. Q: Is dark fibre faster than a leased line? A: It's not inherently faster - it's uncapped. A lit leased line runs at the speed you bought; dark fibre runs at whatever your optical equipment drives, and upgrades by changing optics rather than re-contracting. For a fixed, steady requirement that flexibility may be worth little; for compounding growth it's the whole point. Q: Who should buy dark fibre? A: Organisations connecting data centres or large sites, ISPs and public-sector estates with heavy growth, and anyone whose control or encryption requirements demand owning the transmission layer - provided they have the optical engineering to run it. Most SMEs are better served by a lit ethernet circuit with an SLA, and we'll say so when that's the honest answer. Q: What is Ethernet First Mile (EFM), and should I consider it? A: EFM delivered ethernet over bonded copper pairs - a respectable pre-full-fibre product that is now legacy: speed-capped, running on infrastructure being retired, and rarely available for new orders. In 2026 the practical alternatives are fibre ethernet where built, and SoGEA or 4G/5G as bridges where it isn't. --- # Leased Line Prices 2026: 100Mb from £69, 1Gb from £129/Month URL: https://amvia.co.uk/leased-lines/pricing Last updated: 2026-08 Leased line pricing by speed tier: 100Mbps from £69, 1Gbps from £129, 10Gbps from £349/month on 36-month terms, install typically £500–£2,000. The floors, what moves them, and exact per-postcode quotes in 24 hours. ## 100Mbps leased line cost From £69 a month on a 36-month term in well-served areas. At this tier the decision is rarely the monthly price - it's whether to take the 100Mbps service on a 1Gb bearer, which raises the monthly slightly but turns a future upgrade to 500Mbps or 1Gbps into a configuration change instead of a second installation. For most businesses buying 100Mbps today, the honest advice is: take the bigger bearer, because bandwidth demand only moves one way. ## 1Gbps leased line cost From £129 a month - and the reason it's our most-quoted tier is that the step up from 100Mbps is small in cash terms and large in headroom. A 1Gbps symmetric, uncontended circuit comfortably carries VoIP, video, cloud backup and a full office's SaaS workload simultaneously. If your quote for 1Gbps comes back far above this floor, it's usually a one-carrier postcode - worth checking alternative routes before accepting it, which is exactly what we do across carriers. ## 10Gbps and beyond From £349 a month for 10Gbps, and from £1,999 for 100Gbps. These tiers stop being about user counts and start being about workloads: large file movement, site-to-site replication, media, CAD, or aggregating branch traffic at a head office. Install lead times matter more here too - higher-bearer circuits are more likely to need carrier network build, so start the conversation before the capacity crunch, not during it. ## Installation costs, honestly UK leased line installation typically runs £500–£2,000 (2026), covering the civil works, fibre, carrier hand-off and router. The spread is almost entirely about your address: urban premises near existing fibre sit at the bottom of the range, sites needing new ducting or wayleaves at the top - and a genuinely difficult site can exceed it, which a proper survey will tell you before you commit, not after. Carriers periodically waive or subsidise install on 36-month terms; when that promotion exists on a route we quote, it shows up in your quote. ## Why "from" prices are honest here Every leased line price on this page is a floor, not an average - the best case in a well-served area on a 36-month term. We publish them anyway because the alternative, quote-form-only pricing, wastes everyone's time. Your exact figure depends on postcode, carrier routes, bearer and term; the leased line checker turns those floors into a real per-address price within 24 hours, compared across BT Openreach, CityFibre, Virgin and route-dependent carriers such as Zayo, Colt and regional networks. For the full budgeting picture - including router, resilience options and what happens at renewal - see the leased line cost guide, or compare against a cheaper alternative in leased line vs broadband. ## Leased line deals: what a good one looks like The deals worth taking are structural, not promotional: the right bearer for your growth, install included on the term you'd have chosen anyway, an SLA with defined fix times, and a price benchmarked across every carrier that reaches your postcode rather than one provider's list price. That last one is the whole game - most "expensive" leased line quotes are simply single-carrier quotes. We compare routes as standard, and customers who take connectivity alongside managed IT get the circuit, the network edge and the support under one SLA. ## Frequently asked questions Q: How much does a leased line cost in the UK? A: From £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps on 36-month terms in well-served areas, plus installation typically £500–£2,000 depending on the address. These are floors, not averages - the exact price is always quoted per postcode because carrier routes and civil works vary street by street. Q: How much does a 100Mb leased line cost? A: From £69/month on a 36-month term where carrier competition is good. Consider paying slightly more for the 100Mbps service delivered on a 1Gb bearer: it makes the eventual upgrade a configuration change rather than a second installation. Q: How much is a 1Gb leased line? A: From £129/month on a 36-month term in well-served areas - the most popular tier we quote, because the uplift from 100Mbps is small against the headroom gained. Quotes far above that floor usually indicate a single-carrier postcode, which is worth challenging with alternative routes before accepting. Q: Why do leased line prices vary so much by postcode? A: Because the price is mostly the cost of reaching you. Premises near existing fibre routes from BT Openreach, CityFibre or Virgin connect cheaply; addresses needing new ducting, road crossings or wayleaves carry real construction cost. Carrier competition matters too - postcodes served by multiple networks price sharpest. Q: Is installation free on a leased line? A: Sometimes, on longer terms, when a carrier is running an install promotion on your route - but the honest default is to budget £500–£2,000 (typical UK 2026 range). Any quote claiming universally free installation is recovering the cost somewhere else, usually in the monthly. Q: What's included in AMVIA's leased line price? A: The circuit itself - symmetric, uncontended, SLA-backed (typically 99.99% uptime) - with the router and proactive monitoring, quoted per address across every carrier that reaches your postcode. Options like 4G/5G backup, managed firewalls and a second diverse circuit are priced separately so you only pay for the resilience you actually want. --- # What Is a Leased Line? Plain-English Guide (+ 2026 Costs) URL: https://amvia.co.uk/leased-lines/what-is-a-leased-line Last updated: 2026-03 A leased line is a dedicated, uncontended internet connection reserved for one business. Unlike shared broadband, the bandwidth is yours alone, upload and download speeds are equal, and a service level agreement guarantees uptime with financial compensation. AMVIA sources and manages business leased lines from multiple UK carriers as one accountable, security-first provider. A leased line goes by several names - Ethernet leased line, dedicated internet access (DIA), or private circuit - but the principle never changes. A dedicated fibre runs point-to-point from your premises to the carrier's network, then to the internet. That path is yours. Nobody else's traffic touches it, so the speed you buy is the speed you get, every hour of every day. ## How is a leased line different from business broadband? A leased line is dedicated and uncontended; broadband is shared. With broadband, many homes and businesses use the same exchange infrastructure at once, so your real-world speed drops when the network is busy. A leased line removes that contention entirely and adds symmetric speed, static IPs and a hard SLA. The differences go well beyond headline speed. Each one maps to a day-to-day operational outcome: | | Feature | Leased line | Business broadband | Bandwidth | Dedicated, uncontended | Shared, contended | Upload vs download | Symmetric (equal) | Asymmetric (slow upload) | IP addresses | Block of static public IPs | Usually dynamic | Uptime SLA | 99.99% with compensation | Best-efforts, no compensation | Fault response | Priority, fix-time targets | Standard queue For context, Ofcom's UK Home Broadband Performance reporting put the UK average broadband download speed at 69.4 Mbps in 2024. That number is an average of a shared, asymmetric service - upload speeds on FTTC broadband are often only 10–20 Mbps regardless of download, which throttles VoIP, video calls and cloud backup. A leased line gives equal upload, so those workloads stop fighting for headroom. ## What types of leased line can UK businesses buy? There are three main leased line types in the UK, and the right one depends on budget, location and bandwidth. Most SMEs buy an Ethernet Access Direct circuit; some choose a lower-cost FTTC variant; a minority of large sites take dark fibre and run their own electronics. - Ethernet Access Direct (EAD): A full dedicated fibre from your premises to the carrier exchange, available from 100 Mbps to 100 Gbps. This is what most businesses mean by "a leased line". - Ethernet over FTTC (EoFTTC): Uses existing FTTC infrastructure but delivers a dedicated, uncontended service. Cheaper than full EAD, with lower top speeds - a sensible middle tier when broadband isn't reliable enough but a full circuit isn't justified. - Dark fibre: An unlit fibre pair where you provide the active equipment. Used by larger organisations with very high bandwidth or specialist routing needs. If your priority is fast deployment over a guaranteed dedicated path, an FTTP leased line can be a strong middle ground in areas where full-fibre is already built. ## What speed of leased line does your business need? Leased lines run from 100 Mbps to 100 Gbps, but most UK SMEs sit at 100 Mbps, 500 Mbps or 1 Gbps. The right figure depends on user count, how cloud-heavy your workloads are, and whether you host services others connect into. Because the line is symmetric, upload capacity matters as much as download. | | Speed | Typical fit | 100 Mbps | 30–50 staff on cloud apps and VoIP | 500 Mbps | 100–200 users or heavy cloud data transfer | 1 Gbps | Hosted infrastructure, cloud ERP, large file transfer Symmetric upload is the quiet differentiator. Businesses backing up to the cloud or running hosted phone systems feel it immediately - a busy call queue or a nightly backup no longer collides with everyone else's traffic. Ofcom's Connected Nations reporting shows roughly 96% of UK premises can now get superfast broadband of 30 Mbps or more (Ofcom, 2024), yet that headline still hides weak, asymmetric upload - which is exactly where a leased line wins. ## How much does a leased line cost in the UK? UK leased line pricing is driven mainly by distance from your premises to the nearest carrier point of presence, then by speed and contract term. Urban sites near existing fibre are cheapest; rural sites can carry excess construction charges. As a current guide: | | Speed | Typical UK monthly cost | 100 Mbps | from £69/month | 500 Mbps | ~£300–£600 (typical UK 2026 range) | 1 Gbps | from £129/month Prices are usually quoted on 36-month terms; shorter terms cost more per month. Installation can be zero on well-served business parks or significant where new fibre must be dug. AMVIA compares quotes from multiple carriers for your exact postcode rather than pushing a single network, so the figure you see reflects what's genuinely buildable at your site. ## How long does leased line installation take? Leased line installation typically takes 30 to 90 days from order to go-live. The biggest variable is civil engineering: how far new fibre must be laid and whether the route crosses third-party land needing wayleave agreements. City-centre and business-park sites with nearby infrastructure land at the short end of that range. The stages are predictable: site survey, fibre route planning, any wayleaves, civil works, then installation of the network termination equipment inside your building. Because timelines swing on groundwork, we advise starting procurement at least 60 days before your required go-live date. If a critical cutover is looming, that lead time is the difference between a calm migration and an emergency. ## What uptime does a leased line SLA guarantee? A leased line SLA typically guarantees 99.9% or higher availability - under nine hours of unplanned downtime a year - with the strongest tiers at 99.99% (under an hour). Crucially, leased line SLAs are backed by financial compensation when targets are missed, unlike the best-efforts SLAs that come with broadband. Just as important are the response and fix targets. A standard business leased line usually carries a four-hour response and a next-business-day fix; enhanced SLAs offer four-hour fix guarantees for businesses where an outage costs real money by the hour. For sites that cannot tolerate any downtime, a leased line is often paired with backup connectivity so a second, diverse path takes over automatically. ## Which businesses actually need a leased line? A leased line suits any business where reliable, high-performance connectivity is operationally critical. Clear signals include 20+ staff on one connection, heavy use of Microsoft 365 or cloud ERP, on-site or hosted servers reached over VPN, daily video conferencing, or a contractual requirement for guaranteed bandwidth and an SLA. If you run several offices, the line rarely sits alone - it becomes the backbone for multi-site connectivity, often wrapped in SD-WAN to route traffic intelligently between sites and the cloud. For smaller firms not yet at that threshold, full-fibre broadband can be a sensible interim step. Ofcom's Connected Nations data shows gigabit-capable coverage now reaches the large majority of UK premises - but coverage is not the same as a guaranteed, contended-free service, and that distinction is the whole point of a leased line. AMVIA advises honestly on which side of that line your business sits. ## Frequently asked questions Q: What is the difference between a leased line and business broadband? A: A leased line is a dedicated, uncontended fibre connection with symmetric speeds, static IP addresses, and an SLA that guarantees uptime with financial compensation. Business broadband is a shared, contended service with asymmetric speeds, usually dynamic IPs, and best-efforts support. The leased line delivers its contracted bandwidth at all times; broadband speeds are not guaranteed. Q: What price range should you expect for a UK leased line? A: UK leased lines start from around £69 per month for entry-level 100 Mbps connections and rise into several hundred pounds a month for higher speeds, depending mainly on your distance from the nearest carrier fibre. Contracts are usually 36 months. AMVIA compares quotes from multiple carriers for your exact location to find the most competitive buildable option. Q: How long does leased line installation take? A: Leased line installation typically takes 30 to 90 days from order to go-live. The main variable is civil engineering - how much new fibre must be laid and whether wayleave agreements are needed for third-party land. Well-served urban and business-park sites land at the shorter end. Start procurement at least 60 days before your required go-live date. Q: Does a leased line include an uptime guarantee? A: Yes. A leased line typically guarantees 99.9% or higher availability - under nine hours of unplanned downtime a year - with the top tiers at 99.99%. Unlike broadband, the SLA carries financial compensation if targets are missed, plus defined response and fix times: commonly a four-hour response with next-business-day fix, and enhanced four-hour fix options. Q: What speed of leased line does my business need? A: Most UK SMEs choose 100 Mbps, 500 Mbps or 1 Gbps. As a rough guide, 100 Mbps comfortably supports 30–50 staff on cloud apps and VoIP, 500 Mbps suits 100–200 users or data-heavy workloads, and 1 Gbps fits hosted infrastructure and large routine file transfers. Because leased lines are symmetric, upload capacity counts as much as download. Q: Is a leased line worth it for a small business? A: It depends on your dependence on connectivity, not just your headcount. If VoIP calls drop, cloud apps stall, or remote staff lose VPN access, the cost of downtime usually outweighs the price gap over broadband. Smaller firms with lighter needs can start on full-fibre broadband and move up later. AMVIA advises honestly on which fits. --- # Dedicated Internet Access (DIA): Uncontended Business Fibre URL: https://amvia.co.uk/leased-lines/dedicated-internet-access Last updated: 2026-03 Dedicated internet access (DIA) is an uncontended, symmetric leased-line circuit reserved entirely for one business. Unlike shared broadband, it guarantees the same upload and download speed at all times, backed by a financially-enforced SLA. AMVIA delivers DIA from £69 a month - one provider, security-first, Microsoft-certified. DIA sits at the heart of our business leased lines range. If you are still weighing the basics, start with what a leased line is before you read on. ## What is dedicated internet access? Dedicated internet access is a private fibre circuit that belongs to your business alone, with a 1:1 contention ratio and matching upload and download speeds. No other organisation shares the line, so performance does not sag at peak times. Every DIA circuit ships with a service level agreement that pays out if uptime targets are missed. That uncontended design is the whole point. A standard broadband connection is sold many times over on the same exchange; a DIA circuit is sold once, to you. The result is predictable latency, predictable throughput, and a contract that holds the carrier financially accountable. - Uncontended (1:1): the full bandwidth is yours at all hours - Symmetric: identical upload and download speeds - SLA-backed: financial credits when the provider misses targets - Scalable: speeds from 10 Mbps to 10 Gbps on the same circuit type ## How does AMVIA deliver your dedicated connection? AMVIA manages the whole DIA lifecycle: survey, carrier procurement, install, and 24/7 monitoring. We hold the carrier relationship so you deal with one accountable provider, not three. Critical issues are responded to within one hour, with a named engineer assigned to your circuit. 1. Site survey and pricing - we check carrier availability at your postcode and quote across multiple providers to find the best fit. 2. Circuit provisioning - we order and project-manage the dedicated fibre circuit, keeping you updated through every carrier milestone. 3. Install and testing - engineers fit the circuit and CPE, then run throughput and latency tests to confirm the SLA is met on day one. 4. Monitoring and support - round-the-clock circuit monitoring with proactive alerting and direct escalation to the carrier on your behalf. For sites that need resilience, pair DIA with backup connectivity so a single fibre fault never takes you offline. ## DIA vs business broadband: what's the real difference? Dedicated internet access guarantees the speed you pay for; broadband does not. Broadband contends bandwidth across many users and offers upload speeds far below download. DIA gives you symmetric, uncontended throughput with an SLA - the standard a business running cloud platforms and VoIP actually needs. | | Feature | Dedicated internet access (DIA) | Business broadband | Contention ratio | 1:1 (uncontended) | Up to 50:1 (shared) | Upload vs download | Symmetric (equal) | Asymmetric (low upload) | Uptime SLA | Financially-backed | Best-effort, no credits | Speed consistency | Guaranteed at all times | Drops at peak hours | Typical install | 45–90 working days | Days to weeks For context, the UK average broadband download speed is around 69.4 Mbps (Ofcom Connected Nations 2024). A DIA circuit delivers its rated speed both ways, every hour, regardless of how busy the local exchange gets. ## Why do UK SMEs need dedicated internet access? UK businesses now run on cloud platforms - Microsoft 365, hosted servers, VoIP, video - and every one of those depends on reliable upload as much as download. When a shared broadband line slows at 3pm, calls drop and backups stall. DIA removes that risk with guaranteed, symmetric bandwidth. The wider network is shifting too: copper-based phone services are being switched off as the UK moves to all-IP connectivity (Ofcom PSTN switch-off guidance). A dedicated fibre circuit is the dependable foundation for that move, and it pairs naturally with SD-WAN connectivity when you scale across sites. - Cloud backups and large file transfers finish on time, both directions - VoIP and video conferencing stay clear under load - Latency-sensitive apps behave predictably for every user - A financial SLA gives you recourse when something breaks ## How much does dedicated internet access cost? AMVIA dedicated internet access starts from £69 per month for a 100 Mbps circuit, with speeds available from 10 Mbps up to 10 Gbps. Price depends on the speed you need and how far existing fibre reaches your premises. Where new fibre is required, civils work can affect both cost and lead time. | | Speed tier | Typical use | Starting price | 100 Mbps | Small office, cloud-first team | From £69/mo | 1 Gbps | Growing SME, heavy cloud use | Quoted on survey | 10 Gbps | Multi-site or data-intensive | Quoted on survey Running several locations? Our multi-site connectivity options bring every office onto one managed network, and leased line security hardens the circuit against threats. ## How does AMVIA support your circuit after install? Support does not stop at handover. AMVIA monitors every DIA circuit 24/7, responds to critical issues within one hour, and escalates faults straight to the carrier so you do not have to chase. You get a named account team that already knows your environment. AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we manage IT and connectivity for over 1,200 UK businesses across legal, finance, healthcare, and professional services. One provider, security-first, Microsoft-certified. ## Frequently asked questions Q: What is dedicated internet access (DIA)? A: DIA is an uncontended, symmetric leased-line circuit reserved entirely for your business - the full contracted speed, upload and download, at all times, backed by a financially-backed SLA. It's the same product as a business leased line; DIA is simply the industry term. Q: How much does dedicated internet access cost? A: From £69/month for 100Mbps in well-served postcodes, with 1Gbps from £129 and 10Gbps from £349. The exact figure depends on which carriers have fibre near your building - which is why AMVIA compares every network at your exact postcode rather than quoting one rate card. Q: Is DIA different from fibre broadband? A: Fundamentally. Fibre broadband - even full-fibre FTTP - is contended: capacity is shared with other premises and speeds are best-effort with no fix-time guarantee. DIA is dedicated to you alone, symmetric, and backed by an SLA of typically 99.99% with service credits when it's breached. Q: Who actually needs dedicated internet access? A: Businesses where connectivity failure has a direct cost: cloud-first teams, VoIP-dependent offices, firms hosting systems others must reach, and anyone whose broadband visibly drags at peak times. Around 25+ staff on cloud apps is the practical threshold where DIA starts paying for itself. --- # FTTP Leased Line for Business: Speeds, Costs & SLAs URL: https://amvia.co.uk/leased-lines/fttp-leased-line Last updated: 2026-03 An FTTP leased line is a dedicated, uncontended fibre circuit delivered over the Openreach full-fibre network, giving your business symmetric speeds from 100Mbps to 1Gbps on a contractual uptime SLA. AMVIA compares 15+ UK carriers to find the right circuit at the lowest price - one provider, security-first, Microsoft-certified. If you are weighing connectivity options, start with our business leased lines pillar overview, then check whether FTTP, EAD, or alternative-network fibre suits your site below. ## What is an FTTP leased line? An FTTP (fibre to the premises) leased line is a private, dedicated internet circuit carried over Openreach's full-fibre infrastructure. Unlike shared broadband, the bandwidth is yours alone - uncontended, symmetric, and backed by a contractual service level agreement covering uptime and fault repair. The difference from consumer FTTP broadband matters. Both arrive on full fibre, but a leased line guarantees the throughput you pay for around the clock, where consumer FTTP is best-effort and shared. For background on the technology, read what is a leased line. - Symmetric speeds - upload matches download, 100Mbps to 1Gbps - Uncontended - no sharing with 20–50+ other users - SLA-backed - a 100% availability guarantee on Amvia-supplied circuits, with automatic service credits if targets are missed - Low latency - typically under 10ms within the UK for VoIP and cloud apps ## How is FTTP different from a traditional EAD leased line? FTTP leased lines run over Openreach full fibre, while EAD (Ethernet Access Direct) circuits are delivered over dedicated point-to-point fibre paths. Both give you symmetric, uncontended, SLA-backed bandwidth - but FTTP is usually faster to install and cheaper for equivalent speeds where Openreach fibre already reaches your site. | | Feature | FTTP leased line | EAD leased line | Network | Openreach full fibre | Dedicated fibre path | Speeds | 100Mbps–1Gbps symmetric | 100Mbps–10Gbps symmetric | Typical install | 20–45 working days | 60–90 working days | Relative cost | 20–40% cheaper (typical UK 2026 range) | Higher for equivalent speed | Availability | Openreach fibre footprint | Near-universal (build cost varies) | SLA | 99.95% uptime | 99.95%+ uptime If you need 10Gbps, multi-site routing, or build-anywhere reach, EAD or SD-WAN may fit better. For most single-site SMEs in a fibre area, FTTP delivers the same guarantees for less. ## Why do UK businesses need an FTTP leased line? Downtime is expensive and shared broadband makes it likelier. A leased line removes contention, guarantees throughput, and puts repair times in a contract - so a peak-hour slowdown or an unexplained outage stops costing you staff hours, sales, and cloud access. UK businesses lose an estimated £3.7bn a year to internet failures (Beaming, 2023). Against that, a guaranteed circuit is cheap insurance. It also fixes the throughput gap: the UK average broadband download speed is just 69.4Mbps (Ofcom Connected Nations 2024), whereas an FTTP leased line gives guaranteed symmetric speed up to 1Gbps. - Cloud and Microsoft 365 - fast, symmetric upload keeps backups and Teams HD video reliable - VoIP quality - low latency and minimal jitter keep calls clear; pair it with a hosted phone system - Resilience - SLA-backed fix times, with optional backup connectivity for failover - Growth headroom - scale bandwidth without re-cabling ## Leased line vs business broadband - what's the real difference? Business broadband shares one connection across many users on a best-effort basis, so speeds drop at peak times. An FTTP leased line is contended by no one: you get 100% of your provisioned, symmetric bandwidth 24/7, plus a financially backed uptime guarantee broadband never offers. For a side-by-side breakdown, see leased line vs business broadband. The short version: broadband suits low-stakes browsing; a leased line suits any business that depends on the cloud, VoIP, or guaranteed availability. If you want a private, secure path for multiple offices, look at dedicated internet access. ## How long does an FTTP leased line take to install? Where Openreach fibre is already in place, FTTP leased line installation typically takes 20–45 working days - noticeably faster than the 45–90 working days a general leased line or EAD build can need. Rural sites or those needing civil works sit at the longer end. A typical install runs through four stages: 1. Site survey - a surveyor confirms the fibre route and whether civil works are needed (week 1–2) 2. Wayleave - legal permissions if fibre crosses third-party land; the most common source of delay (week 2–6) 3. Civil engineering - engineers run fibre from the exchange to your building where required (week 4–10) 4. Go-live - the circuit is terminated, tested against the SLA, and handed over (week 10–12) ## How much does an FTTP leased line cost? A 100Mbps leased line typically costs £69–£320/month depending on location, because pricing varies street by street with distance to the nearest fibre aggregation point. For most businesses that is less than the cost of a single serious outage. The only way to know your exact price is a postcode check. AMVIA compares 15+ UK carriers and shows transparent breakdowns - install fees, monthly cost, and any excess construction charges - before you commit. Going direct to one carrier only ever shows you their pricing; comparison makes them compete. ## Why choose AMVIA for your FTTP leased line? AMVIA Limited is registered with Ofcom as a communications provider, with BT-trained network engineers and 15+ years of carrier infrastructure experience. We are a security partner first, so your connectivity is delivered by a team that also runs your Microsoft 365 and security stack - one accountable provider. - Independent comparison - 15+ UK suppliers quoted for your exact postcode, no hidden charges - Direct UK engineers - call 0333 733 8050 for UK-based, BT-trained engineers; no offshore call centres - Same speeds, lower prices than going direct to BT or Virgin - Cyber Essentials Plus certified - AMVIA protects over 1,200 UK businesses, with security built into how we deliver connectivity That security-first stance is why connectivity, voice, and Microsoft 365 sit better under one provider than three - one accountable team for the whole estate. ## Frequently asked questions Q: What is the difference between FTTP and a traditional EAD leased line? A: FTTP leased lines use the Openreach full-fibre network, whereas EAD circuits are delivered over dedicated point-to-point fibre paths. FTTP is usually cheaper for equivalent speeds and has shorter lead times. Both deliver symmetric, uncontended bandwidth with SLA-backed uptime, but FTTP availability depends on Openreach coverage at your site. Q: How long does an FTTP leased line take to install? A: FTTP leased line installation typically takes 20–45 working days where Openreach fibre is already in place - significantly faster than EAD circuits, which often take 60–90 days. Sites needing wayleaves or civil engineering sit at the longer end of that range, so an early site survey helps set realistic expectations. Q: What speed options are available on FTTP leased lines? A: FTTP leased lines run at symmetric speeds from 100Mbps up to 1Gbps, depending on the Openreach product and carrier. Every speed is uncontended and guaranteed, unlike consumer FTTP broadband, which is best-effort. AMVIA quotes across multiple carriers to find the best speed and price for your requirements. Q: Is FTTP available at my business premises? A: FTTP leased line availability depends on Openreach's full-fibre rollout to your area. Because a leased line carries a contractual uptime SLA, it is worth checking eligibility. AMVIA runs a free site survey to confirm whether FTTP, EAD, or alternative-network fibre is available at your postcode and recommends the best-value option. Q: Does an FTTP leased line come with an SLA? A: Yes. FTTP leased lines include a service level agreement covering uptime, fault response, and fix targets - commonly 99.9%–99.95% availability with five-hour fix times for critical faults. Amvia's own published Leased Line SLA goes further: a 100% availability guarantee on Amvia-supplied circuits, a 5-hour return-to-service target, and automatic service credits when targets are missed. AMVIA monitors your circuit around the clock and raises faults proactively, often before you notice a problem, so your business stays connected. --- # SD-WAN for Multi-Site UK Businesses: How It Works & When It Wins URL: https://amvia.co.uk/leased-lines/sd-wan Last updated: 2026-03 SD-WAN (software-defined wide area network) is an intelligent overlay that pools every connection at every site - leased lines, FTTP, broadband, 4G/5G - and routes each application down the best-performing path in real time. AMVIA designs, deploys and manages it end to end: one provider, security-first, Microsoft-certified. If you are weighing this against a dedicated circuit, start with our business leased line pillar, then compare the two side by side in MPLS vs SD-WAN. ## What is SD-WAN and how does it work? SD-WAN replaces rigid, hardware-defined routing with software policies that sit across all of your WAN links. Edge appliances at each site continuously measure latency, jitter and packet loss, then steer traffic - voice, Microsoft 365, line-of-business apps - onto whichever path performs best, failing over in milliseconds when a link degrades. In practice that means: - Active-active links - broadband and leased line carry traffic together, not one sitting idle as a spare. - Application-aware routing - Teams calls take the low-latency path; backups take the cheap one. - Sub-second failover - a dropped circuit reroutes before users notice. - Central policy control - one dashboard governs every branch, not box-by-box configuration. ## What's included in AMVIA's managed SD-WAN? AMVIA's managed SD-WAN is a fully run service, not a box you self-configure. Our Sheffield-based engineers handle design, edge hardware, traffic policies, security overlay and ongoing optimisation, with monitoring around the clock and critical issues responded to within one hour. - Edge appliances shipped, installed and configured at every site. - Traffic-steering policies tuned to your priority applications. - Encrypted overlay with segmentation between sites and the internet - pair it with leased-line security for end-to-end protection. - 24/7 monitoring and proactive fault resolution by UK-based engineers. - Monthly reporting on performance, availability and capacity. ## Why do UK SMEs need SD-WAN? Most multi-site SMEs over-pay for under-used circuits while critical apps still stutter. SD-WAN fixes both: it makes ordinary broadband enterprise-grade by bonding and prioritising it, so you add resilience without buying a dedicated line for every branch. The headroom is real. The UK average broadband download speed was 69.4 Mbps in 2024 (Ofcom Connected Nations 2024) - fast enough that, steered intelligently, commodity links can carry production traffic that once demanded MPLS. As your applications move to the cloud, direct breakout to Microsoft 365 at each site removes the hairpin back to head office. Microsoft 365 now serves over 400 million paid commercial seats globally, so cloud-path performance is no longer a side issue. Securing that wider attack surface matters too. The NCSC recommends segmentation and encrypted transport across distributed networks - both native to a well-designed SD-WAN fabric. ## SD-WAN vs MPLS - which is right for multi-site? MPLS guarantees performance but is expensive and slow to provision; SD-WAN layers intelligent routing over any connection at lower cost, and many businesses run a hybrid of both. The table below sets out the trade-offs. | | Factor | MPLS | SD-WAN (AMVIA managed) | Link types | Single carrier circuit | Any mix: leased line, FTTP, broadband, 5G | Cost profile | High, fixed per site | Lower; uses commodity links efficiently | Provisioning | Weeks to months | 2–4 weeks on existing broadband | Failover | Manual / limited | Automatic, sub-second | Cloud breakout | Backhauled via core | Direct at each site | Central control | Carrier-managed | Self-service policy dashboard For a deeper resilience design, combine SD-WAN with backup connectivity and multi-site connectivity. ## How does AMVIA deploy your SD-WAN? Deployment runs in four stages and typically takes 2–4 weeks where suitable broadband already exists; allow 45–90 working days when new leased lines are required. We map first, design second, and only ship hardware once the policy model is agreed. 1. Network discovery - map the existing WAN, measure bandwidth at each site, capture application priorities. 2. SD-WAN design - build the overlay: traffic-steering rules, failover logic, security and segmentation policy. 3. Edge deployment - ship, install and configure appliances at every location. 4. Optimisation and management - continuous tuning, 24/7 monitoring and proactive fault resolution. If you are still settling the underlying circuit, read what is a leased line or compare dedicated internet access options first. ## How much does SD-WAN cost? There is no single sticker price - cost depends on site count, link mix and bandwidth - but the saving lever is consistent: replacing or supplementing premium circuits with intelligently steered commodity links. AMVIA SD-WAN deployments typically reduce WAN costs by 30–50% - a typical UK 2026 range for multi-site networks - while improving resilience. - Per-site model - pricing scales with the number of edge appliances and managed sites. - Hybrid savings - keep a leased line where you need a 99.99% uptime SLA; use SD-WAN-steered broadband everywhere a guaranteed circuit is overkill. - One bill, one provider - connectivity, overlay and security under a single accountable contract. ## Why choose AMVIA for SD-WAN? AMVIA is a UK managed security and connectivity partner, not a telecoms reseller. We run SD-WAN as a security-first service for 1,200+ UK businesses across legal, finance, healthcare and professional services, with in-house engineers and accountability that sits with one provider. - Sheffield-based, UK-focused delivery and support team. - Cyber Essentials Plus certified; Microsoft Solutions Partner status (Modern Work, Security, Infrastructure). - 1,200+ UK businesses managed across regulated sectors. - Critical issues answered within one hour, monitored 24/7. ## Frequently asked questions Q: What is SD-WAN in plain terms? A: An intelligent overlay that pools every connection at every site - leased lines, FTTP, broadband, 4G/5G - and steers traffic across them by policy: business-critical apps get the best path, everything fails over automatically, and it's all managed from one portal. Q: Do we need SD-WAN or just better connectivity? A: One site with one connection doesn't need SD-WAN. The case starts at multiple sites or multiple connections per site - when you want traffic prioritised, circuits pooled rather than idle, and failover that happens in seconds without anyone touching anything. Q: Is SD-WAN a replacement for MPLS? A: Often, but not always. SD-WAN over internet circuits is cheaper per site and more flexible; MPLS still wins for some latency-sensitive, guaranteed-path requirements. Plenty of real networks run a hybrid - see our MPLS vs SD-WAN comparison for the honest trade-offs. Q: Does SD-WAN improve security? A: It centralises it: segmentation between sites, encrypted tunnels over every path, and one place to enforce policy instead of per-site firewall drift. Combined with a security-first provider managing it, the network and its protection stop being separate problems. --- # Multi-Site Connectivity: MPLS, SD-WAN & Leased Line Networks URL: https://amvia.co.uk/leased-lines/multi-site-connectivity Last updated: 2026-03 Multi-site connectivity links all your offices, branches and remote workers onto one private, managed network - so files, phone calls and cloud apps behave the same at every location. AMVIA designs, installs and monitors the whole network end to end on dedicated business leased lines. One provider, security-first, Microsoft-certified. ## How does multi-site connectivity work? Multi-site connectivity joins your locations using dedicated circuits, SD-WAN, or MPLS, then routes traffic across them as a single private network. Each site connects to a central hub or a resilient mesh, so staff in any office reach the same servers, applications and phone system. AMVIA owns the design, the install and the day-to-day monitoring. We build every multi-site network in four stages: - Network assessment - we survey each site, measure real bandwidth demand, and check carrier availability so each location gets the right circuit, not an over-priced guess. - Network design - we map your topology (MPLS, SD-WAN, or hybrid) with redundancy and automatic failover built in from the start. - Circuit provisioning - circuits are ordered and installed per site, with customer-premises equipment pre-configured for secure inter-site traffic. - Monitoring and management - 24/7 monitoring across every site, with proactive fault management, performance reporting and capacity planning. ## What's included in AMVIA's multi-site connectivity service? Every multi-site deployment is fully managed: you get the circuits, the routing hardware, the security policy and a named team that runs it for you. There is one contract, one support number and one provider accountable for the whole network - not a finger-pointing chain of carriers and resellers. - Proactive monitoring - continuous network and threat monitoring across all sites, catching faults and intrusions before they reach your users. - UK-based engineering - Sheffield-based engineers handle configuration, changes and incident response. - Resilience by design - automatic failover and optional backup connectivity keep critical sites online when a primary circuit drops. - Security baked in - traffic between sites is encrypted and policy-controlled, backed by AMVIA's Cyber Essentials Plus certification and aligned to NCSC network security guidance. - Regular reporting - monthly reporting on uptime, performance and capacity, plus recommended improvements. ## MPLS vs SD-WAN: which suits your multi-site network? MPLS gives you a private, carrier-managed network with guaranteed quality of service, ideal for latency-sensitive traffic. SD-WAN uses software to route intelligently across multiple links - leased line, broadband, 4G/5G - and is usually cheaper and more flexible. Many UK multi-site businesses run a hybrid of both. | | Factor | MPLS | SD-WAN | Network type | Private carrier-managed | Software-defined overlay | Quality of service | Guaranteed, per-class | Application-aware routing | Underlying links | Dedicated circuits | Mix: leased line, broadband, 4G/5G | Cost profile | Higher | Lower, more flexible | Deployment speed | Slower (circuit-dependent) | Faster over existing broadband | Best for | Latency-sensitive, voice-heavy | Cloud-first, cost-conscious, agile For most SMEs moving traffic to Microsoft 365 and cloud apps, SD-WAN over a leased-line core gives the best balance of cost, control and resilience. ## Why do UK SMEs need reliable multi-site connectivity? When offices run on consumer-grade broadband, performance varies wildly between sites and remote work suffers. The UK average broadband download speed is around 69.4 Mbps (Ofcom Connected Nations 2024) - fine for email, but inconsistent for VoIP, cloud ERP and large file transfers across multiple locations. A managed multi-site network removes that lottery and gives every site predictable, business-grade performance. A single managed network also means VoIP and Teams calling work across every site without quality drops, and your security policy is applied uniformly rather than per-office. That consistency is what makes hybrid and multi-branch working actually reliable. ## How much does multi-site connectivity cost? Cost depends on how many sites you connect, the circuit type at each, and whether you need MPLS, SD-WAN or a hybrid. The single biggest cost driver is the dedicated circuit at each location - AMVIA's business leased lines start from £69 per month per site, with SD-WAN overlays adding modest per-site licensing. We size each site to its real demand rather than selling the same circuit everywhere, then give you one consolidated monthly cost for the whole network. New leased-line circuits typically take 30 to 90 working days to install, so we stagger rollouts and provide temporary 4G/5G connectivity for sites awaiting a fixed line. ## Why choose AMVIA for multi-site connectivity? AMVIA is a security-first provider, not a telecoms reseller - we design connectivity and the security that protects it as one system. We manage IT and connectivity for 1,200+ UK businesses across legal, finance, healthcare and professional services. - Sheffield-based, UK-focused - engineering and support run from Sheffield, with a clear grip on UK compliance and infrastructure. - Certified and accountable - Cyber Essentials Plus certified and a Microsoft Solutions Partner. - One accountable provider - a single contract and a named team for the whole network, not a chain of carriers. - Fast response - critical issues are responded to within one hour, by phone, email or portal. ## Frequently asked questions Q: What is multi-site connectivity? A: A private, managed network linking all your offices, branches and remote workers - so files, calls and cloud apps behave the same at every site, and inter-site traffic never rides the public internet. Q: MPLS or SD-WAN for connecting our sites? A: MPLS gives private, predictable paths; SD-WAN gives flexibility and better economics per site by pooling whatever circuits each location has. For most UK SMEs adding sites, SD-WAN over a leased-line core is the default answer - with MPLS where guaranteed paths genuinely matter. Q: What does connecting multiple sites cost? A: It's built from the circuits: each site needs appropriate connectivity (leased lines from £69/month for 100Mbps where sites are critical), plus the SD-WAN or MPLS layer on top. Sizing each site honestly - not every branch needs what head office needs - is where the design earns its keep. Q: How do remote workers fit into a multi-site network? A: As first-class citizens: secure access into the same private network from home or anywhere, with the same policies applied. Hybrid working made this the rule rather than the exception - a multi-site design that ignores remote workers is designing for the wrong decade. --- # Backup Internet Connectivity: Failover Options for Business URL: https://amvia.co.uk/leased-lines/backup-connectivity Last updated: 2026-03 Backup connectivity is a second, independent internet connection that takes over automatically when your primary line fails - keeping calls, cloud apps and payments running with no manual switch. AMVIA designs failover across a different carrier and technology, then monitors both links 24/7 alongside your business leased lines. One provider. Security-first. Microsoft-certified. ## How does automatic failover work? Automatic failover uses an intelligent router or SD-WAN appliance to detect the moment your primary connection drops and reroute traffic to the backup line. Most setups achieve a switchover time under 30 seconds, so staff and customers rarely notice the change. Voice, email and cloud sessions stay connected. - A monitoring router continuously probes your primary circuit for packet loss and dropouts. - On failure, it shifts active sessions to the backup link automatically - no human intervention. - Quality-of-service rules prioritise voice and critical traffic so VoIP call quality holds up. - When the primary line recovers, traffic switches back cleanly. For multi-circuit and load-balanced designs, our SD-WAN failover configuration manages several connections from a single policy. ## What types of backup connection can you use? The three common options are 4G/5G mobile broadband, a secondary fixed line from an alternative carrier, or a dedicated leased line. The golden rule: your backup must use a different technology and a different carrier from your primary, so a single fault can't take both down. AMVIA matches the option to your risk and budget. | | Backup option | Best for | Typical role | Notes | 4G/5G mobile | Fast deployment, any site | Backup to a fixed primary | Independent of your fixed-line carrier | Secondary fixed line | Higher-bandwidth failover | Backup or load-balanced pair | Use a different carrier to avoid shared infrastructure | Dedicated leased line | Mission-critical primaries | Primary, with 4G/5G as backup | Carries a 99.99% uptime SLA A leased line is typically the primary connection, with mobile or a second fixed line as the resilient backup. For sites that need protected, always-on links, our dedicated internet access and multi-site connectivity services build resilience in from the start. ## Why do UK businesses need backup connectivity? A single internet outage stops VoIP calls, card payments, Microsoft 365 and remote access at once. Even reliable lines suffer faults: the UK average broadband download speed sits at 69.4 Mbps and connections still drop for street works, exchange faults and power cuts. Backup connectivity turns an outage into a non-event. The financial case is straightforward. UK businesses lost an estimated £3.7 billion to internet outages in 2023 - lost orders, idle staff and missed calls add up fast. According to Ofcom's Connected Nations report, fixed-line availability is high but not absolute, which is why resilience planning matters. The NCSC's guidance on operational resilience treats redundant connectivity as a core part of keeping services running through disruption. For the wider plan around outages, ransomware and recovery, pair backup connectivity with structured business continuity planning. ## How much does backup connectivity cost? Backup connectivity is modest next to the cost of downtime. Pricing depends on the technology, bandwidth and data allowance you choose. Mobile failover is the most affordable entry point; a second fixed line costs more but delivers higher sustained throughput. | | Backup type | Typical monthly cost | What drives the price | 4G/5G mobile broadband | from £30 per month | Data allowance and hardware | Secondary fixed line | from £35 per month | Bandwidth and carrier A 4G/5G backup solution typically costs from £30 per month, and a secondary fixed line from £35 per month. Set against the revenue lost in a single half-day outage, the spend is easy to justify. ## How does AMVIA set up and manage your backup connection? We design, install and monitor the whole failover path so it works on the day it's actually needed. Backup links that are never tested are the ones that fail silently - so we simulate real outages before you rely on them. - Risk assessment - we review your primary connection, estimate downtime cost, and pick the right failover technology for your location. - Circuit provisioning - we provision the backup on a different carrier and technology to remove single points of failure. - Failover configuration - automatic failover is set so traffic switches the moment your primary drops. - Testing and monitoring - we simulate failover, verify switchover times, and monitor both connections 24/7. Where connectivity protects sensitive data, our leased line security approach adds encryption and traffic controls on top of the resilient design. ## Why choose AMVIA for backup connectivity? AMVIA manages connectivity and security for 1,200+ UK businesses as a single accountable provider, so one team owns both your primary line and its failover. Critical issues are responded to within one hour by a UK-based helpdesk. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status. - One provider for line and failover - no finger-pointing between carriers when something breaks. - Cyber Essentials Plus certified - independently assessed UK security baseline. - Microsoft Solutions Partner - Modern Work, Security and Azure Infrastructure. - 1,200+ UK businesses supported across legal, finance, healthcare and professional services. ## Frequently asked questions Q: What is backup internet connectivity and why does my business need it? A: Backup connectivity is a secondary internet connection that activates automatically when your primary line fails, keeping you online during outages. It prevents lost revenue, dropped VoIP calls and interrupted access to Microsoft 365 and cloud apps. Even reliable lines fault occasionally, so a backup turns an outage into a brief, unnoticed switchover. Q: How does automatic failover work? A: An intelligent router or SD-WAN appliance constantly checks your primary connection and reroutes traffic to the backup the instant it drops. Most businesses see a switchover time under 30 seconds. Critical services such as VoIP, email and cloud applications keep running, so staff and customers usually notice no interruption at all. Q: What types of backup connection are available? A: The common options are 4G/5G mobile broadband, a secondary fixed line from an alternative carrier, or a dedicated leased line. A leased line typically delivers a 99.99% uptime SLA, making it ideal as the primary with 4G/5G as backup. AMVIA always uses a different technology and carrier for the backup to remove single points of failure. Q: How much does backup internet connectivity cost? A: A 4G/5G backup solution typically costs from £30 per month, and a secondary fixed line from £35 per month, depending on bandwidth and data. That is small against downtime losses - UK businesses lost an estimated £3.7 billion to internet outages in 2023 (Beaming, vendor estimate) - making backup connectivity a sound investment. Q: Can backup connectivity support VoIP and cloud applications? A: Yes. Modern 4G and 5G backup connections carry enough bandwidth and low enough latency for VoIP, Microsoft Teams and cloud-hosted apps. AMVIA configures quality-of-service rules to prioritise voice and critical traffic on the backup link, so call quality stays acceptable even while you run on the secondary connection. Q: How quickly can AMVIA add backup connectivity to an existing line? A: Mobile 4G/5G failover can often be deployed quickly because it needs no new fixed-line installation - just compatible hardware and configuration. A secondary fixed line takes longer because the alternative carrier must provision a circuit. We confirm realistic timescales during the risk assessment stage. --- # Leased Line Security: Why Dedicated Connectivity Is Safer URL: https://amvia.co.uk/leased-lines/leased-line-security Last updated: 2026-03 Leased line security is the protection that comes from a dedicated, unshared fibre connection: a static public IP block, symmetric bandwidth for security appliances, no carrier-grade NAT, and a clean perimeter for firewall whitelisting. AMVIA delivers the connectivity and the security together - one provider, security-first, Microsoft-certified. Most buyers weigh business leased lines on speed and SLA. The security case is quieter but real: how you connect shapes how well you can defend the connection. This page sets out the architectural reasons a dedicated line is easier to secure than shared broadband, and what AMVIA's managed cybersecurity team builds on top of it. ## What makes a leased line more secure than broadband? A leased line is an unshared, point-to-point fibre connection between your premises and the carrier network. Your traffic never shares physical exchange equipment or dynamic IP pools with other businesses. That dedicated architecture removes structural weaknesses - shifting IPs, carrier-grade NAT, contention - that shared broadband cannot escape, whatever its headline speed. Standard broadband - FTTC, FTTP, or 4G/5G - is a shared service. Providers segment traffic logically, but many businesses share the same physical exchange equipment and dynamic IP address pools. The UK average broadband speed reached 69.4 Mbps in 2024 (Ofcom, UK Home Broadband Performance Report 2024); decent speed, but speed alone does nothing for the security limits baked into shared infrastructure. For the baseline controls every SME should run regardless of connection, the NCSC's Small Business Guide is the practitioner reference. The differences that matter for security: - Dynamic IPs change periodically, breaking firewall whitelists and IP-based access rules. - Carrier-grade NAT (CGNAT) shares one public IP across many customers, complicating VPNs, logging and attribution. - Contention means security appliances slow down exactly when load - and threat activity - peaks. ## Why do static IPs and firewall whitelisting matter? Firewall whitelisting - restricting connections to known, trusted IP addresses - is one of the simplest, most effective controls a business can run. It only works with a stable IP identity. A leased line gives you a dedicated block of static public IPs allocated exclusively to your business, so the rules you write stay valid. The UK business broadband market is worth an estimated £4.2 billion as of 2026 (Ofcom, Communications Market Report), yet much of it runs without the static addressing whitelisting depends on. With a leased line and static IPs you can: - Require connections to Microsoft 365, AWS and Azure to originate from your registered IP range. - Define Microsoft Conditional Access named locations that apply stricter authentication outside your office IPs. - Remove remote desktop and management interfaces from public exposure, restricting them to your static IP. - Let partners and suppliers whitelist your connection for secure data exchange. - Produce clean audit trails that identify traffic from your premises. ## Dedicated leased line vs shared broadband - the security view | | Security factor | Shared broadband | Dedicated leased line | Public IP | Dynamic / CGNAT-shared | Static block, exclusively yours | Firewall whitelisting | Breaks as the IP changes | Stable, reliable rules | Site-to-site VPN | NAT-traversal complications | Directly routable IP, clean IPsec | Bandwidth direction | Asymmetric (low upload) | Symmetric in both directions | NGFW / SSL inspection | Degrades under contention | Full-rate, consistent | Network perimeter | Blurred by shared infrastructure | Clear, auditable boundary ## How does a leased line improve VPN security and performance? NAT traversal is the workaround needed when VPN traffic crosses a network-address-translation device - routine on broadband. It adds complexity, causes connection failures, and in some configurations weakens the tunnel by forcing protocol changes. A dedicated public IP removes that problem for multi-site connectivity and site-to-site VPNs. Your firewall or VPN appliance holds a publicly routable IP directly, so IPsec IKE negotiation and ESP encapsulation work cleanly. Symmetric bandwidth matters too: broadband is asymmetric - a 100 Mbps download line may offer 10–20 Mbps upload - and VPN traffic runs both ways, so that thin upload throttles every remote user. A leased line delivers equal speed in both directions and typically carries a 99.99% uptime SLA, giving you both performance and the reliability to enforce controls consistently. ## What about encryption, NGFW and compliance? Encryption still matters on a leased line. Traffic runs unshared between your premises and the carrier's point of presence, but internet-bound data enters the public internet from there - so encrypt everything with IPsec or TLS regardless of connection type. The leased-line advantage is performance: dedicated, consistent bandwidth means encryption and deep-packet inspection run at full rate. Next-generation firewalls (NGFW) - appliances that perform deep packet inspection, application identification, SSL/TLS inspection and intrusion detection - are bandwidth-hungry. On contended broadband, security throughput drops under peak load. With 96% of UK premises having access to superfast broadband of 30 Mbps or above (Ofcom, Connected Nations 2024), even "fast" connections struggle to hold appliance performance steady under contention. For regulated sectors, the line shapes compliance posture. Leased lines support UK GDPR, FCA and NHS Data Security and Protection Toolkit compliance by providing consistent, auditable addressing, reliable VPN infrastructure, and the headroom to run controls without degradation. The ICO's security guidance sets the expectation for appropriate technical measures. A dedicated, exclusively allocated connection also makes the network boundary that frameworks require far easier to define. ## What does AMVIA's managed connectivity and security include? AMVIA provides leased lines with managed security under a single contract and one monthly invoice. Rather than juggling a connectivity provider, a firewall vendor and a separate security service, you get dedicated connectivity combined with next-generation firewall management, DNS filtering, VPN configuration and Barracuda email security as one integrated service. The team that runs the connectivity runs the security - so firewall configuration, IP whitelisting and policy live together, with no finger-pointing between suppliers when something breaks. Total FTTP coverage reached 78% of UK premises (23.7 million premises) in Q3 2025, so dedicated fibre is now reachable for most businesses that want enterprise-grade network security without running it in-house. That is the AMVIA model: one provider, security-first, Microsoft-certified. ## Frequently asked questions Q: What makes a leased line inherently more secure than broadband? A: A leased line is an unshared, point-to-point fibre connection dedicated to your business. Your traffic never crosses shared exchange infrastructure, which removes the risks of dynamic IPs and carrier-grade NAT. Static IPs enable consistent firewall whitelisting and clean audit trails. With 43% of UK businesses identifying a breach or attack in 2025 (DSIT, Cyber Security Breaches Survey 2025), removing that structural weakness is a practical, low-cost gain. Q: Do I still need encryption on a dedicated leased line? A: Yes. A leased line carries traffic between your premises and the carrier's point of presence; from there, internet-bound data enters the public internet. Best practice is to encrypt everything with IPsec or TLS regardless of connection type. The advantage of a leased line is that its dedicated, symmetric bandwidth lets encryption run at full speed without the throughput drops contended broadband suffers under load. Q: How do static IP addresses strengthen network security? A: Static IPs let you restrict cloud services, remote management portals and partner systems to traffic from your known IP range only. Microsoft 365 Conditional Access, AWS IAM and Microsoft Entra ID all support IP-based policies that are unreliable on the dynamic addresses broadband hands out. A fixed IP identity gives you a stable basis for firewall rules, named locations and audit trails. Q: Does a leased line help with regulatory compliance? A: It supports it. For financial services, healthcare and legal firms, consistent and auditable network addressing simplifies the boundary definition most frameworks require. Leased lines support UK GDPR, FCA and NHS Data Security and Protection Toolkit compliance by providing reliable VPN infrastructure and the bandwidth to run security controls without performance degradation. The connection is one control among many, not a certification in itself. Q: Can AMVIA manage the leased line and the security together? A: Yes. AMVIA delivers the dedicated line plus next-generation firewall management, DNS filtering, VPN configuration and Barracuda email security under one contract and one invoice. The same team owns connectivity and security, so whitelisting, policy and incident response sit in one place - no gaps between a telecoms supplier and a separate security vendor. One provider, security-first, Microsoft-certified. --- # How Business Connectivity and Cybersecurity Work Together URL: https://amvia.co.uk/leased-lines/connectivity-and-security Last updated: 2026-03 Connectivity and security are the same decision. The type of internet connection you buy sets the ceiling on the firewall rules, VPN performance, and identity controls you can enforce. A leased line gives you dedicated bandwidth and static IP addresses - the foundation strong security depends on. AMVIA delivers both as one accountable, security-first, Microsoft-certified service. ## Why is your internet connection a security decision? Most businesses choose connectivity on speed and price alone. But how a connection is configured - whether it is contended, what IP addresses it uses, and how traffic routes - directly affects your attack surface and your ability to enforce controls. The connection is the gateway every threat passes through. Shared broadband, including standard FTTC and FTTP business products, is contended at the exchange and uses dynamic, shared IP ranges. That creates real limits: - Dynamic, shared IPs make consistent firewall whitelisting unreliable. - Contention degrades VPN and security-appliance performance under load - exactly when you need it most. - Asymmetric upload throttles VPN tunnels that carry traffic in both directions. A business leased line removes these limits. Your connection is uncontended, dedicated, and ships with a static block of public IPs allocated only to you - a fundamentally stronger base for managed cybersecurity. For UK premises, total FTTP coverage reached 78% (23.7 million premises) in Q3 2025 (Ofcom Connected Nations 2025), yet coverage alone does nothing for these structural security gaps. ## Broadband vs leased line: which is more secure? A leased line is more secure by architecture, not by add-on. Dedicated bandwidth, static IPs, and symmetric speeds let you enforce IP-based access controls, run inspection appliances at full capacity, and keep VPNs performant enough that staff do not bypass them. The table below compares the two for security-led buyers. | | Security factor | Shared broadband (FTTC/FTTP) | Leased line | IP addressing | Dynamic, shared | Static, dedicated block | Firewall whitelisting | Unreliable | Reliable, IP-based | Bandwidth | Contended | Uncontended, guaranteed | Upload for VPN | Asymmetric (e.g. 10–20 Mbps) | Symmetric (full rate) | NGFW / SSL inspection | Degrades at peak | Consistent at full capacity | Conditional Access by IP | Impractical | Supported Even where coverage is strong - 96% of UK premises can access superfast broadband of 30 Mbps or above (Ofcom Connected Nations 2024) - contention still limits full-featured appliance operation during business hours. ## How do static IP addresses improve firewall security? A leased line's biggest practical security win is a static, dedicated IP block. Static IPs make firewall whitelisting work: you can restrict cloud admin portals, remote management, and sensitive apps to traffic from your known addresses, instead of leaving them open to the whole internet. That single capability enables several controls: - Microsoft 365 Conditional Access policies scoped to named locations by IP range, so Conditional Access policies prompt for extra authentication only outside your office IPs. Microsoft documents named-location IP scoping directly (learn.microsoft.com). - Firewall-to-firewall VPN tunnels with fixed endpoints between sites. - Allow-listing your connection for administrative access to hosted services. For firms handling client financial data, patient records, or legal files, IP-based access control is a baseline expectation - and the NCSC treats network access restriction as a core control (ncsc.gov.uk). ## How does a leased line support VPN and SD-WAN security? VPNs live or die on upload bandwidth and stability. Broadband is asymmetric - a 100 Mbps download line may offer only 10–20 Mbps upload - so site-to-site and remote-access VPNs bottleneck. A symmetric leased line delivers full rate in both directions, removing that constraint and keeping tunnels fast enough that staff do not route around them. This matters most across multiple sites. SD-WAN over leased lines encrypts all inter-site traffic with IPsec, giving MPLS-equivalent privacy over the public internet, with local breakout protected by cloud security or local firewall policy. The global SD-WAN market is growing at roughly 26% CAGR (Gartner, 2025 market data), driven by exactly this need for reliable, application-aware routing at every site. Consistency is itself a security property. When VPN performance is poor, people disable it; uncontended bandwidth keeps multi-site connectivity predictable enough that the secure path is also the fast path. ## How does AMVIA combine connectivity and security? AMVIA delivers the leased line and the security stack under one contract, managed by one team. Rather than splitting connectivity and security across suppliers - which creates accountability gaps when something breaks - AMVIA runs both layers together: firewall management, VPN configuration, DNS filtering, email security, and endpoint protection on an SLA-backed, AMVIA-managed circuit. What this changes in practice: - One accountable provider. No finger-pointing between an ISP and a security vendor during an incident. - Security-first design. IP whitelisting, leased line security controls, and firewall policy are set by the people who run the network. - Microsoft-certified delivery. As a Microsoft Solutions Partner, AMVIA aligns connectivity with Microsoft 365 access controls, using Microsoft Defender and the Barracuda email and network suite. (See Microsoft Security.) The result is enterprise-grade capability at a predictable monthly cost - one provider, security-first, Microsoft-certified. ## Frequently asked questions Q: Why does a leased line improve cybersecurity compared with broadband? A: A leased line gives you dedicated, uncontended bandwidth and a static IP block allocated only to your business. Static IPs make firewall whitelisting and Microsoft 365 Conditional Access by location reliable, while broadband's dynamic, shared IPs and contention undermine those controls. Security is set by your connection's architecture, not just the appliances bolted on top. Q: Can I run a next-generation firewall effectively over broadband? A: Next-generation firewalls perform deep packet inspection, SSL decryption, and intrusion detection - all bandwidth-intensive. On contended broadband these degrade during peak hours, exactly when threats are most active. A leased line provides the stable, symmetric bandwidth those appliances need to run at full capacity without latency spikes that blunt their effectiveness. Q: Do static IP addresses really make a security difference? A: Yes. Static, dedicated IPs let you restrict cloud admin portals, remote management, and sensitive applications to traffic from your known addresses. They also enable fixed VPN endpoints between sites and Microsoft 365 Conditional Access policies scoped to your office IP range - controls that are impractical on shared, dynamic broadband IPs. Q: Is SD-WAN over a leased line as secure as MPLS? A: SD-WAN encrypts all inter-site traffic with IPsec, giving privacy equivalent to MPLS while running over the public internet. Application-aware routing keeps sensitive traffic on the most reliable path, and automatic failover means a circuit fault does not open a security gap because encryption is maintained across the failover. Q: Does poor VPN performance create a security risk? A: It does. When VPN tunnels are slow - usually because of broadband's limited upload bandwidth - staff are tempted to bypass them, creating gaps attackers exploit. A symmetric leased line keeps VPN and zero-trust access fast and consistent, so the secure route is also the convenient one and adoption stays high. Q: Can AMVIA manage both my connectivity and my security? A: Yes. AMVIA delivers the leased line and managed security - firewall, VPN, DNS filtering, email security, and endpoint protection - under a single SLA-backed contract managed by one team. That removes supplier finger-pointing during incidents and means the people running your network also set your security policy. --- # How Much Does a Leased Line Cost in the UK? (2026 Prices) URL: https://amvia.co.uk/leased-lines/questions/leased-line-cost-uk Last updated: 2026-03 A business leased line in the UK runs from £69/month for entry-level 100Mbps, with symmetrical 1Gbps from £129/month, plus a one-off install charge. Price hinges on your postcode, bandwidth and term - and buying connectivity from a security-first provider means one accountable partner, not a telecoms reseller. ## How much does a leased line cost in the UK? Expect £69/month at the entry point and from £129/month for a gigabit circuit, with installation from £500–£2,000. The single biggest swing factor is location: urban sites with multiple carriers nearby price far lower than rural premises that need new fibre dug to the door. A leased line is a dedicated, symmetrical, uncontended connection - you get the full speed in both directions, all the time, backed by a Service Level Agreement. That guaranteed performance is why it costs more than shared business broadband. If you want the underlying concept first, read what a leased line actually is before you compare quotes. | | Bandwidth | Typical monthly cost | Notes | 100Mbps | from £69/mo | Entry point in well-served urban postcodes | 200–500Mbps | £150–£350/mo | Mid-range symmetrical circuit, typical UK 2026 range | 1Gbps | from £129/mo | Full symmetrical gigabit | Installation | £500–£2,000 | Often discounted or waived on 60-month terms Coverage is the backdrop to all of this. Full-fibre (FTTP) now reaches 78% of UK premises - 23.7 million homes and businesses - and gigabit-capable broadband covers 87% of the UK, up from 84% a year earlier (Ofcom Connected Nations 2025). More fibre in the ground means more carriers competing for your postcode, and that competition pushes prices down. ## What's included in leased line installation costs? Installation covers the physical build to your premises: civil works, fibre, the carrier's hand-off and the router. It typically ranges from £500–£2,000 (typical UK 2026 range), and the number depends almost entirely on how far the nearest fibre is from your building. A site already passed by full fibre is cheap to connect; a premises needing a new dig can cost far more. Where a build is unusually expensive, carriers sometimes quote an Excess Construction Charge on top. A good dedicated internet access provider checks for these before you sign, so there are no surprises after the order goes in. On longer contracts, install is frequently discounted or waived entirely to win the deal. ## What determines the monthly price of a leased line? Four factors set the monthly price: bandwidth, location, contract length and carrier availability. Of these, location does the heavy lifting - distance to the nearest exchange or Point of Presence drives the build cost, and build cost is amortised into your monthly rental. Urban sites with several carriers see the most competitive pricing. - Bandwidth - circuits scale from 100Mbps to 100Gbps; you pay for the bearer (the port size) and the speed you light up on it. - Location - the further the fibre has to travel, the higher the cost; multiple nearby carriers create price competition. - Contract length - terms typically run 36–60 months; longer terms lower the monthly rate. - Carrier availability - where Openreach, CityFibre and alt-nets all serve a postcode, you get the keenest quotes. A leased line typically carries a 99.99% uptime SLA, and that guaranteed, symmetrical performance is the core of what you pay for. Compare that with UK broadband's average download speed of 69.4 Mbps (Ofcom Connected Nations 2024) - fast on paper, but shared, asymmetric and without a fix-time guarantee. If you want the full breakdown, see our leased line vs broadband comparison. ## Are leased line prices falling in the UK? Yes. Leased line prices have dropped considerably over the past decade as fibre networks have expanded and alt-net providers like CityFibre have entered urban markets. A 100Mbps circuit that cost £500–£700/month five years ago now costs from £69/month in well-served postcodes - a substantial fall driven almost entirely by competition. That trend has further to run. The government's Project Gigabit programme is subsidising fibre into harder-to-reach areas, and Openreach is investing up to £15 billion to expand full fibre coverage to 25 million premises by December 2026 (Openreach's stated target). Fixed leased line connections still dominate the UK business internet market, with a share exceeding 39% (Ofcom Connected Nations, 2024) - businesses keep choosing guaranteed connectivity, and more supply keeps nudging the price down. For sites that can't yet get fibre, an FTTP leased line may be available now, or a backup connectivity circuit can bridge resilience while you wait for the main line. ## Does a longer contract make a leased line cheaper? Generally, yes. A 60-month contract typically costs 10–20% less per month than a 36-month term for the same circuit, and longer terms are where carriers waive installation. The trade-off is flexibility: a five-year commitment locks you in if your bandwidth needs change. For most SMEs we recommend a 36-month term. It balances meaningful cost savings against the freedom to scale bandwidth as the business grows or to upgrade to SD-WAN across multiple sites. Sign a five-year deal only when you are certain the speed and the site won't change. ## How can you get the best leased line price for your postcode? Because location dominates pricing, the only way to know your real cost is a postcode-level quote across every carrier that serves your building. Pricing varies so much street to street that a single-carrier quote almost always leaves money on the table. Compare across providers, then factor in install, term and SLA - not just the headline monthly rate. This is where a broker-led approach pays off. AMVIA checks pricing across multiple carriers for your exact postcode, sanity-checks for excess construction charges, and delivers connectivity and security from one accountable provider rather than a box-shifting reseller. One provider, security-first, Microsoft-certified. ## Frequently asked questions Q: How much does a leased line cost in the UK? A: A UK business leased line costs from £69/month for 100Mbps and from £129/month for symmetrical 1Gbps, plus installation of £500–£2,000. Location is the biggest variable - urban sites near existing fibre cost far less than rural premises needing a new build. Always get a postcode-level quote across carriers. Q: What is the installation cost for a leased line? A: Leased line installation typically runs £500–£2,000 (typical UK 2026 range), covering civil works, fibre, the carrier hand-off and the router. The figure depends on how far the nearest fibre sits from your premises. Sites already passed by full fibre are cheap to connect; new digs cost more. Longer contract terms often reduce or waive the install charge entirely. Q: Why are leased lines more expensive than broadband? A: A leased line is dedicated, symmetrical and uncontended, with a 99.99% uptime SLA and guaranteed fix times. Broadband is shared, asymmetric and best-effort. You pay for guaranteed performance and accountability, not just raw speed. For a business that loses money when the connection drops, that guarantee is the entire point of the cost difference. Q: Does contract length affect leased line price? A: Yes. A 60-month contract typically costs 10–20% less per month than a 36-month term for the same circuit, and longer terms are where carriers waive installation. The trade-off is flexibility. We recommend 36-month terms for most SMEs, balancing savings against the freedom to scale bandwidth or change provider as the business grows. Q: Are leased line prices going down in the UK? A: Yes. Prices have fallen considerably over the past decade as full-fibre coverage expanded and alt-net carriers entered urban markets. More carriers competing for the same postcode pushes monthly rates down, especially in cities. Government-backed fibre rollout is extending that downward pressure into areas that previously had only a single, expensive option. Q: Can I get a leased line at my address? A: Likely, yes. With full fibre now reaching most UK premises, the majority of business addresses can get a leased line - the question is price, not availability. A postcode check across every carrier serving your building shows which options exist and what each costs, including any excess construction charge before you commit. --- # How Long Does a Leased Line Take to Install? (UK Timescales) URL: https://amvia.co.uk/leased-lines/questions/leased-line-installation-time Last updated: 2026-03 A leased line takes 30–90 working days to install in the UK. Sites close to existing fibre infrastructure install faster; rural or complex sites requiring civil works take longer. AMVIA recommends ordering 90 days before you need the line live, starting with a postcode check and site survey. *Last updated: March 2026* The single biggest mistake UK businesses make with connectivity is treating a business leased line like a broadband order - expecting it live in days. It is closer to a small construction project. Understanding the leased line installation time, and what moves it, is the difference between a clean cutover and weeks of disruption. This guide walks through the realistic timeline, the steps inside it, and how to stop the avoidable delays. ## What Is the Typical Leased Line Installation Time in the UK? The realistic range is 30–90 working days. Sites with existing fibre reach can connect in 30 working days; new routes requiring road work can take 60–90 days or longer. The variable is rarely the carrier - it is the physical distance between your building and usable fibre. A leased line is a dedicated fibre connection built specifically to your premises, so part of the timeline is genuine civil engineering. Three site categories drive most of the variation: | | Site type | Typical installation time | What's involved | Fibre already at or near the building | ~30 working days | Survey, internal cabling, commissioning | Standard route, no major civils | 45–60 working days | Survey, jointing, light street works | New route needing road works / wayleaves | 60–90+ working days | Excavation, ducting, third-party permissions Because the line is dedicated rather than shared, it also delivers the consistent symmetric speeds and a 99.99% uptime SLA that ordinary broadband cannot - which is why the wait is usually worth it. If you want the underlying technology explained plainly, read what is a leased line. ## Why Do Leased Lines Take So Long to Install? The installation involves a site survey, wayleave permissions if the fibre route crosses third-party land, civil engineering works to lay ducting, fibre splicing, and equipment commissioning. Each step depends on the one before it, so a single hold-up - a survey finding, a landlord signature - pushes the whole schedule. Here is the order in which it actually happens: 1. Order and postcode check. The carrier confirms whether your site is on-net (fibre present) or off-net (build required). This determines whether excess construction charges apply. 2. Site survey. An engineer confirms the physical route, entry point, and any obstructions. 3. Planning and wayleaves. If the fibre crosses land you do not own, the landowner must sign a wayleave agreement granting access. 4. Civil works. Ducting is laid, which may need a local authority street-works permit and traffic management. 5. Fibre installation and splicing. The fibre is pulled through and jointed to the network. 6. Commissioning and handover. The router is installed, the circuit is tested, and the service goes live. The UK fibre picture is improving fast, which shortens step one for more businesses each year. Total FTTP coverage reached roughly 78% of UK premises in Q3 2025, and gigabit-capable broadband now covers 87% of the UK, up from 84% in 2024, according to Ofcom's Connected Nations data (Ofcom). Government-backed rollout under Project Gigabit continues to extend reach into harder-to-build areas (gov.uk). ## What Can Delay a Leased Line Installation? Common delays include wayleave disputes with landlords or authorities, underground obstructions discovered during civil works, and survey findings that force a route change. Each of these adds time outside the carrier's direct control, which is why padding your order date matters more than chasing the provider. The delays we see most often: - Wayleave hold-ups. A landlord who is slow to sign, or asks for legal review, can add weeks. Start this conversation early if you rent. - Excess construction charges (ECCs). If the build cost exceeds the standard allowance, the carrier issues a quote you must approve before work proceeds - a common silent pause. - Street-works permits. Local authority permitting and traffic management for road excavation run on their own timetable. - Underground surprises. Blocked or collapsed ducting found mid-build means a re-plan. - Internal readiness. Comms room location, power, and access on the day all need confirming up front. AMVIA manages each of these proactively rather than reacting once the clock has already slipped. For a full picture of the connection itself, see dedicated internet access and the FTTP leased line option, which can shorten build time where full-fibre infrastructure already passes the premises. ## Can I Get a Temporary Connection While Waiting? Yes. Businesses can run on business-grade broadband or 4G/5G during installation, and AMVIA can provision this so you are never offline waiting for the leased line. UK broadband average download speed is 69.4 Mbps (Ofcom Connected Nations 2024) - adequate for short-term office use while the dedicated line is built. We set the temporary service up as a stepping stone, then migrate your traffic onto the leased line once it activates. Treating it as planned backup connectivity rather than a panic measure means no downtime on cutover day, and the backup circuit keeps earning its place as resilience afterwards. ## How Far Ahead Should You Order a Leased Line? Order 90 days before you need the line live. That window absorbs the survey, wayleave, and civil-works steps without forcing you into a crisis if any single stage runs long. If you are moving offices or opening a new site, the order should go in the moment the lease is signed. A realistic planning checklist: - 90 days out: Place the order, run the postcode check, confirm the contract end date of your current line. - 60 days out: Chase wayleave sign-off and approve any excess construction charge quote. - 30 days out: Confirm the install date, comms room readiness, and the temporary connection plan. - Go-live week: Engineer attends, circuit tested, services migrated, old line retained briefly as fallback. Leased lines start from £69/mo, and the cost is driven more by bandwidth and build distance than by the wait. For a full breakdown, read the leased line cost guide. ## Does a Faster Line Change Your Security Exposure? Yes - and it is the step most businesses skip. A dedicated line moves more of your business onto the internet, faster, which widens the surface attackers can probe. The connection should be commissioned alongside the controls that protect what runs over it, not bolted on months later. A leased line is the right moment to review firewalling, segmentation, and monitoring as one design. AMVIA does this as standard: connectivity and security from one accountable provider. See how the two fit together in leased line security. One provider, security-first, Microsoft-certified - so the line that carries your business is also defended properly. ## Frequently asked questions Q: How long does a leased line take to install in the UK? A: A leased line takes 30–90 working days to install in the UK. Sites already close to fibre can connect in around 30 working days, while new routes needing road works and wayleaves take 60–90 days or longer. AMVIA recommends ordering 90 days before you need the line live. Q: Why does a leased line take longer than broadband? A: Broadband uses an existing shared network, so it activates in days. A leased line is a dedicated fibre circuit built to your premises, involving a survey, wayleave permissions, civil engineering, fibre splicing, and commissioning. Because each step depends on the last, the realistic timeline is weeks, not days. Q: What is the most common cause of leased line delays? A: Wayleave permissions are the most common delay. If the fibre route crosses land you do not own, the landowner must sign an access agreement, and slow sign-off can add weeks. Excess construction charges and street-works permits are the next most frequent causes. Q: Can I stay online while my leased line is being installed? A: Yes. AMVIA provisions a temporary business-grade broadband or 4G/5G connection so you are not offline during the build. The UK average broadband download speed of 69.4 Mbps (Ofcom Connected Nations 2024) is adequate for short-term use, and your traffic migrates to the leased line once it goes live. Q: How far in advance should I order a leased line? A: Order 90 days ahead of when you need the line live. That window covers the site survey, wayleave sign-off, and any civil works without forcing a rushed install. If you are relocating, place the order as soon as the new lease is signed. Q: Will an existing fibre connection nearby speed up installation? A: Yes. Sites where full-fibre infrastructure already passes the building can often connect in around 30 working days, because the carrier avoids new road works and ducting. A postcode check at the point of order confirms whether your site is on-net and how much build, if any, is required. --- # What Is a Contention Ratio? Why It Matters for Broadband URL: https://amvia.co.uk/leased-lines/questions/what-is-contention-ratio Last updated: 2026-03 A contention ratio is the number of users sharing the same bandwidth capacity. Standard business broadband typically runs at 20:1 to 50:1 (typical UK 2026 range), so up to 50 businesses can share one connection. A leased line is 1:1 - bandwidth dedicated only to you. That dedicated 1:1 line is the foundation AMVIA recommends for any business running VoIP or cloud-critical work. If you have ever watched download speeds collapse at 11am, contention is usually why. The headline speed your provider sells you is the *maximum* you might see when the line is quiet. The speed you actually get depends on how many other businesses are pulling data through the same shared pipe at the same moment. Understanding this one ratio explains most "our internet is slow again" complaints - and points directly to the fix. Compare the options on our business leased line pillar before you renew any connectivity contract. ## What does a contention ratio actually mean? A contention ratio expresses how heavily a connection is shared. Written as X:1, it tells you how many subscribers are designed to share one unit of backhaul capacity. A 50:1 ratio means fifty premises share that capacity; 1:1 means nobody shares it but you. Lower is always better. The number matters because broadband is sold on *contended* capacity to keep prices low. Providers assume not everyone uses full bandwidth simultaneously - which holds true until peak hours, when it doesn't. The ratio is effectively a measure of how much your speed can degrade when your neighbours get busy. - 50:1 - typical residential and entry-level business broadband - 20:1 - better-provisioned business broadband - 1:1 - a leased line, uncontended and dedicated ## What contention ratio does UK business broadband have? Residential broadband is usually contended at 50:1, meaning up to 50 premises share the same backhaul capacity. Business broadband improves this to around 20:1, but speeds still drop noticeably during peak hours. The UK average download speed is 69.4 Mbps (Ofcom Connected Nations 2024), but that average hides large swings caused by contention - particularly between 9am and 5pm when business demand peaks. Contention is invisible on a quiet line and brutal on a busy one. A connection that benchmarks beautifully at 8am can buckle by mid-morning, not because anything broke, but because the shared backhaul filled up. Ofcom's own broadband speed guidance confirms that real-world throughput varies with network demand, not just your package. | | Connection type | Typical contention ratio | Behaviour at peak | Best for | Residential broadband | 50:1 | Noticeable slowdown | Home use | Business broadband | 20:1 | Variable, dips 9am–5pm | Small offices, light use | Leased line | 1:1 | No slowdown - dedicated | VoIP, cloud, multi-site ## Why does a 1:1 leased line contention ratio matter? A leased line has a contention ratio of 1:1: the bandwidth is dedicated exclusively to your business. No other company shares it, so the speed you buy is the speed you get - at 9am, at 2pm, and at month-end when everyone is invoicing. It is symmetric, too: upload matches download. This predictability is the whole point. Contended broadband gives you a *best-case* number; a leased line gives you a *guaranteed* number backed by a service level agreement. A leased line typically carries a 99.99% uptime SLA with fixed fault-fix times - something no contended product offers. For a deeper breakdown of the trade-offs, read our leased line vs broadband comparison. - Dedicated capacity - your bandwidth is never shared or oversold - Symmetric speed - upload equals download, vital for cloud backup and video - Guaranteed SLA - uptime and repair times are contractual, not aspirational - Predictable performance - no peak-hour collapse to plan around ## How does contention affect VoIP and video calls? Voice and video need consistent, low-latency delivery. On a contended line, other users' traffic causes jitter and packet loss that degrade call quality - choppy audio, frozen video, dropped calls. These problems appear exactly when you are busiest, because that is when contention bites. A leased line's 1:1 contention ratio eliminates this entirely. With dedicated bandwidth, voice and video packets are never fighting fifty strangers for room on the pipe, so quality stays consistent through the working day. This is why we treat a 1:1 line as the proper foundation for business VoIP and hosted phone systems rather than a nice-to-have. If you are running cloud telephony over contended broadband, contention - not your phone system - is usually the culprit behind call complaints. ## Is an uncontended leased line worth the cost? For businesses running VoIP, cloud-hosted applications, or services where consistent performance directly affects revenue or productivity, 1:1 contention is worth the premium. The monthly cost gap between a contended broadband line and an uncontended dedicated internet access circuit has narrowed considerably in recent years, with entry leased lines now available from £69/mo. That said, be honest about your needs. For an office of fewer than ten people with no VoIP and light cloud use, a well-provisioned business broadband connection may still be adequate. The decision should follow your dependency on real-time and cloud services, not the marketing. - Choose a leased line if: you run VoIP, depend on cloud apps, or have lost money to downtime - Business broadband may suffice if: you are small, office-based, and not latency-sensitive - Always check: the SLA, the contention ratio, and the symmetric upload figure ## How do you check the contention ratio on your line? Providers rarely publish contention ratios openly, so ask directly: "What is the contention ratio on this product, and is the upload speed symmetric?" A straight answer of 1:1 means a leased line; anything else is contended. If a salesperson dodges the question, treat that as your answer. You can also infer contention from behaviour. Run a speed test early morning and again at 11am and 3pm. A large, repeatable drop at peak times is contention in action. Consistent speeds across the day point to a dedicated or lightly contended line. ## Frequently asked questions Q: What contention ratio does business broadband typically have? A: Business broadband is usually contended at around 20:1, an improvement on the 50:1 common to residential lines but still shared. Up to 20 businesses can use the same backhaul capacity, so speeds dip during peak hours between 9am and 5pm when demand is highest. A leased line removes this with a dedicated 1:1 ratio. Q: What is a 1:1 contention ratio? A: A 1:1 contention ratio means no one shares your bandwidth - the full capacity is dedicated to your business alone. It is the defining feature of a leased line. Because nothing is shared or oversold, the speed you buy is the speed you get at every hour of the day, backed by a contractual service level agreement. Q: Does contention ratio affect upload speed? A: Yes. Contended broadband is typically asymmetric, with much lower upload than download, and that upload is shared too. This hurts cloud backup, video calls, and large file transfers. A leased line is symmetric and uncontended, so upload matches download and stays consistent regardless of how busy other users are. Q: Is contention the reason my internet slows down at peak times? A: Usually, yes. If speeds are fine early morning but collapse mid-morning and mid-afternoon, contention is the most common cause - the shared backhaul fills up as more businesses come online. Run a speed test at 8am, 11am and 3pm; a repeatable peak-time drop is the signature of a contended line. Q: Can a contended business broadband line run VoIP reliably? A: For a very small office with light call volumes it can, but performance is not guaranteed. Contention causes jitter and packet loss that degrade call quality exactly when you are busiest. For any business that depends on its phone system, a 1:1 leased line is the reliable foundation, because voice traffic never competes with other companies for capacity. Q: How much does a leased line cost compared with broadband? A: The gap has narrowed considerably, with entry-level leased lines now available from £69/mo. The right comparison is not price alone but cost per guaranteed Mbps: a leased line gives dedicated, symmetric capacity with an SLA, while broadband gives a best-case figure that varies with contention. Weigh it against what downtime and poor call quality cost you. --- # Leased Line vs Business Broadband: Which Is Right for You? URL: https://amvia.co.uk/leased-lines/compare/leased-line-vs-broadband Last updated: 2026-03 A leased line gives your business a dedicated, uncontended connection with symmetrical speeds and a 99.99% uptime SLA. Business broadband is shared, cheaper and best-effort. Choose a leased line when downtime costs you money or your team depends on cloud apps, VoIP and video; choose broadband for very small offices or as a failover line. This is the question we get asked most often by MDs and IT directors weighing up connectivity. The honest answer is that both have a place - what matters is matching the connection to how your business actually works. Below we set out the real differences, the costs, and when each option earns its keep. For the full picture, start with our business leased lines pillar, then read what a leased line is if you want the fundamentals first. ## What's the difference between a leased line and business broadband? A leased line is a dedicated fibre circuit reserved for your business alone, delivering identical upload and download speeds backed by a contractual uptime SLA. Business broadband shares capacity with other premises in your area, so speeds and reliability vary with demand. The core difference is contention: broadband is shared, a leased line is not. | | Feature | Leased line | Business broadband | Guaranteed speeds | Yes | No | Symmetrical upload/download | Yes | No | SLA-backed uptime | 99.99% | Best effort | Uncontended (not shared) | Yes | No | Proactive monitoring | Yes | No | Typical install time | 30–90 working days | 5–15 days | Best for VoIP/video | Yes | Unreliable That uncontended, symmetrical design is why a leased line behaves the same at 9am Monday as it does at midnight. A dedicated internet access circuit removes the variables that make shared broadband unpredictable for a busy team. ## How widely available is full fibre in the UK? Full-fibre availability has grown fast, which changes the maths for both options. Ofcom's Connected Nations reporting shows full-fibre (FTTP) reached roughly four-fifths of UK premises by 2025 (Ofcom, 2025 data), and the rollout keeps expanding the addresses where both fast broadband and competitively priced leased lines can be ordered. On the wholesale side, the Openreach FTTP network had passed 20m+ premises by September 2025 (Openreach, 2025 data). Wider fibre coverage has narrowed the historic gap between consumer-grade broadband and dedicated circuits - but availability is not the same as a guarantee. Broadband over FTTP is still contended and still carries no SLA, so the underlying trade-off stands. You can check the national picture in Ofcom's Connected Nations report. ## When should you choose a leased line? Choose a leased line when an internet outage has a direct financial cost, or when your team genuinely cannot work without connectivity. If you run cloud applications, hosted VoIP, video conferencing or regular large file transfers, the guaranteed symmetrical bandwidth and rapid-fix SLA pay for themselves in avoided downtime. In practice, we recommend a leased line if any of these apply to your business: - You have more than five regular users sharing the connection at once. - Phone calls run over VoIP and dropped calls cost you customers. - Staff upload large files, run cloud backups or host video calls daily. - Your core systems are hosted in the cloud rather than on-site. - A few hours offline would stop people billing, shipping or selling. This is where the "one provider, security-first" model matters: a single accountable partner who designs the circuit, monitors it and secures it removes the finger-pointing when something breaks. If connectivity and security sit together, see how we pair them on leased line security. ## When is business broadband the right call? Business broadband is the sensible choice when your needs are light, your office is small, or you want a low-cost second line. For a handful of users browsing, emailing and using a few cloud tools without heavy upload demands, a quality FTTP broadband service is fast, affordable and quick to install. Broadband also earns its place as a backup. Many of our clients run a leased line as the primary connection and keep an inexpensive broadband line on standby for automatic failover - covered in detail on our backup connectivity page. The point is to be deliberate: broadband as a primary line for a critical operation is a false economy, but broadband as a resilience layer is smart engineering. ## Does the cost of a leased line justify the premium? Often, yes - once you price in the cost of downtime rather than just the monthly line rental. Leased lines start from £69 per month; business broadband typically starts from £35 per month. The gap is real, but it is narrower than most people assume, and it shrinks further the moment an outage costs you a day's work. Here is the worked example we share with clients: > "A leased line starts from £69/month - more than business broadband, but for a 20-person office losing just one hour of productivity per month to broadband issues (at an average loaded salary of £25/hour), the cost of unreliable broadband is £500/month - already exceeding the leased line premium." The lesson is simple: the headline price difference is only half the story. For most businesses a serious outage means a day or more of disruption - at that scale, lost productivity dwarfs the monthly premium. For a full breakdown of pricing variables, read our leased line cost guide. ## How long does each connection take to install? Broadband installation typically takes five to fifteen working days because it usually rides existing infrastructure. A leased line takes 30 to 90 working days, because it often requires new fibre to be physically built to your premises and provisioned end to end. The trade-off is straightforward: broadband is fast to switch on, a leased line is slower to deliver but far more dependable once live. Because lead times are long, plan connectivity changes well ahead of office moves, headcount growth or contract renewals. Rushed decisions under pressure are how businesses end up tied to the wrong line. AMVIA runs a free site survey and returns a fixed quote within 24 hours, so you can plan with real numbers rather than estimates. ## Can you run broadband as failover behind a leased line? Yes - and it is one of the most cost-effective resilience moves a UK SME can make. A leased line serves as the primary connection under its 99.99% uptime SLA, while a broadband line provides automatic failover if the leased line faults. This dual-WAN design keeps you online without doubling your connectivity spend. Resilient connectivity is also a security control: losing your line can knock out cloud-hosted security tooling and remote access at exactly the wrong moment. The NCSC treats availability as a core part of operational resilience - see its guidance for organisations. For phone systems that depend on a stable line, a leased line plus failover underpins a reliable hosted phone system. ## The AMVIA recommendation If your business relies on cloud tools or VoIP, or has more than five regular users, we recommend a leased line. The price gap with business broadband has narrowed, leased lines now start from £69 per month, and the resilience pays for itself the first time an outage would have stopped work. Keep a broadband line as failover and you get the best of both. One provider, security-first, Microsoft-certified - connectivity designed and supported by the same team that secures it. ## Leased line vs dedicated line: same thing? Yes - “dedicated line”, “dedicated leased line”, “dedicated internet access (DIA)” and “ethernet leased line” all describe the same product: a fibre circuit reserved for one business, symmetric, uncontended and SLA-backed. The vocabulary varies by who is selling it; the thing being sold does not. If a quote uses one of these terms at a dramatically different price, compare the SLA and bearer, not the label - see our dedicated internet access page for the product in full. ## Types of leased line Four you will meet in UK quotes. Fibre ethernet (the default): full fibre to your premises on a 100Mb, 1Gb, 10Gb or 100Gb bearer - what almost every new circuit is. EoFTTC (ethernet over FTTC): a lower-cost hybrid using fibre to the cabinet with an ethernet service over the last copper stretch; useful where full fibre construction is uneconomic, limited in speed. EFM (ethernet in the first mile): ethernet over bonded copper pairs - a legacy option that made sense before fibre coverage widened and is now rarely the right answer. Dark fibre: the physical fibre itself, unlit, for organisations that run their own equipment on it - see our dark fibre page. For most businesses the decision is simply fibre ethernet at the right bearer size, priced per address on the pricing page. ## Frequently asked questions Q: At what team size should I switch from broadband to a leased line? A: Most businesses find broadband becomes unreliable once roughly ten or more staff use cloud applications, VoIP and video conferencing at the same time. Shared broadband suffers from contention and slow upload speeds, which make performance unpredictable as the team grows. A leased line guarantees symmetrical speeds with no contention, so performance stays consistent regardless of how many people are online. Q: Why are leased line upload speeds so much better than broadband? A: Leased lines are symmetrical - upload and download speeds are identical - whereas broadband upload is typically five to ten times slower than download. For teams uploading large files, running cloud backups or hosting video calls, that asymmetry creates a bottleneck. A leased line removes it entirely through a dedicated, uncontended circuit reserved for your business alone. Q: Can I use broadband as a failover alongside a leased line? A: Yes, and it is a popular resilience setup for UK businesses. The leased line acts as the primary connection under a 99.99% uptime SLA, while a broadband line provides automatic failover if the leased line develops a fault. This dual-WAN approach keeps you online during outages without doubling your connectivity budget, and is straightforward to configure. Q: How long does a leased line take to install compared to broadband? A: Broadband installation usually takes five to fifteen working days because it uses existing infrastructure. A leased line takes 30 to 90 working days, as it often needs new fibre built to your premises. Because lead times are long, plan ahead of office moves or growth, and ask your provider for a firm installation date in writing before you commit. Q: Is full fibre broadband the same as a leased line? A: No. Full-fibre (FTTP) broadband and a leased line can both use fibre to your building, but FTTP broadband is still contended - shared with other users - and carries no uptime SLA. A leased line is uncontended and dedicated to your business, with guaranteed symmetrical speeds and a contractual fix time. Same cable type, very different service. Q: Does a leased line come with better support than broadband? A: Generally yes. Leased lines include proactive monitoring and SLA-backed fix times, so faults are detected and prioritised rather than queued behind consumer tickets. Business broadband is best-effort, with no guaranteed response. With AMVIA, the same team that provisions and monitors the circuit also secures it, so there is a single point of accountability when something needs fixing. --- # MPLS vs SD-WAN: Which Is Best for Multi-Site Businesses? URL: https://amvia.co.uk/leased-lines/compare/mpls-vs-sd-wan Last updated: 2026-03 SD-WAN beats MPLS for most UK multi-site businesses moving to cloud-first working: it cuts WAN costs, deploys in days, and routes traffic intelligently across cheaper internet circuits. MPLS still wins only where strict data sovereignty or legacy private-network apps demand it. AMVIA designs and manages both, security-first. If you run several sites and your applications now live in Microsoft 365, Azure or other cloud platforms, the wide-area network you bought a decade ago is probably costing you more than it should. This is the practitioner's comparison of MPLS and SD-WAN - what each actually does, where the money goes, and which one we recommend. For the underlying circuits behind either approach, start with our business leased lines pillar. ## What is the difference between MPLS and SD-WAN? MPLS is a private carrier network that moves traffic between your sites over dedicated, contended-free circuits the provider controls. SD-WAN is a software layer that sits on top of any internet connections you already have - broadband, FTTP, leased lines or 4G/5G - and intelligently steers traffic across them. The distinction matters because it changes who controls the network and what it costs. With MPLS, the carrier owns the routing and the quality guarantees, and you pay a premium per site for that. With SD-WAN, you own the policy: your team (or AMVIA) decides which application takes which path, and you buy the underlying bandwidth on the open market. SD-WAN is transport-agnostic, so a single site can blend a dedicated internet access circuit with a cheaper broadband backup under one managed policy. ## MPLS vs SD-WAN: side-by-side comparison The two approaches solve the same problem - reliable connectivity across multiple locations - in very different ways. This table is the at-a-glance view; the sections below explain the trade-offs. | | Factor | MPLS | SD-WAN | Underlying network | Private carrier MPLS circuits | Any mix of broadband, FTTP, leased line, 4G/5G | Typical cost | High - premium private circuits per site | Lower - commodity internet; up to ~50% WAN saving (industry-quoted, 2025) | Deployment time | Weeks to months per circuit | Days using existing internet | Cloud / SaaS traffic | Backhauled via a central data centre | Direct local breakout at each site | Traffic control | Carrier-managed quality of service | Application-aware routing you control | Resilience | Single private circuit per site | Multiple circuits bonded with automatic failover | Best suited to | Data sovereignty, legacy private apps | Cloud-first, fast-growing multi-site SMEs ## How much cheaper is SD-WAN than MPLS? SD-WAN is usually the cheaper option because it runs over commodity internet circuits rather than premium private MPLS bandwidth. The source figure most often quoted is that "SD-WAN typically reduces WAN costs by approximately 50% compared to MPLS" - the exact saving depends on your circuit mix and site count. A worked example makes it concrete. A five-site business paying around £2,000 per month for MPLS can often achieve equivalent or better performance on SD-WAN for roughly half that, while gaining faster deployment and central control. AMVIA designs and manages SD-WAN deployments for multi-site SMEs from as little as £150 per site per month. A 100 Mbps leased line underlay is available from £69 per month - useful where you want guaranteed bandwidth under the SD-WAN layer. For a full breakdown of circuit pricing, see our leased line cost guide. ## When does MPLS still make sense? MPLS still earns its keep where the network must stay private end to end. It was designed to route traffic between private data centres, so organisations with strict data sovereignty rules, regulated workloads that cannot touch the public internet, or legacy applications built for private transport may still prefer it. That profile is shrinking. As more workloads move to Microsoft 365 and Azure, backhauling cloud traffic across a private core to a central breakout point adds latency and cost for no benefit. If most of your applications are SaaS, MPLS is solving a problem you no longer have. The honest rule of thumb: choose MPLS only when a specific compliance or legacy constraint forces private transport - not as a default. ## When should you choose SD-WAN? Choose SD-WAN when your applications live in the cloud, you have multiple sites to connect, and you want to control cost and routing yourself. It gives each location direct local breakout to the internet, prioritises voice and video automatically, and fails over between circuits without manual intervention. It is the stronger fit for the businesses we work with most: - Fast-growing or multi-site SMEs that need to add or move locations quickly - a new site can come online in days, not months. See multi-site connectivity. - Cloud-first organisations running Microsoft 365, Azure or hosted line-of-business apps. - Teams that want resilience by combining two diverse circuits with automatic backup connectivity. - Cost-conscious finance leaders who want predictable per-site pricing on commodity bandwidth. ## Can SD-WAN match MPLS reliability for voice and video? For most use cases, yes. SD-WAN uses application-aware routing to identify voice and video and place it on the best-performing path in real time, bonding multiple internet connections for redundancy. The result is comparable call and video quality to MPLS without the private-circuit premium. UK internet quality supports this: average fixed broadband download speeds sit around 69.4 Mbps (Ofcom Connected Nations 2024), and most business districts now have full-fibre options. Where calls and conferencing are genuinely mission-critical, pair SD-WAN with a leased line underlay to deliver MPLS-grade performance on the path that matters. Outages are not hypothetical - UK businesses lost around £3.7bn to internet downtime in 2023 (Beaming research), which is exactly why diverse-circuit failover is worth designing in. ## How does the choice affect your network security? Security is where the WAN decision quietly matters most. MPLS keeps traffic on a private core but offers little inspection at the edge; SD-WAN gives each site direct internet breakout, which improves performance but widens the attack surface unless every branch is properly protected. This is the security-first part of the brief. Direct breakout at twenty sites means twenty places an attacker can probe, so an SD-WAN rollout should ship with edge firewalling, segmentation and monitoring as standard - not as an afterthought. The UK's National Cyber Security Centre sets out sound design principles for exactly this kind of distributed network in its secure network design guidance. We build connectivity and protection together - see how we combine leased line security with managed monitoring so your network is fast and defended. ## What AMVIA recommends for UK multi-site businesses For UK businesses with multiple sites moving to cloud-first working, SD-WAN offers better value than MPLS. It delivers traffic prioritisation, failover and central management across every location - without the long lead times and rigid pricing of MPLS circuits. We design, deploy and manage the whole stack: the underlying circuits, the SD-WAN policy, and the security around it. That is the AMVIA difference in one line: one provider, security-first, Microsoft-certified. You get a single accountable team for connectivity and protection, rather than a telecoms reseller who stops at the router. ## Frequently asked questions Q: Is SD-WAN cheaper than MPLS? A: Generally, yes. SD-WAN runs over commodity internet circuits - broadband, FTTP or leased lines - rather than premium private MPLS bandwidth, so most multi-site businesses see a meaningful drop in their monthly WAN bill. The exact saving depends on your site count, circuit mix and whether you keep a guaranteed leased line underlay for critical traffic. Q: Is MPLS obsolete? A: Not obsolete, but increasingly niche. MPLS was built to connect private data centres, which suits organisations with strict data-sovereignty rules or legacy applications that need private transport. For cloud-first businesses running Microsoft 365 or Azure, direct internet breakout via SD-WAN is more efficient, so MPLS is now the exception rather than the default choice. Q: Can SD-WAN handle voice and video as well as MPLS? A: For most businesses, yes. SD-WAN uses application-aware routing to detect voice and video and steer it onto the best path in real time, while bonding multiple circuits for redundancy. Where calls are mission-critical, pairing SD-WAN with a guaranteed leased line underlay delivers performance on par with a traditional MPLS circuit. Q: How long does SD-WAN take to deploy compared with MPLS? A: SD-WAN can usually be turned up at a new site within days because it uses internet connectivity you already have. New MPLS circuits are provisioned by the carrier and commonly take several weeks to a few months. For fast-growing businesses or temporary locations, that agility is a significant operational advantage. Q: Is SD-WAN secure? A: It can be, when it is designed properly. Direct internet breakout at each site improves performance but widens the attack surface, so every branch needs edge firewalling, segmentation and monitoring. AMVIA builds SD-WAN with security integrated from day one, following NCSC network design principles, so faster connectivity does not mean weaker defences. Q: Do I still need a leased line with SD-WAN? A: Often, for at least one path. SD-WAN can blend broadband, FTTP and mobile, but a guaranteed-bandwidth leased line underlay gives critical voice, video and cloud traffic a contention-free path. Many businesses run a leased line plus a diverse second circuit, then let SD-WAN balance and fail over between them automatically. --- # Business Broadband vs Leased Line for Remote Teams: A Comparison URL: https://amvia.co.uk/leased-lines/compare/broadband-vs-leased-line-remote-teams Last updated: 2026-03 For a remote or hybrid team, a leased line usually wins. It gives uncontended, symmetric bandwidth and a hard uptime SLA, so the office hub that anchors a distributed workforce stays fast at 4pm. Business broadband is cheaper and faster to install, but it shares capacity and guarantees nothing. The right call depends on how many people depend on that one connection. If you are sizing connectivity for a distributed workforce, start with the parent guide to business leased lines and then weigh it against broadband using the breakdown below. This page sits alongside our wider leased line vs business broadband comparison and the plain-English what is a leased line explainer. ## What is the real difference between broadband and a leased line? The core difference is sharing and symmetry. Business broadband shares one local connection across many premises and prioritises download over upload. A leased line is a dedicated fibre circuit with the same speed up and down, no contention, and a contractual uptime guarantee. For a team where everyone uploads to the cloud at once, that distinction decides the day. | | Feature | Business Broadband | Leased Line | Typical SLA | Best efforts; no guaranteed uptime | 99.99% uptime SLA | Fault response time | Next business day (typical) | 4hr P1 response, 8hr repair | Contention | 10:1 to 50:1 | Uncontended (1:1) | Symmetric speeds | No (download >> upload) | Yes | Bandwidth guarantee | No | Yes | Installation time | 5–15 business days | 30–90 working days | Typical cost (100Mbps) | from £35/month | from £69/month Contention is the part most buyers underestimate. On a contended broadband product, the headline speed is a best case you share with neighbouring businesses, and it sags when demand peaks. Ofcom's consumer guidance explains how shared networks and peak-time demand affect real-world broadband performance (ofcom.org.uk). A leased line removes that variable entirely. ## Which connection do remote and hybrid teams actually need? It depends on where you are measuring. The office or data hub that anchors a distributed team needs a leased line, because every VPN tunnel, video call and cloud sync converges on that single point. Individual home workers are usually fine on standard broadband, since each home connection only carries one person's traffic. In practice, most UK SMEs run a hybrid model: - The office hub carries the shared load - VPN concentration, hosted phone systems, large file transfers and backups. This is where contention and upload symmetry bite, so a leased line earns its cost. - Home and field workers connect over their own broadband. The NCSC's home working guidance covers securing those endpoints with device controls and conditional access (ncsc.gov.uk), which matters more than raw speed for most remote roles. - Voice and collaboration ride on top of the office connection. If your team lives in Teams, see how a dedicated circuit underpins Microsoft Teams calling. The question is rarely "broadband or leased line for everyone". It is "what does the hub need, and what do the spokes need". ## Can business broadband handle Microsoft Teams and cloud apps? For small teams, yes. Business broadband with upload above 50Mbps can carry several concurrent Microsoft 365 sessions and Teams calls. The risk is contention: during peak periods, available bandwidth can drop and call quality wobbles unpredictably. Where Teams quality is business-critical, a leased line removes that variability outright. The deciding factor is upload. Cloud apps, video and backups are upload-heavy, and broadband starves the upload path to protect download headline figures. A symmetric leased line gives the same capacity in both directions, which is why ten people on simultaneous video calls feel the difference. For always-on access to cloud workloads, our dedicated internet access page covers how a guaranteed uplink behaves under load. ## How much does each option cost for a remote team? Business broadband starts from £35 per month depending on speed and provider. A 100Mbps leased line starts from £69 per month, with pricing varying by location, provider and contract term. AMVIA leased line quotes start from £69 per month. The gap is real, but so is the cost of an unreliable hub. Price the decision against downtime, not against the headline number: - A best-efforts broadband fault can mean a next-business-day fix - potentially a full working day with the team idle. - A leased line SLA puts a 4-hour P1 response and 8-hour repair clock on faults and backs it contractually. - For a 20-person team, one lost working day usually costs more than the monthly premium of the dedicated line. For a full cost breakdown by speed and term, see our leased line cost guide. If your hub load is light and budget is tight, the business broadband route may still be the pragmatic choice. ## When should a remote-first business choose each option? Choose business broadband when the office hub is small, headcount is low, and the team's heavy lifting happens on individual home connections. It is cheaper, installs in days rather than months, and is enough when no single shared connection is mission-critical. Choose a leased line when ten or more users depend on one connection for cloud tools, video and voice, when upload symmetry matters, or when an SLA-backed fix time is non-negotiable. Multi-site organisations and anyone running hosted telephony from a central hub almost always land here. - Broadband fits: micro-teams, light hub load, fast deployment, tight budgets. - Leased line fits: 10+ users on one circuit, video-heavy or voice-critical work, guaranteed uptime, multi-site backbones. ## The AMVIA recommendation For remote-first businesses with 10 or more users relying on cloud tools and video conferencing, we recommend a leased line. Predictable, uncontended performance removes the productivity drain of peak-time broadband congestion. AMVIA leased line quotes start from £69 per month - often less than the hidden cost of a single lost working day caused by connectivity problems. One provider, security-first, Microsoft-certified. ## Frequently asked questions Q: Is a leased line better than broadband for remote workers? A: It depends where you measure. For the office hub supporting a distributed team, a leased line delivers consistent, uncontended, symmetric bandwidth that broadband cannot match at peak hours. For individual home workers, standard broadband is typically enough for Microsoft 365 and video calls, so most SMEs use both. Q: Can broadband support Microsoft Teams calls reliably? A: For small teams, yes. Business broadband with upload above 50Mbps can support several concurrent Teams calls. The risk is contention - during busy periods, available bandwidth may drop and affect quality unpredictably. Where call quality is business-critical, a leased line removes that variability and keeps performance steady. Q: How much faster is a leased line than broadband? A: Leased lines run from 100Mbps to 100Gbps with symmetric upload and download. A 100Mbps leased line gives 100Mbps both ways, consistently, without contention. Broadband may advertise higher download figures but offers far lower upload and is subject to peak-time contention, so real-world performance is less predictable. Q: What is the typical cost difference between broadband and a leased line? A: Business broadband starts from £35 per month. A 100Mbps leased line starts from £69 per month, varying by location and contract term. The premium is significant, but for businesses where connectivity is critical infrastructure, the leased line's reliability and SLA often represent better value. Q: Do home workers need a leased line too? A: No. Each home connection carries one person's traffic, so standard broadband is usually sufficient there. The leased line belongs at the office or data hub, where many users' traffic converges. Secure the home endpoints with device management and access controls rather than upgrading every home line. Q: How long does a leased line take to install versus broadband? A: Business broadband typically installs in 5 to 15 business days. A leased line involves dedicated fibre and usually takes 30 to 90 working days, because it may require new physical infrastructure to the premises. Plan the lead time early if you are moving a hub or opening a new site. --- # UK Leased Line Providers Compared 2026: BT vs Virgin vs CityFibre URL: https://amvia.co.uk/leased-lines/compare/uk-leased-line-providers Last updated: 2026-09 There is no single best UK leased line provider - the right one depends on which networks reach your postcode. BT/Openreach has the widest coverage, Virgin Media Business is strong where its network runs, and alt-nets like CityFibre often undercut both (1Gbps from £129/month) in the cities they serve. Comparing all of them for your exact address routinely beats any single provider's rate card. Ask five UK businesses who their leased line is "with" and you'll hear five brand names - BT, Virgin, Vodafone, TalkTalk, or a reseller they found on Google. Underneath, most circuits ride one of a handful of physical networks, and the brand on the invoice matters far less than whose fibre actually reaches the building. This comparison sets out how the market really fits together, using the same postcode-first logic we apply on our business leased lines hub. ## How the UK leased line market is actually structured Three layers matter. First, the network owners: Openreach (BT's access network), Virgin Media Business's own cable-and-fibre estate, and the alt-nets - CityFibre being the largest - building full-fibre city footprints. Second, the direct sellers: BT, Virgin and enterprise players like Colt and Zayo selling circuits on networks they control. Third, the resellers and aggregators - Vodafone, TalkTalk Business and many others - selling over Openreach, CityFibre and more, often at sharper prices than the network owner's direct channel. The practical consequence: the same 1Gbps circuit to the same building can carry several different prices depending on who sells it and whose network it rides. Wholesale networks like Openreach and CityFibre can't be bought directly at all - a partner has to sell them to you. ## Where each provider is strong BT/Openreach is the coverage play. If your site is rural, or you need one carrier relationship across a multi-site estate, BT's reach is genuinely hard to match - that's what you're paying for when BT direct quotes £200–£600/month for circuits that alt-nets price from £129 in the cities. Virgin Media Business is aggressive where its own network runs: from £69/month for 100Mbps on-net, with quicker installs where no construction is needed. CityFibre and the alt-nets are the value story of the 2020s - modern symmetric fibre, expanding footprints, and 1Gbps from £129/month via partners. Colt and Zayo serve high-capacity metro and enterprise requirements in major cities, and matter most at 10Gbps and above. ## The main UK leased line providers, one by one ## BT Business The incumbent, selling over its own Openreach access network. Coverage is the genuine differentiator - rural sites and multi-site estates the alt-nets don't reach - and its enhanced SLA options suit organisations that want one carrier everywhere. The trade-off is price: BT direct is rarely the sharpest quote in well-served urban areas, and renewing by default is the most expensive habit in UK connectivity. See BT leased line vs alternatives. ## Virgin Media Business The only national rival that owns its network end to end. Where its fibre runs close to your premises, on-net pricing is aggressive - from £69/month for 100Mbps - and installs land quicker because no new construction is needed. Off-net, quotes climb steeply. Its independence from Openreach also makes it the natural second circuit for resilience. See Virgin leased line vs alternatives. ## CityFibre The largest alt-net, and wholesale-only: you buy CityFibre circuits through partner providers, never direct. Inside its city footprints, partner competition frequently produces the sharpest 1Gbps price in the market - from £129/month - on modern fibre built for symmetric business traffic. Outside those footprints it simply isn't an option, which is why the postcode check comes first. ## Vodafone Business No fixed access network of its own - Vodafone resells over Openreach and CityFibre, often at sharper rates than the network owners' direct channels, and can bundle mobile. Because its cost base changes with the underlying network, its competitiveness genuinely varies street by street. See Vodafone leased line vs alternatives. ## TalkTalk Business A reseller in the same mould: Openreach and CityFibre underneath, keen pricing on top. Shortlist it for price competition on standard 100Mbps–1Gbps circuits rather than for complex multi-site engineering. ## Colt An enterprise fibre operator with its own metro networks in major UK and European cities. Colt matters when the requirement is high-capacity - multi-gigabit and 10Gbps+ circuits, low-latency links between city sites, connectivity into data centres - rather than a single-site SME connection. ## Zayo Similar territory: international backbone, metro fibre in the biggest cities, and a focus on wholesale, carrier and enterprise capacity. For most SMEs Zayo appears indirectly - as the network under a partner's quote - rather than as the brand on the invoice. ## Why comparing beats choosing Leased line pricing is engineered per address: UK pricing spans roughly £69 to £1,200+ per month across speeds and regions, with install charges from £0 to £2,500 and excess construction charges possible where fibre must be built - the UK Business Connectivity Pricing Index publishes the actual quoted-price and construction-charge distributions from live market data. Each provider prices from where its fibre already runs relative to your building - so provider league tables are close to meaningless at the level of a single postcode. The provider that wins on your street may lose two streets away. That's the whole case for a network-agnostic comparison: query every carrier with fibre near your premises, surface construction charges before contract, and weigh price against install time and SLA repair terms together. It's how we quote - and it's why businesses coming off a default BT renewal typically save 15–35% in our experience. Start with the full UK cost breakdown or go straight to a multi-carrier quote for your postcode. ## What to compare beyond price - SLA repair terms: uptime percentages look identical (99.95%–99.99% across the market); mean time to repair and service credits are where products differ. - Install lead time: everyone works to 30–90 working days, but a provider already on-net at your building lands at the short end - often the real tiebreaker. - Construction charges: get them surfaced in writing before you sign, whoever you buy from. - Security: a dedicated circuit is a direct path into your network - factor in leased line security whoever provides the line. ## Frequently asked questions Q: Who is the best leased line provider in the UK? A: There is no universal best - it depends on which networks reach your postcode. BT/Openreach has the widest coverage, Virgin Media Business prices aggressively on its own network, and alt-nets like CityFibre are frequently cheapest in the cities they serve. The provider with fibre closest to your building usually wins on both price and install time, which is why a postcode-level comparison beats brand loyalty. Q: Is BT the most expensive leased line provider? A: Often, but not always. BT direct pricing for 100Mbps–1Gbps circuits has commonly sat in the £200–£600/month range, while alt-net routes start from £129/month for 1Gbps where available. In our experience, businesses comparing the market rather than renewing with BT by default typically save 15–35% - but at rural sites BT is sometimes the only realistic option, and coverage is worth paying for. Q: Do all leased line providers offer the same SLA? A: SLAs are broadly similar on paper - typically 99.95%–99.99% uptime with defined fix times - but the detail differs: mean time to repair, service credits, and how faults are prioritised vary by provider and product. Compare the repair commitment, not just the uptime percentage. A 99.99% SLA with a 5-hour fix is a different product from one with a 24-hour fix. Q: Can I buy CityFibre or Openreach leased lines directly? A: Generally no - both are wholesale networks sold through partners and resellers. That's precisely why the reseller market exists and why prices for the same underlying circuit vary between sellers. A network-agnostic partner compares the wholesale routes and the reseller pricing at once, so you see the best route to your building rather than one seller's margin. Q: Should I use a broker or go direct to a provider? A: Going direct gets you one network's price for your postcode. A network-agnostic partner queries every carrier with fibre near your building - including routes you can't buy directly, like CityFibre wholesale - and manages the install and faults through one relationship. Unless you already know which network is closest to your premises, comparison first is the safer default. Q: How long do leased line installs take with each provider? A: All providers work to the same physics: 30–90 working days from order to live service, depending on whether fibre already reaches your building. Where a provider is already on-net at your premises, installs land at the shorter end. This is often the tiebreaker between two similar quotes - ask every provider for a firm date in writing. Q: Who are the main leased line providers in the UK? A: Seven names cover most of the market: BT (selling over its own Openreach network), Virgin Media Business (its own national network), CityFibre (wholesale-only, bought through partners), Vodafone and TalkTalk Business (resellers over Openreach and CityFibre), and Colt and Zayo (enterprise metro fibre in major cities). Dozens of smaller resellers sell over the same underlying networks - which is why the network at your postcode matters more than the brand list. Q: Which leased line provider is cheapest? A: The one whose fibre is already closest to your building. As a pattern: alt-net routes bought via partners are frequently the sharpest 1Gbps price (from £129/month), Virgin Media Business is aggressive on-net (100Mbps from £69/month), and BT direct tends to sit at the £200–£600/month end but reaches sites nobody else serves. No provider is cheapest everywhere - two streets can produce two different winners, which is the whole case for comparing at postcode level. Q: Can I switch leased line providers before my contract ends? A: You can, but early termination charges usually make it uneconomic - most businesses time the comparison to the renewal window instead. The practical approach: start comparing a few months before term ends, because a new circuit's 30–90 working day install can run in parallel with the old contract, letting you switch at expiry without downtime or double-paying. --- # BT Leased Line vs Alternatives: Is BT Worth the Premium in 2026? URL: https://amvia.co.uk/leased-lines/compare/bt-leased-line-vs-alternatives Last updated: 2026-07 BT leased lines have commonly been priced at £200–£600/month for 100Mbps–1Gbps direct, while the same speeds start from £69/month (100Mbps) and £129/month (1Gbps) via Virgin Media Business and alt-net routes like CityFibre where they serve your postcode. BT still wins on coverage - especially rural and multi-site - but in well-served areas, businesses comparing the market instead of renewing with BT by default typically save 15–35%. BT is where most UK businesses start - and stop - when they buy a leased line. Sometimes that's the right call; often it's an expensive default. This comparison lays out where BT direct genuinely earns its premium, where the alternatives beat it, and how to tell which situation your postcode is in. For the wider market picture, see our full UK provider comparison. ## What BT actually sells (and what it costs) BT sells dedicated circuits over Openreach, the access network its group owns - the widest in the UK, passing 20m+ premises with full fibre by September 2025. That coverage is the product: for rural sites and multi-site estates wanting one national carrier, BT is frequently the only realistic bidder. Direct pricing for 100Mbps–1Gbps circuits has commonly sat at £200–£600 per month - a premium that makes sense where no one else reaches, and much less sense at a city postcode served by three networks. ## The alternatives, honestly stated Virgin Media Business runs its own national cable-and-fibre network and prices aggressively on it: from £69/month for 100Mbps and £129/month for 1Gbps where on-net. CityFibre is wholesale-only - you buy it via partners - and its expanding city footprints carry some of the sharpest 1Gbps pricing in the market, from £129/month. Vodafone and TalkTalk Business resell over Openreach and CityFibre, often undercutting BT direct on the very same physical network. SLA structures across all of these are comparable to BT's: 99.95%–99.99% uptime with defined repair terms. Two honest caveats. First, coverage: none of the alternatives matches Openreach's reach, so at plenty of UK postcodes the comparison is BT versus nothing. Second, brand isn't circuit quality - but neither is it a guarantee. Compare mean time to repair and service credits, not logos. ## The renewal trap The most expensive leased line decision in the UK is the unexamined BT renewal. Alt-net and Virgin footprints expand every year, so an address with no alternative at your last renewal may have two now - at half the price for the same SLA class. A like-for-like 1Gbps comparison takes 24 hours and costs nothing; against a £400–£600 BT renewal, a £129–£200 alternative route returns £3,000–£5,600 a year. In our comparison experience, businesses that check the market instead of auto-renewing typically save 15–35% - and when BT still wins, they renew knowing it's on merit. ## How to run the comparison properly - Check every network for your exact postcode - footprints are street-level, not city-level. Start with a multi-carrier quote. - Compare repair terms, not just uptime percentages - 99.99% with a 5-hour fix and 99.99% with a 24-hour fix are different products. - Get construction charges in writing before you sign, whoever you buy from. - Sequence the migration - new circuit installed and tested before the BT cease, so switching means a planned cutover, not downtime. See our installation timeline guide. - Treat the circuit as part of your security perimeter - whoever wins, factor in leased line security. ## Frequently asked questions Q: How much does a BT leased line cost? A: BT direct pricing for 100Mbps–1Gbps leased lines has commonly sat in the £200–£600 per month range, depending on speed, location and contract term. The same speeds start from £69/month (100Mbps) and £129/month (1Gbps) via Virgin Media Business and alt-net routes where they serve your postcode - which is why a market comparison before any BT renewal is worth 24 hours of your time. Q: Is a BT leased line better quality than the alternatives? A: Not inherently. Uptime SLAs across BT, Virgin Media Business and alt-net business circuits are comparable - typically 99.95%–99.99% with defined repair times. The meaningful differences are coverage (BT's is widest), install lead time at your specific address, and price. Compare the repair commitment and service credits rather than assuming the bigger brand means a better circuit. Q: When is BT genuinely the right choice? A: When coverage is the constraint: rural sites, multi-site estates that want one national carrier, or postcodes where neither Virgin nor an alt-net has fibre. BT's Openreach reach is real and worth paying for in those cases. The mistake is paying the coverage premium at a city-centre postcode that three networks already serve. Q: Can I keep my BT line but pay less? A: Sometimes. Openreach-delivered circuits are sold by many resellers, not just BT - the same underlying network can carry different retail prices. A market comparison will often surface an Openreach route via a reseller at a sharper price than a BT direct renewal, alongside any Virgin or alt-net options for your address. Q: How disruptive is switching from BT to another provider? A: A new circuit is installed and tested before your old one is ceased, so a well-managed migration involves a planned cutover rather than downtime. Allow 30–90 working days for the new line's installation and coordinate the BT cease date to follow it. AMVIA manages that sequencing - survey, install, cutover, cease - as standard. Q: Do the alternatives cover my area? A: Footprints change every year - Virgin Media Business and CityFibre have both expanded significantly, and an address that had no alternative at your last renewal may have two now. The only reliable answer is a live availability check for your exact postcode, which is free and typically returns within 24 hours. --- # Virgin Media Business Leased Line vs Alternatives (2026) URL: https://amvia.co.uk/leased-lines/compare/virgin-leased-line-vs-alternatives Last updated: 2026-07 Virgin Media Business leased lines are among the sharpest big-brand prices in the UK - from £69/month (100Mbps) and £129/month (1Gbps) where Virgin's own network reaches your premises. The trade-off is footprint: Virgin is strongest in urban and suburban areas, while BT/Openreach reaches almost everywhere and CityFibre partner routes often match Virgin's pricing in the cities. On-net, Virgin is usually a front-runner; off-net, construction charges can erase the advantage - a postcode check settles it. Virgin Media Business is the most credible national alternative to BT for dedicated connectivity - the only big brand selling leased lines over a network it fully owns and that owes nothing to Openreach. That independence is worth real money on the right postcode and nothing at all on the wrong one. This comparison lays out where Virgin genuinely wins, where BT or a CityFibre route beats it, and how to tell which situation your address is in. For the wider market picture, see our full UK provider comparison. ## What Virgin Media Business actually sells (and what it costs) Virgin's dedicated circuits are full Ethernet leased lines - symmetrical, uncontended, SLA-backed - delivered over its own national cable-and-fibre estate rather than Openreach. Don't confuse them with Virgin's shared business broadband: same brand, different product class entirely. Where the network is on-net, pricing is aggressive: from £69/month for 100Mbps and £129/month for 1Gbps, against BT direct pricing that has commonly sat at £200–£600/month for the same speed range. Installs also tend to land at the quicker end of the standard 30–90 working day window when no construction is needed. ## The alternatives, honestly stated BT sells over Openreach - the widest network in the UK, and at plenty of postcodes the only one. Rural sites and multi-site estates consolidating onto one national carrier are BT's home ground, and no Virgin quote changes that where Virgin hasn't built. CityFibre routes, bought via partners like Vodafone, Zen and TalkTalk Business, carry some of the sharpest 1Gbps pricing in the market - from £129/month - on modern wholesale full fibre, and in CityFibre cities they're frequently Virgin's toughest competition. SLA structures across all three are comparable: 99.95%–99.99% uptime with defined repair terms. Compare mean time to repair and service credits, not logos. ## The on-net question decides everything Virgin prices from where its fibre already runs. On-net, it's routinely a front-runner; off-net, excess construction charges to extend the network - sometimes thousands of pounds - flip the answer to another provider. Footprints are street-level, not city-level, so neither a coverage map nor last year's quote settles it. The only reliable answer is a live serviceability check for your exact building, with construction charges surfaced in writing before you sign. ## The resilience case: two networks beat one Virgin's genuine differentiator isn't just price - it's physics. Because the network is independent of Openreach, a Virgin circuit paired with an Openreach or CityFibre line gives true path diversity: no single carrier fault can take both down. For businesses where connectivity failure stops trading, the strongest design is a primary leased line on one network and automatic failover on another - and Virgin is one of the few ways to get that second physical path at scale. Check the two routes don't share ducts into your building, or the diversity is theoretical. ## How to run the comparison properly - Establish on-net status first - it moves the price more than any negotiation. Start with a multi-carrier quote for your exact postcode. - Compare repair terms, not just uptime percentages - 99.99% with a 5-hour fix and 99.99% with a 24-hour fix are different products. - Get construction charges in writing before contract, whoever you buy from. - Design resilience across networks, not within one - a second circuit on the same infrastructure shares its failure modes. See leased line vs broadband for backup-tier options. - Treat the circuit as part of your security perimeter - whoever wins, factor in leased line security. ## Frequently asked questions Q: How much does a Virgin Media Business leased line cost? A: Where Virgin's network is at or near your premises, dedicated circuits start from £69/month for 100Mbps and £129/month for 1Gbps - among the sharpest big-brand pricing in the UK market. Off-net, excess construction charges to extend the network can change the picture entirely, so the on-net question is the first thing to establish. A postcode-level check answers it within about 24 hours. Q: Is a Virgin leased line the same as Virgin business broadband? A: No. Virgin business broadband is a shared service over the DOCSIS cable network, with asymmetric speeds and best-efforts performance. A Virgin Media Business leased line is a dedicated Ethernet fibre circuit: symmetrical, uncontended, and backed by an uptime SLA with defined repair times. They're different products at different prices - the leased line is the one you build a business on. Q: What does on-net mean for a Virgin leased line quote? A: On-net means Virgin's network already reaches your building or passes very close to it, so no significant construction is needed. That's when Virgin's pricing is at its sharpest and installs land at the quicker end of the 30–90 working day range. Off-net, Virgin must build to reach you, and excess construction charges plus longer lead times usually follow - often making another network the better route. Q: Is Virgin Media Business as reliable as BT for leased lines? A: The SLA classes are comparable: 99.95%–99.99% uptime with defined repair commitments on both. The networks are different - Virgin runs its own infrastructure rather than Openreach - but that's an argument about coverage and diversity, not quality. As with any provider, compare the mean time to repair and service credits in the actual contract rather than assuming either brand is inherently more reliable. Q: Can I pair a Virgin leased line with an Openreach circuit for resilience? A: Yes - and it's one of the strongest reasons to buy Virgin. Because Virgin's network is physically independent of Openreach, a carrier-level Openreach fault can't take both circuits down. A common resilient design is a primary leased line on one network with an automatic failover circuit on the other, so no single network failure stops the business. Confirm the two routes don't share ducts into your building. Q: How do I find out if Virgin Media Business covers my address? A: Virgin's business network is strongest in urban and suburban areas, but footprints are street-level - coverage maps only approximate the answer. The reliable method is a live serviceability check against your exact postcode and building, which also surfaces any construction charges up front. AMVIA runs that check across Virgin, Openreach, CityFibre and Zayo in a single enquiry, typically within 24 hours. --- # Vodafone Leased Line vs Alternatives (2026): The Reseller Question URL: https://amvia.co.uk/leased-lines/compare/vodafone-leased-line-vs-alternatives Last updated: 2026-07 Vodafone doesn't own a UK access network - its leased lines ride Openreach and CityFibre wholesale fibre, typically priced below BT direct for the same speeds. On CityFibre routes, 1Gbps starts from £129/month. That makes Vodafone a price-and-bundling play (fixed plus mobile under one provider) rather than a coverage play: where CityFibre is absent, a Vodafone quote is Openreach economics, and comparing every reseller on the same physical route routinely finds a sharper price than any single brand's rate card. Vodafone occupies an unusual position in the UK leased line market: a global telecoms brand that owns no UK access network for fixed lines. Every Vodafone leased line rides Openreach or CityFibre wholesale fibre - which is precisely why it's often cheaper than BT, and precisely why comparing it against other sellers of the same fibre matters. This comparison lays out how the reseller model works, when Vodafone wins, and when another route beats it. For the wider market picture, see our full UK provider comparison. ## What Vodafone actually sells (and how the reseller model works) Vodafone buys wholesale capacity from Openreach - the same network BT sells - and from CityFibre, where it is one of the largest partners. On top of the circuit it adds the service wrap: provisioning, SLA, support and billing. The result is effectively national reach without owning a metre of local fibre. Pricing typically undercuts BT direct for like-for-like Openreach circuits, and on CityFibre routes Vodafone fronts some of the sharpest 1Gbps pricing in the market, from £129/month. SLA classes are comparable to the rest of the market: 99.95%–99.99% uptime with defined repair terms. The reseller model cuts both ways. The physical repair of a broken circuit is always the network operator's job - Openreach or CityFibre - whoever bills you. What you're actually choosing between resellers is the wrap: repair commitments, service credits, escalation quality, and price. That's the comparison worth doing carefully. ## The alternatives, honestly stated BT sells the same Openreach circuits with the strongest coverage story in the UK - at direct pricing that has commonly sat at £200–£600/month. Where neither CityFibre nor Virgin has built, the fight is BT versus other Openreach resellers (Vodafone included), and the winner is whoever prices that route sharpest. Virgin Media Business is the structural alternative: its own network, independent of Openreach, from £69/month for 100Mbps where on-net - and the natural second path for resilient designs. TalkTalk Business, Zen and other resellers sell the same wholesale routes as Vodafone; on any given street, one of them may beat Vodafone's number on identical fibre. ## The bundling question Vodafone's distinctive card is consolidation: business mobiles and fixed connectivity under one national brand, one account team, one bill. For businesses already reviewing their mobile estate, that's a genuine simplification - and occasionally unlocks better pricing. The discipline is to price the bundle against best-of-breed before signing: a sharper circuit from another reseller can outweigh a bundle discount, and mobile contracts renew on different cycles from a 36-month circuit. Make the convenience a choice, not a default. ## How to run the comparison properly - Compare routes first, brands second - establish which of Openreach, CityFibre and Virgin reach your building, then compare every seller of each route. Start with a multi-carrier quote. - Compare repair terms, not just uptime percentages - the network fixes the fibre; the reseller's SLA decides how hard anyone chases it. - Get construction charges in writing before contract, whoever you buy from. - Price bundles against best-of-breed - bundling mobiles is worth exactly the discount it carries, no more. - Treat the circuit as part of your security perimeter - whoever wins, factor in leased line security. ## Frequently asked questions Q: How much does a Vodafone leased line cost? A: Vodafone doesn't publish a single rate card - pricing depends on which wholesale route reaches your building. On CityFibre routes, 1Gbps circuits start from £129/month; on Openreach routes, Vodafone typically prices below BT direct (which has commonly sat at £200–£600/month for 100Mbps–1Gbps). Because other resellers sell the same physical routes, the reliable method is comparing every seller of the fibre at your postcode rather than taking any single brand's quote. Q: Does Vodafone have its own leased line network in the UK? A: No - Vodafone owns no UK access network for fixed lines. Its leased lines are delivered over Openreach and CityFibre wholesale fibre, with Vodafone providing the service wrap: provisioning, support, SLA and billing. That's not a weakness in itself - it gives Vodafone effectively national reach - but it means the circuit under a Vodafone contract is physically identical to the same route sold by another reseller. Q: Is buying a leased line from a reseller riskier than buying from the network owner? A: Not inherently - most UK leased lines are sold this way, and wholesale networks like CityFibre can only be bought through partners. The physical circuit and its repair are the network operator's job either way; what varies is the reseller's service wrap: SLA terms, service credits, escalation quality and price. Compare mean time to repair and support arrangements between resellers rather than assuming the network owner's own retail arm is automatically safer. Q: Should I bundle business mobiles with a Vodafone leased line? A: Bundling fixed and mobile under one provider genuinely simplifies management and can unlock better pricing - it's Vodafone's strongest card. But price the bundle against best-of-breed before signing: a sharper leased line quote from another reseller sometimes outweighs the bundle discount, and mobile contracts renew on different cycles from 36-month circuits. Run both numbers, then decide. Q: What is the difference between Vodafone and BT for leased lines? A: Where CityFibre is absent, surprisingly little physically: both are selling Openreach circuits, and the differences are price, SLA wrap and support - with Vodafone typically the cheaper of the two. Where CityFibre is present, Vodafone can quote a genuinely different network at aggressive pricing, which BT direct doesn't offer. BT's remaining edge is at the margins of coverage: rural and multi-site estates where Openreach reach and single-carrier consolidation matter most. Q: How do I find out what Vodafone can actually deliver at my address? A: Check the underlying networks, not the brand: whether Openreach fibre and CityFibre reach your building determines what any Vodafone quote can contain, what it will cost, and how long the install takes. A multi-carrier serviceability check for your exact postcode surfaces those routes and every reseller's pricing on them - including Vodafone's - typically within 24 hours, with construction charges stated up front. --- # 100Mbps Leased Line Cost UK 2026: From £69/Month URL: https://amvia.co.uk/leased-lines/100mb-leased-line-cost Last updated: 2026-07 What a 100Mbps leased line really costs in the UK: from £69/month in London and major cities, up to £320+ in rural areas. Regional pricing table, install charges, and how to pay less for your postcode. ## Who is a 100Mbps leased line right for? A 100Mbps dedicated circuit suits small-to-mid offices of roughly 25–50 staff - teams that have outgrown contended broadband but don't yet need gigabit capacity. Because a leased line is uncontended and symmetric, 100Mbps dedicated performs very differently from "100Mbps" broadband: you get the full speed in both directions at all times, backed by an uptime SLA with service credits. It's usually the right tier if you run cloud apps (Microsoft 365, CRM, ERP) and VoIP for a modest headcount, upload as much as you download, and can't afford peak-time slowdown. If your team is larger, cloud-heavy, or growing fast, compare against the 1Gbps tier - the price gap is often smaller than expected. ## Monthly cost vs one-off costs The monthly rental (from £69/month in well-served areas) is only part of the picture. Budget for: - Installation: typically £500–£2,000 as a one-off, frequently waived on a 36-month contract. - Excess construction charges (ECCs): where fibre has to be physically built to your premises, ECCs can range from £500 to £10,000+. A real multi-carrier check surfaces these before you commit. - Failover: many businesses pair the circuit with backup connectivity (broadband or 4G/5G) so a single fault never takes them offline. ## Why prices vary so much between postcodes Leased line pricing is engineered per address, not per product. Each carrier prices from where its existing fibre runs relative to your building - so the same 100Mbps circuit can be £69/month on one street and several times that a mile away. Urban postcodes (London, Manchester, Birmingham, Sheffield) generally price lower than rural ones because more carriers compete there. This is why comparing BT Openreach, Virgin Media Business, CityFibre and Zayo for your specific postcode routinely beats accepting a single provider's rate card - see our full UK leased line cost breakdown. ## 100Mbps leased line vs business broadband Business broadband is cheaper per month, but it is contended (shared with neighbouring premises), asymmetric (slow uploads), and carries no meaningful fix-time guarantee. A leased line costs more because the SLA is the product: guaranteed speed, symmetric bandwidth, and contractual repair times. If downtime costs you real money, the comparison usually resolves quickly - our leased line vs broadband comparison covers the decision in detail. ## How to get the best 100Mbps price Three moves consistently reduce the price: commit to a 36-month term (install usually waived), order on a 1Gbps bearer for cheap future upgrades, and - most importantly - compare every carrier that reaches your postcode rather than taking the first quote. AMVIA runs that comparison across BT Openreach, Virgin Media Business, CityFibre, Zayo and others, then manages the install end to end. Start with your postcode and a tailored quote typically lands within 24 hours. ## Frequently asked questions Q: How much does a 100Mbps leased line cost per month? A: A 100Mbps leased line starts from £69 per month in London and major UK cities, with suburban and rural postcodes typically ranging up to £320+ per month. The exact price depends on your address and which carriers have fibre nearby, so an accurate figure always comes from a postcode-level quote. Q: Is there an installation charge for a 100Mbps leased line? A: Installation is typically £500–£2,000 as a one-off charge, but many carriers waive it entirely on a 36-month contract. Where fibre has to be physically built to your premises, excess construction charges can apply - a proper multi-carrier availability check surfaces these before you sign anything. Q: Is 100Mbps enough for my business? A: A 100Mbps dedicated line comfortably supports roughly 25–50 staff using cloud applications and VoIP, because the bandwidth is uncontended and symmetric - you get the full 100Mbps up and down at all times. Larger or cloud-heavy teams should compare the 1Gbps tier, which starts from £129 per month. Q: How long does a 100Mbps leased line take to install? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre build, and testing. If you need connectivity sooner, a temporary 4G/5G router can bridge the gap until the circuit goes live. Q: Why do 100Mbps leased line quotes vary so much? A: Because pricing is engineered per address. Each carrier prices from where its existing fibre runs relative to your building, so the same circuit can cost very different amounts on neighbouring streets. Comparing BT Openreach, Virgin Media Business, CityFibre and Zayo for your exact postcode is the only way to find the genuine best price. Q: Can I upgrade from 100Mbps later without a new install? A: Yes - if the circuit is delivered on a 1Gbps bearer. The bearer is the physical capacity of the fibre; your committed speed is what you pay for. Ordering 100Mbps on a 1Gbps bearer means a later upgrade is a configuration change and a price adjustment, not a fresh 30–90 day installation. --- # 1Gbps Leased Line Cost UK 2026: From £129/Month URL: https://amvia.co.uk/leased-lines/1gb-leased-line-cost Last updated: 2026-07 1Gbps leased line pricing across the UK: from £129/month, with typical ranges up to £1,200+ by region. What drives the price and how to compare carriers for your exact address. ## Who is a 1Gbps leased line right for? The gigabit tier is the most popular leased line speed for UK SMEs - the sweet spot for cloud-heavy businesses, multi-team sites, and anyone whose work involves moving serious data: large file transfers, off-site backups, video production, heavy Microsoft 365 or ERP use across 50+ staff. Because a leased line is symmetric and uncontended, 1Gbps dedicated means 1Gbps upload as well as download, all day, backed by an SLA. If your team is under ~50 staff with modest cloud use, the 100Mbps tier (from £69/month) may be plenty. If you aggregate multiple sites or run data-intensive workloads, look at 10Gbps. ## Why does the same 1Gbps circuit get such different quotes? Gigabit pricing starts from £129/month and is engineered per address: each carrier prices from where its existing fibre runs relative to your building, and the sharpest offers come from alt-nets such as CityFibre and Hyperoptic on postcodes their networks already serve. Step outside those footprints and pricing rises with distance to fibre. That's why the only meaningful gigabit price is a multi-carrier quote for your postcode - see the full UK leased line cost breakdown for how this works across every tier. ## Monthly cost vs one-off costs - Installation: typically £500–£2,000 as a one-off, frequently waived on a 36-month contract. - Excess construction charges (ECCs): £500–£10,000+ where fibre has to be physically built to your premises - always surfaced by a proper availability check before you commit. - Enhanced SLA: faster repair targets typically add 10–15% to the monthly cost. - Failover: pairing the circuit with backup connectivity protects against the outages even a 99.99% SLA can't prevent. ## Is the jump from 100Mbps worth it? Often, yes - and by less margin than expected. In well-served urban postcodes the gap between 100Mbps (from £69/month) and 1Gbps (from £129/month) can be under £100/month for ten times the capacity. If your headcount is growing or your workloads are getting heavier, buying the gigabit tier now avoids paying for a second installation later. Where budgets are tight, a 1Gbps bearer with a lower committed rate gives you the upgrade path without the full gigabit price today. ## How to get the best 1Gbps price Commit to a 36-month term, check whether an alt-net already serves your postcode, and compare every carrier rather than accepting one rate card. AMVIA runs that comparison across BT Openreach, Virgin Media Business, CityFibre, Zayo and others, surfaces any construction charges upfront, and manages the 30–90 working-day install end to end. Start with your postcode - a tailored quote typically lands within 24 hours. ## Frequently asked questions Q: How much does a 1Gbps leased line cost per month? A: 1Gbps leased lines start from £129 per month, with the sharpest pricing on alt-net routes such as CityFibre and Hyperoptic. Typical ranges are £129–£700 in London, £129–£800 in regional cities, and up to £1,200+ in semi-rural areas. Your exact price depends on which carriers have fibre near your building. Q: Why do 1Gbps leased line quotes vary so much between providers? A: The lowest advertised pricing comes from alt-net carriers on postcodes their fibre already serves. Where your building sits relative to each carrier's network determines who can offer what - so two providers can quote very different prices for the same circuit. A multi-carrier comparison for your exact postcode resolves this. Q: Is a 1Gbps leased line worth it over 100Mbps? A: For cloud-heavy teams, multi-team sites, or anyone moving large files daily, usually yes. In well-served urban areas the price gap between 100Mbps (from £69/month) and 1Gbps (from £129/month) can be under £100 per month for ten times the capacity - and it avoids paying for a second install when you outgrow 100Mbps. Q: What one-off costs should I budget for? A: Installation is typically £500–£2,000, though many carriers waive it on a 36-month contract. Where fibre must be physically built to your premises, excess construction charges of £500–£10,000+ can apply - these should always be surfaced by an availability check before you sign. Q: How long does a 1Gbps leased line take to install? A: Like all leased lines, typically 30–90 working days from order to live service: desktop survey, physical site survey, fibre work where needed, then testing and cutover. A temporary 4G/5G router can bridge the gap if you need connectivity before the line goes live. Q: Is 1Gbps leased line speed symmetric? A: Yes. A 1Gbps leased line delivers 1Gbps upload and 1Gbps download simultaneously, uncontended, at all times - unlike gigabit broadband, where upload speeds are typically a fraction of the headline figure and bandwidth is shared with neighbouring premises. --- # 10Gbps Leased Line Cost UK 2026: From £349/Month URL: https://amvia.co.uk/leased-lines/10gb-leased-line-cost Last updated: 2026-07 10Gbps dedicated fibre starts from £349/month in UK cities, rising to £1,200+ in harder-to-reach areas. Who actually needs 10Gbps, what drives the cost, and how to get an exact quote for your site. ## Who actually needs a 10Gbps leased line? Ten-gigabit is the tier for data-intensive operations and multi-site aggregation: businesses hosting systems on-premises for external users, media and engineering teams moving very large files daily, and organisations consolidating several offices' traffic onto one high-capacity circuit behind SD-WAN or MPLS. Because a leased line is symmetric and uncontended, a 10Gbps circuit genuinely carries what several 1Gbps sites would otherwise need individually. Most single-site SMEs don't need this tier - the 1Gbps tier (from £129/month) covers even heavy cloud use for most teams. The honest test: if you can't name the workload that saturates 1Gbps, buy 1Gbps on a bigger bearer and upgrade later. ## Monthly cost vs one-off costs - Monthly rental: from £349/month in well-served city postcodes, up to £1,200+ where fibre must be extended. - Installation: typically £500–£2,000, often waived on a 36-month term. - Excess construction charges: more likely at this tier than any other, because 10Gbps needs a clean path to core fibre - £500–£10,000+ where builds are required. A proper availability check surfaces these before you commit. - Resilience: most 10Gbps deployments add a secondary circuit or diverse routing; factor it into the total cost of ownership rather than treating it as an optional extra. ## Why 10Gbps pricing varies so much The same postcode logic that governs every leased line tier applies with more force at 10Gbps: the circuit must reach high-capacity carrier infrastructure, and each carrier's core network runs in different places. City-centre premises often sit within metres of suitable fibre; business parks and edge-of-town sites may not. Comparing BT Openreach, Virgin Media Business, CityFibre and Zayo for your exact address is the difference between the £349 end of the range and the £1,200+ end - see the full UK leased line cost breakdown for how pricing works across all tiers. ## 10Gbps vs multiple smaller circuits If you run several sites, the choice is usually one 10Gbps aggregation circuit at head office plus smaller lines at branches, versus 1Gbps everywhere. Aggregation simplifies security and management (one perimeter, one set of policies) and often costs less in total - but it concentrates risk, which is why resilience design matters at this tier. AMVIA models both options as part of a quote, alongside backup connectivity for the aggregation site. ## How to get the best 10Gbps price Commit to a 36-month term, get every carrier checked rather than accepting a single rate card, and have construction charges surfaced in writing before signing. AMVIA compares BT Openreach, Virgin Media Business, CityFibre, Zayo and others for your postcode, designs the resilience around the circuit, and manages the 30–90 working-day install end to end. Start with your postcode - a tailored quote typically lands within 24 hours. ## Frequently asked questions Q: How much does a 10Gbps leased line cost per month? A: A 10Gbps leased line starts from £349 per month in well-served UK city postcodes. Typical ranges run £349–£850 in London, £349–£950 in major cities and suburban areas, and £349–£1,200+ where fibre has to be extended to reach the premises. Q: Who needs a 10Gbps leased line? A: Data-intensive operations and multi-site businesses: teams moving very large files daily, organisations hosting systems for external users, and companies aggregating several offices onto one circuit with SD-WAN or MPLS. Most single-site SMEs are better served by the 1Gbps tier from £129 per month. Q: What one-off costs apply to a 10Gbps leased line? A: Installation is typically £500–£2,000 and often waived on a 36-month contract. Excess construction charges are more likely at this tier than any other - £500–£10,000+ where fibre must be physically extended - so insist they're surfaced in writing before you sign. Q: How long does a 10Gbps leased line take to install? A: Typically 30–90 working days from order to live service, the same as other leased line tiers: desktop survey, physical site survey, fibre work where required, then testing and cutover. City-centre installs with existing nearby fibre land at the shorter end. Q: Is 10Gbps overkill compared with 1Gbps? A: For most single-site businesses, yes - 1Gbps symmetric and uncontended covers even heavy cloud use. 10Gbps earns its cost when you can name the workload that saturates a gigabit: multi-site aggregation, large-scale data movement, or hosting for external users. If you can't, buy 1Gbps on a larger bearer and upgrade by configuration later. Q: Do I need backup connectivity with a 10Gbps circuit? A: Strongly recommended. A circuit carrying multiple sites' traffic concentrates risk, so most 10Gbps deployments pair the primary line with a secondary circuit or diverse routing - a second fibre path into the building - rather than relying on basic broadband failover. --- # UK Leased Line Pricing Map 2026: Costs by Speed & Postcode URL: https://amvia.co.uk/research/uk-leased-line-pricing-2026 Last updated: 2026-07-08 What a UK business leased line costs in 2026: entry prices from £69/mo (100Mbps) to £1,999/mo (100Gbps), why the same circuit costs more at one postcode than another, and how to read a quote. Data confirmed July 2026. ## What this pricing map shows There is no single "UK leased line price". A leased line is a dedicated, uncontended fibre circuit built to your specific building, so the figure you pay is shaped by your postcode as much as by the speed you order. This page fixes the two things you can actually pin down: the entry price for each speed tier in a well-served area, and the reasons that price moves once you quote a real address. The four national floors, confirmed July 2026: - 100 Mbps - from £69/month. The entry point for a 25–50 person office that has outgrown contended broadband. - 1 Gbps - from £129/month. Ten times the capacity of 100 Mbps for less than twice the price. For most growing SMEs this is the tier that makes sense. - 10 Gbps - from £349/month. Data-intensive operations, media, and sites aggregating traffic for several offices. - 100 Gbps - from £1,999/month. A specialist tier for data centres, high-performance computing and hyperscale workloads, not a typical office purchase. These are floors - the best case in a postcode where fibre already reaches the building. Check the live figure for your address with our leased line quote tool, or read the tier-by-tier breakdowns for 100 Mbps, 1 Gbps and 10 Gbps. ## Methodology and data vintage Transparency is the point of a pricing asset, so here is exactly what these numbers are and are not. - Source: AMVIA's confirmed commercial floor for each speed tier, verified with our commercial team on 8 July 2026. AMVIA is network-agnostic and quotes across BT Openreach, Virgin Media Business, CityFibre, Zayo and Hyperoptic, so the floor reflects the most competitive carrier for a well-served postcode rather than a single network's list price. - What "from" means: the monthly rental for a symmetric, uncontended circuit at the stated speed, in a commercial postcode where fibre is already present, on a standard 36-month term. It excludes any one-off install or construction charge (covered below). - What it excludes: VAT, managed-router and SD-WAN options, and Excess Construction Charges where fibre has to be built to the premises. - Data vintage: July 2026. Circuit pricing moves with carrier tariffs and network build, so we re-verify these floors quarterly; the next review is due October 2026. We deliberately do not publish invented per-city price tables. Because a leased line is quoted per address, a headline "leased line price in Manchester" figure would be misleading - the number for two buildings on the same street can differ. What genuinely varies by location is explained next. ## Why leased line prices vary by location Four factors move a quote away from the floor. Understanding them tells you whether a price you've been given is fair - and where there's room to push. - Network footprint. Where BT Openreach, CityFibre, Virgin Media Business and regional altnets all serve a postcode, carriers compete and prices fall toward the floor. Where only one network reaches the building, there is no competitive tension and you pay more. Dense urban centres - London, Manchester, Birmingham, Leeds, Sheffield - are typically well served; business parks on the edge of town often are not. - Excess Construction Charges (ECCs). If no fibre reaches your building, the carrier has to physically build it - trenching, ducting and blowing fibre from the nearest access point. That civil-engineering cost is passed on as a one-off ECC, and it is the single biggest reason two identical circuits differ in price. Where fibre is already present, ECCs are usually zero. - Distance to the nearest Point of Presence. The further your building sits from the carrier's nearest aggregation node, the more fibre path and, sometimes, the higher the recurring rental. Rural and semi-rural sites feel this most. - Contract term. Longer terms lower the monthly rental because the carrier amortises any build cost over more months. A 36-month term is standard; 60 months can cut the monthly figure further, and 12-month deals carry a premium. The practical takeaway: the recurring monthly rental clusters near the tier floors in competitive areas, and the number that really swings your total cost is the one-off install/ECC. Always ask for both, separately. ## The economics of scale: why 1 Gbps is the sweet spot Leased line pricing does not scale linearly with speed, and that is the most useful thing on this page. Priced per megabit of dedicated capacity, higher tiers are dramatically cheaper: - 100 Mbps at £69 works out at roughly 69p per Mbps. - 1 Gbps at £129 is about 13p per Mbps - an 81% lower unit cost than 100 Mbps. - 10 Gbps at £349 is about 3.5p per Mbps. - 100 Gbps at £1,999 is about 2p per Mbps. The jump from 100 Mbps to 1 Gbps gives you ten times the headroom for under twice the monthly cost. Because the install cost and SLA are effectively identical across tiers, most businesses that can justify a leased line at all are better served buying 1 Gbps and growing into it than saving a few pounds a month on 100 Mbps. Our 1 Gbps cost guide works through when that logic holds. ## How to read a leased line quote A leased line quote has two numbers, and buyers routinely focus on the wrong one. Check both: - Monthly rental. The recurring cost. In a competitive postcode this should sit near the tier floor above. If it's well above and only one carrier serves you, that's the footprint effect, not a rip-off - but it's worth having a broker test every network. - One-off install / ECC. Often zero where fibre is present, but potentially four or five figures where it must be built. This is where quotes diverge most, and where a survey across multiple carriers can save the most. Also confirm the term, the SLA (typically 99.99% or 99.95% uptime with defined fault-response and repair windows), and whether managed router, firewalling or SD-WAN are included or extra. Comparing offers across carriers is exactly what a network-agnostic broker does - see our UK leased line providers comparison for how the major networks stack up, or go straight to a quote for your postcode. ## How to cite this data Cite as: AMVIA, UK Leased Line Pricing Map, July 2026 - amvia.co.uk/research/uk-leased-line-pricing-2026. The figures are AMVIA's published entry prices per speed tier (100Mbps £69, 1Gbps £129, 10Gbps £349, 100Gbps £1,999 per month), owner-confirmed July 2026 and re-checked quarterly against the same pricing registry that renders every price on this site. Journalists and researchers are welcome to reproduce the table and chart with attribution; for regional detail or comment, contact AMVIA on 0333 733 8050. ## Frequently asked questions Q: What do UK leased line prices look like across speed tiers in 2026? A: In 2026, business leased line entry prices start from £69/month for 100 Mbps, £129/month for 1 Gbps, £349/month for 10 Gbps and £1,999/month for 100 Gbps. These are best-case monthly floors for a symmetric, uncontended circuit in a well-served UK commercial postcode on a 36-month term, excluding VAT and any one-off construction charge. Because a leased line is built to your specific building, the exact price depends on your postcode - the only reliable figure is a quote for your address. Q: Why do leased line prices vary by postcode? A: Four factors: network footprint (where multiple carriers serve a postcode they compete and prices fall; where only one does, they don't), Excess Construction Charges where fibre must be physically built to the premises, distance to the carrier's nearest Point of Presence, and contract term. The recurring monthly rental clusters near the tier floor in competitive urban areas; the one-off install/construction charge is what swings the total cost most between addresses. Q: What is an Excess Construction Charge (ECC) on a leased line? A: An ECC is a one-off charge a carrier passes on when there is no existing fibre to your building and it has to be physically built - trenching, ducting and blowing fibre from the nearest access point. Where fibre is already present the ECC is usually zero; where significant civil works are needed it can run to four or five figures. It is the single biggest reason two otherwise-identical leased line quotes differ, so always ask for it itemised separately from the monthly rental. Q: Is a 1 Gbps leased line worth it over 100 Mbps? A: Usually, yes. Priced per megabit, 1 Gbps at £129/month works out at about 13p per Mbps versus 69p per Mbps for 100 Mbps at £69/month - an 81% lower unit cost for ten times the capacity, at under twice the monthly price. Because the install cost and SLA are effectively the same across tiers, most businesses that can justify a leased line are better buying 1 Gbps and growing into it than saving a few pounds a month on 100 Mbps. --- # PSTN Switch-Off Statistics 2026: The UK Analogue Countdown in Numbers URL: https://amvia.co.uk/research/pstn-switch-off-statistics Last updated: 2026-09-02 The UK's analogue phone network (PSTN) is retired on 31 January 2027. Ofcom data shows residential PSTN landline customers fell from 5.2 million in July 2024 to 3.2 million in July 2025 - roughly a fifth of residential landline connections still to move - while around 1.8 million UK households rely on telecare devices that must be checked before migration. No new analogue services have been sold since September 2023. This page collects the verified statistics, with sources, for businesses and journalists tracking the switch-off. The retirement of the Public Switched Telephone Network (PSTN) is the largest change to UK telecoms infrastructure in decades, and it has a hard finish line: 31 January 2027, the date BT Group has set for withdrawing the analogue network entirely (Openreach - upgrading the UK to digital phone lines). This page collects the verified numbers in one place. Every figure carries its source, and the page is updated as new Ofcom and Openreach data is published - cite it freely with attribution. ## How fast is the migration actually going? Faster than it was - but with a substantial tail. Ofcom's tracking shows residential PSTN landline customers fell from 5.2 million in July 2024 to 3.2 million in July 2025, a reduction of two million customers in a year. By July 2025, PSTN connections accounted for roughly a fifth of all residential landline connections, and around one million households dropped their landline entirely in favour of broadband-only service in that year (Ofcom Connected Nations 2025). The direction was set earlier: Openreach stopped selling new analogue services nationally in September 2023, having reported just under 10 million lines still to convert when it set out the retirement plan, with more than 500 exchange areas covering some 4.6 million premises already in the stop-sell phase at that point (Openreach, 2023). ## The telecare exposure The most sensitive number in the programme: around 1.8 million UK households use telecare - personal alarms and monitoring devices, many of which were designed for analogue lines. Under the Government's PSTN Charter, signed by the major providers, no telecare user should be migrated until their device is confirmed compatible with a digital line, and the Department of Health and Social Care's Telecare National Action Plan sets out the safeguarding steps in detail (UK Government - Telecare National Action Plan). For businesses the equivalent exposure is operational: intruder alarm signalling, lift emergency phones, door entry systems and older card terminals all commonly dial out over analogue lines. None of them survives the switch-off unconverted - our PSTN switch-off guide covers the migration path for each. ## What this means for UK businesses Three practical conclusions fall out of the numbers. First, the deadline does not move with demand - the original 2025 date was extended once to give the industry time, and 31 January 2027 is now the planning assumption every provider works to. Second, the tail is where the risk concentrates: the organisations still on analogue lines in the final year are disproportionately those with the most complex dependencies - multiple sites, alarm and lift lines, payment devices. Third, capacity tightens as the deadline nears: migration engineering is a finite resource, and the closer to the date a business starts, the less scheduling control it has. The commercial migration path is well established: cloud telephony from business VoIP providers (AMVIA's published tiers start at £5.95/user/month against a UK market norm of £12–£20), carried over full-fibre broadband or a dedicated leased line, with analogue-dependent devices replaced or converted during the same project. A business can establish its exposure in about sixty seconds with our free readiness check. ## How to cite this data Cite as: AMVIA, PSTN Switch-Off Statistics, July 2026 - amvia.co.uk/research/pstn-switch-off-statistics. Primary figures belong to their named sources (Openreach, Ofcom, UK Government) and should be attributed to them; this page's contribution is the compilation, the business analysis and the migration-market pricing context. Journalists are welcome to reproduce the summary numbers with attribution; for comment on the business migration wave, contact AMVIA on 0333 733 8050. ## Frequently asked questions Q: When is the PSTN switch off date? A: The UK's analogue phone network (PSTN) is switched off on 31 January 2027 - a hard deadline for every remaining analogue line. The original end-2025 date was extended once, explicitly to give industry and vulnerable users more migration time, and no new analogue services have been sold since September 2023. Anything still running on an analogue line after that date - phones, alarms, lifts, card terminals - stops working. Q: How many UK phone lines are still on the analogue network? A: Ofcom's most recent tracking put residential PSTN landline customers at 3.2 million in July 2025, down from 5.2 million a year earlier - about a fifth of residential landline connections. Business lines, ISDN circuits and the analogue lines behind alarms, lifts and card terminals sit on top of that figure, which is why business exposure is best established per site rather than inferred from national numbers. Q: Is the 2027 PSTN switch-off date likely to move again? A: Plan as if it won't. The original end-2025 date was extended once, to 31 January 2027, explicitly to give the industry and vulnerable users more migration time - and the industry has organised around that date since. No new analogue services have been sold since September 2023, so the network is already closed to growth; the remaining question is only when each line migrates, not whether. Q: How many telecare users are affected by the switch-off? A: Around 1.8 million UK households use telecare devices - personal alarms and monitoring systems, many built for analogue lines. Under the Government's PSTN Charter, providers have committed not to migrate a telecare user until the device is confirmed to work on a digital line, and the Telecare National Action Plan coordinates the safeguarding work between government, councils and providers. Q: Where do these PSTN statistics come from? A: Three primary sources: Openreach (the switch-off date, the September 2023 stop-sell, and the scale of lines to convert), Ofcom (the migration-pace figures, most recently Connected Nations 2025), and UK Government publications (the telecare figures and the PSTN Charter). Each figure on this page is attributed inline, and the page is updated as those sources publish new data. --- # UK Business Connectivity Pricing Index 2026: Live Corpus Data URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index Last updated: 2026-08-08 The UK Business Connectivity Pricing Index publishes AMVIA’s proprietary connectivity statistics as dated, versioned data (headline feeds CC BY 4.0): the median quoted excess construction charge on a UK leased-line order is £2,197 (n=97), 58.4% of currently-billed circuits are past their contract end (n=1,338), and the median 1Gbps leased-line order took 78 days from order to live in 2023–25 (n=101) - all as of 2026-08-08. ## What this index is AMVIA and Compare Fibre have traded UK business connectivity for over a decade. This index publishes the aggregate statistics from that corpus as citable, licensed data: no customer identifiers, no supplier buy prices, every cell built from at least 5 underlying records, and every figure stamped with its as-of date, sample size and method version. The full rules are on the methodology page. ## What it covers - Excess construction charges - the quoted-amount distribution behind the most feared line on a leased-line quote. We’re not aware of any other UK source publishing this. - Regional price benchmarks - 189 published cells of leased-line pricing by region, speed band and term (quoted amounts; see the 2026 report for the regional tables). - Delivery lead times - order-to-live day counts for delivered circuits, by era and service family. - Contract status - the live-book share of circuits already past contract end. ## Reading the numbers honestly Figures are quoted amounts from real quotes and priced email threads unless a cell’s basis says otherwise - quoted-market and transacted views are never mixed. The ECC incidence figure is published as a floor, not a rate. Where a regional sample is too thin, the feed rolls the cell up and says so in the cell’s own note; nothing is interpolated. Headline feeds (ECC, delivery lag, contract status) are licensed CC BY 4.0 - reuse freely with the attribution "Source: Amvia UK Connectivity Data" linked to this index. Regional benchmark cells are published here for reference; contact AMVIA to licence reuse. ## Browse the benchmarks by region East Midlands · East of England · London · North East · North West · Scotland · South East · South West · Wales · West Midlands · Yorkshire and the Humber. (Northern Ireland’s samples are currently below the regional threshold, so its cells carry the UK-wide roll-up - see the 2026 report tables.) ## Frequently asked questions Q: Where does the data come from? A: From AMVIA’s own trading corpus: site-deduplicated tracker records, priced email threads and billing records accumulated over a decade of UK connectivity trading, aggregated and anonymised before publication. The methodology page documents each feed’s basis verbatim. Q: Can I reuse these figures? A: Yes - the headline feeds (excess construction charges, delivery lead times, contract status) are CC BY 4.0: reuse freely with the attribution "Source: Amvia UK Connectivity Data" linked here. The granular regional benchmark cells are published for reference; contact AMVIA to licence reuse. Q: How often does the index refresh? A: When a new dated set publishes upstream. Published sets are immutable - a dated statistic never changes; corrections ship as a new dated set, so any figure you cite stays verifiable at its as-of date. Q: Why do sample sizes differ between cells? A: Every cell reports its own n. Cells with fewer than 5 underlying records are suppressed or rolled up to a wider grouping, and the cell’s note says when that has happened. --- # Connectivity Pricing Index Methodology: How the Corpus Works URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/methodology Last updated: 2026-08-08 Every statistic in the UK Business Connectivity Pricing Index is an aggregate over at least 5 underlying records from AMVIA’s trading corpus, published in immutable dated sets (current: 2026-08-08, method v1.0.0) with sample size and as-of date on every figure. No customer identifiers and no supplier buy-side prices are ever published. ## Where the data comes from The corpus is AMVIA’s own trading history: site-deduplicated tracker records, priced email threads, provisioning records and billing truth, accumulated across a decade of UK business connectivity trading. Each published feed states its basis verbatim - for example the ECC feed’s quoted-amount statistics are built from “site-deduped tracker records + priced email threads, pooled” and the contract-status snapshot is anchored on “billed_from_anchor”. ## Privacy and confidentiality No customer identity, no supplier buy price and no row-level record appears in any published artifact - enforced in the publishing code, not by editorial care. Every cell aggregates at least 5 underlying entities; cells that cannot meet that threshold are suppressed outright or rolled up to a wider grouping, and rolled-up cells carry a note saying exactly that. ## Quoted vs transacted Price cells state their view. The current set publishes the all-quotes view - amounts as quoted to real enquiries - and quoted-market figures are never blended with transacted ones. The ECC incidence figure is explicitly “a floor, not a rate”: it counts distinct sites with an ECC over ethernet provisioning orders, so the true incidence can be higher but not lower. ## Immutability and versioning Sets are dated and immutable: 2026-08-08 will always contain exactly these numbers, verifiable against the published manifest’s checksums. Corrections are published as a new dated set. Definition changes bump the method version (currently v1.0.0), so a cited figure always identifies the rules it was computed under. ## Licensing Headline feeds (ECC, delivery lag, contract status) are licensed CC BY 4.0 - reuse freely with the attribution "Source: Amvia UK Connectivity Data" linked to this index. Regional benchmark cells are published here for reference; contact AMVIA to licence reuse. The index hub is here; the flagship excess construction charges page shows the contract in action. ## Frequently asked questions Q: Why is the ECC incidence a “floor, not a rate”? A: Because it counts distinct sites where an ECC was recorded over 1313 ethernet provisioning orders. ECCs that were quoted but not recorded against a tracked order don’t count towards it - so the published 1.6% (n=21) can understate the true incidence, never overstate it. Q: What happens when a regional sample is too thin? A: The cell is rolled up to a wider grouping (or suppressed), and the published cell carries a note naming the roll-up. Nothing is interpolated and no cell below n=5 is ever published at its own granularity. Q: How would a correction be published? A: As a new dated set. Published sets are immutable - the set you cite today stays byte-identical at its date, verifiable against its manifest checksums. --- # Excess Construction Charges 2026: UK Leased Line ECC Data URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/excess-construction-charges Last updated: 2026-08-08 The median quoted excess construction charge on a UK leased-line order is £2,197, the middle half of quotes run £348–£7,412, and one in ten quoted ECCs reaches £16,000 or more (n=97, AMVIA corpus, as of 2026-08-08). ECCs were recorded on at least 1.6% of ethernet orders - a floor, not a rate. ## What an excess construction charge is An excess construction charge (ECC) is the one-off cost a carrier quotes when connecting your site needs physical build work beyond the standard installation - new duct, road crossings, wayleaves, or distance to the nearest fibre spine. It arrives after survey, often weeks into an order, and it is the single most common reason a leased-line project stalls: the monthly rental was budgeted, the £2,197 median build charge was not. ## What the distribution actually looks like The published corpus data - a distribution we’re not aware of any other UK source publishing - shows a long tail. Half of quoted ECCs land at or under £2,197, and the middle half of quotes run between £348 and £7,412. But the tail is where the danger is: one in ten quoted ECCs reaches £16,000 or more, and the largest quoted amount in the corpus is £79,000. These are quoted amounts on real orders (“site-deduped tracker records + priced email threads, pooled”), not estimates. ## How often ECCs happen Across 1313 ethernet provisioning orders in the corpus, at least 1.6% of sites carried a recorded ECC. That figure is deliberately published as a floor, not a rate - the counting method (see the methodology) can miss ECCs, never invent them. Treat “it probably won’t happen to us” as optimism, not planning. ## How to de-risk an ECC before you commit - Compare every network at the address, not one. ECCs are network-specific: a second carrier with closer fibre can turn a five-figure build into a standard install. That comparison is the job of our leased-line service. - Get the survey before you sign anything else. An ECC quoted after contract puts you negotiating from the wrong side. - Ask about alternative products. Where the build cost is irreducible, FTTP-based circuits or a different bearer can deliver the requirement without the civils. - Budget the tail, not the median. A project that survives a £7,412 charge is planned; one that only survives £2,197 is lucky. ## Frequently asked questions Q: What is a typical excess construction charge in the UK? A: The median quoted ECC on a UK leased-line order is £2,197, with the middle half of quotes between £348 and £7,412 (n=97, AMVIA corpus, as of 2026-08-08). One in ten quoted ECCs reaches £16,000 or more. Q: How often do leased-line orders get an ECC? A: At least 1.6% of ethernet orders in the corpus carried a recorded ECC (n=21 sites over 1313 orders). The figure is a floor, not a rate - the true incidence can be higher. Q: Can an excess construction charge be avoided? A: Often, yes - ECCs are network-specific, so comparing every carrier at the exact address is the single most effective control. Where build cost is genuinely irreducible, alternative products (FTTP-based circuits, different bearers) can meet the requirement without the civils. Q: Who sets the ECC - the provider or the carrier? A: The network carrier doing the build sets it, after survey; your provider passes it through. That is why the same site can get radically different ECCs from different networks - and why a network-agnostic comparison protects you. --- # UK Business Connectivity Report 2026: Delivery, Contracts & Prices URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/2026 Last updated: 2026-08-08 In the 2026 set of the UK Business Connectivity Pricing Index (2026-08-08): the median 1Gbps leased-line order went live in 78 days in 2023–25 (n=101), 58.4% of currently-billed circuits are past their contract end (n=1,338), and the median quoted excess construction charge is £2,197 (n=97). ## Three findings that should change buying behaviour 1. Delivery time is a planning number, not a footnote. The pooled series shows 2020–22 as the slow era - a median of 128 days across all bands (n=45), against 84 days in 2016–19 (n=24). In 2023–25 the feed publishes by speed band: the dominant 1Gbps band ran a 78-day median (n=101), but one in ten 1Gbps orders still took 348 days or longer. The planning consequence is blunt: order the circuit when the lease is signed, not when the fit-out finishes, and treat the p90 as your contingency. 2. More than half the live base is out of contract. 58.4% of currently-billed circuits (781 of 1,338) are past their contract end - past the point where a re-sign or re-tender typically prices sharper. If you don’t know your circuit’s contract end date, that statistic is probably about you. 3. The ECC tail is the project risk. Half of quoted excess construction charges sit at or under £2,197 - but one in ten reaches £16,000 or more. The full distribution and the de-risking playbook are on the ECC page. ## Regional 100Mbps benchmarks Two regional cuts, published and rendered separately so quoted-market and won-business figures are never conflated: the all_quotes view (every quote issued) and the won_only view (quotes that converted). Regions whose samples were too thin for their own cell carry the UK-wide roll-up, marked in the tables, per the methodology. ## Reading and reusing this report Headline feeds (ECC, delivery lag, contract status) are licensed CC BY 4.0 - reuse freely with the attribution "Source: Amvia UK Connectivity Data" linked to this index. Regional benchmark cells are published here for reference; contact AMVIA to licence reuse. Cite any figure with its as-of date (2026-08-08) and sample size - both are printed beside every number on this page. ## Frequently asked questions Q: How long does a leased line take to install in 2026? A: For the dominant 1Gbps band, the corpus median is 78 days from order to live in 2023–25 (n=101), with one in ten orders taking 348 days or longer; thinner bands and earlier eras run slower (2020–22 pooled median: 128 days). Order early and treat the p90 as your contingency. Q: What share of UK business circuits are out of contract? A: In the corpus live-book snapshot, 58.4% of currently-billed circuits are past their contract end (781 of 1,338, as of 2026-08-08) - past the point where a renewal typically prices sharper. Q: What does a 100Mbps leased line cost by region? A: The regional table on this page publishes the quoted-amount distribution per region (all terms pooled, as of 2026-08-08). AMVIA’s own entry pricing is from £69/month for 100Mbps - the benchmark cells show what the wider quoted market looks like around that. --- # East Midlands Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/east-midlands Last updated: 2026-08-08 In East Midlands, the median monthly amount quoted for a 100Mbps business leased line is £227 across all terms (n=8, all-quotes view, as of 2026-08-08). ## How to read the East Midlands tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a East Midlands sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Nottingham, Leicester. --- # East of England Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/east-of-england Last updated: 2026-08-08 In East of England, the median monthly amount quoted for a 100Mbps business leased line is £321 across all terms (n=6, all-quotes view, as of 2026-08-08). ## How to read the East of England tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a East of England sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Peterborough. --- # London Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/london Last updated: 2026-08-08 In London, the median monthly amount quoted for a 100Mbps business leased line is £311 across all terms (n=34, all-quotes view, as of 2026-08-08). ## How to read the London tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a London sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: London. --- # North East Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/north-east Last updated: 2026-08-08 For North East, thin regional samples mean several cells carry the UK-wide roll-up - the tables below mark exactly which (set 2026-08-08). ## How to read the North East tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a North East sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Newcastle. --- # North West Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/north-west Last updated: 2026-08-08 In North West, the median monthly amount quoted for a 100Mbps business leased line is £157 across all terms (n=10, all-quotes view, as of 2026-08-08). ## How to read the North West tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a North West sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Manchester, Liverpool. --- # Scotland Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/scotland Last updated: 2026-08-08 In Scotland, the median monthly amount quoted for a 100Mbps business leased line is £279 across all terms (n=9, all-quotes view, as of 2026-08-08). ## How to read the Scotland tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a Scotland sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Edinburgh, Glasgow, Aberdeen. --- # South East Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/south-east Last updated: 2026-08-08 In South East, the median monthly amount quoted for a 100Mbps business leased line is £287 across all terms (n=24, all-quotes view, as of 2026-08-08). ## How to read the South East tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a South East sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Milton Keynes, Southampton. --- # South West Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/south-west Last updated: 2026-08-08 In South West, the median monthly amount quoted for a 100Mbps business leased line is £349 across all terms (n=6, all-quotes view, as of 2026-08-08). ## How to read the South West tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a South West sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Bristol. --- # Wales Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/wales Last updated: 2026-08-08 For Wales, thin regional samples mean several cells carry the UK-wide roll-up - the tables below mark exactly which (set 2026-08-08). ## How to read the Wales tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a Wales sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Cardiff. --- # West Midlands Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/west-midlands Last updated: 2026-08-08 In West Midlands, the median monthly amount quoted for a 100Mbps business leased line is £271 across all terms (n=9, all-quotes view, as of 2026-08-08). ## How to read the West Midlands tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a West Midlands sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Birmingham, Coventry. --- # Yorkshire and the Humber Leased Line Prices 2026: Corpus Benchmarks URL: https://amvia.co.uk/research/uk-business-connectivity-pricing-index/yorkshire-and-the-humber Last updated: 2026-08-08 In Yorkshire and the Humber, the median monthly amount quoted for a 100Mbps business leased line is £289 across all terms (n=21, all-quotes view, as of 2026-08-08). ## How to read the Yorkshire and the Humber tables Cells are quoted monthly amounts from real enquiries in the AMVIA corpus, split by speed band and contract term. The two views are published separately and never blended: all_quotes covers every quote issued; won_only covers quotes that converted. Rows marked * had too thin a Yorkshire and the Humber sample at that granularity, so the feed publishes the UK-wide cell in their place - the methodology explains the roll-up rule. Benchmarks tell you the market; they don’t price your building. Availability, network reach and build cost are address-specific - the excess construction charge data shows how wide that address-level variance runs. City-level service pages in this region: Sheffield, Leeds, York. --- # Business VoIP Systems | UK Hosted Telephony from £5.95/user URL: https://amvia.co.uk/business-voip Last updated: 2026-03 Business VoIP routes your company's calls over the internet instead of copper phone lines, replacing on-site exchanges with a cloud-managed phone system. AMVIA designs, migrates and manages hosted VoIP for UK businesses - desk phones, softphones and Microsoft Teams calling - from one security-first, Microsoft-certified provider. This is the hub for everything VoIP. Below, work through how it works, what it costs, how it compares to legacy ISDN, and which path fits your business - then drill into the detailed pages on hosted phone systems, Microsoft Teams Direct Routing and the PSTN switch-off migration. ## What is business VoIP and how does it work? Business VoIP (Voice over Internet Protocol) carries phone calls as data over your broadband or leased line rather than over the traditional copper telephone network. A cloud platform replaces the physical PBX, so calls, voicemail and routing all run in software you manage through a web portal. Because the exchange lives in a data centre, features that used to need extra hardware come as standard: - Auto-attendant and IVR call menus - Call recording for compliance - Hunt groups, call queuing and voicemail-to-email - Desk phone, softphone and mobile-app calling on one number - Provisioning of new users in minutes, not site visits For the underlying technology and call-quality guidance, Microsoft documents its cloud calling stack in detail on Microsoft Learn. ## Why do UK SMEs need to move to VoIP now? The analogue phone network is being switched off. The old PSTN and ISDN lines that carried UK business calls for decades are being retired as Openreach migrates every line to all-IP, with stop-sell orders on new PSTN and ISDN lines already in force. Any business still on a legacy line needs a migration plan. The switch-off completion deadline is 31 January 2027, confirmed by the UK telecoms regulator Ofcom. Many businesses have already been shifted onto basic "Digital Voice" products that are not equivalent to a full hosted VoIP system - they replace the line but not the phone system. Moving deliberately, rather than being defaulted onto a cut-down product, protects your numbers, your features and your call quality. Treat the migration as a security project as well as a telephony one - voice traffic carries sensitive data, which is why we cover hardening on our VoIP security page in line with NCSC guidance. ## VoIP vs traditional ISDN landlines: how do they compare? VoIP removes per-channel line rental and bundles enterprise features that ISDN charged extra for. The headline difference is cost and flexibility: lines provision in minutes through a portal instead of waiting on physical installation. | | Category | ISDN (legacy) | Business VoIP | Line rental | £25–£50 per channel per month | Typically zero | International calls | Per-minute retail rates | Inclusive minutes or lower rates | Features | Require additional hardware | Standard (call recording, auto-attendant, IVR, call queuing) | Scalability | Requires physical line and hardware | Provisioned in minutes via web portal | Remote working | Limited | Works on any internet-connected device AMVIA customers typically cut phone bills by up to 70% versus traditional ISDN line rental - a typical 2026 saving - while gaining features ISDN never offered. ## Is Microsoft Teams the same as business VoIP? Not on its own. Microsoft Teams includes chat, video and file sharing but does not include PSTN calling by default - it cannot dial or receive normal phone numbers until you add a calling capability. There are two routes, and the right one depends on call volume and number flexibility. | | Option | How it works | Best for | Teams Direct Routing | Connects Teams to a SIP trunk for calls to any UK or international number | Businesses wanting flexibility and lower per-user cost | Microsoft Calling Plans | Microsoft supplies the minutes; simpler to set up | Smaller teams wanting an all-Microsoft bill Teams Phone is a serious, widely adopted enterprise phone platform - not a video add-on. AMVIA adds dialling through Direct Routing or a dedicated SIP trunk, connecting your Microsoft 365 environment straight to the telephone network. ## What internet speed do you need for VoIP? Each concurrent VoIP call needs roughly 100 kbps of symmetrical bandwidth - a standard 2026 codec planning figure - so ten simultaneous callers need around 1 Mbps reserved for voice. That is modest, but it must be consistent - jitter and packet loss, not raw speed, are what break calls. For 20+ concurrent calls or guaranteed quality, a leased line gives uncontended, symmetric bandwidth and predictable latency. Businesses running high call volumes alongside cloud apps should size connectivity deliberately, and our multi-site VoIP page covers routing across locations. ## What does business VoIP cost? Every business specs differently - call recording, Teams routing, compliance storage, handsets - so we publish honest per-user ranges instead of a teaser rate that doubles at quote stage. Essentials starts from £5.95/user/month (unlimited UK calls, apps, auto-attendant); Business typically runs £10–£14/user, adding call recording, Microsoft Teams and CRM integration and multi-site support; Complete typically runs £15–£20/user with compliant call storage, full Teams Direct Routing and advanced analytics. The UK market norm for hosted VoIP is £12–£20/user, so even the mid tier undercuts most rate cards. What moves you within a range, stated plainly: call-recording retention and compliance level, Teams Direct Routing versus app-only calling, number of sites, handset choice (rental or purchase, typically £50–£150 per IP handset), and contract term. Number porting is typically included. See the full breakdown in our VoIP cost guide. A worked example: a typical 15-user business on the Business tier lands around £150–£210/month with UK calls included. The equivalent ISDN setup costs £25–£50 per channel in line rental before a single call charge - and those lines stop working on 31 January 2027 regardless. The maths and the deadline point the same way. ## Which VoIP setup fits your business size? The right architecture scales with headcount and compliance needs. Smaller teams want simplicity; larger SMEs need routing, recording and integration. - Small businesses (5–25 staff): simple hosted VoIP with auto-attendant, voicemail-to-email and mobile-app calling. Teams Direct Routing is often most cost-effective if you already run Microsoft 365. - Mid-market (25–100 staff): multi-site routing, call recording for compliance, CRM integration and call queuing. A dedicated cloud PBX with a management portal is the usual fit. - Larger SMEs (100–500 staff): high call volumes need capacity planning, advanced IVR and call-centre features. AMVIA designs bespoke VoIP architectures and can deliver them as part of a wider UCaaS platform. ## Frequently asked questions Q: What does AMVIA business VoIP cost per user per month? A: AMVIA hosted business VoIP starts from £5.95 per user/month, against legacy ISDN line rental of £25–£50 per channel per month. Your exact rate depends on user count, calling plans and whether you want physical handsets - softphone apps for laptops and mobiles are typically included. Q: Do I have to move to VoIP before the PSTN switch-off? A: Yes - the PSTN and ISDN networks are retired on 31 January 2027, after which analogue phone lines stop working. Migrating early avoids the engineer bottleneck near the deadline and gives you time to port numbers properly rather than under pressure. Q: Can I keep my business phone numbers when switching to VoIP? A: Yes. Numbers port to the new platform in typically 5–15 working days. The golden rule: port the numbers before ceasing the old lines, never after - done in that order, callers never notice the change. Q: Does VoIP work with Microsoft Teams? A: Yes - via Teams calling plans or direct routing, which turns Teams into your phone system with your business numbers. Whether that's cheaper than a standalone VoIP platform depends on your Microsoft licensing, so it's worth modelling both ways before committing. Q: What internet connection do I need for VoIP? A: Call quality is a bandwidth question: business-grade broadband carries VoIP well for most smaller teams, but on contended lines at peak times, calls degrade first. Where phones are business-critical, an uncontended leased line with guaranteed bandwidth is the safer platform - which is why AMVIA quotes telephony and connectivity together. --- # Business VoIP Cost UK 2026: From £5.95/User/Month URL: https://amvia.co.uk/business-voip/business-voip-cost Last updated: 2026-07 What business VoIP really costs: from £5.95/user/month vs the UK market's £12–£20, against ISDN at £25–£50/channel. What moves the bill, provider entry prices compared, and the 2027 switch-off budget. ## The honest way to price business VoIP Start with what you're leaving, not what you're buying. Legacy ISDN runs £25–£50 per channel per month, and an on-premises PBX for a 20-user office represents £5,000–£15,000 in hardware before maintenance. Hosted VoIP replaces both with per-user pricing - from £5.95 per user/month with AMVIA, or £12–£20 across mainstream UK managed platforms - with no switch hardware to own and numbers that cost less than landline equivalents to run. ## The 2027 deadline changes the question The PSTN and ISDN switch-off completes on 31 January 2027, so for businesses still on analogue or ISDN the question isn't whether to move - it's when, and to what. Migrating early avoids the engineer bottleneck as the deadline approaches, and the sequence matters: choose the platform, port the numbers (5–15 working days), then cease the legacy lines - never the other way round. Our PSTN switch-off guide covers the timeline in full. ## Comparing providers on more than the headline rate Entry pricing across the UK market clusters tightly (8x8 from £12, Vonage from £14, RingCentral from £15, BT from £16, AMVIA from £5.95), so the real comparison is what the rate includes: calling plans, mobile apps, Teams integration, support quality and contract terms. Our UK provider comparison puts the big names side by side - and the case for AMVIA is the same one that runs through everything we do: the phones, the connectivity they run on, and the support sit with one accountable provider. See hosted phone systems for what the platform includes. ## Don't price the phones without the connection Call quality is a bandwidth question before it's a platform question. VoIP on contended broadband at peak times is where dropped-call complaints come from - which is why we quote telephony and connectivity together. For most offices that means business-grade broadband; where phones are business-critical, a leased line with guaranteed bandwidth is the safer platform. Start with your postcode and we'll price the whole stack. ## Frequently asked questions Q: How much does business VoIP cost per user? A: AMVIA hosted business VoIP starts from £5.95 per user/month, while mainstream UK managed platforms typically run £12–£20 per user (8x8 from £12, Vonage from £14, RingCentral from £15, BT from £16). Your exact rate depends on user count, calling plans and whether you need physical handsets. Q: Is VoIP cheaper than ISDN or landlines? A: Almost always. Legacy ISDN line rental runs £25–£50 per channel per month before call charges, against hosted VoIP from £5.95 per user/month - and the PSTN/ISDN switch-off on 31 January 2027 is retiring the legacy option anyway. The comparison now is between VoIP providers, not VoIP versus staying put. Q: What setup costs should I budget for? A: Hosted VoIP has no PBX hardware to buy - the £5,000–£15,000 capex of an on-premises system for a 20-user office simply disappears. Budget instead for handsets if you want desk phones (softphone apps are typically included), and allow 5–15 working days for number porting during migration. Q: Will we need a dedicated line to run VoIP well? A: Not necessarily - business-grade broadband carries VoIP well for most smaller teams. But call quality is a bandwidth question: on contended broadband at peak times, calls degrade first. Where phones are business-critical, uncontended connectivity with guaranteed bandwidth is the safer platform, which is why we price telephony and connectivity together. Q: Can I keep my business phone numbers? A: Yes - numbers port to the new platform, typically in 5–15 working days. The critical rule during any migration: port the numbers before ceasing the old lines, never after, so there's no gap and no lost numbers. --- # Business Broadband for UK SMEs | Full-Fibre from £29/month URL: https://amvia.co.uk/business-broadband Last updated: 2026-06 Business broadband is a fixed internet connection built for organisations rather than households - prioritised support, static IP options, and stronger reliability than a consumer line. It runs over full fibre (FTTP), part-fibre (FTTC) or copper, and underpins cloud, VoIP and email. AMVIA delivers it security-first, from one accountable provider. For most UK SMEs, broadband is the day-to-day workhorse and a dedicated leased line is the upgrade for heavier, uptime-critical sites. This page explains the connection types, the speeds you actually need, and how AMVIA secures the line - not just supplies it. If you are weighing the two, our leased line vs broadband comparison breaks down the trade-offs in detail. ## What is business broadband and how is it different from home broadband? Business broadband is the same underlying fibre or copper technology as a home connection, but sold with business-grade terms: faster fault response, static IP addresses, business-hours support SLAs, and no traffic-management throttling. The hardware and contract assume the line carries revenue, so reliability and support are prioritised over headline consumer price. The practical differences that matter to a 10–500 staff business: - Support priority: faults are escalated against a business SLA, not a consumer queue. - Static IP: needed to host services, run a VPN, or whitelist access. - Symmetry options: business full fibre can offer faster, more even upload than most home plans. - No fair-use throttling: capacity is provisioned for sustained, all-day use. ## What types of business broadband are available in the UK? UK business broadband comes in four main flavours, defined by how much of the route to your premises is fibre. Full fibre (FTTP) runs fibre all the way to the building; FTTC and G.fast use fibre to the street cabinet and copper for the last stretch; SoGEA is a single-line fibre-to-the-cabinet product without a phone line. More fibre means faster, more stable speeds. | | Type | What it means | Typical download | Best for | FTTP (full fibre) | Fibre to the premises | 100 Mbps–1 Gbps+ | Cloud-heavy SMEs, VoIP, future-proofing | G.fast | Fibre to cabinet, short copper | Up to ~300 Mbps | Sites near the cabinet with no FTTP yet | FTTC | Fibre to cabinet, copper last mile | 30–80 Mbps | Smaller teams, light cloud use | SoGEA | FTTC without a separate phone line | 30–80 Mbps | PSTN-switch-off migrations Availability is postcode-specific. Ofcom reports UK full-fibre coverage is expanding rapidly, but many commercial postcodes still rely on FTTC, so check what your building can actually order. If you want the detail on the part-fibre option, see our guide to FTTC speeds explained or whether full fibre is right for your business. ## How fast does business broadband need to be? Size the connection to concurrent users and what they do, not just headcount. A rough rule: allow 5–10 Mbps of headroom per active user for cloud apps, video calls and file sync, then add margin for VoIP and backups. The UK's average broadband download speed is just 69.4 Mbps (Ofcom, Connected Nations 2024) - fine for a small team, tight for a busy office on Microsoft 365 and Teams. - Under 10 staff, light cloud use: FTTC or entry full fibre (up to ~80 Mbps) is usually enough. - 10–50 staff on Microsoft 365 and VoIP: target 200 Mbps–1 Gbps full fibre. - 50+ staff, heavy uploads, hosted systems: consider a dedicated leased line for symmetric, SLA-backed bandwidth. Upload speed matters as much as download for cloud-first teams. Backups, large file shares and video calls all push data up, where consumer asymmetric plans are weakest. ## Business broadband vs leased line - which does your business need? Broadband is shared (contended) and usually asymmetric with no firm uptime guarantee; a leased line is dedicated, symmetric and SLA-backed but costs more. Choose broadband for cost-efficient connectivity at most sites, and a leased line where downtime directly costs revenue or you need guaranteed upload. | | Factor | Business broadband | Leased line | Bandwidth | Shared / contended | Dedicated / uncontended | Speed profile | Often asymmetric | Symmetric up and down | Uptime SLA | No firm guarantee | Typically 99.9%+ with credits | Install time | Days | 60–90 days | Best fit | Most SME sites | Uptime-critical or upload-heavy sites If you are torn, compare current deals on our business broadband comparison page, and read what BT-network options look like in our BT business broadband breakdown. ## How much does business broadband cost in the UK? Business broadband pricing depends on the technology, speed and your postcode. Entry FTTC and SoGEA packages sit at the lower end; business full fibre rises with committed speed and SLA. Costs are driven by available infrastructure at your building, contract length, the static IP and support tier, and any managed router or security add-ons. Because pricing is so location-dependent, the only reliable figure is a quote for your exact address. AMVIA compares packages across UK carriers so you see the most competitive option for your speed and term, rather than one network's list price. ## How does AMVIA secure your business broadband? A connection is only as useful as it is safe. AMVIA delivers broadband as a managed, security-first service: the line is protected behind the Barracuda firewall suite, endpoints are covered by Microsoft Defender for Business, and the whole estate is run by Microsoft-certified engineers under one accountable contract. One provider. Security-first. Microsoft-certified. That matters because the connection is the front door to your cloud. The NCSC's Small Business Guide stresses securing internet-facing services and keeping routers and firmware patched - work AMVIA handles for you rather than leaving it to chance. Broadband, business VoIP and security sit on one bill, with one team to call. Customers who combine business broadband with managed IT support get one provider and one SLA across connectivity and IT - which is usually cheaper to run and much simpler to support than juggling separate suppliers. ## Frequently asked questions Q: What is business broadband? A: Business broadband is a fixed internet connection sold to organisations with business-grade terms - prioritised fault response, static IP options, business support SLAs and no consumer-style throttling. It runs over full fibre (FTTP), part-fibre (FTTC/G.fast) or copper, and underpins cloud apps, email and VoIP. AMVIA supplies and secures it as one managed service. Q: What is the difference between FTTP and FTTC? A: FTTP (fibre to the premises) runs fibre all the way to your building, delivering faster, more stable speeds up to 1 Gbps and beyond. FTTC (fibre to the cabinet) uses fibre to the street cabinet then copper for the last stretch, capping most lines at 30–80 Mbps. More fibre in the route means more reliable performance. Q: Is business broadband faster than home broadband? A: Not necessarily faster in raw speed - they often use the same fibre - but business broadband is more reliable in practice. It comes with priority fault repair, static IP addresses, a business support SLA and no fair-use throttling, so a busy office gets consistent all-day performance rather than a connection tuned for an evening at home. Q: Do I need business broadband or a leased line? A: Business broadband suits most SME sites and is far cheaper. Choose a leased line once downtime directly costs revenue, you need guaranteed symmetric upload, or you host systems clients depend on. Broadband is shared and unguaranteed; a leased line is dedicated and SLA-backed. Many businesses run broadband with a leased line at their busiest site. Q: How secure is business broadband? A: Broadband itself is just transport - security depends on what protects it. AMVIA wraps the line in the Barracuda firewall suite and covers endpoints with Microsoft Defender for Business, managed by certified engineers. Following NCSC guidance, we keep routers patched and internet-facing services locked down, so the connection is a managed asset, not an open door. Q: How fast should my business broadband be? A: Size it to concurrent users, not headcount. Allow 5–10 Mbps of headroom per active user for cloud, video and file sync, then add margin for VoIP and backups. Under 10 staff with light usage are fine on FTTC; a 10–50 person team on Microsoft 365 and Teams should target 200 Mbps–1 Gbps full fibre. --- # FTTP for Business: Full-Fibre Broadband Explained (2026) URL: https://amvia.co.uk/business-broadband/fttp-for-business Last updated: 2026-07 Full fibre runs all the way to your building - no copper final mile. FTTP availability (25M premises committed by end 2026), FTTP on Demand costs, business pricing from £29/month, and when a leased line beats it. ## What makes FTTP different from the broadband you probably have? Most UK business broadband is still FTTC - fibre to the street cabinet, copper for the final stretch - which caps real-world speeds at roughly 40–80Mbps down and 8–20Mbps up, degrading with distance from the cabinet. FTTP removes the copper entirely: fibre runs into your building, supporting 100Mbps to 1Gbps+ with far more consistent performance. For businesses still on ageing copper tiers, the upgrade is often overdue. ## Can your business actually get FTTP? Availability is the whole question. Openreach had passed more than 16 million premises with full fibre by early 2026 and has committed to 25 million by the end of 2026, while alt-nets like CityFibre add coverage in their build cities - but availability remains address-by-address. A postcode check against live availability data across both Openreach and CityFibre takes a minute and settles it; our Openreach fibre checker guide explains how the checkers work and what the results mean. ## What if FTTP hasn't reached your building yet? Openreach offers FTTP on Demand (FTTPoD) - building fibre to your premises on request. The economics depend almost entirely on distance to the existing network: within 100m the construction charge is typically £0, 100–500m runs £500–£3,000, 500m–1km £3,000–£10,000+, and beyond 1km costs escalate past £10,000. Lead times run 3–4 months for simple builds and 6–12+ months for complex ones. Beyond roughly 500m, it's usually worth comparing a full leased line instead - the install economics converge and you gain an SLA. ## When FTTP isn't enough: the leased line question FTTP is still broadband: contended (shared with other premises), usually asymmetric, and best-effort - no guaranteed speeds, no fix-time commitment. For teams that live on cloud apps, VoIP and uploads, the question isn't FTTP vs FTTC, it's broadband vs dedicated. A leased line delivers symmetric, uncontended bandwidth with a 99.99% SLA from £69/month for 100Mbps - see the full comparison for when each wins. ## What does business FTTP cost? Entry business FTTP starts from £29/month (80/20 Mbps with a static IP), with faster full-fibre tiers priced by speed and postcode. The full breakdown - by technology, and against the leased-line upgrade path - is in our business broadband cost guide. ## Frequently asked questions Q: What is FTTP and how is it different from FTTC? A: FTTP (Fibre to the Premises) runs fibre all the way into your building, supporting 100Mbps to 1Gbps+ speeds. FTTC (Fibre to the Cabinet) uses copper for the final stretch, capping speeds at roughly 40–80Mbps down and 8–20Mbps up, and degrading with distance from the cabinet. Same word - fibre - very different products. Q: Is FTTP available at my business address? A: Openreach had passed over 16 million UK premises with full fibre by early 2026 and has committed to 25 million by the end of 2026, with alt-nets like CityFibre adding city coverage - but availability is address-by-address. A live postcode check across both networks settles it in under a minute. Q: How much does business FTTP cost? A: Entry business FTTP starts from £29/month for 80/20 Mbps with a static IP. Faster full-fibre tiers are priced by speed and postcode. That's substantially cheaper than a dedicated line - but with no SLA or guaranteed speeds in exchange. Q: What is FTTP on Demand and what does it cost? A: FTTPoD is Openreach building fibre to your premises on request where FTTP hasn't arrived. Construction charges scale with distance: typically £0 within 100m, £500–£3,000 for 100–500m, £3,000–£10,000+ for 500m–1km, and £10,000+ beyond that, with 3–12+ month lead times. Past roughly 500m, compare a leased line instead. Q: Is FTTP good enough for VoIP and video calls? A: Usually, for smaller teams - but FTTP is still contended, best-effort broadband with no fix-time guarantee. If dropped calls cost you customers or your team can't work offline, a leased line's symmetric, SLA-backed bandwidth (from £69/month for 100Mbps) is the safer platform for voice. --- # Best FTTP Providers for UK Business 2026: Full Fibre Compared URL: https://amvia.co.uk/business-broadband/compare/fttp-providers Last updated: 2026-09 The best FTTP provider is the one whose fibre actually reaches your postcode. BT and Vodafone resell Openreach full fibre (20M+ premises passed) with the widest reach; Virgin Media Business runs its own independent network; CityFibre and altnets like Hyperoptic, Toob and Netomnia are frequently cheapest where they've built. Business FTTP starts from £29/month - a multi-network check at your exact address beats any single provider's rate card. Ask who the "best FTTP provider" is and you'll get a brand name. The more useful question is which networks have built fibre to your street - because the provider on the invoice and the fibre in the ground are usually different companies, and the price for the same speed can vary significantly between postcodes two streets apart. This comparison sets out how the UK full fibre market actually fits together, using the same postcode-first logic as our business broadband hub. ## How the UK FTTP market is actually structured Three layers matter. First, the network builders: Openreach (BT's access network, 20M+ premises passed as of September 2025 and 25 million committed by the end of 2026), Virgin Media's independent cable-and-fibre estate, and the altnets - CityFibre across 60+ towns and cities, plus direct-sell builders like Hyperoptic, Toob and Netomnia. Second, the ISPs who sell service over that fibre: BT, Vodafone, Zen, TalkTalk Business and dozens more compete over the same Openreach and CityFibre infrastructure. Third, the product wrapper - the same fibre sold as a consumer package (no SLA) or a business package (static IP, defined fault response, business support). Full fibre now reaches 78% of UK premises (Ofcom, Q3 2025), driven by Openreach's build and the government's Project Gigabit programme. The practical consequence of all this overlap: the same 1Gbps service to the same building carries several different prices depending on who sells it and whose network it rides. ## Where each provider is strong BT Business is the coverage-and-certainty play: the whole Openreach footprint, enhanced SLA options, static IPs - at pricing that sits toward the top of the market. Vodafone Business rides the same Openreach fibre at sharper rates and bundles mobile. Virgin Media Business runs its own network, which makes it both a competitor and a resilience option - an Openreach fault can't take out a Virgin line, though DOCSIS cable upload trails pure FTTP. CityFibre wholesales modern symmetric fibre through partners (Vodafone, Zen, TalkTalk Business among them), and where it's live, partner competition frequently produces the sharpest price in the market. Zen Internet - selling over both Openreach and CityFibre - consistently tops SME satisfaction surveys and is the pick when support quality weighs as heavily as price. Hyperoptic, Toob and Netomnia sell direct within their own build areas, usually aggressively. ## The FTTP providers, one by one ## BT Business Sells across the entire Openreach footprint with enhanced SLA options and static IPs on business tiers. The certainty play: recognised support structure, national reach, no surprises - at pricing that sits toward the top of the market. Where CityFibre or an altnet has also built to your street, you can usually beat BT's rate for the same speed. ## Vodafone Business The same Openreach fibre at sharper prices, CityFibre in its footprints, and mobile bundling if you want fixed and mobile under one provider. Regularly the value pick among the national brands for standard business FTTP tiers. ## Zen Internet Sells over both Openreach and CityFibre and consistently tops SME support surveys - the pick when the quality of the people answering the phone weighs as heavily as the monthly price. ## TalkTalk Business Openreach and CityFibre underneath, keen pricing on top, and a long-established wholesale operation. Shortlist it for price competition on standard tiers. ## Virgin Media Business Its own network, independent of Openreach - which makes it both a competitor and the natural resilience pairing, since an Openreach fault can't touch a Virgin line. Gig1 reaches 1Gbps download; confirm the upload figure before committing, because DOCSIS cable uploads trail pure FTTP. ## CityFibre partner ISPs CityFibre doesn't sell direct - Vodafone, Zen, TalkTalk Business and others sell over its fibre across 60+ towns and cities. Where it's live, partner competition frequently produces the sharpest price in the market on modern symmetric fibre. ## Hyperoptic, Toob and Netomnia Direct-sell altnet builders, usually priced aggressively inside their own footprints. Coverage is postcode-specific: excellent if they've built to your street, irrelevant if they haven't. Whichever you choose, buy the business package rather than the consumer one if the connection earns you money. ## What to compare beyond the headline price - Upload speed: FTTP is near-symmetrical; cable is not. If you push backups, video or VoIP upstream, the upload figure matters more than the download. - SLA: business packages carry defined fault response; consumer packages owe you nothing. Check the repair commitment, not just the uptime claim. - Static IP: required for VPNs, hosting and IP whitelisting - included on most business packages, an add-on elsewhere. - Contract length: 24–36 months is standard; shorter terms cost more. - Network diversity: if you're pairing a backup line with a leased line, put it on a physically different network. ## Why comparing networks beats choosing a brand Business FTTP starts from £29/month, but each ISP prices from where its network already runs relative to your building - so provider league tables are close to meaningless at the level of a single postcode. The brand that wins on your street may lose two streets away - the UK Business Connectivity Pricing Index publishes the quoted-price distributions from live market data that show exactly how wide that spread runs. A network-agnostic check queries every builder with fibre near your premises and surfaces the real choice: which networks can serve you, at what price, with what SLA. And when the honest answer is that shared FTTP isn't enough - downtime costs you real money, or you need guaranteed symmetrical throughput - the right product is a leased line rather than broadband, with dedicated 100Mbps from £69/month and 1Gbps from £129/month. ## Frequently asked questions Q: Who is the best FTTP provider in the UK? A: There is no universal best - it depends on which networks have built to your postcode. BT and Vodafone offer the widest reach over Openreach full fibre (20M+ premises passed), Virgin Media Business runs its own independent network, and altnets like CityFibre partners, Hyperoptic, Toob and Netomnia are frequently cheapest inside their footprints. Zen Internet consistently tops SME support surveys. Check coverage at your exact address first, then compare the providers that can actually serve you. Q: What is the difference between an FTTP network and an FTTP provider? A: The network is the physical fibre in the ground - Openreach, Virgin, CityFibre, or an altnet build. The provider (ISP) is who sells you service over it and answers the phone when it breaks. Dozens of ISPs sell over the same Openreach fibre at different prices and SLAs, and CityFibre can only be bought through partner ISPs. That's why comparing providers without knowing the underlying network misses half the picture. Q: How much does business FTTP cost in 2026? A: Business FTTP starts from £29/month for an 80/20 full-fibre service with a static IP, rising with speed tier. Gigabit packages vary most by location: postcodes with CityFibre or altnet competition price noticeably below Openreach-only areas. A leased line - dedicated rather than shared - starts from £69/month for 100Mbps and £129/month for 1Gbps if you need guaranteed speeds and a repair SLA. Q: Can I get FTTP at my business address? A: Full fibre now reaches 78% of UK premises (Ofcom, Q3 2025), so the odds are good - but footprints overlap unevenly. Openreach passes 20M+ premises, Virgin covers most urban areas, and altnet builds are postcode-specific. Coverage maps are approximate; the only reliable answer is a live check of every network against your exact address, which is what AMVIA runs for each enquiry. Q: Is business FTTP different from home FTTP? A: The fibre is identical - the product wrapper isn't. Business FTTP packages add a static IP (needed for VPNs, hosting and IP whitelisting), defined fault-response commitments, and business-hours support with escalation. Consumer FTTP usually carries no SLA at all: if it breaks on Monday, nobody owes you a fix by Tuesday. For any premises where the connection earns money, the business wrapper is worth the modest premium. Q: Should I choose FTTP or a leased line for my business? A: FTTP is shared, best-efforts bandwidth; a leased line is dedicated and guaranteed. Most cloud-first SMEs run happily on business FTTP at a fraction of the cost. Choose a leased line when downtime carries material cost, you need symmetrical guaranteed throughput, or a financially backed repair SLA matters - dedicated 100Mbps starts from £69/month. Many businesses pair the two: leased line primary, FTTP backup on a separate network. Q: Who actually installs business FTTP - the ISP or the network builder? A: The network builder's engineers install the fibre: Openreach for BT, Vodafone, Zen and other Openreach-based ISPs; CityFibre's build teams for its partner ISPs; the altnet's own engineers for direct-sell builders like Hyperoptic. Your ISP owns the order, the router and the ongoing support relationship. That split is why install experiences feel similar across ISPs on the same network - and why changing ISP over the same fibre is usually quick once it's in. Q: Which FTTP provider has the best coverage? A: Openreach-based ISPs - BT, Vodafone, Zen and dozens of others - share the widest footprint: 20M+ premises passed as of September 2025, with 25 million committed by the end of 2026, including rural areas no altnet will reach. Virgin Media Business covers most urban and suburban areas on its own network; CityFibre and the altnets are city-and-town specific. Coverage league tables don't decide your options, though - only a check of every network against your exact address does. Q: Are altnet FTTP providers reliable enough for business use? A: The fibre itself is typically newer than the incumbents' - modern, symmetric networks built this decade. The real differences are commercial: support hours, fault-response commitments and static IP provision vary by provider and package. On any network, buy the business wrapper rather than the consumer one, and if downtime carries real cost, pair two physically separate networks or step up to a leased line with a repair SLA. --- # SoGEA Broadband Explained: Costs, Speeds & the 2027 Switch-Off URL: https://amvia.co.uk/business-broadband/sogea Last updated: 2026-07 SoGEA (Single Order Generic Ethernet Access) is broadband without a phone line - the same ~80Mbps as FTTC, minus £10–£15/month line rental, and switch-off ready. SoGEA vs FTTC vs FTTP, costs, and who should choose it. ## Why does SoGEA exist? Historically, broadband over copper required an active phone line underneath it - you paid line rental whether or not anyone used the phone. SoGEA breaks that link: one order, one line, broadband only. The timing matters because the analogue phone network it replaced is being retired: the PSTN and ISDN switch-off completes on 31 January 2027, and PSTN lines still account for 19% of UK landline connections - down from 27% in 2024 (Ofcom Connected Nations 2025). Everyone on FTTC-with-phone-line eventually needs to make this move. ## What is SoGEA, exactly? SoGEA stands for Single Order Generic Ethernet Access - an Openreach product that delivers VDSL broadband over the copper-and-fibre access network without an underlying analogue phone service. Technically it is the same connection as FTTC (fibre to the cabinet, copper to your premises, up to around 80Mbps down / 20Mbps up); commercially it is one order and one bill, with no line rental for a phone line nobody uses. Every UK provider selling SoGEA - AMVIA included - is reselling that same Openreach product, which is why availability at your postcode matters far more than the logo on the router. ## SoGEA vs FTTC vs FTTP | | | SoGEA | FTTC | FTTP (full fibre) | What it is | FTTC broadband without the phone line | Fibre to the cabinet + copper, with an analogue line underneath | Fibre all the way to your premises | Typical top speed | ~80Mbps down / 20Mbps up | ~80Mbps down / 20Mbps up | 115Mbps to 1Gbps+ (symmetric options on business products) | Phone line required | No | Yes - being retired January 2027 | No | Survives the PSTN switch-off | Yes | No - must migrate | Yes | Long-term future | Transitional - copper is being retired as full fibre arrives | End of life | The end state The honest summary: SoGEA is a bridge, not a destination. It exists so businesses in areas where full fibre hasn’t arrived can get off the analogue network before January 2027 without waiting for an FTTP build. If FTTP is already available at your postcode, order that instead - it is faster, more reliable, and it is where Openreach is heading anyway. Check with our Openreach fibre checker, or see our business broadband page for the full-fibre options from £29/month. ## How much does SoGEA cost? SoGEA business packages are typically priced close to the FTTC service they replace, minus the £10–£15 a month of line rental that disappears - which is why like-for-like migrations often cost less than the setup they retire. AMVIA’s business SoGEA pricing starts from £29/month - the same entry floor as our full-fibre business broadband - spec-dependent as with everything we publish, with the exact figure confirmed against your postcode at quotation. And that price parity is the point: where FTTP is available at your address for the same money, take the fibre. ## Who is business SoGEA right for? Three situations, in practice. No FTTP at your postcode yet: SoGEA is the way off the analogue network without waiting for the fibre build to reach you. Analogue services still in the building: phone lines, alarm lines, door entry and card machines riding on copper pairs need a migration plan before January 2027, and SoGEA plus VoIP is the standard answer where fibre isn’t an option. Multi-site estates: branches in FTTP areas go straight to fibre; branches outside them take SoGEA - one provider managing both keeps the estate on a single migration plan. Voice moves to hosted VoIP in every case; your numbers port over and the cloud phone system replaces what the copper line did. ## What speeds does SoGEA deliver? SoGEA uses the same fibre-to-the-cabinet infrastructure as FTTC: up to 80Mbps down and 20Mbps up, with real-world speeds depending on your distance from the cabinet. It's the right product where full fibre hasn't arrived yet - where FTTP is available (100Mbps–1Gbps+), FTTP is almost always the better order for the same reasons at similar money. ## What happens to your phone numbers? Voice moves to hosted VoIP running over the broadband - typically £5.95–£20 per user/month, with your existing numbers ported across (allow 5–15 working days for porting). Done properly, the combined SoGEA + VoIP bill is usually lower than the old broadband + line rental + phone system stack, and the phones gain mobile apps, Teams integration and call routing the analogue line never had. See business VoIP for how AMVIA runs the voice side. ## The bottom line for the 2027 switch-off Don't wait for the deadline: engineer availability tightens as it approaches, and a rushed migration is how numbers get lost. The sequence that works: check what your postcode supports (SoGEA or FTTP), order the data line, port the numbers to VoIP, then cease the analogue services. AMVIA manages that sequence end to end - see the full PSTN switch-off guide for the timeline and planning detail. ## Frequently asked questions Q: What does SoGEA stand for and what is it? A: Single Order Generic Ethernet Access - broadband delivered over the Openreach network with no phone service attached. One order, one line, data only. You get the same up-to-80/20 Mbps speeds as FTTC without paying £10–£15/month line rental for an analogue phone service. Q: How much does SoGEA save compared with FTTC plus a phone line? A: Removing the line rental typically saves £10–£15 per month - £360–£540 over a standard 36-month term. Voice moves to hosted VoIP at £5.95–£20 per user/month, and the combined bill is usually lower than the old broadband-plus-line-rental-plus-phone-system stack. Q: What happens to my phone number with SoGEA? A: Your numbers port to a hosted VoIP service running over the broadband - allow 5–15 working days for porting. The critical rule: port the numbers before ceasing the old lines, never after, so there's no gap and no lost numbers. Q: Do I have to move before the PSTN switch-off? A: Yes - the PSTN and ISDN networks switch off on 31 January 2027. Anything running on an analogue line (phones, alarms, card terminals) stops working after the switch-off. Migrating early avoids the engineer bottleneck as the deadline approaches. Q: Should I order SoGEA or FTTP? A: If FTTP is available at your address, order FTTP - full fibre at 100Mbps–1Gbps+ beats SoGEA's up-to-80Mbps copper-assisted speeds for similar money. SoGEA is the right answer where full fibre hasn't arrived yet. Either way the phone-line migration is the same. Q: What does SoGEA stand for? A: Single Order Generic Ethernet Access. "Single order" is the point: historically broadband over copper needed an analogue phone line ordered underneath it, with line rental charged for a service many businesses never used. SoGEA delivers the same VDSL broadband as one order with no phone line - voice moves to VoIP over the connection instead. Q: Is SoGEA faster than FTTC? A: No - it is the same underlying technology at the same speeds, typically up to around 80Mbps down and 20Mbps up depending on your line length to the cabinet. The difference is commercial, not technical: no analogue phone line, no line rental, and it survives the January 2027 PSTN switch-off, which FTTC-with-phone-line does not. Q: Should I choose SoGEA or full fibre (FTTP)? A: If FTTP is available at your postcode, choose FTTP - it is faster, more consistent, and it is the network Openreach is migrating everyone to as copper retires. SoGEA is the right answer where full fibre has not arrived yet and the 2027 switch-off deadline will not wait for the build. It is a transition product, and a good provider will say so. --- # Business Broadband Cost UK 2026: From £29/Month URL: https://amvia.co.uk/business-broadband/business-broadband-cost Last updated: 2026-07 What business broadband really costs: entry FTTP from £29/month, technologies compared (FTTP, G.fast, FTTC, SoGEA), what moves the price, and the point where a leased line becomes the better spend. ## The honest way to price business broadband The monthly fee is the smallest part of the decision. Business broadband - even full-fibre - is contended and best-effort: no guaranteed speeds, no fix-time commitment. Price it in three steps: first, what your postcode actually supports (FTTP where available, otherwise G.fast, FTTC or SoGEA); second, the speed tier your headcount needs (roughly 5–10Mbps per heavy user); third - and most skipped - what an outage costs you per hour, because that number decides whether broadband is the right product at all. ## Where broadband stops and leased lines start The crossover is sharper than most businesses expect: entry business FTTP is from £29/month, and a dedicated 100Mbps leased line - symmetric, uncontended, 99.99% SLA with service credits - starts from £69/month. For a 20-person office losing one hour a month to broadband problems, the maths favours the leased line quickly. See the full comparison and the 100Mbps cost guide for the numbers side by side. ## Don't forget the 2027 switch-off in the budget Any broadband decision made now should be PSTN-switch-off ready: analogue lines retire on 31 January 2027, so if your current setup includes phone line rental, budget the move to SoGEA or FTTP plus hosted VoIP (typically £5.95–£20 per user/month) as one migration rather than two. The switch-off guide covers sequencing. ## Get an exact figure Because availability decides so much, the only accurate price is a postcode-level check. AMVIA checks Openreach and CityFibre for your exact address, quotes the right tier, and tells you honestly when a leased line is the better spend. Start with your postcode - no obligation. ## Frequently asked questions Q: How much does business broadband cost per month? A: Entry business FTTP starts from £29/month for 80/20 Mbps with a static IP. Faster full-fibre tiers are priced by speed and postcode, while G.fast, FTTC and SoGEA sit at similar entry money with lower speed ceilings. Your postcode determines which technologies - and therefore which price bands - are available. Q: Why is business broadband more expensive than home broadband? A: Business products include a static IP, business-grade support and priority fault handling that consumer lines don't carry. The premium is modest - and a consumer line that can't host a VPN or gets consumer-queue support costs more than it saves the first time something breaks in working hours. Q: Is SoGEA cheaper than FTTC? A: Effectively yes, where you're currently paying line rental: SoGEA delivers the same up-to-80/20 speeds without the £10–£15/month analogue phone line underneath - £360–£540 saved over a 36-month term. Voice moves to hosted VoIP, which the 2027 PSTN switch-off requires anyway. Q: When is a leased line worth the extra cost over broadband? A: When downtime has a real hourly cost. A 100Mbps leased line from £69/month buys symmetric, uncontended bandwidth with a 99.99% SLA and service credits - against entry broadband at £29/month with no guarantees. For most offices past ~10 heavy users, one avoided outage a month covers the gap. Q: What broadband speed does my business actually need? A: Plan on roughly 5–10Mbps per heavy cloud user, then add headroom for VoIP and video. The UK average download of 69.4Mbps (Ofcom Connected Nations 2024) is below what a busy office needs - which is why FTTP tiers of 100Mbps+ have become the business default where available. --- # Cloud Phone System for UK Businesses | Hosted VoIP from £5.95/User URL: https://amvia.co.uk/business-voip/hosted-phone-system Last updated: 2026-03 A hosted phone system is a business phone service delivered entirely from the cloud - calls, voicemail, auto-attendants and call routing all run on a provider's servers instead of a PBX box in your comms cupboard. AMVIA designs, ports, configures and supports the whole thing: one accountable provider, security-first, Microsoft-certified engineers. It is the natural upgrade as the old analogue network is retired, and it sits inside our wider business VoIP service for UK SMEs. ## What is a hosted phone system? A hosted phone system (also called hosted PBX or cloud telephony) gives you every feature of an office phone system - extensions, hunt groups, IVR menus, call recording - without owning any on-site hardware. Your handsets and apps connect over the internet to a platform the provider runs, manages and updates for you. That means no PBX server to maintain, no engineer visits for moves and changes, and the ability to add or remove users in minutes. It is the foundation most UK businesses now choose ahead of the PSTN switch-off. ## What's included in a hosted phone system from AMVIA? Every AMVIA hosted phone system ships with the full enterprise call-handling feature set, configured to match how your business actually answers calls - not a generic default template. You get cloud control over routing, so changes are instant. - Auto-attendant and IVR - route callers to the right team without a receptionist - Hunt groups and call queues - distribute inbound calls and hold callers in order - Voicemail-to-email - voicemails delivered as audio to the inbox - Call recording - all calls, inbound-only, or on-demand, stored securely in the cloud - Softphone and mobile apps - make and take calls from a laptop or smartphone - Number porting - keep your existing geographic and non-geographic numbers Recording can be set up for FCA-regulated firms with tamper-evident storage and searchable archives, which supports FCA compliance for dispute resolution and call-quality review. ## How does AMVIA set up your hosted phone system? AMVIA deploys a hosted phone system in five to ten working days from order, including number porting, handset delivery and user configuration. There is no on-premises server to install, which removes most of the cost and disruption of a traditional PBX project. 1. Requirements and number porting - we capture your call flows and extension structure, then begin porting your existing numbers 2. System configuration - auto-attendants, hunt groups, voicemail and routing built around your workflow 3. Handset deployment - pre-configured IP handsets or softphones shipped to each site, ready on plug-in 4. Training and support - staff training, then ongoing support for moves, adds, changes and call-quality monitoring Temporary numbers can run while porting completes, so there is no gap in service. ## Why are UK businesses moving to hosted phone systems? The biggest driver is the retirement of the old analogue network. Openreach is withdrawing the traditional PSTN and ISDN phone network, with the industry switch-off scheduled for the end of January 2027, after which legacy analogue and ISDN lines stop working permanently (Ofcom). Any business still running a legacy on-site PBX must migrate to an IP-based hosted phone system before that deadline. The shift is already well underway, with cloud calling platforms such as Microsoft Teams Phone increasingly displacing desk-bound hardware. For multi-site organisations, hosted telephony also unifies every office onto one platform - see our multi-site VoIP and Microsoft Teams direct routing options. ## Hosted phone system vs traditional on-site PBX A hosted system moves the cost, maintenance and upgrade burden off your premises and onto the provider. The table below compares the two for a typical UK SME. | | Factor | Hosted phone system | Traditional on-site PBX | Hardware | Cloud-based, no server on site | PBX box and cards on your premises | Upfront cost | Low - handsets/apps only | High - server, install, cabling | Moves, adds, changes | Instant, in the admin portal | Engineer visit, often chargeable | Remote/hybrid working | Built in via apps | Add-on or unsupported | Upgrades | Automatic by provider | Manual, periodic, costly | PSTN switch-off ready | Yes | No - requires migration by Jan 2027 | Resilience | Reroutes in the cloud if a site fails | Tied to one location ## How much does a hosted phone system cost? Hosted phone systems are priced per user per month, which scales cleanly with headcount and removes the large upfront capital cost of a PBX. Final pricing depends on user count, handset choice, call-package and recording requirements, so we quote against your actual call profile rather than a headline rate. If you run Microsoft 365, calling can be added to your existing tenant. Microsoft 365 Business Premium - the security-first bundle AMVIA recommends - lists at £16.90 per user per month (ex VAT, annual) (Microsoft), with Teams Phone licensing added on top. AMVIA's own hosted phone system pricing is confirmed at quotation. For a like-for-like comparison against analogue lines, see VoIP vs landline. ## Is a hosted phone system secure? Yes - when it is configured and monitored properly. Because calls travel over the internet, a hosted phone system needs the same disciplines as the rest of your network: encryption, fraud monitoring, strong authentication and secure session controls. The UK's National Cyber Security Centre publishes guidance on protecting VoIP and unified-comms services (NCSC). AMVIA hardens every deployment and monitors for toll fraud and abnormal call patterns. Read more on our VoIP security page and how telephony fits with your wider Microsoft 365 calling setup. ## Is a cloud phone system the same as a hosted phone system? Yes. “Cloud phone system”, “hosted phone system”, “hosted VoIP” and “hosted PBX” all describe the same architecture: the phone system runs on the provider’s cloud platform and your handsets, softphones and mobile apps connect to it over the internet. When you compare cloud phone systems, the questions that actually separate providers are UK call quality (where the platform is hosted and how calls are routed), what is included per user versus charged as an add-on, number porting handling, contract term, and whether support is UK-based. AMVIA’s cloud phone system starts from £5.95 per user per month with UK support from our Sheffield team - and if your business lives in Microsoft Teams, Teams Phone may fit better still. Most customers take the phone system with its connectivity as a phone and broadband bundle, which puts call quality under one SLA instead of two suppliers. ## Frequently asked questions Q: What is a hosted phone system? A: A business phone service delivered entirely from the cloud - calls, voicemail, auto-attendants and call routing run on the provider's platform instead of a PBX box in your comms cupboard. Handsets and apps connect over your internet connection, and the system is managed for you. Q: What does a hosted phone system cost? A: AMVIA hosted VoIP starts from £5.95 per user/month, with the exact rate depending on user count, calling plans and handsets. There's no PBX hardware to buy or maintain - the capital cost of the old on-premises model simply disappears. Q: What happens to our phone system when the PSTN switches off? A: If your current system depends on analogue or ISDN lines, it stops working when the PSTN is retired on 31 January 2027. A hosted system is the standard replacement - and migrating early means porting numbers on your schedule rather than in the pre-deadline rush. Q: Can staff use the phone system from home or on mobiles? A: Yes - that's one of the main reasons businesses switch. Softphone apps put the business line on laptops and mobiles, so calls follow people rather than desks, with the same numbers, transfers and voicemail wherever they're working. --- # Microsoft Teams Direct Routing Service for UK Businesses URL: https://amvia.co.uk/business-voip/microsoft-teams-direct-routing Last updated: 2026-03 Microsoft Teams Direct Routing connects Microsoft Teams to the public phone network through a Session Border Controller (SBC) and your own SIP trunk, so you keep any UK carrier instead of buying Microsoft Calling Plans. AMVIA provisions the SBC, ports your numbers and runs go-live testing end-to-end - one provider, security-first, Microsoft-certified. If you are weighing up how Teams telephony fits your wider voice estate, start at our business VoIP pillar, then come back here for the direct routing detail. ## How does Microsoft Teams Direct Routing work? Direct routing sits an SBC between Teams and a SIP trunk from your chosen carrier. The SBC handles call signalling, media, security and protocol translation, and Teams routes outbound calls down whichever trunk your voice policy specifies. Microsoft documents this as the supported way to bring third-party PSTN connectivity into Teams Phone (learn.microsoft.com). In practice the call path looks like this: - Teams client places the call and applies your voice routing policy. - SBC (physical appliance or cloud-hosted) authenticates, secures and translates the call. - SIP trunk carries the call to your carrier and out to the PSTN. - Dial plans and least-cost routing decide which trunk and number range each call uses. A SIP trunk is the carrier-grade line that replaces legacy ISDN; the SBC is what makes that trunk safe to expose to Teams. ## What's included in AMVIA's Direct Routing service? AMVIA delivers direct routing as a managed service: design, build, number porting, testing and ongoing support. UK-based engineers own the configuration so your internal team never touches SBC firmware or SIP signalling. Everything is scoped to your site count, call volumes and resilience needs before a single number moves. Our four-stage rollout: 1. SBC and trunk setup - we provision SIP trunks and configure the SBC to connect your carrier to Teams. 2. Number porting - your existing numbers are ported to the new trunk; we manage the carrier process end-to-end. 3. Call routing and policies - voice routing policies, dial plans and emergency calling are configured for every call scenario. 4. Testing and go-live - internal, external and international call testing, then a phased rollout to your team. This pairs naturally with Microsoft Teams Calling and a hosted phone system where you want handsets, call queues and auto-attendants alongside softphone calling. ## Direct Routing vs Microsoft Calling Plans: which should you choose? Direct routing gives you carrier choice and competitive call rates; Calling Plans give you a faster, Microsoft-billed setup with less flexibility. The right answer depends on whether you already have a carrier relationship, need geographic number ranges, or want least-cost routing across high call volumes. | | Factor | Direct Routing (AMVIA) | Microsoft Calling Plans | Carrier choice | Any UK SIP/PSTN carrier | Microsoft only | Call rates | Competitive, negotiable | Fixed Microsoft tariff | Number porting | Full UK geographic ranges | Limited availability | Least-cost / failover routing | Yes, via SBC | No | Multi-site resilience | Centralised or local SBCs | Limited | Best for | Established estates, higher volumes | Small, simple deployments Direct routing is the route most UK businesses pick when they want to keep an existing carrier. ## Why do UK SMEs need Direct Routing now? The UK's analogue phone network is closing. Openreach is migrating every line to digital, with switch-off completion scheduled for January 2027 (Openreach), which means legacy PBX and ISDN telephony has a hard end date. Moving Teams onto direct routing now removes that risk and consolidates voice into the platform staff already use. The wider shift to digital landlines is documented by the regulator (ofcom.org.uk). Acting early gives you: - A clean cut-over instead of a rushed, deadline-driven migration. - One bill and one platform for calls, chat and meetings. - Number continuity - your geographic numbers port across untouched. For organisations with several offices, multi-site VoIP topologies let a single SBC route calls for every location, or local SBCs add resilience site by site. The PSTN switch-off guide covers the migration timeline in full. ## Is Microsoft Teams Direct Routing secure? Yes - when the SBC is hardened and the SIP trunk is correctly authenticated. The SBC is the security boundary between Teams and the PSTN, so it must enforce encryption, fraud controls and call admission limits. AMVIA configures these by default, because exposed voice infrastructure is a common toll-fraud target. Security is the connective tissue across everything we run. Direct routing inherits the same controls we apply to VoIP security more broadly - encrypted signalling, monitored trunks and rate limiting. Microsoft sets out the platform-side controls for Teams telephony in its UK security guidance (microsoft.com/en-gb/security). ## How much does Microsoft Teams Direct Routing cost? Cost has three parts: Microsoft licensing (a Teams Phone-capable plan per user), SIP trunk and call charges from your carrier, and the SBC plus AMVIA's managed setup and support. Because trunk pricing and site count vary widely, we quote per environment rather than publish a single headline figure. What shapes the quote: - User count and licence type - every calling user needs a Teams Phone-capable licence. - SBC model - on-premises appliance versus cloud-hosted, and whether you need redundancy. - Number of sites and trunks - drives SBC topology and porting effort. - Call profile - destinations and volumes determine the carrier tariff. AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we manage IT and telephony for 1,200+ UK businesses - so the build is done once, correctly, by certified engineers. Critical issues are responded to within one hour. ## Frequently asked questions Q: What is Microsoft Teams Direct Routing? A: It connects Microsoft Teams to the public phone network through a Session Border Controller and your own SIP trunks - so Teams becomes your full phone system, with your business numbers, while you control the calling rates and carrier rather than buying Microsoft's bundled plans. Q: Direct Routing or Microsoft Calling Plans - which is cheaper? A: Direct Routing usually wins on cost at scale because SIP trunk rates undercut Microsoft's bundled per-user calling plans, especially for heavy or international callers. Calling Plans win on simplicity for small teams. The crossover depends on your call profile - worth modelling both. Q: Can we keep our existing numbers with Direct Routing? A: Yes - numbers port to the SIP trunks behind the SBC, typically in 5–15 working days, and present through Teams exactly as before. Porting is sequenced before any legacy line cease so there's no gap. Q: What do we need in place for Direct Routing to work well? A: Teams Phone licensing, a certified SBC (AMVIA manages this), SIP trunks sized to your concurrent call volume - and honest bandwidth: voice quality is a connectivity question, which is why we design the calling and the circuit together. --- # Microsoft Teams Calling Plans for UK Businesses URL: https://amvia.co.uk/business-voip/microsoft-teams-calling Last updated: 2026-08-19 Microsoft Teams Calling lets UK businesses make and receive standard phone calls directly inside Microsoft Teams, replacing desk phones and separate phone systems. AMVIA provisions it with Calling Plans or Direct Routing - handling licensing, number porting, hunt groups and auto-attendants. One provider, security-first, Microsoft-certified engineers from setup to live calls. It is the cloud telephony layer of business VoIP: your team dials out, takes inbound calls, and routes them through queues and auto-attendants without a physical PBX. Because calls run through the same Teams client your staff already use for chat and meetings, there is one app to manage and one provider to call when something needs changing. ## How does Microsoft Teams Calling work? Teams Calling adds a public phone number to a user's Teams licence, then connects that number to the public telephone network (PSTN). Calls route through Teams on a laptop, mobile or certified desk phone - no on-premises phone system required. You choose how the PSTN connection is delivered: Microsoft Calling Plans, Direct Routing, or Operator Connect. - Calling Plans - Microsoft provides the phone numbers and minutes directly as part of the licence. - Direct Routing - AMVIA connects your own UK carrier and SIP trunk to Teams, giving you control over call rates and number ranges. - Operator Connect - a UK telecoms provider supplies numbers and minutes through a managed connection inside the Teams admin centre. Microsoft documents each connectivity model in its Teams Phone guidance on learn.microsoft.com. AMVIA helps you pick the model that matches your call volumes, existing numbers and budget. ## What's included when AMVIA sets up Teams Calling? AMVIA runs the full deployment - from licence activation to trained users making live calls, typically operational within five working days. We handle the Microsoft licensing, the PSTN connectivity, and the call-flow design so your phones work on day one. - Licence and number setup - we activate calling licences, port or assign your numbers, and configure emergency calling addresses. - Call-flow design - auto-attendants, call queues and hunt groups are built in Teams to match how your business answers calls. - User configuration - each Teams client is set up with voicemail, caller ID and call-forwarding rules. - Training and go-live - staff are trained on making and receiving calls, with ongoing call-quality monitoring and change support. This sits alongside our wider managed Microsoft 365 service, so licensing, security and telephony are looked after by the same team. ## Calling Plans vs Direct Routing vs Operator Connect - which is right? The right model depends on whether you want Microsoft to supply the lines, keep your existing UK carrier, or use a provider-managed connection. Direct Routing usually wins on call rates and number flexibility; Calling Plans win on simplicity. Here is how they compare. | | Factor | Calling Plans | Direct Routing | Operator Connect | PSTN supplier | Microsoft | Your chosen UK carrier | Partner operator | Carrier choice | Fixed | Full control | Operator list | Call rates | Standard | Often lowest | Competitive | Setup complexity | Lowest | Higher (managed by AMVIA) | Low | Best for | Small, simple estates | Higher volumes, existing numbers | Mid-size estates wanting a managed line ## Why do UK SMEs need Teams Calling now? The biggest driver is the PSTN switch-off: traditional analogue and ISDN lines are being retired, so every business on legacy phone lines must move to IP telephony. The UK PSTN switch-off is scheduled for completion by 31 January 2027 (Openreach). Teams Calling is a cloud-native replacement that removes any dependence on copper lines. There is no bandwidth barrier for most firms. The UK average broadband download speed is 69.4 Mbps (Ofcom Connected Nations 2024), which is comfortably enough for clear Teams calls once voice traffic is prioritised. The real work is in the migration - porting numbers, rebuilding call flows, and configuring quality-of-service correctly. See our PSTN switch-off guide for the full timeline and migration steps. ## How much does Microsoft Teams Calling cost? Cost is built from two parts: the Microsoft Teams Phone licence per user, plus a calling plan or PSTN connectivity for the minutes. There is no single sticker price - it scales with how many users need an external phone number and how you connect to the network. - Microsoft 365 base licences start at £4.60/user/month (Business Basic), £9.60 (Business Standard) and £16.90 (Business Premium), ex VAT on an annual plan (Microsoft 365 UK pricing). - Teams Phone is a separate add-on layered on top, plus either a Microsoft Calling Plan or your own carrier minutes via Direct Routing. - Not every user needs an external number - internal-only staff can stay on standard Teams licences, which keeps the total down. AMVIA scopes the exact licence mix for your headcount so you only pay for external calling where it is actually needed. ## Why choose AMVIA for Microsoft Teams Calling? AMVIA is a security-first Microsoft partner, not a telecoms reseller - so Teams Calling is deployed with the same hardening and oversight as the rest of your Microsoft 365 estate. We manage IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. - Sheffield-based UK engineers who understand UK numbering, compliance and network infrastructure. - Cyber Essentials Plus certified and a Microsoft Solutions Partner - your telephony is configured to recognised UK security and quality standards. - One accountable provider for licences, connectivity, call quality and security - no finger-pointing between vendors. - Certified hardware supplied and configured from Poly, Yealink and Jabra where users want a physical handset. ## What does AMVIA’s managed Teams Phone service cost? Teams Phone pricing has two parts: the Microsoft licensing covered above, plus the calling element - Operator Connect, Direct Routing minutes or a Microsoft Calling Plan - and the setup and management. AMVIA’s managed service is priced from £5.95 per user per month - the same published floor as our hosted VoIP platform - with the exact figure depending on carrier route and call volumes. One bill covers licensing advice, number porting, call-flow build and ongoing support. ## Migrating from a legacy PBX If you run an on-premise PBX or ISDN lines today, the safe migration path is parallel, not big-bang: stand up Teams Phone alongside the old system, prove the call flows, port the numbers, then retire the PBX - so there is never a day without a working phone system. And the deadline is real: Openreach withdraws the analogue network in January 2027, so ISDN-dependent PBXs have a hard end date whether or not you choose Teams. A hosted phone system is the alternative route if your business isn’t standardised on Teams - and either way, pairing the phone system with its connectivity in a phone and broadband bundle puts call quality under one SLA. ## Frequently asked questions Q: What is the difference between Microsoft Calling Plans and Operator Connect? A: Microsoft Calling Plans bundle PSTN connectivity directly from Microsoft, which makes setup simple but fixes your carrier. Operator Connect lets you choose a UK telecoms provider through the Teams admin centre, often improving call rates and local number availability. AMVIA helps you choose the option that fits your call volumes and budget. Q: Can we keep our existing phone numbers when moving to Teams Calling? A: Yes. Number porting transfers your existing business numbers from your current provider to your Teams calling platform. UK ports typically take five to ten working days once the request is submitted. AMVIA manages the whole process, coordinates with your outgoing provider, and makes sure no calls are missed during the cutover. Q: How do you ensure call quality on Microsoft Teams? A: Call quality depends on network configuration, bandwidth and quality-of-service settings. AMVIA configures QoS policies to prioritise voice traffic so calls stay clear even under heavy data load. With the UK average download speed at 69.4 Mbps (Ofcom Connected Nations 2024), bandwidth is rarely the constraint - correct traffic prioritisation is what matters. Q: Do we need special handsets for Teams Calling? A: No. Teams Calling works on any device running the Teams desktop or mobile app - laptops, tablets and smartphones. Certified Teams desk phones and headsets do give a more professional experience with dedicated call controls and better audio. AMVIA supplies and configures certified hardware from Poly, Yealink and Jabra where it is wanted. Q: What happens to our phone system during the PSTN switch-off? A: Traditional analogue and ISDN lines are being retired in the UK, so businesses on legacy lines must migrate to IP-based telephony before the deadline. Microsoft Teams Calling is a cloud-native replacement that removes reliance on copper infrastructure and adds call queues, auto-attendants and voicemail transcription. AMVIA plans and runs the migration so there is no service gap. Q: Is Microsoft Teams Calling secure? A: Yes - calls and signalling are encrypted by Microsoft, and AMVIA hardens the surrounding Microsoft 365 tenant with Microsoft Defender, conditional access and MFA. Because we deploy telephony and security together, your phone system is covered by the same monitoring as the rest of your environment rather than bolted on separately. Q: What is the difference between Calling Plans and Direct Routing? A: Calling Plans provide PSTN connectivity directly from Microsoft - simple and fully managed. Direct Routing uses a third-party certified SBC to connect Teams Phone to a SIP carrier of your choice. Direct Routing is more complex to set up but usually offers lower per-minute rates and more flexibility for higher call volumes or existing SIP contracts. Q: What is Operator Connect? A: Operator Connect is a Microsoft-managed connectivity option where a certified carrier links its SIP network to your Teams Phone environment directly through Microsoft's cloud. It sits between Calling Plans (simple, Microsoft-provided) and Direct Routing (flexible, carrier-chosen) for setup effort and control. Certified UK operators include BT and Gamma. --- # Multi-Site VoIP Phone System for UK Businesses URL: https://amvia.co.uk/business-voip/voip-multi-site Last updated: 2026-03 Multi-site VoIP is a single cloud phone system that connects every office, branch and remote worker your business runs. Each site shares one extension directory, one set of call routing rules and one management portal, with internal site-to-site calls carried free over your internet. One provider, security-first, runs the lot. ## What is a multi-site VoIP phone system? A multi-site VoIP phone system replaces separate phone lines at each location with one cloud platform that all your sites log into. Staff in Sheffield, Manchester and home offices appear in the same directory, dial each other by extension, and share queues - managed centrally rather than site by site. This is the natural successor to the analogue phone network, which Ofcom confirms is being retired as the UK migrates landline services to digital, internet-based technology (Ofcom). If you run more than one location, a unified system removes the cost and admin of maintaining a separate phone setup per site. It sits inside our wider business VoIP offering, so call plans, handsets and softphones are configured once and applied everywhere. ## What's included in a multi-site VoIP system? A multi-site deployment gives every location the same features and the same control. Instead of each office running its own island of telephony, you get one directory, one routing engine and one portal. The result is lower call costs, consistent customer handling and far less day-to-day management overhead. - Single extension directory - every employee at every site has an extension reachable from any other site. Calling a Manchester colleague from Sheffield is just dialling the extension: no external call charges, no looking up site numbers. - Intelligent call routing - route inbound calls by DDI number, by time of day, or by overflow rules so a main number can ring head office in hours and divert to a second site after. - Shared hunt groups and call queues - sales, support and accounts teams that span sites answer from one queue, so a customer reaches whoever is free regardless of location. - Centralised management - users, extensions, queues, auto-attendant menus and call recording are all administered from one web portal, not by chasing different IT contacts per office. - Free inter-site calls - calls between your locations travel as data over your existing connections, removing inter-site PSTN charges entirely. ## How does AMVIA connect your sites with VoIP? We deploy multi-site VoIP in four controlled stages so each location goes live without disrupting the ones already running. Survey first, design one unified plan, roll out site by site with number porting tested at each step, then hand over a single managed platform. 01. Multi-site survey - we assess network readiness, bandwidth and call routing needs at every location. 02. System design - a unified call plan with site-to-site dialling, centralised reception and local breakout where needed. 03. Phased rollout - handsets and softphones deploy site by site, with number porting and routing tested at each stage. 04. Unified management - all sites run from one platform with centralised reporting, call recording and ongoing UK support. Where a site handles heavy concurrent call volumes, we pair the deployment with the right connectivity - typically a leased line for HQ and quality business broadband with QoS for smaller offices. See our multi-site connectivity approach for how the network underneath is built. ## Multi-site VoIP vs traditional multi-site phone lines The difference between one cloud system and a phone setup per site shows up in cost, management and resilience. The table below compares the two for a typical UK business running three or more locations. | | Factor | Multi-site VoIP (AMVIA) | Traditional per-site lines | Inter-site calls | Free over the internet | Charged as external calls | Extension dialling | One directory across all sites | Per-site, external numbers needed | Management | One central portal | Separate admin per location | Adding a site | Configured remotely, same day | New lines, new install per site | Remote workers | Same extension and queues as office | Usually excluded | Resilience | Reroute to another site instantly | Site outage isolates that office ## How does multi-site VoIP handle security? Because calls and management run over your internet connection, the phone system becomes part of your attack surface - and should be secured like any other business application. We harden the platform with enforced authentication, fraud monitoring and encrypted call signalling, and we treat telephony as a security service, not a telecoms add-on. The NCSC sets out why voice and collaboration tooling needs the same controls as email and endpoints (NCSC). For Microsoft-centric organisations, calls can run through Teams using Microsoft Teams Direct Routing, which keeps voice inside the same identity and Conditional Access controls as the rest of Microsoft 365 (Microsoft Learn). If telephony security is your priority, our VoIP security guidance covers the full control set. ## Why choose AMVIA for multi-site VoIP? AMVIA runs telephony for UK businesses as a security partner, not a reseller - so your phone system is designed, deployed and monitored by Microsoft-certified engineers under one accountable contract. - Sheffield-based, UK-focused - our engineering and support team operates from Sheffield and understands UK compliance and network realities. - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status. - 1,200+ UK businesses - we manage IT and security for over 1,200 UK businesses across legal, finance, healthcare and professional services. - Fast, responsive support - critical issues carry a If your sites also need a single-site system or trunk-only setup, our hosted phone system and SIP trunks pages cover those options. ## Frequently asked questions Q: How does a multi-site VoIP phone system work? A: One cloud phone system spans every office, branch and remote worker: a single extension plan, free internal calls between sites, shared receptionist and call groups, and one admin portal - instead of separate phone systems that can't transfer a call to the next town. Q: Can each site keep its own local numbers? A: Yes - each location presents its own local numbers outward (a Manchester number in Manchester, a Leeds number in Leeds) while everything behind them runs as one system. Existing numbers port in as standard. Q: What happens if one site's internet fails? A: Only that site's connectivity is affected - and calls re-route by policy: to mobiles, to another site, or to voicemail, automatically. The phone system itself lives in the cloud, so a local fault never takes down the company's phones. Q: How do remote and hybrid staff fit in? A: As extensions like anyone else: the softphone app puts the business line on laptops and mobiles, so home workers appear in the same directory, ring groups and transfers as office staff. Multi-site increasingly means multi-place, not multi-building. --- # What Is Business VoIP? A Complete Guide for UK Businesses URL: https://amvia.co.uk/business-voip/what-is-business-voip Last updated: 2026-07-21 Business VoIP (Voice over Internet Protocol) carries phone calls over your internet connection instead of copper PSTN or ISDN lines. With the UK's analogue phone network being retired, every business must migrate. VoIP runs on any device, scales in software and is the calling foundation AMVIA manages end to end - one provider, security-first, Microsoft-certified. ## What is business VoIP, and why does it matter now? VoIP converts your voice into digital data packets and sends them over an IP network - your broadband or leased line - then reassembles them into speech at the other end in milliseconds. On a properly configured connection, a VoIP call is indistinguishable from a landline call. It is the modern replacement for analogue and ISDN telephony, and the core of every business VoIP deployment. The timing matters because the UK's PSTN - the old analogue phone network - is being switched off, and Ofcom has confirmed all voice services must move to digital, internet-based calling (Ofcom). The industry completion date is 31 January 2027. After that, analogue lines and ISDN connections stop working - a hard cut-off, not a gradual phase-out. More than 2 million UK businesses still rely on PSTN/ISDN lines (Ofcom estimates), and Openreach has already stopped selling new PSTN and ISDN products across hundreds of exchange areas. Roughly 31% of businesses have already switched; the rest are now on the clock. ## How does VoIP actually work? When you speak into a desk phone, softphone or mobile app, a codec digitises and compresses your voice into small packets tagged with routing information. Those packets travel across your internet connection using SIP (Session Initiation Protocol) to set up the call and RTP (Real-time Transport Protocol) to carry the audio, then are reassembled and decoded at the far end. Modern codecs such as G.722 and Opus deliver high-definition voice that surpasses the narrowband audio of traditional ISDN. Calls between two VoIP users stay entirely on the internet; calls to mobiles or not-yet-migrated landlines convert from IP to the public network at a gateway, transparently in the background. ## How much bandwidth does VoIP need? Each concurrent call needs roughly 80–100 Kbps up and down on the G.711 codec, or 30–40 Kbps on more efficient codecs like G.729. A 20-person office at peak load needs around 2 Mbps of dedicated upload - comfortable for most FTTP or FTTC connections. Bandwidth alone is not enough. Three quality metrics decide whether calls sound clean: - Latency - keep below 150 ms (the delay between speaking and being heard). - Jitter - keep below 30 ms (variation in packet arrival times). - Packet loss - keep below 1% (packets that never arrive). Quality of Service (QoS) settings on your router prioritise voice over bulk data, so calls stay clear even when the line is busy. ## SIP trunking vs hosted VoIP - which path is right? There are two main ways to deploy business VoIP. SIP trunking replaces your ISDN lines but keeps your on-premise PBX; hosted VoIP (UCaaS) replaces the phone system entirely with a cloud platform. The right choice depends on the age and life left in your current PBX. | | Factor | SIP trunking | Hosted VoIP (UCaaS) | On-premise PBX | Kept - manages internal routing | None - fully cloud-hosted | Best for | Modern SIP-ready PBX with years of life | Ageing PBX, hybrid teams, consolidation | Handsets | Existing PBX and phones | IP phones, softphones, mobile apps | Management | Your team / PBX | Provider-managed in their data centres | Scaling | Add SIP channels | Add users in software SIP trunking is the most cost-effective route when you have a capable PBX - only the external connection changes. SIP trunking keeps hunt groups, extensions and call routing exactly as they are. Hosted UCaaS for SMEs suits businesses with end-of-life hardware or hybrid working. For organisations already on Microsoft 365, Microsoft Teams Calling is the most natural path - Teams reports over 320 million monthly active users globally (Microsoft, 2024), so staff are already in the app (Microsoft 365). ## What features does a business VoIP system include? Business VoIP - whether SIP or hosted - provides features that analogue and ISDN systems either cannot offer or need expensive add-on hardware to support. Most are configured through a web portal, not an engineer visit. - Auto-attendant and IVR - automated greeting and menus that route callers to the right department. - Hunt groups and call queues - distribute inbound calls by ring-all, round-robin, longest-idle or skills-based rules. - Call recording - automatic or on-demand, stored in the cloud, searchable by date, caller or extension. - Voicemail to email - messages delivered as audio attachments, with transcription on many platforms. - Presence and status - see who is available, on a call or away before you dial. - Mobile and desktop apps - make and take calls on your business number from any device, anywhere. - CRM integration - caller account history on-screen the moment a call lands. ## What are the benefits of moving to business VoIP? The financial case is strong: many UK businesses cut monthly telephony costs by around 30–50% (typical UK saving, 2026) after leaving ISDN, mainly by removing ISDN line rental and lowering per-minute rates. But the operational gains matter just as much. Scaling is immediate - adding a user or channel is a software change that takes effect in minutes. Geographic flexibility means staff make and receive calls on their business number from any location, which is essential for hybrid working. Integration with Microsoft 365 and CRM systems removes friction between apps. Resilience improves too. If an office becomes inaccessible - power cut, flooding, anything - calls divert automatically to mobiles or another site. With ISDN, losing the building means losing the phone lines until you are back in. ## Why must UK businesses act before the PSTN switch-off? The switch-off is a hard deadline, not a soft target. Once the analogue network is retired, every PSTN line and ISDN connection stops permanently, and Openreach's stop-sell programme is already live across hundreds of exchanges. Acting early protects your install slot and your numbers. The risk of delay is practical: constrained installer availability, longer number-porting queues and fewer migration slots as demand peaks. Start your assessment now even if go-live is months out - number porting alone takes 7–14 working days. Read the full PSTN switch-off breakdown for the affected-services detail. It is not only desk phones. Alarm systems, lift emergency lines, PDQ card terminals, fax machines, door entry and PSTN-connected CCTV all stop on the same date and each needs its own IP or 4G/5G migration plan. ## What should you check before migrating? Audit every PSTN and ISDN line first - including non-telephony devices like alarms, lifts and payment terminals - so nothing is missed and you can choose SIP or hosted correctly. Then test connection quality under real load, plan number porting early, and decide whether your access network itself needs upgrading. - Connectivity type - if your broadband runs over FTTC (copper for the final hop), consider FTTP or a dedicated leased line so the access network itself is switch-off-proof. - Call continuity - configure inbound divert to mobiles, plus a 4G/5G backup router that activates on broadband failure. - Security - VoIP is an internet service and needs hardening against toll fraud and eavesdropping; see VoIP security and apply the NCSC's guidance on protecting voice services (NCSC). ## How AMVIA helps you migrate AMVIA provides fully managed VoIP for UK SMEs - from auditing your current phone system and recommending the right fit, through number porting, configuration and ongoing support. Whether SIP trunking, hosted UCaaS or Microsoft Teams Phone is right, AMVIA assesses your needs honestly and manages the migration end to end. AMVIA has delivered VoIP migrations for over 1,200 UK businesses. Call 0333 733 8050 to start your assessment. ## Frequently asked questions Q: Is VoIP call quality as good as a traditional phone line? A: On a well-configured connection, business VoIP quality equals or beats a traditional ISDN call. Modern codecs deliver high-definition voice ISDN cannot match. Echo, delay or dropped calls almost always trace back to insufficient upload bandwidth, high jitter or missing QoS - not VoIP itself. AMVIA tests connectivity and configures QoS before every migration. Q: What happens if my internet connection goes down? A: If the connection at a site fails, VoIP at that site stops. The standard mitigation is automatic call divert - inbound calls route to mobiles so clients always reach someone. A 4G/5G backup router that activates on broadband failure adds further resilience. AMVIA configures both as part of a complete VoIP deployment. Q: Can I keep my existing phone numbers when moving to VoIP? A: Yes. Number porting transfers your existing geographic and non-geographic numbers to the new provider, typically over 7–14 working days. Calls continue on your existing lines until the port completes, so there is no gap in service. AMVIA manages porting as part of every migration it delivers. Q: How much does business VoIP cost compared to ISDN? A: Most businesses see a meaningful drop in monthly telecoms costs after moving to VoIP, before lower per-minute rates are even counted. The exact saving depends on how many ISDN channels you replace and your call volumes. AMVIA provides a detailed cost comparison before any migration so you can see the expected saving first. Q: When is the PSTN switch-off? A: Openreach is retiring the analogue PSTN and ISDN network nationally, with the industry completion date set for 31 January 2027. New PSTN and ISDN sales have already stopped across many exchanges. Any business still on analogue or ISDN lines must migrate to internet-based calling before the cut-off to keep its phones, alarms and card terminals working. Q: Does business VoIP require dedicated connectivity? A: Not necessarily. Most small offices run VoIP comfortably on FTTP or quality FTTC broadband. A leased line becomes worthwhile when you need guaranteed upload bandwidth, symmetrical speeds and an uptime SLA for many concurrent calls. AMVIA assesses your call volumes and recommends the right access - broadband or leased line - before you commit. --- # What Is a SIP Trunk? Explained for UK Business Owners URL: https://amvia.co.uk/business-voip/sip-trunk Last updated: 2026-07-21 A SIP trunk is a virtual phone line that connects your existing on-premise PBX to the public telephone network over an internet connection, replacing expensive ISDN lines. It keeps your phones, extensions and numbers while cutting line rental. AMVIA plans and runs the full migration - one provider, security-first, Microsoft-certified. ## What is a SIP trunk and why does it matter? A SIP (Session Initiation Protocol) trunk carries your business calls as digital data packets over an IP connection instead of a physical copper ISDN circuit. It lets you keep your current PBX hardware and internal extensions while swapping only the expensive lines that connect that system to the outside world. This makes SIP trunking the most cost-effective migration route for a business with a reasonably modern, SIP-compatible PBX it does not want to replace. With the UK PSTN switch-off scheduled for completion by 31 January 2027 and over 2 million UK businesses still relying on PSTN/ISDN lines (Ofcom estimates), SIP trunking is one of the two main paths off the old network - the other being a full move to a hosted phone system. For the wider picture, see our business VoIP solutions and what the PSTN switch-off means for your phones. Ofcom's guidance on migrating landlines to digital technology confirms the analogue and ISDN network is being retired industry-wide. ## How does SIP trunking work? SIP trunking uses two protocols. SIP sets up, manages and ends each call - the signalling that connects two parties, handles hold or transfer, and closes the session. RTP (Real-time Transport Protocol) carries the actual voice audio. Together they replace what an ISDN line used to do over copper. A provider allocates a set of virtual channels to your business, and each channel supports one simultaneous call. When a member of staff dials out, the PBX sends a SIP INVITE over your data connection to the provider, which completes the call to the public network; the audio then flows via RTP. Incoming calls arrive at the provider and route to your PBX over the same link. Crucially, the PBX still handles all internal routing, hunt groups, auto-attendants, voicemail and extensions exactly as before. Only the external connection changes, so staff keep the same phones, extensions and features. Most modern PBX systems from Avaya, Cisco, 3CX, Mitel, Panasonic and NEC support SIP natively or after a firmware upgrade; older ISDN-only systems can connect through a media gateway. AMVIA checks PBX compatibility as part of migration planning. ## SIP trunking vs ISDN: what is the difference? SIP trunking beats ISDN on cost, scalability, resilience and geographic flexibility, and it is the only one of the two with a future - ISDN is being switched off permanently. ISDN ties calls to a fixed copper circuit; SIP moves them onto an IP connection you can scale and re-route in software. | | Factor | ISDN | SIP trunk | Line rental | £25–£50 per channel per month | £5–£15 per channel per month | Adding channels | Engineer visit, days to weeks | Software change, within hours | Resilience | Lost if copper circuit fails | Failover to 4G/5G or divert to mobile | Location | Fixed to one site | Moves with you; shared across sites | Future | Switched off 31 January 2027 | Long-term replacement technology For a business running 30 ISDN channels, the saving on line rental alone can exceed £500 a month. ## SIP trunking vs hosted VoIP: which should you choose? SIP trunking keeps your on-premise PBX; hosted VoIP (UCaaS) replaces it entirely with a cloud platform. Choose SIP if your PBX is modern, SIP-compatible and has useful life left. Choose hosted VoIP if your system is near end of life or you want cloud flexibility for hybrid teams. | | Consideration | SIP trunking | Hosted VoIP / UCaaS | PBX hardware | Keep existing on-premise PBX | None - fully cloud-hosted | Best for | Modern PBX, under 5–7 years old | Ageing PBX or remote-first teams | Upfront cost | Lower if PBX already owned | No PBX to buy | Remote working | Limited by PBX features | Built in via apps and softphones | Microsoft 365 fit | Via gateway | Native with Microsoft Teams Phone If your PBX is more than seven or eight years old, or carries an expensive maintenance contract, a move to UCaaS for UK SMEs or Microsoft Teams Phone is usually the better long-term call. AMVIA assesses both objectively rather than defaulting to one path. ## How many SIP channels does your business need? The number of SIP channels you need equals your peak concurrent call volume - not your total extensions or headcount. One channel supports one simultaneous call, so a 50-extension office that never exceeds 15 calls at once needs 15 channels, not 50. Over-provisioning wastes money; under-provisioning gives callers a busy tone at peak times. AMVIA analyses your existing ISDN call data - which your current provider can supply - to size the trunk accurately from day one. Channels can be flexed up or down later as your calling patterns change, without an engineer visit. ## What connectivity do you need for SIP trunking? Each concurrent call uses roughly 80–100 Kbps up and down on the G.711 codec, so 15 calls need only about 1.5 Mbps - well within most FTTC or FTTP broadband. Bandwidth is rarely the limiting factor; connection stability matters more. Three metrics decide call quality: latency (ideally below 150 ms), jitter (ideally below 30 ms) and packet loss (ideally below 1%). Quality of Service (QoS) settings on your router must prioritise voice over bulk traffic such as backups and downloads, or a single large file transfer can degrade calls. Where call quality is business-critical, a dedicated leased line gives symmetric bandwidth with guaranteed quality, removing the contention inherent in shared broadband. AMVIA assesses your connection before recommending whether it is fit for SIP. ## How much does a SIP trunk cost? SIP trunk pricing has two parts: a per-channel monthly rental and per-minute call charges. Channel rental typically runs £5–£15 per channel per month, against £25–£50 per channel per month for ISDN, and call rates are lower, often with inclusive UK landline and mobile bundles. A business migrating from a 30-channel ISDN30 circuit with line rental around £1,000–£1,500 a month might pay £150–£450 a month for equivalent SIP capacity - a saving of 50–70% on line rental alone. With lower call charges added in, the total saving often recovers any upfront migration cost within 6 to 12 months. Number porting takes 7 to 14 working days, with no gap in service when managed correctly. ## How does AMVIA manage SIP trunk migration? AMVIA delivers fully managed SIP trunking for UK businesses: PBX compatibility assessment, connectivity evaluation, channel planning from real call data, number porting, QoS configuration and ongoing management. Where a full hosted VoIP or Teams Phone move makes more sense, we say so. The migration follows a clear sequence: - PBX compatibility assessment - confirm native SIP support or specify a gateway. - Provisioning and testing - stand up the trunk on temporary numbers. - QoS configuration - prioritise voice on your router and network. - Number porting - transfer your geographic numbers (7–14 working days). - Cutover and go-live - switch traffic with calls still protected. - Post-migration monitoring - verify quality and tune as needed. Because voice now rides your data network, securing it matters: see our approach to VoIP security, aligned with NCSC guidance on telephony and network security. Call 0333 733 8050 to discuss your PSTN migration options. ## Frequently asked questions Q: Is SIP trunking better than replacing my PBX with hosted VoIP? A: It depends on your PBX. If it is under five years old, SIP-compatible and has features you rely on, trunking is often the most cost-effective path. If it is near end of life, needs costly maintenance, or lacks mobile and Teams integration, hosted VoIP is usually the better long-term investment. AMVIA assesses both honestly based on your situation. Q: How many SIP channels do I need? A: The number equals the maximum simultaneous calls your business makes at any one time, not your total extensions. Most businesses need far fewer channels than extensions - a 30-person firm typically needs 8 to 12. AMVIA analyses your current call data to recommend the right number and avoid paying for capacity you will not use. Q: Can I keep my existing phone numbers on SIP trunks? A: Yes. Number porting transfers your existing geographic numbers to the new SIP provider, and the process takes 7 to 14 working days. During the porting window, calls keep routing through your existing ISDN lines until the port completes, so there is no gap in service. AMVIA manages porting as part of installation. Q: What quality of internet connection do I need for SIP trunking? A: Each call needs around 80–100 Kbps up and down, so bandwidth is rarely the limit on FTTC or FTTP broadband. Stability matters more - jitter and packet loss affect quality more than raw speed. AMVIA configures QoS to prioritise voice traffic and confirms whether your connection is suitable before installation. Q: When is the PSTN switch-off and what should I do? A: The UK PSTN and ISDN network is scheduled to be retired by 31 January 2027, so any business still on ISDN must migrate to an IP-based service. SIP trunking lets you keep a compatible PBX; hosted VoIP replaces it. Start early, as porting queues are expected to lengthen as the deadline nears. --- # Unified Communications as a Service (UCaaS) for UK SMEs URL: https://amvia.co.uk/business-voip/ucaas-for-smes Last updated: 2026-07-21 UCaaS for SMEs (Unified Communications as a Service) is a cloud-hosted platform that brings voice calling, video conferencing, instant messaging, and collaboration into one application, billed per user each month. It replaces on-premise PBX hardware with software you access over the internet, on any device. AMVIA supplies and manages it end to end as part of its business VoIP services. ## What is UCaaS and how does it differ from standard VoIP? UCaaS is a single cloud platform that unifies every communication channel - calls, video, chat, and file sharing - under one subscription. Standard VoIP only changes how calls travel: it swaps copper lines for IP delivery. UCaaS builds on that and replaces the whole phone system, not just the line. The distinction matters when you are comparing quotes. VoIP can mean simply moving an existing PBX onto IP lines via SIP trunking. UCaaS removes the on-premise system entirely and hosts everything with the provider. For most UK SMEs buying a new phone system, UCaaS is the relevant concept - one platform, one bill, one provider accountable for it. - Voice: make and receive calls on your business number from a desk phone, laptop softphone, or mobile app. - Video: HD meetings with internal and external participants, screen sharing, and recording in the same app as calling. - Messaging: persistent team chat channels that replace scattered email threads. - Admin: auto-attendants, hunt groups, call recording, and reporting configured through a web portal - no engineer visit. The global UCaaS market is projected to reach $107 billion by 2027, and around 31% of UK businesses have already switched - a clear signal that the move from fragmented legacy systems to unified cloud platforms is now the default. ## How does UCaaS work in practice for UK SMEs? The provider runs all the infrastructure - servers, software, security patching, and feature updates - inside a per-user monthly subscription. Add a licence when someone joins, remove it when they leave. There is no hardware to depreciate and no on-site IT expertise required to keep the system running. Staff use whichever device suits them: a desk phone in the office, a softphone on a laptop at home, or a mobile app on the road. Calls show your business number regardless of device, giving clients a consistent experience and your team genuine hybrid flexibility. Presence indicators show who is available or on a call, cutting wasted internal call attempts. Existing numbers are ported during setup, so contacts see no change. Call routing, auto-attendants, hunt groups, voicemail, and recording are all managed through the admin portal, and changes take effect immediately. ## Which UCaaS platforms are available to UK SMEs? Several established platforms serve the UK market, and the right one depends on your existing technology, team size, and requirements. AMVIA works across multiple platforms and recommends by fit, not by default vendor. Microsoft Teams Phone is the natural choice if you already run Microsoft 365 - it folds calling into the app staff use for meetings and documents, via Microsoft Teams Direct Routing or a calling plan. Microsoft reports Teams has over 320 million monthly active users globally, and Microsoft documents Teams Phone as a managed calling option within Microsoft 365 (Microsoft 365). Other widely deployed UK platforms include Gamma Horizon, 8x8, RingCentral, and Cisco Webex Calling. | | Option | Best for | Voice | Video + chat | On-premise hardware | UCaaS (full platform) | New phone system, hybrid teams | Yes | Yes | None | Microsoft Teams Phone | Microsoft 365 organisations | Yes | Yes (Teams) | None | SIP trunking | Keeping a modern PBX | Yes | No | PBX retained | Legacy PBX + ISDN | End-of-life systems | Yes | No | Full PBX ## How much does UCaaS cost for a UK SME? UCaaS is priced per user, per month. Most business-grade platforms range from £10 to £25 per user, usually covering unlimited UK landline and mobile calls, the desktop and mobile apps, voicemail, and the admin portal. Premium tiers add call recording, analytics, CRM integration, or contact-centre features. Set that against the combined cost of ISDN line rental, PBX maintenance contracts, and per-minute call charges on legacy systems. Most UK SMEs find UCaaS delivers a 25–50% reduction in total telephony cost on an equivalent basis - a typical UK 2026 range - before counting the elimination of PBX hardware replacement cycles, which can run to £5,000–£30,000 (UK 2026 rates) depending on system size. ## Why does the PSTN switch-off make UCaaS urgent? The UK is retiring its analogue phone network. Openreach is migrating customers off the legacy Public Switched Telephone Network, with the programme due to complete around the end of January 2027 - after which analogue lines and ISDN connections stop working (Ofcom: the future of landline calls). Openreach reports around 2.8 million lines still remain on the legacy network as of 2026, more than 500,000 of them serving business premises, and every one must move to an IP-based solution before the deadline. For businesses with ageing PBX hardware - particularly systems more than seven or eight years old - the switch-off is a natural decision point. Rather than buying new on-premise kit, UCaaS offers a migration path that removes telephony hardware entirely. Our PSTN switch-off guide walks through the deadline and the options in detail. ## What does migrating to UCaaS involve? A well-run migration follows a structured process over roughly four to eight weeks, depending on the complexity of your current setup. The point of a managed migration is that no step is left to chance and no number drops. - Discovery: audit the current system, find every PSTN and ISDN line (including alarm and payment-terminal lines), and check internet quality. - Design: select the platform and design the call flow - DDI allocation, hunt groups, auto-attendant menus, and voicemail. - Number porting: existing geographic and non-geographic numbers are ported, typically over 7–14 working days, coordinated to avoid any service gap. - Configuration and testing: deploy handsets and apps, then test inbound and outbound calls, transfers, voicemail, and 999 access. - Go-live and training: train staff, complete the port, and monitor closely for the first few days. Where you also need Microsoft 365 calling integration, that is designed in at the platform-selection stage rather than bolted on later. ## What should UK SMEs check before choosing UCaaS? UCaaS depends entirely on your internet and your configuration. A handful of checks separate a smooth deployment from a frustrating one, so treat the points below as a buyer's checklist rather than a formality. - Internet quality is foundational: assess upload speed, jitter, and packet loss for your peak concurrent call volume. Pairing UCaaS with resilient backup connectivity removes most outage risk. - Mobile app usability drives adoption: the system only pays back if staff actually use it on the move. - Emergency calling must be configured: Ofcom requires accurate 999 access, which matters most for multi-site and remote workers. - Security must be built in: harden accounts, calling policies, and toll-fraud controls from day one - see VoIP security. - Contract terms matter: understand the minimum term, how mid-term user changes work, and how numbers port away if you ever switch provider. ## Frequently asked questions Q: What is the difference between UCaaS and standard VoIP? A: Standard VoIP replaces phone lines with IP-based calling - it is about how calls are transmitted. UCaaS builds on VoIP to deliver a full communications platform: voice, video, messaging, and collaboration in one place. VoIP can mean simply migrating a PBX to IP via SIP trunking; UCaaS replaces the whole phone system with a cloud platform. Q: How much does UCaaS cost for a UK SME? A: UCaaS is priced per user, per month, with most business-grade platforms in a broad mid-range band that usually includes unlimited UK calls, the apps, and full system management. Set against ISDN line rental, PBX maintenance, and per-minute charges, most businesses find UCaaS meaningfully cheaper than traditional telephony on an equivalent basis. Q: Can UCaaS work for a business with multiple offices? A: Yes - and it is one of the biggest advantages over a traditional PBX. A single cloud platform serves every site, with staff calling each other as internal extensions at no cost. Each location connects via its own internet line, so there is no central PBX or expensive inter-site links to maintain. Q: What happens if our internet connection goes down? A: If a site's connection fails, calls through it stop. The standard mitigation is automatic call divert to mobile numbers, so callers always reach someone. For business-critical sites, pairing UCaaS with a resilient connection - bonded broadband or a leased line with failover - removes most of that risk. Q: Do we have to move before the PSTN switch-off? A: Yes. Openreach is retiring the analogue PSTN, with completion due around the end of January 2027, after which analogue and ISDN lines stop working. Any business still on those lines must migrate to an IP-based system such as UCaaS before the deadline to keep its phones running. --- # How VoIP Integrates with Microsoft 365 for Your Business URL: https://amvia.co.uk/business-voip/voip-microsoft-365 Last updated: 2026-07-21 VoIP and Microsoft 365 come together through Teams Phone, which adds external (PSTN) calling to Microsoft Teams. Staff make and receive business calls inside the app they already use for chat, video and files - no separate phone system. AMVIA configures, ports and manages the whole thing: one provider, security-first, Microsoft-certified. ## What does it mean to run VoIP through Microsoft 365? It means your phone system stops being a separate platform and becomes a feature of Microsoft 365. Microsoft Teams already handles internal calls, video meetings and chat; Teams Phone bolts on a calling layer to the public telephone network, so the same app dials any UK or international number. Every Microsoft 365 Business plan includes Teams, which is the most widely deployed collaboration platform in the world - over 320 million monthly active users globally (Microsoft, 2024). Teams Phone uses that existing footprint rather than asking staff to learn a second tool. There is no extra phone app, and no new hardware beyond the PCs, laptops and smartphones people already carry. This is the natural next step once you have adopted business VoIP solutions and want one accountable platform instead of two. - Dial and receive on any business number directly inside Teams - One set of credentials, one mobile app, one support contract - Voicemail, transfers, queues and call recording in the same interface ## How does Microsoft 365 connect to the phone network? Teams handles Teams-to-Teams calls over Microsoft's cloud natively. To reach external numbers it must connect to the public telephone network, and there are three ways to do that. The right one depends on your call volumes, number estate and how much infrastructure you want to manage. | | Connection method | How it works | Best for | Trade-off | Microsoft Calling Plans | Buy numbers and minutes direct from Microsoft | Small estates wanting fastest setup | Higher per-minute cost, limited UK number availability | Direct Routing | Teams connects to a third-party SIP trunk via a certified Session Border Controller | UK businesses with existing geographic numbers and higher call volumes | Needs SBC management - AMVIA runs this for you | Operator Connect | A Microsoft-certified operator (AMVIA is one) provisions calling inside the Teams admin centre | Businesses wanting carrier pricing without managing an SBC | Newer model, operator availability varies For most UK SMEs, Microsoft Teams Direct Routing wins on cost and number flexibility. Your existing numbers are ported to a SIP trunk provider and calls route through Teams via an Azure-certified Session Border Controller - the bridge that handles call setup, security and media conversion. AMVIA owns the SBC and carrier relationship as a fully managed service. Microsoft documents all three models in its Teams Phone deployment guidance. ## What Microsoft 365 licence do you need for Teams Phone? Teams Phone needs a Teams Phone Standard licence added to a Microsoft 365 plan that already includes Teams. The add-on typically costs around £7–10 per user per month (market rates as of 2026) and is only required for users who make external calls. People who only need internal Teams calls, meetings and chat do not need it. The add-on is included as standard in Microsoft 365 E5, but must be purchased separately on Business Basic, Business Standard, Business Premium, E1 and E3. Microsoft publishes its UK plan list prices - Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month (ex VAT, annual) - on the Microsoft 365 UK pricing pages. Even with the Phone System add-on, the combined cost is usually lower than running a standalone phone system alongside Microsoft 365. AMVIA reviews your licence estate and recommends the cheapest compliant configuration. ## Why do UK SMEs need this now? The UK PSTN is being switched off, and businesses still on ISDN have to move to a digital service before it goes. Doing that move through Microsoft 365 lets you retire the old lines and the old phone system in a single transition, instead of swapping one piece of legacy kit for another. The switch-off completes by 31 January 2027 (Openreach), and around 2.8 million lines still remain on the PSTN - more than 500,000 of them serving business premises (Openreach, 2026). You can read the regulator's own position on the migration on the Ofcom PSTN switch-off pages. For a business already living in Outlook, Teams, SharePoint and OneDrive, Teams Phone is usually the most cost-effective path off ISDN. AMVIA covers the deadline in detail on the PSTN switch-off guide. - Voicemail lands in your Teams and Outlook inbox, transcribed and searchable - Call history sits alongside chat history for each contact - Presence shows colleagues your availability before they call ## What features come with Teams Phone? Once Teams Phone is live with PSTN connectivity, UK businesses get a full enterprise calling feature set inside Teams. There is no separate handset platform to administer - everything is configured through the Teams admin centre and managed by AMVIA. - Inbound and outbound calling to any UK, mobile or international number on PC, Mac, iOS or Android - Auto-attendant greetings and menus that route callers to the right department - Call queues distributing calls by simultaneous ring, round-robin or longest idle - Voicemail with transcription delivered to Teams and Outlook - Call transfer, hold, park and conferencing, with one-click escalation to video - Call recording for compliance, training or quality assurance, stored in Microsoft's cloud - Desk phone support for Teams-certified IP handsets from Yealink, Poly, and AudioCodes Each concurrent call uses roughly 80–100 Kbps, so a stable, low-latency connection matters; Microsoft sets out the network requirements for Teams in its admin documentation. AMVIA assesses your connectivity before migration to confirm it supports peak call volumes. ## What should you plan before migrating? Treat the move as a project, not a switch flip. The technology is proven, but a clean cutover depends on getting licensing, numbers, call flow and connectivity lined up first. AMVIA runs this checklist on every Teams Phone deployment. - Verify the licence tier so every external caller has a Teams Phone Standard add-on - Choose the connectivity method - Direct Routing or Operator Connect usually beat Calling Plans on UK value - Plan number porting - moving geographic numbers to a Teams-compatible carrier takes 7 to 14 working days - Assess the internet connection for bandwidth and latency under peak load - Map existing call flow - auto-attendants, hunt groups, DDIs and voicemail - so Teams replicates it correctly - Configure 999 access with location information for every Teams Phone user Calling is also a security surface. Migrating telephony into Microsoft 365 means it inherits your identity and conditional-access controls, which is why we align it with VoIP security and your wider Microsoft 365 security posture rather than treating the phone system as a standalone box. ## Frequently asked questions Q: Can Microsoft Teams replace our phone system? A: Yes - Teams Phone adds external calling to the Teams your staff already use, with your business numbers, call queues and voicemail. Whether it should depends on cost and call profile: licensing typically adds £7–10 per user/month on top of your M365 plan, against hosted VoIP alternatives. Q: What does Teams Phone cost? A: The add-on licensing typically runs £7–10 per user/month on top of Microsoft 365 (plans themselves span £4.60–£16.90/user/month ex VAT), plus calling - Microsoft's bundled plans or cheaper SIP rates via Direct Routing. Model it against hosted VoIP from £5.95/user before deciding. Q: Do our numbers move into Teams? A: Yes - existing business numbers port into Teams Phone as standard (allow 5–15 working days), whether via Microsoft's calling plans or Direct Routing. Port before ceasing old lines, as with any migration. Q: Teams Phone or a dedicated VoIP platform - how do we choose? A: Teams-first organisations that live in Teams all day usually benefit from one app for everything. Businesses with heavy call-handling needs (reception-driven, high volume, contact-centre-ish) often find dedicated VoIP platforms stronger on pure telephony. AMVIA runs both, so the recommendation follows your call profile, not our product list. --- # VoIP Security: How to Protect Your Business Calls from Attack URL: https://amvia.co.uk/business-voip/voip-security Last updated: 2026-07-16 VoIP security is the set of controls that protect an internet-based phone system from toll fraud, call interception, SIP attacks and voice phishing. It combines encrypted call transport, strong SIP authentication, fraud monitoring and a session border controller. AMVIA delivers it as one security-first, Microsoft-certified managed service. Most UK businesses moving off the old phone network treat the switch to VoIP as a telecoms decision. It is a security decision. A voice system reachable over the internet is a server reachable over the internet - and attackers scan for it around the clock. This page sits under our business VoIP pillar and explains the threats, the controls, and where managed cybersecurity cover the gaps a typical installer leaves open. ## Why does VoIP security matter for UK businesses? VoIP is attacked because it offers something most cyberattacks do not: direct, immediate financial payoff. The Communications Fraud Control Association estimates global telecommunications fraud costs the industry around $38–40 billion annually (CFCA survey, market estimate as of 2026), with toll fraud a significant share. The UK's migration off the old PSTN network, due to complete by 31 January 2027, is widening the attack surface as more firms expose voice systems to the public internet. The risk is concentrated and fast. Unlike a slow data breach, a compromised phone system bleeds money in hours, usually overnight or across a weekend when no one is watching the call logs. - Toll fraud turns your phone system into someone else's revenue stream - SIP scanners probe internet-facing systems continuously, not occasionally - Unencrypted calls can be captured on shared or poorly segmented networks - Voice phishing targets your staff, not your switchboard ## What are the main VoIP security threats? The four threats that matter for UK SMEs are toll fraud, SIP scanning, call interception and vishing. Each has a clear technical control and, in the case of vishing, a human one. Treating them together - voice plus the wider security stack - is what separates a managed service from a phone install. ## How does toll fraud work, and how do you stop it? Toll fraud (international revenue share fraud) happens when attackers gain VoIP access through brute-force attacks, credential stuffing or default-password exploitation, then place large volumes of calls to premium-rate international destinations they profit from. "An undetected attack running for 48 hours over a weekend...can generate bills of tens of thousands of pounds." Single weekend attacks producing losses above £50,000 have been documented in UK cases (typical 2026 range). Prevention requires layered controls: - Strong, unique passwords on every SIP account - Failed-authentication alerting with automatic lockout - Blocking calls to high-risk international destinations by default - Daily and weekly spend limits with automatic cut-offs - Real-time monitoring for unusual call patterns, not month-end invoice review ## What is SIP scanning, and how is it blocked? SIP scanning is the automated probing of internet-facing IP addresses to find VoIP systems and test default credentials. Tools such as SIPVicious are freely available, so this is constant background noise on any exposed system. Protection means never exposing SIP ports directly to the public internet, enforcing strong non-default passwords of at least 16 characters, configuring fail2ban-equivalent brute-force protection, and restricting SIP registration to known IP ranges. ## Can business calls be intercepted or overheard? Yes. Unencrypted VoIP calls can be captured on shared network segments - a real risk for businesses using shared or public Wi-Fi, poorly segmented guest networks, or already-compromised internal networks. The fix is to enable SRTP, which encrypts the voice content, and TLS, which encrypts the SIP signalling, on every business VoIP system. Treat an unencrypted call the same way you would treat a plain-text password. ## How does vishing target your staff? Vishing - voice phishing - uses phone calls to manipulate staff into disclosing credentials, authorising payments or granting system access, with attackers impersonating HMRC, banks, IT support, couriers or senior management. STIR/SHAKEN caller authentication and call filtering block many spoofed numbers, but the decisive control is human. As the NCSC's phishing guidance makes clear, staff awareness is a primary defence: legitimate IT, banks and HMRC never request passwords on unsolicited calls. Our anti-phishing and managed cybersecurity services cover this training alongside the technical filtering. ## What does a session border controller do for VoIP security? A session border controller (SBC) is a network device that sits at the boundary between your internal VoIP network and the public internet. It hides internal VoIP topology from external probing, enforces access control on SIP traffic, defends against SIP-based denial-of-service attacks, handles NAT traversal, and enforces encryption policy. For any deployment involving SIP trunking or Direct Routing to platforms such as Microsoft Teams, an SBC should be treated as essential infrastructure rather than optional. If you are connecting a hosted phone system to the wider internet, the SBC is the front door - and it should be locked. Denial-of-service attacks against VoIP infrastructure overwhelm SIP services or your internet connection with malicious traffic, potentially taking the phone system fully offline. SBC-level rate limiting, firewall rules restricting SIP to known sources, bandwidth management and disaster-recovery call routing to mobiles or alternative sites keep calls flowing under attack. ## In-house DIY versus AMVIA managed VoIP security A phone installer configures call routing. A security partner configures defences. The difference shows up the first time someone scans your system at 2am on a Saturday. | | VoIP security control | Typical DIY / installer setup | AMVIA managed VoIP security | SIP authentication | Default or weak passwords | Strong unique credentials, brute-force lockout | Call encryption | Often left off | SRTP + TLS enforced on every endpoint | Toll-fraud detection | Spotted on the next invoice | Real-time alerts and automatic blocks | Internet exposure | SIP port open to the world | SBC and firewall restrict to known sources | Vishing defence | None | Staff awareness training + call filtering | Monitoring | None | Continuous, tied to the wider security stack ## What are the VoIP security best practices for UK SMEs? The baseline below closes the gaps attackers exploit most. None of it is exotic; the failure is almost always that no one owns it. That ownership is the point of a managed service. - Change all default SIP passwords immediately - at least 16 characters mixing letters, numbers and symbols - Enable SRTP and TLS on your VoIP platform - unencrypted voice is plain-text risk - Deploy a session border controller - never expose a PBX/VoIP SIP interface directly to the internet - Set international call limits and spend caps with alerts and automatic blocks - Implement real-time fraud monitoring rather than waiting for the monthly bill - Segment your voice network onto a separate VLAN from general data traffic - Train finance, reception and PA staff on vishing at regular intervals - Patch VoIP firmware and software with the same discipline as servers and workstations Ofcom's guidance on the PSTN switch-off is a useful reference point for planning the move, but the switch is the moment to get these controls in place - not after the first fraudulent bill. ## How does AMVIA secure business VoIP? AMVIA delivers VoIP security as part of one accountable managed service, not a bolt-on. We harden SIP authentication, enforce encrypted call transport, deploy and manage the SBC, and run continuous toll-fraud detection - then connect it all to the same security operations that protect your Microsoft 365 and endpoints. One provider, security-first, Microsoft-certified engineers. That single-provider model matters: when voice, network and identity are watched together, an unusual call pattern is read in context rather than in isolation. For most SMEs that is the difference between catching fraud in minutes and discovering it on the invoice. ## Frequently asked questions Q: Can VoIP phone systems be hacked? A: Yes - the classic attack is toll fraud: criminals compromise a system or account and pump premium-rate calls through it, with losses that can reach tens of thousands (industry cases run to £50,000+) before anyone reads the bill. SIP attacks and call interception are rarer but real. Q: What is toll fraud and how do we prevent it? A: Attackers use your phone system to route expensive calls they profit from. Prevention is unglamorous and effective: strong credentials and MFA on the platform, international and premium-rate calling restricted by policy, rate limits, and monitoring that flags abnormal call patterns fast. Q: Are VoIP calls encrypted? A: On a properly configured business platform, yes - signalling and media encrypted in transit (TLS/SRTP). The qualifier matters: defaults vary by provider, which is why VoIP security is a configuration discipline, not a product feature you can assume. Q: Who is responsible for VoIP security - us or the provider? A: Both, with a boundary: the provider secures the platform; you (or your managed provider) secure the accounts, devices and calling policies. When AMVIA runs the phones, the connectivity and the security together, that boundary stops being a gap. --- # How Much Does Business VoIP Cost in the UK? (2026 Prices) URL: https://amvia.co.uk/business-voip/questions/business-voip-cost Last updated: 2026-03 Business VoIP in the UK costs from £5.95 per user per month, with UK landline and mobile calls included - far less than ISDN line rental at £25–£50 per channel. Setup depends on number porting and handsets. AMVIA quotes one fixed monthly price: one provider, security-first, Microsoft-certified. If you are scoping a switch, start with our business VoIP pillar for how the pieces fit together, then read on for the real numbers, the costs providers hide, and where the savings actually come from. ## How much does business VoIP cost per user in the UK? Most UK hosted VoIP plans are billed per user per month, from £5.95 depending on the features you need. That single line item usually covers the call plan, the phone number, the app, and the management portal - there is no separate "line rental" the way ISDN charged it. Price scales with capability, not with how many calls you make: - Entry tier (lower end): unlimited UK landline and mobile calls, voicemail-to-email, a softphone or mobile app, call forwarding, and basic reporting. - Mid tier: auto-attendant, call queues, hunt groups, and integration with Microsoft Teams or a CRM. - Premium tier: call recording with storage, wallboard analytics, and supervisor tools for contact-centre-style teams. A 20-person business on a mid-tier plan is therefore looking at a predictable monthly figure rather than the unpredictable per-channel-plus-call-charges model ISDN forced on you. For the system itself, see our hosted phone system breakdown. ## What's included in a typical per-user VoIP price? A hosted VoIP licence from £5.95/user/month normally bundles unlimited UK calls, voicemail-to-email, a softphone or mobile app, call forwarding, and basic call reporting. Premium tiers add call recording, CRM integration, and analytics. Hardware is the main thing billed separately. What you should expect inside the licence: - Unlimited UK landline and mobile calls (check the fair-use cap in the contract). - A geographic or non-geographic number, plus free number porting in most cases. - Desktop and mobile apps so staff can work from anywhere on the same number. - An admin portal to add users, change call routing, and pull basic reports. Cloud calling has moved firmly into the mainstream, and Teams Phone is a big part of that shift. If your team already lives in Teams, calling can sit inside the same licence stack - see Microsoft Teams calling. ## What are the hidden costs of switching to VoIP? The recurring per-user price is rarely the whole story. The usual extras are IP desk phones at £50–£150 each (typical UK 2026 range), number porting fees (often waived), and - occasionally - a connectivity upgrade so voice traffic stays clean. A few providers also charge for recording storage or premium support. | | Cost item | Typical range | When it applies | Per-user licence | from £5.95/user/mo | Always - the core monthly cost | IP desk phone | £50–£150 each (2026 range) | Only if staff want physical handsets | Number porting | Often £0 | Moving existing numbers across | Connectivity upgrade | Varies | If your line can't carry voice reliably | Call recording storage | Add-on | Compliance or quality monitoring The fix is to ask for a fully-costed quote, not a headline per-user rate. AMVIA quotes a single fixed monthly figure with no hidden charges, so the number you sign for is the number you pay. Reliable calls also depend on a stable connection - if your office runs on contended broadband, weigh up a dedicated line, and treat call traffic as something to protect: see VoIP security. ## How does VoIP pricing compare to ISDN line rental? ISDN charged £25–£50 per channel (typical UK 2026 range) before a single call, and each channel carried only one simultaneous call. VoIP folds calls into the per-user licence and gives every user multiple concurrent lines, which is why providers quote savings of up to 70% versus ISDN line rental (2026 UK market data). | | Factor | ISDN | Hosted VoIP | Pricing model | Per channel + call charges | Per user, calls included | Indicative cost | £25–£50 per channel | from £5.95 per user/mo | Simultaneous calls | One per channel | Multiple per user | Remote/mobile working | No | Yes - app on any device | Future-proof | Being switched off | Standard going forward There is also a hard deadline driving the maths. The UK's old PSTN and ISDN network is being retired, with the switch-off scheduled for 31 January 2027, after which traditional line rental simply stops being sold or supported - see Ofcom's guidance on the move away from analogue phone lines. Our PSTN switch-off guide covers the migration timeline in full. ## Does Microsoft Teams count as business VoIP - and what does it cost? Yes - Microsoft Teams becomes a full business phone system once you add a calling plan or connect it to the public network. The cost is your existing Microsoft 365 licence plus a calling component, so for Teams-first businesses it can be cheaper than running a separate VoIP platform. Microsoft 365 Business Standard is £9.60 per user per month (ex VAT, annual) per Microsoft's UK pricing, and Teams Phone capability is added on top via a calling plan or a direct-routing connection. Direct routing - bringing your own SIP service into Teams - is often the cheaper route at scale. For most SMEs the decision comes down to whether you want telephony inside Microsoft 365 or as a standalone platform. Our team can map it to your licences and your call volumes through the managed Microsoft 365 service, and the SIP-trunk option is covered in SIP trunking. ## How much can VoIP actually save your business? Savings come from three places: scrapping per-channel line rental, cutting per-minute UK call charges to near-zero, and removing on-site PBX maintenance. For most small businesses the result is materially lower monthly telephony spend than traditional lines. The bigger return is often operational rather than purely on the bill. One number that follows staff to mobile, app, and desk means fewer missed calls. With PSTN lines down to 19% of UK landline connections (Ofcom Connected Nations 2025) and the switch-off fixed for 2027, the question is no longer whether to move, but how cleanly. ## Frequently asked questions Q: What is the average cost of business VoIP per user in the UK? A: Most UK hosted VoIP plans start from £5.95 per user per month, billed as a single line item that includes UK landline and mobile calls. The lower end covers core calling and apps; the higher end adds call recording, analytics, and CRM integration. Hardware such as desk phones is priced separately. Q: Are there hidden costs when switching to VoIP? A: The main extras are IP desk phones at £50–£150 each (typical UK 2026 range) if staff want physical handsets, number porting (usually free), and occasionally a connectivity upgrade so voice traffic stays reliable. Some providers also bill for recording storage or premium support. Ask for a fully-costed quote up front so the monthly figure you sign for is the figure you actually pay. Q: How does VoIP compare to ISDN line rental on price? A: ISDN charged £25–£50 per channel (typical UK 2026 range) before any call charges, with each channel carrying one call at a time. VoIP includes calls in a per-user licence and supports multiple simultaneous calls, which is why providers cite savings of up to 70% versus ISDN (2026 UK market data). ISDN pricing is also becoming irrelevant as the network is retired. Q: When is the UK PSTN being switched off? A: The UK's analogue PSTN and ISDN network is being retired, with the switch-off scheduled for 31 January 2027. After that date, traditional phone lines are no longer sold or supported and calls move to digital, internet-based services. Ofcom publishes guidance on the migration and what businesses need to do to prepare. Q: Can Microsoft Teams replace a separate VoIP phone system? A: Yes. With a calling plan or direct-routing connection, Microsoft Teams works as a full business phone system. You pay for your Microsoft 365 licence - Business Standard is £9.60 per user per month ex VAT - plus a calling component. For Teams-first businesses, this is often cheaper than running a standalone VoIP platform alongside Microsoft 365. Q: Do I need to upgrade my internet for VoIP? A: Not always, but voice quality depends on a stable, low-latency connection. A single VoIP call uses little bandwidth, yet contended or unreliable broadband causes dropouts under load. If your office already struggles with video calls, a dedicated or business-grade connection is worth costing in. A quick line check before migration avoids quality complaints later. --- # Is VoIP Cheaper Than a Landline for Businesses? URL: https://amvia.co.uk/business-voip/questions/voip-vs-landline-cost Last updated: 2026-03 VoIP is consistently cheaper than a traditional landline for UK businesses. Cloud-hosted VoIP runs from £5.95 per user per month against £15–£35 per PSTN line in rental alone, before a single call. Most firms cut total communications spend by 40–60% after switching - and with the PSTN switch-off landing in 2027, the decision is now a deadline, not a choice. AMVIA runs this migration end to end: one provider, security-first, Microsoft-certified. If you are weighing the move, start with the business VoIP pillar for the full picture, then use this page to pressure-test the numbers. ## Is VoIP actually cheaper than a landline? Yes - in almost every realistic business scenario VoIP costs less than a landline. PSTN line rental is a fixed monthly charge per channel before you make a call, while VoIP bundles inclusive calls into a single per-user fee. Once you account for line rental, ISDN channels and per-minute charges, the gap widens fast. Here is the core comparison most UK buyers care about: | | Cost factor | Traditional landline (PSTN/ISDN) | Cloud VoIP | Monthly cost | £15–£35 per line/channel | from £5.95 per user | Inclusive calls | Usually charged per minute | Typically included | Line rental | Required per channel | None - uses your internet | Hardware | Desk phones + on-site PBX | Softphone (free) or IP handset | New sites/users | Engineer visit, new lines | Added in software, minutes | Future-proof | Retired by 2027 | The replacement standard The landline column is shrinking by design. Openreach is withdrawing the PSTN, so paying to maintain legacy lines is paying to keep a service with a published end date. ## How much can a business save by switching to VoIP? Most businesses cut total telephony spend materially after moving to VoIP, once inclusive calls replace per-minute ISDN charges and line rental disappears. The saving comes from removing line rental, consolidating providers, and scaling users in software rather than via engineer visits. A worked example makes it concrete. A 20-user business paying around £600 a month on ISDN line rental and call charges could expect to land in the £200–£300 range on a comparable hosted VoIP plan with calls included. Small businesses typically see 25–50% lower costs than the equivalent traditional setup. Where the saving lands depends on three things: - Call volume - heavy outbound callers gain most from inclusive minutes. - Number of sites - multi-site firms stop paying per-line at every location. See multi-site VoIP for how that consolidates. - Existing connectivity - if you already run business broadband or a leased line, VoIP adds no new line cost. ## Are there any costs where a landline wins? Rarely, and the exceptions are narrow. A landline needs no internet connection, so in theory a single-line, very-low-call-volume premises with no broadband avoids a connectivity cost. In practice almost every business already pays for internet to run email, Microsoft 365 and cloud apps, which makes that "saving" theoretical. The honest position: for a one-line site that barely makes calls and has no internet, a basic landline can look marginally cheaper on paper. For everyone else - anyone with staff, multiple lines, or existing broadband - VoIP matches or beats the landline once inclusive calls are counted. And the comparison is academic anyway once the PSTN is gone. ## What is the PSTN switch-off and why does it change the maths? The Public Switched Telephone Network (PSTN) - the copper phone network behind traditional landlines and ISDN - is being retired. Openreach's published target for completing the migration is 31 January 2027, after which voice services move to IP (VoIP) by default (Ofcom). This reframes the whole cost question. You are not choosing whether to keep a landline versus adopt VoIP - you are choosing whether to migrate on your own timetable or be forced onto it. The majority of UK landlines have already moved to digital, with PSTN down to 19% of connections (Ofcom Connected Nations 2025). Migrating early means you control the project, test the setup, and capture the savings sooner rather than scrambling against a deadline. ## Do I need to buy new phones to switch to VoIP? Not necessarily. VoIP softphones run on the computers and mobiles your team already use, at zero hardware cost. If you prefer physical desk phones, IP handsets range from around £50 for basic models to £150 for feature-rich units (typical UK 2026 prices) - a one-off cost, not the recurring PBX maintenance a landline system demands. Many businesses skip handsets entirely. With Microsoft Teams Phone, most users make and take calls straight from a laptop or phone. If you already pay for Microsoft 365, running Teams as your phone system is often the lowest-friction route - Microsoft 365 Business plans start at £4.60/user/mo (Basic), £9.60 (Standard) and £16.90 (Premium) ex VAT on an annual commitment (Microsoft), with a Teams Phone licence added on top to enable external calling (Microsoft Teams Phone). ## What hidden costs should you check before switching? The headline per-user price is rarely the whole story. Poor communication already costs businesses real money - so the goal is a system that is cheaper *and* better, not a cut-price setup that drops calls. Watch for these line items when you compare quotes: - Number porting - moving existing numbers; usually a small one-off fee. - Call bundles vs pay-as-you-go - confirm what "inclusive" actually covers. - Connectivity quality - VoIP voice quality depends on your internet; congested broadband causes jitter. - Security - VoIP is internet-facing, so it needs protection like any other service. Read VoIP security before you go live. A genuine like-for-like comparison counts line rental, call charges, hardware, support and porting together - not just the sticker price per user. ## Why does AMVIA recommend a hosted VoIP system? For most UK SMEs, a hosted phone system gives the cleanest cost and lowest risk: no on-site PBX to maintain, predictable per-user pricing, and a setup that scales with headcount instead of engineer call-outs. It also aligns your voice estate with the same Microsoft tooling AMVIA already secures. The differentiator matters here. With AMVIA you get one provider accountable for connectivity, voice and the security wrapped around it - Microsoft-certified engineers configuring it, and a security-first posture by default. That removes the finger-pointing that happens when telephony, IT and security all sit with different suppliers. ## Frequently asked questions Q: How much cheaper is VoIP than a landline in real terms? A: Hosted VoIP runs from £5.95 per user/month against £15–£35 per traditional line before call charges - and VoIP's inclusive calling typically removes most of the call bill too. Across a 10-person office the annual difference is four figures. Q: Are there hidden costs when switching from landlines to VoIP? A: Fewer than people fear: number porting is low-cost, softphone apps are typically included, and desk handsets are optional. The genuine consideration is bandwidth - VoIP needs a solid connection, so budget the phones and the line together. Q: Do landlines even remain an option? A: Not for long - the PSTN switch-off retires analogue lines on 31 January 2027, so the landline column of this comparison has an end date. The real decision is which VoIP platform, not whether. Q: Is call quality worse on VoIP? A: On adequate bandwidth, no - business VoIP on a decent connection matches or beats analogue quality. Problems trace almost exclusively to congested internet lines, which is a connectivity fix, not a reason to stay on copper. --- # What Internet Speed Do I Need for Business VoIP? URL: https://amvia.co.uk/business-voip/questions/what-internet-speed-for-voip Last updated: 2026-03 For business VoIP, each concurrent call needs roughly 85–100 Kbps, so a 10-person office running five simultaneous calls needs about 500 Kbps for voice. Raw download speed rarely matters; low latency and jitter do. AMVIA pairs hosted voice with QoS-managed connectivity under one security-first, Microsoft-certified provider. Most businesses ask "what internet speed for VoIP" expecting a big number. The honest answer is that almost any modern connection has the headroom - what wrecks call quality is congestion, jitter and asymmetric upload, not a low Mbps figure. This guide gives the real numbers, the thresholds that matter, and when to move from broadband to a leased line. It sits under our business VoIP pillar, where you can see how the whole phone system fits together. ## How much bandwidth does a single VoIP call actually use? A single VoIP call uses roughly 85–100 Kbps in each direction on the G.711 codec, or about 30 Kbps on the more compressed G.729 codec. That is a fraction of any business connection. For a 20-person office with up to 10 simultaneous calls, you need around 1 Mbps reserved for voice - trivial against typical UK broadband. Ofcom's Connected Nations 2024 report puts the average UK broadband download speed at 69.4 Mbps, so raw bandwidth is almost never the bottleneck for voice (Ofcom). The number that breaks calls is not Mbps - it is how cleanly each small voice packet arrives. ## Why do latency and jitter matter more than raw speed? Voice is real-time, so timing beats volume. VoIP needs one-way latency below roughly 150ms and jitter below about 30ms for clean calls. Past those thresholds you hear delay, talk-over and robotic, choppy audio - even on a fast line that looks healthy in a speed test. - Latency - the delay between speaking and being heard. High latency causes that awkward "you go… no, you go" overlap. - Jitter - variation in packet arrival time. High jitter scrambles the order voice packets play back in, causing gaps and warble. - Packet loss - dropped packets the codec cannot rebuild, heard as clipped words. A speed test cannot see any of this. That is why a 900 Mbps shared broadband line can sound worse than a modest, well-managed connection: the shared line spikes in latency and jitter under load, and voice is the first thing to suffer. ## How much total internet speed does my business need for VoIP? Size your connection by concurrent calls, not headcount. Most offices peak at far fewer simultaneous calls than people. Multiply your busiest-hour concurrent calls by about 100 Kbps for voice, then leave generous room for everything else on the line - email, cloud apps, backups and video. | | Office size | Typical concurrent calls | Voice bandwidth needed | Recommended connectivity | Small (1–10 staff) | 2–5 | ~0.5 Mbps | Business broadband with QoS | Medium (10–50 staff) | 5–15 | ~1.5 Mbps | FTTP or leased line | Large (50+ staff) | 15+ | 3 Mbps+ | Leased line with QoS Bandwidth figures assume roughly 100 Kbps per concurrent call and exclude other traffic. The takeaway: the voice requirement is tiny, so the real decision is connection *quality* and *symmetry*, not picking a bigger speed tier. For multiple sites, our multi-site VoIP approach keeps quality consistent across every location. ## Why is upload speed critical for VoIP call quality? VoIP sends voice in both directions, so upload matters as much as download. Standard broadband is asymmetric - upload is often a fraction of download - and when a cloud backup or large file transfer saturates that upload, call quality collapses while your download still looks fine. This is the single most common cause of "our internet is fast but calls keep breaking up." A symmetrical connection such as a leased line gives upload equal to download, so voice has reliable headroom regardless of what else is uploading. If you are weighing the options, our guide to what a leased line is explains the symmetry difference in plain terms. ## Do I need a leased line or will business broadband do? For most small offices with light call volumes, FTTP or fibre broadband with QoS is fine. Once you have heavy concurrent call volumes, multiple sites, or calls that directly drive revenue, a leased line becomes the right call - it is uncontended, symmetrical, and comes with a guaranteed service level. - Choose broadband when: under ~10 concurrent calls, single site, occasional file transfers. - Choose a leased line when: consistent high call volumes, contact-centre or sales-floor usage, multi-site voice, or zero tolerance for downtime. A leased line is typically backed by a 99.99% uptime SLA and can carry carrier-level QoS so voice packets are prioritised across the network, not just inside your office. For larger estates, SD-WAN can blend multiple links and steer voice onto the cleanest path automatically. ## What is QoS and does my router need it for VoIP? Quality of Service (QoS) is a network setting that prioritises voice traffic over less time-sensitive data like downloads, backups and web browsing. Without it, one large upload can starve your calls of capacity for a few critical seconds, and you hear it instantly as broken audio. On business broadband, QoS lives in your router and only controls your own LAN. On a leased line, QoS can be enforced at the carrier level, so voice packets keep priority across the whole path. If voice runs through Microsoft Teams or a hosted phone system, getting QoS right is what separates "usable" from "boardroom-grade." ## How does the PSTN switch-off change my VoIP bandwidth planning? The UK's analogue phone network (PSTN) is being retired, with the industry switch-off scheduled for 31 January 2027 - every business line must move to VoIP before then (Ofcom). That makes connection quality a board-level issue, not an IT detail, because your phones now depend entirely on your internet. Industry figures suggest the majority of UK landlines have already migrated to digital voice (industry data, 2026), and adoption is accelerating. Plan the move early: audit your upload, confirm QoS, and decide broadband-versus-leased-line before you are forced to. Our PSTN switch-off guide walks through the deadline and the migration steps. ## What about security once your phones run over the internet? When voice runs over your data network, it inherits your network's risk: toll fraud, call interception and denial-of-service all become possibilities. Securing the connection is now part of securing the phone system, which is why we treat VoIP and security as one job, not two. Good practice - strong SIP credentials, encryption, segmentation and monitoring - keeps voice traffic protected. The NCSC publishes practical guidance on securing business communications and networks (NCSC). For the specifics of locking down hosted voice, see our VoIP security guidance. ## Frequently asked questions Q: How much bandwidth does a single VoIP call use? A: A single VoIP call uses roughly 85–100 Kbps in each direction on the G.711 codec, or about 30 Kbps on the compressed G.729 codec. For a 20-person office with up to 10 simultaneous calls, allow around 1 Mbps for voice. Against an average UK broadband speed of 69.4 Mbps (Ofcom Connected Nations 2024), raw bandwidth is rarely the limiting factor - latency and jitter are. Q: What is a good latency and jitter for VoIP? A: Aim for one-way latency below roughly 150ms and jitter below about 30ms for clean, business-grade calls. Beyond those thresholds you hear delay, overlap and choppy audio. A standard speed test cannot measure latency or jitter under load, so a fast-looking connection can still deliver poor voice quality during busy periods. Q: Why does my internet test fast but VoIP still breaks up? A: Almost always, the cause is a saturated upload or spikes in jitter, not low download speed. Cloud backups and large file transfers can congest your upload and starve voice of capacity in seconds. A symmetrical leased line and properly configured QoS fix this by guaranteeing voice gets priority regardless of other traffic. Q: Do I need a leased line for VoIP? A: Not for light use - FTTP or fibre broadband with QoS handles small offices well. A leased line becomes worthwhile once you have heavy concurrent call volumes, multiple sites, or revenue-critical calls, because it is uncontended, symmetrical, and backed by a guaranteed service level. The decision is about call importance and volume, not headcount. Q: How many simultaneous VoIP calls can my connection handle? A: Divide your reserved voice bandwidth by roughly 100 Kbps per call. A 10 Mbps slice dedicated to voice supports around 100 concurrent calls in theory, but in practice latency, jitter and upload headroom set the real ceiling well before bandwidth does. Always size on busiest-hour concurrent calls, then leave room for everything else on the line. Q: Does the PSTN switch-off mean I have to move to VoIP? A: Yes. The analogue PSTN is being retired, with the industry switch-off scheduled for 31 January 2027, so every UK business line must move to digital voice before then (Ofcom). Plan ahead: check your upload speed, confirm QoS, and decide between broadband and a leased line so call quality is sorted before the deadline forces the issue. --- # VoIP vs Traditional Landline: Which Is Best for UK Businesses? URL: https://amvia.co.uk/business-voip/compare/voip-vs-landline Last updated: 2026-03 For nearly every UK business, VoIP beats a traditional landline on cost, features and flexibility - and with the PSTN switch-off completing in 2027, analogue lines are being retired anyway. The question is not whether to move, but how to migrate without losing numbers or call quality. AMVIA runs the switchover with zero downtime. ## VoIP vs landline: what is the actual difference? A landline carries your call over the copper Public Switched Telephone Network (PSTN). VoIP carries the same call as data over your internet connection. That single change is what enables lower line costs, mobile and desktop apps, and multi-site working - and it is why our business VoIP team treats VoIP as the default for any UK SME, not a nice-to-have. The practical differences show up in the bill and in what each system can do: | | Feature | VoIP (from £5.95/user/mo) | Landline (£15–£30/line + calls) | Monthly cost | Lower, per user | Higher, per physical line | Call recording | Included | Paid add-on | Mobile / desktop app | Yes | No | Remote / hybrid working | Built in | Not supported | CRM integration | Yes | No | Auto-attendant & IVR | Included | Paid add-on | Multi-site working | One system, any location | Separate lines per site | Future-proof | Yes | No - PSTN retiring in 2027 The honest summary: a landline does one thing - connect a fixed handset to a phone number. VoIP does that plus everything a modern, hybrid workforce expects, usually for less money per user. ## How much does VoIP actually save compared to a landline? Most businesses save 40–60% on telephony costs after switching to VoIP (typical UK 2026 range), because VoIP is priced per user with UK calls bundled, while landlines charge per physical line plus per-minute call rates. The bigger the team and the more sites you run, the wider the gap. Worked example for a typical 20-user office: - VoIP: from £5.95 per user per month, calls included, call recording and apps bundled. - Landline: £15–£30 per line per month, plus per-minute charges, plus paid add-ons for recording and IVR. On top of the line saving, VoIP removes the cost of physically cabling new desks or sites - you add a user in software, not with an engineer visit. Compare a hosted setup in detail on our hosted phone system page before you size your plan. ## Is VoIP call quality as good as a landline? On a stable connection, VoIP quality matches or beats a landline, because VoIP supports HD voice codecs that the analogue PSTN never could. Quality only suffers when the underlying internet connection is congested or unreliable - which is a connectivity problem, not a VoIP problem. UK fixed broadband averaged a 69.4 Mbps download speed (Ofcom, Connected Nations 2024), which comfortably carries dozens of simultaneous VoIP calls - a single HD call uses under 0.1 Mbps. If your office runs a shaky line or you cannot tolerate a single dropped call, put VoIP over a dedicated internet leased line so voice gets guaranteed, uncontended bandwidth. What protects quality in practice: - A business-grade connection with headroom, not a consumer line shared with everything else. - QoS rules that prioritise voice traffic over downloads and backups. - A provider who actually configures the network, not just ships you handsets. ## Why are UK landlines being switched off in 2027? The PSTN is being retired nationally, so every business still on analogue or ISDN lines must move to an IP-based phone system. Openreach is closing the old network, with the industry switch-off targeted for 31 January 2027; after that, traditional landlines simply stop working. PSTN lines now account for 19% of UK landline connections, down from 27% in 2024 (Ofcom Connected Nations 2025), and every business behind them will need to migrate. Ofcom's guidance on the future of landline calls confirms the move from analogue to digital voice is happening across the whole country, not just for early adopters. The risk of waiting is not technical - it is commercial: number-porting queues, engineer availability and last-minute pricing all get worse as the deadline nears. Our PSTN switch-off guide breaks down the timeline and what to do first. ## Which businesses should still keep a landline? Very few. A landline only makes sense as a temporary fallback where a site has genuinely no reliable broadband, or for specific legacy equipment - lift lines, alarm panels, some PDQ card machines - that has not yet been certified for IP. Even then, these are being re-engineered for digital, not preserved. To be balanced: if your broadband is poor and cannot be upgraded quickly, a rushed VoIP move can hurt call quality. The right answer there is to fix the connection first - or run a leased line - rather than stay on a network that is being switched off regardless. For anyone with a sound connection, there is no business case left for analogue. ## How does AMVIA migrate you from landline to VoIP? We port your existing numbers, supply handsets or softphones, configure call routing, and cut over without downtime on your live numbers. One provider owns the whole switchover, so there is no finger-pointing between your line provider and your phone supplier when something needs fixing. Where AMVIA fits a UK SME: - Number porting of every existing geographic and non-geographic number, with no loss of identity. - Multi-site rollouts run as one system - see multi-site VoIP for branch and home-worker setups. - Microsoft-native calling if you live in Teams - we set up Microsoft Teams Direct Routing so Teams becomes your phone system. - Security-first by default: VoIP is an internet service and needs hardening, which is why we treat VoIP security as part of the build, not an afterthought. One provider. Security-first. Microsoft-certified. That is how we keep a migration boring - which, when it is your phone system, is exactly what you want. ## Frequently asked questions Q: How much can I save by switching from a landline to VoIP? A: VoIP is priced per user with UK calls bundled, while landlines charge per line plus per-minute rates and paid add-ons. Most UK businesses cut telephony costs by 40–60% after switching, and the saving grows with team size and number of sites because you add users in software rather than paying for new physical lines. Q: Do I have to leave my landline before 2027? A: Yes. The PSTN is being switched off nationally, with the industry target around the end of January 2027, after which analogue and ISDN lines stop working. Migrating early - rather than in the final rush - means easier number porting, better engineer availability and no last-minute price pressure. Treat it as a planned project, not an emergency. Q: Will VoIP call quality be worse than my landline? A: Not on a sound connection. VoIP supports HD voice codecs the analogue network never had, and a single call uses under 0.1 Mbps. UK fixed broadband averaged 69.4 Mbps in 2024 (Ofcom), which carries many simultaneous calls comfortably. Quality only drops on congested or unreliable internet, which is fixed with a better connection or a leased line. Q: Can I keep my existing phone numbers when I move to VoIP? A: Yes. AMVIA ports your existing geographic and non-geographic numbers across to the VoIP platform, so customers keep dialling the same number. Porting is planned so your live numbers stay working throughout the switchover, with no downtime on the day of cutover. You keep your business identity and lose nothing on the move. Q: What features does VoIP give me that a landline cannot? A: VoIP includes call recording, auto-attendant and IVR, mobile and desktop softphone apps, CRM integration, call analytics and true multi-site working - features landlines either cannot provide or charge a premium for. Remote and hybrid staff use the same business number from any location, which a fixed analogue line cannot support without costly call-forwarding workarounds. Q: Is VoIP secure for business use? A: VoIP runs over the internet, so it needs the same hardening as any other internet service: strong authentication, fraud monitoring, encryption and sensible call-barring. Handled properly it is as secure as any business system. AMVIA builds security into every VoIP deployment rather than bolting it on later, which closes the gaps attackers look for in voice services. --- # Microsoft Teams Phone vs Zoom Phone: Which Is Best for UK SMEs? URL: https://amvia.co.uk/business-voip/compare/teams-vs-zoom-phone Last updated: 2026-03 For most UK SMEs already on Microsoft 365, Teams Phone is the better fit: it adds PSTN calling inside the app your team uses all day, with no second platform to license, learn, or secure. Zoom Phone wins only where Zoom is already the daily collaboration tool. AMVIA delivers either, security-first, as a single accountable provider. This is a genuine comparison, not a sales pitch. Both platforms are mature, both carry UK numbers, and both are valid replacements for the analogue lines being withdrawn. The decision turns on which collaboration suite your staff already live in and how you want calling, security, and admin consolidated. If you are weighing up business VoIP options for the first time, start with the question of where your team already works. ## What's the real difference between Teams Phone and Zoom Phone? Teams Phone and Zoom Phone both turn an internet connection into a full business phone system. The difference is the suite each is built around: Teams Phone embeds calling into Microsoft 365, while Zoom Phone bolts onto the Zoom meetings platform. For a Microsoft-centric business, that integration decides which one is simpler to run. Teams Phone lives inside the same desktop and mobile app your staff use for chat, meetings, and file sharing. Zoom Phone is strong, but it assumes Zoom is your collaboration hub - if it is not, you carry two apps and two admin consoles. The cleanest route into Teams calling for most SMEs is Microsoft Teams Direct Routing, which connects UK PSTN calling to Teams without Microsoft's own Calling Plans. | | Factor | Microsoft Teams Phone | Zoom Phone | Built around | Microsoft 365 / Teams | Zoom meetings platform | Best for | M365-centric businesses | Zoom-centric businesses | App footprint | One app (Teams) | Separate Zoom app + console | UK PSTN calling | Direct Routing or Calling Plans | Zoom-provided or BYOC | Admin | Microsoft 365 admin centre | Separate Zoom admin | Security model | Microsoft Entra ID, Defender | Zoom-native controls Microsoft documents the Direct Routing architecture and supported session border controllers in its official guidance (learn.microsoft.com), which is worth reviewing before any migration. ## How do Teams Phone and Zoom Phone compare on cost? Cost depends on what you already pay for. If you hold Microsoft 365 Business licences, Teams Phone adds calling on top of software you own; Zoom Phone adds a new line item on a platform you may not. The per-user calling fee matters less than whether you are paying twice for overlapping tools. Microsoft 365 Business licences run from £4.60 per user per month (Business Basic) to £16.90 (Business Premium), ex VAT on an annual plan, per Microsoft's UK pricing (microsoft.com/en-gb). Calling is then layered on. Through a provider like AMVIA, Teams Direct Routing typically costs from £5.95 per user per month, and your team already has the Teams desktop and mobile app. Zoom Phone requires a separate licence at £10 to £15 per user per month, plus a separate application to deploy and secure. - Already on Microsoft 365? Teams Phone avoids buying into a second platform. - Already standardised on Zoom? Zoom Phone keeps everything in one console. - Mixed estate? Price both against the cost of running two apps, not just per-user fees. For a fuller breakdown of internet-calling economics, see our guide on VoIP vs landline costs. ## Which has better call quality for UK businesses? Neither platform is meaningfully clearer than the other on a healthy connection. Call quality on both Teams Phone and Zoom Phone is governed far more by your underlying internet - latency, jitter, and contention - than by the vendor's codec. Get the connectivity right and both deliver crisp, reliable voice. Teams Phone routes over Microsoft's global network; Zoom runs its own backbone. Both perform reliably. For UK SMEs the practical variable is the access circuit: the UK broadband average download speed is 69.4 Mbps (Ofcom Connected Nations 2024), which comfortably supports either platform for typical office headcounts. Ofcom's Connected Nations programme tracks UK fixed-line performance in detail (ofcom.org.uk). Where voice is business-critical, a dedicated circuit removes contention entirely - and tightening call security matters as much as quality, which is why we treat VoIP security as part of the build, not an afterthought. ## Which platform is better for the PSTN switch-off? Both platforms are valid replacements for traditional analogue lines, so either keeps you compliant. The deciding factor is not the switch-off itself but which migration causes least disruption - and for Microsoft 365 businesses, moving calling into Teams is the shorter path. The UK PSTN switch-off is scheduled for completion by 31 January 2027 (Openreach), after which ISDN and analogue lines are withdrawn. Ofcom oversees the migration of the public phone network to IP (ofcom.org.uk). Teams Phone via Direct Routing offers flexible UK number management and call routing while keeping everything inside your existing Microsoft 365 tenant - no new platform to adopt under deadline pressure. Plan the move early using our PSTN switch-off guidance rather than waiting for your lines to be cut. ## When should you choose each option? Choose on where your people already work, not on a feature checklist. The two platforms are close on capability; the real differentiators are app consolidation, admin overhead, and security model. Pick the one that removes a tool rather than adding one. Choose Microsoft Teams Phone when: - Your business already runs on Microsoft 365 and Teams is the daily app. - You want one app, one admin centre, and one security model (Entra ID + Defender). - You need UK number flexibility via Direct Routing without Microsoft Calling Plans. - You want calling, chat, and meetings consolidated under a single provider. Choose Zoom Phone when: - Zoom is already your primary meetings and collaboration platform. - Staff have deep Zoom habits you do not want to disrupt. - Your telephony requirements are simple and platform consolidation is not a goal. - You are not committed to the Microsoft 365 ecosystem. The momentum is with Teams, reflecting how many businesses are consolidating calling into Microsoft 365. If you want help configuring it, Microsoft Teams Calling is the service to scope. ## What does AMVIA recommend? If your business uses Microsoft 365, we recommend Teams Phone via Direct Routing. It gives full PSTN calling inside the Teams app your team already uses, without buying a second collaboration platform or running parallel admin. One provider, security-first, Microsoft-certified. AMVIA provides Teams Direct Routing from £5.95 per user per month - competitive against Zoom Phone for M365-centric businesses, and delivered with the calling layer, number porting, and security configured together. If you are Zoom-first, we will still build and support Zoom Phone properly; we just will not pretend it is the cheaper or simpler option when you already own Microsoft 365. For tighter integration, see how we connect VoIP with Microsoft 365. ## Frequently asked questions Q: Is Teams Phone cheaper than Zoom Phone for businesses already on Microsoft 365? A: Usually, yes. If you already hold Microsoft 365 Business licences, Teams Phone adds only a calling layer through a provider, and your team already has the Teams app installed. Zoom Phone requires a separate licence and a separate application to deploy, secure, and administer. For Microsoft-centric SMEs, the consolidation removes a duplicate platform cost rather than adding one. Q: Does Zoom Phone offer better call quality than Teams Phone? A: No meaningful difference on a healthy connection. Both platforms deliver comparable call quality when running over adequate internet. Teams Phone uses Microsoft's global network and Zoom uses its own backbone, but for UK businesses call quality depends far more on your access circuit - latency, jitter, and contention - than on the platform. Fix the connectivity and either solution performs well. Q: Can I use Zoom Phone if my business runs on Microsoft 365? A: Yes, but it adds cost and complexity. Your team would switch between Teams for collaboration and Zoom for calling, managing two apps and two admin consoles. Teams Phone embeds calling into the same application used for chat, meetings, and files, so there is one console and one security model. For Microsoft-centric businesses the consolidation benefit is substantial. Q: Which platform is better for the PSTN switch-off? A: Both support the move from analogue lines to internet calling before the switch-off completes, so either keeps you compliant. The difference is disruption: for Microsoft 365 businesses, Teams Phone via Direct Routing keeps calling inside your existing tenant with flexible UK number management, avoiding a new platform rollout under deadline pressure. Q: What is Teams Direct Routing and why does it matter? A: Direct Routing connects UK PSTN calling to Microsoft Teams through a provider's network instead of Microsoft's own Calling Plans. It gives you flexible number porting, competitive per-minute rates, and full control over routing, while keeping calls inside Teams. For most UK SMEs it is the most cost-effective way to turn Teams into a complete business phone system. Q: Do I need a special internet connection for Teams Phone or Zoom Phone? A: Not necessarily. Typical UK office broadband supports either platform for normal headcounts, since voice traffic is light per call. What matters is consistency - low latency and low contention. Where voice is business-critical or you have many concurrent calls, a dedicated circuit removes contention and guarantees headroom for clear, uninterrupted calls. --- # Gamma Horizon vs Alternatives (2026): An Honest UK Comparison URL: https://amvia.co.uk/business-voip/compare/gamma-vs-alternatives Last updated: 2026-07 Gamma Horizon is a carrier-grade, UK-backed hosted phone system at £12–£18/user/month, sold mainly through channel partners - so your day-to-day experience depends on the partner as much as the platform. AMVIA VoIP runs from £5.95/user/month with Microsoft Teams integration and the same provider handling your connectivity and security; Microsoft Teams Phone suits businesses that already live in Teams. All three are PSTN switch-off ready - the right choice comes down to price, support model and how much of your stack you want under one SLA. Gamma occupies an unusual position in UK business telephony: one of the country's most respected voice carriers, whose flagship product - Horizon - you almost never buy from Gamma itself. Understanding that channel model is the key to comparing it fairly against direct providers like AMVIA or licence-based options like Microsoft Teams Phone. For the wider market picture, see our UK business VoIP provider comparison. ## What Gamma Horizon actually is Horizon is a hosted business phone system running on Gamma's own UK voice network - carrier-grade infrastructure with a mature feature set, typically priced at £12–£18 per user per month in the SME market. Gamma sells it channel-first: partners and resellers package Horizon with their own support, SLAs and pricing. The platform is consistent; the experience isn't. Two businesses on identical Horizon deployments can have very different support quality and bills depending on the partner behind them. ## The alternatives, honestly stated AMVIA VoIP runs from £5.95/user/month against a UK market norm of £12–£20, with Microsoft Teams integration - and the structural difference that the same provider manages the connectivity the calls run over and the security around them, under one SLA. Microsoft Teams Phone adds PSTN calling inside Teams via licensing: operationally simple for Teams-first businesses, though dedicated platforms still win on call-centre-style features and analogue-device support (see our Teams vs Zoom Phone comparison for the app-first landscape). RingCentral, 8x8 and Vonage round out the market at international scale - strong platforms, priced above the UK value end. ## The channel question Buying Horizon means choosing a partner, and the partner determines your escalation route, your response times and your renewal pricing. That's not a criticism - a good local partner is genuinely valuable - but it means a Horizon evaluation is really two evaluations. Ask the partner the questions you'd ask any provider: who answers the phone at 5pm on a Friday, what the SLA commits to in writing, and what the seat price includes. The platform's quality can't compensate for a weak partner sitting between you and it. ## The deadline that frames every VoIP decision The PSTN switch-off on 31 January 2027 retires the UK's analogue lines and ISDN circuits. Gamma Horizon, AMVIA VoIP and Teams Phone are all cloud platforms - all switch-off ready. The genuine risk is timing: businesses still on traditional lines that wait for the deadline rush will find installation lead times stretching exactly when they can least afford it. Whichever platform you choose, choose it in 2026. ## How to run the comparison properly - Normalise the seat price - same features (call recording, mobile apps, handsets), same contract length, before comparing numbers. Our VoIP cost guide breaks down what moves the bill. - Evaluate the support model, not the brochure - for Horizon that means the partner's SLA; for AMVIA it's one UK team across phones, circuit and security. - Price the connectivity underneath - call quality is decided by the circuit, and a quote that ignores it is incomplete. - Check Teams integration depth if your business runs on Microsoft 365. - Confirm number porting is handled for you - it's the step that goes wrong most often in DIY migrations. ## Frequently asked questions Q: What is Gamma Horizon and who is it best for? A: Gamma Horizon is a hosted business phone system running on Gamma's own UK voice network - a carrier-grade, UK-backed platform aimed at SMEs that want a managed service. It's best for businesses with a strong channel partner relationship, because Gamma sells Horizon almost entirely through partners and resellers: the platform sets the ceiling, but the partner you buy through sets the day-to-day experience. Q: How much does Gamma Horizon cost per user? A: Typically £12–£18 per user per month in the UK SME market, sitting inside the wider £12–£20 norm for hosted business VoIP. Exact pricing varies by the channel partner you buy through, contract length, and extras like call recording or handsets. For comparison, AMVIA business VoIP starts from £5.95/user/month - when comparing, make sure both quotes include the same features and the connectivity underneath. Q: Can I buy Gamma Horizon directly from Gamma? A: Generally no - Gamma is a channel-first carrier, selling Horizon through a network of partners and resellers rather than direct to end businesses. That model has a real consequence: two companies on identical Horizon platforms can have very different support experiences and prices depending on their partner. If you're evaluating Horizon, evaluate the partner's SLA, escalation route and pricing as rigorously as the product. Q: Is Gamma Horizon or AMVIA VoIP better for my business? A: Neither is universally better. Horizon offers a mature, carrier-grade platform at £12–£18/user/month via a partner; AMVIA runs from £5.95/user/month with Teams integration and - the structural difference - the same provider managing your connectivity and security under one SLA. If you want to keep an existing local partner relationship, Horizon is a solid choice. If you want one accountable provider for the whole stack, that's the AMVIA model. Q: Do Gamma, AMVIA and Teams Phone all survive the PSTN switch-off? A: Yes - all three are cloud voice platforms, which is precisely what the PSTN switch-off migrates businesses onto. The deadline that matters is 31 January 2027, when analogue lines and ISDN circuits stop working. The risk isn't choosing between these platforms; it's businesses still on traditional lines leaving migration until the pre-deadline rush, when installation lead times stretch. Q: What should I compare when choosing between VoIP platforms? A: Five things, in order: the true per-seat cost with identical features included; who actually answers support calls and their SLA; the quality of the connectivity the calls will run over; Microsoft Teams integration if your business uses M365; and number porting handled by the provider. Platform brochures look similar - the differences show up in the support model and the circuit underneath, which is why AMVIA quotes both together. --- # Business Mobiles UK: SIM-Only Plans & Device Management URL: https://amvia.co.uk/business-mobiles Last updated: 2026-03 Business mobiles are company-owned phones, tablets and SIMs procured, managed and secured under a single business account rather than individual consumer plans. They give you centralised billing, volume pricing, pooled data and enrolment in mobile device management so you can enforce security policies across every handset. AMVIA runs the lot - one provider, security-first, Microsoft-certified. ## What does AMVIA's business mobile service include? AMVIA manages the full lifecycle of your mobile estate - sourcing competitive contracts, supplying handsets, enrolling devices in management software, and securing the data on them. It is a single accountable service rather than a stack of network bills and an unmanaged fleet of phones. - Business mobile contracts across O2, Vodafone, EE and Three, with number porting, upgrades and renewals handled for you - SIM-only business mobile plans with pooled data that removes overage charges across your team - Mobile device management to enforce PINs, encryption, app control and remote wipe from one dashboard - Device procurement at trade pricing, plus refresh cycles, insurance claims and warranty repairs - 5G-ready fleet planning for field workers and high-data roles ## How does mobile device management work on a company phone? Mobile device management (MDM) is software that lets your IT team - or your managed provider - remotely control every enrolled device from a central console. The most widely deployed platform for UK businesses is Microsoft Intune, which is included with Microsoft 365 Business Premium licences. With MDM in place, your administrator can: - Enforce PIN, fingerprint or Face ID lock screens on every device - Require encryption so data is unreadable if a handset is lost - Push apps and security settings without touching the device - Restrict which apps staff can install - Trigger a remote wipe of corporate data on a lost or stolen phone MDM matters because mobile is now a primary access point for company data, and basic controls are still missing in most firms. Only 47% of UK businesses have two-factor authentication in place, according to the DSIT Cyber Security Breaches Survey 2025/26. MDM lets you enforce MFA on every device that touches company data. See Microsoft Intune documentation for the underlying platform. ## What is the difference between MDM and MAM? Mobile application management (MAM) is a subset of MDM. MDM manages the entire device; MAM manages only the work apps on it. MAM suits bring-your-own-device cases where staff will not accept full device control - you can secure Outlook and Teams on a personal iPhone without ever seeing personal photos or messages. | | Capability | MDM (full device) | MAM (app-level) | Best for | Company-owned phones | Employee-owned (BYOD) phones | Controls | Whole device: encryption, lock screen, apps | Only work apps and their data | Visibility for IT | Full device configuration | Corporate apps only | Remote wipe | Entire device or corporate data | Corporate data only | Privacy for staff | Lower - device is managed | Higher - personal data untouched ## Why do UK SMEs need a BYOD policy? Most UK SMEs let staff check work email and Teams on personal phones. That is normal, but without a BYOD security policy it carries real risk: a leaver keeps access to company email indefinitely, a malware-infected personal phone reaches company files, and a lost device cannot be cleared of corporate data. A workable BYOD policy should set out: - Which devices and minimum OS versions are permitted - Whether MDM or MAM will manage corporate data on personal devices - Exactly what the business can and cannot see on a personal phone - What happens to company data when an employee leaves - Whether the business contributes to the phone bill AMVIA drafts the policy, deploys the matching MDM or MAM configuration, and briefs your team so the rules are understood, not just written down. For wider device-threat context, the NCSC device security guidance is the authoritative UK reference. ## Business mobile contracts vs consumer plans - what's the difference? Consumer SIMs are built for individuals; business contracts are built for fleets. For any organisation with three or more mobile users, the business account wins on cost control and security. The table below shows where the differences bite. | | Feature | Business contract | Consumer plan | Billing | Single consolidated invoice | One bill per line | Pricing | Volume discounts across lines | Fixed per-SIM retail | Data | Pooled across the estate | Per-SIM, overage charged | Support | Dedicated account manager | Consumer call centre | Management | MDM-ready from day one | No fleet controls Networks differ on coverage, so the right choice depends on where your team works. O2 and EE tend to lead on rural coverage, Vodafone on international roaming, and Three on value urban data. AMVIA is network-agnostic and will split your fleet across networks where coverage needs vary by role. ## How much do business mobiles cost? Business mobile cost depends on device count, networks, whether handsets are supplied or SIM-only, and whether management is included. As a guide, SIM-only business contracts run roughly £8–£20 per SIM per month, and full device contracts add the handset cost over 24 or 36 months. Microsoft licensing and AMVIA's management layer sit on top. | | Component | Typical cost | Notes | SIM-only business contract | £8–£20 per SIM/mo | Volume discounts from ~10 SIMs | Full device contract | From ~£20–£45 per device/mo | 24 or 36 months, by handset model | Microsoft Intune MDM | Included in M365 Business Premium £16.90/user/mo | Licence price per Microsoft 365 pricing | AMVIA managed mobile service | From approximately £15 per device/mo | Contract sourcing, MDM, SIM and device support Businesses that consolidate fragmented mobile contracts through a managed provider report around a 30% average cost saving (2025 UK market data) - mostly from removing overage charges, retiring unused SIMs and using pooled data. ## Which business mobile approach fits your size? The right setup scales with headcount. Small teams need enrolment and remote wipe; larger SMEs need a managed fleet programme with audits and refresh cycles. AMVIA matches the service to the stage you are at. - 10–25 staff: SIM-only contracts with basic Intune MDM - get every device enrolled and remote wipe tested - 25–100 staff: A managed mobile service with consolidated billing, pooled data and a formal BYOD policy - 100–500 staff: A full fleet programme with mobile security monitoring, regular audits and a device refresh cycle, usually inside a broader managed IT engagement ## Frequently asked questions Q: How much do business mobile plans cost? A: SIM-only business plans typically run £8–£20 per user/month, with device-inclusive plans at £20–£45 depending on the handset. Pooled data and volume pricing across a fleet usually beat the sum of individual consumer contracts - and everything lands on one bill. Q: What's the advantage of business mobiles over consumer contracts? A: Centralised billing, volume pricing, pooled data and - the part consumer plans never give you - management and security: mobile device management (MDM), remote wipe for lost devices, and controlled access to business data. For any team handling client information on phones, that control is the point. Q: Can AMVIA manage the phones we already own? A: Yes - bring-your-own-device fleets can be enrolled in mobile device management so business data is containerised, protected and remotely wipeable without touching personal content. It's the standard middle path between company-issued handsets and unmanaged personal phones. Q: What happens when a work phone is lost or stolen? A: With MDM in place: the device is locked and business data remotely wiped within minutes of being reported, and the SIM is barred - so a lost handset stays an inconvenience rather than becoming a data breach. Without MDM, you're relying on the finder's goodwill. --- # Business Mobile Phone Contracts for UK Companies URL: https://amvia.co.uk/business-mobiles/business-mobile-contracts Last updated: 2026-03 Business mobile contracts are managed airtime and handset agreements that connect your staff across the UK networks under one bill, one renewal calendar and one point of contact. AMVIA negotiates the tariffs, ports the numbers and locks every SIM into device management - so your mobile fleet is secure, not just connected. One provider. Security-first. Microsoft-certified. AMVIA manages connectivity and security for 1,200+ UK businesses, and we treat mobile as part of your attack surface, not a side order. Most providers sell you airtime and walk away. We compare networks, run the contract, and enrol every device into mobile device management so a lost phone is a wiped phone, not a breach. ## What is a business mobile contract? A business mobile contract is a commercial airtime agreement between a company and a UK network - billed centrally, scoped to the number of users, and built around shared allowances rather than individual consumer plans. It bundles SIMs, optional handsets, data, and management into a single monthly cost with one renewal date. Unlike a personal contract, a business agreement gives you pooled data, volume pricing, central billing, and the option to layer security and device controls on top. That last layer is where AMVIA differs from a network reseller. - Pooled data across all lines instead of per-user caps - Volume tariffs that improve as connection counts grow - Central billing with one invoice and one account manager - MDM-ready SIMs so every device can be secured and remote-wiped - Mixed terms so renewal dates align across the business ## What contract terms and tariffs are available? Business mobile contracts run on 12, 24, or 36-month terms, and AMVIA mixes those terms across a single agreement so different teams renew on dates that suit them. Shorter terms protect flexibility for growing teams; longer terms enable lower monthly costs and stronger handset subsidies. We also build SIM-only business mobile plans where you keep existing handsets, and 5G business mobile tariffs for field and hybrid teams that depend on fast mobile data. Each user can sit on a different tariff based on their role rather than a one-size plan. | | Contract type | Best for | Typical commitment | Handset subsidy | 12-month airtime | Growing or seasonal teams | Lower, more flexible | Limited | 24-month airtime + handset | Most SME fleets | Balanced cost vs term | Moderate | 36-month airtime + handset | Cost-priority fleets | Lowest monthly cost | Strongest | SIM-only | Keeping existing devices | 30-day to 12-month | None - lowest price ## How does AMVIA manage your mobile contracts? AMVIA runs the full lifecycle: we audit your current contracts, compare every UK network, port your numbers, and then manage usage month to month. You get a single point of contact for billing, upgrades, and support rather than a network call centre queue. 1. Contract review - we audit your existing tariffs, usage, and costs to find waste and overage. 2. Network comparison - we compare tariffs across the major UK networks and negotiate rates, often saving 20–40% (typical UK 2026 range). 3. Migration and setup - we handle number porting, device configuration, and MDM enrolment with no disruption. 4. Ongoing management - monthly usage reviews, upgrade handling, and one contact for every query. Handset upgrades are typically available 60 to 90 days before renewal, and we manage them across the whole fleet so new devices arrive configured and enrolled. ## Why do UK SMEs need secured mobile contracts? Mobiles hold email, files, and saved logins, which makes every handset a route into your business. A mislaid phone without device management is a data incident waiting to happen, so a business mobile contract should ship with security built in, not bolted on later. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a breach in the past year, at an average disruptive-breach cost of £3,550. A managed mobile estate closes one of the easiest doors: lost and unmanaged devices. AMVIA enrols every SIM into Microsoft Intune mobile management and aligns it with your wider managed cybersecurity controls. For teams that bring their own phones, our BYOD security approach separates work data from personal apps so you can wipe company access without touching an employee's photos. The National Cyber Security Centre recommends exactly this device-management baseline for mobile working (NCSC device security guidance). ## How much do business mobile contracts cost? Cost depends on user count, data needs, handset choice, and term length, so there is no single sticker price. Pooled data and volume tariffs make spend predictable, and AMVIA reviews usage quarterly to stop overage and trim unused lines before they cost you. - SIM-only plans are the lowest monthly cost - no handset to fund. - Airtime + handset spreads device cost across the term. - Pooled data removes per-user overage charges across the fleet. - Volume discounts grow with the number of connections. We give you a fixed monthly figure per line and a single invoice, so finance can forecast mobile spend without surprises. Microsoft licence list prices for any bundled M365 security sit at £4.60 (Basic), £9.60 (Standard), and £16.90 (Premium) per user per month, ex VAT on annual terms (Microsoft 365 UK pricing). ## AMVIA vs a typical mobile reseller | | Feature | AMVIA | Typical reseller | Multi-network comparison | Yes - all major UK networks | Often single-network | Device management built in | Yes - Intune / MDM enrolment | Rarely included | Security stack | Microsoft Defender + Barracuda | None | Single point of contact | Dedicated account manager | Call-centre queue | Certification | Cyber Essentials Plus, Microsoft Solutions Partner | Varies AMVIA is a Sheffield-based team that runs UK connectivity and security for a living. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare, and professional services. ## Frequently asked questions Q: What contract lengths are available for business mobile? A: AMVIA offers business mobile contracts on 12-month, 24-month, and 36-month terms. Shorter contracts give growing businesses flexibility; longer terms enable lower monthly costs and better handset subsidies. Multi-line agreements can mix terms so renewal dates line up across different teams and departments in your organisation. Q: What is data pooling and how does it reduce costs? A: Data pooling combines the allowances from all your business mobile lines into one shared pool. Instead of each user hitting an individual cap, heavy users draw from the collective allowance without triggering overage charges. Pooled plans keep mobile spend predictable and stop a handful of data-hungry staff from inflating the monthly bill. Q: When can we upgrade our business handsets? A: Handset upgrades are typically available 60 to 90 days before your contract renewal date. AMVIA manages upgrades across your whole fleet, handling device setup, data migration, and MDM enrolment so new handsets arrive ready to use. Early upgrades are available on some tariffs for staff who need the latest devices sooner. Q: Are there discounts for ordering multiple business mobile lines? A: Yes. Multi-line business mobile contracts attract volume discounts that grow with the number of connections. AMVIA negotiates directly with UK networks to secure preferential tariffs. We also bundle device management and mobile security into multi-line agreements, so a larger fleet is a more protected fleet, not a bigger risk. Q: Can we mix different tariffs across our mobile contract? A: Yes. AMVIA builds bespoke agreements where each user runs a tariff matched to their role. Field workers can have large data allowances while office staff sit on lighter plans. We review usage quarterly and recommend tariff changes to prevent overspending or overage charges across the fleet. Q: Are AMVIA's business mobiles secured against loss or theft? A: Yes. Every SIM AMVIA supplies can be enrolled into Microsoft Intune device management, so a lost or stolen handset can be remotely locked or wiped before company data is exposed. Work data stays separated from personal apps, which matters for both company-owned devices and bring-your-own-device fleets. --- # Mobile Device Management (MDM) for UK Businesses URL: https://amvia.co.uk/business-mobiles/mobile-device-management Last updated: 2026-03 Mobile device management (MDM) is the practice of securing, configuring and monitoring every phone, tablet and laptop that reaches your business data - all from one central console. It enforces encryption, passcodes and remote wipe so a lost device cannot leak company information. AMVIA runs MDM on Microsoft Intune for 1,200+ UK businesses: one provider, security-first, Microsoft-certified. If you are still deciding which devices to enrol, start with our business mobile solutions overview, then come back here to plan how those devices get managed and secured. ## How does mobile device management work? MDM works by enrolling each device into a management platform - usually Microsoft Intune - that pushes security policies, apps and configuration over the air. Once enrolled, a device that drifts out of compliance is automatically blocked from email and files until it is fixed. The lifecycle AMVIA runs looks like this: 1. Device inventory - we audit your estate: makes, models, OS versions and current security status across iOS, Android, Windows and macOS. 2. Policy configuration - we set passcode rules, encryption, app restrictions and remote-wipe capability that match your risk appetite. 3. Enrolment - devices receive Wi-Fi, email, VPN and security profiles automatically, with minimal disruption to the user. 4. Lifecycle management - ongoing compliance monitoring, app deployment, OS-update control and remote support for lost or compromised devices. This is the same control plane behind Microsoft Intune for mobile - the difference is that AMVIA's UK engineers configure and run it for you. ## What's included in AMVIA's managed MDM service? A managed MDM service from AMVIA covers the full estate, not just the platform licence. You get the tooling, the configuration, the monitoring and a named team that owns outcomes - so a non-compliant phone is caught and fixed before it becomes a breach. The service includes: - Proactive protection - continuous compliance monitoring and threat detection across every enrolled device. - Expert management - UK-based engineers handle configuration, app deployment and incident response. - Conditional access - devices that fail policy are blocked from Microsoft 365 automatically. - Remote wipe - selective wipe for personal devices, full factory reset for company-owned ones. - Monthly reporting - device posture, incidents handled and recommended improvements. For tighter control over personal phones, pair MDM with BYOD security and broader mobile security policies. ## Why do UK SMEs need mobile device management? Because phones are now full endpoints holding email, documents and saved credentials - and an unmanaged one is a wide-open door. In the 2025 government survey, 43% of UK businesses reported a cyber breach or attack in the past year (gov.uk Cyber Security Breaches Survey 2025). MDM closes the mobile gap that perimeter security misses. The cost is real: the average disruptive breach cost UK businesses around £3,550. The National Cyber Security Centre recommends enrolling all business mobile devices into a management platform that enforces encryption and remote wipe (ncsc.gov.uk device security guidance). With Microsoft 365 now spanning over 400 million paid commercial seats globally, most UK SMEs already hold the licences needed to manage devices properly - they simply have not switched it on. ## BYOD vs corporate-owned: which model should you manage? There is no single right answer - it depends on cost tolerance and control needs. Corporate-owned devices give full management and standardisation; BYOD cuts hardware spend but needs app-level separation of work and personal data. AMVIA configures MDM for either model, so corporate data stays protected regardless of who owns the device. | | Factor | Corporate-owned | BYOD (bring your own device) | Management control | Full device control | App and data-level control | Hardware cost | Higher (business buys devices) | Lower (staff use own phones) | Remote wipe | Full factory reset | Selective wipe of work data only | Privacy | Business owns the device | Personal content stays untouched | Best for | Regulated sectors, shared devices | Cost-conscious teams, hybrid staff Many businesses run a hybrid: corporate phones for client-facing roles, BYOD for everyone else. For lost-device scenarios, see remote wipe and device security. ## In-house vs managed MDM: what's the difference? Running MDM in-house means buying time and expertise you may not have; a managed service gives you both for a fixed monthly fee. The table below shows where the gap usually sits for a 10–500-staff business. | | Capability | In-house | AMVIA managed MDM | Platform setup | DIY configuration | Configured by Microsoft-certified engineers | Compliance monitoring | Ad-hoc | Continuous, with monthly reporting | Lost-device response | Whoever is free | Remote lock or wipe, fast response | OS and app updates | Manual | Managed centrally | Security backing | Internal only | Cyber Essentials Plus certified provider This sits inside AMVIA's wider managed cybersecurity approach, where mobile is one layer of a single, accountable security posture. ## How much does mobile device management cost? MDM cost has two parts: the platform licence and the management. Microsoft Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual; microsoft.com/en-gb), so many SMEs already own the licence. AMVIA then adds fixed monthly management on top - no lock-in contracts. Because Intune ships inside Business Premium, the marginal cost of proper device management is usually the engineering time, not new software. We scope that against your device count and compliance needs during the audit. ## Frequently asked questions Q: What is mobile device management? A: Securing, configuring and monitoring every phone, tablet and laptop that reaches your business data - enforcing encryption and PINs, separating work data from personal, and giving you remote wipe when a device goes missing. Q: Do we need MDM if staff use their own phones? A: That's exactly when you need it. BYOD without management means client emails and files on devices you can't see or wipe. MDM containerises business data on personal devices - protected and removable - without touching personal photos or apps. Q: What happens when a managed device is lost or stolen? A: Lock and wipe within minutes of the report: business data removed, access tokens revoked, SIM barred if it's a managed contract. A lost phone stays an inconvenience instead of becoming a £3,550-average breach (DSIT 2025). Q: Which platform does AMVIA use for MDM? A: Microsoft Intune for most clients - it's included in many Microsoft 365 plans you may already own, covers iOS, Android, Windows and macOS, and integrates with the rest of the tenant's security. The value is in the policy design and ongoing management, not the licence. --- # Microsoft Intune for Business Mobile Devices URL: https://amvia.co.uk/business-mobiles/microsoft-intune-mobile Last updated: 2026-03 Microsoft Intune is the device management platform that controls and secures company phones, tablets and staff-owned devices used for work. It enforces encryption, PINs and compliance, and lets you remotely wipe a lost handset. AMVIA configures and runs Intune for you as one provider - security-first, Microsoft-certified. Most UK SMEs already own Intune through their Microsoft 365 licence but never switch it on properly. We close that gap. If you are scoping wider business mobile management, Intune is the security layer that sits underneath every handset on your account. ## What is Microsoft Intune for mobile devices? Microsoft Intune delivers Mobile Device Management (MDM) for company-owned phones and Mobile Application Management (MAM) for personal devices. It enforces security policy, controls which apps can hold company data, and connects to Microsoft Entra ID and Conditional Access so only compliant devices reach your email, Teams and files. Intune manages iOS, iPadOS, Android, Windows and macOS from a single console. For mobile specifically, it splits cleanly into two modes: - MDM (full management) - for company-owned iPhones, Androids and tablets. AMVIA controls the whole device: encryption, passcode, OS version, app deployment and remote wipe. - MAM (app-level management) - for staff using personal phones. Policy applies only to the Microsoft 365 apps; the rest of the device stays private and untouched. This is why Intune is the foundation of any serious BYOD security policy - it secures the work data without seizing the personal device. ## What's included in AMVIA's Intune mobile service? AMVIA designs the policies, enrols the devices, deploys your apps and runs the platform day to day. You get managed security across your whole mobile fleet without an internal Intune specialist, backed by our mobile device management service and our wider managed cybersecurity practice. ## Company-owned phones and tablets (MDM) ## Personal devices (MAM) ## iOS-specific controls ## MDM vs MAM: which mode does your business need? The right mode depends on who owns the device. Company-issued phones belong in MDM for full control; personal phones used for work belong in MAM so you secure the data without managing the hardware. Most SMEs run both. The table below is the short version - the full breakdown is in our MDM vs MAM comparison. | | Factor | MDM (company devices) | MAM (personal / BYOD) | Device ownership | Company-owned | Staff-owned | Scope of control | Whole device | Microsoft 365 apps only | Remote wipe | Full factory wipe | Selective (company data only) | Visibility of personal data | No personal content read | None - apps only | Best for | Issued phones, kiosks, field devices | Contractors, BYOD, light users ## Why do UK SMEs need managed mobile security? Phones now carry the same email, files and logins as a laptop, but most are unmanaged. UK government data shows the threat is mainstream, not theoretical: 43% of UK businesses reported a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025, DSIT). The same survey reports phishing as the dominant attack type - around 85% of breached businesses - and an average cost of roughly £3,550 per disruptive breach (DSIT, 2025). A managed, enrolled fleet means a lost or stolen handset is a wipe-and-move-on event, not a data breach. The NCSC's device security guidance treats this baseline - encryption, screen lock, and remote wipe - as essential, and Intune enforces all three. ## How does AMVIA manage your mobiles with Intune? We run a four-stage process so your fleet is secured without disrupting staff. It applies whether you have ten phones or several hundred. 1. Policy design - we define device compliance, app restrictions and data-protection rules for your fleet. 2. Device enrolment - handsets are enrolled into Intune and receive your Wi-Fi, VPN, email and app configuration automatically. 3. App deployment - business apps are pushed silently, with managed app policies preventing data leakage into personal apps. 4. Ongoing management - remote wipe for lost devices, compliance monitoring, OS update management and reporting on device health. This sits inside our broader Microsoft 365 security practice, so device policy, identity and email protection are managed as one - not bolted together by three vendors. ## How much does Microsoft Intune cost? Microsoft Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual commitment), so most SMEs already own it (Microsoft 365 UK pricing). It is not included in Business Basic (£4.60) or Business Standard (£9.60). AMVIA's charge is for designing the policies, enrolling devices and running the platform - the licence itself is rarely an extra cost. ## Why choose AMVIA for Intune mobile management? AMVIA is a Sheffield-based managed security and Microsoft 365 partner. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. Key facts: - 1,200+ UK businesses managed by AMVIA - Critical issues responded to within one hour - 24/7 monitoring and support - Locations: Sheffield, Birmingham, Leeds, London, Manchester, Bristol, Cardiff One provider. Security-first. Microsoft-certified engineers who run Intune for a living - not a reseller passing you to a help line. ## Frequently asked questions Q: Does Microsoft Intune support both iPhones and Android phones? A: Yes. Intune manages iOS and iPadOS devices via Apple Business Manager and Android devices via Android Enterprise, plus Windows and macOS laptops. Every platform is administered from the same Intune console, so your phones, tablets and computers share one set of policies and one compliance view. Q: Can Intune see personal data on my staff's phones? A: No personal content. In MDM mode on company devices, Intune sees device information such as installed apps and compliance status, but not personal messages, photos or app content. In MAM mode for BYOD, Intune manages only the Microsoft 365 apps and has no visibility into personal apps or data whatsoever. Q: What happens when a staff member loses their phone? A: For company devices in full MDM, AMVIA can remotely wipe the handset, removing all data and resetting it to factory settings. For personal devices managed via MAM, a selective wipe removes company data from the Microsoft 365 apps while leaving personal content untouched. Either way, the lost device stops being a risk. Q: Is Microsoft Intune included in Microsoft 365 Business Premium? A: Yes. Intune is included in Microsoft 365 Business Premium at no extra licence cost. It is not included in Microsoft 365 Business Basic or Business Standard, so upgrading to Premium is usually the cheapest route to mobile device management for an SME already on Microsoft 365. Q: Do staff need to do anything to enrol their device? A: For company-owned devices bought through Apple Business Manager or Android Enterprise zero-touch, enrolment is automatic - the device configures itself when first switched on. For BYOD, staff install the Intune Company Portal app and follow a short process of around five minutes. AMVIA provides clear instructions for both. --- # SIM-Only Business Mobile Plans for UK Companies URL: https://amvia.co.uk/business-mobiles/sim-only-business-mobile Last updated: 2026-03 A SIM-only business mobile plan gives your team calls, texts and data on a UK network without a bundled handset - so monthly costs drop sharply when staff already own suitable phones. AMVIA sources business rates across every UK network and wraps each SIM in proper device security. One provider, security-first. That sits alongside the rest of our business mobile service: contracts, 5G and device management, all on a single monthly bill with one UK account team. If your handsets are still in good shape, SIM-only is usually the cheapest way to keep your fleet connected. ## What's included in an AMVIA SIM-only business mobile plan? Every AMVIA SIM-only plan covers airtime, inclusive data and UK business call rates, managed end-to-end so your IT team never has to deal with carriers directly. We handle network selection, activation, billing and renewals, and add optional device security on top. - Negotiated business tariffs across all major UK networks, not consumer pricing - Flexible data allowances from 5 GB to unlimited per user - Number porting handled for you, with no service interruption - Single monthly bill with usage alerts and a named account manager - Optional device security via Microsoft Intune and mobile threat controls This is where a security-first provider differs from a phone reseller: we treat each SIM as an endpoint on your network, not just a line on an invoice. Pair it with mobile device management and every handset is enrolled, encrypted and remotely wipeable from day one. ## How does AMVIA set up SIM-only plans? We start with your actual usage, not a generic package. Our team reviews current spend, picks the right network and tariff per user, ports numbers, and ships activated SIMs to your office or staff directly - typically within a few working days. 1. Usage analysis - we review current mobile spend and usage patterns to find the most cost-effective plans, often saving 30–50% vs consumer plans (typical UK 2026 range). 2. Network selection - we compare deals across all UK networks and negotiate business rates. 3. SIM delivery and activation - SIMs go to your office or staff directly, with number porting handled end-to-end. 4. Account management - one monthly bill, usage alerts, and a dedicated account manager for adds, changes and renewals. ## SIM-only vs standard mobile contract: which is right for your business? SIM-only is cheaper when your team already owns suitable handsets, because you only pay for airtime and data. A standard contract spreads a new device cost across the term, inflating the monthly fee. The right choice depends on handset age and how often you refresh devices. | | Factor | SIM-only plan | Standard (handset) contract | Monthly cost | Lower - airtime and data only | Higher - device cost bundled in | Handset included | No (use existing devices) | Yes (new device, financed) | Contract flexibility | Rolling 30-day to 24-month | Usually 24–36 months | Best for | Teams with good existing phones | Teams needing new hardware | Upgrade cycle | Buy devices separately, when needed | Tied to contract end date If you do need new hardware across the team, our business mobile contracts bundle handsets, and our 5G business mobile plans cover field staff who depend on fast mobile data. ## Why do UK SMEs need secure business mobiles? Mobiles are a soft target. They carry email, Teams, files and saved logins, yet they often sit outside the controls applied to laptops. With 43% of UK businesses hit by a cyber breach or attack in 2025, an unmanaged phone is a real route in. According to the DSIT Cyber Security Breaches Survey 2025, 85% of those breaches involved phishing - and phishing lands on phones as readily as desktops. The NCSC's device security guidance recommends enforced encryption, screen locks and remote wipe on every business handset. That is why AMVIA treats SIM provisioning and security as one job. Enrol each device in Microsoft Intune - Microsoft's cloud device-management platform - apply conditional access, and you can lock or wipe a lost phone in minutes. Our business mobile security controls layer on top of the SIM, not as an afterthought. ## How much does a SIM-only business mobile plan cost? Pricing depends on data allowance, contract length and line volume, so we quote per estate rather than per advert. SIM-only is consistently cheaper than handset contracts because you are not financing a device, and pooled business tariffs beat consumer rates. - Data tiers: 5 GB to unlimited, matched to each user's real usage - Contract terms: rolling 30-day, 12-month or 24-month - mix across your fleet - Typical saving: 30–50% vs consumer plans (typical UK 2026 range) We can mix contract lengths across the estate so seasonal or temporary staff stay flexible while core users lock in lower long-term rates. Number switching in the UK is regulated by Ofcom, so porting is a defined, low-risk process we manage for you. ## Why choose AMVIA for SIM-only business mobile? AMVIA is a UK managed security and Microsoft partner, not a telecoms reseller - so your mobiles arrive already secured and centrally managed. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and support over 1,200 UK businesses. - Sheffield-based UK team - engineering and support that understands UK compliance and networks - Cyber Essentials Plus and Microsoft Solutions Partner status - independently assessed credentials - 1,200+ UK businesses protected across legal, finance, healthcare and professional services - Fast response - critical issues responded to within one hour, by phone, email and portal > "Client testimonial coming soon - AMVIA protects over 1,200 UK businesses." - AMVIA Client ## Frequently asked questions Q: What is a SIM-only business mobile plan? A: Calls, texts and data on a UK network without a bundled handset - so the monthly cost drops sharply when staff already have phones worth keeping. Typically the cheapest way to run a business fleet. Q: How much cheaper is SIM-only than a handset plan? A: Business SIM-only plans typically run £8–£20 per user/month against £20–£45 for device-inclusive plans - the difference is the handset finance. If devices have life left in them, SIM-only banks that difference across the whole fleet. Q: Can we keep our numbers moving to business SIMs? A: Yes - numbers port between networks as standard. Moving a fleet from scattered consumer contracts onto one business account keeps every number while consolidating billing, data pooling and support into one place. Q: Is SIM-only still manageable and secure? A: Fully - management and security live in MDM, not the SIM. Enrolled devices get the same policies, work-data separation and remote wipe whether the SIM came with a handset or not. --- # 5G Business Mobile Plans for UK Businesses URL: https://amvia.co.uk/business-mobiles/5g-business-mobile Last updated: 2026-03 5G business mobile gives UK teams ultrafast mobile data over the latest cellular networks - far quicker and lower-latency than 4G - ideal for field staff, hybrid workers and video calls on the move. AMVIA matches each role to the right network and plan, configures secure SIMs, and manages everything. One provider. Security-first. Microsoft-certified. This page sits inside AMVIA's wider business mobile service, so you can run 5G handsets, SIM-only business mobile plans and device security under a single accountable contract instead of juggling a network reseller and an IT provider. ## Who benefits most from 5G business mobile? 5G earns its place where staff depend on mobile data for heavy, time-sensitive work - large file transfers, cloud apps and video calls - in areas with good coverage. For email and light browsing, a 4G plan is often enough. AMVIA advises per role, based on real usage, not a blanket upgrade. - Field and mobile workers - engineers, sales reps, consultants and delivery teams get faster access to cloud CRM, route planning, reporting and file sharing that drags on congested 4G. - Remote and hybrid staff - a 5G SIM in a mobile router delivers broadband-equivalent speeds where fixed lines are unreliable or absent. - Video conferencing on the move - 5G's higher speed and lower latency make Teams and Zoom calls far steadier on mobile data than 4G. - Construction and manufacturing sites - temporary or fixed-line-free locations can connect staff, IoT devices and site management apps over 5G mobile routers, with backup connectivity where uptime matters. ## What's included in AMVIA's 5G business mobile service? AMVIA runs the whole lifecycle: we check coverage, choose the right network and plan per role, pre-configure devices with your apps and security policies, then manage billing, upgrades and usage. You get one provider accountable for the connection and the security on it, not a hand-off between two suppliers. - Coverage check - we verify 5G availability at each of your sites and recommend the strongest network for your area. - Plan selection - we match data usage, call patterns and budget to the most cost-effective plans across all UK networks. - Device and SIM setup - handsets arrive pre-configured with business apps, email and mobile device management policies already applied. - Ongoing management - we handle upgrades, billing queries and usage monitoring so you never overpay or run short on data. ## How much does 5G business mobile cost in the UK? Costs depend on data allowance, contract length and how many SIMs you take. As a guide, a typical entry-level 5G business plan with a 50GB allowance runs in the low-to-mid teens per SIM each month, before device costs. AMVIA benchmarks live tariffs across networks so you only pay for what each role actually uses. | | Plan Type | Data Allowance | Typical Monthly Cost per SIM | Essential 5G | 50GB | £12–£18 (typical UK 2026 range) Prices exclude VAT and handset costs. We size allowances to measured usage rather than selling every user the largest bundle - pooled data across a fleet usually beats per-SIM upgrades. ## 5G business mobile vs a fixed leased line - which do you need? 5G is excellent mobile connectivity; it is not a replacement for a fixed office line. A leased line gives dedicated, symmetric, uncontended bandwidth with a guaranteed SLA. 5G has no equivalent SLA and is subject to coverage and contention. Use 5G for mobile and resilient backup, a leased line for the primary office. | | Factor | 5G Business Mobile | Fixed Leased Line | Best for | Mobile staff, temporary sites, backup | Primary office connectivity | Bandwidth | Shared, varies with coverage | Dedicated, symmetric, uncontended | SLA | No fixed-line SLA | Guaranteed uptime SLA | Setup time | Days (SIM-based) | Weeks (install required) | Mobility | Fully portable | Fixed to one location ## Why do UK businesses need secure 5G business mobile? Mobile devices are now a primary target, not an afterthought. With 43% of UK businesses reporting a cyber breach or attack in the last 12 months (DSIT Cyber Security Breaches Survey 2025), an unmanaged 5G handset holding email and cloud data is a real exposure. AMVIA treats every SIM as a managed, secured endpoint. Each device we deploy carries mobile security controls - enrolment, encryption, conditional access and remote wipe - applied through Microsoft Intune before the handset reaches the user. The NCSC's mobile device guidance sets the baseline we build to, so a lost phone is an inconvenience, not a breach. ## Which UK network has the best 5G coverage for business? There is no single best network - it depends on where your people work. EE has the widest 5G coverage nationally; Three offers the fastest speeds where available; Vodafone and O2 hold strong urban coverage. AMVIA checks coverage at every key location, drawing on Ofcom's reporting, before recommending a network or a multi-network mix. - EE - widest national 5G footprint, strong for distributed teams. - Three - fastest 5G speeds in covered areas. - Vodafone / O2 - robust city and town-centre coverage. Independent coverage data is published in Ofcom's Connected Nations reports, which we use alongside on-site checks to avoid coverage surprises. ## Frequently asked questions Q: Is 5G worth it for business mobile plans? A: For staff who lean on mobile data for video calls, large file transfers and cloud apps, 5G is a clear upgrade on 4G in covered areas. For users whose mobile use is mostly email and light browsing, the extra cost may not pay off. AMVIA advises per role on actual usage rather than upgrading everyone by default. Q: How does 5G compare to a leased line for office connectivity? A: 5G is not a substitute for a fixed leased line in an office. Leased lines provide dedicated, symmetric, uncontended bandwidth with a guaranteed SLA. 5G offers excellent mobile connectivity but no equivalent SLA and is subject to coverage and contention. Use 5G for mobile workers or as resilient backup, a leased line as the primary office connection. Q: Can I use a 5G SIM as a business broadband replacement? A: In areas with strong indoor 5G coverage, a 5G mobile router can deliver broadband-equivalent connectivity for small or satellite offices, temporary sites and home workers, or as backup to fixed broadband. For permanent offices with significant bandwidth needs, a leased line or full-fibre connection remains the more reliable, cost-effective primary solution. Q: Which network has the best 5G coverage for business in the UK? A: It depends on where your staff work. EE has the widest 5G coverage nationally, Three offers the fastest speeds where available, and Vodafone and O2 hold strong urban coverage. AMVIA checks coverage at all your key locations before recommending a network, or deploys a multi-network strategy for teams spread across a wide area. Q: Is 5G secure enough for business use? A: Yes - when the device is managed. The 5G network itself is encrypted, but the real risk is an unmanaged handset holding business email and data. AMVIA enrols every device in Microsoft Intune with encryption, conditional access and remote wipe, built to NCSC mobile guidance, so a lost or stolen phone does not become a data breach. --- # BYOD Security Policy: Protecting Personal Devices at Work URL: https://amvia.co.uk/business-mobiles/byod-security Last updated: 2026-07-16 BYOD security is the set of policies and technical controls that protect company data on employee-owned phones, tablets and laptops. It pairs a written usage policy with Mobile Device Management (MDM) - enforcing encryption, PIN locks and selective remote wipe. AMVIA delivers it with business mobile security built on Microsoft Intune: one provider, security-first, Microsoft-certified. ## What does BYOD security actually cover? BYOD security covers every control that keeps corporate data safe when staff use personal devices for work. That means a written policy defining acceptable use, plus technical enforcement - encryption, screen locks, separated work data and the ability to remove company information without touching personal content. Most UK firms adopted BYOD informally: staff simply connected personal phones to company email with no policy and no controls. The risk is straightforward - corporate data sits on a device the business does not own. If that handset is lost, stolen, or the employee leaves on bad terms, there is no reliable way to remove company data. Roughly 87% of organisations allow BYOD in some form, yet far fewer enforce it technically. Effective BYOD security closes that gap with mobile device management (MDM) and a clear policy. ## How does BYOD security work? BYOD security works by combining a written policy with technical enforcement - neither is enough alone. A policy without controls is unenforceable; controls without a policy confuse staff and erode trust. Together they let the business protect its data while respecting the employee's right to privacy on their own device. The written element sets out which apps may touch company data, the minimum security settings required (PIN, encryption, current operating system), and exactly what the employer can and cannot see. Transparency drives cooperation - staff enrol willingly when they know personal content stays private. The policy should also cover data ownership, lost-device reporting, and what happens to company data when someone leaves. The technical element uses Microsoft Intune for mobile devices to create a managed work profile - a separate container for company apps and data. The employer pushes security settings to that profile and can selectively wipe only the work container, leaving personal photos, messages and apps untouched. Microsoft documents this work-profile and app-protection model in its Intune deployment guidance. For a lighter touch, Mobile Application Management (MAM) applies policy to specific apps - stopping data copying from Outlook into a personal notes app, for example - without enrolling the whole device. ## MDM vs MAM: which approach fits your business? The choice between MDM and MAM depends on data sensitivity and how much control the business needs. Full MDM gives the strongest enforcement; MAM is lighter and suits staff who resist enrolling personal devices. Many UK SMEs run a mix, matching the control level to the data each role handles. | | Approach | Control level | Best for | Wipe scope | Full MDM (work profile) | Highest - enforce encryption, PIN, OS minimums | Sensitive or regulated client data | Selective wipe of work container | MAM (app-level policy) | App data only - no device-level control | Email and Teams, lower sensitivity | Wipes managed app data only | Containerisation | Strong data separation, no full device management | Mixed BYOD estates | Wipes the secure container only AMVIA advises clients on the right balance based on the data their staff access and the risk the business will accept - then implements and manages it as part of a wider managed cybersecurity service. ## Why do UK SMEs need BYOD security? UK SMEs need BYOD security because personal devices are a common, poorly defended attack vector. A lost phone with access to company email or cloud files can expose client data and trigger a reportable breach. Remote and hybrid working has pushed far more company data onto devices the business does not directly control. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach in the past year - and mobile devices without enforced encryption or PIN locks are a frequent entry point. With around 28% of UK employees now working in a hybrid pattern, staff check email on personal phones and access Teams on personal tablets daily, each interaction a potential exposure point. Mobile malware attacks have also risen sharply year on year, and personal devices are hit hardest because they rarely carry enterprise-grade protection. The NCSC's device security guidance sets out the baseline controls every BYOD programme should enforce. ## How does BYOD security support UK GDPR compliance? BYOD security supports UK GDPR compliance because the business remains the data controller regardless of who owns the device. Under UK GDPR the organisation is responsible for personal data processed on staff handsets, and unmanaged access without controls is unlikely to meet the law's "appropriate technical measures" test. Several GDPR duties map directly onto BYOD controls: - Data protection by design and default (Article 25): controls must be built in, not bolted on - unmanaged access fails this test. - Security of processing (Article 32): encryption, access controls and the ability to remove data remotely are all relevant measures. - Breach notification (Articles 33–34): a lost device holding unencrypted personal data may be reportable to the ICO within 72 hours. - Employee privacy: selective wipe - never full-device wipe - must be used on personal devices, and the policy must state plainly what the employer can see. A documented BYOD policy plus MDM or MAM enrolment records forms the accountability evidence the ICO expects in an investigation. ## What should a BYOD security policy include? A BYOD security policy should pair clear written rules with enforced technical controls and a defined leavers process. It must specify acceptable use, minimum device standards, data separation, and exactly what the employer can and cannot access. Staff should sign an informed acknowledgement before any device is enrolled. - Acceptable use: which apps, systems and data staff may reach from personal devices. - Device security baseline: PIN or biometric lock, OS updates, encryption and screen timeout. - MDM or MAM enrolment: managed work profile or app-level policy enforcing the baseline. - Data separation: work and personal data kept apart - personal content invisible to the employer. - Remote wipe scope: selective wipe of the work profile only, tested before rollout. - Leavers process: access revoked and the work profile wiped on the day of departure, tied to HR offboarding. - Laptops too: personal laptops covered via conditional access policies in Microsoft Entra ID before they reach Microsoft 365. - Annual review: revisit policy and controls each year as threats and devices change. ## How much does BYOD security cost? BYOD security cost depends on how you license the management layer and how many devices you enrol. Most UK SMEs already own the tooling: Microsoft Intune is included in Microsoft 365 Business Premium, so the device-management capability often costs nothing extra beyond a plan upgrade. Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual commitment) and bundles Intune MDM/MAM alongside Defender for Business - confirmed on Microsoft's UK pricing pages. Standard sits at £9.60 and Basic at £4.60, but neither includes Intune. The remaining cost is implementation and ongoing management - policy design, enrolment, baseline configuration and leavers handling - which AMVIA delivers as a managed Microsoft 365 security service so your internal team carries none of the admin. ## Frequently asked questions Q: Can my employer see my personal data if my phone is enrolled in MDM? A: No. When MDM uses a work profile - as with Microsoft Intune on Android or Apple Business Manager on iOS - the employer manages only the work container. Personal apps, photos, messages and contacts stay private and invisible. This separation is a core GDPR requirement and should be stated plainly in your BYOD policy. Q: What happens to company data on my personal device when I leave? A: Under a properly configured BYOD policy, IT remotely wipes the work profile when employment ends. That removes company email, apps and files from the managed container while leaving personal content untouched. Without MDM there is no reliable way to do this - which is exactly why a written policy backed by technical controls matters. Q: Is BYOD security suitable for businesses handling sensitive data? A: Yes, provided the controls are strong enough - mandatory MDM enrolment, data separation, tested remote wipe and a clear written policy. For the most sensitive data, some firms restrict access to company-owned devices instead. AMVIA advises on the right approach based on the data your staff actually process. Q: Does BYOD security need to cover laptops as well as phones? A: Yes. Personal laptops that reach company systems need the same discipline. The controls differ - typically conditional access policies in Microsoft Entra ID that require a device to meet compliance rules before it can open Microsoft 365. AMVIA configures these as part of a complete BYOD implementation. Q: Should BYOD phones be managed with MDM or MAM? A: MDM manages the device and can enforce encryption, PIN and OS minimums through a work profile. MAM manages only specific apps and the data inside them, without controlling the device itself. MDM gives stronger protection for sensitive data; MAM suits staff who only access email and Teams and resist full enrolment. --- # Business Mobile Security: Protecting Company Data on Phones URL: https://amvia.co.uk/business-mobiles/mobile-security Last updated: 2026-07-09 Mobile security protects company data on smartphones and tablets through device management, encryption, strong authentication and remote wipe. For UK businesses, that means enrolling every phone in Microsoft Intune and enforcing Conditional Access so only compliant devices reach Microsoft 365. AMVIA runs this as one security-first, Microsoft-certified service. A modern company phone holds email, files, cloud logins and often MFA codes - so a lost or unmanaged device hands an attacker a working key to your business. Mobile security closes that gap, and it sits inside our wider business mobile services so the same controls cover every handset you issue. The National Cyber Security Centre recommends device management and a minimum security baseline on every device that touches company data. ## What is business mobile security? Business mobile security is the full set of technical controls, policies and software that protect company data on phones and tablets. It guarantees that every device reaching corporate email, files and apps meets a defined baseline - whether company-owned or personal (BYOD). It treats a phone as an endpoint, not an afterthought. In practice that baseline covers five things: encryption at rest, strong authentication, mobile device management (MDM) enrolment, controlled app installation, and a tested remote wipe. Miss one and you leave a documented, exploitable gap. AMVIA enforces all five through mobile device management rather than leaving them to each user's good habits. ## How does business mobile security work? Mobile security is enforced through MDM software. Microsoft Intune - included in Microsoft 365 Business Premium at £16.90 per user per month (microsoft.com/en-gb) - is the most widely adopted platform among UK SMEs. Once a device is enrolled, an administrator pushes policy: mandatory PIN or biometric lock, full-disk encryption, an approved app list and VPN configuration. Conditional Access policies in Microsoft Entra ID work alongside Intune so only compliant, enrolled devices can reach Microsoft 365 email, SharePoint and Teams. A non-enrolled device that tries to pull corporate mail with a correct password is blocked until it meets compliance. Beyond MDM, a complete strategy adds Mobile Threat Defence (MTD). MTD runs on the device, scanning for malicious apps, phishing links and suspicious networks such as man-in-the-middle attacks on public Wi-Fi. When it finds a threat, it flags the device as non-compliant in Intune, and Conditional Access blocks access until the threat is cleared. ## What are the five core mobile security controls? Every UK business that issues phones or allows personal devices for work should have five controls in place. These are the minimum baseline - each one maps directly to a real attack you are otherwise exposed to. - Device encryption: all company devices encrypted at rest. iOS encrypts by default once a passcode is set; Android 10+ supports full-disk or file-based encryption. Intune verifies status and blocks unencrypted devices. - Strong authentication: biometric enable plus a strong alphanumeric passcode as fallback, and MFA for cloud apps. Intune enforces minimum PIN length and complexity across the fleet. - MDM enrolment: every device enrolled before it is issued, giving the business visibility and control it otherwise has none of. - Application management: an approved app catalogue, blocked sideloading (critical on Android), and MAM policies that stop data leaking from Outlook into personal apps. - Remote wipe: a tested process - full wipe for company devices, selective wipe of the work profile for BYOD devices - ready before a device is lost, not after. ## Why do UK SMEs need mobile security? Attackers increasingly target phones because they are often less protected than laptops yet reach the same data. Smishing, malicious apps from unofficial stores and public-Wi-Fi interception are all growing. According to DSIT's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach, with phishing - including attacks delivered via mobile messaging - the most common initial method (gov.uk). With 28% of UK employees now working in a hybrid pattern (ONS 2025), company smartphones routinely connect to home, hotel and hotspot networks where no corporate perimeter applies. Mobile malware attacks also rose around 50% year-on-year (2024 mobile threat data). Device-level controls are what protect data once the network perimeter is gone. Under UK GDPR, you are responsible for personal data processed on work phones; a breach from an unmanaged device can trigger an ICO investigation. Cyber Essentials, the UK government-backed scheme AMVIA holds at Plus level, explicitly requires that all devices accessing company data - phones included - meet minimum controls for encryption, access control and patching. ## Managed vs unmanaged: what changes | | Capability | Unmanaged phone | AMVIA-managed (Intune) | Encryption enforced | Relies on user | Verified by compliance policy | Lost-device response | None | Immediate full or selective wipe | Microsoft 365 access | Password alone | Conditional Access - compliant devices only | App control | Anything installable | Approved catalogue, sideloading blocked | OS update enforcement | Optional | Out-of-date devices restricted | Visibility | None | Live compliance reporting ## What are the most common mobile security mistakes? Even businesses that have started on mobile security leave avoidable gaps. The most common is enrolling devices in MDM but never enforcing Conditional Access - so an unenrolled personal device still reaches corporate email with just a username and password. - Allowing outdated operating systems: old iOS and Android builds carry documented vulnerabilities; Intune can flag and restrict them. - Untested remote wipe: many have it configured but have never run it, so nobody knows the steps when a device actually goes missing. - Ignoring Android sideloading: without MDM restrictions, staff install apps from outside the Play Store and import malware. - Siloing mobile from IT security: phones are endpoints and belong in the same framework as laptops and servers. Linking mobile controls to your wider cybersecurity programme removes the blind spot. ## How does AMVIA manage mobile security? AMVIA configures and runs Microsoft Intune MDM end to end: enrolment, compliance policy, Conditional Access and tested remote wipe. For businesses supplying handsets, we manage the full lifecycle from provisioning to secure disposal, and we integrate every device into the same security framework as the rest of your estate - Microsoft 365 Security included. Whether you are securing a fleet of company phones or running a controlled BYOD programme, you get one accountable provider, security first, with Microsoft-certified engineers. Call 0333 733 8050 to discuss your mobile security requirements. ## Frequently asked questions Q: Do I need MDM if staff only use phones for calls and email? A: Yes. Email on a smartphone holds sensitive business and client data - a lost device without MDM makes that accessible to whoever finds it. MDM enforces encryption and a PIN and gives you remote wipe you would otherwise lack. Microsoft Intune is included in Microsoft 365 Business Premium at no extra charge, so the setup cost is modest against the risk. Q: What is the difference between MDM and mobile threat defence? A: MDM controls device configuration, enforces policy and provides remote wipe. Mobile Threat Defence is a separate layer that actively detects threats on the device - malicious apps, suspicious networks, phishing links in browsers - and flags the device as non-compliant in Intune when it finds one. MDM is the management framework; MTD is the active detection that works alongside it. Q: Can AMVIA manage both iPhones and Android phones? A: Yes. Microsoft Intune supports both iOS and Android, and AMVIA configures and manages both. Apple Business Manager and Android Enterprise provide the enrolment infrastructure for each platform. The security policies applied are broadly equivalent across both, though some specific settings differ between iOS and Android. Q: What happens when a company phone is reported lost? A: With Intune in place, AMVIA initiates a remote wipe immediately - a full wipe for company devices, or a selective wipe of company data only for BYOD handsets with a work profile. The device is removed from the compliant list, blocking further access to company resources. We manage this as part of the service so the response is fast. Q: Does Cyber Essentials require mobile security controls? A: Yes. The UK government-backed Cyber Essentials scheme treats every device that accesses company data - phones and tablets included - as in scope. It requires minimum controls covering encryption, access control, security update management and firewalling. Enrolling devices in Intune and enforcing compliance policy is the most reliable way for an SME to evidence these on mobile. --- # Remote Wipe and Device Security for Company Mobiles URL: https://amvia.co.uk/business-mobiles/remote-wipe-device-security Last updated: 2026-03 Remote wipe device security is the ability to erase company data from a lost, stolen, or departing employee's mobile over the internet - without holding the device. It only works if the phone was enrolled in mobile device management first. AMVIA configures Microsoft Intune so every company phone is wipe-ready: one provider, security-first, Microsoft-certified. This is a core control inside AMVIA's business mobile security management. A company phone with live access to email, Teams, and files - but no way to wipe it - is a data breach waiting to happen. ## What is remote wipe and how does it work? Remote wipe is a feature of Mobile Device Management (MDM) platforms such as Microsoft Intune that lets an administrator send an erase command to a managed device. The device does not need to be online when the command is sent - it queues and executes the wipe the next time it connects to any network. There are two types UK businesses use: - Full wipe (factory reset) - removes all data, apps, settings, and accounts, returning the device to its out-of-box state. Used for company-owned devices that are lost, stolen, or decommissioned. - Selective wipe - removes only company data (Outlook email, Teams, SharePoint, OneDrive, corporate apps) while leaving personal photos, messages, and apps untouched. Used for personal BYOD devices. Selective wipe is the main reason most businesses deploy Mobile Application Management (MAM) for staff-owned phones - you protect company data without destroying someone's personal content. ## Full wipe vs selective wipe: which applies? The right wipe type depends on who owns the device. Company-owned hardware can be fully reset; staff-owned BYOD phones should only have their work profile removed. Getting this wrong either leaves data exposed or wipes an employee's personal life by mistake. | | Factor | Full wipe | Selective wipe | Device type | Company-owned | BYOD / personal | What is erased | Everything (factory reset) | Company data only | Personal content | Removed | Preserved | Typical trigger | Lost, stolen, decommissioned | Leaver, MAM-managed device | Underlying tool | Intune MDM | Intune MAM / app protection AMVIA defines the full-vs-selective policy per device group before any phone is issued, so the correct action fires automatically when an incident is reported. ## Why do UK SMEs need remote wipe? Mobile loss is one of the most common device security incidents UK businesses face. A 2024 UK survey found that 23% of employees had lost a work mobile device at some point, and most were never recovered. Without remote wipe, a lost phone with work email stays a live risk until its battery dies or someone resets it. ## UK GDPR and breach reporting Under UK GDPR, personal data must be protected with appropriate technical measures. A lost company phone holding customer contacts or email correspondence is a personal data breach risk - and serious breaches must be reported to the Information Commissioner's Office (ICO) within 72 hours. Remote wipe is the technical control that can stop a lost device from becoming a reportable breach. If the device is encrypted and wiped before its data is accessed, the ICO weighs those mitigations when assessing severity. The NCSC's device security guidance names remote wipe and encryption as baseline controls for mobile devices that hold business data. ## Leavers and insider risk When someone leaves - especially in difficult circumstances - their phone may still hold client data, financials, or cached business intelligence. A wipe triggered the moment they depart removes that access before it can be misused. Without it, a business often has no way to recover or revoke data on a device a former employee keeps. ## What device security controls work alongside remote wipe? Remote wipe is most effective inside a broader baseline. AMVIA's mobile device management enforces these controls through Intune compliance policies, so a lost device is already hard to break into before any wipe completes. - Device encryption - iOS encrypts by default once a passcode is set; Intune policies enforce encryption on Android. Encrypted data cannot be read without the PIN even if the wipe is delayed. - PIN and biometric lock - every managed device must require a PIN, password, or biometric to enable. Without it, encryption is pointless. - Screen lock timeout - AMVIA typically configures a one to two minute timeout so the screen locks quickly if a phone is set down. - Jailbreak and root detection - compromised devices are marked non-compliant and blocked from Microsoft 365 via Conditional Access. - Minimum OS version - devices running outdated, unpatched operating systems are blocked until updated. These controls are configured and monitored through Microsoft Intune for business mobiles, and tie into AMVIA's wider managed cybersecurity so mobile risk is governed the same way as the rest of your estate. ## How does AMVIA trigger a remote wipe? When a phone is reported lost, stolen, or a staff member leaves, AMVIA runs a documented process so the wipe is fast and auditable. Speed matters: access is revoked first, then the device is wiped, then the event is logged for compliance. 1. AMVIA is notified by the owner, IT manager, or HR that a wipe is required. 2. The device is located in the Intune console. 3. The correct command is sent - full wipe for company devices, selective wipe for BYOD. 4. The device queues the command and executes it on next connection. 5. AMVIA confirms completion and documents the wipe for compliance records. For a senior employee's stolen device holding sensitive data, AMVIA escalates the wipe as a priority incident with immediate action. ## What does AMVIA's mobile device security service include? AMVIA's business mobile security management bundles remote wipe with the full Intune deployment. Microsoft Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual), so most SMEs already hold the licence. - Intune enrolment for all company mobiles and tablets - Compliance policy configuration - encryption, PIN, OS version, jailbreak detection - MAM configuration for BYOD personal devices - Remote wipe on demand, full or selective, with documented response - Regular compliance reporting and alerting on policy failures - Device retirement and decommissioning management ## Remote wipe readiness checklist Confirm these before you need a wipe - the control only works if it was set up in advance. - All devices enrolled in MDM before issue - wipe only works on enrolled devices. - Full-vs-selective policy defined per device group. - Wipe procedure tested on a spare device before a real incident. - Staff know exactly who to call the moment a device is lost. - Access revocation configured in Microsoft Entra ID, ready to block Microsoft 365 instantly. - Lost-device incident process documented, including the GDPR breach assessment timeline. ## Frequently asked questions Q: What is remote wipe for mobile phones? A: Remote wipe is the ability to erase data from a mobile device over the internet, without holding it. An administrator sends a command that removes company data from a lost, stolen, or departing employee's device. A full wipe resets the phone to factory settings; a selective wipe removes only company data from managed apps. Q: Can remote wipe erase a personal phone? A: For personal BYOD devices, AMVIA's standard approach is selective wipe - removing only company data such as Microsoft 365 email, Teams, and SharePoint files, while personal photos, messages, and apps stay untouched. A full factory-reset wipe is only performed on company-owned devices, where erasing everything is appropriate and proportionate. Q: Does the device need Wi-Fi for remote wipe to work? A: No. The wipe command is sent and queued in the management system. When the device next connects to any network - Wi-Fi or mobile data - it receives and executes the command. If the phone is switched off, the wipe runs the moment it is turned back on and reconnects. Q: Is remote wipe required for GDPR compliance? A: UK GDPR requires appropriate technical measures to protect personal data, and remote wipe is a key control for mobiles that store or access it. Without remote wipe, a business cannot properly respond to a lost device, and the ICO may consider the absence of that control when assessing a breach. Q: What data does a selective wipe remove? A: Selective wipe removes data inside Microsoft 365 managed apps: Outlook email, Teams messages, SharePoint and OneDrive files, and other Intune-managed apps. Corporate Wi-Fi and VPN profiles may also be removed. Personal photos, personal messages, personal app data, and personal accounts are unaffected. --- # How Do I Manage Company Mobile Phones? A Guide for UK Businesses URL: https://amvia.co.uk/business-mobiles/questions/how-to-manage-company-mobiles Last updated: 2026-03 Manage company mobiles through a Mobile Device Management (MDM) platform - Microsoft Intune is the standard for businesses already on Microsoft 365. MDM enforces encryption, remotely wipes lost devices, pushes security policy, and walls personal data off from corporate data. AMVIA runs this for you: one provider, security-first, Microsoft-certified. A lost phone is not a lost phone. It is a lost mailbox, a lost set of files, and a lost door into your tenant. If you hand staff a handset without a way to enforce a passcode, encrypt the device, and wipe it on demand, you have handed out unmanaged access to your business. This guide explains, step by step, how to manage company mobiles properly - the controls that matter, what AMVIA actually recommends, and where mobile fits into your wider business mobile management strategy. ## What does "managing company mobiles" actually mean? Managing company mobiles means controlling the security, configuration, and data on every handset that touches your business - whether you bought it or your employee did. It covers enrolment, policy enforcement, app distribution, and the ability to remove corporate data without touching personal photos or messages. The practical building blocks are: - Enrolment - every device registered to a central console before it gets corporate email. - Policy - enforced passcode, encryption, and OS-update rules applied automatically. - App management - push approved apps; block or sandbox the rest. - Conditional access - only compliant, enrolled devices reach Microsoft 365. - Wipe - selective removal of corporate data on loss, theft, or a leaver. Without these, you are trusting each employee to secure your data on a device you cannot see. The UK's National Cyber Security Centre device security guidance is blunt about this: mobile devices need the same baseline controls as laptops, because they hold the same access. ## How do I manage company mobiles with Microsoft Intune? If your business runs Microsoft 365, Microsoft Intune is the answer to managing company mobiles - it is the MDM engine built into the platform you already pay for. You enrol each handset, assign compliance and configuration policies, and Intune enforces them on iOS and Android automatically. Non-compliant devices lose access to corporate data. Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual), per Microsoft 365 UK pricing - so most managed businesses already own the licence without realising it. The set-up steps are consistent: 1. Confirm every user has a Business Premium (or equivalent) licence with Intune entitlement. 2. Define a compliance policy: encryption on, passcode required, minimum OS version, jailbreak/root blocked. 3. Define a configuration profile: Wi-Fi, email, and VPN settings pushed automatically. 4. Turn on conditional access so only compliant devices reach Exchange, Teams, and SharePoint. 5. Enrol devices - company-owned through Apple Business Manager / Android Enterprise, BYOD through the Company Portal app. AMVIA configures Intune end to end and monitors compliance for you, rather than leaving you a console and a manual. See our Microsoft Intune mobile management service for how that day-to-day runs, and the broader Microsoft Intune deployment for laptops and desktops. ## Company-owned vs BYOD: which model should I choose? The right model depends on who owns the device and how much control you need. Company-owned gives you full management of the whole handset; Bring Your Own Device (BYOD) keeps costs down but limits you to managing only the corporate apps and data, not the personal side. Most UK SMEs run a mix. | | Factor | Company-owned (COBO/COPE) | BYOD | Who buys the device | The business | The employee | Control level | Full device management | Corporate apps/data only | Upfront cost | Higher (hardware + contract) | Lower (stipend only) | Privacy boundary | Employer-controlled | Personal data ring-fenced | Best for | Field staff, regulated data | Office staff, cost-sensitive teams | Wipe scope | Full or selective | Selective only Whichever you pick, the security model has to be deliberate. BYOD in particular needs a clear data boundary so you can remove corporate access without wiping someone's family photos - covered in our BYOD security guidance. For mixed fleets, get the policy written down before the first device is enrolled. ## How do I secure a lost or stolen company phone? A managed phone is recoverable; an unmanaged one is a breach. With MDM in place you can locate, lock, and wipe a lost handset from a central console in minutes - either a full wipe of a company-owned device or a selective wipe that strips corporate data and leaves personal content alone. This matters because mobile is now a primary target, not an afterthought. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26), which means a stolen, unwiped phone is often a direct route into email and files. The controls that close that gap: - Remote lock and locate the moment a device is reported missing. - Selective wipe to remove corporate mail, Teams, and files without touching personal data. - Conditional access revocation so the device cannot reconnect even if recovered by the wrong person. - Automatic encryption so data at rest is unreadable regardless. AMVIA's remote wipe and device security service makes this a one-call action for your team. Pair it with broader mobile security hardening so the handset is locked down before it is ever lost. ## Can I manage company mobiles across different networks? Yes - MDM is network-agnostic. Microsoft Intune manages devices regardless of whether they sit on O2, EE, Vodafone, or Three, because it controls the operating system and apps, not the SIM. You can run a multi-network fleet and enforce identical security policy on every handset. This is useful when coverage, contract timing, or acquired businesses leave you on several networks at once. The management layer never changes - one console, one policy set, every device. AMVIA also consolidates billing across all networks under a single account, so a mixed fleet does not mean a mixed admin headache. ## What happens to company data when an employee leaves? When someone leaves, MDM lets you perform a selective wipe - removing corporate email, apps, and files from the device while leaving personal data untouched. It works on both company-owned and BYOD handsets, and it happens centrally without needing the device back in the office. This is the offboarding control most businesses miss. Microsoft 365 has over 400 million paid commercial seats (Microsoft FY2025), and the selective-wipe capability is built into Business Premium at no extra cost - yet many firms still rely on asking a leaver to "delete the email app". Make selective wipe a step in your standard leaver checklist, triggered the moment access is revoked. ## What AMVIA recommends For most UK SMEs: standardise on Microsoft Intune, enrol every device, enforce a single compliance baseline, and turn on conditional access so only managed devices reach your data. Choose company-owned for field and regulated-data staff, BYOD with a strict data boundary for everyone else. Then make remote wipe a rehearsed, one-call action - not a thing you figure out under pressure. The point of managing company mobiles is not control for its own sake. It is making sure that the worst day - a phone left in a taxi - is a five-minute task, not a notifiable data breach. That is the difference between a fleet you manage and devices you merely own. ## Frequently asked questions Q: What is the best way to manage company mobiles? A: The most reliable way to manage company mobiles is a Mobile Device Management platform, with Microsoft Intune the default for any business on Microsoft 365. It enrols every device, enforces encryption and passcodes, controls which apps can run, and lets you wipe corporate data remotely. It turns a fleet of unknown handsets into managed, policy-compliant endpoints. Q: Do I need MDM if I only have a few company phones? A: Yes. Risk scales with data, not device count. Even one unmanaged phone holding business email is a route into your tenant if it is lost or stolen. MDM enforces a passcode, encrypts the device, and lets you wipe it remotely - controls that matter just as much for five phones as for five hundred, and that Intune applies the same way at any scale. Q: Is Microsoft Intune included in my Microsoft 365 licence? A: Microsoft Intune is included in Microsoft 365 Business Premium, listed at £16.90 per user per month ex VAT on annual billing on Microsoft's UK pricing. Many businesses already hold this licence without using the mobile-management capability inside it. If your staff are on Business Premium, you can begin enrolling and securing company mobiles without buying anything new. Q: Can I manage personal phones used for work without invading privacy? A: Yes. BYOD enrolment in Intune manages only the corporate apps and data, never the personal side of the device. You can enforce policy on work email and files, and selectively wipe them when needed, while personal photos, messages, and apps stay private and untouched. A clear, written data boundary makes this acceptable to staff and defensible for the business. Q: How quickly can I wipe a lost company phone? A: With MDM already in place, a remote lock or wipe takes minutes from a central console. You do not need the device back or the employee's cooperation - you trigger the action, and corporate data is removed or the handset is locked. This is why enrolment matters before loss happens: you cannot wipe a device that was never managed. --- # How Much Does a Business Mobile Plan Cost in the UK? URL: https://amvia.co.uk/business-mobiles/questions/business-mobile-plan-cost Last updated: 2026-03 A UK business mobile plan typically costs £8–£20 per SIM per month on SIM-only deals from O2, EE, Vodafone and Three, with full device contracts adding £15–£30 per month. Volume discounts, data pooling and the handset you pick move the final figure. AMVIA sources and manages all four networks under one accountable contract. ## What does a business mobile plan actually cost in the UK? Business mobile SIM-only plans cost £8–£20 per SIM per month from UK networks including O2, EE, Vodafone, and Three. Full device contracts add £15–£30 per month. Where you land in those ranges depends on data allowance, contract length, and how many connections you put on one account. Here is how the typical per-user, per-month cost breaks down by tariff type: | | Plan type | Typical cost (per SIM/mo, ex VAT) | What you get | Entry SIM-only (5–20GB) | £8–£12 | Calls, texts, mid data, your own handset | Standard SIM-only (25–100GB) | £12–£18 | Larger data, 5G, EU roaming | Unlimited SIM-only | £16–£20 | Uncapped data, priority 5G | Device contract (mid-range) | +£15–£25 | New handset bundled over 24–36 months | Device contract (flagship) | +£25–£30 | Premium handset, higher upfront A practitioner's rule of thumb: most 10–500-staff UK businesses we manage settle around £10–£15 per SIM once the right tariff and volume tier are matched to actual usage. For a fuller breakdown of plan structures, see our guide to business mobile contracts, or the business mobiles hub for the full picture. ## SIM-only vs full device contract - which is cheaper? SIM-only is almost always cheaper over the term because you are not financing a handset inside the monthly fee. A £12 SIM-only plan over 24 months costs £288; the same plan bundled with a £700 phone costs roughly £700 more across the contract. The trade-off is the upfront handset spend. | | Factor | SIM-only | Full device contract | Monthly cost | £8–£20 | £23–£50 (SIM + device) | Handset | You supply | Included, financed | Total over 24 months | Lower | Higher (interest on device) | Flexibility to switch | High | Locked to term | Best for | Businesses reusing handsets | Teams needing new devices now If your handsets are under three years old and still supported, SIM-only business mobile plans are the lower-cost route. Reserve device contracts for staff who genuinely need new hardware. ## How do volume discounts and data pooling cut the bill? Volume pricing is where businesses save most. Discounts apply from around 10 SIMs upward, with meaningful discounts at 25 and 50+ connections. Pair that with shared data pooling and you stop paying overage charges on individual SIMs that exceed their allowance. - Volume tiers: networks step the per-SIM price down as connection count rises - 10, 25 and 50+ are the common break points. - Data pooling: all SIMs draw from one shared allowance, so light users subsidise heavy users and you avoid per-line overage fees. - Single bill: one account across the estate cuts admin time and surfaces unused SIMs you can cull. Aggregating connections through a single managed contract, rather than scattering them across consumer accounts, is the simplest way to bring the blended per-user cost down toward the bottom of the £8–£20 range. ## Does 5G change what you should pay? 5G rarely adds a large premium on modern tariffs - most standard and unlimited SIM-only plans now include it by default. What matters is coverage and device support. 5G outdoor coverage is available from at least one operator at 97% of UK premises (Ofcom, 2025), so for most teams it is becoming the baseline rather than an upsell. Check real-world coverage for your sites on the regulator's data before committing - Ofcom publishes operator-by-operator coverage in its Connected Nations reporting. If field staff rely on data in fringe areas, prioritise the network with the strongest local 5G rather than the cheapest headline price. Our 5G business mobile page covers device and coverage selection in detail. ## How does the PSTN switch-off affect mobile strategy? The UK PSTN switch-off is scheduled for completion by January 2027 (Openreach), which is pushing more businesses to consolidate voice onto mobile and internet-based calling. As traditional analogue lines retire, mobile becomes a primary voice channel for many sites, so it is worth budgeting mobile and voice together rather than in isolation. If you are reviewing mobile spend now, do it alongside your voice plan - the two decisions interact. See our PSTN switch-off briefing for the timeline and migration options. Ofcom's guidance on the migration of landlines to digital sets out what changes for businesses. ## What does it cost to secure and manage those mobiles? Budgeting only for airtime understates the real cost. Every business phone touches company email, files and Microsoft 365, so management and security are part of the total. The good news: securing a fleet is inexpensive relative to the risk it removes, and it is where AMVIA's security-first model earns its place. - Mobile device management typically adds a few pounds per device per month and lets you enforce passcodes, encryption and remote wipe - see mobile device management. - Microsoft Intune is included in many Microsoft 365 Business Premium licences (£16.90/user/mo ex VAT, microsoft.com/en-gb), so the control plane may already be paid for - see Microsoft Intune for mobile. - Lost-device risk: the NCSC's device security guidance explains why unmanaged phones are a soft target. Microsoft Intune is documented at learn.microsoft.com for teams that want the technical detail. The point stands: the cheapest plan is not the cheapest outcome if a single lost, unmanaged handset exposes your data. ## Frequently asked questions Q: What does a business mobile plan cost per SIM? A: SIM-only business deals typically run £8–£20 per month across the main UK networks, with device-inclusive contracts adding £15–£30 for the handset finance. Fleet terms improve with volume - consolidating scattered consumer contracts usually beats their sum. Q: Is SIM-only or a handset contract better value? A: If existing phones have life left, SIM-only banks the £15–£30 monthly handset premium across every user. Device contracts make sense at refresh time or for field teams who punish hardware - most fleets sensibly mix both. Q: What should a business plan include beyond minutes and data? A: Pooled data across the fleet, one bill, a business support line, and - the piece consumer plans never carry - management: MDM enrolment, security policies and remote wipe. The plan is the cheap part; the control is the value. Q: Can we move networks without changing numbers? A: Yes - business numbers port between networks as standard. Moving the fleet onto one business account keeps every number while consolidating billing and support, and it's usually the moment to enrol devices into management too. --- # MDM vs MAM: What's the Difference for Business Mobile Security? URL: https://amvia.co.uk/business-mobiles/compare/mdm-vs-mam Last updated: 2026-03 MDM (Mobile Device Management) secures the whole device; MAM (Mobile Application Management) secures only the work apps and data on it. Use MDM for company-owned phones and MAM for staff-owned (BYOD) handsets. Microsoft Intune runs both from one platform - the model AMVIA deploys across its business mobile estates. The two are not rivals. Most UK businesses end up running both: full device management on corporate phones, app-only management on the personal devices staff use to reach email and Teams. Below is exactly how they differ, when each fits, and why a single Intune-based setup beats bolting two tools together. ## What is the difference between MDM and MAM? MDM manages the entire device - enrolment, encryption, OS patch level, app deployment, and full remote wipe. MAM manages only specific apps, applying work policies to Outlook, Teams and SharePoint without touching personal apps or data. MDM controls the phone; MAM controls the corporate data inside it. That distinction decides everything else: who owns the device, how much privacy staff keep, and what happens when someone leaves. MDM gives IT total control, which is appropriate when the business owns the hardware. MAM gives IT control of the data only, which is the right answer when the employee owns the hardware and reasonably expects their photos, messages and personal apps to stay private. For a fuller breakdown of device-level control, see our guide to mobile device management. ## How do MDM and MAM compare feature by feature? At a control level MDM is a superset of MAM: anything MAM does to an app, MDM can also do, plus everything at the device layer. The trade-off is privacy and friction - MDM enrolment is intrusive, MAM is near-invisible to the user. This table maps the practical differences. | | Feature | MDM | MAM | Device enrolment required | Yes | No | Manages personal apps | Yes | No | Manages personal data | Yes (full wipe capability) | No | Enforces device encryption | Yes | No (app-level encryption only) | Enforces OS patch level | Yes | No | Enforces PIN for work apps | Yes | Yes | Blocks copy-paste to personal apps | Yes | Yes | Selective wipe (work data only) | Yes | Yes | Full device wipe | Yes | No | Deploy/remove apps | Yes | Managed apps only | Restrict device features | Yes | No | Employee privacy impact | High | Low | Appropriate for company devices | Yes | - | Appropriate for BYOD | Not recommended | Yes The single most important row is the last two: MDM belongs on hardware you own, MAM belongs on hardware your staff own. Force MDM onto a personal phone and you take on the legal and practical liability of being able to wipe an employee's photos and messages - a fight you do not want. ## When should you choose MDM? Choose MDM when the business owns the device and needs control of the whole thing - encryption, patch level, restricted features, and the ability to wipe it entirely if it is lost or stolen. It is the right model for company phones, shared frontline devices, and any handset holding sensitive data on the device itself. Pick MDM when: - You own the hardware. Company-purchased phones and tablets should be fully managed - there is no privacy trade-off because the device is a business asset. - You need device-level compliance. Enforcing encryption, minimum OS version and screen-lock policy across the fleet requires device control, not just app control. - Loss or theft is a real risk. Frontline, field and logistics staff lose devices. Full remote wipe protects everything on the handset, not just the work apps. - You issue kiosk or single-purpose devices. Locking a device to one app or a fixed configuration is an MDM-only capability. The NCSC's mobile device guidance sets out why corporate devices should enforce encryption and patching at the device level - exactly what MDM provides. ## When should you choose MAM? Choose MAM when staff use their own phones for work. App management protects company data inside Outlook, Teams and SharePoint - enforcing a PIN, blocking copy-paste into personal apps, and allowing a selective wipe of work data - without enrolling or controlling the device. Staff keep their personal apps, photos and data fully private. MAM is the right model when: - Staff use personal devices (BYOD). You protect the data without claiming the device, which keeps both your security team and your employees comfortable. - You cannot mandate enrolment. Contractors, seasonal staff and short-term hires will not hand over their personal phone to full management - MAM still secures the data. - Privacy is a sticking point. App-only control removes the objection that IT can see or wipe someone's personal life. This BYOD reality is widespread: as of 2025, 53% of UK homecare staff use personal devices (BYOD) for work, and 80% of companies say mobile devices are critical to operations. For the policy side of getting this right, see our BYOD security policy guidance. ## Why does the choice matter for security? It matters because unmanaged mobiles are now a primary attack surface. Mobile threats are dominated by phishing and scams rather than classic malware, and an unprotected personal phone reaching your Microsoft 365 tenant is an open door. The right management model closes it without alienating staff. The threat data backs this up: in 2025, 90% of mobile threats stemmed from scams and phishing, and 18.1% of enterprise devices had mobile malware (Zimperium 2025). A phone with no PIN policy, no copy-paste controls and no way to revoke access is the weakest link in an otherwise hardened estate. MAM closes that gap on BYOD; MDM closes it on corporate devices. Either way, the control has to exist before an incident, not after - which is why we fold mobile management into our broader managed Microsoft 365 service. ## Do you need separate tools for MDM and MAM? No. Microsoft Intune delivers both MDM and MAM from a single console and is included in Microsoft 365 Business Premium. You apply full MDM to corporate devices and MAM-only policies to BYOD handsets within the same platform - no second product, no separate licence, no integration overhead. This is the decisive advantage for any business already on Microsoft 365. Running one platform for both models means one set of policies, one place to manage exits, and tight integration with Entra ID conditional access. Microsoft 365 Business Premium lists at £16.90 per user/month (ex VAT, annual) and bundles Intune in full - see the Microsoft 365 plan comparison. For the deployment detail, our Microsoft Intune for mobile page walks through the setup, and Intune's official documentation covers the underlying capabilities. ## What does AMVIA recommend? Use MDM for company-owned devices and MAM for BYOD. Microsoft Intune supports both models within a single platform - included in Microsoft 365 Business Premium. AMVIA recommends a hybrid approach: full MDM on all corporate assets, with MAM-only policies applied to personal devices accessing company email and SharePoint. This is the standard we deploy for all managed clients. The hybrid model gives you full control where you own the hardware and data-only control where you do not - without forcing staff to surrender their personal phones. When someone leaves, disabling their Microsoft 365 account cuts app access, and a selective remote wipe pulls company data off their personal device while leaving everything personal untouched. One provider, security-first, Microsoft-certified engineers - set up once, managed continuously. ## Frequently asked questions Q: What is the difference between MDM and MAM? A: MDM (Mobile Device Management) manages the entire device - applying security policies, enforcing compliance, and enabling remote wipe at the device level. MAM (Mobile Application Management) manages only specific applications, applying security policies to work apps such as Outlook, Teams and SharePoint without affecting personal apps or data. MDM is for company-owned devices; MAM is for personal (BYOD) devices. Q: Can employees use their personal phone for work without full MDM? A: Yes. Mobile Application Management (MAM) lets you protect company data on personal devices by applying security policies specifically to Microsoft 365 apps, without enrolling the device in full management. Staff can use their personal phones for work email and Teams whilst keeping their personal apps, photos and data completely private. Q: Is Microsoft Intune required for MDM and MAM? A: Microsoft Intune is the recommended MDM and MAM platform for businesses using Microsoft 365, and is included in Microsoft 365 Business Premium. Other platforms such as Jamf and VMware Workspace ONE exist but are generally less tightly integrated with the Microsoft 365 ecosystem. AMVIA deploys Intune as the primary MDM/MAM solution for UK SMEs. Q: What happens to MAM-managed data when an employee leaves? A: When an employee leaves, their Microsoft 365 account is disabled or removed from your tenant, which automatically revokes access to Microsoft 365 apps. Intune MAM can also perform a selective wipe, removing all company data from the Microsoft 365 apps on their personal device. Personal apps, photos and personal data on the device are unaffected. Q: Can you run MDM and MAM at the same time? A: Yes, and most businesses should. A hybrid setup applies full MDM to company-owned devices and MAM-only policies to personal BYOD handsets, all managed from a single Microsoft Intune console. This gives IT total control of corporate hardware while protecting company data on personal phones without managing the device itself. Q: Does MAM let IT see or delete personal data? A: No. MAM controls only the managed work apps and the company data inside them. IT cannot see an employee's personal apps, photos, messages or browsing, and a selective wipe removes only company data. This privacy boundary is the main reason MAM, not MDM, is the correct model for personal devices. --- # Managed IT Support UK: Packages & Costs (from £25/User) URL: https://amvia.co.uk/managed-it Last updated: 2026-03 Managed IT support means outsourcing your day-to-day IT operations - helpdesk, infrastructure monitoring, patching, backup and cybersecurity - to a specialist provider for a fixed monthly fee. UK SMEs typically pay £25–65 per user per month for fully managed IT. AMVIA runs IT for 1,200+ UK business networks: one provider, security-first, Microsoft-certified. ## What is managed IT support? Managed IT support is a contract where an external provider takes ownership of running, monitoring and maintaining your business IT. For a UK SME it replaces or extends an internal IT function - giving you a full team of engineers, a UK helpdesk and 24/7 monitoring at a predictable monthly cost instead of unplanned firefighting. The day-to-day scope of a serious managed IT contract covers: - IT helpdesk - phone, email and portal support from UK-based engineers, with documented response times by issue severity. - Infrastructure monitoring - 24/7 automated monitoring of servers, network devices, firewalls and endpoints, remediated before users notice. - Patch management - automated OS and application patching, with a 14-day target for critical vulnerabilities and monthly compliance reports. - Microsoft 365 management - user provisioning, licence optimisation, security configuration and Teams administration. - Backup and disaster recovery - automated daily backup of servers, Microsoft 365 data and cloud apps, with recovery procedures tested at least annually. - Cybersecurity - endpoint protection, email security and firewall management built in, not sold as a separate add-on. For the operational layer of this service, see our managed IT support and UK IT helpdesk pages. ## What's the difference between managed IT and break-fix IT? Break-fix IT is reactive: something breaks, you call an engineer, you pay for the time. Managed IT is proactive: your systems are monitored continuously, problems are fixed before they spread, and you pay a fixed monthly fee. For any business beyond roughly 10 staff, managed IT delivers better uptime at a more predictable cost. | | Factor | Break-fix IT | Managed IT (AMVIA) | Approach | Reactive - fix after failure | Proactive - monitor and prevent | Cost model | Per-incident, spikes when things break | Fixed per-user monthly fee | Strategic input | None - fix and leave | Ongoing roadmap and advice | Incentive | Revenue depends on problems | Contractual incentive to keep you running | Out-of-hours | Ad hoc, often unavailable | 24/7 cover and monitoring See how the co-managed model fits alongside an in-house IT manager on our co-managed IT page. ## Why do UK SMEs need managed IT support? UK SMEs need managed IT because the threat and uptime burden has outgrown what one or two internal hires can cover. The UK government reports that 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025) - continuous monitoring and patching is the practical defence. That figure comes from the UK government's own research; read the Cyber Security Breaches Survey 2025. The National Cyber Security Centre sets out why timely patching and monitored endpoints are among the highest-impact controls a smaller business can put in place. Managed IT closes the gap with: - Continuous patching and monitoring that a stretched internal hire cannot maintain alone. - A documented, supported environment instead of undocumented tribal knowledge. - Built-in security controls aligned to recognised UK guidance. - For deeper protection, our complete business IT protection and business continuity services extend cover to recovery and resilience. ## How does AMVIA onboard a new managed IT client? Switching provider follows a structured four-week programme designed for continuity. AMVIA audits and documents your full estate, deploys monitoring across every device, establishes a security baseline, then moves your team onto the helpdesk - with monthly reporting from day one. No disruptive "rip and replace". - Week 1–2 - Discovery: full audit of servers, devices, licences and cloud services, producing a documented IT asset register and network diagram. - Week 2–3 - Tooling: Remote Monitoring and Management (RMM) agents deployed and monitoring policies configured across the estate. - Week 3–4 - Security baseline: posture assessed against security compliance requirements, with gap remediation started. - Week 4+ - Business as usual: your team uses the AMVIA helpdesk, and monthly reporting on tickets, system health and patch compliance begins. If you run on-premises or hybrid infrastructure, our IT infrastructure management and cloud migration services handle the heavier projects discovery uncovers. ## How much does managed IT support cost? Managed IT support for UK SMEs typically costs £25–65 per user per month for fully managed IT, rising with scope. As a guide, basic helpdesk-and-monitoring cover sits at the lower end, while packages adding Microsoft 365 management, backup and SOC-grade security sit at the top. Pricing is fixed and per-user, with no surprise call-out charges. | | Plan | What it covers | From / user / month | Essentials (most popular) | Helpdesk, monitoring, patching | from £25.00 | Advanced | Essentials + cybersecurity | from £40.00 | Enterprise | Advanced + 24/7 SOC | from £60.00 Compare this to building the same capability in-house. A single in-house IT hire costs £40,000+ before overheads; a mid-level IT engineer in the UK costs £35,000–£55,000 in salary alone, plus employer NI, pension, holiday cover, equipment and recruitment. A team of three - the minimum for adequate coverage - costs well over £150,000 per year. Managed IT delivers equivalent or better capability for a fraction of that for most UK SMEs. ## What service levels should you expect? You should expect contractual response times tied to issue severity, not vague best-effort promises. AMVIA's SLA defines four priority tiers, with response measured as an engineer actively investigating - not an automated acknowledgement. Critical incidents are covered 24/7/365, and breaches of the commitment carry defined consequences. - Priority 1 (Critical): complete outage or security incident - one-hour response, 24/7/365. - Priority 2 (High): significant degradation affecting multiple users - two-hour response in business hours. - Priority 3 (Medium): single-user issue - four-hour response in business hours. - Priority 4 (Low): minor request or change - next business day. Two operational facts worth weighing alongside any provider comparison: AMVIA runs a 10-person team, and our average customer contract term is 24 months. Customers who take co-managed IT or full managed IT alongside connectivity get one provider and one SLA across the whole estate - and if certification is on your roadmap, our plans build the five Cyber Essentials controls in as standard - starting at the network edge with our managed firewall service on Barracuda and Zyxel platforms. ## Frequently asked questions Q: How much does managed IT support cost per user per month? A: UK SMEs typically pay £25–65 per user per month for fully managed IT, with comprehensive packages adding cybersecurity, Microsoft 365 management and SOC monitoring reaching £65–£80+ per user/month. Compare that to a single in-house IT hire at £40,000+ before overheads. AMVIA prices per user, fixed monthly, with no hidden call-out charges. Q: What is the difference between managed IT and break-fix IT? A: Break-fix IT means you call an engineer when something breaks and pay per incident. Managed IT is a proactive subscription service that monitors your systems continuously, prevents issues and runs a helpdesk for daily support. With 43% of UK businesses hit by a breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025), continuous monitoring and patching materially reduces that risk. Q: Do we lose control of our IT if we outsource it? A: No. A good provider works alongside your team in a co-managed model. You keep strategic control, decision-making and vendor relationships, while the provider takes the operational load - monitoring, patching, helpdesk tickets and out-of-hours cover. That frees your internal team to focus on projects rather than firefighting daily issues. Q: How quickly will AMVIA respond to a support request? A: AMVIA's SLA guarantees a one-hour response for critical issues such as complete outages or security incidents, 24/7/365. High-priority issues affecting multiple users get a two-hour response in business hours, single-user issues four hours, and low-priority requests the next business day. These are contractual commitments with defined consequences if breached. Q: What does onboarding look like when switching managed IT provider? A: AMVIA follows a structured four-week programme. Weeks one and two audit every server, device and cloud service to build a documented asset register. Week three deploys monitoring and management tooling across the estate. Week four sets a security baseline and moves your team onto the helpdesk, with monthly reporting starting immediately. The process is designed for continuity, not disruption. Q: Is cybersecurity included in managed IT, or is it extra? A: It is included. AMVIA builds endpoint protection, email security and firewall management into the managed IT service rather than selling them as separate add-ons, in line with NCSC guidance on baseline controls. Security is the connective tissue of the service - one provider, security-first, Microsoft-certified. --- # Managed IT Support for UK Small and Medium Businesses URL: https://amvia.co.uk/managed-it/managed-it-support Last updated: 2026-08-28 Managed IT support is a fully outsourced service where one provider runs, monitors and secures your entire IT estate for a flat monthly fee per user. AMVIA delivers unlimited UK-based helpdesk, 24/7 proactive monitoring and built-in Microsoft security under one accountable, security-first, Microsoft-certified provider - no hourly rates and no ticket limits. This is a core service within our managed IT support pillar, built specifically for UK businesses with 10–500 staff who want predictable IT costs and a security baseline that holds up. ## What's included in AMVIA's managed IT support? Everything that keeps your IT working sits inside one flat monthly subscription: unlimited helpdesk, device monitoring, Microsoft 365 administration, patching and a baked-in security stack. There are no hourly rates, no surprise invoices and no per-ticket charges - you pay one predictable price per user. - Unlimited UK helpdesk - phone, email and live chat from engineers based in Sheffield. See our unlimited IT helpdesk service for response detail. - 24/7 proactive monitoring - RMM agents on every device flag disk health, patch status and backup failures before they cause downtime. - Built-in security stack - Microsoft Defender for Business, email security, DNS filtering and patch management included as standard. - Microsoft 365 management - licensing, provisioning, policy and security configuration for your whole tenancy, run by our managed Microsoft 365 team. - Scheduled on-site visits - a dedicated engineer who knows your estate handles hardware and IT health reviews. - Dedicated account manager - one point of contact who runs quarterly reviews and acts as your virtual IT director. ## How does managed IT support work day to day? Day to day, your team raises tickets and gets them resolved, while monitoring and patching run silently in the background. New clients move across on a structured 30-day onboarding that audits the estate, deploys agents, hardens Microsoft 365, then goes live - designed to land with zero disruption to your staff. Onboarding follows five steps: 1. Discovery & audit - we document devices, licences, cloud services, network topology and security posture. 2. Agent deployment - RMM and security agents roll out silently; first backup is completed and verified. 3. Security hardening - Conditional Access applied, MFA enabled for all users, email security configured, gaps remediated. 4. Team introduction - staff learn how to raise tickets and get a short security-awareness walkthrough. 5. Business as usual - the full service goes live and your account manager books your first quarterly review. For continuity planning beyond day-to-day support, pair this with our business continuity service. ## Why do UK SMEs need managed IT support? Smaller businesses carry the same cyber risk as large ones but rarely have the in-house cover to manage it. The UK government's Cyber Security Breaches Survey 2025/26 found 43% of UK businesses had experienced a cyber breach or attack in the prior 12 months (gov.uk). Managed IT folds prevention, monitoring and recovery into one accountable contract rather than reactive break-fix. The case is straightforward: - Risk - unpatched devices and unconfigured Microsoft 365 tenants are the common entry points the NCSC warns SMEs about. - Cost control - flat per-user pricing removes unpredictable hourly bills. - Continuity - monitoring and verified backups mean failures are caught early, not discovered during an outage. ## In-house IT vs managed IT support: which fits an SME? For most 10–500-staff businesses, a managed service costs less than a single in-house hire while covering more hours, more skills and a defined SLA. The table below sets out the practical trade-offs. | | Factor | In-house IT hire | AMVIA managed IT support | Coverage | Single person, office hours | Full team, 24/7 monitoring | Cost model | Salary + holiday + training | Flat fee per user, per month | Security stack | Bought and configured separately | Microsoft Defender + email security included | Microsoft 365 | Depends on individual skill | Microsoft Solutions Partner team | Holiday / sickness cover | None | Built in | Scales with headcount | Slowly | Immediately ## How much does managed IT support cost? AMVIA's managed IT plans start from £25 per user per month, scaling with the level of security, on-site support and out-of-hours cover you need. Every plan includes unlimited helpdesk tickets, so your cost stays predictable whatever the volume. Typical UK fully-managed IT support sits around £25–£65 per user per month across the wider market. Microsoft 365 licences are billed on top at Microsoft's published UK list prices (microsoft.com/en-gb): | | Microsoft 365 plan | List price (ex VAT, /user/mo) | Business Basic | £4.60 | Business Standard | £9.60 | Business Premium | £16.90 For a full per-user breakdown, see our IT support pricing guide. Need more security depth without giving up your internal team? Our co-managed IT option layers AMVIA alongside an existing IT person. ## How do you choose a managed IT support provider? Most providers describe themselves identically, so judge them on what they will put in writing. Seven tests separate a genuine managed service from rebadged break-fix: - SLA in the contract - response times per priority level, with service credits when they are missed. If it is not written down, it is not guaranteed. - Named security stack - exactly which endpoint, email and backup tools are included, and who monitors the alerts they raise. “Security included” without product names usually means antivirus and hope. - A structured onboarding plan - a provider who cannot describe their first 30 days will improvise with your estate. - Exit terms - your documentation, credentials and data belong to you; handover on leaving should be defined before you join. Treat resistance here as a red flag. - Accreditations that are checkable - Microsoft partner status and Cyber Essentials Plus can be verified in minutes; “partnered with leading vendors” cannot. - References from businesses your size - a provider brilliant at 500 seats can be a poor fit at 30, and vice versa. - A clear exclusions list - projects, hardware, out-of-hours work: what costs extra should be explicit, not discovered on an invoice. The skills context makes the choice matter: DSIT’s cyber skills research puts a basic technical skills gap at around half of UK businesses (49% in the 2025 report), which is precisely the gap a managed provider is contracted to close. ## What does switching IT providers involve? Fear of the switch keeps many businesses on underperforming contracts for years, but a competent handover is routine. The incoming provider runs discovery in parallel with your existing arrangement - nothing is switched off while the estate is documented, agents are deployed and credentials are transferred under dual control. Your staff notice a new helpdesk number and, typically, nothing else. AMVIA’s 30-day onboarding above is designed around exactly this parallel-running principle, and notice periods on your old contract usually cover the whole transition window. Two practical tips: request your documentation pack from the outgoing provider early (it is yours), and never let admin credentials be the last thing handed over - they should transfer at the start of the window, under joint control, not the end. ## Managed IT support vs break-fix: why the model matters Break-fix - paying an hourly rate when something is already broken - optimises for the wrong moment: the provider earns most when your systems fail worst. A managed contract inverts that incentive: the provider profits from your estate being stable, patched and quiet. That is why monitoring, patching and security hardening are core to managed support and afterthoughts under break-fix. For the full cost comparison over a typical year, see our managed IT vs break-fix breakdown. ## What results does AMVIA deliver? AMVIA manages IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, and we publish our operational metrics rather than hide them. - Under 1 hour - guaranteed first response to P1 critical incidents, with a 2-hour target for all other tickets. - 99.97% - average uptime delivered across our managed client base in 2024. - 97% - first-contact resolution rate, issues closed on the first call. - £0 - surprise overage charges, because pricing is flat-rate. Security tooling across all of this is Microsoft-first: endpoint protection runs on Microsoft Defender for Business, monitored by AMVIA. One provider. Security-first. Microsoft-certified. ## Frequently asked questions Q: What is included in AMVIA's managed IT support service? A: AMVIA's managed IT support includes unlimited UK helpdesk, 24/7 proactive monitoring, patch management, Microsoft 365 administration, backup management and a dedicated account manager. Security essentials - Microsoft Defender for Business, email filtering and MFA configuration - are included as standard on every plan, with no per-incident charges. Q: How much does managed IT support cost per user? A: AMVIA's plans start from a flat per-user monthly fee and scale with the security, on-site and out-of-hours cover you need. All plans include unlimited helpdesk tickets with no per-incident charges, so costs stay predictable regardless of ticket volume. Microsoft 365 licences are billed on top at Microsoft's published UK list prices. Q: How does onboarding work when switching to AMVIA? A: AMVIA follows a structured 30-day onboarding. We audit your full IT estate, deploy monitoring and security agents, harden your Microsoft 365 tenant, then introduce your team to the helpdesk. Your previous provider is contacted to arrange a clean handover of credentials, documentation and domain registrations, so most businesses move across with no disruption. Q: What contract terms does AMVIA offer? A: AMVIA offers rolling monthly contracts with no lock-in as standard. We also offer 12-month and 24-month agreements with preferential pricing for businesses that prefer longer commitments. Every contract includes defined SLAs, a named account manager and a 90-day exit clause, so you stay because the service works, not because of a tie-in. Q: What size of business does AMVIA support? A: AMVIA manages IT for UK businesses from roughly 10 to 500 users across legal, finance, healthcare and professional services. As a Microsoft Solutions Partner, we bring enterprise-grade Microsoft 365 and security expertise to businesses that could not justify that depth of skill in-house. Q: Does managed IT support include cyber security? A: Yes. Every AMVIA plan includes a baseline security stack: Microsoft Defender for Business for endpoints, email security, DNS filtering, patch management and MFA enforcement. This means security is configured and monitored as part of the service rather than sold as a separate add-on you have to remember to buy. Q: How quickly does AMVIA respond to IT support issues? A: Critical (P1) incidents get a guaranteed first response within one hour, and all other tickets carry a 2-hour response target - both written into the SLA with service credits if missed. In practice, 97% of issues are resolved on first contact. Q: Can we keep our internal IT person and still use AMVIA? A: Yes - that is co-managed IT. Your internal person keeps day-to-day ownership and local knowledge while AMVIA adds the helpdesk depth, 24/7 monitoring, security stack and escalation cover a single person cannot provide alone. See our co-managed IT service for how the split typically works. --- # Co-Managed IT: How We Work Alongside Your IT Team URL: https://amvia.co.uk/managed-it/co-managed-it Last updated: 2026-03 Co-managed IT support is a shared model where your in-house IT team keeps day-to-day control and AMVIA covers the specialist gaps - cybersecurity, cloud, projects and out-of-hours cover. You get extra capacity and certified expertise without hiring, backed by one accountable, security-first, Microsoft-certified partner. It complements our wider managed IT support service. ## How does co-managed IT work? Co-managed IT splits responsibilities by agreement. Your staff own first-line tickets, user requests and vendor liaison; AMVIA takes the areas that are hard to staff in-house - security monitoring, patching, infrastructure and after-hours support. A shared ticketing system and joint reporting keep both teams looking at the same data. We run a four-stage onboarding so the split is clear from day one: - Team alignment - we meet your IT team, map your infrastructure, and agree responsibilities, escalation paths and SLAs. - Knowledge transfer - we document your environment, take agreed access, and align on tooling and change control. - Shared operations - your team runs day-to-day work; we take specialist areas such as security, projects or out-of-hours cover. - Continuous improvement - monthly reviews rebalance the workload and plan upcoming projects together. ## What's included in AMVIA co-managed IT? Co-managed IT from AMVIA bundles proactive security monitoring, expert configuration and incident response, monthly reporting and a named account team. You decide which layers your staff keep and which we run, and the boundary is documented in the SLA so nothing falls between the two teams. - Proactive protection - continuous monitoring and threat detection using Microsoft Defender for Endpoint, watched by our in-house team. - Expert management - UK-based, Microsoft-certified engineers handle configuration, updates and incident response. - Regular reporting - monthly reports on security posture, incidents handled and recommended improvements. - Dedicated support - direct access to your account team for changes, questions and escalations. For the security layer specifically, co-managed clients lean on our managed cybersecurity and managed Microsoft 365 services, while your team keeps the helpdesk and end-user relationship. ## Why do UK SMEs need co-managed IT? Most UK SMEs cannot staff a 24/7 security rota or deep Microsoft 365 expertise on one or two internal hires. Co-managed IT closes that gap. It matters because the threat level is real: 43% of UK businesses identified a cybersecurity breach or attack in the last 12 months (gov.uk Cyber Security Breaches Survey 2025), and phishing was the most common attack type, hitting roughly 85% of those breached (gov.uk). Other reported figures put the average cost of a disruptive breach for UK businesses at £3,550 (DSIT 2025). A lone internal IT manager rarely has the time or tooling to defend against that, which is why the National Cyber Security Centre recommends continuous monitoring and tested response - exactly the specialist layer co-managed IT adds. ## Co-managed IT vs fully outsourced IT support The difference is control. Co-managed keeps your in-house team in charge and adds capacity; fully outsourced hands the whole function to a provider. Here is how they compare for a typical 10–500-staff UK business. | | Factor | Co-managed IT | Fully outsourced IT | In-house team | Retained, in control | Usually removed or reduced | Day-to-day tickets | Your staff | AMVIA | Specialist security & cloud | AMVIA | AMVIA | Out-of-hours cover | AMVIA | AMVIA | Best for | 1–3 internal IT staff needing depth | Businesses with no internal IT | Admin access | Stays with your team | Held by provider If you have no internal IT at all, fully managed IT support is the better fit. If you have a stretched team that needs reinforcement on security and after-hours cover, co-managed wins. ## How much does co-managed IT cost? Pricing depends on which layers you keep in-house. AMVIA IT support starts from £30/user/month, and fully managed SME IT support typically runs £35–£65/user/month across the UK market as of 2026. Co-managed pricing usually sits lower than fully managed because your staff absorb part of the workload, and you can scale capacity up or down monthly. You only pay for the specialist capacity you actually use, which is why fast-growing firms use co-managed IT to add depth without recruiting hard-to-find engineers. ## Why choose AMVIA for co-managed IT? AMVIA is a security-first managed IT partner, not a telecoms reseller. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, our engineering and support team operates from Sheffield, and we manage IT and security for 1,200+ UK businesses across legal, finance, healthcare and professional services. - UK-based engineers - Sheffield-based support that understands UK compliance and infrastructure. - Certified and accountable - Cyber Essentials Plus and Microsoft Solutions Partner (Microsoft). - Fast response - critical issues responded to within one hour, by phone, email and portal. - Resilience built in - pair co-managed IT with business continuity planning so an incident never stops the business. When you need to offload first-line volume too, your team can hand overflow to our IT helpdesk while keeping ownership of strategy. ## Frequently asked questions Q: What is co-managed IT? A: A shared model: your in-house IT team keeps day-to-day control and ownership, while AMVIA covers the specialist gaps - cybersecurity, cloud projects, out-of-hours cover, and overflow when tickets spike. It's augmentation, not replacement. Q: Why choose co-managed over fully managed IT? A: Because you already have IT staff worth keeping. Co-managed keeps their context and control while adding enterprise tooling, 24/7 monitoring and specialist depth a small internal team can't staff alone - typically at £35–£65 per user/month depending on the split of responsibilities. Q: Will a co-managed provider try to replace our IT team? A: A good one won't - the model only works when the boundary is explicit. AMVIA agrees the responsibility split up front (who owns endpoints, who owns security, who takes out-of-hours) and works inside your team's processes, not around them. Q: What do internal IT teams usually hand to a co-managed partner first? A: Security monitoring and out-of-hours cover - the two things hardest to staff internally. A 24/7 SOC watching alerts and a defined escalation path at 3am relieve exactly the pressure that burns out small IT teams. --- # IT Helpdesk and Service Desk for UK Businesses URL: https://amvia.co.uk/managed-it/it-helpdesk Last updated: 2026-03 An IT helpdesk is the single point of contact your staff use to report and fix technology problems - password lockouts, email faults, slow machines, outages - by phone, email, or portal. AMVIA runs a UK-based IT helpdesk with under-one-hour response on critical issues, staffed by Microsoft-certified engineers. One provider, security-first. It works as part of our wider managed IT support service, so the people answering your tickets are the same people securing and maintaining your environment - not a disconnected call centre reading from a script. ## How does AMVIA's IT helpdesk work? We become your helpdesk in four stages: onboard, tool up, go live, and review. Onboarding documents your systems, users, and recurring issues so engineers fix problems with context, not guesswork. From go-live, staff raise tickets by phone, email, or portal against agreed SLAs. - 01. Environment onboarding - we document your systems, users, and common issues, then build a business-specific knowledge base so fixes are fast and consistent. - 02. Tooling and access - we deploy secure remote support agents and monitoring tools, and give your team access to a ticketing portal. - 03. Go-live - your staff contact our UK helpdesk by phone, email, or portal, and every ticket runs against an agreed SLA. - 04. Reporting and reviews - monthly reports cover ticket volumes, resolution times, and recurring issues so root causes get fixed, not just symptoms. ## What's included in the IT helpdesk service? Every plan includes proactive monitoring, UK-based engineer management, regular reporting, and a named account team. You get a helpdesk that prevents problems as well as resolving them - issues are flagged and patched before they reach your staff, and security is built into day-to-day support rather than bolted on. - Proactive protection - continuous monitoring and threat detection across your devices and Microsoft 365 tenant. - Expert management - UK-based engineers handle configuration, updates, patching, and incident response. - Regular reporting - monthly reports on ticket trends, resolution times, security posture, and recommendations. - Dedicated support - direct access to an account team that knows your environment. Because AMVIA also runs your managed Microsoft 365 service, helpdesk tickets that touch email, Teams, or licensing are resolved by engineers who manage that tenant - not escalated and lost. ## Why do UK SMEs need a managed IT helpdesk? Unresolved IT problems cost time and create security gaps. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the prior 12 months, with phishing involved in roughly 85% of those incidents (gov.uk). A responsive helpdesk is the first line that spots and reports these fast. The same survey put the average cost of a disruptive breach at around £3,550 for UK businesses. Most of that damage starts with something a helpdesk sees first: a suspicious email, a locked account, an unpatched laptop. The National Cyber Security Centre recommends prompt patching and a clear route for staff to report issues (ncsc.gov.uk) - exactly what a managed helpdesk provides. ## In-house helpdesk vs managed IT helpdesk: which is right? A managed helpdesk gives most 10–500-staff businesses broader coverage and predictable cost without hiring and retaining a full internal team. In-house makes sense at larger scale or for highly bespoke systems; for everyone else, a managed model removes single-person dependency and after-hours gaps. | | Factor | In-house helpdesk | AMVIA managed helpdesk | Cost model | Salaries, holiday, training, tools | Fixed per-user monthly fee | Coverage | Limited by team size and leave | UK team with extended/24-7 options | Critical response | Depends on who's available | Under one hour on critical issues | Security expertise | Varies | Microsoft-certified, security-first | Scaling | Hire and onboard | Add users instantly | Single point of failure | High - key-person risk | Low - full team coverage For businesses that already have internal IT but need extra capacity, our co-managed IT service wraps the same helpdesk around your existing team. ## How much does an IT helpdesk cost? AMVIA's IT helpdesk uses flat-rate per-user pricing from £18 per user per month, with no lock-in contracts and no hidden fees. Fully managed IT services in the UK typically run £25–£65 per user per month, depending on scope and security inclusions. Per-user pricing makes budgeting predictable - you scale up or down with headcount rather than negotiating ad-hoc rates per incident. For a full breakdown of what drives the figure, see our IT support cost guide. Security monitoring and incident response are part of the service, not an add-on, which keeps your cybersecurity and IT support under one accountable provider. ## Why choose AMVIA for your IT helpdesk? AMVIA is a Sheffield-based, UK-focused team holding Cyber Essentials Plus certification and Microsoft Solutions Partner status. We manage IT for 1,200+ UK businesses across legal, finance, healthcare, and professional services, with a and a security-first approach built into every ticket. - Sheffield-based, UK-focused - UK engineering and support team that understands UK compliance and infrastructure. - Accredited and certified - Cyber Essentials Plus and Microsoft Solutions Partner (Modern Work, Security, and Azure Infrastructure). - 1,200+ UK businesses managed by AMVIA - proven across regulated and professional sectors. - Fast, responsive support - critical issues responded within one hour. - Resilience built in - pairs naturally with our business continuity service so outages don't become disasters. ## Frequently asked questions Q: What does an IT helpdesk service include? A: A single point of contact for staff technology problems - password lockouts, email faults, slow machines, printer and connectivity issues - handled by UK-based engineers with tracked tickets and defined response targets, instead of 'ask whoever seems technical'. Q: How much does an IT helpdesk cost? A: Standalone UK helpdesk support starts from around £18 per user/month, while AMVIA's full managed IT plans (which include helpdesk plus monitoring, patching and security) run £25–£65 per user/month by tier. Per-user pricing means the cost scales with headcount, not with how often things break. Q: What response times should we expect? A: Defined targets by severity - AMVIA's plans range from next-business-day on Essentials to 2-hour targets on Enterprise, with critical issues triaged fastest. The discipline matters more than the number: a tracked ticket with a target beats a quick answer that sometimes never comes. Q: Is remote helpdesk support enough, or do we need on-site? A: Most issues resolve fastest remotely - screen-sharing beats waiting for a visit. The right model is remote-first with on-site attendance when a job genuinely needs hands on hardware: server moves, network faults, new-office fit-outs. --- # Cloud Migration Services for UK SMEs URL: https://amvia.co.uk/managed-it/cloud-migration Last updated: 2026-03 Cloud migration is the planned move of your email, files, applications and servers from on-premises hardware to a hosted platform such as Microsoft 365 or Azure. Done well, it cuts hardware cost, enables hybrid working and tightens security. AMVIA delivers it as managed work: one provider, security-first, Microsoft-certified engineers. Most UK SMEs migrate as part of a wider managed IT support programme, so the cloud move, ongoing patching and the helpdesk all sit with one accountable team rather than three. ## What is cloud migration and what does AMVIA move? Cloud migration moves workloads off ageing on-premises servers into a managed cloud platform. AMVIA scopes every workload first, then rehosts, refactors or retires it. We move the things UK SMEs depend on daily and harden them as we go, rather than lifting old risk into a new platform. Typical workloads we migrate: - Email and calendars to Exchange Online / Microsoft 365 - File shares and documents to SharePoint and OneDrive - Line-of-business applications and databases to Azure virtual machines or PaaS - On-premises servers consolidated, then securely decommissioned - Backup and recovery repointed to cloud-native Microsoft 365 backup ## How does an AMVIA cloud migration work? An AMVIA migration runs in four controlled phases with defined milestones, rollback points and user acceptance testing at each gate. We migrate in stages, test before we proceed, and keep on-premises copies until the new environment is verified - so the business keeps working throughout. 1. Discovery and planning - we audit current infrastructure, applications and data, then build a prioritised roadmap with a fixed scope. 2. Environment build - your cloud tenant is architected with networking, identity, conditional access and security controls in place before any data moves. 3. Migration and testing - data and applications move in phases; each stage is validated with checksums and sign-off before the next begins. 4. Go-live and optimisation - final cutover during off-peak hours, user acceptance testing, then ongoing performance and cost tuning. ## Will there be downtime during our cloud migration? For most SMEs, no meaningful downtime. AMVIA uses staged replication and planned cutover windows so users keep working during the move. Email and collaboration tools are typically migrated overnight or across a weekend, with staff signing into the new environment the next morning. The largest source of avoidable downtime is an unplanned outage on old hardware mid-project, which is why we keep on-premises copies live until every workload is validated in the cloud. Migration sits naturally alongside a wider business continuity plan, so resilience improves the day you move. ## Why do UK SMEs need cloud migration? Ageing on-premises servers are a cost and a risk: hardware fails, patches lag, and physical sites are vulnerable to fire, flood and theft. Migrating to a managed cloud platform shifts that liability to a hardened, monitored environment and makes secure remote working the default rather than a bolt-on. Resilience matters because breaches are common and expensive. 43% of UK businesses reported a cyber breach or attack in the last 12 months (DSIT Cyber Security Breaches Survey 2025), with an average disruptive-breach cost of around £3,550. A well-architected cloud platform with monitoring and backup is one of the strongest controls against that exposure - which is why we build security in, linking migrations to our managed cybersecurity practice. ## In-house move vs AMVIA managed migration A DIY migration usually means borrowed evenings, no rollback plan, and security treated as an afterthought. A managed migration is scoped, tested and fixed-price. The table below shows the practical difference. | | Factor | In-house / DIY move | AMVIA managed migration | Planning | Ad hoc, often undocumented | Audited roadmap with rollback points | Downtime risk | High - no staged cutover | Minimal - staged replication, off-peak cutover | Security | Bolt-on after go-live | Identity, conditional access and monitoring built in first | Data integrity | Manual, trust-based | Checksum-verified at every stage | Cost certainty | Open-ended | Fixed-price quote after assessment | Accountability | Split across staff and vendors | One provider, end to end ## How much does cloud migration cost for a UK business? Cloud migration is priced on the number of users, data volume and application complexity. A straightforward migration of email and file storage for a 50-user business typically runs £3,000–£8,000 (typical UK 2026 range) as a one-off project, quoted fixed-price after the assessment so there are no surprises mid-project. Running costs then move to per-user Microsoft 365 licensing. UK list prices are Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user/month, ex VAT on an annual plan (Microsoft 365 UK pricing). For ongoing support budgeting, see our guide to managed IT support costs, and consider a co-managed IT model if you have internal staff to work alongside. ## Frequently asked questions Q: What does a cloud migration involve? A: The planned move of email, files, applications and servers from on-premises hardware to a hosted platform such as Microsoft 365 or Azure - sequenced so users keep working throughout: assess, pilot, migrate in waves, decommission. Q: How much does cloud migration cost? A: Project costs for a typical SME migration commonly run £3,000–£8,000 depending on data volume and complexity, plus ongoing licensing (Microsoft 365 runs £4.60–£16.90 per user/month ex VAT by tier). The offset is retiring server hardware, hosting and maintenance you'll no longer buy. Q: How long does a migration take and will we have downtime? A: Weeks, not days - properly sequenced, with the actual cutover per workload measured in hours and scheduled out of business hours. The goal is that users log in on Monday and everything's where they expect it, just faster and elsewhere. Q: Is the cloud actually more secure than our server room? A: The platform is - Microsoft's data centres beat any comms cupboard. But security in the cloud is configuration: MFA, conditional access, backup and hardening are your responsibility, which is why migration should always land with a security baseline, not just moved data. --- # Business Continuity and Disaster Recovery IT Services URL: https://amvia.co.uk/managed-it/business-continuity Last updated: 2026-03 Business continuity is your plan to keep critical systems running - and recover fast - when disruption hits, from ransomware to hardware failure or power loss. It combines tested backups, replication and failover with clear recovery targets (RTO and RPO). AMVIA builds and tests continuity plans for over 1,200 UK businesses - one provider, security-first, Microsoft-certified. This page sits under our managed IT support pillar: business continuity is the discipline that keeps the rest of your IT estate recoverable when something goes wrong. ## What is business continuity and disaster recovery? Business continuity (BC) keeps your operations running during disruption; disaster recovery (DR) is the technical process of restoring IT systems and data afterwards. Together they answer one question an MD cares about: how fast are we back, and how much do we lose? Strong plans pair both with tested, documented runbooks. - Business continuity - the people, processes and priorities that keep the business trading - Disaster recovery - the backups, replicas and failover that restore the IT behind them - RTO - Recovery Time Objective: the maximum downtime you can tolerate - RPO - Recovery Point Objective: the maximum data loss, measured in time A plan you have never tested is a hope, not a plan. AMVIA runs recovery drills, not just backups. ## Why do UK SMEs need a continuity plan? Disruption is now a when, not an if. The UK government's Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a cyber breach or attack in the last 12 months - and downtime, not the breach itself, is what costs you customers. A tested continuity plan turns a crisis into an inconvenience. - 43% of UK businesses experienced a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025, DSIT) - 85% of identified breaches involved phishing - the most common entry point for ransomware - £3,550 average cost of a disruptive breach for UK businesses The NCSC's guidance on backups is blunt: offline, tested backups are the single most effective defence against ransomware. We build to that standard. ## What's included in AMVIA business continuity? AMVIA delivers continuity as a managed service: we design, deploy, monitor and test the whole stack so recovery is proven, not assumed. UK-based engineers own the configuration, the runbooks and the drills, and you get plain-English reporting on where you stand each month. - Proactive protection - continuous monitoring and threat detection to stop incidents before they spread - Expert management - UK-based engineers handle backup configuration, replication, updates and incident response - Regular reporting - monthly reports on recovery posture, incidents handled and recommended improvements - Dedicated support - direct access to your account team for changes, questions and escalations For data specifically, we pair on-premise backup with cloud replication - including Microsoft 365 backup, because Microsoft's shared-responsibility model means your Exchange, SharePoint and OneDrive data is yours to protect. ## How does AMVIA build your continuity plan? We build continuity in four stages, each documented and signed off with your team. The goal is a plan your staff can execute under pressure - with recovery targets agreed in advance, not guessed at during an outage. 1. Business Impact Analysis - we identify critical systems, acceptable downtime thresholds and recovery priorities with your team 2. Recovery design - we architect backup, replication and failover tailored to your RPO and RTO targets 3. Implementation - backup systems, cloud replicas and DR runbooks are deployed and documented 4. Testing and drills - recovery drills verify the plan works under real conditions, with results reviewed and plans updated quarterly This integrates with your wider IT infrastructure and any in-flight cloud migration, so continuity is designed in, not bolted on. ## In-house DR vs managed continuity: what's the difference? In-house disaster recovery depends on one or two people remembering an untested process at 2am. Managed continuity gives you tested runbooks, monitored backups and a 24/7 team that has rehearsed the recovery. The table below shows where the gap usually bites. | | Capability | Typical in-house DR | AMVIA managed continuity | Backup monitoring | Manual, often unchecked | 24/7 automated monitoring | Recovery testing | Rarely, if ever | Drills, reviewed quarterly | Documented runbooks | Tribal knowledge | Written, version-controlled | Defined RTO/RPO | Assumed | Agreed and measured | Out-of-hours response | One person's phone | UK team, | Microsoft 365 data | Often unprotected | Replicated and recoverable ## Why choose AMVIA for business continuity? AMVIA runs IT and security for UK SMEs as a single accountable provider, with security built into every continuity plan. We hold Cyber Essentials Plus certification and Microsoft Solutions Partner status, so your recovery design meets recognised UK security standards - not a reseller's best guess. - Sheffield-based, UK-focused - our engineering and support team operates from Sheffield and understands UK compliance, network infrastructure and the realities facing British businesses - Accredited and certified - AMVIA holds Cyber Essentials Plus certification and Microsoft Solutions Partner status - 1,200+ UK businesses managed by AMVIA - across legal, finance, healthcare and professional services - Fast, responsive support - critical issues responded to within one hour by phone, email and portal, with account managers who know your environment When recovery does need a security response, it ties straight into our incident response capability - containment and restoration handled by the same team. ## How much does business continuity cost? Continuity is usually priced per user alongside managed IT, scaled to your recovery targets and data volumes. AMVIA IT support starts from £30/user/month, with continuity scoped to your RPO/RTO requirements after a business impact analysis. The right number depends on how much downtime your business can actually absorb. - AMVIA IT support from £30/user/month - SME IT support costs typically range £35–£65/user/month (typical UK 2026 market rates) - Continuity and DR scoped per environment after a business impact analysis For a managed estate, continuity often pairs with managed IT support so backups, patching and recovery sit with one team. ## Frequently asked questions Q: What is business continuity planning? A: Your plan to keep critical systems running - and recover fast - when disruption hits: ransomware, hardware failure, power cuts, or the connectivity outage that stops everything. It's the difference between a bad hour and a bad month. Q: What's the difference between backup and business continuity? A: Backup is a copy of data; continuity is the ability to keep operating. A backup you've never test-restored, on systems that take days to rebuild, isn't continuity - the plan covers recovery time targets, alternate ways of working, and who does what while systems come back. Q: What recovery time should we aim for? A: Set by asking what an hour of downtime costs each system's users. Email and phones usually need hours-not-days; archives can wait. Defining recovery time and recovery point objectives per system is the core of the plan - then the technology follows the numbers. Q: How often should we test the continuity plan? A: At least annually, and after significant changes - an untested plan is a hypothesis. The average most-disruptive breach already costs UK businesses £3,550 (DSIT 2025); testing is how you keep a real incident at the average rather than the tail. --- # IT Infrastructure Management for UK Businesses URL: https://amvia.co.uk/managed-it/it-infrastructure Last updated: 2026-03 IT infrastructure management is the ongoing monitoring, patching, and optimisation of the servers, networks, storage, and cloud platforms a business runs on. AMVIA runs all of it for you under one accountable contract - a security-first service delivered by Microsoft-certified engineers, so your estate stays online, current, and protected. This is a core part of our managed IT support offering: one provider for your whole infrastructure, with security built into every layer rather than bolted on afterwards. ## What does AMVIA's IT infrastructure management include? AMVIA's service covers everything that keeps your estate healthy: round-the-clock monitoring, patch and firmware management, backup verification, capacity planning, and scheduled reviews. UK-based engineers own the day-to-day work, so your team stops firefighting and your infrastructure stops surprising you. - Proactive monitoring - agents and SNMP checks track CPU, memory, disk, bandwidth, and service availability, alerting engineers before users feel a problem. - Patch and firmware management - operating systems, hypervisors, and network devices are updated on a scheduled, tested cadence. - Backup verification - backups are checked for integrity, not just assumed to have run. Pair this with our business continuity planning for full recovery cover. - Capacity and lifecycle planning - we track every device's age and headroom so refreshes are budgeted, never emergencies. - Security baked in - Microsoft Defender for Endpoint and the Barracuda email and network suite protect the estate we manage, monitored by AMVIA's in-house SOC. ## How does AMVIA manage your infrastructure? We start by documenting what you actually have, then deploy monitoring, take over routine management, and meet you quarterly to plan ahead. Each stage is owned by AMVIA engineers - you get one team accountable for the whole estate rather than a chain of suppliers pointing at each other. 1. Infrastructure audit - we document servers, network, storage, and cloud resources, flagging risks, performance bottlenecks, and end-of-life hardware. 2. Monitoring deployment - agents and SNMP monitoring go across your estate for real-time health, performance, and capacity visibility. 3. Proactive management - patching, firmware updates, backup verification, and capacity planning run on a scheduled basis. 4. Strategic planning - quarterly reviews recommend upgrades, consolidation, and technology refresh aligned to your budget. For hybrid estates, this extends to Microsoft Azure and Microsoft 365 alongside on-premises kit, often combined with Microsoft Intune for device management. The NCSC's device and asset management guidance sets out why a known, monitored estate is the foundation of good security. ## Why do UK SMEs need managed IT infrastructure? Unmanaged infrastructure is where most avoidable outages and breaches begin: unpatched servers, ageing hardware, and backups nobody checks. With 43% of UK businesses experiencing a cyber breach or attack in 2025 (DSIT Cyber Security Breaches Survey 2025), keeping the estate patched and monitored is no longer optional. Phishing remains the most common attack route, reported by around 85% of UK businesses that identified a breach in the same survey. Good infrastructure management closes the gaps attackers rely on - out-of-date systems, weak segmentation, and unverified backups - before they are exploited. It is the same discipline that underpins managed cybersecurity: you cannot protect what you do not monitor. ## In-house vs managed IT infrastructure: which suits an SME? For most 10–500 staff businesses, fully staffing infrastructure in-house is hard to justify against the cost and the on-call burden. Managed infrastructure gives you enterprise-grade coverage and tooling for a predictable monthly fee, while co-managed IT lets an existing internal team keep control and hand off the heavy lifting. | | Factor | In-house only | AMVIA managed infrastructure | Monitoring coverage | Business hours, gaps overnight | 24/7 automated monitoring | Patching cadence | Reactive, often deferred | Scheduled and tested | Cost model | Salaries + tooling + cover | Fixed monthly fee per user | Specialist depth | One or two generalists | Microsoft-certified specialist team | Critical-issue response | Depends on staff availability | Under 1 hour for critical (P1), 2-hour target for others | Backup assurance | Assumed | Verified and reported ## How much does IT infrastructure management cost? AMVIA prices infrastructure management as a fixed monthly fee per user with no lock-in contracts, from £30/user/month. Fully managed IT services across the UK market typically range from £25–£65/user/month (industry benchmark), with infrastructure management forming the core of that spend. The exact figure depends on the size and complexity of your estate - number of servers, sites, cloud platforms, and the support hours you need. A scoping call and audit produce a concrete quote rather than a guess. Microsoft 365 licences sit on top of management fees; Microsoft lists Business Premium at £16.90/user/month (ex VAT, annual) if you also need licensing folded into one bill. ## Frequently asked questions Q: What does IT infrastructure management cover? A: Ongoing monitoring, patching and optimisation of the platforms your business runs on - servers, networks, storage and cloud - so capacity problems and failures are caught before users feel them. Q: Do we still need infrastructure management if we're in the cloud? A: Yes - the boxes change, the discipline doesn't. Cloud platforms still need patching windows, capacity planning, cost optimisation and security configuration; unmanaged cloud drifts exactly like an unmanaged server room, just with a monthly bill attached. Q: How does proactive monitoring actually save money? A: By converting outages into maintenance: a disk trending toward failure replaced on schedule costs a component; the same disk failing on a Tuesday morning costs a day of downtime. Monitoring plus patching is the unglamorous work that makes IT boring - which is the goal. Q: Is infrastructure management included in AMVIA's plans? A: Yes - it's part of the managed IT plans (£25–£65 per user/month by tier) rather than a separate line item, with monitoring and patching running from day one and the same team accountable for the network, devices and security on top of it. --- # Managed IT Support Explained: Services, Costs & Contracts URL: https://amvia.co.uk/managed-it/what-is-managed-it Last updated: 2026-03 Managed IT is a service where a managed service provider (MSP) takes ongoing responsibility for your entire IT environment - monitoring, patching, Microsoft 365, security and helpdesk - for a fixed monthly fee per user. It replaces reactive break-fix with proactive prevention: one accountable provider, security-first, run by Microsoft-certified engineers. The word that matters is *proactive*. A managed IT provider does not wait for systems to fail - it monitors for early warning signs, patches vulnerabilities before they are exploited, and catches performance problems before they become outages. For most UK SMEs that approach delivers better reliability, stronger security and a lower total cost than the traditional break-fix model. AMVIA's managed IT support is built on exactly this principle: prevention first, security woven through every layer. The UK managed services market is worth £8.4 billion (TechMarketView, 2025 estimate), and that scale reflects a real shift - UK businesses are moving away from reactive firefighting toward outsourced, continuously managed IT. ## What does a managed IT contract typically include? A comprehensive managed IT contract for a UK SME usually bundles six core components into one monthly fee. What separates a genuine managed service from a cheap helpdesk subscription is whether security, backup and Microsoft 365 management are *included* rather than billed as extras. Here is what good looks like. | | Component | What it covers | Why it matters | Helpdesk support | UK-based phone, email and portal support under an SLA | Day-to-day staff productivity | Remote monitoring (RMM) | Continuous device, patch and performance monitoring | Problems caught before users notice | Patch management | Automated Windows, macOS and third-party updates | Closes the vulnerabilities attackers use | Microsoft 365 management | Accounts, licences, Teams, security config | Most SMEs' core platform, secured properly | Endpoint security | EDR (e.g. Microsoft Defender for Business) monitored 24/7 | Stops modern threats signature AV misses | Cloud backup | Independent M365 and server backup, recovery-tested | Protects data Microsoft does not back up for you ## How does the helpdesk and SLA work? The helpdesk is a UK-based team staff contact by phone, email or web portal, with response times defined in a service level agreement (SLA). A typical structure sets P1 (critical, system down) at a one-hour response, P2 (major, department-level impact) at two to four hours, and P3 (minor, workaround available) at next business day. The helpdesk is the most visible part of any managed service, and its quality shapes how staff feel about IT overall. When you compare providers, the UK IT support costs you are quoted should always be read against the SLA targets behind them. ## Why is patch management a security control, not a chore? Patch management is the automated deployment of operating system and third-party software updates within defined timelines. With 43% of UK businesses reporting a cyber security breach or attack in the last 12 months, per the government's Cyber Security Breaches Survey 2025, and most successful attacks exploiting known, patchable flaws, consistent patching is among the highest-impact controls available. The NCSC's guidance on vulnerability management is blunt on this point: timely patching closes the door on the majority of opportunistic attacks. A managed provider patches on a schedule, tests for compatibility, and reports compliance monthly - so the control is evidenced, not assumed. ## Is my Microsoft 365 data really backed up? No - not by default, and this catches businesses out. Microsoft provides infrastructure resilience, but it does not protect you from accidental deletion, ransomware encryption or tenant compromise. Microsoft's own shared responsibility model places data protection on the customer. That is why a proper managed IT contract includes independent backup of Microsoft 365 email, SharePoint and OneDrive to separate storage, with tested recovery procedures. Endpoint protection through Microsoft Defender for Business adds behavioural detection and automated isolation, but it only adds value when alerts are actively monitored - which is the managed part of managed IT. ## How do MSPs charge for managed IT? Most UK MSPs price managed IT per user per month: a fixed fee for each member of staff covered, scaling up as you hire and down as people leave. There are no per-incident charges, no call-out fees, and no extra cost for the time taken to resolve issues - predictability is the whole point. Some providers use per-device pricing instead, charging per laptop, server or network device. That suits environments with a high device-to-user ratio - manufacturing floors with shared workstations, or businesses running many servers. For office-based teams where each person has one laptop, per-user pricing is simpler and easier to budget. As a market guide, comprehensive managed IT commonly falls in the £30 to £80 per user per month range for core service (typical UK 2026 range), with fully-loaded contracts that bundle endpoint security, email security, backup and 24/7 monitoring running higher - broadly £50 to £150 per user per month at market rates as of 2026. The figure matters less than the scope: some providers quote low and bill common services separately. ## How does managed IT compare to break-fix? Break-fix IT is reactive - you call when something breaks, pay for the time to fix it, and the relationship pauses until the next problem. There is no monitoring, no patching and no ongoing management, and the provider has no financial incentive to prevent issues. More breakages mean more revenue. Managed IT aligns incentives the other way. The MSP earns the same monthly fee whether it resolves ten issues or zero, so its interest is in preventing problems: fewer incidents mean lower cost-to-serve and a client who stays. | | | Break-fix | Managed IT | Cost model | Per hour / per incident | Fixed monthly per user | Monitoring | None | Continuous 24/7 | Patching | On request | Scheduled and reported | Provider incentive | More faults = more revenue | Fewer faults = better margin | Security | Reactive | Built in The practical result is fewer outages, faster recovery, better patch compliance and a stronger security posture. Our full MSP vs break-fix comparison sets out where each model genuinely fits. ## What are the benefits of managed IT for UK SMEs? For a 10–500 staff business, managed IT converts unpredictable IT risk into a fixed monthly line item backed by a specialist team. The headline benefits are predictable cost, access to a full bench of skills, and resilience you could not afford to build in-house. - Predictable costs: a fixed monthly fee replaces surprise break-fix invoices. - Specialist skills: access to Microsoft 365, cybersecurity, networking and cloud experts, not one generalist. - Business continuity: 24/7 monitoring, backup and defined incident response keep the business running - see our approach to business continuity. - Compliance support: documented, evidenced IT controls that support UK GDPR and supply-chain requirements. - Scalability: add or remove users without capital investment in kit or headcount. If you are weighing this against hiring, our breakdown of outsourced IT versus an in-house team compares the real costs and capability gaps. ## What should you look for in a UK MSP? Assess providers on more than headline price. The questions that separate a strong MSP from a weak one are about SLA targets, scope of coverage, security capability, UK-based support and clean exit terms. Ask each provider to answer all five before you compare quotes. - Response times: what are the SLA targets per priority, and is out-of-hours included? - Scope: are Microsoft 365 management, endpoint security and backup included or charged as add-ons? - Security capability: can they actually deliver managed cybersecurity, including Microsoft Defender for Business, or just IT support? - UK-based support: is the helpdesk domestic and fluent in your business context? - Contract terms: what is the notice period, and are there penalties for reducing user numbers? ## How AMVIA delivers managed IT AMVIA is a UK managed service provider specialising in IT support, Microsoft 365 management and cybersecurity for SMEs. The managed IT service is priced per user with a single monthly invoice covering helpdesk, monitoring, patching, Microsoft 365 management, endpoint security and backup - no per-incident charges. AMVIA's security stack is built on Microsoft Defender and the Barracuda suite, monitored by an in-house team. Onboarding starts with a full assessment of your existing environment - identifying risks, documenting assets and agreeing scope. The typical timeline for a UK SME is two to four weeks, during which AMVIA deploys monitoring agents, configures security tooling and takes over management of all systems. One provider. Security-first. Microsoft-certified. ## Frequently asked questions Q: How much does managed IT support cost for a UK SME? A: Comprehensive managed IT commonly sits in the £30 to £80 per user per month range for core service (typical UK 2026 range), rising toward £50 to £150 per user per month at market rates as of 2026 for fully-loaded contracts that include endpoint security, email security, backup and 24/7 monitoring. The decisive factor is scope - some providers quote low then bill common services separately. AMVIA gives one per-user price covering the full service; call 0333 733 8050 for a quote. Q: How is managed IT different from a break-fix support contract? A: A break-fix contract gives you a company to call when something breaks, usually with a per-call or per-hour charge. Managed IT goes much further: the MSP proactively monitors your systems, deploys patches, manages Microsoft 365, watches endpoint security alerts and runs the helpdesk for a fixed monthly fee. The MSP owns the outcome, not just the occasional repair. Q: How long does it take to switch to a managed IT provider? A: A typical onboarding for a UK SME takes two to four weeks. The provider starts with documentation and assessment - cataloguing devices, software and services - then deploys monitoring agents, configures endpoint security and sets up backup. If you are leaving another MSP, AMVIA manages the handover so there is no gap in coverage, and advises on existing notice periods. Q: Does managed IT include cybersecurity? A: With a security-capable MSP, yes. A proper managed IT service includes endpoint protection, patch management and Microsoft 365 security configuration as standard - not as optional extras. With 43% of UK businesses reporting a breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), security cannot be bolted on later; it has to be built into day-to-day management. Q: Is Microsoft 365 data backed up automatically? A: No. Microsoft guarantees infrastructure resilience but not your data against accidental deletion, ransomware or tenant compromise - protecting that data is the customer's responsibility under Microsoft's shared responsibility model. A managed IT contract should include independent, recovery-tested backup of Microsoft 365 email, SharePoint and OneDrive to separate storage. --- # Outsourced IT vs In-House IT: Which Is Better for SMEs? URL: https://amvia.co.uk/managed-it/outsourced-it-vs-in-house Last updated: 2026-03 Outsourced IT gives a UK SME a team of specialists and round-the-clock cover for a fixed per-user fee, while in-house IT means one generalist, holiday gaps and hidden employer on-costs. Below roughly 100 staff, outsourced or co-managed IT almost always wins on cost and resilience - one accountable provider, security-first, Microsoft-certified. ## What is the real difference between outsourced and in-house IT? In-house IT is one or more employees on your payroll. Outsourced IT is a managed service provider (MSP) delivering helpdesk, monitoring, cloud and security as a contracted service. The split that matters is not "internal vs external" - it is "one generalist vs a team of specialists". This sits at the centre of any managed IT support strategy. Most businesses compare the two on salary alone. That is the wrong comparison. A single hire carries on-costs and coverage gaps a per-user MSP fee does not, and a per-user fee buys depth a single person cannot. | | Factor | In-house hire | Outsourced MSP | Coverage | One person, business hours | Team, with 24/7 monitoring | Skills | Generalist | Specialists per domain | Holiday / sick cover | None or ad-hoc | Built into the service | Cost model | Salary + variable on-costs | Fixed per-user fee | Single point of failure | Yes | No | Security depth | Usually limited | Dedicated security analysts ## What does an in-house IT hire actually cost? The headline salary is rarely the real number. A mid-level IT support engineer earns roughly £35,000–£45,000 a year in most UK regions, rising to £45,000–£55,000 in London and the South East (typical UK 2026 range). Employer on-costs then push the all-in figure to £45,000–£70,000 per year all-in once you add the items below. - Employer National Insurance - several thousand pounds a year on top of salary - Employer pension contributions - auto-enrolment minimum on qualifying earnings (gov.uk: workplace pensions) - Annual leave and sick cover - when your sole IT person is off, support stops or you pay premium ad-hoc rates - Training and certification - £1,000–£5,000 a year (typical UK 2026 range) to keep one person current - Recruitment - typically £3,000–£8,000 in agency fees plus lost productivity when they leave - Tools and licensing - monitoring, remote access, security and ticketing platforms an MSP absorbs into its fee For context, UK managed services is a large and growing market - valued at around £8.4 billion (TechMarketView, 2025 estimate) - and a chief driver is SMEs discovering that in-house IT costs more and delivers less than the job ad implied. Outsourced managed IT typically runs £30–£80 per user per month (market rates as of 2026), a predictable operating cost rather than a variable headcount one. ## What can a single IT person not cover? Even a strong generalist hits hard limits. Modern business IT spans networking, Windows and Mac endpoints, Microsoft 365 administration, Azure, cybersecurity, telephony, backup and compliance. Expecting one person to be expert across all of it is unrealistic, and the gaps are exactly where risk concentrates. - Cybersecurity depth - 43% of UK businesses identified a cyber breach or attack in the 2025 government survey (gov.uk: Cyber Security Breaches Survey 2025). A generalist may run antivirus but rarely manages endpoint detection and response (EDR) or live incidents - work best handled by a dedicated managed cybersecurity team. - Cloud configuration - a misconfigured Microsoft 365 tenant (legacy authentication left on, no Conditional Access, no backup) is a serious data-loss and breach risk. Conditional Access alone is a specialism (Microsoft Learn: Conditional Access). - Out-of-hours response - a single hire is unavailable evenings, weekends and during leave, which is precisely when ransomware and outages tend to land. - Project capacity - day-to-day tickets consume one person's time, leaving little room for migrations, security hardening or infrastructure work. ## What does outsourced IT deliver instead? An MSP fields a team across every IT domain. You draw on a helpdesk engineer for daily issues, a Microsoft 365 specialist for the cloud tenant, a security analyst for monitoring and a senior engineer for complex projects - not one person stretched across all four. That team-based model removes the single-point-of-failure risk of relying on an individual. A properly structured service adds coverage one hire cannot match: 24/7 monitoring with automated alerting, and defined response times for incidents whenever they occur. The commercial model is cleaner too - a fixed monthly per-user fee with no recruitment, training, holiday-cover or knowledge-loss exposure. AMVIA's security-first stack is built on Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus the Barracuda email and network suite. See exactly what is in scope on our what managed IT covers page. ## When does in-house IT actually make sense? In-house becomes competitive as you scale. Above roughly 150 staff, or with complex on-premise infrastructure or bespoke applications, a small internal team (two to three people across helpdesk, infrastructure and projects) can match the cost of fully managed IT at full-service rates while adding deep business knowledge. In-house also fits when IT is part of the product - proprietary software, complex data pipelines, or heavily regulated systems that an external provider cannot easily replicate. For most of these organisations the optimal answer is not "either/or" but an internal team augmented by specialist MSP services for security and cloud: co-managed IT. ## How does co-managed IT combine both models? Co-managed IT pairs your internal IT staff with an MSP. Your person stays the visible, on-site face of IT - handling staff relationships, hardware and hands-on fixes - while the MSP supplies specialist depth, 24/7 monitoring, cybersecurity management and backup that one hire cannot deliver alone. It suits businesses of 50–150 staff that want internal presence without hiring multiple specialists. Common arrangements: - Internal IT runs helpdesk and on-site support; the MSP runs security, monitoring and Microsoft 365. - Internal IT handles routine requests; the MSP takes escalations and infrastructure projects. - Internal IT covers business hours; the MSP provides out-of-hours monitoring and response. For the full protection picture across connectivity, collaboration and security, see complete business IT protection, and weigh the numbers with our IT support cost breakdown. ## How should an SME make the decision? Work through four factors specific to your business: - Staff count - below 100, outsourced almost always wins; 100–150, co-managed is often optimal; above 150, in-house with specialist MSP support becomes competitive. - IT complexity - straightforward Microsoft 365 environments suit outsourced management; complex on-premise or bespoke estates may need in-house depth. - Risk tolerance - a sole hire is a single point of failure; an MSP's team-based model removes it. - Budget predictability - outsourced IT is a fixed monthly cost; in-house carries variable recruitment, training and tooling spend. ## Frequently asked questions Q: At what size does in-house IT become cost-effective? A: In-house IT typically becomes cost-competitive with outsourced managed IT at around 100–150 staff, where a small internal team of two to three people matches full-service MSP rates. Below that, outsourced IT almost always offers better value and broader specialist cover. Above 150 staff, a co-managed model - internal team plus MSP for security and projects - is common. Q: What happens if our in-house IT person leaves? A: Staff turnover is one of in-house IT's biggest risks. When a sole IT person leaves you face an immediate helpdesk gap, loss of knowledge about your environment, and a recruitment cycle of four to twelve weeks. Outsourced or co-managed IT removes that single point of failure - the provider keeps operating regardless of individual staff changes. Q: Can AMVIA support our existing in-house IT team? A: Yes. AMVIA offers co-managed IT where your internal person keeps day-to-day ownership while AMVIA provides the monitoring platform, specialist depth, cybersecurity management and out-of-hours cover behind them. It suits 50–150 staff businesses that want internal presence with specialist resilience. Call AMVIA on 0333 733 8050 to discuss co-managed IT. Q: Is outsourced IT more secure than in-house? A: Usually, yes - because security is a specialism, not a side task. An MSP runs dedicated analysts, 24/7 monitoring and managed endpoint detection that a generalist rarely has time or training for. AMVIA's service is security-first by design, built on Microsoft Defender for Endpoint and the Barracuda email and network suite. Q: How quickly can we switch from in-house to outsourced IT? A: Most SMEs transition over a few weeks. AMVIA starts with an onboarding assessment that maps your current environment, documents systems and identifies risks before service goes live. That discovery step protects continuity, so day-to-day support does not drop while responsibility moves across. --- # How Much Does IT Support Cost for a UK SME? URL: https://amvia.co.uk/managed-it/it-support-cost-uk Last updated: 2026-03 UK managed IT support typically costs £30–£80 per user per month (typical UK 2026 range), depending on scope. Break-fix support runs £75–£150 per hour but hides downtime and emergency call-out costs. AMVIA prices managed IT as one fixed per-user fee covering support, security and backup - one provider, security-first, Microsoft-certified. The figure on a quote rarely tells the whole story. A low headline price that excludes email security, backup or endpoint protection costs more once you buy those separately. This guide breaks down what UK businesses actually pay, where break-fix bites, and what to check before signing a managed IT support contract. ## What are the IT support pricing models in the UK? UK providers price IT support two ways: break-fix (pay per hour or incident) and managed IT (a fixed monthly fee per user). The right model affects your budget, your security posture and your downtime exposure - not just the invoice total. The UK managed services market is worth £8.4 billion (TechMarketView, 2025 estimate), and a growing share of that spend comes from SMEs moving off reactive break-fix onto predictable managed contracts. The two models are not just different price tags - they are different relationships with your IT. | | Model | How you pay | Proactive monitoring | Cost predictability | Break-fix | Per hour / per incident | No | Low - varies with incidents | Managed IT | Fixed monthly fee per user | Yes | High - flat per-user cost ## How does break-fix IT work and what does it cost? Break-fix charges by the hour or the incident. You call when something breaks, pay for the time to fix it, and that is the whole relationship - no monitoring, no patching, no responsibility for prevention. The provider only earns when something goes wrong. Standard-hours rates run £75–£150 per hour (market rates as of 2026), with out-of-hours often 50–100% higher. Typical break-fix charges look like this: - Standard remote support: £75–£120 per hour - On-site support: £100–£150 per hour plus travel - Emergency out-of-hours: £150–£250 per hour - Server or network incident: £300–£1,500 per incident, depending on complexity Break-fix looks cheaper because there is no monthly commitment. That saving is misleading once the hidden costs land. ## How does managed IT work and what does it cost? Managed IT is proactive and fixed-price. The provider monitors your systems continuously, applies patches, manages your Microsoft 365 environment, runs endpoint security and backup, and handles staff helpdesk - all for one monthly fee per user. UK pricing falls into three broad tiers. ## Entry level: £30–£45 per user per month ## Mid-tier: £45–£60 per user per month ## Full service: £60–£80 per user per month When comparing quotes, the headline per-user price matters less than what it includes. A cheaper tier that excludes email security, backup or endpoint protection can add £15–£30 per user per month once you buy equivalent coverage separately. ## Why does break-fix IT cost more than it looks? Break-fix appears cheap because you only pay when something breaks. The hidden costs are what businesses underestimate. With 43% of UK businesses reporting a cyber breach or attack in the last 12 months in 2025 (DSIT Cyber Security Breaches Survey), the question is not whether an incident hits, but how expensive the reactive response will be. ## Downtime costs ## Unpatched systems ## Emergency call-out rates ## No built-in security ## Break-fix vs managed IT: which is cheaper overall? For a 20-person business, the annual numbers (typical UK 2026 rates) usually favour managed IT once incidents and security are counted properly. Break-fix wins only in an unusually quiet year - and removes all cost predictability. | | Factor | Break-fix (20 users) | Managed IT at £50/user/mo | Annual support spend | £8,000–£25,000, unpredictable | £12,000 fixed | Security/backup/email | £3,000–£7,000 extra | Included | Emergency call-outs | Charged per incident | None | Budget predictability | Low | High Managed IT may sit marginally higher in a quiet year, but it is far cheaper when incidents strike - and the predictability has genuine value for cash flow and planning. For a fuller breakdown of the model, see our guide to outsourced IT vs an in-house hire. ## What should you check when comparing IT support quotes? Not all managed IT quotes are comparable. Before signing, confirm exactly what is in the per-user fee - the gaps are where cheap quotes get expensive. - Is helpdesk unlimited or capped? Some providers cap tickets per user and charge for overage. - Is Microsoft 365 management included? Provisioning, licences and security config should be core, not extra. - Is endpoint security included or an add-on? EDR should be standard; if separate, add it for a fair comparison. - Is cloud backup included? Microsoft 365 backup (Exchange, SharePoint, OneDrive) is essential, not optional. - What are the response SLAs? Confirm guaranteed times for P1, P2 and P3 incidents - and whether they apply 24/7. - Any per-incident or call-out charges? A true managed service has none. - Is out-of-hours response included? Some providers bill it separately even on managed contracts. ## How does AMVIA price its managed IT service? AMVIA prices managed IT per user on a fixed monthly fee covering helpdesk, monitoring, patch management, Microsoft 365 management, endpoint security and cloud backup. No per-incident charges, no call-out fees, no surprise invoices - the monthly fee covers everything. The per-user price is the same whether staff raise zero tickets or twenty. For businesses moving off unpredictable break-fix spending, AMVIA gets all systems under management typically within two to four weeks. It is one accountable provider, security-first, with Microsoft-certified engineers. Call 0333 733 8050 for a no-obligation quote, or see what a full stack looks like in complete business IT protection. ## Frequently asked questions Q: How much does IT support cost for a small business in the UK? A: UK managed IT support typically costs £30–£80 per user per month depending on scope, while break-fix support runs £75–£150 per hour. For a 20-person business, a mid-tier managed contract usually lands around £12,000 a year fixed, covering support, monitoring, Microsoft 365 management, endpoint security and backup with no per-incident charges. Q: Does the per-user price include Microsoft 365 licences? A: It depends on the provider. Some MSPs fold Microsoft 365 licences into the managed IT fee; others bill licensing as a separate pass-through cost. AMVIA can include Microsoft 365 Business Premium licensing within the managed IT per-user fee for a single monthly invoice. Always confirm whether M365 licensing is included or additional when comparing quotes. Q: What is a reasonable response time SLA for managed IT support? A: UK managed IT SLAs usually define three priorities. P1 (critical, system down, multiple users): one-hour response, four-hour resolution target. P2 (major, one user or department): two-to-four-hour response. P3 (minor, workaround available): next business day. Confirm whether out-of-hours response for P1 incidents is included or charged separately. Q: Is managed IT really cheaper than break-fix? A: For businesses with ten or more users, usually yes once hidden costs are counted. Break-fix looks cheaper per hour, but downtime, emergency out-of-hours rates and separately purchased security frequently push its true annual cost above a fixed managed contract - without the budget predictability managed IT provides. Q: Does the location of an IT provider matter? A: For day-to-day services - helpdesk, monitoring, patching, Microsoft 365 management - location is irrelevant, as these are delivered remotely. It matters only for hands-on work like hardware swaps or new office setups. AMVIA is Sheffield-based, serves businesses UK-wide, and has on-site capability across Yorkshire and the North plus partner engineer coverage nationally. Q: What does a managed IT contract typically include? A: A proper managed IT contract bundles helpdesk support, continuous monitoring, Windows and third-party patching, Microsoft 365 management, endpoint security, and cloud backup under one fixed per-user fee. Full-service tiers add 24/7 monitoring, out-of-hours response, security awareness training and certification support for regulated businesses. --- # What Does Managed IT Support Cover? URL: https://amvia.co.uk/managed-it/questions/what-does-managed-it-cover Last updated: 2026-03 Managed IT covers proactive monitoring, a phone-and-remote helpdesk, patch management, backup management, antivirus and security management, Microsoft 365 administration, and regular service reviews. Higher tiers add on-site engineer visits and hardware procurement. AMVIA bundles all of this with integrated cybersecurity under one accountable provider - security-first, Microsoft-certified. The honest answer is that "managed IT" means different things at different providers, and the gaps are where businesses get burned. This guide sets out exactly what a proper managed IT contract should include, what cheaper tiers quietly leave out, and how to read a proposal so you do not pay for a helpdesk while believing you bought security. For the full service definition, see our managed IT support pillar. ## What is included in a standard managed IT contract? A standard managed IT contract covers the day-to-day running and protection of your systems: monitoring that flags faults before users notice, a helpdesk your staff can call, automated patching, managed backups, endpoint security, and Microsoft 365 administration. It is a fixed monthly fee for keeping everything working and secure, not pay-per-fix. Most reputable UK providers structure the scope around these core components: - Proactive monitoring - agents on servers, endpoints, and network devices raise alerts for disk, memory, connectivity, and security events around the clock. - Service desk / helpdesk - phone, email, and remote-control support for end users, usually with a published SLA for response and fix times. See what a good IT helpdesk should deliver. - Patch management - operating system and third-party application updates tested and deployed on a schedule, closing the vulnerabilities attackers rely on. - Backup management - backups configured, monitored, and (in a good contract) restore-tested, not just "switched on". - Endpoint and email security - antivirus/EDR, email filtering, and policy enforcement across every device. - Microsoft 365 administration - user provisioning, licence management, mailbox and SharePoint admin, and security configuration. - Service reviews and reporting - a regular review of tickets, risks, and roadmap with a named account contact. The UK has a deep pool of providers to choose from. Scale varies enormously, so scope - not headcount - is what you should compare. ## What does managed IT cover that break-fix doesn't? Managed IT is proactive and prevention-led; break-fix is reactive and incident-led. Under break-fix you pay per call-out when something has already failed. Under managed IT you pay a fixed monthly fee to monitor, patch, and maintain systems so failures are caught early or prevented entirely. The difference is risk transferred away from your business. The contrast matters because reactive support has a hidden cost: the downtime and breach exposure between failures. The UK government's Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach at around £3,550, and proactive patching plus monitoring is exactly what reduces that exposure (gov.uk). | | Capability | Break-fix | Managed IT | Billing | Per incident | Fixed monthly fee | Monitoring | None - you report faults | 24/7 proactive alerts | Patching | Ad hoc | Scheduled and verified | Backups | Often unmanaged | Monitored, ideally restore-tested | Security posture | Reactive | Continuously maintained | Provider incentive | More faults = more revenue | Fewer faults = better margin If you want the deeper trade-off analysis, our co-managed IT page explains how to blend an internal team with a managed provider rather than choosing one extreme. ## Does managed IT cover cybersecurity and Microsoft 365? It should, but the depth varies wildly. Baseline managed IT includes antivirus, email filtering, and standard Microsoft 365 admin. A security-first provider goes further: endpoint detection and response, conditional access, multi-factor enforcement, and a monitored security stack. Treat "we do security" as a question to interrogate, not a tick-box. At AMVIA the security layer is built in, not bolted on. Endpoints are protected with Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, and email and network traffic are filtered through the Barracuda suite. Microsoft 365 is hardened with multi-factor authentication, conditional access, and Secure Score remediation rather than left on factory defaults - see our Microsoft 365 security approach. For the full threat-led detail, our managed cybersecurity pillar sets out how the SOC operates. Microsoft's own licensing underpins much of this. Microsoft 365 Business Basic is £4.60, Business Standard £9.60, and Business Premium £16.90 per user per month (ex VAT, annual commitment), with Premium adding the security features SMEs actually need (microsoft.com/en-gb). A good managed IT provider tells you which tier fits and configures it properly; a weak one resells the licence and walks away. ## Does managed IT cover remote and hybrid workers? Yes - a modern managed IT service should cover every user and device regardless of location. That means secured laptops and mobiles, VPN or zero-trust access, cloud application management, and mobile device policies applied to home and office workers to the same standard. Location should not change the level of protection. This is where weak contracts leak. Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26), yet remote access without MFA is one of the most exploited weaknesses the NCSC warns about (ncsc.gov.uk). When you assess a provider, confirm that home workers get the same patching, endpoint protection, and access controls as anyone sitting in head office - not a lighter "remote" tier. ## What does managed IT cover for backup and disaster recovery? Most managed IT contracts include backup monitoring as standard, but depth is everything. Basic tiers only alert when a backup fails. Comprehensive services include tested restores, offsite or cloud replication, documented recovery procedures, and a defined recovery time objective so you know how long you would actually be down. The distinction is not academic. In a ransomware incident, a tested, isolated backup is the difference between a controlled recovery and a business-ending event. Ask your provider to show a recent successful restore test, not just a green "backup completed" status. Our business continuity guidance covers how to set realistic recovery objectives. ## How much does managed IT cost and what is included at each tier? Managed IT in the UK is typically priced per user per month, with AMVIA's IT support starting from £30/user/month. Entry tiers cover monitoring, helpdesk, and patching; mid tiers add managed backup and endpoint security; premium tiers add Microsoft 365 hardening, on-site visits, and a named account manager. Price tracks scope, not just headcount. - Entry - monitoring, remote helpdesk, patch management. - Standard - adds managed backup, endpoint security, Microsoft 365 admin. - Premium - adds SOC-monitored detection, M365 hardening, on-site support, account management. Read any quote against the component list above. If a "from" price looks low, the gap is almost always backup testing, security monitoring, or M365 hardening - the parts that matter most when something goes wrong. ## Frequently asked questions Q: What's included in a typical managed IT contract? A: Proactive monitoring, a phone-and-remote helpdesk, patch management, backup oversight, antivirus/security management and Microsoft 365 administration - the run-your-IT baseline. Tiers add security depth: AMVIA's ladder runs Essentials £25 / Advanced £40 / Enterprise £60 per user/month. Q: What's usually NOT covered? A: Projects (migrations, office moves, new infrastructure) are typically scoped and priced separately from the monthly fee, as are hardware purchases and third-party software licences. A good contract makes the boundary explicit so nothing surprises either side. Q: Is cybersecurity included in managed IT? A: At AMVIA, baseline security is in every tier and deepens up the ladder - Advanced adds managed security, Enterprise adds the 24/7 SOC. When comparing providers, this is the question to press on: 'security included' ranges from an antivirus licence to a monitored service. Q: Does managed IT include out-of-hours support? A: Depends on tier: monitoring runs around the clock on all AMVIA plans, while human response targets scale from next-business-day (Essentials) to 2-hour targets (Enterprise). Match the tier to what an evening outage actually costs you. --- # How Much Does Managed IT Support Cost Per Month in the UK? URL: https://amvia.co.uk/managed-it/questions/how-much-is-managed-it-support Last updated: 2026-03 Managed IT support costs £30–£80 per user per month for UK SMEs (typical UK 2026 range), depending on scope. Basic helpdesk and monitoring sits at the lower end; comprehensive packages with cybersecurity and Microsoft 365 management cost more. AMVIA's plans start from £25 per user per month (Essentials), with fully managed Enterprise including a 24/7 SOC from £60 - one provider, security-first. That headline range hides a lot. Two quotes at "£40 per user" can describe completely different services: one a remote helpdesk that answers tickets in business hours, the other a fully managed estate with 24/7 monitoring, patching, backup, and a security operations centre watching for threats. The number only means something once you know what sits behind it. This guide breaks down what you actually pay for, why prices vary, and how to compare managed IT support quotes without getting caught out. ## What does managed IT support cost per user per month? Most UK SMEs pay £30–£80 per user per month for managed IT support, billed on a per-seat basis so the cost scales with headcount. The figure you land on depends on the tier of service, your response-time guarantees, and whether cybersecurity and Microsoft 365 management are bundled in or charged as extras. Per-user pricing is the dominant model because it is predictable: you know your monthly bill the moment you know your staff count. Here is how the tiers typically break down across the £30–£80 band: | | Service tier | Position in the £30–£80 band | What's typically included | Essential | Lower end | Remote helpdesk (business hours), device monitoring, patch management, basic onboarding/offboarding | Standard | Middle | Everything in Essential plus Microsoft 365 administration, cloud backup, asset management, defined SLAs | Fully managed | Upper end | Everything in Standard plus 24/7 monitoring, managed cybersecurity, endpoint protection, vCIO/strategy reviews AMVIA's plans run £25 (Essentials) / £40 (Advanced) / £60 (Enterprise) per user per month, with security built into every tier rather than sold as a bolt-on. For a wider connectivity and cost breakdown, see our IT support cost guide for the UK. ## What drives the price difference between providers? The biggest price drivers are scope of service, response-time guarantees, and whether cybersecurity is included. A provider quoting £35 per user and one quoting £75 are rarely selling the same thing - the gap is almost always coverage hours, security depth, and how fast someone actually picks up when something breaks. Watch these variables when you compare quotes: - Coverage hours - business-hours support is cheaper than genuine 24/7 cover. - Response and resolution SLAs - a one-hour priority response costs more than next-business-day. - Security inclusion - bundled managed cybersecurity vs. an unprotected helpdesk. - Microsoft 365 management - licence administration, hardening, and backup add value and cost. - Onsite vs. remote - guaranteed onsite visits raise the per-user figure. Cybersecurity is the variable that matters most right now. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the last 12 months. A provider that bundles real protection may quote more per user but removes a risk that a cheaper, security-light contract leaves wide open. ## What's included in managed IT support pricing? A genuine managed service should cover proactive monitoring, helpdesk support, patching, backup, and security as standard - not as a menu of add-ons. If a quote looks cheap, the gap is usually in what has been quietly left out: out-of-hours cover, endpoint protection, or backup verification. A complete managed IT support package usually includes: - Unlimited remote helpdesk within agreed hours - Proactive monitoring and automated patching of servers and endpoints - Microsoft 365 administration, licensing, and security hardening - Endpoint protection via Microsoft Defender, monitored continuously - Cloud backup with tested, documented recovery - Onboarding and offboarding of staff and devices - Regular reporting and a named technical contact AMVIA delivers this as a single accountable contract: one provider, security-first, Microsoft-certified engineers. The National Cyber Security Centre's guidance for small and medium organisations sets the baseline every managed service should meet - backups, patching, and access control are non-negotiable, not premium extras. ## Is it cheaper to bundle IT support with cybersecurity? Yes, in most cases. Running IT support and cybersecurity through separate providers creates integration gaps, duplicated tooling, and finger-pointing during an incident. A combined service removes that overhead and usually lowers total per-user cost, because one team manages the estate end to end. The hidden cost of splitting providers shows up at the worst moment - during an incident, when your IT supplier blames the security vendor and nobody owns the fix. A single provider closes that gap. For a deeper look at where security spend lands, read how much managed cybersecurity costs, or explore AMVIA's managed cybersecurity approach. The UK managed services sector is large and competitive - so you have leverage to demand bundled value rather than paying twice for overlapping coverage. ## How do contract length and business size affect cost? Contract length and headcount both move the per-user price. Most UK providers offer 12, 24, or 36-month terms, and longer commitments attract lower per-user rates. Larger user counts also reduce the per-seat figure because fixed onboarding and tooling costs spread across more people. - Contract term - 36-month deals typically beat rolling monthly agreements, which sit at a premium for flexibility. - User count - sub-10-user businesses often pay a higher per-seat rate or a minimum monthly fee. - Growth plans - agree how new starters are priced before you sign, so scaling doesn't trigger a renegotiation. Always check renewal terms, price-review clauses, and exit provisions before committing. Compare the break-fix vs. managed IT models too - paying per incident can look cheaper until the first serious outage. Businesses with an internal IT person often find co-managed IT the most cost-effective route, splitting day-to-day tickets from strategic work. ## Frequently asked questions Q: How much does managed IT support cost per user per month in the UK? A: UK SMEs typically pay £30–£80 per user per month (typical UK 2026 range), depending on scope. Basic helpdesk and monitoring sits at the lower end, while fully managed packages with 24/7 cover, cybersecurity, and Microsoft 365 management cost more. AMVIA's plans start from £25 per user per month (Essentials), with Enterprise from £60. Q: Why do managed IT support quotes vary so much? A: The main variables are scope of service, response-time guarantees, and whether cybersecurity is included. Two quotes at the same headline price can describe very different services - one a business-hours helpdesk, the other a fully monitored, secured estate. Always compare coverage hours, SLAs, and security depth, not just the per-user number. Q: Is it more cost-effective to bundle IT support with cybersecurity? A: Yes, in most cases. Using separate providers creates integration gaps and duplicated overhead, and triggers finger-pointing during an incident. A combined service gives you one accountable team, removes duplicated tooling, and usually reduces total per-user cost while improving protection. Q: What contract length is typical for managed IT support? A: Most UK providers offer 12, 24, or 36-month contracts, with longer terms attracting lower per-user rates. Some offer rolling monthly agreements at a premium for the flexibility. Always check renewal terms, price-review clauses, and exit provisions to avoid being locked in. Q: What's usually included in a managed IT support contract? A: A complete contract covers remote helpdesk, proactive monitoring, automated patching, Microsoft 365 administration, endpoint protection, and tested cloud backup. Weaker or cheaper quotes often omit out-of-hours cover, security, or backup verification - so check the inclusions line by line before comparing prices. Q: Does business size change the per-user price? A: Yes. Larger user counts reduce the per-seat figure because fixed onboarding and tooling costs spread across more people. Businesses under 10 users often face a higher per-user rate or a minimum monthly fee. Agree how new starters are priced before signing so growth doesn't trigger a renegotiation. --- # What SLA Should You Expect from a Managed IT Provider? URL: https://amvia.co.uk/managed-it/questions/msp-sla Last updated: 2026-03 An MSP SLA is the contract clause that defines how fast your managed IT provider responds to and fixes problems, and how much uptime it guarantees. A strong one commits to P1 critical issues answered within 1 hour and resolved within 4 hours, 99.99% infrastructure uptime, and service credits when targets are missed. If you only read one part of your managed IT contract, read the SLA. It is where vague promises become measurable, enforceable commitments - or where they quietly disappear. Below is what a credible MSP SLA contains, how AMVIA structures ours, and how to compare providers like an IT director buying managed IT support rather than a buyer taking marketing at face value. ## What is an MSP SLA? An MSP SLA (Service Level Agreement) is the section of your managed services contract that defines measurable commitments: how quickly the provider responds, how quickly it resolves, what uptime it guarantees, and what you are owed when it falls short. It turns "we'll look after your IT" into numbers you can hold to account. A real SLA does three things a sales deck cannot. It separates *response* time (someone acknowledges and starts work) from *resolution* time (the issue is actually fixed) - two very different promises that weak providers blur together. It assigns priority levels so a downed server is not queued behind a password reset. And it attaches consequences, usually service credits, when the provider misses a target. Anything softer than that is an aspiration, not an agreement. ## What response and resolution times should an MSP SLA guarantee? A good MSP SLA tiers issues by business impact and sets a separate response and resolution clock for each. The benchmark AMVIA works to: P1 critical issues responded to within 1 hour and resolved within 4 hours; P2 standard issues within 4 hours; P3 low-priority issues within 8 hours. Critically, these are contractual, not "best efforts". The distinction between response and resolution is where most weak SLAs hide. A provider can boast a "15-minute response" and still leave you offline for two days, because responding only means a ticket was acknowledged. Insist on a resolution target for every priority tier, and confirm how priority is assigned - it should reflect business impact, not the provider's convenience. | | Priority | Example | Response target | Resolution target | P1 - Critical | Server down, site-wide outage, active security incident | 1 hour | 4 hours | P2 - Standard | Single application failing, one user fully blocked | 4 hours | Same business day | P3 - Low | Minor bug, non-urgent request, "how do I" query | 8 hours | Scheduled Pair the SLA with a clear escalation path. You want to know - before you sign - who gets called when a P1 resolution target is about to slip, and how that ties into your IT helpdesk and out-of-hours cover. ## What uptime should an MSP SLA guarantee? For managed infrastructure, 99.99% uptime is the benchmark to aim for. The catch most buyers miss is what that percentage actually buys you in real time, and how the provider measures it. Two providers quoting the same number can mean very different things depending on what is in scope and how downtime is counted. Run the maths before you accept any uptime figure. At 99.99%, that works out at roughly 53 minutes of permitted downtime a year - verify the exact window in your own contract, because a single decimal place changes the answer dramatically. Then nail down three things in writing: - What's covered - the whole environment, or only the provider's own data centre? Your broadband line and on-site hardware may sit outside the guarantee. - How it's measured - rolling 12 months or per calendar month? Per-month is stricter and harder to game. - What you get when it's missed - automatic service credits, or credits you have to claim? Automatic is the standard to hold out for. Uptime promises are only as good as the recovery plan behind them, so read the SLA alongside the provider's business continuity commitments. A four-nines number means little without tested backups and a defined recovery time. ## Should security incident response be in your MSP SLA? Yes - and it should be the strictest clause in the document. A live cyber attack is a P1 event by definition, so your SLA must classify security incidents at the fastest response and resolution tier, with a dedicated escalation path and clear containment obligations. Treating a ransomware outbreak like a routine ticket is how a contained incident becomes a business-ending one. UK breach rates make this non-negotiable. The government's annual Cyber Security Breaches Survey consistently finds a large share of UK businesses - around 43% in the latest figures - identifying a breach or attack each year, and the most disruptive incidents carry real cost (the source we worked from cites an average of £3,550 per most-disruptive breach). Confirm the figures relevant to your sector against the government's published survey and follow the NCSC's incident management guidance for what a credible response process looks like. This is where a single accountable provider earns its keep. One provider, security-first, with Microsoft-certified engineers means the team fixing your outage is the same team containing the threat - no finger-pointing between an IT supplier and a separate security vendor. If your MSP outsources security, make sure the SLA names who owns incident response and how fast they must act. For a fuller view of how managed IT and managed cybersecurity interlock, treat the security SLA as part of the same contract, not a bolt-on. ## How do you compare MSP SLAs? Compare SLAs on substance, not headline numbers. Three tests separate a genuine commitment from marketing: does it distinguish response from resolution, are service credits automatic or claimed, and is security classified separately at the top priority tier? Score every provider against the same checklist and the weak ones surface quickly. | | What to check | Strong SLA | Weak SLA | Response vs resolution | Separate target for both | Only a "response" time | Priority model | Tiered by business impact | One-size queue | Security incidents | Classified P1, dedicated path | Treated as standard tickets | Service credits | Automatic on breach | You must claim them | Uptime scope | Clearly defined, measured monthly | Vague "99%+" with no scope Cost and SLA strength move together - tighter targets need more people and tooling behind them, which is why it pays to read the SLA next to the pricing. Our breakdown of how much managed IT support costs in the UK shows where the money goes, and our managed IT support page sets out the response tiers we actually commit to. ## What does the UK managed services market look like? The UK has a deep MSP market, which is good news for buyers - you have real choice and real bargaining power to demand a strong SLA. That maturity matters because SMEs - which make up roughly 99% of UK businesses (UK business population, 2025) - increasingly buy managed IT as a single accountable service rather than stitching together break-fix suppliers. A competitive market means you should never accept a one-sided SLA. If a provider resists putting resolution times and automatic service credits in writing, that tells you how the relationship will run. ## Frequently asked questions Q: What response times should an MSP SLA guarantee? A: Tiered by severity: critical issues measured in hours (AMVIA's Enterprise targets 2 hours; critical remote response under one hour), routine requests in business days. Any SLA quoting one blanket number for everything hasn't thought about severity. Q: What's the difference between response time and fix time? A: Response is when work starts; fix is when the problem's gone. An SLA that only commits to responding can 'meet' its promise while your system stays down - look for repair/resolution language and escalation paths, not just acknowledgement clocks. Q: What does 99.9% uptime actually mean? A: Roughly 8.8 hours of allowed downtime a year - versus under an hour at 99.99%. The digits matter, and so does what's measured: uptime of the provider's platform is not uptime of your systems. Ask which one the number describes. Q: What happens if the MSP misses the SLA? A: A real SLA carries consequences - service credits, escalation rights, and at persistent failure, exit clauses. An SLA without remedies is a marketing page. Ask to see the credits table before signing, not after the first bad month. --- # Managed IT vs Break-Fix IT: Which Is Right for Your Business? URL: https://amvia.co.uk/managed-it/compare/msp-vs-break-fix Last updated: 2026-03 The core difference in MSP vs break-fix is timing. An MSP (managed service provider) prevents problems with proactive monitoring and a fixed monthly fee; break-fix only reacts after something breaks, billed by the hour. For any UK business where downtime costs money, the managed IT support model wins - and with AMVIA you get one provider, security-first, Microsoft-certified. ## What is the difference between MSP and break-fix IT support? A managed service provider runs your IT continuously for a predictable monthly fee - monitoring, patching, securing and supporting your systems before faults surface. Break-fix is the opposite: you call an engineer when something fails and pay an hourly rate to repair it. One model prevents incidents; the other only cleans them up. Break-fix made sense when IT was a back-office convenience. Today most UK SMEs run their entire business on connected systems, so the gap between "we noticed and fixed it overnight" and "we found out when staff couldn't log in" is the gap between a good week and a lost one. The UK MSP market is crowded and mature, reflecting how decisively buyers have moved toward the proactive model. ## MSP vs break-fix: how do the two models compare? On almost every axis that affects a growing business - predictability, security, response speed and planning - the managed model outperforms break-fix. Break-fix only retains an edge on raw headline cost in months where nothing goes wrong, and that "saving" disappears the moment one serious incident lands. | | Feature | Managed IT (MSP) - £30–£80/user/month (typical UK 2026) | Break-Fix - £80–£150/hour (typical UK 2026) | Proactive monitoring | Yes | No | Guaranteed response times (SLA) | Yes | No | Predictable monthly cost | Yes | No | Patch & update management | Yes | No | Security built in | Yes | No | Strategic IT planning | Yes | No | 24/7 support available | Yes | Rarely | Dedicated account manager | Yes | No The pattern is clear: break-fix is a repair service, not an IT strategy. Managed IT folds monitoring, cybersecurity and planning into one accountable relationship, so problems are caught early and your systems improve over time rather than drifting toward the next failure. ## How much does MSP support cost versus break-fix over a year? Managed IT looks more expensive per month but is almost always cheaper per year once you price in risk. A 30-person business on managed IT pays a steady, budgetable fee. The same firm on break-fix pays less in quiet months - then absorbs a single server failure, ransomware hit or network outage that can run to £5,000–£20,000 in callouts, recovery and lost productivity. Typical UK SME managed IT runs around £25–£65 per user per month as an industry benchmark, giving predictable annual costs you can plan against. Break-fix at £80–£150 per hour looks cheaper until one bad incident eats several months of managed fees in a single invoice. For a full breakdown, see our IT support cost guide. - Predictable budgeting - managed IT is a fixed line item, not a surprise. - Prevention over repair - most incidents never happen, so you rarely pay emergency rates. - Hidden break-fix costs - downtime, data loss and overtime dwarf the hourly invoice. ## When should you choose managed IT over break-fix? Choose managed IT when downtime affects revenue, when you need security baked into support, or when you can't afford to discover problems only after they've stopped work. If more than five people depend on IT to do their jobs, the proactive model pays for itself in avoided disruption. With 43% of UK businesses identifying a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), reactive support is a real exposure. Managed IT bundles in patching and monitoring aligned to NCSC small-business guidance, so the fixes that stop most attacks happen automatically rather than waiting for a callout. It also keeps business continuity covered, so a single failure doesn't become a crisis. ## When does break-fix still make sense? Break-fix can suit a very small operation - under five staff, basic needs, high tolerance for downtime, and no regulatory or security obligations to meet. If a laptop being out of action for two days is merely annoying rather than costly, paying per incident is defensible. That window is closing fast. As soon as a business relies on email, cloud apps, shared files or customer data to trade, the economics flip toward managed IT. If you already have internal IT staff but need extra cover and tooling, a hybrid co-managed IT arrangement often beats both pure models. ## What does AMVIA recommend? We recommend managed IT for any UK business with more than five users that depends on technology to operate. Predictable cost, proactive monitoring and SLA-backed response times outweigh the apparent saving of break-fix, because the saving evaporates the first time something serious breaks. AMVIA's managed IT support service starts from £25 per user per month and includes unlimited helpdesk, patch management and security monitoring as standard. We protect 1,200+ UK businesses, hold Cyber Essentials Plus, and run as a Microsoft Solutions Partner - one provider, security-first, Microsoft-certified. The UK skills picture makes this harder to replicate in-house: the median cyber security salary is around £55,000 and 49% of UK businesses report a basic cyber security skills gap, so outsourcing to a security-led MSP is usually faster and cheaper than hiring. ## Frequently asked questions Q: How much does managed IT cost compared to break-fix over a year? A: Managed IT is a fixed monthly fee per user, giving a 30-person business predictable annual costs you can budget for. Break-fix looks cheaper in quiet months at an hourly rate, but a single major incident can exceed several months of managed fees in one invoice - making annual costs unpredictable and often higher overall. Q: Does managed IT prevent problems that break-fix only reacts to? A: Yes. Managed IT includes proactive monitoring, automated patching and security management that stop most incidents before they happen. Break-fix providers only engage after a failure. Because most UK businesses now face attempted cyber breaches each year, the continuous security monitoring built into managed IT meaningfully reduces the chance of a successful attack. Q: What response-time guarantees does managed IT offer compared to break-fix? A: Managed IT contracts include SLA-backed response times - typically minutes for critical issues. Break-fix providers respond on a best-effort basis and may be tied up with other clients. When a server fails at 6pm on a Friday, a guaranteed response is the difference between hours and days of downtime. Q: Can I switch from break-fix to managed IT without disruption? A: Yes. A reputable MSP runs an onboarding audit first - documenting your infrastructure, fixing immediate risks and deploying monitoring - before taking over support. The transition usually takes two to four weeks and runs alongside your existing arrangement, so there's no gap in coverage during the changeover. Q: Is break-fix ever cheaper than an MSP? A: Only in the short term, and only if nothing goes wrong. In quiet months a small firm may pay less on break-fix. But that model carries the full cost of every incident, plus downtime and recovery, so over a year managed IT is usually cheaper once risk is priced in honestly. Q: Do small businesses really need a managed service provider? A: If your business depends on email, cloud apps, customer data or connected systems to trade, then yes. The threshold is roughly five users. Below that, with minimal needs and high downtime tolerance, break-fix can work - but the security and continuity benefits of managed IT increasingly apply even to very small teams. --- # Managed IT Provider vs In-House IT Team: A Full Comparison URL: https://amvia.co.uk/managed-it/compare/msp-vs-in-house Last updated: 2026-03 MSP vs in-house IT comes down to breadth versus control. A managed service provider gives a 10-500 staff business a full team - helpdesk, infrastructure, networking and security - for a predictable monthly fee. A single in-house hire gives you presence and ownership, but rarely covers every discipline. AMVIA delivers all of it from one provider, security-first. For most UK SMEs under 100 users, an MSP wins on cost and coverage. For larger or highly specialised teams, a hybrid model often beats either extreme. This guide sets out exactly where each option fits, what it costs, and how to decide. Start with our managed IT support pillar for the full service picture. ## MSP vs in-house IT: how do they compare at a glance? A managed IT provider spreads a whole team across your estate for a fixed per-user fee, while an in-house team gives you dedicated headcount you fully control. The right answer depends on size, risk appetite, and how many IT disciplines you actually need covered each week. | | Factor | Managed IT Provider (MSP) | In-House IT Team | Best for | SMEs under ~100 users needing broad coverage | Larger firms with constant, specialist daily demand | Cost model | Predictable £25-£60 per user/mo | £35,000-£55,000 salary per hire + on-costs | Expertise breadth | Team across helpdesk, network, cloud, security | Limited to what each individual knows | Coverage hours | Up to 24/7, no single point of failure | Office hours; gaps for leave and sickness | Scaling | Add or remove users on demand | Slow - recruit, onboard, train | Knowledge ownership | Documented and contractually yours | Held in-house, but tied to individuals | Security depth | Specialist SOC and tooling included | Often the first gap when stretched ## When does a managed IT provider make sense? An MSP makes sense when you need broad expertise without broad headcount. Rather than one generalist juggling everything, you get specialists across networking, cloud, telephony, helpdesk and security - available across longer hours and without the single-person risk that one resignation can create. This model fits the typical UK SME well. With most SMEs now running critical workloads in cloud platforms, the skills needed span identity, Microsoft 365, endpoint and network security - more than one person can master. The National Cyber Security Centre's small business guidance makes clear how much basic protection a modern business has to maintain, and an MSP carries that load as standard. - No single point of failure when someone is on leave or leaves entirely - Specialist depth in security and cloud, not just break-fix - Predictable monthly cost instead of lumpy salary and recruitment spend - Faster access to tooling, licensing and vendor relationships If you want to see how this differs from paying only when something breaks, compare MSP vs break-fix IT. ## When does an in-house IT team make sense? An in-house team makes sense when IT is central to your product, demand is constant, and you need someone physically present every day. Firms with heavy bespoke applications, regulated on-site systems, or 200+ staff often justify dedicated headcount - and value the deep institutional knowledge a long-tenured employee builds. The trade-off is breadth and resilience. One in-house generalist cannot realistically cover networking, cybersecurity, cloud administration, telephony and helpdesk across all working hours. With hybrid working now standard and remote access part of every estate, the surface area a lone hire must defend keeps growing. That is why many in-house teams end up stretched and reach for outside specialists anyway. ## How do the costs compare for a UK SME? For businesses under 100 users, an MSP is usually cheaper than the loaded cost of one specialist hire. A single in-house IT person costs £35,000 to £55,000 in salary alone (typical UK 2026 range), plus employer National Insurance, pension, training and holiday cover. An MSP turns that into a predictable per-user fee covering a whole team. AMVIA's managed IT service provides a full support team - helpdesk, infrastructure, networking and security specialists - for £25-£60 per user per month. For a 50-user business, that buys access to a multi-discipline team for roughly the loaded cost of one generalist employee. A large and growing share of UK SMEs have already made this switch. - One in-house hire = one skill set, fixed hours, single point of failure - MSP fee = team coverage, longer hours, included tooling and licensing - Hidden in-house costs: recruitment, training, churn, holiday and sick cover For a fuller breakdown, see our IT support cost guide. ## Can you combine both with co-managed IT? Yes - co-managed IT lets you keep your in-house team and add an MSP alongside it. Your internal staff handle day-to-day operations and business-specific applications, while the MSP supplies specialist depth in security, cloud and after-hours cover. It is the most common answer for growing firms, not an either/or choice. This model works well for businesses with 50 to 250 staff whose existing IT team is stretched beyond capacity. You keep institutional knowledge and on-site presence, but stop asking one or two people to be experts in everything. Learn how co-managed IT divides responsibilities, or see the full managed IT support service for outsourced coverage. ## What about security and Microsoft 365 expertise? Security is where the in-house gap bites hardest. Specialist cybersecurity knowledge is difficult and expensive to hold in a single hire, yet the risk is rising - the UK government's Cyber Security Breaches Survey reports 43% of UK businesses faced a breach or attack in the past 12 months (DSIT 2025), rising to 65% of medium-sized firms in the 2025/26 edition. An MSP brings a security team and tooling as standard. AMVIA pairs managed IT with a security-first approach: Microsoft Defender and Barracuda protection, monitored by our in-house SOC, delivered by Microsoft-certified engineers. As a Microsoft Solutions Partner, we manage and harden your tenant using the official Microsoft 365 security tooling rather than bolting on third-party guesswork. Explore our managed cybersecurity and Microsoft 365 security services to see how the two fit together. One provider, accountable for both your IT and your security. ## Frequently asked questions Q: Is an MSP cheaper than hiring an in-house IT person? A: For businesses under 100 users, typically yes. A single in-house IT hire costs £35,000 to £55,000 in salary alone (typical UK 2026 range), plus employer costs, training and holiday cover. AMVIA's per-user MSP fee gives a 50-user business access to a full team of specialists for roughly the loaded cost of one generalist employee, with predictable monthly billing instead of fixed headcount. Q: What expertise gaps does an MSP fill that a single in-house IT person cannot? A: One in-house generalist cannot cover networking, cybersecurity, cloud administration, telephony and helpdesk across all working hours. An MSP provides a team spanning these disciplines with coverage up to 24/7. Cybersecurity in particular is hard to maintain in one hire, so most SMEs gain meaningful specialist depth the moment they bring an MSP on board. Q: Can I keep my in-house IT team and use an MSP at the same time? A: Yes - this is called co-managed IT. Your internal team handles day-to-day operations and business-specific applications, while the MSP provides specialist support in areas like cybersecurity, cloud management and after-hours coverage. This model works well for businesses with 50 to 250 staff whose existing IT team is stretched beyond its capacity. Q: What happens to our IT knowledge if we rely entirely on an MSP? A: A reputable MSP maintains comprehensive documentation of your infrastructure, credentials and configurations. This documentation should be contractually yours to retain if you change providers. A good MSP also helps you achieve and maintain certifications, such as Cyber Essentials Plus, that remain with your business regardless of who supports it. Q: When does an in-house IT team make more sense than an MSP? A: An in-house team makes more sense when IT is core to your product, demand is constant every day, and you need someone physically present on site. Firms running heavy bespoke applications, regulated on-site systems, or with more than around 200 staff often justify dedicated headcount - frequently alongside an MSP in a co-managed model rather than instead of one. --- # Complete Business IT Protection, Connectivity & Security URL: https://amvia.co.uk/managed-it/complete-business-it-protection Last updated: 2026-03 Complete business IT protection bundles every layer a UK SME runs on - connectivity, Microsoft 365, endpoint security, backup, and helpdesk - into one managed IT contract. Instead of juggling separate suppliers and the accountability gaps between them, you get one invoice, one number to call, and one provider that is security-first and Microsoft-certified. ## What is complete business IT protection? Complete business IT protection is the principle that everything your technology depends on - connectivity, devices, software, communication tools, backup, and security - is managed coherently as one service, not bought piecemeal from different suppliers. One provider owns the whole environment, monitors it actively, and answers for it when something breaks. For most SMEs the reality is the opposite. Broadband sits with one provider, Microsoft 365 licences with another, endpoint security with a third, and IT support is a break-fix arrangement called on when things go wrong. The result is predictable: gaps in accountability, slow incident response, and security blind spots that exist precisely because no single party can see the whole picture. AMVIA folds all of it into managed IT support delivered on a single per-user monthly fee. The UK managed services market is worth around £8.4 billion (TechMarketView, 2025 estimate), growth driven substantially by businesses recognising that fragmented IT creates more problems than it solves. ## What does a complete managed IT service include? A complete managed IT service for a UK business typically covers seven core areas. Each matters on its own, but the real value comes from managing them together as one system rather than as isolated products with no shared visibility. - UK helpdesk support - a UK-based IT helpdesk staff can contact for any issue, with response targets set in a service level agreement (SLA) and critical faults prioritised over routine requests. - 24/7 monitoring - automated monitoring of servers, endpoints, network devices, and cloud services, so a failing disk or a backup that quietly stopped is caught as a small signal, not an outage. - Patch management - automated deployment of security updates within defined timelines. The National Cyber Security Centre identifies unpatched, known vulnerabilities as one of the most common routes attackers exploit, so consistent patching is among the highest-impact controls available. - Microsoft 365 management - licensing, starter/leaver provisioning, Exchange Online and Teams administration, and security configuration, handled by the provider rather than demanding in-house expertise. - Endpoint security - managed Microsoft Defender for Business (endpoint detection and response, or EDR) deployed and monitored across every device, detecting suspicious behaviour and isolating compromised machines. - Cloud backup - independent backup of Microsoft 365 and server data to separate storage. Microsoft's native retention is not a substitute for backup, as Microsoft's own guidance makes clear - accidental deletion, ransomware encryption, and tenant compromise all need an independent copy to recover from. - Cybersecurity management - firewall and email security (Barracuda), DNS filtering, staff security-awareness training, and support for compliance certifications, all built into the service rather than bolted on. ## Why does fragmented IT cost UK SMEs more? Fragmented IT fails at the seams. When a security incident spans multiple suppliers, the broadband provider blames the firewall, the firewall vendor points at Microsoft 365, and Microsoft calls it a configuration problem. No one owns the outcome, and the business coordinates between parties while the incident stays live. The same drag hits day-to-day work. An update from one supplier breaks software managed by another. An endpoint alert needs action across systems owned by different parties. Response is slow because cross-supplier coordination is inherently slow - separate ticket queues, separate SLAs, separate priorities. It also creates security blind spots. If the email filter spots a phishing campaign but cannot pass that intelligence to the endpoint tooling, the business loses the chance to block related malware at the device. A single-provider model closes that gap because one team sees every layer at once. With 43% of UK businesses reporting a cyber breach or attack in the prior 12 months (Cyber Security Breaches Survey 2025, DSIT), and most breaches exploiting known weaknesses, that shared visibility is the point. ## Fragmented IT vs a complete managed service | | Factor | Multiple suppliers | Complete managed IT | Accountability | Gaps between vendors; blame-shifting | One provider owns the outcome | Incident response | Slow cross-supplier coordination | Single team, full-stack visibility | Security | Bolted on; intelligence not shared | Built in; signals shared across layers | Billing | Multiple invoices, renewal cycles | One per-user monthly invoice | Point of contact | Several helpdesks | One number to call ## What are the three pillars of complete IT protection? AMVIA structures complete protection around three pillars that together cover the full technology environment of a UK SME: connectivity, collaboration, and security. Managing them under one roof is what removes finger-pointing and shortens fault diagnosis. - Connectivity - leased lines, broadband, and mobile, managed by the same provider that manages your systems, so faults are diagnosed across both ends with no ISP-versus-IT standoff. - Collaboration - Microsoft 365 (Teams, Exchange Online, SharePoint, OneDrive) licensed, configured, and secured through managed Microsoft 365 services, including Conditional Access, MFA enforcement, and data loss prevention. - Security - endpoint protection, email security, firewall management, and backup delivered as part of managed cybersecurity, built into the service from day one rather than sold as a separate contract. ## How much does complete IT protection cost? Pricing is per user, per month, so cost scales cleanly with headcount instead of arriving as unpredictable capital spikes. Average UK IT support costs range from £50 to £150 per user per month (typical UK 2026 range), with the position in that range driven by device count, security depth, and SLA targets. Consolidation is the practical win: rather than separate invoices for broadband, Microsoft 365, endpoint security, backup, and support - each on its own renewal cycle - everything lands on one figure. That turns IT from a capital expense into a predictable operating cost and lets you budget without the spike costs of hardware failure, emergency call-outs, or unplanned security remediation. ## How does AMVIA's all-in-one managed IT service work? New clients start with an onboarding assessment that documents every device, application, service, and supplier relationship, and flags immediate risks. AMVIA then builds a transition plan and takes over monitoring, patching, helpdesk, and security management on a per-user monthly fee with no hidden charges. Headcount changes are handled by a simple notification. New starters get a provisioned device, a configured Microsoft 365 account, and security software on day one; leavers have access revoked, data preserved to policy, and devices wiped on departure. The aim is one accountable provider for the entire stack - security-first and Microsoft-certified. Call AMVIA on 0333 733 8050 to discuss what complete IT protection looks like for your business. ## Frequently asked questions Q: Can we keep some existing suppliers and just add a managed IT service? A: Yes. AMVIA can work alongside existing supplier agreements and manage third-party contracts on your behalf where they cannot be replaced immediately. The accountability benefits are greatest when one provider manages everything, so a common path is to consolidate suppliers as contracts expire - typically moving to full management over 12 to 24 months. AMVIA advises on the most practical route for your situation. Q: Does a complete managed IT service include Microsoft 365 licences? A: Yes. AMVIA includes Microsoft 365 licensing - procurement, billing, and management - within the monthly fee, so M365 sits on one IT invoice rather than a separate Microsoft billing relationship. Licence changes for starters and leavers are handled by AMVIA as part of the service, alongside security configuration of the tenant. Q: What happens during the transition from our current IT setup? A: Onboarding starts with a full environment assessment documenting devices, software, services, suppliers, and configurations. AMVIA then deploys monitoring and security tooling and takes over each component in a structured sequence, managing the handover from any incumbent provider to keep service continuous. A typical SME onboarding runs two to four weeks. Call 0333 733 8050 to discuss the process. Q: Is security really included, or is it an add-on? A: Security is built into the core service, not a separate line item. Endpoint protection with Microsoft Defender for Business, Barracuda email and network security, patch management, and backup are standard components. Integrating security with IT management means every device, user, and data store is covered by one consistent framework rather than depending on a separate contract. Q: Does complete IT protection support compliance? A: A well-managed IT environment is foundational for UK GDPR and supply-chain security requirements, and AMVIA holds Cyber Essentials Plus. A complete service keeps every layer in scope - patched, monitored, backed up, and access-controlled - which supports the evidence regulators and auditors expect. AMVIA supports compliance work but does not replace formal certification or legal advice. --- # Managed IT Support and Cybersecurity Sheffield URL: https://amvia.co.uk/locations/sheffield Last updated: 2026-08-28 AMVIA delivers managed IT support, cybersecurity, leased lines, VoIP and Microsoft 365 to businesses across Sheffield and South Yorkshire. You get proactive 24/7 monitoring, clear SLAs and a named account manager - delivered remote-first with on-site visits where they matter. One provider, security-first, Microsoft-certified. Key facts: - 1,200+ UK businesses managed by AMVIA - Under 1 hour remote response target for critical issues - 24/7 monitoring and support ## Why do Sheffield businesses choose AMVIA for IT support? Sheffield firms pick AMVIA because they get one accountable provider for IT, security and connectivity instead of three suppliers blaming each other. We run managed IT support remote-first from a 24/7 operations centre, with engineers who learn your business before they touch a single setting. That model matters locally. We support businesses across the whole region - Sheffield (S1–S14), Rotherham (S60–S65), Barnsley (S70–S75) and Doncaster (DN postcodes) - without forcing every fix into a van journey. Most issues are resolved remotely in minutes; on-site attendance is arranged when the problem or your plan genuinely needs it. The threat picture is the reason security sits at the centre of everything we ship. 43% of UK businesses experienced a cyber breach or attack in the last 12 months (gov.uk Cyber Security Breaches Survey 2025). For a Sheffield SME, that is not an abstract risk - it is a coin-flip every year. ## What managed IT services does AMVIA provide in Sheffield? AMVIA provides the full stack a growing Sheffield business needs: security, connectivity, voice, Microsoft 365 and day-to-day support. Each service stands alone or combines into one managed agreement with a single SLA and a single point of contact. Here is what you get and where each piece links. - Managed cybersecurity - 24/7 monitoring, endpoint protection, email security and incident response, built on Microsoft Defender and the Barracuda suite, monitored by our in-house SOC. - Microsoft 365 security - deployment, migration, hardening and ongoing management for email, data and Teams. - Business leased lines - dedicated, uncontended FTTP and SD-WAN, delivered over Openreach, CityFibre and other UK carriers. - Business VoIP - cloud-hosted phone systems with local Sheffield numbers, mobile apps, call recording and CRM integration. - Business mobiles - managed mobile estates with device management and security baked in. - IT helpdesk - a UK-based desk staffed by qualified engineers who know your environment, not an offshore script. ## How fast is broadband and connectivity for Sheffield businesses? Connectivity in Sheffield is strong and getting stronger, but availability still varies street by street, so a survey before you commit is essential. Gigabit-capable broadband now reaches roughly 87% of UK premises (Ofcom, 2025), and Sheffield's CityFibre and Openreach footprints are expanding across the city. For businesses that can't tolerate downtime, a leased line removes the gamble. A serious outage on best-efforts broadband routinely means a day or more of disruption - a dedicated, uncontended line with a guaranteed SLA and fix-time commitment is how you avoid that. We check exact availability at your postcode before quoting. ## What does managed IT support cost for a Sheffield business? Pricing is fixed monthly per user - the same plans AMVIA runs UK-wide, with no hidden charges and no per-ticket fees. The table below shows the three tiers. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Security is built into the higher tiers rather than sold as a bolt-on. Following NCSC small-business guidance, the controls that stop most attacks - patching, MFA, endpoint protection and monitored backups - should be standard, not premium (NCSC Small Business Guide). ## Which areas around Sheffield does AMVIA cover? AMVIA supports businesses across the whole of South Yorkshire, delivered remote-first with on-site attendance arranged where appropriate. Coverage spans Sheffield and the surrounding towns, so a single agreement covers multi-site operations without a patchwork of regional suppliers. - Sheffield - S1 to S14 - Rotherham - S60 to S65 - Barnsley - S70 to S75 - Doncaster - DN postcodes - Wider South Yorkshire and the Sheffield City Region ## Frequently asked questions Q: Is AMVIA actually based in Sheffield? A: Yes - Sheffield is AMVIA's home city, with an operations centre here and clients across South Yorkshire including Rotherham, Barnsley and Doncaster. Support is remote-first for speed, with local on-site attendance when needed. Q: What do South Yorkshire businesses typically buy first? A: Usually managed IT with security included, then connectivity as contracts renew - leased lines and broadband compared per postcode across BT Openreach, CityFibre and Virgin Media Business. One provider, one bill, one accountable SLA. Q: Do you support manufacturers around Sheffield? A: Yes - South Yorkshire's manufacturing base is a natural fit: office IT and helpdesk alongside the segmentation, monitoring and resilient connectivity that production environments need. Q: What makes AMVIA different from other Sheffield IT companies? A: Security-first as a structure, not a slogan: every plan tier includes security, AMVIA holds Cyber Essentials Plus itself, and connectivity, phones and IT sit under one roof - so there's a single accountable party when something breaks. --- # Managed Cybersecurity Sheffield URL: https://amvia.co.uk/locations/sheffield/cybersecurity Last updated: 2026-08-28 AMVIA provides managed cybersecurity for Sheffield and South Yorkshire businesses - 24/7 threat monitoring, email security and endpoint protection - delivered remote-first from our Sheffield operations centre and UK SOC, with on-site support where it counts. One accountable provider, security-first, staffed by Microsoft-certified engineers. ## What cybersecurity does AMVIA provide for Sheffield businesses? We run a fully managed security service for Sheffield and the wider South Yorkshire area, covering threat detection, incident response and compliance support. Monitoring is continuous from our UK security operations centre; on-site assessments are arranged where the engagement needs them. Sheffield's economy spans advanced manufacturing, digital and creative industries, professional services and a large university sector - each carrying its own security obligations. Businesses across Sheffield, Rotherham and Barnsley are increasingly hit by opportunistic and supply-chain attacks, which is exactly where a single accountable provider earns its place. ## What is the cyber threat picture for South Yorkshire SMEs? The risk is not theoretical and it is not reserved for big names. UK government data shows breaches reach businesses of every size, and Sheffield's manufacturing and digital sectors are frequent targets because they sit inside larger supply chains. - 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months (DSIT 2025), per the Cyber Security Breaches Survey 2025. - 65% of medium businesses reported breaches or attacks (DSIT 2025/26). - 69% of large businesses reported breaches or attacks (DSIT 2025/26). - UK businesses lost £3.7bn to internet outages in 2023 (Beaming, 2023). The NCSC's small business guidance is clear that most attacks are untargeted and preventable with managed monitoring and good email hygiene - the two controls SMEs most often lack. ## What do you get with managed cybersecurity in Sheffield? A managed security service covering threat detection, compliance and ongoing protection for South Yorkshire businesses - built on Microsoft Defender and the Barracuda email and network suite, monitored around the clock. ## 24/7 SOC and managed detection Our UK SOC monitors client environments continuously using Microsoft Defender for Endpoint, providing managed detection and response. Threats are investigated and contained as part of the service - no manual escalation needed from your team. ## Email security and anti-phishing Phishing and spear-phishing remain the most common threat vector for SMEs. Our email security layer adds email authentication, attachment sandboxing and user-awareness tooling through the Barracuda suite. ## Remote-first, on-site where appropriate Monitoring and response run remotely from our UK SOC. On-site security assessments and incident support across Sheffield and South Yorkshire are arranged where the severity or the engagement calls for it. ## How much does managed cybersecurity in Sheffield cost? Fixed monthly per-user pricing, identical to AMVIA's UK-wide plans. No hidden charges, no per-incident surprises. The table below sets out the three tiers and what each one targets for response. | | Plan | From / User / Month | Response Target | Out-of-Hours | Essentials (Most Popular) | from £25.00 | Next business day | Email only | Advanced | from £40.00 | Same day (4hr target) | Phone & email | Enterprise | from £60.00 | 2-hour target | 24/7 dedicated ## What other services does AMVIA offer in Sheffield? Cybersecurity sits alongside the rest of AMVIA's stack, so Sheffield businesses can consolidate security, Microsoft 365 and connectivity under one provider with one bill and one point of accountability. - Managed cybersecurity - detection, response and compliance - Microsoft 365 security - hardening, MFA and Defender for Business - Managed IT support - helpdesk and infrastructure - Leased lines, business VoIP and business mobiles ## Frequently asked questions Q: Do you provide managed cybersecurity across South Yorkshire? A: Yes. AMVIA provides managed cybersecurity for businesses across South Yorkshire, including Sheffield, Rotherham, Barnsley and Doncaster. Monitoring and response are delivered remotely from our UK SOC on a 24/7 basis, with on-site security assessments and incident support arranged where appropriate for the engagement. Q: Can you respond to cybersecurity incidents in Sheffield? A: Yes. Incident detection and response are handled remotely by AMVIA's UK SOC as part of the managed service. Where an incident requires on-site attendance, a visit across Sheffield and South Yorkshire can be arranged and scheduled according to the severity of the incident and your plan tier. Q: Where is AMVIA based? A: AMVIA Limited is registered in England and Wales and runs a Sheffield operations centre and UK SOC. Managed cybersecurity is delivered UK-wide, remote-first, with on-site assessments and incident support arranged where appropriate. Q: Do small businesses in Sheffield really need managed cybersecurity? A: Yes. UK government data (DSIT 2025) shows breaches affect businesses of all sizes, and Sheffield's advanced manufacturing and digital sectors are frequently targeted. Many supply-chain contracts and procurement frameworks now require demonstrable security controls, which a managed service helps you put in place and evidence. Q: What security tooling does AMVIA use? A: AMVIA's managed security is built on Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus the Barracuda suite for email and network protection. AMVIA holds Cyber Essentials Plus, and our engineers are Microsoft-certified - one accountable provider, not a chain of vendors. --- # Managed IT Support Sheffield URL: https://amvia.co.uk/locations/sheffield/managed-it Last updated: 2026-09-02 AMVIA delivers fully managed IT support to Sheffield and South Yorkshire businesses: proactive 24/7 monitoring, an unlimited UK-based helpdesk, patching and clear SLAs, run remote-first from our Sheffield operations centre with on-site cover where it is needed. One provider, security-first, with Microsoft-certified engineers accountable for your whole IT estate. - 1,200+ UK businesses managed by AMVIA - Under one hour critical-issue remote response target - 24/7 monitoring and out-of-hours support available This is our managed IT support offer for Sheffield - the same fixed-price service we run UK-wide, delivered locally from South Yorkshire. ## What does AMVIA's managed IT support in Sheffield include? Managed IT support in Sheffield from AMVIA covers proactive monitoring, an unlimited UK-based helpdesk, patch management, and security built in from day one. We act as your single accountable provider, so one team owns your devices, your Microsoft 365 tenant, and your security posture - no finger-pointing between vendors. - Proactive protection: 24/7 monitoring and threat detection across endpoints and your Microsoft 365 tenant, backed by our in-house managed cybersecurity team. - Expert support: UK-based, Microsoft-certified engineers on an unlimited IT helpdesk - remote-first, with on-site attendance where remote fixes will not do. - Compliance support: practical guidance on Cyber Essentials Plus and data-protection obligations, mapped to how your business actually works. - Clear SLAs: defined response targets and transparent service-level agreements, so you know exactly what you have paid for. We are a security partner first, not a telecoms reseller - every managed IT plan is hardened from the start rather than bolted on later. ## How big is the UK managed IT market? The UK managed services sector is large and maturing, which matters when you are choosing who to trust with your whole IT estate. It is a crowded, mature market - which is exactly why provider selection and accountability are worth getting right. The lesson for a Sheffield MD is simple: there are thousands of providers, so judge them on accountability, security depth, and Microsoft certification - not on which one answers the phone fastest in a sales call. ## What cyber risks do Sheffield businesses face? Cyber risk is now an everyday operational problem for South Yorkshire businesses, not an edge case. The UK Government's Cyber Security Breaches Survey 2025 shows breaches remain common and that phishing is overwhelmingly the way in - which is why our managed IT is security-first rather than security-optional. - 85% of businesses that identified a breach pointed to phishing as the attack type (Cyber Security Breaches Survey 2025) - gov.uk - 65% of medium-sized businesses reported a cybersecurity breach or attack in the last 12 months (Cyber Security Breaches Survey 2025/26) - gov.uk The NCSC recommends layered controls - monitored endpoints, multi-factor authentication, and rapid patching - all of which are standard across AMVIA's managed IT and Microsoft 365 security plans. ## How much does managed IT support cost in Sheffield? Managed IT support in Sheffield uses the same fixed monthly per-user pricing as AMVIA's UK-wide plans, with no per-ticket fees and no hidden charges. You pick the response target your business needs; final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Core managed services | Advanced | from £40.00 | 4-hour target | Essentials + security | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Pricing is per user, billed monthly, and identical to our national rates - your Sheffield location does not change the price. ## How should a Sheffield business choose an IT support provider? Sheffield's options split three ways: national MSPs with no local presence, small local firms with two or three engineers, and providers in between. Brand names matter less than five tests that separate a provider you can hold accountable from one you can't: - Written SLAs with response targets - a number in a contract, not “we're usually quick”. Ask what happens when the target is missed. - Security depth in-house - who actually watches the alerts at 2am? A helpdesk that resells someone else's security tooling is a different product from a provider running its own monitoring. - Microsoft 365 competence you can verify - ask them to walk through your tenant's MFA coverage and admin roles in the first meeting. Certified engineers will; box-shifters won't. - A real switching process - documented onboarding, credential handover, and an exit clause that returns your documentation. If joining is easy but leaving is vague, that's deliberate. - Scale that matches yours - a two-person outfit can be excellent until its one senior engineer is on holiday during your outage. Ask about cover, not headcount. Apply the same tests to AMVIA - we publish our service-level agreements and our full managed IT service description precisely so you can. ## What does switching IT providers involve for a Sheffield business? Less than most MDs fear, if it's run properly. A competent incoming provider handles the outgoing one directly: credentials and admin access transfer under a documented checklist, monitoring agents swap over out of hours, and your team notices a new helpdesk number rather than an outage. The typical window from signed agreement to full handover is a few weeks, with both providers overlapping so nothing is unmanaged on any given day. Being Sheffield-based helps here - the hardware-touching parts of onboarding (network audit, device checks) happen on-site across South Yorkshire without waiting for a contractor. ## Which IT and security services does AMVIA offer in your area? AMVIA supports Sheffield and the wider South Yorkshire area with a full managed IT and security stack, all from a single accountable provider. Whether you need day-to-day support, tighter Microsoft 365 security, or faster connectivity, one team owns the outcome. - Managed IT support and unlimited helpdesk - Managed cybersecurity and 24/7 monitoring - Microsoft 365 security and hardening - Leased lines, business VoIP, and business mobiles ## Frequently asked questions Q: What do Sheffield businesses pay for managed IT? A: The standard AMVIA ladder - Essentials £25, Advanced £40, Enterprise £60 per user/month - with Sheffield getting the benefit of AMVIA's home-city operations centre for on-site work across South Yorkshire. Q: Is support delivered locally in Sheffield? A: Remote-first from the UK team for speed - most issues resolve fastest that way - with local on-site attendance across Sheffield, Rotherham, Barnsley and Doncaster when hardware or network jobs need it. Being Sheffield-based makes those visits easy. Q: What does 24/7 actually cover on each plan? A: Monitoring runs around the clock on every tier - problems are detected whenever they happen. Human response targets scale by plan, from next-business-day on Essentials to 2-hour targets and the 24/7 SOC on Enterprise. Q: Can you take on our Microsoft 365 mess? A: Almost certainly - untangling licensing, enforcing MFA properly and cleaning up admin sprawl is standard onboarding work. M365 administration is included in the plans, and a tenant audit early on shows exactly what needs fixing. Q: How quickly can AMVIA get an engineer on-site in Sheffield? A: Most issues resolve remotely from our Sheffield operations centre, which is faster than any van. Where hands-on work is genuinely needed - hardware, cabling, site moves - we attend on-site across Sheffield and South Yorkshire, typically next business day. Response targets are agreed in the SLA, not left to goodwill. Q: Who provides IT support in Sheffield? A: The Sheffield market has three tiers: national MSPs serving the city remotely, small local firms of a few engineers, and mid-sized providers in between - AMVIA sits in that middle tier, Sheffield-based with a UK-wide client base. There is no shortage of choice, so judge providers on written SLAs, in-house security capability and Microsoft certification rather than proximity alone. The right provider is the one you can hold accountable in a contract. Q: Do you support businesses outside Sheffield and South Yorkshire? A: Yes - AMVIA supports businesses UK-wide with the same plans and pricing; support is remote-first, so distance changes nothing about response times. Sheffield is home: our operations centre is here, which is why on-site attendance across Sheffield, Rotherham, Barnsley and Doncaster is straightforward, and why South Yorkshire businesses get the shortest travel times for hardware and network work. Q: Can AMVIA help Sheffield businesses get Cyber Essentials certified? A: Yes - preparing businesses for Cyber Essentials and Cyber Essentials Plus is standard work for our security team, and the technical controls the scheme requires (MFA, patching, access control, malware protection) are the same ones a managed IT plan enforces day to day. Our Cyber Essentials guide and free certification checker are linked in the resources below. --- # Business Leased Lines Sheffield: Compare Costs & Providers URL: https://amvia.co.uk/locations/sheffield/leased-lines Last updated: 2026-08-28 AMVIA provides fully managed business leased lines for Sheffield companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare every carrier at your exact address, then manage installation and faults end to end as one security-first, Microsoft-certified provider. 1,200+ UK businesses managed by AMVIA · critical-issue remote response · 24/7 monitoring and support ## What is a leased line, and why do Sheffield businesses choose one? A leased line is a dedicated fibre circuit reserved for your business alone, so your bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business leased lines marketed as "broadband" cannot match. For Sheffield firms running cloud apps, VoIP, and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Full-fibre availability across the UK reached 78% of premises in Q3 2025 (Ofcom Connected Nations 2025), and gigabit-capable coverage hit 87%, up from 84% in 2024 - but coverage is not the same as a guaranteed, managed circuit. | | Feature | Leased line | Standard broadband | Bandwidth | Dedicated, uncontended | Shared / contended | Speeds | Symmetric (equal up/down) | Asymmetric | SLA | Yes - typically 99.99% uptime | Best-effort, no guarantee | Fault fix | Defined response target | No formal target If your priority is resilience and security rather than headline price, a dedicated internet access circuit is the right starting point. ## What does AMVIA's managed leased line service include in Sheffield? Every Sheffield leased line comes fully managed: AMVIA compares carrier availability at your address, handles provisioning, and owns fault resolution directly with the underlying network. You get one accountable provider for connectivity and security, not a reseller passing tickets up a chain. - Carrier comparison across BT Openreach, CityFibre, and Virgin Media Business at your exact postcode - End-to-end installation management - wayleaves, surveys, and handover - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - UK-based qualified engineers - no offshore first line - Security-first design - links into leased line security and Cyber Essentials Plus practices - Multi-site ready for firms connecting more than one Sheffield or regional office via multi-site connectivity Openreach had passed more than 20m premises with FTTP by September 2025, widening the addresses where a competitively priced circuit is achievable - but the right carrier still depends entirely on your specific location. ## How much does a leased line cost in Sheffield? Leased line pricing depends on speed, address, and carrier reach. In well-served Sheffield postcodes, circuits start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - see the 100Mbps, 1Gbps and 10Gbps cost guides for full regional ranges. | | Speed | From / month | Best suited to | 100 Mbps | from £69.00 | Small-to-mid offices, 25–50 staff | 1 Gbps (most popular) | from £129.00 | Cloud-heavy SMEs, multi-team sites | 10 Gbps | from £349.00 | Data-intensive or multi-site aggregation Your exact circuit price is quoted per address once we confirm carrier availability. We give you the real installed cost before you commit - no estimate-then-escalate. ## How long does leased line installation take in Sheffield? In Sheffield's S1–S5 on-net postcodes, provisioning typically takes 30–60 working days. For off-net addresses in outer Sheffield or the surrounding area, expect 60–90 working days, depending on distance from the nearest carrier point of presence and any wayleave requirements. AMVIA manages this timeline for you across Sheffield, Rotherham, Barnsley, and Doncaster - chasing the carrier, coordinating surveys, and keeping you informed at each milestone rather than leaving you to interpret Openreach updates. ## Which other services can Sheffield businesses bundle with a leased line? Most Sheffield clients run their leased line alongside other AMVIA services so one provider owns the whole stack. That simplifies fault resolution and guarantees your phones and apps have the bandwidth they need. - Business VoIP phone systems that depend on your circuit's uncontended capacity - Managed IT support for day-to-day helpdesk and infrastructure - Microsoft 365 Security and managed cybersecurity, delivered security-first This is the AMVIA model: one provider, security-first, Microsoft-certified - connectivity, telephony, and IT under a single SLA. ## Frequently asked questions Q: Do you install leased lines across South Yorkshire? A: Yes. AMVIA provisions and manages leased lines across Sheffield, Rotherham, Barnsley, and Doncaster. We compare carrier availability at your specific address across BT Openreach, CityFibre, and Virgin Media Business, then manage the full installation end to end. Q: How long does a leased line take to install in Sheffield? A: In Sheffield's S1–S5 on-net postcodes, provisioning typically takes 30–60 working days. For off-net addresses in outer Sheffield or the surrounding area, 60–90 working days is more typical, depending on distance from the nearest carrier point of presence and any wayleave requirements. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Do you serve businesses across Sheffield's business districts? A: Yes. AMVIA manages leased line connections across Sheffield city centre and the S1–S14 postcode areas, including the main business parks. We compare carrier availability at your address and manage provisioning and fault resolution end to end, working directly with the underlying carriers. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Sheffield? A: Yes. AMVIA provides leased lines, VoIP phone systems, and managed IT support as an integrated package. Running connectivity, telephony, and IT through a single provider simplifies fault resolution and ensures your VoIP system has the underlying bandwidth it needs to perform reliably. Q: Where can I check Sheffield broadband and fibre coverage? A: Ofcom publishes independent UK fibre and gigabit coverage data in its Connected Nations reports, and the NCSC small business guide covers securing the connection once it is live. AMVIA confirms the exact carriers and speeds available at your specific Sheffield address before you commit. --- # Business Leased Lines Birmingham: Compare Costs & Providers URL: https://amvia.co.uk/locations/birmingham/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Birmingham companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, CityFibre, Virgin Media Business, Zayo and Colt at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Birmingham businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Birmingham network picture Birmingham businesses are spoilt for network choice by UK standards. CityFibre's metro fibre runs through much of the city, Virgin Media Business and Openreach cover the wider West Midlands, and enterprise carriers Zayo and Colt serve the core business districts. That competition is why like-for-like quotes vary so much here - the carrier with fibre in your street wins on both price and install time, whether you're in Digbeth, Aston, the Jewellery Quarter or out towards the business parks. AMVIA compares all of them for your exact address rather than defaulting to one network's rate card. ## How much does a leased line cost in Birmingham? In well-served Birmingham postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Birmingham? - Carrier comparison across BT Openreach, CityFibre, Virgin Media Business, Zayo and Colt at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Birmingham clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Birmingham? A: Birmingham is served by multiple competing networks: CityFibre's metro fibre, Virgin Media Business, the BT Openreach footprint, and enterprise carriers Zayo and Colt in the core business districts. Which one is cheapest and fastest to install depends on which network's fibre runs closest to your building - AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across the West Midlands? A: Yes. AMVIA provisions and manages leased lines across Birmingham and the wider West Midlands - from the city core, Digbeth, Aston and the Jewellery Quarter to the surrounding business parks. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Birmingham? A: Leased lines in well-served Birmingham postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Because Birmingham has competing networks, comparing all of them routinely beats a single provider's quote. Q: How long does a leased line take to install in Birmingham? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Birmingham? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Manchester: Compare Costs & Providers URL: https://amvia.co.uk/locations/manchester/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Manchester companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, CityFibre, Virgin Media Business and Zayo at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Manchester businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Manchester network picture Manchester's digital economy has pulled serious network investment into the city: CityFibre and Zayo fibre runs alongside Virgin Media Business and the Openreach footprint, and the Salford/MediaCity corridor is one of the best-connected business locations outside London. For media, tech and professional firms moving large files or running production workloads, that competition translates into sharp gigabit pricing - where your building sits relative to each network decides who wins. AMVIA compares every carrier for your exact Manchester address before you commit. ## How much does a leased line cost in Manchester? In well-served Manchester postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Manchester? - Carrier comparison across BT Openreach, CityFibre, Virgin Media Business and Zayo at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Manchester clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Manchester? A: Manchester is served by CityFibre, Zayo, Virgin Media Business and the BT Openreach footprint, with the Salford and MediaCity corridor particularly well connected. The cheapest, fastest-to-install option depends on which network's fibre runs closest to your premises - AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across Greater Manchester? A: Yes. AMVIA provisions and manages leased lines across Manchester and Greater Manchester - the city centre, Salford, MediaCity and the surrounding boroughs. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Manchester? A: Leased lines in well-served Manchester postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Because Manchester has competing networks, comparing all of them routinely beats a single provider's quote. Q: How long does a leased line take to install in Manchester? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Manchester? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Glasgow: Compare Costs & Providers URL: https://amvia.co.uk/locations/glasgow/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Glasgow companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, CityFibre and Virgin Media Business at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Glasgow businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Glasgow network picture Glasgow is one of Scotland's most competitive connectivity markets. CityFibre has invested heavily in its Glasgow network, Virgin Media Business covers much of the city, and the Openreach footprint reaches everywhere else - which means most Glasgow postcodes have a genuine three-way comparison available. For businesses used to a single BT quote, that competition is worth real money on a like-for-like circuit. AMVIA compares every carrier at your exact Glasgow address and manages installation and faults end to end. ## How much does a leased line cost in Glasgow? In well-served Glasgow postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Glasgow? - Carrier comparison across BT Openreach, CityFibre and Virgin Media Business at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Glasgow clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Glasgow? A: Glasgow is served by CityFibre's expanding Scottish network, Virgin Media Business, and the BT Openreach footprint - most city postcodes have a genuine multi-carrier choice. Which is cheapest depends on whose fibre runs closest to your building; AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across the west of Scotland? A: Yes. AMVIA provisions and manages leased lines across Glasgow and the west of Scotland. We compare carrier availability at your specific address across CityFibre, Virgin Media Business and Openreach, then manage the full installation end to end. Q: How much does a leased line cost in Glasgow? A: Leased lines in well-served Glasgow postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Because Glasgow has competing networks, comparing all of them routinely beats a single provider's quote. Q: How long does a leased line take to install in Glasgow? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Glasgow? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines London: Compare Costs & Providers URL: https://amvia.co.uk/locations/london/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for London companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, CityFibre, Virgin Media Business, Community Fibre and Hyperoptic at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do London businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The London network picture No UK city has more network choice than London. Beyond the Openreach footprint and Virgin Media Business, the capital carries dense alt-net fibre - Community Fibre, Hyperoptic and CityFibre among them - plus enterprise metro networks serving the City, Canary Wharf and Shoreditch. That density is why London consistently sees the sharpest leased line pricing in the country, and also why single-provider quotes are least defensible here: at most central postcodes, four or more networks genuinely compete for your circuit. AMVIA compares all of them for your exact London address. ## How much does a leased line cost in London? In well-served London postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in London? - Carrier comparison across BT Openreach, CityFibre, Virgin Media Business, Community Fibre and Hyperoptic at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most London clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in London? A: London has the densest business fibre in the UK: the Openreach footprint, Virgin Media Business, CityFibre, and alt-nets including Community Fibre and Hyperoptic, plus enterprise metro networks in the City and Canary Wharf. At most central postcodes several networks genuinely compete - AMVIA compares all of them for your exact address. Q: Do you cover businesses across Greater London? A: Yes. AMVIA provisions and manages leased lines across Greater London - the City, Canary Wharf, Shoreditch, the West End and the wider boroughs. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in London? A: Leased lines in well-served London postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Because London has competing networks, comparing all of them routinely beats a single provider's quote. Q: How long does a leased line take to install in London? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in London? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Liverpool: Compare Costs & Providers URL: https://amvia.co.uk/locations/liverpool/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Liverpool companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, Virgin Media Business and the LCR Connect full-fibre network at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Liverpool businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Liverpool network picture Liverpool's connectivity story is unusual: LCR Connect - the publicly backed full-fibre network built across the Liverpool City Region - runs alongside the Openreach footprint and Virgin Media Business, extending competitive fibre into Knowsley, Sefton and Wirral as well as the city itself. For businesses across the region, that means genuine carrier choice in areas that would otherwise be single-network territory. AMVIA compares every route for your exact address - including LCR Connect where it serves your postcode - and manages installation and faults end to end. ## How much does a leased line cost in Liverpool? In well-served Liverpool postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Liverpool? - Carrier comparison across BT Openreach, Virgin Media Business and the LCR Connect full-fibre network at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Liverpool clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Liverpool? A: Liverpool is served by the Openreach footprint, Virgin Media Business, and LCR Connect - the Liverpool City Region's publicly backed full-fibre network, which extends competitive fibre into Knowsley, Sefton and Wirral. AMVIA checks every route for your exact postcode, including LCR Connect where available. Q: Do you cover businesses across the Liverpool City Region? A: Yes. AMVIA provisions and manages leased lines across Liverpool and the wider City Region - including Knowsley, Sefton and Wirral. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Liverpool? A: Leased lines in well-served Liverpool postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Because Liverpool has competing networks, comparing all of them routinely beats a single provider's quote. Q: How long does a leased line take to install in Liverpool? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Liverpool? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Managed IT Support and Cybersecurity Coventry URL: https://amvia.co.uk/locations/coventry Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Coventry and Warwickshire businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable contract. Support is remote-first with on-site attendance across the CV postcode areas when an issue needs hands on hardware. One provider, security-first. At a glance: - 1,200+ UK businesses managed by AMVIA - Under 1hr remote response target on critical issues - 24/7 monitoring and support ## What IT support does AMVIA provide in Coventry? AMVIA runs a full managed IT desk for Coventry firms: a UK-based helpdesk, proactive monitoring and patching, Microsoft 365 management, and security baked into every plan rather than sold as an afterthought. We support businesses across Coventry and Warwickshire - the city core, Canley, Tile Hill, Longford, and the Westwood, Middlemarch and A45 business parks. Coventry's economy spans manufacturing, logistics, professional services and education, and each carries specific uptime and data-handling obligations. Our engineers are Microsoft-certified and our plans are designed so one provider owns connectivity, devices and security - no finger-pointing between vendors when something breaks. ## Why do Coventry businesses need managed cybersecurity? Cyber risk is now a board-level operating cost, not an IT line item. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the prior 12 months (DSIT, Cyber Security Breaches Survey 2025), which makes monitoring and response a baseline requirement rather than a nice-to-have. AMVIA holds Cyber Essentials Plus and builds every Advanced and Enterprise plan around Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus the Barracuda email and network security suite - delivered as practitioner guidance for firms working toward sector frameworks. ## What managed services can Coventry businesses get from AMVIA? Every service below is available on its own or as one integrated managed contract. The advantage of a single provider is a single accountable point of contact for connectivity, phones, devices and security. | | Service | What it covers | Where it links | Managed cybersecurity | 24/7 SOC monitoring, endpoint protection, email security, incident response | /cybersecurity | Microsoft 365 security | Migration, hardening, MFA, ongoing admin | /microsoft-365-security | Leased lines | Dedicated business internet - Openreach, Virgin and CityFibre compared across Coventry | Coventry leased lines | Business VoIP | Cloud phone systems with Coventry numbers, mobile apps and Teams integration | /business-voip | Business mobiles | Managed business mobile contracts and device security | /business-mobiles ## How much does IT support cost for a Coventry business? AMVIA uses fixed monthly per-user pricing - the same as our UK-wide plans, with no per-ticket fees or hidden charges. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC ## Which areas does AMVIA cover around Coventry? AMVIA serves businesses across Coventry and Warwickshire, delivered remote-first across the CV postcode areas with on-site visits scheduled by priority and plan when an issue needs an engineer on the ground. Remote-first does not mean remote-only: for server moves, network faults or new-office fit-outs, we attend in person across the region. ## Frequently asked questions Q: Which areas around Coventry does AMVIA cover? A: AMVIA serves businesses across Coventry and Warwickshire - the city centre and ring-road corridor, Canley, Tile Hill, Longford, and the main business parks including Westwood, Middlemarch and sites along the A45 corridor. Support is remote-first across the CV postcode areas, with on-site visits scheduled by priority and plan. Q: Do you support manufacturing and logistics businesses? A: Yes - Coventry's manufacturing and logistics base is a core part of the local economy, and these environments carry specific requirements: production systems that cannot tolerate downtime, warehouse management platforms, OT alongside IT, and shift patterns that need support beyond office hours. AMVIA's 24/7 monitoring and defined response targets are built for exactly this. Q: Can AMVIA provide connectivity as well as IT support in Coventry? A: Yes. AMVIA compares Openreach, Virgin Media Business, CityFibre and other alt-net routes for your exact Coventry postcode and manages leased line installation end to end - see our dedicated Coventry leased lines page. Running connectivity, telephony and IT through one provider means a single accountable SLA. Q: Is support remote or on-site? A: Remote-first, on-site when it matters. Most issues resolve fastest remotely - our critical-issue remote response target is under one hour. For server moves, network faults or new-office fit-outs across Coventry and Warwickshire, we attend in person, scheduled by priority and plan. Q: How much does managed IT support cost in Coventry? A: AMVIA uses fixed monthly per-user pricing, the same as our UK-wide plans: Essentials from £25, Advanced from £40, and Enterprise from £60 per user per month. Final pricing depends on user count and scope - request a quote for an exact figure. --- # Managed IT Support and Cybersecurity Newcastle URL: https://amvia.co.uk/locations/newcastle Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Tyneside and the North East businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the NE and SR postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Newcastle IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Newcastle businesses actually operate Newcastle's economy runs on professional services, a fast-growing digital and tech scene, the universities and the public sector. What that means practically: connectivity quoted per exact address across every carrier with fibre near your building, security monitored around the clock rather than reviewed quarterly, and support that resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Tyneside and the North East firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Newcastle? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Newcastle businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Newcastle? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the NE and SR postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas of the North East does AMVIA serve? A: AMVIA serves businesses across Newcastle, Gateshead and Sunderland, covering the NE and SR postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Newcastle business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Newcastle business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Managed IT Support and Cybersecurity Leicester URL: https://amvia.co.uk/locations/leicester Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Leicestershire businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the LE postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Leicester IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Leicester businesses actually operate Leicester's economy runs on manufacturing, textiles and food production alongside the logistics operations of the East Midlands distribution corridor. What that means practically: connectivity quoted per exact address across every carrier with fibre near your building, security monitored around the clock rather than reviewed quarterly, and support that resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Leicestershire firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Leicester? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Leicester businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Leicester? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the LE postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas of Leicestershire does AMVIA serve? A: AMVIA serves businesses across Leicester, Loughborough and the county distribution corridor, covering the LE postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Leicester business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Leicester business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Managed IT Support and Cybersecurity Southampton URL: https://amvia.co.uk/locations/southampton Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Hampshire and the South Coast businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the SO postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Southampton IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Southampton businesses actually operate Southampton's economy runs on the port and maritime sector, logistics, and the professional and university presence around the Solent. What that means practically: connectivity quoted per exact address across every carrier with fibre near your building, security monitored around the clock rather than reviewed quarterly, and support that resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Hampshire and the South Coast firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Southampton? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Southampton businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Southampton? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the SO postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas of Hampshire does AMVIA serve? A: AMVIA serves businesses across Southampton, Eastleigh and the Solent business parks, covering the SO postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Southampton business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Southampton business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Managed IT Support and Cybersecurity Aberdeen URL: https://amvia.co.uk/locations/aberdeen Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Aberdeen and the North East of Scotland businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the AB postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Aberdeen IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Aberdeen businesses actually operate Aberdeen's economy - the energy sector and North Sea services alongside professional services and the universities - runs on connectivity that holds up around the clock. Aberdeen is one of the Scottish cities in CityFibre's full fibre build, so alongside the national Openreach footprint many postcodes have a genuine second physical network - with the competition on price and infrastructure that brings. Coverage is street-by-street - which makes Aberdeen a market where comparing carriers per address genuinely pays. Security is monitored around the clock rather than reviewed quarterly, and support resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Aberdeen and the North East of Scotland firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Aberdeen? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Aberdeen businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Aberdeen? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the AB postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas of the North East of Scotland does AMVIA serve? A: AMVIA serves businesses across Aberdeen and Aberdeenshire, covering the AB postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building, including CityFibre's build here - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Aberdeen business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Aberdeen business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Managed IT Support and Cybersecurity Milton Keynes URL: https://amvia.co.uk/locations/milton-keynes Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Milton Keynes and Buckinghamshire businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the MK postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Milton Keynes IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Milton Keynes businesses actually operate Milton Keynes' economy - logistics and distribution, technology firms and national head-office operations across its planned business districts - depends on connectivity as deliberate as the city's grid. CityFibre's investment has produced a wide full fibre footprint across Milton Keynes' commercial areas, business parks and central districts, running alongside the national Openreach network - real choice on price, speed and provider for most MK businesses - which makes Milton Keynes a market where comparing carriers per address genuinely pays. Security is monitored around the clock rather than reviewed quarterly, and support resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Milton Keynes and Buckinghamshire firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Milton Keynes? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Milton Keynes businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Milton Keynes? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the MK postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas around Milton Keynes does AMVIA serve? A: AMVIA serves businesses across Milton Keynes, Bletchley and the surrounding business parks, covering the MK postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building, including CityFibre's build here - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Milton Keynes business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Milton Keynes business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Managed IT Support and Cybersecurity Peterborough URL: https://amvia.co.uk/locations/peterborough Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Peterborough and Cambridgeshire businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable provider with one SLA. Remote-first delivery with on-site attendance across the PE postcodes: managed IT from £25/user/month, dedicated leased lines from £69/month, VoIP from £5.95/user/month. ## One provider for Peterborough IT, connectivity and security Most business IT problems live in the gaps between suppliers: the ISP blames the phone platform, the IT company blames the circuit, and nobody owns the fix. AMVIA's model removes the gaps - managed IT support, managed cybersecurity, dedicated leased lines, business broadband and business VoIP under one SLA, one account team and one number to call. ## Built around how Peterborough businesses actually operate Peterborough's economy - distribution and logistics, financial services operations and manufacturing - runs on links that have to move data as dependably as its warehouses move goods. Peterborough is one of the UK cities where CityFibre has invested heavily, with full fibre coverage across the city centre, established commercial areas and the main business parks - a genuine gigabit-capable alternative running alongside the national Openreach footprint - which makes Peterborough a market where comparing carriers per address genuinely pays. Security is monitored around the clock rather than reviewed quarterly, and support resolves most issues remotely with a AMVIA publishes its pricing: managed IT support runs £25–£60/user/month by service level, dedicated leased lines start from £69/month (100Mbps) and £129/month (1Gbps), business VoIP from £5.95/user/month and full-fibre broadband from £29/month. Your exact connectivity price depends on your postcode - start with a multi-carrier quote and tailored pricing typically lands within 24 hours. ## Security-first, certified AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner - the same engineers who run your Microsoft 365 estate monitor it for threats. For Peterborough and Cambridgeshire firms facing cyber-insurance questionnaires or supply-chain security requirements, that turns compliance evidence from a scramble into paperwork we already hold. Start with a free security audit to see your current exposure. ## Frequently asked questions Q: What IT services does AMVIA provide in Peterborough? A: The full stack: managed IT support from £25/user/month, managed cybersecurity with 24/7 monitoring, dedicated leased lines from £69/month, full-fibre business broadband, business VoIP from £5.95/user/month, business mobiles and Microsoft 365 management. Peterborough businesses run all of it under one SLA with one provider accountable end to end. Q: Does AMVIA have engineers in Peterborough? A: AMVIA is a Sheffield-headquartered provider serving the whole UK on a remote-first model, with on-site attendance arranged across the PE postcodes when hands-on work is needed. Most day-to-day support - monitoring, helpdesk, security response - is delivered remotely with a <1hr critical response commitment, which is faster than waiting for any engineer to drive to you. Q: Which areas around Peterborough does AMVIA serve? A: AMVIA serves businesses across Peterborough and the surrounding commercial areas, covering the PE postcodes. Connectivity is quoted per exact address - we compare every carrier with fibre near your building, including CityFibre's build here - and IT support and security are delivered UK-wide on the same remote-first model. Q: How quickly can AMVIA take over IT support for a Peterborough business? A: A typical onboarding runs two to four weeks: an audit of your current environment, documentation, security baseline (MFA, endpoint protection, backup checks), then a cutover date with your outgoing provider. Connectivity, if you're switching circuits, runs on its own 30–90 working day installation track alongside - we manage both so there's no gap. Q: Can AMVIA take on just one service for our Peterborough business, like connectivity or security? A: Yes - plenty of clients start with a single leased line, a VoIP migration or a security review, keeping their existing IT arrangements. The advantage of the model is the option: because AMVIA runs the full stack, you can consolidate later at your own pace rather than being sold everything on day one. --- # Business Leased Lines Leeds: Compare Costs & Providers URL: https://amvia.co.uk/locations/leeds/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Leeds companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, Virgin Media Business and CityFibre (which lists Leeds among its build cities) at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Leeds businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Leeds network picture Leeds' business core - financial services, legal and professional firms with regulatory data-handling and uptime obligations - is exactly the profile that outgrows contended broadband first. The network picture is competitive: CityFibre lists Leeds among its full-fibre build cities, Virgin Media Business covers much of the city, and the Openreach footprint reaches everywhere else, so most commercial postcodes across Leeds, Bradford, Wakefield and Huddersfield have a genuine multi-carrier comparison available. Availability is street-by-street - the carrier with fibre nearest your building wins on price and install time. ## How much does a leased line cost in Leeds? In well-served Leeds postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Leeds? - Carrier comparison across BT Openreach, Virgin Media Business and CityFibre (which lists Leeds among its build cities) at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Leeds clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Leeds? A: Leeds is served by the national BT Openreach footprint, Virgin Media Business, and CityFibre - which lists Leeds among its full-fibre build cities. Coverage is street-by-street, so which carrier is cheapest and fastest to install depends on whose fibre runs closest to your building. AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across West Yorkshire? A: Yes. AMVIA provisions and manages leased lines across Leeds and West Yorkshire - including Bradford, Wakefield, Huddersfield and Harrogate, across the LS, BD, WF and HG postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Leeds? A: Leased lines in well-served Leeds postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Leeds? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Leeds? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Bristol: Compare Costs & Providers URL: https://amvia.co.uk/locations/bristol/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Bristol companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, Virgin Media Business and CityFibre at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Bristol businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Bristol network picture Bristol's tech and creative sector - one of the UK's strongest outside London - generates exactly the workloads that justify dedicated fibre: studios moving large media files, SaaS teams with uptime commitments, agencies running everything in the cloud. The network picture is strong: the CityFibre and Openreach footprints are expanding across Temple Quarter (BS1) and the surrounding tech corridor, and Virgin Media Business covers much of the wider city and into Bath. As everywhere, availability is street-by-street - comparing every carrier for your exact BS or BA postcode is the difference between the £129 end of gigabit pricing and paying a coverage premium you don't need to. ## How much does a leased line cost in Bristol? In well-served Bristol postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Bristol? - Carrier comparison across BT Openreach, Virgin Media Business and CityFibre at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Bristol clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Bristol? A: Bristol is served by the CityFibre and Openreach footprints - both expanding across Temple Quarter (BS1) and the surrounding tech corridor - plus Virgin Media Business across the wider city. Which carrier wins for your building depends on whose fibre runs closest; AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across the West of England? A: Yes. AMVIA provisions and manages leased lines across Bristol and the West of England - including Bath, Weston-super-Mare and South Gloucestershire, across the BS and BA postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Bristol? A: Leased lines in well-served Bristol postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Bristol? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Bristol? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Edinburgh: Compare Costs & Providers URL: https://amvia.co.uk/locations/edinburgh/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Edinburgh companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach and CityFibre (Edinburgh has one of the more developed CityFibre footprints in the UK), plus Virgin Media Business at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Edinburgh businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Edinburgh network picture Edinburgh's connectivity market has a genuine structural advantage: one of the more developed CityFibre footprints in the UK runs alongside BT Openreach full fibre in many postcodes, so a real dual-network comparison is available across the city centre (EH1–EH3), Leith and the waterfront, Haymarket and west Edinburgh, and the Lothian Road corridor - plus the peripheral business parks. Two networks bidding for the same circuit is precisely what pulls pricing toward the £129 gigabit floor. AMVIA compares both routes (and Virgin Media Business where present) for your exact address. ## How much does a leased line cost in Edinburgh? In well-served Edinburgh postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Edinburgh? - Carrier comparison across BT Openreach and CityFibre (Edinburgh has one of the more developed CityFibre footprints in the UK), plus Virgin Media Business at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Edinburgh clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Edinburgh? A: Edinburgh has one of the more developed CityFibre footprints in the UK, running alongside BT Openreach full fibre in many postcodes - from the city centre (EH1–EH3) to Leith, Haymarket and the Lothian Road corridor. That dual-network competition is good news for pricing. AMVIA compares both routes, plus Virgin Media Business where present, for your exact postcode. Q: Do you cover businesses across Edinburgh and the Lothians? A: Yes. AMVIA provisions and manages leased lines across Edinburgh and the Lothians - the city centre, Leith and the waterfront, west Edinburgh and the surrounding business parks. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Edinburgh? A: Leased lines in well-served Edinburgh postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Edinburgh? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Edinburgh? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Cardiff: Compare Costs & Providers URL: https://amvia.co.uk/locations/cardiff/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Cardiff companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach, Virgin Media Business and CityFibre (which lists Cardiff and Newport among its build cities) at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Cardiff businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Cardiff network picture Cardiff anchors South Wales' business corridor, with Newport and Swansea completing a market that carriers have invested in: CityFibre lists Cardiff and Newport among its full-fibre build cities, Virgin Media Business covers much of the region, and the Openreach footprint reaches everywhere else. For firms across the CF and SA postcode areas that means a genuine multi-carrier comparison at most commercial addresses - and street-by-street availability, so the winning carrier two streets away may not be the winner at yours. AMVIA compares every route for your exact address. ## How much does a leased line cost in Cardiff? In well-served Cardiff postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Cardiff? - Carrier comparison across BT Openreach, Virgin Media Business and CityFibre (which lists Cardiff and Newport among its build cities) at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Cardiff clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Cardiff? A: Cardiff is served by the national BT Openreach footprint, Virgin Media Business, and CityFibre - which lists Cardiff and Newport among its full-fibre build cities. Which carrier is cheapest for your building depends on whose fibre runs closest; AMVIA checks all of them for your exact postcode. Q: Do you cover businesses across South Wales? A: Yes. AMVIA provisions and manages leased lines across Cardiff and South Wales - including Newport and Swansea, across the CF and SA postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Cardiff? A: Leased lines in well-served Cardiff postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Cardiff? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Cardiff? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Nottingham: Compare Costs & Providers URL: https://amvia.co.uk/locations/nottingham/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Nottingham companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Nottingham businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Nottingham network picture Nottingham, Derby and Leicester form the East Midlands business triangle, and connectivity across it follows the national pattern: the Openreach footprint reaches every commercial postcode, while Virgin Media Business and a growing number of alt-net fibre builds add competition where their networks serve your address. Availability genuinely varies street by street - which is why we don't promise a specific carrier here, we check them all. The practical consequence for NG, DE and LE businesses: a multi-carrier availability check frequently surfaces a sharper quote than the incumbent renewal, and always surfaces construction charges before you sign. ## How much does a leased line cost in Nottingham? In well-served Nottingham postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Nottingham? - Carrier comparison across the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Nottingham clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Nottingham? A: Nottingham is reached by the national BT Openreach footprint at effectively every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. Availability varies street by street, so AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across the East Midlands? A: Yes. AMVIA provisions and manages leased lines across the East Midlands - Nottingham, Derby and Leicester, covering the NG, DE and LE postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Nottingham? A: Leased lines in well-served Nottingham postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Nottingham? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Nottingham? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines York: Compare Costs & Providers URL: https://amvia.co.uk/locations/york/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for York companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do York businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The York network picture York's economy - heritage and tourism operators alongside a growing tech and professional scene - depends on connectivity that doesn't wobble in peak season. The network picture follows the national pattern: the Openreach footprint reaches every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. One York-specific note: historic city-centre buildings can add wayleave and installation complexity, which makes the site survey and a carrier-by-carrier availability check more valuable here than in most cities - construction charges surface before you sign, not after. ## How much does a leased line cost in York? In well-served York postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in York? - Carrier comparison across the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most York clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in York? A: York is reached by the national BT Openreach footprint at effectively every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across North Yorkshire? A: Yes. AMVIA provisions and manages leased lines across North Yorkshire - York, Harrogate and Scarborough, covering the YO and HG postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in York? A: Leased lines in well-served York postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in York? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in York? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Coventry: Compare Costs & Providers URL: https://amvia.co.uk/locations/coventry/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Coventry companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare BT Openreach (via resellers), Virgin Media Business, CityFibre and a growing number of alt-nets at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Coventry businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Coventry network picture Coventry's economy - manufacturing and logistics operations alongside professional services and two universities - generates connectivity requirements that contended broadband can't carry: production systems, warehouse management, and campus-scale traffic. The network picture is genuinely competitive: Openreach (via resellers), Virgin Media Business, CityFibre and a growing number of alt-nets run West Midlands metro fibre across the city, from the ring-road corridor to Canley, Tile Hill and Longford, and out to Westwood Business Park, Middlemarch Business Park and sites along the A45 corridor. AMVIA compares every route for your exact address and manages installation end to end. ## How much does a leased line cost in Coventry? In well-served Coventry postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Coventry? - Carrier comparison across BT Openreach (via resellers), Virgin Media Business, CityFibre and a growing number of alt-nets at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Coventry clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Coventry? A: Coventry is served by BT Openreach (via resellers), Virgin Media Business, CityFibre and a growing number of alt-nets running West Midlands metro fibre. Coverage reaches the main business parks - Westwood, Middlemarch and the A45 corridor - as well as the city core. AMVIA checks every route for your exact postcode. Q: Do you cover businesses across Coventry and Warwickshire? A: Yes. AMVIA provisions and manages leased lines across Coventry and the West Midlands - the city centre and ring-road corridor, Canley, Tile Hill, Longford, and the Westwood, Middlemarch and A45 business parks. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Coventry? A: Leased lines in well-served Coventry postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Coventry? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Coventry? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Newcastle: Compare Costs & Providers URL: https://amvia.co.uk/locations/newcastle/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Newcastle companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Newcastle businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Newcastle network picture Newcastle's economy - professional services and a fast-growing digital and tech scene alongside the universities and public sector - runs on connectivity that holds up all day. The network picture follows the national pattern: the Openreach footprint reaches every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. One Newcastle-specific note: Quayside and city-centre offices sit alongside business parks spread across Tyneside, so carrier availability genuinely varies by address - the multi-carrier check matters more than any coverage map. ## How much does a leased line cost in Newcastle? In well-served Newcastle postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Newcastle? - Carrier comparison across the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Newcastle clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Newcastle? A: Newcastle is reached by the national BT Openreach footprint at effectively every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across Tyneside and the North East? A: Yes. AMVIA provisions and manages leased lines across Tyneside and the North East - Newcastle, Gateshead and Sunderland, covering the NE and SR postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Newcastle? A: Leased lines in well-served Newcastle postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Newcastle? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Newcastle buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Newcastle? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Newcastle businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Leicester: Compare Costs & Providers URL: https://amvia.co.uk/locations/leicester/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Leicester companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Leicester businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Leicester network picture Leicester's economy - manufacturing, textiles and food production alongside the logistics operations drawn to the East Midlands distribution corridor - depends on links that move data as reliably as goods. The network picture follows the national pattern: the Openreach footprint reaches every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. One Leicester-specific note: Distribution parks and manufacturing units on the city's edge often sit further from existing carrier fibre than city-centre offices, which makes the site survey and construction-charge check especially worthwhile here. ## How much does a leased line cost in Leicester? In well-served Leicester postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Leicester? - Carrier comparison across the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Leicester clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Leicester? A: Leicester is reached by the national BT Openreach footprint at effectively every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across Leicestershire? A: Yes. AMVIA provisions and manages leased lines across Leicestershire - Leicester, Loughborough and the county's distribution corridor, covering the LE postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Leicester? A: Leased lines in well-served Leicester postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Leicester? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Leicester buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Leicester? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Leicester businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Southampton: Compare Costs & Providers URL: https://amvia.co.uk/locations/southampton/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Southampton companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Southampton businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Southampton network picture Southampton's economy - the port and maritime sector, logistics, and the professional and university presence around the Solent - includes operations that simply cannot go offline. The network picture follows the national pattern: the Openreach footprint reaches every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. One Southampton-specific note: Port-adjacent and maritime operations often run around the clock, which puts a premium on SLA repair terms and failover design rather than headline price alone. ## How much does a leased line cost in Southampton? In well-served Southampton postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Southampton? - Carrier comparison across the national BT Openreach footprint, plus Virgin Media Business and alt-net fibre where their networks serve your postcode at your exact postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Southampton clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Southampton? A: Southampton is reached by the national BT Openreach footprint at effectively every commercial postcode, with Virgin Media Business and alt-net fibre adding competition where their networks serve your address. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across Hampshire and the South Coast? A: Yes. AMVIA provisions and manages leased lines across Hampshire and the South Coast - Southampton, Eastleigh and the Solent business parks, covering the SO postcode areas. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Southampton? A: Leased lines in well-served Southampton postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Comparing every available network routinely beats a single provider's quote. Q: How long does a leased line take to install in Southampton? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Southampton buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Southampton? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Southampton businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Aberdeen: Compare Costs & Providers URL: https://amvia.co.uk/locations/aberdeen/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Aberdeen companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, CityFibre's independent full fibre where it has built, and Virgin Media Business at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Aberdeen businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Aberdeen network picture Aberdeen's economy - the energy sector and North Sea services alongside professional services and the universities - runs on connectivity that holds up around the clock. Aberdeen is one of the Scottish cities in CityFibre's full fibre build, so alongside the national Openreach footprint many postcodes have a genuine second physical network - with the competition on price and infrastructure that brings. Coverage is street-by-street. One Aberdeen-specific note: CityFibre reaches some Aberdeen streets and not others, so the only answer that matters is a live check of your exact address - where both networks bid, pricing routinely sharpens. Read more in our guide to CityFibre in Aberdeen. ## How much does a leased line cost in Aberdeen? In well-served Aberdeen postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Aberdeen? - Carrier comparison across the national BT Openreach footprint, CityFibre's build here, and Virgin Media Business where its network serves your postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Aberdeen clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Aberdeen? A: Aberdeen is one of the Scottish cities in CityFibre's full fibre build, so alongside the national Openreach footprint many postcodes have a genuine second physical network - with the competition on price and infrastructure that brings. Coverage is street-by-street. Virgin Media Business adds a third option where its network runs. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across Aberdeenshire? A: Yes. AMVIA provisions and manages leased lines across Aberdeen and Aberdeenshire, covering the AB postcodes. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Aberdeen? A: Leased lines in well-served Aberdeen postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Where CityFibre and Openreach both reach an address, the competition routinely sharpens the quote. Q: How long does a leased line take to install in Aberdeen? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Aberdeen buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Aberdeen? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Aberdeen businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Milton Keynes: Compare Costs & Providers URL: https://amvia.co.uk/locations/milton-keynes/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Milton Keynes companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, CityFibre's independent full fibre where it has built, and Virgin Media Business at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Milton Keynes businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Milton Keynes network picture Milton Keynes' economy - logistics and distribution, technology firms and national head-office operations across its planned business districts - depends on connectivity as deliberate as the city's grid. CityFibre's investment has produced a wide full fibre footprint across Milton Keynes' commercial areas, business parks and central districts, running alongside the national Openreach network - real choice on price, speed and provider for most MK businesses. One Milton Keynes-specific note: with two strong networks across most commercial districts, MK is one of the markets where a multi-carrier comparison most reliably beats any single provider's rate card. Read more in our guide to CityFibre in Milton Keynes. ## How much does a leased line cost in Milton Keynes? In well-served Milton Keynes postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Milton Keynes? - Carrier comparison across the national BT Openreach footprint, CityFibre's build here, and Virgin Media Business where its network serves your postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Milton Keynes clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Milton Keynes? A: CityFibre's investment has produced a wide full fibre footprint across Milton Keynes' commercial areas, business parks and central districts, running alongside the national Openreach network - real choice on price, speed and provider for most MK businesses. Virgin Media Business adds a third option where its network runs. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across the MK postcode area? A: Yes. AMVIA provisions and manages leased lines across Milton Keynes, Bletchley and the surrounding business parks, covering the MK postcodes. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Milton Keynes? A: Leased lines in well-served Milton Keynes postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Where CityFibre and Openreach both reach an address, the competition routinely sharpens the quote. Q: How long does a leased line take to install in Milton Keynes? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Milton Keynes buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Milton Keynes? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Milton Keynes businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business Leased Lines Peterborough: Compare Costs & Providers URL: https://amvia.co.uk/locations/peterborough/leased-lines Last updated: 2026-07 AMVIA provides fully managed business leased lines for Peterborough companies - dedicated, uncontended fibre with symmetric speeds, a 99.99% uptime SLA and 24/7 UK-based monitoring. We compare the national BT Openreach footprint, CityFibre's independent full fibre where it has built, and Virgin Media Business at your exact address, then manage installation and faults end to end as one security-first provider. ## Why do Peterborough businesses choose a leased line? A leased line is a dedicated fibre circuit reserved for your business alone, so bandwidth is never shared or slowed at peak times. It delivers symmetric upload and download speeds and a formal SLA - typically 99.99% uptime - that ordinary business broadband cannot match. For firms running cloud apps, VoIP and large file transfers, the uncontended capacity is the difference between a connection that drags at 3pm and one that performs identically all day. Start with what a leased line is if you want the fundamentals. ## The Peterborough network picture Peterborough's economy - distribution and logistics, financial services operations and manufacturing - runs on links that have to move data as dependably as its warehouses move goods. Peterborough is one of the UK cities where CityFibre has invested heavily, with full fibre coverage across the city centre, established commercial areas and the main business parks - a genuine gigabit-capable alternative running alongside the national Openreach footprint. One Peterborough-specific note: with CityFibre built across the main commercial areas, many Peterborough postcodes get two networks bidding for the same circuit - which is exactly when comparing beats choosing. Read more in our guide to CityFibre in Peterborough. ## How much does a leased line cost in Peterborough? In well-served Peterborough postcodes, leased lines start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps - with the exact figure decided by which carriers reach your building. Installation is typically £500–£2,000 as a one-off, frequently waived on a 36-month term. See the full tier guides for the detail: 100Mbps costs, 1Gbps costs and 10Gbps costs, or compare the market in our UK provider comparison. ## What does AMVIA's managed service include in Peterborough? - Carrier comparison across the national BT Openreach footprint, CityFibre's build here, and Virgin Media Business where its network serves your postcode - End-to-end installation management - surveys, wayleaves and handover, typically 30–90 working days - 24/7 proactive monitoring with sub-one-hour remote response on critical issues - Security-first design - see leased line security - Failover options via backup connectivity so a single fault never takes you offline ## One provider for connectivity, telephony and IT Most Peterborough clients run their leased line alongside business VoIP and managed IT support, so one provider owns the whole stack under a single SLA - no finger-pointing between suppliers when something needs fixing. Start with your postcode and a tailored multi-carrier quote typically lands within 24 hours. ## Frequently asked questions Q: Which networks provide leased lines in Peterborough? A: Peterborough is one of the UK cities where CityFibre has invested heavily, with full fibre coverage across the city centre, established commercial areas and the main business parks - a genuine gigabit-capable alternative running alongside the national Openreach footprint. Virgin Media Business adds a third option where its network runs. Availability varies street by street - AMVIA runs a live multi-carrier check for your exact postcode rather than assuming any one network. Q: Do you cover businesses across the PE postcode area? A: Yes. AMVIA provisions and manages leased lines across Peterborough and the surrounding commercial areas, covering the PE postcodes. We compare carrier availability at your specific address and manage the installation end to end. Q: How much does a leased line cost in Peterborough? A: Leased lines in well-served Peterborough postcodes start from £69/month for 100Mbps, £129/month for 1Gbps and £349/month for 10Gbps, with your exact price depending on which carriers have fibre near your building. Where CityFibre and Openreach both reach an address, the competition routinely sharpens the quote. Q: How long does a leased line take to install in Peterborough? A: A new leased line typically takes 30–90 working days from order to live service, covering the desktop survey, physical site survey, any fibre work and testing. Peterborough buildings close to existing carrier fibre land at the shorter end. AMVIA tracks every milestone and can provide a temporary 4G/5G router if you need connectivity sooner. Q: What is a leased line and how is it different from broadband? A: A leased line gives your business dedicated, uncontended bandwidth, so speeds hold steady at peak times and you share capacity with no one. Unlike broadband, it offers symmetric upload and download speeds and a formal SLA for fault response and uptime, typically 99.99%. Q: Can I combine a leased line with VoIP or managed IT from AMVIA in Peterborough? A: Yes. AMVIA provides leased lines, VoIP phone systems and managed IT support as an integrated package for Peterborough businesses. Running connectivity, telephony and IT through a single provider simplifies fault resolution and ensures your VoIP system has the bandwidth it needs. --- # Business VoIP Sheffield URL: https://amvia.co.uk/locations/sheffield/business-voip Last updated: 2026-08-28 AMVIA delivers managed business VoIP to Sheffield and South Yorkshire businesses - cloud phone systems, Microsoft Teams calling and full PSTN migration handled end to end. We provision the phones, port your numbers and manage the connectivity underneath, so calls stay clear and secure. One provider. Security-first. Microsoft-certified. We run it as a managed service, not a box sale. That means a single accountable team for your phones, your Microsoft 365 environment and the line they ride on - part of our wider IT and connectivity services in Sheffield. Trusted by 1,200+ UK businesses. ## What does AMVIA's business VoIP cover for Sheffield firms? AMVIA gives Sheffield businesses a fully managed cloud phone system: number porting, handset and softphone setup, call routing, and ongoing support from UK-based engineers. We design the deployment, configure it to how your team actually works, and stay on for the lifetime of the system. What you get: - Cloud phone system - desk phones, mobile and desktop softphones on one platform - Number porting - keep your existing Sheffield numbers across the S and DN postcodes - Microsoft Teams calling - make and take external calls inside Teams - Managed connectivity - we can supply the broadband or leased line underneath - UK-based support - qualified engineers, clear SLAs, defined response targets - Security built in - call encryption and fraud controls as standard On-site attendance across the S1–S14 area is arranged for hardware installs and troubleshooting; day-to-day management is handled remotely. ## Why are Sheffield businesses moving to VoIP now? Two things are driving the switch: the old phone network is being retired, and VoIP simply does more. The UK's analogue PSTN and ISDN network is being switched off, with the industry deadline now 31 January 2027 - every business still on traditional lines has to move before then. Adoption is already well advanced: PSTN lines are down to 19% of UK landline connections, from 27% in 2024 (Ofcom Connected Nations 2025). Ofcom's migration to digital landlines is the reason the legacy network is going away (ofcom.org.uk). | | Feature | Traditional PSTN / ISDN | Managed VoIP from AMVIA | Calls travel over | Copper phone lines | Your internet connection | Multi-site numbers | Separate lines per site | One cloud platform | Microsoft Teams calling | Not supported | Built in | Future-proof | Switched off by 2027 | The standard going forward | Who manages it | DIY across vendors | Single accountable provider Moving early means a planned migration instead of a forced one. We handle the PSTN switch-off for Sheffield businesses from porting through to system configuration. ## How much does business VoIP cost in Sheffield? Pricing is fixed monthly per user - the same plans AMVIA runs UK-wide, with no hidden charges. Sheffield businesses pay the standard rate, and the connectivity to support it is quoted separately based on your site. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £5.95 | Next business day | Core managed services | Advanced | from £5.95 | 4-hour target | Essentials + security | Enterprise | from £5.95 | 2-hour target | Advanced + 24/7 SOC If you need a dedicated line to guarantee call quality, a 100 Mbps leased line in urban areas starts from £69/month. We will tell you plainly whether your existing broadband is enough before you spend on connectivity you do not need. ## Can you provide Microsoft Teams Direct Routing in Sheffield? Yes. AMVIA deploys and manages Microsoft Teams Direct Routing for Sheffield businesses, so your Microsoft 365 environment can make and receive external calls through Teams. It is the most popular option for firms that want calls, chat and meetings on one platform instead of a separate phone system. Teams Phone with Direct Routing connects your tenant to the public telephone network through a managed session border controller - Microsoft documents the architecture in detail (learn.microsoft.com). We handle the setup, licensing and number management so your team just makes calls. ## What internet connection do I need for VoIP in Sheffield? Each simultaneous VoIP call needs roughly 100 Kbps of bandwidth, so the real question is how many calls run at once. For Sheffield businesses with 10 or more users, a high-quality FTTP connection or a dedicated leased line is the safe choice for consistent call quality. Because we supply both the VoIP system and the connectivity, we size them together - no finger-pointing between a phone provider and a separate ISP when a call drops. ## Frequently asked questions Q: Do you provide VoIP phone systems across South Yorkshire? A: Yes. AMVIA deploys and manages VoIP phone systems across Sheffield, Rotherham, Barnsley and Doncaster. We handle number porting, hardware provisioning and system setup for businesses across the S and DN postcode areas, with ongoing remote management and on-site attendance arranged where appropriate. Q: Can you provide on-site support for VoIP installations in Sheffield? A: Yes. Most VoIP deployment and management is handled remotely, but on-site attendance can be arranged for hardware installation, setup and troubleshooting across the S1–S14 postcode area. Visits are scheduled according to the nature and priority of the issue and your plan. Q: Do Sheffield businesses need to migrate from PSTN before January 2027? A: Yes. BT is switching off the PSTN and ISDN network on 31 January 2027, which affects every Sheffield business still using traditional phone lines. AMVIA manages the full migration - number porting, hardware replacement and VoIP configuration - with minimal disruption to your operations. Q: Do you provide Microsoft Teams Direct Routing for Sheffield businesses? A: Yes. AMVIA deploys and manages Microsoft Teams Direct Routing for Sheffield businesses, enabling your Microsoft 365 environment to make and receive external calls through Teams. It is popular with firms consolidating communications onto a single platform. Q: What internet connection do I need for VoIP in Sheffield? A: VoIP calls require roughly 100 Kbps of bandwidth per simultaneous call. For Sheffield businesses with 10 or more users, a leased line or high-quality FTTP connection is strongly recommended for reliable call quality. AMVIA can provision both the VoIP system and the connectivity underneath it. --- # Business Mobile Phones Sheffield URL: https://amvia.co.uk/locations/sheffield/business-mobiles Last updated: 2026-08-28 AMVIA manages business mobiles for companies across Sheffield and South Yorkshire - contracts, SIM-only plans, 5G devices and the security that sits behind them. We source from every major UK network, then manage billing, devices and policy from one place. One provider, security-first, Microsoft-certified. Most Sheffield businesses don't have a mobile problem - they have a management problem: too many tariffs, no device control, and no one accountable when a phone is lost. We fix that. Explore the full range on our business mobiles pillar, or read on for what Sheffield firms get. ## What do Sheffield businesses get with managed mobiles? A single managed mobile estate: the right network for each site, devices enrolled and locked down, and a UK team that answers when something breaks. You get contracts, security and support from one accountable provider instead of three separate suppliers. - Network-agnostic contracts - we pick the best coverage per location, not per commission. See business mobile contracts. - Device control - enrolment, policy enforcement and remote wipe via mobile device management. - SIM-only flexibility - keep your handsets, cut your tariff. See SIM-only business mobile plans. - Identity-led security - devices tied to Microsoft Entra ID through Microsoft Intune mobile management. - UK-based support - Microsoft-certified engineers, clear SLAs, no offshore queue. 5G outdoor coverage is available from at least one operator at 97% of UK premises (Ofcom 2025) - so Sheffield field teams get genuine high-speed mobile, not just a logo on a bar. ## Why does mobile security matter for Sheffield firms? A business phone is now a door into your Microsoft 365 tenant, your email and your data. Lose the phone, and you can lose the lot. 43% of UK businesses experienced a cyber breach in 2025, with the most disruptive incident costing an average of £3,550 - and mobile is one of the softest entry points. AMVIA's approach is security-first by default. Every managed device is enrolled, encrypted and governed by policy, so a lost handset is a non-event rather than a data breach. Our security stack is built on Microsoft Defender and the Barracuda suite - no bolt-on tools you've never heard of. - Conditional access - only compliant Sheffield devices reach company data - Remote wipe - kill a lost or stolen device in minutes - Separation of work and personal data on BYOD handsets - Mobile security that ties into your wider managed IT estate ## How much do managed business mobiles cost in Sheffield? Fixed monthly per-user pricing, identical to AMVIA's UK-wide plans - no Sheffield premium, no hidden charges. You pay for the management tier you need, and handset and airtime costs sit on top of the network contract we negotiate for you. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Core managed services | Advanced | from £40.00 | 4-hour target | Essentials + security | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Pair mobiles with business VoIP and you get one number plan, one bill and one support team across desk phones and handsets - useful for hybrid Sheffield teams splitting time between the office and the road. ## Which areas do you cover around Sheffield? We manage business mobiles across the whole South Yorkshire footprint - Sheffield, Rotherham, Barnsley and Doncaster - and select networks by real coverage at your sites, not a national average. City-centre offices and rural depots get tuned to different operators where it helps. - Sheffield city centre and business parks - Rotherham, Barnsley and Doncaster - Field and multi-site teams working across South Yorkshire - Hybrid workers splitting office and home ## Frequently asked questions Q: What business mobile services does AMVIA offer in Sheffield? A: Contracts and SIM-only plans across the main UK networks, 5G devices, and - the differentiator - the management and security behind them: MDM enrolment, work-data separation and remote wipe, run by the same team that handles your IT. Q: Can you consolidate our mixed bag of mobile contracts? A: Yes, and it's the most common starting point: scattered consumer contracts move onto one business account with pooled data and one bill, keeping every number. The consolidation moment is also the right time to enrol devices into management. Q: What happens when a phone goes missing in the field? A: Report it and the device is locked, business data wiped and the SIM barred within minutes - a lost phone stays an inconvenience instead of a breach. That's the practical difference managed mobiles make. Q: Do Sheffield businesses need 5G for work phones? A: For most office staff, 4G is fine; 5G earns its keep for field teams moving large files, site workers on video calls, and anywhere a phone doubles as a hotspot. We spec by role rather than defaulting everyone to the premium tier. --- # Managed IT Support and Cybersecurity Leeds URL: https://amvia.co.uk/locations/leeds Last updated: 2026-08-28 AMVIA delivers managed IT support and managed cybersecurity to Leeds and West Yorkshire businesses - 24/7 monitoring, leased lines, business VoIP and Microsoft 365 under one accountable contract. Support is remote-first with on-site attendance across the LS, BD, WF and HG postcodes when an issue needs hands on hardware. One provider, security-first. At a glance: - 1,200+ UK businesses managed by AMVIA - Under 1hr remote response target on critical issues - 24/7 monitoring and support ## What IT support does AMVIA provide in Leeds? AMVIA runs a full managed IT desk for Leeds firms: a UK-based helpdesk, proactive monitoring and patching, Microsoft 365 management, and security baked into every plan rather than sold as an afterthought. We support businesses across Leeds, Bradford, Wakefield, Huddersfield and the wider West Yorkshire area. Leeds has a dense financial services, legal and professional services sector, and each carries specific data-handling and uptime obligations. Our engineers are Microsoft-certified and our plans are designed so one provider owns connectivity, devices and security - no finger-pointing between vendors when something breaks. ## Why do Leeds businesses need managed cybersecurity? Cyber risk is now a board-level operating cost, not an IT line item. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the prior 12 months, which makes monitoring and response a baseline requirement rather than a nice-to-have. AMVIA holds Cyber Essentials Plus and builds every Advanced and Enterprise plan around Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus the Barracuda email and network security suite. We also support clients working toward ISO 27001 and sector frameworks, and support FCA compliance for regulated Leeds firms - as practitioner guidance, not a badge we lend you. - 43% of UK businesses experienced a cyber breach in 2025 (DSIT, Cyber Security Breaches Survey 2025) - £3.7bn lost by UK businesses to internet outages in 2023 (Beaming, vendor estimate) - 20m+ premises passed by Openreach's FTTP network (September 2025) ## What managed services can Leeds businesses get from AMVIA? Every service below is available on its own or as one integrated managed contract. The advantage of a single provider is a single accountable point of contact for connectivity, phones, devices and security. | | Service | What it covers | Where it links | Managed cybersecurity | 24/7 SOC monitoring, endpoint protection, email security, incident response | Managed security | Microsoft 365 security | Migration, hardening, MFA, ongoing admin | M365 management | Leased lines | Dedicated business internet with guaranteed speeds for Leeds city centre and business parks | /leased-lines | Business VoIP | Cloud phone systems with Leeds numbers, mobile apps and Teams integration | /business-voip | Business mobiles | Managed business mobile contracts and device security | /business-mobiles For teams standardising on Microsoft 365, current Microsoft UK list pricing runs from £4.60 (Business Basic) to £16.90 (Business Premium) per user per month, ex VAT on an annual plan (Microsoft 365 UK). AMVIA manages licensing, security hardening and day-to-day admin on top of whichever tier fits. ## How much does IT support cost for a Leeds business? AMVIA uses fixed monthly per-user pricing - the same as our UK-wide plans, with no per-ticket fees or hidden charges. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC ## Which areas of West Yorkshire does AMVIA cover? AMVIA serves businesses across West Yorkshire including Leeds, Bradford, Wakefield, Harrogate and Huddersfield. Support is delivered remote-first across the LS, WF, BD and HG postcode areas, with on-site visits scheduled by priority and plan when an issue needs an engineer on the ground. Remote-first does not mean remote-only. For server moves, network faults or new-office fit-outs, we attend in person across the region - you get the speed of remote support with local hands when the job genuinely needs them. ## Frequently asked questions Q: Which West Yorkshire areas does AMVIA cover? A: Leeds, Bradford, Wakefield, Huddersfield and Harrogate - the LS, BD, WF and HG postcode areas - remote-first with on-site attendance when an issue needs hands on hardware. Q: Do you understand regulated professional firms? A: Leeds' financial services, legal and professional sector is a core client profile: data-handling obligations, uptime expectations and client-confidentiality requirements are built into how plans are designed, with Cyber Essentials Plus held by AMVIA itself. Q: What response times do Leeds businesses get? A: The same UK-wide targets: critical-issue remote response in under an hour, with plan tiers from next-business-day (Essentials) to 2-hour targets (Enterprise). Remote-first is why geography doesn't slow it down. Q: Can you take over from our current Leeds IT provider mid-contract? A: Yes - the usual pattern is onboarding during your notice period so there's no gap: audit, documentation, tooling, cutover. We'll also tell you honestly if your notice terms make a particular timing cheaper. --- # Cybersecurity Services Leeds URL: https://amvia.co.uk/locations/leeds/cybersecurity Last updated: 2026-08-28 AMVIA provides managed cybersecurity services in Leeds, covering the LS1 city core, Leeds Dock and the wider LS1–LS11 postcodes. You get 24/7 UK SOC threat monitoring, managed endpoint protection and email security from one accountable, Microsoft-certified provider. Security comes first here - not bolted on as an afterthought. This is the local front door to our managed cybersecurity service: the same platform that protects 1,200+ UK businesses, delivered to Leeds firms that handle regulated and client-sensitive data. ## Why do Leeds businesses need managed cybersecurity? Leeds is one of the UK's busiest financial and professional services centres outside London, with law firms, accountancy practices and financial companies concentrated in the LS1 core and Leeds Dock (LS10). These firms hold sensitive client data, carry compliance obligations and attract targeted attacks - a combination that makes managed defence a business requirement, not an optional extra. The national picture backs this up. 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months (Cyber Security Breaches Survey 2025). Among larger organisations the figures climb: 65% of medium and 69% of large businesses reported breaches or attacks (Cyber Security Breaches Survey 2025/26). - £3,550 - average cost of the most disruptive breach for UK businesses (Cyber Security Breaches Survey 2025) - 85% of breaches involved phishing (Cyber Security Breaches Survey 2025) - 1,200+ UK businesses managed by AMVIA ## What do Leeds businesses get with AMVIA? A managed security service built for the regulated, data-sensitive firms common across Leeds. Monitoring and response run from AMVIA's UK SOC, backed by Microsoft-certified engineers and our 24/7 managed SOC service. One provider owns the outcome - detection, containment and reporting. ## 24/7 SOC and managed detection Our UK SOC monitors Leeds client environments continuously using Microsoft Defender for Endpoint telemetry. Analysts investigate and contain threats as part of the managed service, with no manual escalation needed from your team. You get round-the-clock cover without staffing a security desk in-house. ## Email security and business email compromise protection Business email compromise is a real risk for Leeds professional services firms. We deploy and manage email authentication, impersonation detection and attachment scanning through the Barracuda email security suite, paired with our phishing protection service. Phishing is the entry point for most breaches, so we treat the inbox as the front line. ## Remote-first, on-site where it matters Monitoring and response are delivered remotely from AMVIA's UK SOC, which keeps cover constant and costs predictable. On-site security assessments and incident support across Leeds and West Yorkshire are arranged where the engagement calls for it - for example during a live incident or an annual review. ## Certification and compliance support We help Leeds firms achieve and maintain Cyber Essentials Plus, the UK government-backed certification scheme. For financial, legal and accountancy clients we align controls to support FCA compliance and tighten the data-protection posture the ICO expects. See our cybersecurity for financial services for the sector detail. ## How much do managed cybersecurity services in Leeds cost? Fixed monthly per-user pricing, identical to AMVIA's UK-wide plans - no hidden charges and no postcode premium. Leeds firms pay the same transparent rate as every other AMVIA security client, scaled to the response speed and out-of-hours cover they need. | | Plan | From / User / Month | Response Target | Out-of-Hours | Essentials (Most Popular) | from £25.00 | Next business day | Email only | Advanced | from £40.00 | Same day (4hr target) | Phone & email | Enterprise | from £60.00 | 2-hour target | 24/7 dedicated Pair your security plan with Microsoft 365 security and you cover identity, endpoints and email under a single accountable provider. ## Frequently asked questions Q: Do you provide managed cybersecurity across West Yorkshire? A: Yes. AMVIA provides managed cybersecurity across West Yorkshire, including Leeds, Bradford, Wakefield, Harrogate and Huddersfield. Monitoring and response are delivered remotely from AMVIA's UK SOC across the LS, WF, BD and HG postcode areas, with on-site incident support arranged where appropriate. Q: Can you respond on-site to cybersecurity incidents in Leeds? A: Yes. Incident detection and response are handled remotely by AMVIA's UK SOC as part of the managed service. Where an incident requires on-site attendance, a visit across Leeds and West Yorkshire is arranged and scheduled according to the severity of the incident and your plan. Q: Do you serve financial services businesses in Leeds? A: Yes. Leeds is one of the UK's most active financial services centres outside London, and AMVIA supports financial services, legal and accountancy firms across the LS1 core and Leeds Dock district. We help with controls that support FCA compliance and with Cyber Essentials Plus certification. Q: What cybersecurity coverage do you provide across the LS postcode area? A: AMVIA provides managed cybersecurity coverage across the LS postcode area, including LS1 city centre, LS10 Leeds Dock, LS5 Kirkstall and outlying areas such as Garforth, Morley and Otley. Remote monitoring starts immediately; on-site response times vary by location within the LS area. Q: How much do managed cybersecurity services in Leeds cost? A: AMVIA's Leeds plans start from £25.00 per user per month for Essentials, from £40.00 for Advanced and from £60.00 for Enterprise. Pricing is fixed and UK-wide - there is no Leeds surcharge. The plan you choose sets your response target and out-of-hours cover, from next-business-day email up to a 24/7 dedicated response. --- # Managed IT Support Leeds URL: https://amvia.co.uk/locations/leeds/managed-it Last updated: 2026-08-28 AMVIA provides managed IT support to businesses across Leeds and West Yorkshire - proactive 24/7 monitoring, clear SLAs, and UK-based engineers, delivered remote-first with on-site attendance where it's genuinely needed. We run IT and security together under one accountable provider: security-first, Microsoft-certified, and no finger-pointing between suppliers when something breaks. ## What do Leeds businesses get with AMVIA? A single provider that handles day-to-day IT and the security wrapped around it - helpdesk, monitoring, patching, and threat detection - sized to a 10–500 staff business. You get a named team that knows your environment, not a different stranger on every call. - 1,200+ UK businesses managed by AMVIA - a track record across regulated and unregulated sectors - Sub-1-hour critical-issue remote response on covered plans, with on-site backup in West Yorkshire - 24/7 monitoring and support available on higher tiers - Cyber Essentials Plus certified - the audited tier of the NCSC-backed scheme - Cyber Essentials Plus certified - we hold the certification we recommend you achieve We are a security partner first, not a telecoms reseller. That means the fully managed IT support service you buy already has endpoint protection, monitoring, and response built in - not bolted on after an incident. ## Why does managed IT matter for Leeds businesses? UK businesses face a real, measured risk from downtime and cyber attack - and Leeds firms are no exception. The economics are simple: prevention and fast recovery cost far less than an outage or a breach. Independent UK data makes the case. - 43% of UK businesses identified a cyber breach or attack in the last 12 months (DSIT Cyber Security Breaches Survey 2025) - £3.7bn lost by UK businesses to internet outages in 2023 (Beaming, vendor estimate) Ransomware and phishing remain the most common routes in for SMEs, and the NCSC's small-business guidance is clear that monitoring, patching, and tested backups are the controls that move the needle. That is exactly the work a managed provider does every day so your team doesn't have to. ## How big is the UK managed IT market? Managed services are now mainstream, not a niche - the UK market has thousands of active providers. The point for a Leeds MD: outsourcing IT to a specialist is the default operating model, not an experiment. The differentiator is whether your provider treats security as core or as an upsell. AMVIA builds on Microsoft Defender and the Barracuda email and network suite, monitored by our in-house team - see Microsoft's security guidance for how the underlying platform works. ## What's included in AMVIA's managed IT for Leeds? Every plan covers the fundamentals; higher tiers add faster SLAs, deeper security, and out-of-hours cover. You choose the level of protection and response that matches your risk and budget. | | Capability | What it means for you | Proactive protection | 24/7 monitoring and threat detection for your Leeds estate | Expert support | UK-based, Microsoft-certified engineers handling your tickets | Compliance support | Cyber Essentials Plus and Microsoft 365 hardening; supports FCA, SRA and GDPR compliance | Fast response | Clear SLAs with defined, plan-based response targets For regulated Leeds firms - financial services, accountancy, and legal - we also support the specific data-handling and compliance obligations those sectors carry, including Microsoft 365 security hardening and access control. ## What does managed IT support cost in Leeds? Pricing is fixed monthly, per user, and the same as AMVIA's UK-wide managed IT plans - no per-ticket fees and no hidden charges. You scale the plan, not the surprises. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Core managed services | Advanced | from £40.00 | 4-hour target | Essentials + security | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC ## Which services can Leeds businesses get from AMVIA? AMVIA is a single provider for connectivity, communications, devices, and security across Leeds and West Yorkshire. One contract, one support line, one team accountable for the lot. - Managed cybersecurity - monitoring, detection, and response - Microsoft 365 security - hardening, MFA, and backup - Leased lines - dedicated business connectivity - Business VoIP - cloud phone systems and Teams calling - Business mobiles - managed contracts and device security - Managed IT support - helpdesk, monitoring, and patching ## Frequently asked questions Q: What does managed IT support cost in Leeds? A: The same UK-wide ladder as everywhere: Essentials from £25, Advanced from £40, Enterprise from £60 per user/month - no regional premium. Final pricing depends on user count and scope, quoted after a short audit. Q: How fast is support for Leeds businesses? A: Critical issues get sub-one-hour remote response; plan tiers set the broader targets from next-business-day to 2-hour. Monitoring runs 24/7 on every tier, so most problems are caught before users report them. Q: Do you visit Leeds offices in person? A: When the job needs it, yes - server moves, network faults, office fit-outs across LS, BD, WF and HG postcodes are attended in person, scheduled by priority. Everything that resolves faster remotely is done remotely, which is most things. Q: Can our in-house IT person work with AMVIA? A: Yes - that's the co-managed model: your person keeps day-to-day ownership and local knowledge while AMVIA adds 24/7 monitoring, security depth and overflow capacity. The responsibility split is agreed explicitly up front. --- # Managed IT Support and Cybersecurity Manchester URL: https://amvia.co.uk/locations/manchester Last updated: 2026-08-28 AMVIA delivers managed IT support, cybersecurity, connectivity and Microsoft 365 to businesses across Greater Manchester - from the city centre to Salford, Stockport and Trafford. UK engineers, clear SLAs and on-site cover where it counts, from one accountable, security-first, Microsoft-certified provider. - 1,200+ UK businesses managed by AMVIA - Sub-1-hour remote response on critical issues - 24/7 monitoring and support across the M postcode areas We run managed IT support the way an in-house team would - except you get a whole bench of certified engineers, a 24/7 SOC and a single bill. If you operate in Greater Manchester and you are tired of chasing a break-fix supplier, this is the page for you. ## What managed IT support covers in Manchester AMVIA gives Manchester businesses one provider for IT support, security, connectivity and Microsoft 365. That means a single helpdesk, one set of SLAs and one team accountable for whether your technology works. No finger-pointing between a telecoms reseller and an IT firm. - Managed IT support and helpdesk - UK-based engineers, ticket triage, patching and monitoring - Managed cybersecurity - endpoint protection, email security and incident response, monitored 24/7 - Microsoft 365 management - deployment, migration, hardening and ongoing administration - Business connectivity - leased lines, FTTP and SD-WAN across Greater Manchester - VoIP phone systems - cloud-hosted telephony with Manchester numbers and Teams integration - Compliance support - Cyber Essentials Plus guidance for regulated Manchester sectors ## Why do Manchester businesses need stronger cybersecurity? Cyber risk is now a mainstream operational problem, not an IT footnote. The UK government's 2025 Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months, and the rate climbs sharply for larger SMEs - exactly the 10–500-staff firms across Manchester that AMVIA protects. Manchester's digital, media and professional-services clusters hold the kind of data attackers want, and a single ransomware hit can stop a business for days. The figures below are drawn from the same government survey. | | Metric (UK, 2025) | Figure | Source | Businesses hit by a breach or attack in 12 months | 43% | DSIT 2025 | Medium businesses reporting breaches | 65% | DSIT 2025/26 | Breaches where phishing was the reported attack type | 85% | DSIT 2025 Phishing is the dominant route in, which is why our managed cybersecurity wraps email security and endpoint detection around every user. The National Cyber Security Centre recommends the same layered controls we deploy as standard. ## What do Manchester businesses get with AMVIA? You get a complete IT and security function, run remote-first with on-site engineering across Greater Manchester when a problem needs hands on a machine. Every service can be bought on its own or bundled into one managed agreement with a single SLA and a single point of accountability. - Managed cybersecurity - 24/7 threat monitoring, Microsoft 365 security hardening, endpoint protection and incident response, built on Microsoft Defender and the Barracuda email and network suite. - Business connectivity - business leased lines, FTTP and SD-WAN across Manchester city centre, Salford Quays, MediaCityUK, Trafford Park and Stockport. - VoIP phone systems - cloud-hosted business VoIP with Manchester numbers, multi-site support and Microsoft Teams calling. - Business mobiles and devices - business mobile plans with mobile device management for a hybrid Manchester workforce. - Microsoft 365 management - migration, security configuration and day-to-day administration by Microsoft Solutions Partner engineers. - UK helpdesk - qualified UK-based engineers on every ticket, with on-site Manchester visits scheduled by priority. ## What does IT support cost for a Manchester business? Pricing is per user, per month, and scales with the response speed and security depth you need. The plans below are starting points - final pricing depends on user numbers, devices and which services you bundle. Microsoft 365 licences are billed separately at Microsoft's list prices. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC If Microsoft 365 is part of your stack, licensing is transparent: Business Basic is £4.60, Standard £9.60 and Business Premium £16.90 per user per month (ex VAT, annual commitment). We handle the licensing, security configuration and ongoing management on top. ## Which areas of Greater Manchester does AMVIA cover? We support businesses across the full M postcode footprint and the surrounding boroughs, combining remote-first support with on-site attendance where the job needs it. Wherever you sit in Greater Manchester, you get the same SLAs and the same accountable team. - Manchester city centre (M1–M4) and the Northern Quarter tech community - Salford, Salford Quays and MediaCityUK (M50) - Trafford Park and the wider Trafford industrial estates - Stockport, Wigan and the outer Greater Manchester boroughs ## Frequently asked questions Q: Which parts of Greater Manchester does AMVIA cover? A: The city centre, Salford Quays, MediaCityUK, Trafford Park and Stockport - the full Greater Manchester spread - delivered remote-first with on-site engineering visits where a job needs hands on hardware. Q: What makes Manchester's IT needs distinctive? A: The digital and creative concentration: agencies and production teams moving heavy files, tech firms with cloud-first stacks, and the MediaCityUK corridor's appetite for serious bandwidth. IT support here is usually a connectivity conversation too, which suits a provider that runs both. Q: Can AMVIA handle both our IT support and our internet? A: Yes - that's the model: managed IT, cybersecurity, leased lines and VoIP under one contract, so the provider fixing your laptop is accountable for the circuit it runs on. Manchester's competitive carrier market (CityFibre, Zayo, Virgin, Openreach) makes the connectivity half especially worth comparing. Q: How does onboarding work for a Manchester business? A: Audit first, then a documented transition running alongside your current provider's notice period - tooling deployed, credentials transferred, cutover scheduled. Users keep working throughout; the switch is a managed project, not a cliff edge. --- # Cybersecurity Services Manchester URL: https://amvia.co.uk/locations/manchester/cybersecurity Last updated: 2026-08-28 AMVIA delivers managed cybersecurity services in Manchester for SMEs across Spinningfields, MediaCityUK and the M1–M4 postcodes. You get 24/7 SOC monitoring, email and endpoint protection, and certification support from one accountable, Microsoft-certified UK provider. Book a free security audit to see your exposure first. ## What cybersecurity services does AMVIA provide in Manchester? AMVIA provides end-to-end managed cybersecurity for Manchester businesses: 24/7 SOC monitoring, Microsoft Defender endpoint protection, email and phishing defence, vulnerability management, and Cyber Essentials Plus certification support. Monitoring runs from our in-house UK SOC, with on-site incident support across Greater Manchester arranged where the engagement needs it. Manchester's commercial base is mixed: the Spinningfields financial district (M3), MediaCityUK in Salford (M50), and the Northern Quarter tech community (M4). Each has different risk profiles, but the same core need - a single provider who watches the environment, responds to threats, and proves compliance. That is what we do. - 24/7 threat monitoring from AMVIA's UK SOC - Endpoint detection and response built on Microsoft Defender for Endpoint - Email and phishing defence with impersonation protection and attachment sandboxing - Certification support for Cyber Essentials and Cyber Essentials Plus - One provider, security-first, Microsoft-certified - no finger-pointing between vendors ## Why do Manchester businesses need managed cybersecurity? The threat is not hypothetical. 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, rising to 65% of medium and 69% of large businesses (DSIT Cyber Security Breaches Survey 2025/26). For most Manchester SMEs, the question is when, not if. Phishing is the dominant route in. 85% of breaches involved phishing (DSIT 2025), which is why email security and 24/7 monitoring matter more than any single product. The NCSC recommends layered defence and active monitoring rather than one-off tooling - exactly the model AMVIA runs. | | Risk (DSIT CSBS 2025/26) | Figure | What it means for you | All UK businesses breached | 43% | Baseline odds in any 12 months | Medium businesses breached | 65% | Higher exposure as you scale | Large businesses breached | 69% | Supply-chain pressure flows down | Phishing the most disruptive attack type | 69% | Email is the front line ## What do Manchester businesses get with AMVIA? You get a managed service, not a product licence. AMVIA monitors, detects, contains and reports - and tells you in plain English what happened and what we did. Coverage spans Greater Manchester: the city centre, Salford, Trafford Park, Stockport and Wigan. ## 24/7 SOC and managed detection Continuous monitoring of your environment using Microsoft Defender for Endpoint telemetry. Threats are detected and contained by AMVIA's in-house UK SOC team as part of the managed service - no extra call-out fees, no out-of-hours gaps. ## Email security and phishing defence We deploy and manage email security including Microsoft Defender for Office 365 to cut phishing exposure for Manchester teams. Impersonation protection and attachment sandboxing are included as standard. ## Remote-first, on-site where it counts Monitoring and response are delivered remotely from AMVIA's UK SOC. On-site incident support, security assessments and pre-certification audits across the M postcodes are arranged where the severity or engagement calls for it. ## How much does managed cybersecurity in Manchester cost? Fixed monthly per-user pricing, the same as AMVIA's UK-wide plans - no hidden charges and no Manchester surcharge. Three tiers cover most SMEs, from baseline monitoring to a dedicated 24/7 response target. | | Plan | From / User / Month | Response Target | Out-of-Hours | Essentials (Most Popular) | from £25.00 | Next business day | Email only | Advanced | from £40.00 | Same day (4hr target) | Phone & email | Enterprise | from £60.00 | 2-hour target | 24/7 dedicated AMVIA is trusted by 1,200+ UK businesses. If you are unsure which tier fits, a free security audit gives you a clear picture before you commit. ## Does AMVIA respond on-site to incidents in Manchester? Yes. Detection and response are handled remotely by AMVIA's UK SOC as part of the managed service, which is faster than waiting for an engineer to travel. Where an incident genuinely needs hands on hardware, a visit across Greater Manchester is arranged and prioritised by severity and your plan tier. ## Frequently asked questions Q: Which Manchester areas does the cybersecurity service cover? A: SMEs across Spinningfields (M3), MediaCityUK in Salford (M50), the Northern Quarter tech community (M4) and the wider M1–M4 postcodes - delivered remotely by design, since security monitoring doesn't need a van. Q: What does 24/7 SOC monitoring give a Manchester business? A: Every alert from your endpoints, email and Microsoft 365 triaged as it fires - nights, weekends, bank holidays - with containment started on genuine incidents rather than queued for morning. Attacks on Manchester firms don't keep office hours. Q: Do Manchester's media and tech firms have specific security risks? A: Their value is in accounts and content: compromised identities, hijacked client channels and data theft matter more than defaced websites. Identity-first controls - MFA enforcement, conditional access, session monitoring - are where their protection starts. Q: How do we get started without ripping anything out? A: A security audit of what's already there - most Manchester SMEs on Microsoft 365 own more protection than they've configured. The audit shows the gaps; the managed service then runs what you have properly before anyone proposes new spend. --- # Managed IT Support Manchester URL: https://amvia.co.uk/locations/manchester/managed-it Last updated: 2026-08-28 AMVIA delivers fully managed IT support to Manchester and Greater Manchester businesses: proactive 24/7 monitoring, an unlimited UK-based helpdesk, patching and clear SLAs, run remote-first with on-site cover where it is needed. One provider, security-first, with Microsoft-certified engineers accountable for your entire IT estate. - 1,200+ UK businesses managed by AMVIA - Under one hour critical-issue remote response target - 24/7 monitoring and out-of-hours support available This is our managed IT support offer for Manchester - the same fixed-price service we run UK-wide, delivered locally across Greater Manchester. ## What does AMVIA's managed IT support in Manchester include? Managed IT support in Manchester from AMVIA covers proactive monitoring, an unlimited UK-based helpdesk, patch management, and security built in from day one. We act as your single accountable provider, so one team owns your devices, your Microsoft 365 tenant, and your security posture - no finger-pointing between vendors. - Proactive protection: 24/7 monitoring and threat detection across endpoints and your Microsoft 365 tenant, backed by our in-house managed cybersecurity team. - Expert support: UK-based, Microsoft-certified engineers on an unlimited IT helpdesk - remote-first, with on-site attendance where remote fixes will not do. - Compliance support: practical guidance on Cyber Essentials Plus and data-protection obligations, mapped to how your business actually works. - Clear SLAs: defined response targets and transparent service-level agreements, so you know exactly what you have paid for. We are a security partner first, not a telecoms reseller - every managed IT plan is hardened from the start rather than bolted on later. ## How big is the UK managed IT market? The UK managed services sector is large and maturing, which matters when you are choosing who to trust with your whole IT estate. It is a crowded, mature market - which is exactly why provider accountability is worth getting right. The takeaway for a Manchester MD is simple: there are thousands of providers, so judge them on accountability, security depth, and Microsoft certification - not on which one answers the phone fastest in a sales call. ## What cyber risks do Manchester businesses face? Cyber risk is now an everyday operational problem for Greater Manchester businesses, not an edge case. The UK Government's Cyber Security Breaches Survey 2025 shows breaches and attacks remain common across UK organisations, which is why our managed IT is security-first rather than security-optional. - 43% of UK businesses experienced a cyber security breach or attack in the last 12 months (Cyber Security Breaches Survey 2025, DSIT) - gov.uk The NCSC recommends layered controls - monitored endpoints, multi-factor authentication, and rapid patching - all of which are standard across AMVIA's managed IT and Microsoft 365 security plans. Where downtime is the real risk, our business continuity cover gets Manchester firms back up faster. ## How much does managed IT support cost in Manchester? Managed IT support in Manchester uses the same fixed monthly per-user pricing as AMVIA's UK-wide plans, with no per-ticket fees and no hidden charges. You pick the response target your business needs; final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Core managed services | Advanced | from £40.00 | 4-hour target | Essentials + security | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Pricing is per user, billed monthly, and identical to our national rates - your Manchester location does not change the price. ## Which IT and security services does AMVIA offer in your area? AMVIA supports Manchester and the wider Greater Manchester area with a full managed IT and security stack, all from a single accountable provider. Whether you need day-to-day support, tighter Microsoft 365 security, or faster connectivity, one team owns the outcome. - Managed IT support and unlimited helpdesk - Managed cybersecurity and 24/7 monitoring - Microsoft 365 security and hardening - Leased lines, business VoIP, and business mobiles ## Frequently asked questions Q: What's included in managed IT support for Manchester businesses? A: Proactive 24/7 monitoring, an unlimited UK-based helpdesk, patching, backup oversight and Microsoft 365 administration - with security built into every tier rather than sold separately. Plans run £25–£60 per user/month. Q: Do you support businesses across Greater Manchester? A: Yes - city centre, Salford Quays, MediaCityUK, Trafford Park and Stockport, remote-first with on-site attendance where the work genuinely needs an engineer present. Q: Our media company moves huge files - can support and connectivity come together? A: That's the preferred shape: Manchester's digital and creative sector usually needs the connectivity conversation (uncontended bandwidth, symmetric uploads) alongside the IT one, and AMVIA quotes both as one design rather than two vendors. Q: How disruptive is switching to AMVIA? A: Users shouldn't notice: audit, documentation and tooling deployment happen alongside your incumbent's notice period, and cutover is scheduled, tested and reversible. The transition plan is shown before you sign, not discovered after. --- # Managed IT Support and Cybersecurity London URL: https://amvia.co.uk/locations/london Last updated: 2026-08-28 AMVIA delivers managed IT support, cybersecurity, leased lines, VoIP and Microsoft 365 to businesses across London and the M25. You get 24/7 monitoring, clear SLAs and a named account manager - without the premium pricing of London-only providers. One provider, security-first, Microsoft-certified. Key facts: - 1,200+ UK businesses managed by AMVIA - 24/7 monitoring and response from an in-house SOC - Cyber Essentials Plus certified, Microsoft Solutions Partner ## Why do London businesses choose AMVIA for IT support? London firms pick AMVIA because they get one accountable provider for IT, security and connectivity instead of three suppliers passing blame between them. We run managed IT support remote-first from a 24/7 operations centre, with engineers who learn your business before they touch a single setting. The capital's risk profile is the reason security sits at the centre of everything we ship. London concentrates financial, legal and professional-services firms - the sectors attackers target hardest. 43% of UK businesses experienced a cyber breach or attack in the last 12 months (gov.uk Cyber Security Breaches Survey 2025). For a London SME holding client money or sensitive data, that is not an abstract risk - it is a coin-flip every year. We price for that reality without the London markup. You get enterprise-grade security and a UK helpdesk on fixed monthly pricing, whether you sit in the City or an outer borough. ## What managed IT services does AMVIA provide in London? AMVIA provides the full stack a growing London business needs: security, connectivity, voice, Microsoft 365 and day-to-day support. Each service stands alone or combines into one managed agreement with a single SLA and a single point of contact. Here is what you get and where each piece links. - Managed cybersecurity - 24/7 monitoring, endpoint protection, email security and incident response, built on Microsoft Defender and the Barracuda suite, monitored by our in-house SOC. - Microsoft 365 security - deployment, migration, hardening and ongoing management for email, data and Teams. - Business leased lines - dedicated, uncontended FTTP and SD-WAN, delivered across London's complex multi-carrier landscape. - Business VoIP - cloud-hosted phone systems with London numbers, Teams integration, call recording and multi-site support. - Business mobiles - managed mobile estates with device management and security baked in. - IT helpdesk - a UK-based desk staffed by qualified engineers who know your environment, not an offshore script. ## How does connectivity work for London businesses? Connectivity in London is dense but uneven - coverage and carrier access vary building by building, especially in multi-tenant offices, so a survey before you commit is essential. 78% of UK premises now have full fibre (FTTP) coverage (Q3 2025) (Ofcom), and London's Openreach and CityFibre footprints continue to expand. For businesses that can't tolerate downtime, a leased line removes the gamble. A serious outage on best-efforts broadband routinely means a day or more of disruption - a dedicated, uncontended line with a guaranteed SLA and fix-time commitment is how you avoid that. In multi-tenanted London buildings we coordinate carrier access and landlord wayleaves so provisioning doesn't stall. ## What does managed IT support cost for a London business? Pricing is fixed monthly per user - the same plans AMVIA runs UK-wide, with no London premium, no hidden charges and no per-ticket fees. The table below shows the three tiers. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Security is built into the higher tiers rather than sold as a bolt-on. Following NCSC small-business guidance, the controls that stop most attacks - patching, MFA, endpoint protection and monitored backups - should be standard, not premium (NCSC Small Business Guide). ## Which London boroughs does AMVIA cover? AMVIA serves every London postcode, delivered remote-first with on-site attendance arranged where the issue or your plan needs it. A single agreement covers multi-site operations across the capital, so you avoid a patchwork of regional suppliers. - City of London (EC) and Canary Wharf (E14) - Shoreditch and Tech City (EC2A) - West End and central London (W1, WC) - Inner boroughs across N, NW, SE, SW and E - Outer London and the surrounding M25 corridor ## Frequently asked questions Q: Does AMVIA support businesses across all of London? A: Yes - across London and the M25, remote-first with on-site attendance where jobs need it. London's density actually favours the model: engineers reach client sites quickly when hardware work is genuinely required. Q: Why does London carry higher cyber risk? A: Concentration: the density of financial and professional services firms makes London businesses disproportionately targeted, and supply chains transmit the pressure - your clients' security questionnaires arrive whether you're ready or not. 24/7 monitoring is the practical answer. Q: What's the connectivity picture for London offices? A: The most competitive in the UK - Openreach, Virgin Media Business, CityFibre plus alt-nets like Community Fibre and Hyperoptic, with dense coverage from the City to Canary Wharf and Shoreditch. Multi-carrier comparison matters most where choice is widest. Q: Can you support multi-site London businesses? A: Yes - multiple offices inside the M25 (or beyond) run on one contract, one helpdesk and one network design, with connectivity, phones and security consistent across sites rather than accumulated per office. --- # Cybersecurity Services London URL: https://amvia.co.uk/locations/london/cybersecurity Last updated: 2026-08-28 AMVIA delivers managed cybersecurity services in London: 24/7 monitoring from our UK-based SOC, managed detection and response, email security and certification support. We protect 1,200+ UK businesses, from City and Canary Wharf financial firms to Shoreditch tech companies, with one accountable, security-first, Microsoft-certified provider. London SMEs face a higher volume of targeted attacks than most UK cities, driven by the density of financial, legal and professional services firms across the EC, E1, WC and W1 postcodes. Our managed cybersecurity service covers the City (EC2–EC4), Canary Wharf (E14), Shoreditch and the West End, with UK-based engineers handling every escalation. 43% of UK businesses suffered a cyber breach or attack in the past 12 months (Cyber Security Breaches Survey 2025), so round-the-clock cover is no longer optional for London firms. ## Why do London businesses need managed cybersecurity? London concentrates the data attackers want most - client money, legal files, regulated records - into dense commercial postcodes. That makes its SMEs high-value targets. 43% of UK businesses reported a breach or attack in the last year, rising to 65% of medium and 69% of large businesses (Cyber Security Breaches Survey 2025/26). - City & Canary Wharf (EC2–EC4, E14): financial and legal firms under FCA and SRA scrutiny. - Shoreditch & East London: tech and creative businesses holding source code and customer data. - West End (W1): professional services and agencies facing client security audits. The National Cyber Security Centre reports that most attacks on smaller firms are opportunistic and preventable with the right monitoring and email controls in place. ## What do London businesses get with AMVIA? A layered managed service: continuous threat monitoring, fast response and the certification evidence London clients and insurers ask for. Everything runs through one provider, so there is no finger-pointing when something needs fixing. Our engineers understand the FCA, ICO and SRA context London firms operate in. - 24/7 SOC & managed detection and response: our UK Security Operations Centre uses Microsoft Defender for Endpoint telemetry to detect, investigate and contain threats around the clock. - Email security & anti-phishing: Microsoft Defender for Office 365 and the Barracuda suite cut the volume of malicious mail reaching staff. - Cyber Essentials Plus certification support: we prepare, remediate and submit your application, including the technical fixes needed to pass assessment. - UK helpdesk - never offshore: incidents are handled by UK-based engineers, not a remote call centre. ## How much do cybersecurity services in London cost? Pricing is fixed monthly per user - the same plans AMVIA runs UK-wide, with no hidden charges. London firms choose a tier by how fast they need a response and whether they need out-of-hours cover. All AMVIA service prices below are indicative starting points. | | Plan | From / User / Month | Response Target | Out-of-Hours | Essentials (Most Popular) | from £25.00 | Next business day | Email only | Advanced | from £40.00 | Same day (4hr target) | Phone & email | Enterprise | from £60.00 | 2-hour target | 24/7 dedicated The average cost of the most disruptive breach for UK businesses is £3,550 - a managed plan typically costs a fraction of cleaning up a single incident. ## Which London areas and sectors do you cover? We cover every major London commercial district and the regulated sectors clustered in them. Coverage spans the City, Canary Wharf, Shoreditch, the West End and Southwark, with sector experience in financial services, law, accountancy and technology - the firms most often asked for security certification by clients and insurers. - Financial services & legal (City, Canary Wharf): FCA operational resilience and SRA obligations. - Technology & media (Shoreditch, Bethnal Green): endpoint monitoring and cloud security posture. - Multi-tenanted offices: network segmentation and shared-infrastructure security. ## Frequently asked questions Q: Do you provide managed cybersecurity for businesses across London? A: Yes. AMVIA provides managed cybersecurity for London businesses across all major commercial districts - the City (EC2–EC4), Canary Wharf (E14), Shoreditch (EC2A), West End (W1) and Southwark. Our UK-based SOC monitors London environments continuously, with UK-based engineers handling all incident escalations. Q: Do you serve financial services and legal firms in the City of London? A: Yes. AMVIA supports financial services, legal and professional services firms across the City and Canary Wharf. We assist with FCA operational resilience requirements, Cyber Essentials Plus certification, and ongoing managed detection and response - key obligations for regulated London businesses. Q: Can you handle cybersecurity for London businesses in multi-tenanted offices? A: Yes. Many London firms work in shared or multi-tenanted buildings where physical security and network segmentation present specific challenges. Our UK-based engineers understand the regulatory and operational context, including building access protocols and shared infrastructure security, and design controls to match. Q: What cybersecurity coverage do you provide for Shoreditch and East London tech businesses? A: AMVIA provides managed cybersecurity for technology, media and creative businesses across Shoreditch, Bethnal Green and the wider East London tech corridor. Coverage includes 24/7 endpoint monitoring, email security, cloud security posture management and Cyber Essentials Plus certification for tech-first firms. Q: What security tools does AMVIA use to protect London businesses? A: We run Microsoft Defender for Endpoint and Defender for Office 365 alongside the Barracuda email and network suite, all monitored by our in-house 24/7 SOC. AMVIA is a Microsoft Solutions Partner, so your environment is secured and managed by Microsoft-certified engineers under one accountable provider. Q: Is AMVIA certified, and can you help us get certified? A: AMVIA holds Cyber Essentials Plus, the UK government-backed standard. We also prepare London clients for their own Cyber Essentials Plus assessment, handling the technical remediation and submission so you meet the certification many City clients and insurers now require. --- # Managed IT Support and Cybersecurity Birmingham URL: https://amvia.co.uk/locations/birmingham Last updated: 2026-08-28 AMVIA delivers managed IT support and cybersecurity to Birmingham and West Midlands businesses - covering IT helpdesk, Microsoft 365, leased lines, VoIP and business mobiles. Support is remote-first with clear SLAs and on-site attendance where it matters. One provider, security-first, with Microsoft-certified engineers accountable for the lot. The numbers that matter: - 1,200+ UK businesses managed by AMVIA - Under 1 hour critical-issue remote response target - 24/7 monitoring and support available ## What managed IT services does AMVIA provide in Birmingham? AMVIA runs the full IT and security stack for Birmingham firms: managed IT support and UK helpdesk, managed cybersecurity, Microsoft 365 security, connectivity and phones. You can take services individually or as one integrated managed contract with a single point of accountability. Birmingham's economy spans manufacturing, automotive supply chains, professional services and a fast-growing tech sector - each with different operational and compliance needs. AMVIA's model flexes to fit, rather than forcing every business onto an identical template. - Managed cybersecurity - 24/7 monitoring, endpoint protection, email security and incident response, built on Microsoft Defender and the Barracuda suite. - Microsoft 365 - deployment, security hardening and ongoing management of your Microsoft 365 environment. - Business connectivity - leased lines and FTTP across Birmingham and the West Midlands, working with regional and national carriers. - VoIP phone systems - cloud phone systems with Birmingham numbers and multi-site support across the region. - Business mobiles - managed mobile and device security for hybrid and field-based teams. - UK IT helpdesk - qualified UK-based engineers providing remote and on-site support across the B, WV and CV postcodes. ## Why do Birmingham businesses need stronger cybersecurity? Cyber risk is now a baseline operating cost, not an edge case. 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and 65% of medium businesses reported a breach or attack (2025/26 edition), according to the UK Government's Cyber Security Breaches Survey 2025. For a regional hub like Birmingham, that exposure scales with every supplier link and client connection. The financial sting is real. The average cost of the most disruptive breach for UK businesses sits around £3,550, and UK firms lost £3.7bn to internet outages in 2023 (Beaming, vendor estimate) - which is why connectivity resilience and security belong in the same conversation. | | UK threat indicator | Figure | Source | Businesses breached or attacked (last 12 months) | 43% | Cyber Security Breaches Survey 2025 | Medium businesses reporting a breach | 65% | Cyber Security Breaches Survey 2025/26 | Average cost of most disruptive breach | £3,550 | - | UK losses to internet outages (2023) | £3.7bn (Beaming, vendor estimate) | - The National Cyber Security Centre recommends layered controls - patching, MFA, monitored endpoints - for exactly this profile of business. AMVIA delivers those controls as a managed service rather than a checklist you have to run yourself. ## How much does IT support cost for a Birmingham business? AMVIA uses fixed monthly per-user pricing, identical to its UK-wide plans - no per-ticket fees and no hidden charges. Birmingham businesses pay the same transparent rate as the rest of the country, with final pricing set by user count and scope. Request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC For context on connectivity costs, a 100 Mbps leased line in urban areas typically runs £240–£320 per month (typical UK 2026 range) before any managed-service wrap - AMVIA prices connectivity separately and transparently alongside support. ## Which areas across the West Midlands does AMVIA cover? AMVIA serves businesses across Birmingham, Solihull, Wolverhampton, Coventry and the wider West Midlands. Support is delivered remote-first across the B, WV and CV postcode areas, with on-site attendance arranged where the issue and your plan call for it. Regional reach, national carrier relationships, one accountable provider. That regional footprint matters for sector-specific work. AMVIA supports West Midlands manufacturing and automotive firms - including businesses supplying Tier 1 automotive clients - that face strict supply-chain security requirements, plus firms in public-sector supply chains who need Microsoft 365 security hardening and Cyber Essentials Plus to win contracts. ## What do Birmingham businesses get with AMVIA? A single security-first provider for the whole IT estate, staffed by Microsoft-certified engineers and backed by a 24/7 in-house SOC. Microsoft 365 licensing is transparent and citable: Business Basic £4.60, Business Standard £9.60 and Business Premium £16.90 per user per month, ex VAT on annual billing, per Microsoft's UK pricing. - One provider for IT, security, connectivity, voice and mobile - fewer suppliers, clearer accountability. - Security-first by default: Microsoft Defender plus Barracuda email and network protection. - UK-based helpdesk with named SLAs and an under-1-hour critical response target. - Compliance support, including Cyber Essentials Plus, for regulated and supply-chain businesses. - Cyber Essentials Plus certified, with an in-house 24/7 SOC. ## Frequently asked questions Q: Which areas around Birmingham does AMVIA support? A: Birmingham, Solihull, Wolverhampton, Coventry and the wider West Midlands. Support is remote-first - most issues resolve fastest that way - with on-site attendance across the region when a job needs an engineer at the desk or in the comms room. Q: Can you support both our manufacturing site and head office? A: Yes - Birmingham's mix of manufacturing, professional services and logistics is exactly the multi-environment profile we run daily: office IT and helpdesk on one side, the connectivity and security around production systems on the other, under one contract. Q: How quickly can a Birmingham business switch to AMVIA? A: Onboarding typically runs a few weeks: audit, documentation, tooling deployment, then cutover - with your old provider's exit period running in parallel. Nothing stops working on switchover day; that's the point of the audit. Q: Do West Midlands businesses get the same pricing as everywhere else? A: Yes - AMVIA's per-user plans (£25/£40/£60 Essentials/Advanced/Enterprise) are UK-wide with no regional weighting. Connectivity is the postcode-dependent part, which we quote per address across every carrier. --- # Cybersecurity Services Birmingham URL: https://amvia.co.uk/locations/birmingham/cybersecurity Last updated: 2026-08-28 AMVIA delivers managed cybersecurity for Birmingham businesses across Colmore Row, Brindleyplace and the Jewellery Quarter - combining 24/7 SOC monitoring, managed detection and response, and email security. We protect 1,200+ UK businesses and run it as one accountable, security-first provider with Microsoft-certified engineers. ## What does AMVIA's managed cybersecurity in Birmingham cover? AMVIA runs a layered managed cybersecurity service for Birmingham and the wider West Midlands: continuous threat monitoring, endpoint protection, email security and certification support. Detection and response are handled from our in-house UK SOC, with on-site assessments arranged across the B, WV and CV postcodes where an engagement needs them. - Endpoint protection built on Microsoft Defender for Endpoint - Email and anti-phishing controls for the region's most common attack vector - Cyber Essentials Plus readiness and certification support - On-site incident attendance across the West Midlands when severity demands it Our security stack is Microsoft Defender plus the Barracuda suite for email and network - no bolt-on third-party agents to manage separately. That single-provider model keeps accountability with one UK team. ## Why do Birmingham businesses need managed security now? The threat level facing West Midlands SMEs is no longer theoretical. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach or attack in the past 12 months - and the figure climbs sharply with company size. The NCSC's guidance for small organisations confirms phishing remains the dominant entry point. | | Metric (UK, 2025) | Figure | Source | Businesses breached in past 12 months | 43% | Cyber Security Breaches Survey 2025 | Medium businesses breached | 65% | Cyber Security Breaches Survey 2025/26 | Large businesses breached | 69% | Cyber Security Breaches Survey 2025/26 | Average cost of most disruptive breach | £3,550 | Cyber Security Breaches Survey 2025 For Birmingham firms supplying the NHS, local government or automotive Tier 1 clients, a breach is not just a cost - it can end a contract. Demonstrable security is increasingly a condition of being on the supplier list. ## What's included in the Birmingham managed security service? Every Birmingham engagement combines around-the-clock monitoring with the controls that stop the most common attacks. The service is delivered remotely from AMVIA's UK SOC, with engineers attending on-site when an incident requires it. ## 24/7 SOC and managed detection and response Our in-house UK SOC monitors Birmingham client environments continuously using Microsoft Defender for Endpoint telemetry. Suspicious activity is investigated and contained as part of the managed detection and response service - see how the 24/7 managed SOC service works for SMEs. ## Email security and anti-phishing We deploy and manage Microsoft Defender for Office 365 alongside the Barracuda email suite to cut phishing and business email compromise risk. Microsoft's own security guidance backs layered email defence as a baseline control. Read more on phishing protection for UK SMEs. ## Certification and compliance support We manage Cyber Essentials Plus readiness end to end - the certification increasingly mandatory for NHS, council and public-sector supply chains in the region. AMVIA supports the wider compliance requirements that follow from those frameworks rather than claiming to award them. ## How much does managed cybersecurity in Birmingham cost? Fixed monthly per-user pricing, identical to AMVIA's UK-wide plans, with no hidden charges. You pick the response target that matches your risk profile and contractual obligations. | | Plan | From / User / Month | Response Target | Out-of-Hours | Essentials (most popular) | from £25.00 | Next business day | Email only | Advanced | from £40.00 | Same day (4hr target) | Phone & email | Enterprise | from £60.00 | 2-hour target | 24/7 dedicated Need Microsoft 365 hardening alongside monitoring? Pair the service with Microsoft 365 security for identity, MFA and Secure Score management. ## Which Birmingham areas and sectors does AMVIA cover? AMVIA serves the full B postcode footprint - from the Colmore Row (B3) and Brindleyplace (B1) commercial core to the Jewellery Quarter (B18) and industrial premises - plus Solihull, Wolverhampton and Coventry across the WV and CV areas. We support professional services, manufacturing and automotive supply-chain firms. - Professional services and financial firms in the central business district - Manufacturing and automotive Tier 1 suppliers needing supply-chain assurance - Public-sector suppliers to NHS trusts and Birmingham City Council - Jewellery Quarter SMEs needing 24/7 monitoring and email security ## Frequently asked questions Q: Do you provide managed cybersecurity across the West Midlands? A: Yes. AMVIA provides managed cybersecurity across the West Midlands, including Birmingham, Solihull, Wolverhampton, Coventry and the wider B, WV and CV postcode areas. Monitoring and response are delivered remotely from AMVIA's in-house UK SOC, with on-site incident support and security assessments arranged where the engagement requires them. Q: Can you respond on-site to cybersecurity incidents in Birmingham? A: Yes. Incident detection and response are handled remotely by AMVIA's UK SOC as part of the managed service. Where an incident requires physical attendance, a visit across Birmingham and the wider West Midlands can be arranged and scheduled according to the severity of the incident and your plan tier. Q: Do you serve businesses supplying to the NHS or Birmingham City Council? A: Yes. AMVIA supports West Midlands businesses with public-sector supply-chain requirements, including NHS trust and local authority procurement frameworks. We manage Cyber Essentials Plus certification, which is increasingly mandatory for NHS and government contracts in the region, and support the compliance evidence those buyers ask for. Q: What cybersecurity coverage do you provide for Birmingham's automotive and manufacturing sector? A: AMVIA provides managed cybersecurity for West Midlands manufacturing and automotive businesses, including supply-chain security assessments and Cyber Essentials Plus certification support. Firms supplying Tier 1 automotive clients often face strict security requirements, and we manage the full monitoring and compliance process so contracts stay protected. Q: Do you serve businesses in Birmingham's Jewellery Quarter? A: Yes. AMVIA serves businesses across Birmingham's Jewellery Quarter (B18) and the wider B postcode area, from the city-centre core to suburban and industrial premises. The managed cybersecurity service includes 24/7 threat monitoring, email security and on-site incident support for Jewellery Quarter businesses. Q: What security tools does AMVIA use to protect Birmingham businesses? A: AMVIA's stack is Microsoft Defender for Endpoint and Office 365 plus the Barracuda email and network suite, monitored by our in-house 24/7 UK SOC. We do not resell a patchwork of third-party agents - one provider runs detection, response and email security, which keeps accountability and response times tight. --- # Managed IT Support and Cybersecurity Bristol URL: https://amvia.co.uk/locations/bristol Last updated: 2026-08-28 AMVIA delivers managed IT support, cybersecurity, leased lines, VoIP and Microsoft 365 to businesses across Bristol and the South West. You get 24/7 monitoring, clear SLAs and a named account manager, delivered remote-first with on-site visits where they matter. One provider, security-first, Microsoft-certified. Key facts: - 1,200+ UK businesses managed by AMVIA - Under 1 hour remote response target for critical issues - 24/7 monitoring and support ## Why do Bristol businesses choose AMVIA for IT support? Bristol firms pick AMVIA because they get one accountable provider for IT, security and connectivity instead of three suppliers blaming each other. We run managed IT support remote-first from a 24/7 operations centre, with engineers who learn your business before they touch a single setting. That model suits a fast-growing city. Bristol has one of the UK's strongest tech, creative and professional-services clusters, and those firms scale quickly - from an early-stage team needing its first professional IT setup to an established practice that requires enterprise-grade security and compliance. We support that growth without forcing every fix into a van journey across the M32. Security sits at the centre of everything we ship because the threat picture demands it. 43% of UK businesses experienced a cyber breach or attack in the last 12 months (gov.uk Cyber Security Breaches Survey 2025). For a Bristol SME, that is not an abstract risk - it is close to a coin-flip every year. ## What managed IT services does AMVIA provide in Bristol? AMVIA provides the full stack a growing Bristol business needs: security, connectivity, voice, Microsoft 365 and day-to-day support. Each service stands alone or combines into one managed agreement with a single SLA and a single point of contact. Here is what you get and where each piece links. - Managed cybersecurity - 24/7 monitoring, endpoint protection, email security and incident response, built on Microsoft Defender and the Barracuda suite, monitored by our in-house SOC. - Microsoft 365 security - deployment, migration, hardening and ongoing management for email, data and Teams. - Business leased lines - dedicated, uncontended FTTP and SD-WAN, delivered over Openreach, CityFibre and other UK carriers serving Temple Quarter and the wider city. - Business VoIP - cloud-hosted phone systems with local Bristol numbers, mobile apps, call recording and Teams integration. - Business mobiles - managed mobile estates with device management and security baked in. - IT helpdesk - a UK-based desk staffed by qualified engineers who know your environment, not an offshore script. ## How fast is broadband and connectivity for Bristol businesses? Connectivity in Bristol is strong and improving, but availability still varies street by street, so a survey before you commit is essential. Gigabit-capable broadband now reaches roughly 87% of UK premises (Ofcom, 2025), and the Openreach FTTP network has passed 20m+ premises as of early 2026 - with Bristol's CityFibre and Openreach footprints expanding across Temple Quarter and the surrounding tech corridor. For businesses that cannot tolerate downtime, a leased line removes the gamble. A dedicated, uncontended line with a guaranteed SLA gives you symmetric speeds and a fix-time commitment that shared broadband cannot match. We check exact availability at your BS or BA postcode before quoting. ## What does managed IT support cost for a Bristol business? Pricing is fixed monthly per user - the same plans AMVIA runs UK-wide, with no hidden charges and no per-ticket fees. The table below shows the three tiers. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Security is built into the higher tiers rather than sold as a bolt-on. Following NCSC small-business guidance, the controls that stop most attacks - patching, MFA, endpoint protection and monitored backups - should be standard, not premium (NCSC Small Business Guide). The risk is real even for mid-sized firms: 65% of medium-sized UK businesses reported a breach or attack last year (DSIT 2025/26) (gov.uk Cyber Security Breaches Survey 2025). ## Which areas around Bristol does AMVIA cover? AMVIA supports businesses across Bristol and the wider South West, delivered remote-first with on-site attendance arranged where appropriate. A single agreement covers multi-site operations without a patchwork of regional suppliers. - Bristol - BS postcodes, including Temple Quarter (BS1) - Bath - BA postcodes - Weston-super-Mare and North Somerset - South Gloucestershire and the wider South West - Multi-site businesses operating across the region ## Frequently asked questions Q: What kinds of Bristol businesses does AMVIA work with? A: Bristol's tech, creative and professional services scene is the core profile - teams that live in the cloud, care about security credentials, and grow fast enough that IT needs to scale without re-procurement every year. Q: Do you cover Bath and the wider South West? A: Yes - Bristol, Bath, Weston-super-Mare and South Gloucestershire across the BS and BA postcode areas, remote-first with on-site visits scheduled by priority when hands-on work is genuinely needed. Q: Our startup is scaling fast - can support keep up? A: That's the design: per-user pricing that scales with headcount month to month, onboarding/offboarding as routine helpdesk work, and security that's in the plan from day one rather than bolted on at Series A due diligence. Q: What connectivity options do Bristol businesses have? A: Strong ones - the CityFibre and Openreach footprints are expanding across Temple Quarter (BS1) and the surrounding tech corridor, with Virgin Media Business across the wider city. We compare every carrier at your exact postcode. --- # Managed IT Support and Cybersecurity Nottingham URL: https://amvia.co.uk/locations/nottingham Last updated: 2026-08-28 AMVIA delivers managed IT support and cybersecurity to businesses across Nottingham and the East Midlands. One security-first provider handles your helpdesk, Microsoft 365, connectivity and phones - proactive monitoring, clear SLAs, and UK-based engineers, remote-first with on-site attendance where the job needs it. - 1,200+ UK businesses managed by AMVIA - Under one hour critical-issue remote response target - 24/7 monitoring and support - Cyber Essentials Plus certified ## What managed IT services does AMVIA provide in Nottingham? AMVIA gives Nottingham businesses a single accountable provider for IT, security and connectivity - no juggling four suppliers when something breaks. We cover the NG, DE and LE postcodes, serving Nottingham, Derby, Leicester and the wider East Midlands from helpdesk to 24/7 security monitoring. Nottingham's economy spans manufacturing, logistics, professional services and a growing creative sector, and each needs IT that fits how it actually works. Our core services include: - Managed IT support - UK helpdesk, monitoring, and patching from Microsoft-certified engineers - Managed cybersecurity - 24/7 detection and response, email and endpoint protection - Microsoft 365 security - deployment, hardening, and ongoing management - Business leased lines - dedicated, uncontended connectivity for the city centre and business parks - Business VoIP - cloud phone systems with Nottingham numbers and full features - Business mobiles - managed contracts and secured devices ## Why does cybersecurity matter for Nottingham businesses? Cyber risk is now a baseline operating cost for any UK firm, not an edge case. 43% of UK businesses reported a cyber security breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey 2025. For a Nottingham SME, a single phishing hit can stop invoicing for days. AMVIA runs a security-first managed service. Our protection stack is built on Microsoft Defender for Endpoint, monitored by AMVIA's in-house 24/7 SOC, plus the Barracuda suite for email and network security. We hold Cyber Essentials Plus, the NCSC-backed certification that proves your controls have been independently tested. For East Midlands manufacturers in national supply chains, that certification is increasingly a condition of winning contracts. ## What does business connectivity cost in Nottingham? Connectivity pricing depends on technology and location. A 100 Mbps leased line starts from around £69 per month with AMVIA, while typical urban market rates run £240–£320 per month depending on provider and contract (typical UK 2026 range), and full-fibre broadband now reaches a large majority of UK premises - around 78% of premises by Q3 2025, according to Ofcom Connected Nations data. Nottingham city centre and most business parks have strong fibre availability. | | Connectivity option | Typical use | Notes | Full-fibre broadband (FTTP) | Small offices, shared use | Widely available across Nottingham | Business leased line | Mission-critical, multi-user | Dedicated, uncontended bandwidth with SLA | Backup / failover circuit | Resilience | Keeps phones and cloud apps online We size connectivity to the workload and pair it with security by default - a fast line that isn't protected is just a faster route in for an attacker. ## How much does managed IT support cost for a Nottingham business? AMVIA uses fixed monthly per-user pricing - the same plans nationwide, with no per-ticket fees or hidden charges. Final pricing depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Microsoft 365 licences sit on top at Microsoft's published list prices - Business Basic £4.60, Standard £9.60, and Premium £16.90 per user per month (ex VAT, annual commitment). ## What do you get with AMVIA in Nottingham? You get one provider, security-first, with Microsoft-certified engineers - accountable for the whole stack rather than passing tickets between suppliers. Every service is available on its own or bundled into an integrated managed plan. - 24/7 monitoring and response - endpoint and email protection that never clocks off - UK helpdesk - qualified engineers, no offshore call centre - Microsoft 365 management - secure configuration, backup, and licensing handled - Connectivity - leased lines and full-fibre across the East Midlands - Compliance support - we support Cyber Essentials, GDPR and supply-chain security requirements - Clear SLAs - response targets in writing, not vague promises ## Frequently asked questions Q: What IT services does AMVIA provide in Nottingham? A: AMVIA provides a full managed IT service for Nottingham businesses: UK helpdesk and IT support, cybersecurity with 24/7 detection and response, business leased lines and full-fibre connectivity, VoIP phone systems, business mobiles, and Microsoft 365 management. Services are available individually or as one integrated, security-first managed plan. Q: Do you serve businesses across the East Midlands? A: Yes. AMVIA serves Nottingham, Derby, Leicester and the wider East Midlands across the NG, DE and LE postcode areas. Support is delivered remote-first, which keeps response times fast, with on-site engineer attendance arranged where the issue and your service plan require a physical visit. Q: How quickly does AMVIA respond to IT issues? A: Response targets depend on your plan. Critical issues carry a remote response target of under one hour, and 24/7 monitoring catches many problems before you notice them. The Advanced plan targets four-hour response and Enterprise targets two hours, with all targets written into your SLA rather than left vague. Q: What cybersecurity does AMVIA provide for Nottingham businesses? A: AMVIA runs a security-first managed service built on Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, with the Barracuda suite securing email and network traffic. We hold Cyber Essentials Plus, the independently tested NCSC-backed certification, and support GDPR and supply-chain security requirements common to East Midlands manufacturers. Q: Does AMVIA hold Microsoft partner status? A: Yes. AMVIA is a Microsoft Solutions Partner across Modern Work, Security, and Infrastructure (Azure), and our engineers are Microsoft-certified. That means your Microsoft 365 deployment, security hardening, and ongoing management are handled by accredited specialists rather than generalists, with licensing supplied at Microsoft's published UK list prices. Q: How much does managed IT support cost for a Nottingham business? A: AMVIA uses fixed monthly per-user pricing, identical to its UK-wide plans, with no per-ticket fees. Plans scale from a helpdesk-and-monitoring tier up to a 24/7 SOC tier, and Microsoft 365 licences are added at Microsoft's published list prices. Final cost depends on user count and scope, so request a quote for an exact figure. --- # Managed IT Support and Cybersecurity York URL: https://amvia.co.uk/locations/york Last updated: 2026-08-28 AMVIA delivers managed IT support across York and North Yorkshire - one provider running your helpdesk, cybersecurity, Microsoft 365, connectivity and phones. We support 1,200+ UK businesses with 24/7 monitoring and sub-hour critical response. One provider, security-first, Microsoft-certified, and accountable for your whole IT estate. - 1,200+ UK businesses managed by AMVIA - critical-issue remote response time - 24/7 monitoring and support ## What does AMVIA's managed IT support cover in York? AMVIA gives York businesses a single accountable provider for every layer of IT - instead of juggling a helpdesk vendor, a security supplier and a telecoms reseller. Our managed IT support wraps proactive monitoring, patching and a UK helpdesk around a security-first core, so one team owns the outcome. What a York business gets: - Helpdesk and monitoring - UK-based engineers, proactive patching, 24/7 alerting - Managed cybersecurity - Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC, plus Barracuda email and network protection - Microsoft 365 management - migration, hardening, licensing and day-to-day admin - Business connectivity - leased lines and full-fibre broadband for York city-centre and North Yorkshire sites - VoIP phone systems - cloud phones with York numbers and Microsoft Teams calling - Business mobiles - managed SIMs and mobile device management ## Why do York businesses need security-first IT support? Cyber risk is the reason "IT support" and "security" can no longer be bought separately. The UK Government's Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months - a board-level risk, not an IT footnote. The wider picture for UK SMEs: - 43% of UK businesses suffered a breach or attack in the past 12 months (Cyber Security Breaches Survey 2025, DSIT) AMVIA holds Cyber Essentials Plus and builds every York engagement around the NCSC's small business security guidance. Security is the default, not an upsell. ## How much does managed IT support cost in York? AMVIA uses fixed monthly per-user pricing - the same plans nationwide, with no per-ticket charges and no hidden fees. York businesses pick the tier that matches their risk and response needs; final cost depends on user count and scope. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + managed cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Microsoft 365 licences sit on top at Microsoft's UK list prices - Business Basic £4.60, Standard £9.60 and Premium £16.90 per user per month (Microsoft 365 UK pricing). ## Which York sectors does AMVIA support? AMVIA supports York's mix of professional services, heritage and tourism, and growing technology firms. Each has a different risk profile - a law firm guards client confidentiality, a tourism business needs uptime through peak season - and a security-first managed provider tunes controls to fit. - Professional services - accountancy, legal and financial firms in and around York city centre that need data protection and compliance support - Heritage and tourism - visitor-facing businesses that cannot afford downtime in summer and event seasons - Technology and growth - scaling teams that need IT to keep pace without adding internal headcount ## What connectivity and phone options are available in York? York and North Yorkshire businesses can move to full-fibre and cloud telephony today. Ofcom reports 78% of UK premises now have full-fibre (FTTP) coverage as of 2025, and AMVIA pairs that connectivity with secured VoIP so your network and phones come from one provider. - Leased lines - guaranteed-bandwidth dedicated internet for York HQ and multi-site businesses - Full-fibre broadband - high-speed FTTP where leased lines aren't required - VoIP and Teams calling - keep your York numbers, add Microsoft Teams direct routing ## Frequently asked questions Q: What IT services does AMVIA provide in York? A: AMVIA provides a full managed IT service for York businesses: UK helpdesk and proactive monitoring, managed cybersecurity (24/7 SOC, endpoint and email protection), business leased lines and full-fibre, VoIP phone systems, business mobiles, and Microsoft 365 management. Take services individually or as one integrated, security-first managed contract. Q: Do you serve businesses across North Yorkshire? A: Yes. AMVIA serves York, Harrogate, Scarborough and the wider North Yorkshire region. Support is delivered remote-first across the YO and HG postcode areas, with on-site attendance arranged where the issue and your plan require it. You get the same UK engineers and response targets wherever you are based. Q: Do you support York's professional services and heritage businesses? A: Yes. AMVIA manages IT for York's professional services community - accountancy, legal and financial firms in and around the city centre - where data protection and compliance matter. We also support heritage and tourism operators that depend on reliable systems through peak visitor seasons and busy event calendars. Q: How much does IT support cost for a York business? A: AMVIA's managed IT support starts from £25 per user per month on Essentials, with Advanced and Enterprise tiers adding faster response targets and a 24/7 SOC. Pricing is fixed monthly per user with no per-ticket fees. Final cost depends on user count and scope - request a quote for an exact figure. Q: Is cybersecurity included or extra? A: Security is built in, not bolted on. Every AMVIA plan runs on a security-first foundation - Microsoft Defender for Endpoint monitored by our in-house 24/7 SOC, plus Barracuda email and network protection. Advanced and Enterprise tiers add deeper managed cybersecurity. AMVIA holds Cyber Essentials Plus and aligns controls with NCSC guidance. Q: How quickly can AMVIA respond to a critical issue? A: AMVIA targets a sub-one-hour remote response for critical issues, with monitoring running 24/7. Response targets are set by plan: next business day on Essentials, four hours on Advanced and two hours on Enterprise. Critical incidents are escalated immediately regardless of plan, so York businesses are never left waiting on a serious outage. --- # Managed IT Support and Cybersecurity Edinburgh URL: https://amvia.co.uk/locations/edinburgh Last updated: 2026-08-28 AMVIA provides managed IT support, cybersecurity and Microsoft 365 services to businesses across Edinburgh and the Lothians. You get one accountable provider, a UK-based helpdesk staffed by Microsoft-certified engineers, and a 24/7 security operations centre. One provider, security-first, with fixed monthly per-user pricing and no per-ticket fees. ## What managed IT support does AMVIA provide in Edinburgh? AMVIA runs the whole IT and security stack for Edinburgh businesses under one contract: helpdesk, patching, monitoring, cybersecurity and Microsoft 365. We are a security partner first, not a telecoms reseller, so protection is built into every layer rather than bolted on afterwards. Explore our managed IT support pillar for the full scope. Most Edinburgh clients come to us tired of juggling three or four suppliers who each blame the other when something breaks. We consolidate that into a single team that owns the outcome - the network, the laptops, the email security and the phones. ## What is the cyber risk picture for Edinburgh businesses? Edinburgh's concentration of financial services, professional firms and universities makes it a high-value target for phishing and ransomware. The national data backs that up. These figures come from the UK Government's annual breaches research and frame why a security-first approach matters for any EH-based business. - 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months (DSIT Cyber Security Breaches Survey 2025) - 85% of breaches involved phishing (DSIT 2025) Phishing is the front door for most of these incidents, which is why the National Cyber Security Centre treats email defence and staff awareness as baseline controls. You can read the full Government dataset in the Cyber Security Breaches Survey 2025. AMVIA's email and endpoint defences are built on the Microsoft Defender and Barracuda stack, monitored around the clock by our in-house SOC. ## What do Edinburgh businesses get with AMVIA? Edinburgh clients get a single integrated managed service, or any individual component, delivered by one team. Each service is designed to interlock with the others so security, identity and connectivity are managed as one system rather than disconnected products from competing vendors. - Managed cybersecurity - 24/7 monitoring, endpoint detection and incident response through our managed cybersecurity service. - Microsoft 365 security - deployment, migration and hardening via Microsoft 365 security, run by Microsoft Solutions Partner engineers. - Business connectivity - business leased lines, FTTP and SD-WAN with guaranteed bandwidth for Edinburgh offices. - VoIP phone systems - cloud-hosted business VoIP with Edinburgh numbers and CRM integration. - Business mobiles - managed business mobile connectivity with device security built in. - IT helpdesk - UK-based engineers who learn your environment and answer in plain English. Openreach's full-fibre network has now passed more than 20m UK premises (September 2025), so most Edinburgh business parks and city-centre offices can move onto resilient FTTP or a dedicated leased line without a long civils wait. ## How much does managed IT support cost in Edinburgh? AMVIA's managed IT support for Edinburgh businesses starts from £25 per user per month on the Essentials plan, with fixed monthly per-user pricing and no per-ticket fees. Pricing matches our UK-wide plans; final cost depends on user count and scope, so request a quote for an exact figure. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC ## Does AMVIA support Edinburgh's financial services and public sector? Yes. AMVIA supports Edinburgh asset managers, insurers and professional services firms with the security controls and certification they need, and helps public-sector suppliers meet procurement requirements. We hold Cyber Essentials Plus, the certification most Scottish public bodies expect from their IT and data suppliers. For regulated financial firms, we support FCA operational resilience compliance with documented controls, monitoring and incident response. For suppliers bidding into the Scottish Government, NHS Scotland or local authority contracts, we manage the full Cyber Essentials certification process, including the technical remediation needed to pass. You can check the baseline requirements on the Cyber Essentials scheme page. ## Which areas of Edinburgh does AMVIA cover? AMVIA serves businesses across the EH postcode area and the wider Lothians, including Leith (EH6), Edinburgh Park (EH12) and the city centre. Support is remote-first, with on-site attendance arranged where the issue and your plan require it, so response times do not depend on an engineer being in the building. ## Frequently asked questions Q: Does AMVIA cover Edinburgh and the Lothians? A: Yes - Edinburgh and the surrounding Lothians, delivered remote-first with on-site attendance where a job needs it. One accountable provider for IT, security, Microsoft 365 and connectivity. Q: How does remote-first support work for a Scottish business with an English provider? A: Distance is irrelevant for the 90%+ of issues that resolve remotely - response targets are the same UK-wide. For the remainder (hardware, network faults, office moves), visits are scheduled by priority and plan, exactly as they would be from a local firm. Q: What's Edinburgh's connectivity picture like? A: One of the better ones in the UK: a well-developed CityFibre footprint runs alongside Openreach full fibre in many postcodes - from the city centre and Leith to Haymarket - and that dual-network competition helps pricing. We compare both for your address. Q: Can you handle compliance requirements for financial services firms? A: Yes - practitioner support for the security controls regulated firms need to evidence: monitoring, access control, incident response and the documentation behind them. AMVIA holds Cyber Essentials Plus and prepares clients for their own certification. --- # Managed IT Support and Cybersecurity Glasgow URL: https://amvia.co.uk/locations/glasgow Last updated: 2026-08-28 AMVIA delivers managed IT support to Glasgow businesses with 10 to 500 staff: 24/7 cybersecurity monitoring, Microsoft 365 management, business connectivity, VoIP and a UK-based helpdesk. You get one accountable provider that puts security first and staffs the desk with Microsoft-certified engineers - not a telecoms reseller. We support more than 1,200 UK businesses, hold Cyber Essentials Plus, and are a Microsoft Solutions Partner for Modern Work, Security and Infrastructure. If you run a Glasgow business and want IT and security under one roof, start with our managed IT support service or browse every UK location we cover. ## What IT services does AMVIA provide in Glasgow? AMVIA runs a full managed IT stack for Glasgow businesses - security, connectivity, telephony and Microsoft 365 - delivered as one service or picked individually. Every service is monitored from our in-house SOC and backed by per-user pricing with no per-ticket fees, so your costs stay predictable as you grow. - Managed cybersecurity - 24/7 monitoring, Microsoft Defender for Endpoint, email and network protection, and incident response. See our managed cybersecurity service. - Business connectivity - leased lines, FTTP and SD-WAN with guaranteed bandwidth for Glasgow sites. See business leased lines. - VoIP phone systems - cloud-hosted phones with Glasgow numbers, Microsoft Teams calling and CRM integration. See business VoIP. - Microsoft 365 security - deployment, migration, hardening and ongoing management. See Microsoft 365 security. - IT helpdesk - UK-based, staffed by qualified engineers who learn your environment. - Compliance support - practical guidance that supports Cyber Essentials and regulated-sector requirements. ## Why does cyber risk matter for Glasgow businesses? Cyber risk is now a baseline operating cost, not an edge case. 43% of UK businesses experienced a cyber breach or attack in the last 12 months, according to the Cyber Security Breaches Survey 2025. That is why AMVIA leads every Glasgow engagement with security rather than bolting it on later. The wider numbers back the same point. UK businesses lost an estimated £3.7bn to internet outages in 2023 (Beaming, 2023), and 87% of UK premises now have gigabit-capable broadband (Ofcom, 2025) - so the connectivity is there, but resilience and protection are where most firms are exposed. The National Cyber Security Centre sets the baseline controls we build every Glasgow client up to. ## What does managed IT support cost in Glasgow? AMVIA's managed IT support for Glasgow starts from £25 per user per month, with fixed per-user pricing and no per-ticket fees. Three plans scale by response target and depth of security, and Glasgow pricing matches AMVIA's UK-wide rates. Final figures depend on user count and scope. | | Plan | From / user / month | Response target | Includes | Essentials | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Pricing is the same per-user model across every plan, so you only step up when you need a faster response target or 24/7 SOC cover - request a quote for an exact figure against your headcount. ## Which Glasgow areas and sectors does AMVIA cover? AMVIA serves businesses across Greater Glasgow and the wider G and ML postcode areas, including Lanarkshire, East Renfrewshire and Renfrewshire. Support is remote-first across those postcodes, with on-site attendance arranged where the issue and your plan call for it. We have specific experience with financial services, professional services and technology firms in Glasgow's International Financial Services District (G1–G2) and Finnieston. For regulated clients we support FCA compliance, handle security certification, and manage the IT requirements that come with Scottish public sector and NHS Greater Glasgow and Clyde supply-chain procurement. ## Frequently asked questions Q: What size of Glasgow business does AMVIA support? A: The published range is 10 to 500 staff - big enough that IT failures cost real money, small enough that a full in-house team doesn't make sense. Both fully managed and co-managed models are available. Q: Do you have engineers in Glasgow? A: Support is remote-first from AMVIA's UK team - which is how the sub-one-hour critical response works - with on-site attendance arranged across Glasgow and the west of Scotland when hardware or network jobs need it. We don't claim a local office; we claim the response targets. Q: Which networks serve Glasgow for business connectivity? A: CityFibre's expanding Scottish network, Virgin Media Business and the Openreach footprint - most Glasgow postcodes have genuine multi-carrier choice, which we compare at your exact address for leased lines and broadband. Q: What does switching IT provider involve for a Glasgow business? A: An audit first, then a documented handover running alongside your incumbent's notice period: tooling deployed, credentials transferred, users unaffected. The switch is a project we run, not a leap you take. --- # Managed IT Support and Cybersecurity Cardiff URL: https://amvia.co.uk/locations/cardiff Last updated: 2026-08-28 AMVIA delivers managed IT support to Cardiff and South Wales businesses: 24/7 security monitoring, a UK-based helpdesk, Microsoft 365 management, connectivity and VoIP from one accountable provider. Engineers fix critical issues remotely, on-site where the job needs it. One provider, security-first, Microsoft-certified - not a generic support script. 1,200+ UK businesses managed by AMVIA · critical-issue remote response · 24/7 monitoring and support ## What does AMVIA's managed IT support in Cardiff include? AMVIA gives Cardiff businesses a single provider for the whole IT stack: helpdesk and proactive monitoring, managed cybersecurity, Microsoft 365, connectivity, and phone systems. You get clear SLAs, fixed per-user pricing, and UK engineers who learn your business before they touch it. - Managed cybersecurity - 24/7 monitoring, endpoint protection and incident response via our managed cybersecurity service. - Microsoft 365 - deployment, migration and hardening through Microsoft 365 security management. - Business connectivity - leased lines and FTTP with guaranteed bandwidth for Cardiff offices. - Phone systems - cloud-hosted business VoIP with Cardiff numbers and CRM integration. - Mobile - business mobiles and managed devices for hybrid teams. - Helpdesk - a UK-based IT helpdesk staffed by qualified engineers. This is the core of our managed IT support offer, delivered the same way to every Cardiff client. ## Why do Cardiff businesses need stronger cybersecurity? The threat picture for UK SMEs is not abstract. National data shows breaches are common, phishing dominates as the entry point, and recovery is slow and expensive - which is why security sits at the centre of every plan AMVIA runs, not bolted on afterwards. - 43% of UK businesses experienced a cyber security breach or attack in the past 12 months (Cyber Security Breaches Survey 2025). - 85% of businesses that identified a breach pointed to phishing as the attack type (Cyber Security Breaches Survey 2025). AMVIA holds Cyber Essentials Plus, the government-backed standard for baseline cyber hygiene (Cyber Essentials scheme). For practical hardening guidance, the NCSC's small business advice is the authority we point Cardiff clients to. ## How fast does AMVIA respond to Cardiff IT issues? Response is tiered by plan, not left to chance. Critical issues get a remote response in under an hour, with on-site attendance across the CF and SA postcode areas where the fault genuinely needs hands on hardware. Monitoring runs 24/7, so many problems are caught before you notice them. Support is remote-first, which keeps response fast and predictable. On-site visits are arranged when the issue and your plan call for it - no waiting on a regional engineer rota. ## How much does managed IT support cost in Cardiff? AMVIA uses fixed monthly per-user pricing, the same as our UK-wide plans. No per-ticket fees, no surprise charges. Cardiff businesses choose the tier that matches the response time and security depth they need. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Final pricing depends on user count and scope. Request a quote for an exact figure. ## Which areas of South Wales does AMVIA cover? AMVIA serves Cardiff and the wider South Wales region, including Newport, Swansea and the surrounding CF and SA postcode areas. Coverage is delivered remote-first, with on-site attendance arranged where the issue and your plan require it, so distance never slows down a fix. We support Cardiff's growing technology and digital sector alongside the city's established professional-services base, tailoring the managed service to each. ## Frequently asked questions Q: What IT services does AMVIA provide in Cardiff? A: AMVIA provides a full range of managed IT services for Cardiff businesses: managed IT support and helpdesk, cybersecurity including managed detection and email security, business leased lines, VoIP phone systems, and Microsoft 365 management. Each service is available individually or as one integrated managed service from a single provider. Q: Do you serve businesses across South Wales? A: Yes. AMVIA serves Cardiff and South Wales, including Newport, Swansea and the surrounding CF and SA postcode areas. Support is delivered remote-first across these areas, with on-site attendance arranged where the issue and your plan make a visit the right call. Q: Does AMVIA support Cardiff's growing tech sector? A: Yes. AMVIA supports Cardiff's technology and digital sector as well as the city's professional-services community. We understand the IT and security requirements of Cardiff's diverse business base and tailor our managed services to each organisation rather than applying a one-size template. Q: How much does IT support cost for a Cardiff business? A: AMVIA's managed IT support for Cardiff starts from £25 per user per month on the Essentials plan. Advanced adds a 4-hour response target; Enterprise adds a 2-hour target and 24/7 support. Pricing matches our UK-wide plans, with fixed per-user costs and no per-ticket fees. Request a quote for an exact figure. Q: Is AMVIA's IT support secure by default? A: Yes. Security is built into every plan, not sold as an add-on. AMVIA holds Cyber Essentials Plus, the UK government-backed baseline standard, and runs 24/7 monitoring with endpoint protection and incident response. That security-first approach is the core reason Cardiff businesses consolidate IT and security under one provider. --- # Managed IT Support and Cybersecurity Liverpool URL: https://amvia.co.uk/locations/liverpool Last updated: 2026-08-28 AMVIA gives Liverpool businesses one security-first provider for managed IT support, managed cybersecurity, Microsoft 365, leased lines and VoIP. You get proactive monitoring, clear SLAs and UK-based engineers - delivered remote-first, with on-site attendance across Merseyside when a job needs hands on the hardware. Why Liverpool businesses choose AMVIA: - 1,200+ UK businesses managed by AMVIA - Under one hour critical-issue remote response time - 24/7 monitoring and support - Microsoft-certified engineers, Cyber Essentials Plus certified ## What IT services does AMVIA provide in Liverpool? AMVIA runs the full IT and security stack for Liverpool firms: helpdesk and managed IT support, 24/7 cybersecurity monitoring, Microsoft 365 security, connectivity and phones. One provider, one bill, one accountable team - instead of three vendors blaming each other when something breaks. | | Service | What Liverpool businesses get | Managed cybersecurity | 24/7 monitoring, Microsoft Defender for Endpoint, Barracuda email and network protection, incident response | Business connectivity | Business leased lines, FTTP and SD-WAN with guaranteed bandwidth and uptime SLAs | VoIP phone systems | Cloud-hosted business VoIP with Liverpool numbers and CRM integration | Microsoft 365 security | Deployment, migration, hardening and ongoing management as a Microsoft Solutions Partner | IT helpdesk | UK-based desk staffed by qualified engineers, no per-ticket fees | Compliance support | Practical guidance that supports Cyber Essentials and GDPR compliance ## Why does cybersecurity matter for Liverpool SMEs? Cyber risk is now an operational cost, not a hypothetical. 43% of UK businesses experienced a cyber breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey 2025. For a growing Liverpool SME, a single incident stalls billing, fulfilment and client trust at once. - 43% of UK businesses hit by a breach or attack in 2025 (DSIT) - £3,550 average cost of the most disruptive breach for UK businesses - More than half of UK small businesses increased their cybersecurity spending (2024 UK market data) AMVIA's security-first approach means monitoring, endpoint protection and email filtering are built into the managed service - not sold as an upsell after a breach. ## Do you serve businesses across Merseyside? Yes. AMVIA serves Liverpool, Wirral, St Helens and the wider Merseyside area. We provide remote support and on-site engineering across the L and CH postcode areas, covering Liverpool city centre, the Baltic Triangle and surrounding commercial districts. Remote-first keeps response times fast; engineers attend in person when the work demands it. The region's connectivity is now strong enough to underpin cloud-first IT. Around 78% of UK premises had full-fibre (FTTP) coverage in Q3 2025, and 87% had gigabit-capable broadband, per Ofcom (Q3 2025 UK data). AMVIA designs your connectivity and security together so faster lines do not widen your attack surface. ## How much does IT support cost for a Liverpool business? AMVIA uses fixed monthly per-user pricing, the same as our UK-wide plans - no hidden charges and no per-ticket fees. Liverpool businesses choose the tier that matches the response time and security depth they need, and final pricing depends on user count and scope. | | Plan | From / user / month | Response target | Includes | Essentials (most popular) | from £25.00 | Next business day | Helpdesk, monitoring, patching | Advanced | from £40.00 | 4-hour target | Essentials + cybersecurity | Enterprise | from £60.00 | 2-hour target | Advanced + 24/7 SOC Request a quote for an exact figure based on your team size. ## Frequently asked questions Q: What IT services does AMVIA provide in Liverpool? A: AMVIA provides a full range of managed IT services for Liverpool businesses: managed IT support and helpdesk, cybersecurity monitoring and email security, business leased lines, VoIP phone systems, and Microsoft 365 management. Take services individually or as one integrated managed service from a single accountable provider. Q: Do you serve businesses across Merseyside? A: Yes. AMVIA serves Liverpool, Wirral, St Helens and the wider Merseyside area. Our team provides remote support and on-site engineering across the L and CH postcode areas, covering Liverpool city centre, the Baltic Triangle and surrounding commercial districts. Q: Do you support Liverpool's creative and digital businesses in the Baltic Triangle? A: Yes. AMVIA supports technology, creative and digital businesses across Liverpool's Baltic Triangle and city centre. We understand the IT and security needs of the city's growing digital sector and tailor managed services to the operational demands and budgets of SMEs in this community. Q: What cybersecurity does AMVIA use to protect Liverpool businesses? A: AMVIA's security stack is built on Microsoft Defender for Endpoint and the Barracuda suite for email and network protection, monitored 24/7 by AMVIA's in-house team. As a Cyber Essentials Plus certified Microsoft Solutions Partner, we layer endpoint protection, email filtering and incident response into the managed service rather than selling them after an incident. Q: How much does IT support cost for a Liverpool business? A: AMVIA's managed IT support for Liverpool businesses uses fixed monthly per-user pricing across three tiers, the same as our UK-wide plans. Higher tiers add faster response targets and deeper security, up to a 24/7 SOC. There are no per-ticket fees; final pricing depends on user count and scope, so request a quote for an exact figure. --- # What Is Ransomware and How Does It Affect UK Businesses? URL: https://amvia.co.uk/cybersecurity/questions/what-is-ransomware Last updated: 2026-03 Ransomware is malicious software that encrypts your files and demands a payment - usually in cryptocurrency - in exchange for the decryption key. Modern strains add "double extortion": attackers steal your data before encrypting it, then threaten to leak it. For UK businesses, layered prevention is far cheaper than recovery, which is why AMVIA runs security-first managed cybersecurity. ## How does ransomware actually work? Ransomware works in stages: it gains access, spreads quietly, then encrypts. Once inside a network it locates valuable files - documents, databases, backups - encrypts them with a key only the attacker holds, and drops a ransom note. Double-extortion strains exfiltrate that data first, so paying never guarantees it stays private. The mechanics matter because they tell you where to break the chain. The earlier you detect the intrusion, the cheaper it is to stop. By the time files are being encrypted, you are already in incident-response territory rather than prevention. That is the entire argument for continuous monitoring through endpoint detection and response rather than relying on antivirus alone. ## How does ransomware get into a UK business network? The most common entry points are phishing emails with malicious attachments or links, exposed Remote Desktop Protocol (RDP) services, and unpatched software vulnerabilities. Phishing dominates: 85% of businesses that experienced a breach identified phishing as the attack type (Cyber Security Breaches Survey 2025), which is why email is the single most important control to harden. That makes email security your first line of defence. AMVIA combines Microsoft Defender with the Barracuda email suite to filter malicious attachments and links before they reach an inbox, backed by DMARC, SPF and DKIM authentication to block spoofing. According to the NCSC, keeping software patched and disabling unused remote-access services closes the other two main routes attackers use. - Phishing emails - malicious links and attachments delivered to staff inboxes. - Exposed RDP - internet-facing remote desktop with weak or reused passwords. - Unpatched software - known vulnerabilities attackers scan for and exploit. - Stolen credentials - reused passwords bought on criminal marketplaces. ## How bad is the ransomware threat to UK businesses? Ransomware is rising sharply. It hit around 1% of all UK businesses in each of the last two survey years (DSIT Cyber Security Breaches Survey 2025 and 2025/26). Encryption outcomes are getting worse too: 70% of UK ransomware attacks resulted in data being encrypted, up from 46% in 2024 (2025 UK market data). The trend line is the point - this is no longer a large-enterprise problem. The financial impact lands hardest on smaller organisations without tested recovery. The average cost of the most disruptive breach is £3,550 (DSIT 2025), but a full ransomware event - downtime, recovery, lost revenue, regulatory exposure - runs far higher. The Cyber Security Breaches Survey 2025 shows phishing and ransomware remain the dominant threats facing UK businesses of every size. ## How do you protect your business from ransomware? Effective ransomware protection is layered - no single control is enough. The goal is defence in depth: stop most attacks at the email gateway, detect the rest at the endpoint, and guarantee recovery with backups you have actually tested. AMVIA delivers all of this from one accountable provider. - Email security - advanced filtering plus DMARC/SPF/DKIM authentication cuts the most common delivery route. See email security. - Endpoint detection (EDR) - Microsoft Defender for Endpoint watches device behaviour in real time, catching ransomware before it encrypts, even when the malware is brand new. - Tested, immutable backups - air-gapped backups, tested regularly, are your last line of defence. Microsoft 365 backup protects cloud data that native retention does not. - Staff awareness - training people to spot phishing reduces the chance of initial access. - Patch management - updating software and operating systems closes the vulnerabilities ransomware uses to spread. - 24/7 monitoring - AMVIA's in-house SOC detects ransomware activity in its early stages, before encryption begins, enabling rapid managed detection and response. ## Should you pay a ransomware demand? Pay vs recover vs prevent You should not pay. UK law enforcement and the NCSC advise against paying ransoms - payment does not guarantee recovery, funds criminal groups, and marks you as a willing payer for future attacks. The economics are stark once you compare paying, recovering without backups, and preventing the attack outright. | | Factor | Pay Ransom £50K–£500K+ | Recover (No Backup) £20K–£200K+ | Prevent (Managed) £15–£25/user/month | Data recovered | Maybe (no guarantee) | Partial | N/A - attack prevented | Downtime | Days to weeks | Days to weeks | Minimal | Legal/regulatory risk | High | High | Low | Reputational damage | Significant | Significant | None | Funds future attacks | Yes | No | No Note: ransom amounts and recovery costs vary significantly with business size and attack severity. The managed-prevention figure is the only one you control in advance - and it is a fraction of the alternatives. ## What should you do if you are hit by ransomware? Isolate first, then escalate. Disconnect affected devices from the network to stop the spread, but do not power them off - volatile memory can hold evidence. Engage incident response specialists immediately, preserve logs, and begin recovery from your most recent tested backup rather than negotiating with attackers. Reporting matters too. UK businesses should report ransomware to Action Fraud and the NCSC, and notify the ICO within 72 hours if personal data is affected. A rehearsed plan turns a crisis into a procedure - which is exactly what AMVIA's 24/7 SOC and incident-response process exist to provide. ## Frequently asked questions Q: Should my business pay a ransomware demand? A: No. The NCSC and UK law enforcement advise against paying. Payment does not guarantee data recovery, funds criminal organisations, and marks your business as a willing payer for future attacks. Focus instead on restoring from tested backups and engaging incident-response specialists - a tested recovery plan is far more reliable than attacker cooperation. Q: How does ransomware typically enter a business network? A: The most common entry points are phishing emails with malicious attachments or links, exposed Remote Desktop Protocol (RDP) services, and unpatched software vulnerabilities. With 85% of businesses that experienced a breach identifying phishing as the attack type (Cyber Security Breaches Survey 2025), email security and staff awareness training are your most important preventive controls. Q: What role do backups play in ransomware recovery? A: Tested, immutable backups stored separately from your production network are the primary recovery mechanism after an attack. Without them, businesses face paying the ransom or permanently losing data. Backups must be tested regularly - untested backups frequently fail during real recovery. Organisations with verified backups recover faster and at lower cost. Q: Is antivirus enough to stop ransomware? A: No. Traditional signature-based antivirus only recognises known threats, and modern ransomware is often brand new or modified to evade signatures. Endpoint detection and response (EDR) monitors device behaviour in real time, catching the encryption activity itself rather than waiting to match a signature. EDR plus email filtering is the practical baseline. Q: How is double-extortion ransomware different? A: Double-extortion ransomware steals your data before encrypting it, then threatens to publish the stolen information if you do not pay - even if you can restore from backup. It defeats a backup-only strategy because the data exposure has already happened. This is why prevention and early detection, not just recovery, are essential. Q: Are small UK businesses really a target for ransomware? A: Yes. Attackers automate scanning for exposed services and weak credentials, so smaller organisations with limited defences are frequently hit precisely because they are easier to compromise. The Cyber Security Breaches Survey 2025 shows ransomware affecting businesses of every size, and smaller firms without tested backups feel the impact hardest. --- # How to Prevent Ransomware Attacks on Your Business URL: https://amvia.co.uk/cybersecurity/questions/how-to-prevent-ransomware Last updated: 2026-03 Prevent ransomware by layering controls that block, detect, and recover: advanced email filtering, multi-factor authentication, fast patching, endpoint detection and response, and immutable offsite backups. No single tool stops every attack - defence in depth does. AMVIA runs this stack as one accountable, security-first, Microsoft-certified provider. Ransomware is the threat that turns a routine Tuesday into a board-level crisis. It encrypts your files, halts trading, and often steals data before the lock screen even appears. The good news for UK SMEs is that the controls that stop it are well understood, affordable, and mostly things you should be doing anyway. This guide walks through what actually works, in priority order, and where the common gaps sit. It sits under our managed cybersecurity pillar, where we cover the wider security programme these controls plug into. If you only take one idea away: ransomware prevention is not a product you buy, it is a set of layers you maintain. Attackers look for the weakest one. Your job is to make sure none of them is missing. ## What is the single most important step to prevent ransomware? The single most important step is removing the easy ways in: enforce multi-factor authentication on every account, and filter email aggressively. The overwhelming majority of attacks start with a stolen password or a malicious email, so closing those two doors blocks most opportunistic ransomware before it ever runs. Phishing is the dominant entry route. 85% of businesses that experienced a breach identified phishing as the attack type (Cyber Security Breaches Survey 2025, DSIT) - see the official UK survey. MFA neutralises the second route: even when a password leaks, the attacker cannot log in without the second factor. These two controls cost little and stop a disproportionate share of attacks, which is why we treat them as non-negotiable on every account, not just admin ones. ## How does layered ransomware protection actually work? Layered protection means stacking controls so that if one fails, the next catches the attack. A malicious email gets filtered; if it slips through, MFA stops the credential theft; if access still happens, EDR spots the encryption behaviour; and if everything fails, immutable backups let you recover without paying. Each layer covers the others' blind spots. Here are the core layers we recommend for UK SMEs, in order of priority: - Advanced email filtering - scans attachments and links in real time and blocks the malicious payloads ransomware crews rely on. Pair it with DMARC and DKIM to cut spoofed email reaching staff. This is the heart of our email security service. - Multi-factor authentication - the single most effective control against credential-based access. Compromised passwords become useless without the second factor. - Patch management - high and critical patches applied within 14 days close the known vulnerabilities attackers exploit. Fourteen days is the Cyber Essentials standard, and unsupported software should be removed or isolated. - Endpoint detection and response (EDR) - detects ransomware behaviour such as mass file encryption and unusual process activity, then terminates the process before damage spreads. This underpins our endpoint security and 24/7 detection work. - Immutable offsite backups - stored where ransomware cannot reach or modify them, these are your guaranteed recovery path. Test them regularly. - Security awareness training - staff who recognise phishing trigger fewer infections. Simulated phishing campaigns find and train the most vulnerable users. The order matters. Email filtering and MFA stop the most attacks for the least money. Backups are the safety net that decides whether an incident is an inconvenience or an existential threat. ## Why is signature-based antivirus not enough? Signature-based antivirus only blocks malware it already recognises. Modern ransomware mutates constantly and is increasingly built to disable or bypass traditional antivirus altogether. Behavioural detection through EDR is the more robust layer because it watches what software does - mass encryption, privilege escalation - rather than matching a known fingerprint. The table below shows why basic antivirus leaves dangerous gaps, and what a full ransomware defence stack adds. | | Control | Antivirus Only (signature-based) | Layered Protection (full ransomware defence) | Known malware blocked | Yes | Yes | Phishing emails filtered | No | Yes | MFA enforced on all accounts | No | Yes | Behavioural / ransomware detection | No | Yes | Patches managed and enforced | No | Yes | Immutable backup for recovery | No | Yes | Staff phishing training | No | Yes If your defence stops at antivirus, you are protected against yesterday's threats and exposed to today's. The NCSC's ransomware guidance makes the same point: prevention depends on a combination of controls, not a single product. ## What should you do if you are hit despite prevention? If ransomware gets through, do not pay and do not improvise. Isolate affected devices from the network immediately, preserve evidence, identify the entry point, and recover from clean immutable backups. A rehearsed incident response plan turns a panicked scramble into a controlled process - which is exactly why the plan must exist before the attack, not after. Prevention and response are two halves of the same job. The fastest, cheapest recoveries we see are at organisations that had isolated backups and a tested plan ready to go. Our incident response team handles containment and recovery, and for the backups themselves, Microsoft 365 backup protects the data most SMEs forget is not backed up by default. If you want to understand the threat itself in more depth, start with what is ransomware. ## How much does ransomware actually cost a UK business? The direct ransom is often the smaller number. The average cost of the most disruptive breach is £3,550 (Cyber Security Breaches Survey 2025, DSIT), but that headline figure hides downtime, lost orders, recovery labour, and reputational damage that can run far higher for a business that cannot trade for days. Ransomware is no longer a problem only large enterprises face - SMEs are targeted precisely because their defences are assumed to be thinner. The economics favour prevention overwhelmingly: the layered controls above cost a fraction of a single serious incident, and they reduce dozens of other risks at the same time. ## Frequently asked questions Q: What's the single most effective ransomware defence? A: There isn't one - that's the point of layering. But if forced to rank: MFA (blocks the credential path), tested offline backups (removes the leverage), and EDR (catches the behaviour). With 85% of breaches involving phishing (DSIT 2025), email filtering is where the chain usually starts. Q: Should we ever pay the ransom? A: The NCSC's position - and ours - is to avoid paying: payment funds the ecosystem, doesn't guarantee recovery, and increasingly triggers a second extortion over stolen data. Tested backups and a rehearsed recovery plan are what make 'no' a practical answer rather than a brave one. Q: How do we know if our backups would survive ransomware? A: Test the restore, not the backup job. Modern ransomware hunts backup systems first, so at least one copy must be offline or immutable - and the only proof is a timed, practised restore. An untested backup is a hope. Q: How fast does ransomware spread once it's in? A: Modern intrusions often dwell quietly for days - then encrypt everything in hours, usually out of business hours. That window is why 24/7 detection matters: the difference between one isolated laptop and a company-wide event is who noticed on day one. --- # What to Do After a Cyber Breach: Step-by-Step for UK Businesses URL: https://amvia.co.uk/cybersecurity/questions/what-to-do-after-cyber-breach Last updated: 2026-03 After a cyber breach, move fast and in order: isolate affected systems without powering them off, preserve the logs and evidence, work out what data was hit, report to the ICO within 72 hours if personal data was involved, then bring in professional incident response. The first 24 hours decide how much damage you contain. The hours after you discover a breach are chaotic, and the wrong instinct - wiping a machine, rebuilding a server, quietly hoping it goes away - destroys the evidence you need and can put you on the wrong side of the law. This guide sets out the exact sequence we run for clients, why each step matters, and where your legal clock is already ticking. It sits under our managed cybersecurity practice, where detection, response and recovery are handled by one accountable provider. ## What counts as a cyber breach you must act on? A cyber breach is any incident where an attacker gains unauthorised access to your systems or data - ransomware, a compromised email account, stolen credentials, data exfiltration, or a successful phishing attack. If personal data may have been accessed, altered, or stolen, it becomes a reportable event under UK GDPR and the clock starts the moment you become aware. Not every alert is a breach, but treat anything that touches personal or financial data as one until you can prove otherwise. The cost is real: the government's Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach for UK businesses at £3,550 (gov.uk), and that figure excludes the reputational and legal fallout that follows a mishandled response. ## What should you do in the first 24 hours after a cyber breach? In the first 24 hours, contain the threat, preserve evidence, assess the impact, and start your reporting obligations. Speed limits the blast radius and protects your legal position. Do not rebuild, do not pay anyone, and do not communicate externally until you understand what happened. Follow this sequence. 1. Contain the threat. Isolate affected systems from the network - pull the network cable or disable the NIC. Do not power machines off; that wipes volatile memory evidence. 2. Preserve evidence. Leave logs, system images, and any malware samples intact for forensic capture. 3. Assess the impact. Establish what data was accessed, stolen, or encrypted, and whether the attacker still has access. 4. Report to the ICO. If personal data was compromised, the 72-hour clock applies (see below). 5. Notify affected individuals. Required where there is a high risk to their rights and freedoms. 6. Engage professional incident response. Bring in a team to eradicate the threat, verify it is gone, and guide recovery. 7. Report the crime. Report to Action Fraud, and to the NCSC if the incident is nationally significant. The NCSC's incident management guidance is the authoritative UK reference for working through these stages under pressure. ## How do you contain a breach and preserve evidence at the same time? Containment and evidence preservation pull in opposite directions, so do them in the right order: isolate first by cutting network access, then capture forensic images before you change anything. Disconnecting a machine stops lateral movement; powering it down or rebuilding it destroys the logs, memory, and artefacts an investigator needs to find the root cause. Preserve these as a minimum: - Firewall and VPN logs - Email server and mailbox audit logs - Endpoint detection and response (EDR) alerts and telemetry - Full disk images of affected machines - Any malware samples or suspicious files This evidence underpins three things at once: root-cause analysis, a defensible ICO report, and any future legal or insurance claim. If you are not confident capturing forensic images cleanly, stop and call an incident response team before you touch the machine. ## When must you report a cyber breach to the ICO? If a breach involves personal data and poses a risk to individuals' rights and freedoms, you must report it to the ICO within 72 hours of becoming aware. Miss the deadline or get the assessment wrong and the maximum penalty under UK GDPR is fines of up to £17.5 million or 4% of annual turnover, whichever is higher. The 72 hours runs from awareness, not from when you finish investigating - so notify even if your picture is incomplete, then follow up. Use the ICO's self-assessment and reporting tool to decide whether your breach meets the threshold and to file. If the breach poses a *high* risk to individuals, you must also tell those people directly and without undue delay. ## Should you pay a ransomware demand after a breach? No. The NCSC and UK law enforcement strongly advise against paying ransoms. Payment does not guarantee you get your data back, it marks you as a business that pays, and it funds further criminal activity. There is no legal protection in paying, and it does not discharge your ICO obligations. Recovery from clean, tested backups is the route the NCSC recommends - see its ransomware guidance. The headline cost figures understate ransomware specifically: the average most-disruptive-breach cost across all UK businesses is £3,550 (Cyber Security Breaches Survey 2025), but ransomware recovery routinely runs far higher once downtime, rebuild, and lost revenue are counted. If you want the full picture, read our ransomware guide. ## DIY response vs professional incident response - which do you need? For anything beyond a single contained mailbox compromise, use professional incident response. Internal IT can isolate a machine, but verifying full eradication, preserving court-grade evidence, and producing ICO-ready documentation is specialist work. The table below shows where DIY response tends to fall down. | | Outcome | DIY response (internal staff only) | Professional IR (£5K–£30K, typical UK 2026 range) | Threat fully eradicated | Uncertain | Verified | Evidence preserved for legal/insurance | Often lost | Yes | Root cause identified | Rarely | Yes | ICO-compliant documentation | Unlikely | Yes | Typical recovery time | Weeks | Days | Recurrence prevented | Uncertain | Yes The hidden risk with DIY is the breach you *think* you cleaned. Attackers leave persistence - extra accounts, scheduled tasks, web shells - and without a thorough sweep they walk straight back in. Our managed detection and response service exists to catch exactly that, with Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC. ## How do you prevent a repeat breach after recovering? Run a structured post-incident review to find the root cause, then close the specific gap that let the attacker in - not a generic shopping list. Most repeat breaches happen because the original entry point was never fixed. Tie every remediation step back to how this attacker actually got in. Common, high-value remediations: - Enforce multi-factor authentication on every account, with no exceptions - Tighten Microsoft 365 Conditional Access policies - Strengthen email filtering and anti-phishing controls - Deploy endpoint detection and response across all devices - Run targeted staff awareness and phishing-simulation training That last point matters most: with 85% of breaches originating from phishing (Cyber Security Breaches Survey 2025), the human layer is where most repeat incidents start. A clean rebuild with the same untrained staff and the same weak email controls just resets the clock until the next one. Cyber insurers increasingly demand evidence of these controls too - see our guide to cyber insurance in the UK. ## Frequently asked questions Q: How quickly must I report a data breach to the ICO? A: You must report a personal data breach to the ICO within 72 hours of becoming aware of it, where it poses a risk to individuals' rights and freedoms. The clock starts at awareness, not at the end of your investigation, so report even with partial information. Failure to report can attract fines of up to £17.5 million or 4% of annual turnover under UK GDPR. Q: Should we pay a ransomware demand after a breach? A: No. The NCSC and UK law enforcement strongly advise against paying ransoms. Payment does not guarantee data recovery, it marks you as a soft target, and it funds further crime. It also does not remove your legal obligation to report. Focus on restoring from clean, tested backups and engaging professional incident response to verify the threat is gone. Q: What evidence should we preserve after a cyber breach? A: Preserve firewall and VPN logs, email and mailbox audit logs, endpoint detection alerts, full disk images, and any malware samples. Do not rebuild, wipe, or power down affected machines until forensic imaging is complete. This evidence is critical for root-cause analysis, your ICO report, insurance claims, and any legal proceedings. A professional IR team will guide you through correct collection. Q: Do I have to tell customers about a cyber breach? A: You must notify affected individuals directly and without undue delay where the breach poses a high risk to their rights and freedoms. Below that threshold, direct notification is not legally required, but you must still document the breach internally. The ICO's self-assessment tool helps you judge the risk level and your notification duties. Q: Who else should I report a cyber breach to in the UK? A: Beyond the ICO, report cyber crime to Action Fraud, the UK's national reporting centre, and to the NCSC if the incident is nationally significant or affects critical services. If financial fraud occurred, tell your bank immediately. Your cyber insurer also usually requires notification within a set window - check your policy, as late notice can void cover. Q: How long does it take to recover from a cyber breach? A: With professional incident response, most SME breaches are contained and recovered within days; DIY recovery often stretches to weeks because eradication is rarely verified the first time. The variable is whether you have clean, tested backups and a documented response plan ready before the incident - preparation, not luck, is what shortens recovery. --- # How Often Should UK Businesses Patch Their Software? URL: https://amvia.co.uk/cybersecurity/questions/how-often-should-patch-software Last updated: 2026-03 How often should you patch software? Apply critical security patches within 24 hours, and routine operating-system and application updates within 14 days of release - the window Cyber Essentials sets for high-risk flaws. AMVIA automates patch management across every managed endpoint, so the clock starts the moment a vendor ships a fix. Last updated: June 2026 Patching is the least glamorous and most reliably ignored control in security. It is also one of the most exploited gaps attackers use to get in. This guide sets out what "often enough" actually means for a UK business, what the standards require, and how a managed cybersecurity provider keeps the work from slipping. The figures here come from the NCSC and the UK Government's annual breaches survey - not vendor marketing. ## How often should you patch software in practice? Patch on a fixed cadence, not when someone remembers. Critical and high-severity vulnerabilities should be remediated within 24 hours where a fix exists; routine operating-system and application updates within 14 days of release. Anything that cannot meet those windows needs a documented exception and a compensating control. The 14-day figure is not arbitrary. It is the maximum the Cyber Essentials scheme allows for applying patches that fix vulnerabilities rated high or critical (CVSS 7 and above). Miss it on an in-scope system and you fail certification - and certification is increasingly a condition of winning public-sector and enterprise contracts. In practice, most breaches do not exploit zero-days. They exploit known flaws that had a patch available for weeks or months. The NCSC is blunt about this: keeping software up to date is one of its core vulnerability management recommendations precisely because the exploited bugs are usually old news. ## What patching timeframe applies to each severity? Treat severity as the dial that sets your deadline. A critical remote-code-execution flaw on an internet-facing server is not the same risk as a low-severity bug in an internal tool, and your patching SLA should reflect that. The table below is the cadence AMVIA runs for managed endpoints. | | Severity | Example | Target patch window | Who decides | Critical | Actively exploited RCE, internet-facing | Within 24 hours | Auto-deploy + SOC sign-off | High | CVSS 7.0–8.9, no active exploit yet | Within 14 days | Automated, tested | Medium | CVSS 4.0–6.9, limited exposure | Next monthly cycle | Scheduled | Low | Minor, internal-only | Routine maintenance | Scheduled | Unpatchable | Vendor end-of-life software | Remove or isolate | Risk-accepted decision The point of formalising this is removing the judgement call from a busy Tuesday. When the cadence is written down and automated, "we'll get to it" stops being a security strategy. ## Why does the 14-day patching window matter? Because the gap between a patch being released and you applying it is the exact window attackers race to exploit. Once a vendor publishes a fix, they also publish - implicitly - what was broken. Within days, working exploits for that flaw circulate. Every unpatched day after that is borrowed time. The scale of the problem is well documented. "43% of UK businesses experienced a breach or attack" in the last year (DSIT Cyber Security Breaches Survey 2025). Unpatched and out-of-date software remains one of the most common entry points behind those incidents, alongside phishing. Closing the patch gap removes a whole category of opportunistic attack. For regulated firms - and anyone carrying cyber insurance - timely patching is also a contractual expectation. Insurers increasingly ask for evidence of a patch-management process before they will pay out. "We meant to" is not evidence. ## What should you do when you can't patch in time? When a patch cannot be applied - usually because it breaks a line-of-business application - isolate the system from the wider network or wrap it in additional compensating controls until you can. Software that has reached end-of-life and no longer receives patches at all must be removed from scope entirely, not nursed along. This is where most patch programmes quietly fail. A single legacy application that "can't be touched" becomes a permanent hole, and over time more systems get pinned to it. The disciplined approach is to treat every unpatchable system as a tracked, time-boxed risk with an owner and an exit plan - not a fixture. Compensating controls worth deploying around a system you cannot patch include: - Network segmentation so a compromise can't move laterally - Restricting inbound and outbound traffic to the bare minimum - Endpoint detection and response to catch exploitation attempts in real time - Removing the system from internet exposure entirely where possible - 24/7 monitoring so any anomaly is seen immediately None of these replace patching. They buy you time and visibility while you engineer the legacy dependency out. ## Should you automate patching or do it manually? Automate the routine, supervise the sensitive. Automated patching is strongly recommended for operating systems and standard applications - it removes human delay and keeps you inside the 14-day window without anyone tracking it on a spreadsheet. Critical line-of-business applications keep manual oversight, with patches tested before deployment. A good managed IT and security provider runs both lanes at once: automated rollout for the bulk of your estate, scheduled and tested deployment for the handful of systems where an untested update could halt operations. That split is the practical answer to the false choice of "automate everything and risk an outage" versus "do it by hand and fall behind". The stakes rose in 2026: exploitation of vulnerabilities is now the number-one initial access vector in breaches at 31%, overtaking stolen credentials for the first time (Verizon DBIR 2026). Automation also reinforces other controls. "Only 47% of UK businesses have two-factor authentication in place" (DSIT Cyber Security Breaches Survey 2025/26) - the same management gap that leaves software unpatched usually leaves MFA unconfigured. Automating security baselines closes both consistently, instead of relying on someone remembering. ## How does patching fit into a wider security strategy? Patching is one layer, not a strategy. It belongs inside a broader vulnerability management programme that continuously scans your estate, prioritises what to fix, and feeds detections to a monitoring team. Patching alone tells you nothing about what slipped through before the fix landed. That is why AMVIA wraps patch management inside a single accountable service. Continuous scanning finds the gaps, automated patching closes the routine ones, and our in-house SOC monitors for exploitation of anything still open. When a critical flaw is actively exploited in the wild, our managed detection and response team is watching for it on your endpoints while the patch is being deployed - not after. One provider. Security-first. Microsoft-certified. The reason to consolidate patching, monitoring and response under one roof is simple: gaps live in the handoffs between vendors, and a single accountable team has nowhere to pass the blame. ## Frequently asked questions Q: How often should you patch software for Cyber Essentials? A: Cyber Essentials requires you to apply patches that fix high or critical vulnerabilities (CVSS 7 and above) within 14 days of release on all in-scope devices and software. Missing this window is a certification failure. Unsupported software that no longer receives security updates must be removed from scope entirely. Q: How quickly should critical vulnerabilities be patched? A: Critical vulnerabilities should be patched within 24 hours where a fix exists, especially anything internet-facing or under active exploitation. Working exploits for newly disclosed flaws typically circulate within days of a patch release, so every additional day of exposure meaningfully raises the chance of compromise. Q: What happens if we cannot patch a system in time? A: Isolate the system from the wider network or apply additional compensating controls - segmentation, restricted traffic, endpoint detection - until a fix is possible. Treat it as a tracked, time-boxed risk with a named owner. Software that is end-of-life and no longer receives patches should be removed entirely, not kept running. Q: Should patching be automated or done manually? A: Automate operating-system and standard application patches to stay inside the 14-day window without manual tracking. Retain manual, tested deployment for critical line-of-business applications where an untested update could cause an outage. A managed provider runs both lanes, so routine updates are fast and sensitive systems are handled carefully. Q: How common are breaches from unpatched software? A: Unpatched and outdated software is one of the most common entry points behind UK breaches. The DSIT Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a breach or attack in the last year, with known, already-patched vulnerabilities - not zero-days - behind a large share of opportunistic attacks. Q: Does AMVIA manage patching for us? A: Yes. AMVIA automates patch management across every managed endpoint, applies critical fixes inside the 24-hour window, and schedules tested rollouts for sensitive applications. It sits inside our vulnerability management and 24/7 SOC monitoring, so gaps are found, closed, and watched under one accountable provider. --- # What Is Social Engineering in Cybersecurity? URL: https://amvia.co.uk/cybersecurity/questions/what-is-social-engineering Last updated: 2026-03 Social engineering is the use of psychological manipulation to trick people into revealing information or taking actions that compromise security, rather than exploiting technical vulnerabilities. Phishing is the most common form, alongside vishing, smishing and pretexting. The strongest defence is trained staff backed by strict verification and managed cybersecurity that catches what people miss. Last updated: June 2026 ## What does social engineering actually mean? Social engineering is hacking the human, not the firewall. Instead of breaking encryption or exploiting a software flaw, the attacker manipulates a person into handing over credentials, approving a payment, or opening a malicious file. It works because it targets trust, urgency, authority and the simple desire to be helpful. This is why it bypasses expensive technical controls. A locked-down network still depends on people who answer emails, take phone calls and process invoices. Get one of them to act, and the attacker walks through the front door with valid credentials. The UK's National Cyber Security Centre treats it as one of the primary routes into an organisation, which is why its phishing guidance for organisations focuses on process and people, not just software. ## What are the main types of social engineering attacks? The main types are phishing (fraudulent emails), vishing (voice calls impersonating IT support or banks), smishing (malicious SMS), pretexting (fabricated scenarios to extract information), baiting (infected USB drives left to be found), and tailgating (physically following authorised staff into secure areas). Email-based attacks dominate by a wide margin. Phishing is the headline threat: "85% of businesses that experienced a breach identifying phishing as the vector" (DSIT 2025), per the UK government's Cyber Security Breaches Survey 2025. Knowing the variants helps staff recognise an attack when it arrives by a channel they were not expecting. | | Attack type | How it works | Primary defence | Phishing | Fraudulent email posing as a trusted brand or colleague | Email filtering, phishing protection, staff training | Spear phishing | Targeted email using researched personal detail | Verification procedures, phishing simulation training | Vishing | Phone call impersonating IT, a supplier or a bank | Call-back on a known number, never trust caller ID | Smishing | Malicious link or request sent by SMS | Block external links on mobile, report-and-delete culture | Pretexting | Fabricated story to extract information or access | Strict identity checks before releasing data | Baiting | Infected USB or "free" download left to tempt a user | Device control policy, disable autorun | Tailgating | Following staff through a secure door | Badge discipline, visitor sign-in ## Why is social engineering so effective against businesses? Social engineering exploits human psychology - trust, urgency, authority and helpfulness - rather than technical weakness. Even well-trained staff can be deceived by a convincing pretext, especially when attackers research their targets first using LinkedIn, company websites and public filings to make the approach feel legitimate. The financial impact is real: "The average cost of the most disruptive breach is £3,550" (DSIT 2025), and social engineering is the initial access method behind the majority of these incidents. Worse, AI is sharpening the threat - generative tools now produce flawless, personalised emails and clone voices, removing the spelling mistakes and awkward phrasing that used to give attackers away. The old advice to "spot the typo" no longer holds. ## How big is the social engineering threat to UK businesses? It is the dominant cause of UK breaches and the harm is rising. According to the Cyber Security Breaches Survey 2025, "21% of businesses that experienced a breach reported a negative outcome such as loss of money or data," and "7% of businesses that experienced a breach reported temporary loss of access to files or networks - up from 4% in 2024." The trend at national level matches what businesses see day to day. The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant - the highest-ever number, a pattern set out in the NCSC threat reporting. Business email compromise is a particular growth area: "overall IC3-reported cybercrime losses attacks increased 33% in 2025" (FBI IC3 Report). For most UK SMEs, the question is not whether social engineering reaches their inbox, but whether a member of staff acts on it. - Email is the primary channel - start defending there with email security. - Targeted attacks on named individuals are growing - understand spear phishing and how it differs from mass phishing. - Finance teams are the highest-value target because they can move money. ## How can your business defend against social engineering? Effective defence combines regular staff awareness training, simulated phishing campaigns, strict verification procedures for financial requests, and technical controls such as email filtering and multi-factor authentication. The aim is a workforce that pauses, questions and reports - backed by technology that blocks what people miss. No single control is enough. A blameless reporting culture, where staff feel safe flagging a suspicious email or call, is as important as any tool. Organisations with formal verification procedures for payment changes are significantly less likely to fall victim to invoice fraud. - Train continuously, not annually. Short, frequent sessions and live phishing simulation training beat a once-a-year slide deck. - Verify out of band. Confirm any payment or bank-detail change by calling a known number - never the contact details in the request. - Turn on MFA everywhere. Stolen credentials are far less useful behind a second factor; see our MFA setup for Microsoft 365. - Filter at the gateway. Strong email security and phishing protection remove most malicious messages before staff ever see them. - Have a plan for when it works. Even good defences fail occasionally - rehearse your incident response so a click does not become a crisis. At AMVIA we run this for 1,200+ UK businesses on a security-first model: one accountable provider, Microsoft-certified engineers, and Microsoft Defender plus Barracuda doing the technical heavy lifting behind the training. One provider. Security-first. Microsoft-certified. ## What should you do if someone falls for a social engineering attack? Act fast and assume compromise. Reset the affected credentials immediately, revoke active sessions, and check for mailbox rules or forwarders the attacker may have set up. Tell your IT or security team and your bank if money or payment details were involved, and preserve the evidence rather than deleting it. Speed limits the damage. A reported phishing click contained within minutes is an inconvenience; the same click discovered weeks later via an unexplained invoice is a breach. This is exactly where managed monitoring earns its keep - our incident response and 24/7 SOC work to contain an account takeover before it spreads across the business. ## Frequently asked questions Q: What are the different types of social engineering attacks? A: The main types are phishing (fraudulent emails), vishing (voice calls impersonating IT support or banks), smishing (malicious SMS), pretexting (fabricated scenarios to extract information), baiting (infected USB drives), and tailgating (following authorised staff into secure areas). Phishing dominates: "85% of businesses that experienced a breach identifying phishing as the vector" (DSIT 2025), making email the most prevalent route. Q: How can businesses defend against social engineering? A: Combine regular staff awareness training, simulated phishing campaigns, strict verification procedures for financial requests, and technical controls like email filtering and MFA. A blameless reporting culture, where staff flag suspicious contacts without fear, is critical. Organisations with formal out-of-band verification for payment changes are significantly less likely to fall victim to invoice and BEC fraud. Q: Why is social engineering so effective? A: It exploits human psychology - trust, urgency, authority and helpfulness - rather than technical vulnerabilities. Even trained staff can be deceived by a sophisticated pretext, especially when attackers research targets on LinkedIn and company websites first. AI now removes the spelling and grammar errors that once gave attacks away, making convincing fakes faster to produce and harder to spot. Q: Is phishing a type of social engineering? A: Yes. Phishing is the most common form of social engineering, using fraudulent emails to manipulate people into revealing credentials, approving payments, or opening malicious files. Other forms include vishing (phone), smishing (SMS) and pretexting. In UK breaches, phishing is identified by 85% of affected businesses as the attack type (DSIT 2025), making it the dominant social engineering technique. Q: Can technology alone stop social engineering? A: No. Email filtering, MFA and endpoint protection block a large share of attacks, but social engineering targets people, so some attempts always reach a human. The reliable defence is layered: technical controls to reduce volume, ongoing training to build judgement, and verification procedures so a single mistake cannot authorise a payment or expose data on its own. Q: What is the difference between phishing and spear phishing? A: Phishing is sent in bulk to many recipients using a generic lure. Spear phishing is targeted at a specific person or role, using researched detail - a real supplier name, a colleague's writing style, a live project - to make the approach believable. Spear phishing has a far higher success rate, which is why high-value staff such as finance teams need extra verification. --- # What Is the Difference Between a Virus and Malware? URL: https://amvia.co.uk/cybersecurity/questions/difference-between-virus-and-malware Last updated: 2026-03 Malware is the umbrella term for any malicious software - viruses, ransomware, trojans, spyware and worms. A virus is one specific type that spreads by attaching to legitimate files. Most modern UK business attacks are ransomware and info-stealers, not classic viruses, so you need behavioural endpoint detection, not legacy antivirus. That is exactly what AMVIA runs - security-first. People use "virus" and "malware" interchangeably, but they are not the same thing, and the difference matters when you are buying protection. Get the terms wrong and you buy the wrong defence. This guide explains both clearly, shows the threats UK businesses actually face in 2026, and sets out what real protection looks like. It is part of our wider managed cybersecurity guidance for UK SMEs. ## What is malware? Malware - short for "malicious software" - is any program written to damage, disrupt, steal from, or gain unauthorised access to a device or network. It is the parent category. Viruses, ransomware, trojans, spyware, worms, adware and rootkits are all sub-types of malware, each with a different method and goal. The UK's National Cyber Security Centre treats malware as a broad family of threats rather than a single thing, because the way each type behaves - and the way you stop it - varies enormously. When a vendor sells you "anti-malware", they should be defending against the whole family, not just one member of it. ## What is a virus, and how is it different? A virus is a specific type of malware that replicates by attaching itself to a legitimate file or program. When that file runs, the virus runs too, then copies itself into other files. The key trait is that a virus needs a host file and usually some user action - opening an attachment, running a download - to spread. So every virus is malware, but not every piece of malware is a virus. A worm, by contrast, spreads on its own across a network with no host file and no user action. A trojan hides inside something that looks legitimate. Treating "virus" as the whole problem is like calling every illness "the flu" - it leads you to the wrong treatment. ## What are the main types of malware UK businesses face? Classic file-infecting viruses are now a small slice of the threat landscape. The malware that actually hurts UK businesses today is built to make money - by encrypting your files, stealing your credentials, or quietly siphoning data. Very few modern ransomware strains behave like a traditional virus. Here is how the common types differ: | | Malware type | How it spreads | Primary risk to your business | Virus | Attaches to a file; runs when the file is opened | File corruption, system disruption | Worm | Self-replicates across networks; no user action needed | Rapid network-wide infection | Trojan | Disguised as legitimate software the user installs | Backdoor access, payload delivery | Ransomware | Phishing, stolen credentials, unpatched software | Encrypted files, ransom demand, downtime | Spyware / info-stealer | Silent install via phishing or bundled software | Stolen credentials, keystrokes, data theft Two patterns stand out. First, ransomware is now the dominant business threat, and it overwhelmingly arrives via phishing or stolen logins rather than a self-spreading file. Second, info-stealers run silently. 22% of breaches involved compromised credentials (Verizon DBIR 2025), many of them harvested by malware that sat undetected for weeks. If you want a deeper breakdown of the costliest type, read our explainer on what ransomware is and how it works. ## Why is "antivirus" now an outdated term? Traditional antivirus was built to spot known viruses by matching them against a database of signatures. That model struggles against modern threats - ransomware, fileless attacks, and info-stealers frequently have no known signature, or change with every infection. Signature matching simply does not see them. This is why the industry shifted to endpoint detection and response (EDR), which watches for malicious *behaviour* - a process encrypting files en masse, a script reaching out to a command server - rather than a known fingerprint. 85% of businesses that experienced a breach identified phishing as the attack type, according to the UK Cyber Security Breaches Survey 2025 (DSIT), and phishing-delivered malware routinely bypasses signature-based tools. Calling modern protection "antivirus" undersells what a business actually needs. We unpack the practical gap in our managed detection and response overview. ## How do you actually protect a business from modern malware? Effective protection is layered: stop the delivery (mostly phishing), detect malicious behaviour on the endpoint, and have someone watching around the clock to respond before a foothold becomes a full breach. No single product does all three, which is why managed services exist. AMVIA's approach is deliberately one accountable stack: - Behavioural endpoint protection with endpoint detection and response, using Microsoft Defender for Endpoint rather than signature-only antivirus. - Email and network filtering via the Barracuda suite, because most malware still arrives by email - backed by dedicated phishing protection. - 24/7 monitoring and response from our in-house SOC, so behavioural alerts are investigated and contained day or night - see 24/7 security monitoring. One provider, security-first, with Microsoft-certified engineers. That single line of accountability matters: when something is flagged at 2am, you want one team that owns detection, response, and your Microsoft environment - not three vendors pointing at each other. ## Frequently asked questions Q: Is ransomware a virus? A: Technically it's malware but rarely a true virus - ransomware seldom self-replicates by infecting files; it arrives via phishing, stolen credentials or exploited systems, then encrypts. The distinction matters because defences aimed at 'viruses' miss how modern attacks actually get in. Q: Does antivirus stop all malware? A: No - signature-based antivirus catches known files, while modern attacks increasingly use no recognisable malware at all: stolen logins, legitimate admin tools, fileless techniques. That's why the current standard is EDR (behaviour-based detection), ideally watched by someone. Q: What malware should UK businesses actually worry about? A: Ransomware for impact, infostealers for quiet credential theft, and the phishing that delivers both - 85% of UK breaches involve phishing (DSIT 2025). The category names matter less than the entry route, which is overwhelmingly email and identity. Q: How do we know if we're already infected? A: Signs include odd account activity, unexpected mail rules, machines suddenly slow or noisy at strange hours - but modern malware is deliberately quiet. The reliable answer is detection tooling and monitoring rather than symptoms; by the time it's visible, it's late. --- # How to Report Cybercrime in the UK URL: https://amvia.co.uk/cybersecurity/questions/how-to-report-cyber-crime-uk Last updated: 2026-03 To report cyber crime in the UK, report fraud and cyber-enabled crime to Action Fraud (actionfraud.police.uk or 0300 123 2040), report any personal data breach to the ICO within 72 hours under UK GDPR, and escalate serious or ongoing attacks to the NCSC. Report fast - delay raises both regulatory and insurance risk. Knowing exactly who to call, in what order, and inside which deadline is the difference between a contained incident and a six-figure fine. This guide sets out the reporting path UK businesses must follow, what evidence each body needs, and how a managed cybersecurity partner shortens the whole process. It matters: 43% of UK businesses experienced a breach or attack (DSIT 2025), and most of them had no documented reporting plan. ## Who do you report cyber crime to in the UK? There is no single phone number. UK cyber crime reporting splits across three bodies with different jobs: Action Fraud handles fraud and most cyber-enabled crime, the Information Commissioner's Office (ICO) handles personal data breaches, and the National Cyber Security Centre (NCSC) handles nationally significant or ongoing technical attacks. Many incidents require reports to more than one. The trap businesses fall into is treating these as alternatives. They are not. A ransomware attack that exposes customer records can be an Action Fraud crime report, an ICO data-breach notification, and an NCSC incident report at the same time. | | Body | What it handles | How to report | Deadline | Action Fraud | Fraud, phishing, ransomware, most cyber crime | actionfraud.police.uk or 0300 123 2040 | As soon as possible | ICO | Personal data breaches under UK GDPR | ico.org.uk breach reporting | Within 72 hours of awareness | NCSC | Significant/ongoing attacks, critical infrastructure | ncsc.gov.uk report tool | As soon as possible ## How do you report cyber crime to Action Fraud? Report to Action Fraud, the UK's national reporting centre for fraud and cyber crime, online at actionfraud.police.uk or by phone on 0300 123 2040. You will be issued a crime reference number, which your insurer and bank will ask for. Report even if no money was lost - the data feeds national policing intelligence. Action Fraud will ask for the attack type, the date you discovered it, the affected systems or data, any financial loss, and preserved evidence. Because 85% of businesses that experienced a breach identified phishing as the attack type (DSIT 2025), keep original phishing emails intact with full headers rather than deleting or forwarding them. What to have ready before you call: - A short timeline of when the attack was discovered and by whom - Affected systems, accounts, and any data categories involved - Financial losses or attempted fraudulent transactions - Preserved evidence: emails with headers, logs, screenshots, ransom notes ## When must you report a data breach to the ICO? If the cyber crime exposed personal data, you must report it to the ICO within 72 hours of becoming aware, under UK GDPR - unless the breach is unlikely to result in a risk to people's rights and freedoms. The clock starts at awareness, not at full diagnosis. A partial, honest report on time beats a complete report that misses the deadline. You report to the ICO directly; an Action Fraud report does not satisfy this duty. If the breach poses a high risk to individuals, you must also tell the affected people without undue delay. Document your reasoning even when you decide not to report - the ICO expects to see that judgement recorded. ## When should you involve the NCSC? Involve the NCSC for significant or ongoing attacks - active ransomware, large-scale data compromise, or anything touching critical national infrastructure. The National Cyber Security Centre provides technical incident guidance and tracks attacks at national scale, but it is not a substitute for Action Fraud or the ICO. Use it alongside them. For an active ransomware incident, early NCSC contact can shape containment decisions before you pay for - or rule out - recovery options. ## What evidence should you preserve before reporting? Preserve everything in its original state before you start cleaning up. The instinct to delete the malicious email, wipe the infected machine, or "just get back to work" destroys the evidence every reporting body and your cyber insurer will ask for. Isolate, do not erase. Practical preservation steps: - Disconnect affected devices from the network - power them off only on expert advice, as memory evidence can be lost - Keep phishing emails with full headers; export rather than forward - Screenshot ransom notes, error messages, and unusual account activity - Preserve firewall, VPN, and authentication logs before they rotate - Record names, times, and actions in a running incident log This is exactly the discipline a professional incident response team brings - evidence handling that survives both an ICO inquiry and an insurance claim. ## What happens if you fail to report cyber crime? Failing to report carries two distinct costs. A missed ICO notification can trigger regulatory enforcement and fines under UK GDPR. Separately, late or incomplete reporting frequently invalidates cyber insurance claims, because policies require prompt notification and preserved evidence. The financial hit often lands harder than the original attack. There is a slower cost too: unreported crime is invisible to national policing, which weakens the intelligence picture for everyone. Reporting is not just compliance - it is how the UK builds a defence against repeat offenders. ## How AMVIA shortens the reporting process When AMVIA monitors your environment, reporting starts from a position of evidence, not panic. Our in-house 24/7 SOC detects the incident, preserves the logs and artefacts each body requires, and helps you notify Action Fraud, the ICO, and the NCSC within their deadlines. One provider. Security-first. Microsoft-certified - so your defence, detection, and reporting sit under a single accountable team rather than three disconnected suppliers. The strongest reporting position is the one you never have to use because the attack was stopped first. Strengthening phishing protection removes the vector behind most reportable incidents before it reaches an inbox. ## Frequently asked questions Q: Is reporting cyber crime to Action Fraud mandatory? A: For most private businesses, reporting fraud and cyber crime to Action Fraud is strongly encouraged but not a legal duty in itself. However, reporting personal data breaches to the ICO within 72 hours is a legal requirement under UK GDPR. Regulated sectors may face additional mandatory reporting obligations to their own regulators. Q: Do I report to the ICO and Action Fraud separately? A: Yes. They serve different purposes and one report does not cover the other. Action Fraud records the crime and issues a reference number for police intelligence and insurers. The ICO handles your statutory data-breach notification. A single incident involving personal data typically requires both reports, made independently. Q: How long do I have to report a data breach in the UK? A: You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it under UK GDPR. The countdown begins at awareness, not at full investigation. If you cannot provide all details in time, submit an initial report and follow up - a late report is harder to defend than a partial one. Q: What information does Action Fraud need when I report? A: Action Fraud asks for the attack type, the date of discovery, affected systems or data, any financial losses, and preserved evidence. Because phishing is the leading attack vector for UK breaches, keep original phishing emails with full headers intact. A clear timeline of who discovered what, and when, speeds the report significantly. Q: Can reporting cyber crime affect my insurance claim? A: Yes, directly. Most cyber insurance policies require prompt notification of an incident and preservation of evidence as conditions of cover. Delayed reporting or destroyed evidence can reduce or invalidate a claim. Reporting quickly to Action Fraud and the ICO, and keeping a full incident log, protects both your compliance position and your payout. --- # What Is Dark Web Monitoring and Does My Business Need It? URL: https://amvia.co.uk/cybersecurity/questions/what-is-dark-web-monitoring Last updated: 2026-03 Dark web monitoring continuously scans criminal forums, marketplaces, and breach dumps for your business email addresses, passwords, and sensitive data. When stolen credentials surface, it alerts you fast - so you can reset passwords before attackers log in. AMVIA builds it into managed cybersecurity with monitored alerts, not just a one-off report. Most businesses only learn their credentials are compromised after an account is already breached. Dark web monitoring flips that order: it gives you a warning while the password is still being traded, not after it has been used. That early window is the entire point. ## How does dark web monitoring actually work? Dark web monitoring works by indexing the parts of the internet that standard search engines never touch - closed forums, paste sites, Telegram channels, and credential marketplaces - and matching what it finds against your domains, email addresses, and chosen identifiers. When a match appears, you get an alert with the source and the exposed data. The "dark web" is the slice of the internet that needs special software, such as Tor, to reach. It is where breached databases are sold, traded, and dumped for free. A monitoring service maintains feeds into these places and runs continuous comparisons so you do not have to. A typical workflow looks like this: - Define watchlist - your domains, executive email addresses, and brand terms. - Continuous scanning - automated collection across forums, dumps, and marketplaces. - Match and verify - flag credentials or data tied to your watchlist. - Alert - notify your IT team or security provider with the exposure detail. - Respond - force a password reset, confirm MFA, and check for account misuse. The detection is only half the value. The response is what stops a leaked password from becoming a breach. ## Why do UK businesses need dark web monitoring? UK businesses need dark web monitoring because stolen credentials are now one of the most common ways attackers get in, and most firms have no other way of knowing a password has leaked until it is used against them. Credential theft is a volume game, and SMEs are squarely in scope. The numbers make the case. "22% of breaches involving compromised credentials (Verizon DBIR 2025)" shows how routinely stolen logins drive incidents. The risk is sharper in the UK because basic defences are still patchy - "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)", according to the government's Cyber Security Breaches Survey 2025. A leaked password on an account without MFA is, in practice, an open door. There is a hard cost attached. "The average cost of the most disruptive breach is £3,550 (DSIT 2025)" for the typical affected business - and that figure climbs steeply once you add downtime, recovery, and customer trust. The NCSC is clear that credential reuse and weak password hygiene remain among the most exploited weaknesses in UK organisations. ## What data shows up on the dark web? Far more than passwords. Once a third-party service you use is breached, your staff's reused logins, personal details, and sometimes full session tokens can end up for sale. Monitoring catches the exposures that matter to your specific domain. | | Data type | Why it matters | Typical attacker use | Email + password pairs | Often reused across business systems | Account takeover, email fraud | Employee personal data | Fuels convincing phishing | Targeted social engineering | Financial / payment details | Direct monetary loss | Fraud, invoice redirection | Session tokens / cookies | Bypass passwords and MFA | Silent account hijack | Internal documents | Leverage for extortion | Ransom demands, data extortion If any of these tie back to your business, you want to know on day one - not when a fraudulent payment lands. ## How is dark web monitoring different from breach notification? Breach notification tells you after a company publicly discloses an incident, often weeks or months late. Dark web monitoring watches the underground markets where credentials trade *before* a breach is public - and frequently before the breached company even knows. The difference is timing, and timing decides whether you prevent damage or clean it up. Public breach notices are useful but slow. By the time a disclosure reaches the news, the stolen data has usually already circulated. Continuous managed detection and response pairs dark web alerts with active monitoring of your own systems, so a flagged credential is checked against real sign-in activity straight away. ## What should you do when credentials are found? Move quickly and methodically. A single alert should trigger a short, repeatable response: reset the affected password, confirm multi-factor authentication is on, and check for any sign-in or activity you do not recognise. Speed is everything - the value of a leaked password drops to near zero the moment you rotate it. A practical response checklist: 1. Force a reset on the exposed account and any account sharing that password. 2. Confirm MFA is enforced - see our MFA setup guide. 3. Review activity for unfamiliar logins, mailbox rules, or data access. 4. Contain - if misuse is found, invoke your incident response plan. 5. Harden - block password reuse and roll out awareness training. This is exactly the loop AMVIA's in-house 24/7 SOC runs for clients, so an alert becomes an action within minutes rather than sitting in an inbox. ## Is dark web monitoring enough on its own? No. Dark web monitoring is a detection control, not prevention - it tells you a credential has leaked, but it does not stop the leak or block the login. It earns its place as one layer in a defence that also enforces MFA, strong password policy, and staff awareness. On its own it is an alarm with no locks behind it. Treat it as the early-warning system inside a broader stack. The most effective setup combines monitoring with multi-factor authentication, 24/7 security monitoring, and tested response. One provider running all of it - security-first, Microsoft-certified - beats stitching together tools that never talk to each other. ## Frequently asked questions Q: What happens when dark web monitoring finds my credentials? A: When a service detects your business email or password in a dark web dump, it alerts you immediately so you can force a password reset and confirm MFA is enabled on the affected accounts. Speed matters - "22% of breaches involving compromised credentials (Verizon DBIR 2025)", so rotating the password before it is used is what stops an exposure becoming a breach. Q: How does dark web monitoring differ from breach notification services? A: Breach notification alerts you after a company publicly discloses an incident. Dark web monitoring scans underground forums and marketplaces where credentials trade before breaches become public - often before the breached firm knows. The timing gap matters, especially when "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)" and a leaked password on an MFA-free account is an open door. Q: Is dark web monitoring enough to protect against credential theft? A: No - it is a detection control, not prevention. "The average cost of the most disruptive breach is £3,550 (DSIT 2025)", so detection alone does not protect your balance sheet. Pair it with enforced MFA, a strong password policy, and security awareness training to actually reduce the chance of account takeover. Q: Can dark web monitoring remove my data from the dark web? A: No. Once data is on the dark web it cannot be deleted - it is copied across countless sites and sellers. What monitoring does is tell you the data is out there so you can neutralise its value: reset exposed passwords, enforce MFA, and watch for misuse. The goal is making stolen credentials useless, not erasing them. Q: How often should a business scan the dark web? A: Continuously. A one-off check is a snapshot that is stale the moment it finishes, because new dumps appear daily. Effective dark web monitoring runs around the clock and alerts in near real time, which is how AMVIA delivers it - automated scanning tied to a 24/7 SOC that acts on every credible match. Q: Does dark web monitoring work for Microsoft 365 accounts? A: Yes, and it should be a priority. Microsoft 365 logins are a top target because one compromised account can reach email, files, and Teams. Monitoring flags exposed M365 credentials, and combining it with Microsoft Defender for Business and Conditional Access keeps a leaked password from turning into a full tenant compromise. --- # On-Premise vs Cloud Cybersecurity: Which Is Best for UK SMEs? URL: https://amvia.co.uk/cybersecurity/compare/on-premise-vs-cloud-security Last updated: 2026-03 For most UK SMEs running Microsoft 365, cloud-native security wins. On-premise appliances still suit air-gapped or heavily regulated sites, but they carry hardware refresh cycles and manual patching. Cloud-native tools update automatically, integrate with your tenant, and let AMVIA run one accountable, security-first stack on your behalf. This is a buyer's comparison, not a sales pitch. Below we set out where each model genuinely earns its place, what it costs to run, and why we steer most clients toward a cloud-native approach built around their existing managed cybersecurity and Microsoft estate. If you only manage one thing this quarter, make it the gap between what your security tooling promises and what it actually inspects. ## What is the difference between on-premise and cloud security? On-premise security runs on hardware you own and host - firewalls, appliances, and servers inside your building. Cloud-native security runs as a service from the vendor's platform, scaling with your users and updating automatically. The practical split is who owns the boxes, who patches them, and what traffic they can actually see. On-premise gives you physical control of logs and inspection data, which a small number of regulated workloads still demand. The trade-off is operational: someone on your team owns firmware updates, capacity planning, and the three-to-five-year replacement cycle. Cloud-native shifts that burden to the provider and, crucially, can inspect encrypted cloud and Microsoft 365 traffic that an on-premise appliance often cannot see natively. ## On premise vs cloud security: side-by-side comparison Here is how the two models compare on the factors that actually drive the decision for a 10–500-staff UK business. Use it to pressure-test any quote you are given - vague "it depends" answers usually hide a hardware refresh you will pay for later. | | Factor | On-premise security | Cloud-native security | Upfront cost | Capital outlay on appliances and servers | No hardware; subscription only | Ongoing cost | Licence renewals + in-house patching time | Predictable per-user monthly fee | Updates | Manual firmware and signature updates | Automatic, vendor-pushed | Scaling | Capacity planning and re-sizing | Scales with user/seat count | Microsoft 365 visibility | Limited; struggles with encrypted cloud traffic | Native integration with the tenant | Threat intelligence | Periodic, depends on update discipline | Continuous, global telemetry | Maintenance owner | Your IT team | Provider-managed | Best fit | Air-gapped, fixed-site, tightly regulated | Cloud-first SMEs on Microsoft 365 ## When should a UK SME choose on-premise security? Choose on-premise when a specific, documented requirement forces it - not by default. The honest use cases are narrow: workloads that must be physically air-gapped, sites with strict data-residency rules that rule out cloud inspection, or legacy operational technology that cannot route through a cloud service. Sensible reasons to keep on-premise controls: - A regulator or contract requires inspection data to stay on your physical premises. - You run industrial or OT equipment that cannot be cloud-managed safely. - You have stable, fixed headcount and existing appliances mid-lifecycle. - You have in-house staff who can patch and monitor the hardware reliably. Even then, most organisations run on-premise as one layer rather than the whole strategy. With 43% of UK businesses reporting a breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), an unpatched appliance is one of the most avoidable risk factors going. ## When should a UK SME choose cloud security? Choose cloud-native security when your business already lives in the cloud - which, for most SMEs, it does. If your email, files, and identity sit in Microsoft 365, cloud-native protection inspects that traffic directly, updates without your intervention, and removes the hardware refresh cycle entirely. It is the lower-friction, lower-risk default for cloud-first teams. Cloud-native is the right call when: - Your core workloads are in Microsoft 365 or another SaaS platform. - You want predictable monthly costs instead of capital spikes. - You lack the in-house time to patch and monitor appliances 24/7. - You are growing or hybrid, and need security that scales with seats. This is where Microsoft Defender for Business and identity controls like Conditional Access do their best work - enforcing policy at the point of sign-in and on the endpoint, not at a box on the network edge. ## How do the costs compare over time? On-premise looks cheaper in year one and gets more expensive after that. Appliances need replacing every three to five years, plus annual licence renewals and staff time to patch them. Cloud-native spreads cost into a predictable per-user monthly fee that scales with headcount - easier to budget and easier to forecast. The numbers behind the risk are worth keeping in view. UK figures put the average breach cost for businesses with negative outcomes at £8,260 and the most disruptive breach at an average of £3,550 (DSIT 2025). Whatever model you run, the cost of getting patching wrong dwarfs the licence line. For context on the scale of the cloud shift: Microsoft 365 now has over 400 million paid commercial seats (Microsoft FY2025), which is why cloud-native protection has become the default standard rather than the exception. The National Cyber Security Centre's cloud security guidance reflects the same direction of travel for UK organisations. ## Can you run a hybrid of on-premise and cloud security? Yes - and many businesses do during transition. A common pattern keeps an on-premise firewall in place while cloud-native tools handle endpoints, email, and identity. The discipline that makes hybrid work is shared signal: both layers must feed the same monitoring and policy enforcement, or you simply double your blind spots. In practice, hybrid is a staging post, not a destination. As clients retire ageing servers and move workloads to cloud hosting, they consolidate onto cloud-native platforms. AMVIA runs this consolidation through a single managed detection and response service, with Microsoft Defender for Endpoint monitored by our in-house 24/7 SOC and Barracuda handling email and network filtering. One provider, one set of policies, one accountable team. ## The AMVIA recommendation For UK SMEs migrating to or already using cloud services, cloud-native security is the right choice. It removes hardware refresh cycles, applies threat intelligence updates automatically, and integrates directly with Microsoft 365 rather than fighting it. AMVIA deploys cloud-native stacks - managed detection and response, email security, and identity protection - built on Microsoft Defender and the Barracuda suite, monitored around the clock by our own SOC. That is the security-first, single-provider model we put our name to. If you are weighing this against an EDR or antivirus decision too, our MDR vs EDR comparison is the natural next read. ## Frequently asked questions Q: Is cloud security more effective than on-premise appliances for UK SMEs? A: For most SMEs using Microsoft 365, cloud-native security is more effective because it integrates directly with those platforms and updates automatically with new threat intelligence. On-premise appliances require manual firmware updates and cannot inspect encrypted cloud traffic natively, which leaves gaps as more of your business moves into the cloud. Q: Does on-premise security offer better data control than cloud security? A: On-premise keeps logs and inspection data within your physical premises, which some regulated industries still require. However, modern cloud platforms offer UK-based data residency and meet GDPR requirements. For most businesses, the marginal control benefit is outweighed by the burden of maintaining hardware, applying patches, and managing capacity in-house. Q: How do update and maintenance costs compare? A: On-premise appliances need hardware replacement every three to five years, plus annual licence renewals and staff time for patching. Cloud-native security updates automatically and scales at a predictable monthly fee. Given that 43% of UK businesses reported a breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), delayed patching on owned equipment is a real and avoidable risk. Q: Can I run a hybrid of on-premise and cloud security? A: Yes. Many businesses keep on-premise firewalls alongside cloud-native tools like Microsoft Defender and Conditional Access during transition. The key is ensuring both layers share threat intelligence and policy enforcement. Over time most SMEs consolidate onto cloud-native platforms as they retire on-premise servers and move workloads to the cloud. Q: Which is cheaper, on-premise or cloud security? A: On-premise is usually cheaper in year one but more expensive across a three-to-five-year cycle once you add hardware replacement, licence renewals, and staff patching time. Cloud-native spreads cost into a predictable per-user monthly fee that scales with headcount, making it easier to budget and generally lower total cost of ownership for SMEs. Q: Does AMVIA support compliance requirements with cloud security? A: Yes. AMVIA's cloud-native stack supports GDPR and Cyber Essentials Plus compliance, with UK data residency options and audit-ready logging. We hold Cyber Essentials Plus ourselves and configure controls to support the framework your sector requires, rather than claiming a regulator's endorsement no vendor can give. --- # SIEM vs SOC: What's the Difference? URL: https://amvia.co.uk/cybersecurity/compare/siem-vs-soc Last updated: 2026-03 SIEM and SOC are not competing products - they are two halves of the same job. SIEM (Security Information and Event Management) is the software that collects and correlates security logs. A SOC (Security Operations Centre) is the team of analysts who read those alerts and act. SIEM is the tool; the SOC is the people who wield it. That distinction matters because most UK SMEs buy the wrong half. They license a SIEM platform, switch it on, and assume they are protected - then discover nobody is reading the alerts it produces. AMVIA runs both as one accountable service: SIEM technology operated by an in-house 24/7 SOC, under the principle of one provider, security-first, Microsoft-certified. If you want the wider picture of how detection, response and monitoring fit together, start with our managed cybersecurity pillar. ## What is SIEM, in plain terms? A SIEM is a data platform. It ingests logs from your firewalls, servers, Microsoft 365 tenant, endpoints and network, correlates events across all of them, and raises alerts when a pattern looks like an attack. It is the engine that turns millions of raw log lines into a shortlist of things worth investigating. What a SIEM does well: - Centralises logs from across your estate into one searchable place - Correlates events - linking a failed login in one system to data exfiltration in another - Raises alerts against detection rules and threat-intelligence feeds - Retains evidence for compliance, audits and post-incident forensics What a SIEM does not do: investigate, decide, or respond. It produces alerts. Without skilled people to triage them, a SIEM becomes an expensive log-storage box. The NCSC's logging guidance is clear that collecting logs only delivers value when someone monitors and acts on them. For the managed, SME-priced version of this, see our SIEM for SMEs service. ## What is a SOC, in plain terms? A SOC is the human and process layer. It is a team of security analysts who monitor the alerts your SIEM (and other tools) generate, investigate which are real, contain threats, and coordinate response. A SOC turns "an alert fired" into "the threat is shut down". It is the difference between owning a smoke detector and having a fire brigade on standby. A functioning SOC delivers: - 24/7 human monitoring - attacks do not wait for office hours - Triage and investigation - separating false positives from genuine threats - Threat hunting - proactively looking for what the rules missed - Incident response - containing and remediating, not just flagging A SOC can be built in-house or bought as a managed service. For most UK SMEs the maths only works as a service - covered in our managed SOC service and SOC-as-a-service pages. ## SIEM vs SOC: how do they compare? The simplest way to see it: SIEM is a *what*, a SOC is a *who*. One is a technology you license; the other is a capability you staff. You need both - and a managed SOC bundles them. | | Dimension | SIEM | SOC | What it is | Software platform | Team of analysts + process | Primary job | Collect, correlate, alert | Investigate, decide, respond | Runs without people? | No - alerts go unread | No - needs data from SIEM | Operating hours | Always-on data collection | 24/7 human coverage (if resourced) | Typical cost | £5,000–£50,000/yr platform | £150,000+/yr for 3 in-house analysts | Best fit for SMEs | Only as part of a managed service | Managed SOC (technology + analysts bundled) The figure of SIEM software costing £5,000 to £50,000 per year for the platform alone, and building a minimal SOC with three analysts on rotating shifts costing an additional £150,000 or more annually in salaries, reflect typical UK market rates as of 2026. Either way, the in-house route is out of reach for most businesses under 250 staff. ## Why do SMEs need both - and why a managed SOC wins? For most UK SMEs, the right answer is a managed SOC service rather than standalone SIEM. A managed SOC includes the SIEM technology, threat intelligence, and 24/7 analyst coverage in one service - delivering the outcomes SIEM alone promises but rarely achieves without dedicated staff to operate it. The threat data explains the urgency. Phishing remains the dominant entry point: 85% of breaches involved phishing (DSIT 2025), and 82.6% of phishing emails now use AI-generated content (KnowBe4) - which makes them harder for filters and untrained staff to spot. The government's Cyber Security Breaches Survey 2025 is the UK reference point for these numbers. Where breaches carry negative outcomes, the survey puts the average cost at £8,260. A SIEM will see the signs of these attacks. Only a SOC stops them. That is why standalone SIEM gives SMEs a false sense of security - the alerts fire, but nobody is watching. The NCSC's guidance on cyber threats reinforces that detection without response is incomplete protection. If endpoint detection or fully managed detection is more your question than logging specifically, compare MDR vs SIEM and read our managed detection and response overview. ## The AMVIA recommendation For most UK SMEs, choose a managed SOC over standalone SIEM. A managed SOC includes SIEM technology, threat intelligence, and 24/7 analyst coverage - the outcomes SIEM alone promises but rarely delivers without people to operate it. AMVIA's managed SOC service provides full coverage from £5,000 per year for organisations under 50 users, pairing Microsoft Defender telemetry with our in-house 24/7 SOC under a single, accountable contract. You get the platform and the people, billed as one service, backed by our 24/7 security monitoring. ## Frequently asked questions Q: Do I need a SIEM, a SOC, or both? A: They're two halves of one job: the SIEM is the software that collects and correlates security logs; the SOC is the team that investigates what it finds. A SIEM without a SOC generates alerts nobody reads; a SOC without log visibility is guessing. For SMEs the practical answer is a managed service that bundles both. Q: Why is running your own SIEM so expensive? A: The licence is the small part - SIEM platforms commonly run £5,000–£50,000+ a year - but the real cost is the analysts to tune it and watch it, which is why in-house SOC staffing starts around £150,000+ a year for even minimal coverage. Managed SOC services exist precisely to share that cost across clients. Q: What does a managed SOC actually do day to day? A: Ingests your logs and alerts, triages everything the tooling flags, discards the noise, investigates the genuine signals and escalates real incidents with containment already underway. You hear about the one alert that mattered, not the thousand that didn't. Q: Is a SIEM overkill for a small business? A: A full enterprise SIEM usually is - but the outcome (correlated visibility plus someone watching) isn't. SME-appropriate delivery is a managed service on modern tooling: 24/7 monitoring included in AMVIA's Enterprise plans rather than a six-figure internal build. --- # What Is Multi-Factor Authentication? UK Business Guide URL: https://amvia.co.uk/cybersecurity/questions/what-is-multi-factor-authentication Last updated: 2026-03 Multi-factor authentication requires a user to prove their identity with two or more separate factors before they can sign in, not just a password. It is the single most effective control a UK business can switch on, blocking over 99% of automated account compromise attacks and now treated as a baseline by insurers and most compliance frameworks. If you run security for a 10–500 staff business, MFA is the cheapest, highest-impact thing on your list. This guide explains how it works, which methods to trust, where attackers still get through, and how AMVIA rolls it out. As a security-first managed cybersecurity partner, we configure MFA correctly across Microsoft 365 every week, so the advice here is what we actually do, not theory. ## What are the three factors of authentication? A "factor" is a category of evidence that you are who you claim to be. MFA combines at least two of the three so that stealing one is not enough. A password alone is one factor; add a phone prompt and you have two. The categories are independent on purpose. - Something you know - a password, PIN or passphrase. - Something you have - a phone running an authenticator app, or a hardware security key. - Something you are - a fingerprint or face, read by the device. The strength of MFA comes from forcing an attacker to defeat two unrelated categories at once. A phished password is useless without the physical key sitting in your pocket. The NCSC sets out the same model in its multi-factor authentication guidance for organisations. ## Which MFA methods are most secure? Not all MFA is equal. The method you choose decides whether you stop ordinary credential theft only, or also resist targeted phishing. Authenticator apps are the right default for most businesses; hardware keys protect your highest-risk accounts; SMS is a last resort because it can be intercepted. ## Authenticator app ## SMS codes ## Hardware security keys ## Biometric ## MFA methods compared | | Property | SMS code | Authenticator app | Hardware security key | Phishing resistant | No | Partial | Yes | Works offline | No | Yes | Yes | SIM-swap resistant | No | Yes | Yes | User convenience | High | High | Medium | Cost per user | Free | Free | £20–£50 | Best used for | Fallback only | Most staff | Admin & finance accounts ## Can MFA be bypassed by attackers? Yes, weak MFA can be bypassed, which is why method choice matters. Adversary-in-the-middle (AitM) phishing relays your login in real time, and MFA fatigue spams push prompts until a tired user taps approve. SMS is exposed to SIM swapping. Phishing-resistant methods close these gaps. The defences that hold up are number-matching push notifications and hardware security keys, both of which break the AitM and fatigue playbooks. Pair them with strong email filtering, because phishing is still the front door. With 85% of businesses that experienced a breach identifying phishing as the vector (DSIT 2025), combining phishing-resistant MFA with managed email security gives you the strongest practical defence. ## Which accounts should have MFA enabled first? Start with the accounts that hand an attacker the keys to everything else. Administrator and global-admin accounts, email mailboxes, remote access such as VPN and RDP, finance and payment systems, and cloud service dashboards are the first targets in almost every intrusion. Protect these before worrying about low-privilege users. - Global administrator and IT admin accounts - Email and Microsoft 365 sign-ins - Remote access: VPN, RDP and any web portal - Finance, payroll and banking systems - Cloud and SaaS admin consoles With 22% of breaches involving compromised credentials (Verizon DBIR 2025), putting MFA on high-privilege accounts first removes your most exploitable attack surface fast. AMVIA enforces this through Microsoft Defender for Business and Conditional Access, so admin sign-ins simply cannot complete without a strong second factor. ## Why do cyber insurers require MFA as a policy condition? Insurers require MFA because credential-based attacks drive a large share of the most expensive claims, and MFA removes most of them. Policies now routinely specify that MFA must be live on email, VPN and cloud services as a precondition of cover. No MFA can mean a declined claim, not just a higher premium. The economics are blunt. The average cost of the most disruptive breach is £3,550 (DSIT 2025), and insurers see materially fewer and less severe claims from MFA-enabled organisations. If you are arranging or renewing cover, read our UK cyber insurance guide so the MFA box is genuinely ticked before the assessor checks. ## How should a UK business roll out MFA? Roll out in priority order, not all at once. Enable phishing-resistant MFA on admin and email accounts first, switch on number-matching to kill fatigue attacks, then extend to all staff with an authenticator app. Hand hardware keys to your highest-risk users. Document exceptions and review them. In Microsoft 365 this means enforcing MFA through Conditional Access rather than per-user toggles, disabling legacy authentication protocols that bypass MFA entirely, and registering a backup method so nobody gets locked out. This is exactly what our Microsoft 365 MFA setup service delivers, and it sits inside a wider zero trust model where identity, not the network perimeter, is the control point. One provider, security-first, Microsoft-certified - configured once, properly. ## Frequently asked questions Q: What is the difference between 2FA and MFA? A: Two-factor authentication (2FA) is MFA with exactly two factors - typically a password plus a phone code. MFA is the broader term covering two or more factors. In practice most business sign-ins use 2FA, and the terms are often used interchangeably. The security principle is identical: never rely on a password alone. Q: Is MFA the same as a password manager? A: No. A password manager stores and generates strong, unique passwords, which protects the "something you know" factor. MFA adds a second, independent factor on top. They solve different problems and work best together: a manager stops password reuse, while MFA stops a stolen password from being enough to log in. Q: Does MFA slow staff down? A: Barely, when configured well. With number-matching push notifications, signing in adds a single tap on a phone, and trusted devices can be remembered for a set period under Conditional Access. The friction is tiny next to the cost of a credential-based breach, and most users adapt within days of rollout. Q: Is SMS-based MFA still acceptable? A: SMS MFA is far better than none, but it is the weakest method because it is exposed to SIM-swapping and interception. The NCSC and Microsoft both recommend moving to an authenticator app or hardware key. Keep SMS only as a temporary fallback while you migrate staff to stronger methods. Q: Does Microsoft 365 include MFA? A: Yes. Every Microsoft 365 business plan includes MFA, and security defaults enable it out of the box. For real control you should enforce it through Conditional Access and disable legacy authentication, which security defaults alone do not fully cover. AMVIA configures this properly as part of a Microsoft 365 hardening project. Q: How long does it take to deploy MFA across a business? A: For a typical 10–500 staff business, a phased Microsoft 365 rollout takes days to a few weeks, not months. Admin and email accounts are secured first, then staff are enrolled in waves with an authenticator app. The work is mostly policy design and user communication, not technical complexity. --- # How Much Should a Small Business Spend on Cybersecurity? URL: https://amvia.co.uk/cybersecurity/questions/cyber-security-budget-small-business Last updated: 2026-03 A UK small business (10–50 staff) typically spends £400–£1,200 per month on cyber security - roughly £15–£25 per user per month for managed endpoint protection, email security, and monitoring. As a rule of thumb, allocate 5–15% of your total IT budget to security, weighted by the value of what you are protecting. AMVIA delivers all of it under one accountable, security-first provider. That is the short answer. The longer answer matters, because a cyber security budget set badly either wastes money on tools nobody watches or leaves the controls that actually stop attacks underfunded. This guide explains how to size your budget, where to spend first, and how to justify it to the people who sign it off. For a deeper breakdown of managed pricing, read our managed cybersecurity cost guide, and see the full managed cybersecurity pillar for the services these budgets buy. ## How much should a small business spend on cyber security? Most UK SMEs land between £200 and £1,500 per month (typical UK 2026 range), depending on headcount, sector, and risk profile. A 10-person firm with low-sensitivity data sits near the bottom; a 50-person professional-services business handling client money or health data sits near the top. The honest answer is risk-based: spend in proportion to what a breach would cost you. That context is not abstract. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a breach or attack in the past year (Cyber Security Breaches Survey 2025), and the average cost of the most disruptive breach was £3,550 (Cyber Security Breaches Survey 2025). Underspending is rarely a saving - it is deferred cost with interest. A useful comparison: a single in-house security hire costs £40,000–£55,000 per year in salary alone (market rates as of 2026), before tooling, training, holiday cover, or out-of-hours response. Managed security spreads that capability across many clients, which is why per-user pricing usually wins for businesses under 250 staff. | | Business size | Typical monthly spend (UK, 2026) | What it usually covers | Micro (1–10) | £100–£300/mo | Endpoint protection, email security, MFA | Small (10–50) | £300–£1,200/mo | The above + 24/7 monitoring, vulnerability management | Medium (50–250) | £1,200–£5,000/mo | The above + incident response retainer, compliance support Budget ranges are indicative. Actual cost depends on industry, risk profile, and compliance requirements. ## How do you build a practical security budget? Build it in four moves: assess risk, prioritise by impact, factor in compliance, and choose pricing that scales. Skip the assessment and you will buy tools that protect the wrong things. The goal is not "maximum security" - it is the most risk reduced per pound, in the order that reduces it fastest. Start with a risk assessment. Identify the data and systems whose loss would hurt most - customer records, financial systems, intellectual property, the email accounts that authorise payments. Your budget protects those first. The NCSC's Small Business Guide is a free, practical starting point for working out where you are exposed. Prioritise by impact. Fund the controls that close the most common attack routes before anything exotic: multi-factor authentication, email security, endpoint protection, and reliable backups. These cover the overwhelming majority of how SMEs actually get breached. Start with MFA across Microsoft 365 and managed email security - they stop the phishing and credential attacks that drive most incidents. Factor in compliance. If you bid for enterprise or public-sector work, or operate in a regulated sector, budget for the certifications those contracts demand. Cyber Essentials Plus is the baseline most UK buyers now expect; some larger frameworks reference ISO 27001. AMVIA holds Cyber Essentials Plus, which means we run our own estate to the standard we help you meet. Plan for growth. Choose per-user pricing that scales as you hire, and avoid large upfront capital spend on security hardware that dates quickly. Cloud-delivered controls flex with headcount and keep your budget predictable. ## Where should the first £500 a month go? If you only have a modest monthly budget, spend it on the controls with the highest stop rate per pound: MFA, managed email security, and managed endpoint detection. These three block the entry points behind most SME breaches and cost far less than recovering from one. Monitoring comes next, so a real human sees the alert that matters. In practical order of priority: - Multi-factor authentication on every account - the single highest-leverage control, and effectively free with Microsoft 365. - Managed email security - email security filtering using the Microsoft Defender and Barracuda stack to stop phishing and business email compromise. - Managed endpoint protection - endpoint security built on Microsoft Defender for Endpoint, so a compromised laptop is contained, not catastrophic. - 24/7 monitoring - round-the-clock monitoring from AMVIA's in-house SOC, because attacks do not keep office hours. - Tested backups - the control that turns a ransomware crisis into an inconvenience. Only once those are funded does it make sense to add vulnerability management, an incident-response retainer, and formal compliance work. Buying a SIEM before you have MFA is buying a smoke alarm for a house with the front door open. ## How do you justify cyber security spend to the board? Frame it as risk reduction, not a cost centre. Put the budget next to the exposure it removes: the cost of a disruptive breach, the regulatory fines a data loss would trigger, the cyber-insurance premium it lowers, and the contracts a certification enables. Boards fund quantified risk far more readily than they fund "security". Two numbers do most of the work. First, the average most-disruptive breach costs £3,550 (Cyber Security Breaches Survey 2025) - and that rises sharply once data loss, downtime, and ICO involvement enter the picture. Second, only 14% of UK businesses review the cyber risks posed by their immediate suppliers (Cyber Security Breaches Survey 2025), which means demonstrable security is increasingly a competitive advantage in tenders, not just a defence. Present three things and most boards say yes: the financial exposure the budget mitigates, the insurance and contract upside it creates, and the named provider accountable for delivering it. ## Frequently asked questions Q: What percentage of our IT budget should go to cyber security? A: Industry guidance suggests 5–15% of total IT spend, though the right figure depends on your risk profile and the data you hold. Regulated firms and those handling sensitive client information should budget towards the higher end. With 43% of UK businesses hit by a breach or attack last year (Cyber Security Breaches Survey 2025), underspending is usually a false economy. Q: How much does cyber security cost per user per month? A: For a managed bundle of endpoint protection, email security, and monitoring, UK SMEs typically pay £15–£25 per user per month. Per-user pricing scales cleanly as you hire and avoids large upfront hardware costs. Exact pricing depends on the controls included and your compliance requirements - our managed cybersecurity cost guide breaks it down. Q: Is managed security cheaper than hiring in-house? A: For most businesses under 250 staff, yes. A single in-house security analyst costs £40,000–£55,000 per year in salary alone, plus tooling, training, and holiday and out-of-hours cover. Managed security spreads a 24/7 team and enterprise tooling across many clients, so you get round-the-clock coverage for a fraction of one full-time salary. Q: Are there grants or tax benefits for cyber security spending? A: Cyber security spend is an allowable business expense for corporation tax. Some local enterprise partnerships and industry bodies run funded cyber-readiness programmes for SMEs, and the NCSC publishes free guidance and tools. Achieving Cyber Essentials is low-cost and can be a contractual requirement for public-sector work. Q: What should we fund first on a small budget? A: Fund MFA, managed email security, managed endpoint protection, and tested backups before anything else. These four close the entry points behind most SME breaches and cost far less than recovering from one incident. Add 24/7 monitoring next so alerts reach a human, then layer on vulnerability management and compliance support as budget allows. Q: How often should we review the security budget? A: Review it at least annually, and whenever you change headcount, win a contract with new security obligations, or adopt new systems. Threats and business risk both move, so a budget set once and forgotten drifts out of line with your actual exposure within a year. --- # What Is a Business Continuity Plan and Does My Business Need One? URL: https://amvia.co.uk/cybersecurity/questions/what-is-business-continuity-plan Last updated: 2026-03 A business continuity plan (BCP) is a documented, tested process for keeping your essential operations running during and after a disruption - a cyberattack, power cut, supplier failure or lost premises. It defines what must stay up, how fast, and who does what. AMVIA builds tested continuity into managed cybersecurity: one accountable provider, security-first. ## What does a business continuity plan actually do? A business continuity plan keeps your business trading when something breaks. It identifies your critical systems and processes, sets recovery time targets, and documents exactly how people, data and communications carry on while the primary environment is unavailable. The goal is simple: limit downtime, protect revenue, and reach customers and staff fast. Downtime is where the money goes. Only 25% of UK businesses have a formal incident response plan in place (DSIT Cyber Security Breaches Survey 2025/26) - which means most are improvising during the exact hours when improvisation is most expensive. A BCP turns a panicked scramble into a rehearsed sequence. A good plan answers four questions before disaster strikes: - What must stay running? The handful of systems and processes the business cannot trade without. - How quickly must each recover? Your recovery time objective (RTO) and recovery point objective (RPO). - Who decides and who acts? Named roles, deputies, and an escalation chain that works at 2am. - How do people keep working? Failover connectivity, manual workarounds, and alternative access to data. ## What should a business continuity plan include? At a minimum a BCP should cover critical-system identification, recovery time and recovery point objectives, backup and restore procedures, a communications protocol, defined roles and deputies, and alternative working arrangements. It must be written down, owned by a named person, and tested - an untested plan is a guess, not a control. The components that separate a real plan from a shelf document: - Business impact analysis - which functions hurt most, and how fast, when they stop. - Tested backups - verified restores, not just "the backup ran". Backups that have never been restored fail at the worst moment. - Failover connectivity - a second route to the internet so a single line cut does not close the office. This is where a business continuity service earns its keep. - Incident communications - a contact tree, holding statements, and a channel that works when email is down. - An incident response runbook - the technical steps to contain, eradicate and recover from a security event. The UK's National Cyber Security Centre publishes detailed incident management guidance that pairs well with a BCP and is worth reading alongside your own plan (ncsc.gov.uk). ## How is a BCP different from a disaster recovery plan? A disaster recovery (DR) plan is the IT-restoration half of the picture: getting systems, servers and data back online after a failure. A business continuity plan is the wider organisational view - how the whole business keeps serving customers during the disruption, including people, premises, communications and manual workarounds. You need both, and they must reference each other. | | Aspect | Business Continuity Plan (BCP) | Disaster Recovery Plan (DR) | Scope | Whole organisation - people, process, premises, IT | IT systems, data and infrastructure only | Core question | How do we keep trading? | How do we restore the technology? | Owner | Leadership / operations | IT or managed IT provider | Typical contents | Impact analysis, roles, comms, workarounds | Backups, failover, restore runbooks, RTO/RPO | When it activates | Any major disruption | Specifically a systems/data outage The practical takeaway: DR is a subset of continuity. A business that has invested in Microsoft 365 backup and failover but never wrote down who calls customers, who authorises spend, or where staff work has a recovery plan, not a continuity plan. ## Why do UK businesses need a business continuity plan now? Because disruption is no longer rare. 43% of UK businesses experienced a cyber breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey 2025 (gov.uk). When the worst breach lands, the average cost is around £3,550 - and that headline figure excludes the operational losses that downtime piles on top. Three forces make continuity planning a board-level issue for SMEs in 2026: - Ransomware stops operations, not just data. A single ransomware attack can freeze every endpoint at once. Recovery time, not ransom payment, is the real cost. - Cloud dependence concentrates risk. When Microsoft 365 or your primary line is the whole business, a single failure is an existential one without failover. - Customers and regulators expect resilience. Buyers ask about continuity in due diligence; supply-chain questionnaires now treat a tested BCP as table stakes. A plan does not stop incidents. It decides whether one costs you an hour or a fortnight. ## How often should you test a business continuity plan? Test your BCP at least annually, and again after any significant change to systems, premises or staffing. Testing should verify backup restores, run a failover simulation, and walk the communication chain end to end. Most failures - corrupted backups, stale contact lists, a deputy who left last year - only surface in a test, which is exactly why you run one before an incident finds them for you. A sensible testing cadence: - Quarterly - verify a real restore from backup, not just the backup job status. - Annually - a full tabletop exercise walking the team through a realistic scenario. - After major change - new ERP, office move, merger, or a switch of IT provider. Pair testing with continuous 24/7 security monitoring so the events your plan is built for are detected early, when they are cheapest to contain. ## How does AMVIA build business continuity into managed IT? AMVIA bakes continuity into the day job rather than selling it as a separate document. Tested backups, failover connectivity, a documented incident runbook and clear recovery objectives sit inside the managed service, monitored by an in-house 24/7 SOC using Microsoft Defender for Endpoint. One provider, security-first, Microsoft-certified - so the people who run your systems also own your recovery. That single-accountability model matters during an incident. There is no finger-pointing between a backup vendor, an IT contractor and a connectivity reseller - the same team that detects the event also restores the service and keeps you informed. ## Frequently asked questions Q: What is a business continuity plan in simple terms? A: A business continuity plan is a written, tested set of instructions for keeping your essential operations running through a disruption such as a cyberattack, outage or loss of premises. It names your critical systems, sets how quickly each must recover, and assigns who does what - so the business keeps trading instead of grinding to a halt. Q: What should a small business continuity plan include? A: At minimum: a business impact analysis, recovery time and recovery point objectives, tested backups, failover connectivity, a communications plan, and named roles with deputies. Keep it short enough to actually use under pressure. A two-page plan people have rehearsed beats a fifty-page binder nobody has opened since it was written. Q: How is a business continuity plan different from disaster recovery? A: Disaster recovery restores IT systems and data after a failure. Business continuity is broader - it covers how the whole organisation keeps operating during the disruption, including staff, premises, communications and manual workarounds. Disaster recovery is effectively the IT chapter inside a complete business continuity plan, and the two should cross-reference each other. Q: How often should a business continuity plan be tested? A: Test it at least once a year, and again after any major change to your systems, premises or staffing. Verify a genuine backup restore quarterly, run a full tabletop exercise annually, and update the plan whenever contacts or infrastructure change. Untested plans routinely hide corrupted backups and out-of-date contact details that only appear during a real incident. Q: Does a small UK business really need a business continuity plan? A: Yes. 43% of UK businesses suffered a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), and smaller firms are least likely to have a formal plan. Downtime costs mount by the minute, and customers and insurers increasingly expect evidence of a tested plan before they trust you with their data. Q: Who should own the business continuity plan? A: A named senior person should own the plan, with the technical recovery elements run by your IT or managed IT provider. Ownership cannot be vague - someone must be accountable for keeping it current, scheduling tests, and making the call to activate it. AMVIA takes ownership of the technical recovery layer as part of its managed IT support. --- # What Is the Dark Web and Should UK Businesses Be Worried? URL: https://amvia.co.uk/cybersecurity/questions/what-is-dark-web Last updated: 2026-03 The dark web is a hidden layer of the internet reachable only through anonymising software like Tor and never indexed by Google. It hosts privacy tools, but also criminal marketplaces where stolen business credentials, financial data and network access are bought and sold. UK businesses should treat it as a live risk, not background noise. The uncomfortable part: your staff's stolen passwords can sit on a dark web market for months before anyone uses them to break into your systems. That gap between theft and exploitation is exactly where a security-first provider earns its keep. If you want the operational view of how that data gets caught early, read our managed cybersecurity approach, which treats credential exposure as a monitored, alertable event rather than an after-the-fact surprise. ## What exactly is the dark web? The dark web is the portion of the internet that standard browsers and search engines cannot reach. You get to it with specialised software such as Tor, which anonymises traffic by routing it through multiple relays. It is not inherently criminal - journalists and privacy advocates use it - but its anonymity also shelters illegal marketplaces. It helps to separate three layers: - Surface web - everything Google indexes: public websites, blogs, product pages. - Deep web - content behind logins or paywalls: your email inbox, online banking, internal portals. Most of the internet sits here, and it is not sinister. - Dark web - sites deliberately hidden and reachable only via Tor or similar networks. The confusion usually comes from treating "deep web" and "dark web" as the same thing. They are not. Your CRM login page is deep web. A marketplace selling that login is dark web. ## What is the difference between the surface web, deep web and dark web? The surface web is indexed and openly searchable, the deep web is legitimate content gated behind authentication, and the dark web is intentionally concealed infrastructure accessed through anonymising tools. Only the third layer is where stolen business data is routinely traded, which is why it matters to UK decision-makers. | | Layer | How you reach it | Indexed by Google? | Typical content | Business risk | Surface web | Any browser | Yes | Public sites, marketing pages | Low | Deep web | Browser + login | No | Email, banking, internal apps | Medium (if credentials leak) | Dark web | Tor / specialist software | No | Hidden marketplaces, forums | High (your data may be for sale) The practical takeaway: you cannot monitor the dark web by browsing it casually, and you should not try. What you can do is monitor whether your domains, mailboxes and credentials have surfaced there - covered in our guide to dark web monitoring. ## What business data is sold on the dark web? The product on dark web marketplaces is your data. Employee email credentials, customer databases, financial records, and VPN or remote desktop access into corporate networks are all traded openly. Ransomware groups also sell "initial access" - a working route into an organisation - to other criminals who carry out the actual attack. What changes hands most often: - Email and Microsoft 365 logins - the master key to most businesses, because email resets everything else. - Reused passwords - harvested from unrelated breaches, then tried against your systems. - VPN and remote desktop access - a direct tunnel into the network. - Customer and financial records - sold for fraud or used as ransomware leverage. With "22% of breaches involving compromised credentials (Verizon DBIR 2025)", stolen logins are not a fringe concern - they are one of the most common ways attackers get in. The UK government's annual Cyber Security Breaches Survey tells the same story at national scale: credential theft and phishing dominate the breach data year after year. ## How do business credentials end up on the dark web? Credentials reach the dark web through phishing, third-party breaches where staff reused passwords, and malware that quietly harvests saved browser logins. Once stolen, they are sold in bulk or used directly to access corporate systems. Email compromise is the most common starting point by a wide margin. The usual routes, in order of how often we see them: 1. Phishing - a convincing email tricks a member of staff into typing their password into a fake login page. 2. Password reuse - a breach at an unrelated service exposes a password your employee also uses at work. 3. Infostealer malware - malicious software grabs saved passwords, cookies and session tokens from the browser. 4. Social engineering - an attacker manipulates someone into handing over access directly. The data backs the ranking. "85% of breached businesses identified phishing as the vector (DSIT 2025)" - which is why email security and staff awareness are the highest-leverage controls most SMEs can deploy. If phishing is your front door, harden it: our email security service exists precisely to stop the messages that start this chain. The NCSC's guidance on phishing is a sound, free starting point for any UK business. ## Can law enforcement shut the dark web down? No - not in any lasting way. Agencies like the National Crime Agency regularly seize marketplaces and arrest operators, but replacements appear within weeks because the infrastructure is decentralised and anonymous. Waiting for a takedown is not a strategy. The controls you own - multi-factor authentication, monitoring and staff training - are what actually protect you. This is the part businesses get wrong. They read about a marketplace being seized and assume the threat receded. It did not. The data already traded is still out there, and a new market is already trading it. The gap is preventable but widely ignored. Only "47% of UK businesses have two-factor authentication in place (DSIT 2025/26)", which means stolen passwords remain directly usable at most companies. Turning on multi-factor authentication is the single cheapest, highest-impact control available - the NCSC strongly recommends MFA for exactly this reason. ## How should UK businesses defend against dark web threats? Defence is about closing the loop between theft and exploitation: stop credentials leaking, detect them when they do, and make stolen ones useless. That means layered controls - MFA, credential monitoring, fast detection and staff awareness - rather than any single product. The goal is to make a stolen password worthless before it is ever used. What we recommend, in priority order: - Enforce MFA everywhere, especially on Microsoft 365 and remote access. A stolen password alone should never grant entry. - Monitor for exposed credentials so a leak triggers an alert and a forced reset, not a breach. - Detect and respond fast - managed detection and response backed by AMVIA's in-house 24/7 SOC catches the use of stolen access in minutes, not months. - Train your people - phishing is the number-one entry point, so the inbox is the front line. - Have a plan for when prevention fails - a tested incident response process turns a crisis into a procedure. One provider, security-first, with Microsoft-certified engineers is how AMVIA keeps these controls joined up rather than scattered across vendors who each see only their slice of the problem. ## Frequently asked questions Q: What is the dark web in simple terms? A: The dark web is a hidden part of the internet you can only reach with anonymising software like Tor, and which search engines do not index. It is used for legitimate privacy as well as criminal marketplaces. For businesses, it matters because stolen logins, customer data and network access are bought and sold there. Q: Is it illegal to access the dark web in the UK? A: Accessing the dark web is not illegal in the UK - the Tor network itself is a legal privacy tool. What is illegal is buying, selling or accessing criminal goods and services found there. For most businesses there is no reason to visit it; the right response is to monitor whether your data has appeared on it, not to browse it. Q: What types of business data are sold on the dark web? A: Employee email and Microsoft 365 credentials, customer databases, financial records, and VPN or remote desktop access are all traded on dark web marketplaces. Ransomware groups also sell initial access into compromised organisations. With "22% of breaches involving compromised credentials (Verizon DBIR 2025)", your data can appear there long before you notice a breach. Q: How do business credentials end up on the dark web? A: Credentials reach the dark web mainly through phishing, breaches at third-party services where passwords were reused, and malware that harvests saved browser logins. They are then sold in bulk or used directly. With "85% of breached businesses identified phishing as the vector (DSIT 2025)", email compromise is the most common starting point. Q: Can the dark web be shut down by law enforcement? A: Agencies regularly seize marketplaces and arrest operators, but new platforms replace them quickly because the infrastructure is decentralised and anonymous. Waiting for enforcement is not a defence. Practical controls - MFA, credential monitoring and staff awareness - are what protect you. Only "47% of UK businesses have two-factor authentication in place (DSIT 2025/26)", leaving stolen credentials highly exploitable. Q: How do I know if my business data is on the dark web? A: You find out through dark web monitoring, which scans marketplaces and breach dumps for your domains, mailboxes and credentials, then alerts you so you can force password resets before the data is used. AMVIA includes this in its managed security service, pairing detection with the response needed to act on a hit. --- # How Much Does Penetration Testing Cost in the UK? URL: https://amvia.co.uk/cybersecurity/questions/penetration-testing-cost-uk Last updated: 2026-03 Penetration testing in the UK typically costs £2,000 to £15,000+, depending on scope. A small external network test sits at the lower end; complex web-application or multi-environment testing reaches the top. Price tracks the size of your attack surface, the test type, and whether social engineering is included. AMVIA scopes every test to your real risk, not a template. If you are weighing up a pen test as part of a wider security budget, read it alongside our managed cybersecurity guide for UK SMEs - a pen test is a point-in-time check, not a substitute for continuous monitoring. This guide breaks down what you actually pay, what changes the number, and how to tell a real test from an automated scan dressed up as one. ## What does a penetration test cost in the UK? A penetration test in the UK costs £2,000 to £15,000+ as of 2026, depending on what is in scope. A basic external network test for a typical SME is the cheapest engagement; web-application testing and full-scope work cost considerably more because they take more skilled tester days. The figures below are market ranges, not a fixed price list - always get a scoped quote. | | Test type | Typical UK cost (2026) | Best for | Basic external network test (SME) | £2,000–£5,000 | Validating your internet-facing perimeter | Web application test | £3,000–£10,000 | Apps handling logins, payments or customer data | Full / complex scope | £2,000–£15,000+ | Cloud, hybrid or multi-environment estates The single biggest lever on cost is tester time. A perimeter with a handful of public IPs is a couple of days' work; a bespoke web application with dozens of authenticated user journeys can run to a week or more. The NCSC's guidance on penetration testing is clear that a test is only as good as its scope - a cheap test against the wrong targets tells you nothing useful. ## What drives the price of a penetration test? Price is set by how much there is to test and how hard it is to test safely. The number of in-scope IP addresses, applications and environments sets the baseline; complexity and the type of test then move the number up or down. Social engineering and physical testing add cost because they need extra planning and sign-off. The main cost drivers: - Scope - the count of IP addresses, applications and environments in the engagement. - Complexity - cloud, hybrid or on-premise; a single estate is cheaper than three. - Test type - external, internal, web application, wireless or red team. - Social engineering - phishing or pretext calling adds planning and reporting time. - Retesting - a re-test to confirm fixes have landed is often quoted separately. Authentication is where attackers win, so it is worth paying to test it properly. With 22% of breaches involving compromised credentials (Verizon DBIR 2025), a test that exercises your login flows, MFA and privilege boundaries earns its fee. Pair pen testing with continuous vulnerability management so issues found are tracked and closed, not filed and forgotten. ## What types of penetration test are there? There are several test types, and most SMEs do not need all of them. The right mix depends on where your risk actually sits - a software business lives or dies by its web application, while a professional-services firm worries more about its perimeter and email. Scope to the assets that would hurt most if breached. - External network test - probes your internet-facing systems the way an opportunistic attacker would. - Internal network test - assumes a foothold (a stolen laptop, a phished account) and tests how far an intruder could move. - Web application test - examines a specific app for flaws like broken access control and injection. - Wireless test - checks your Wi-Fi segmentation and authentication. - Social engineering - tests your people and processes, not just your technology. If you are not sure which applies, our penetration testing service page sets out how AMVIA scopes an engagement before any quote is issued. ## Do you need an accredited penetration testing provider? Look for recognised accreditation. CREST (or CHECK for public-sector work) signals that a testing firm meets agreed standards for methodology, ethics and data handling, and that its testers follow a structured approach rather than running an automated scanner and exporting the results. Many cyber insurers and compliance frameworks now expect tests to be carried out by accredited providers. Accreditation matters because "penetration test" is an unregulated label. Anyone can sell one. The difference between a skilled manual test and an automated vulnerability scan with a nicer cover page is the difference between finding the chained flaw that actually gets someone in and producing a list of low-severity noise. Ask any prospective provider who will run the test, what methodology they follow, and how they handle your data during and after the engagement. ## How does a pen test compare to Cyber Essentials Plus? They do different jobs. Cyber Essentials Plus includes a hands-on technical audit that verifies five core controls are in place and working - it is a baseline assurance certification. A penetration test goes deeper, actively trying to exploit weaknesses across your real attack surface. Most businesses handling sensitive data want both. | | | Cyber Essentials Plus | Penetration test | Purpose | Verify five baseline controls | Find and exploit real weaknesses | Depth | Defined audit checklist | Open-ended, attacker-led | Output | Pass / fail certification | Ranked findings + remediation | Renewal | Annual | After major change or annually Cyber Essentials is government-backed and worth holding regardless - see the official Cyber Essentials scheme for what it covers. The certification carries real insurance weight too: organisations certified with Cyber Essentials are 92% less likely to claim on cyber insurance (IASME). A pen test then gives auditors and insurers the granular, real-world evidence that certification alone does not. AMVIA holds Cyber Essentials Plus and uses it as the floor, not the ceiling. ## How often should you run a penetration test? Annually at minimum, and again after any major change. Annual pen testing is recommended for businesses handling sensitive data or pursuing certifications. A test is a snapshot - a new web feature, a cloud migration or a network redesign can introduce a flaw the day after a clean report, so re-test when your attack surface changes materially. The UK threat picture makes the case on its own: the government's Cyber Security Breaches Survey 2025 shows cyber attacks remain a routine hazard for British businesses. Between annual tests, lean on continuous controls - managed detection and response catches what a point-in-time test cannot, because attackers do not wait for your testing window. ## What should a penetration test report include? A good report is written for two audiences. Leadership needs an executive summary that explains business risk in plain English; your technical team needs findings ranked by severity, evidence of exploitation, and prioritised, specific remediation steps. A report that is just a tool's raw output is not worth paying for. A thorough report includes: - An executive summary for non-technical leadership. - Technical findings ranked by severity (critical, high, medium, low). - Evidence of exploitation - proof each finding is real, not theoretical. - Prioritised remediation guidance mapped to each finding. - A clear path to re-testing so you can prove fixes worked. If you would rather spend on continuously closing gaps than on a once-a-year document, compare the cost of testing with the cost of managed protection in our guide to how much managed cybersecurity costs. ## Frequently asked questions Q: How much does penetration testing cost for a small business in the UK? A: For most small businesses, a basic external network test runs £2,000–£5,000, while a web-application test can reach £3,000–£10,000 depending on complexity. Overall, UK pen tests span £2,000–£15,000+ (typical UK 2026 range). The figure depends on scope, test type and whether social engineering is included, so always get a scoped quote rather than relying on a list price. Q: What factors affect the price of a penetration test? A: The main drivers are scope (number of IP addresses, applications or environments), complexity (cloud, hybrid or on-premise), test type (external, internal or web application), and whether social engineering is included. Because 22% of breaches involve compromised credentials (Verizon DBIR 2025), testing authentication and access controls is consistently worth the investment. Q: Is penetration testing a legal requirement in the UK? A: There is no blanket UK law requiring penetration testing, but it is often a practical requirement. Cyber insurers, larger customers and frameworks such as PCI DSS frequently expect regular testing, and it supports your wider data-protection obligations. Treat it as a commercial and compliance expectation rather than an optional extra. Q: What is the difference between a vulnerability scan and a penetration test? A: A vulnerability scan is an automated tool that lists known weaknesses - fast, cheap and shallow. A penetration test is a skilled human actively trying to exploit those weaknesses, chaining flaws the way a real attacker would. A scan tells you what might be wrong; a pen test proves what an intruder could actually do with it. Q: Should I choose a CREST-accredited provider? A: Accreditation such as CREST (or CHECK for public-sector work) signals that testers meet recognised standards for methodology, ethics and data handling. Many cyber insurers and compliance frameworks now expect accredited providers. Always ask who runs the test, what methodology they follow, and how your data is handled during and after the engagement. Q: Does Cyber Essentials Plus include a penetration test? A: No. Cyber Essentials Plus includes a hands-on technical audit that verifies five baseline controls are working, but it is not a full penetration test. A pen test goes deeper, actively exploiting weaknesses across your real attack surface. Many businesses hold Cyber Essentials Plus as a baseline and add an annual pen test for deeper assurance. --- # How to Protect Your Business from AI-Generated Cyber Attacks URL: https://amvia.co.uk/cybersecurity/questions/how-to-protect-against-ai-attacks Last updated: 2026-03 To protect against AI attacks, move from signature-based tools to behavioural detection, enforce out-of-band verification for payments, filter email with AI-aware security, and put a 24/7 human-led SOC over the lot. AI changes the speed and quality of attacks, not the fundamentals of good defence - and one accountable, security-first provider makes that defence far easier to run. AI has not invented a new category of crime. It has industrialised the old ones. Phishing, fraud and malware now arrive with perfect grammar, cloned voices and code that mutates faster than any signature can keep up. This guide is the version we send to MDs and IT directors who ask, plainly, "what do we actually do about this?" It maps to our wider managed cybersecurity approach for UK SMEs. ## What makes AI-powered attacks different from traditional ones? AI attacks differ in three ways: quality, speed and scale. Generative models write flawless, personalised phishing; they automate reconnaissance and exploitation at machine speed; and they let one attacker target thousands of businesses at once. The tactics are familiar - the volume and believability are not. The old tells are gone. Spelling mistakes, clumsy phrasing and generic greetings used to give phishing away. Now an attacker scrapes a target's LinkedIn, feeds it to a model, and produces an email that references a real project and a real colleague by name. The NCSC has been clear that AI is lowering the barrier to entry for less-skilled attackers while making capable ones more efficient. | | Feature | Traditional attacks (still common) | AI-enhanced attacks (growing rapidly) | Phishing quality | Often obvious errors | Perfect grammar, personalised | Attack speed | Manual, slower | Automated, rapid | Social engineering | Email-based | Deepfake voice and video | Malware evasion | Static variants | Polymorphic, adaptive | Scale | Limited by human effort | Thousands of targets at once ## How do you defend against AI-generated phishing emails? Defend against AI phishing with AI-aware email security plus trained people. Modern filtering reads intent and context, not just keywords and known-bad links, so it flags convincing lures that rule-based gateways wave through. Pair that with staff who know what an AI-crafted email now looks like. Phishing is still the front door. 85% of businesses that experienced a breach identified phishing as the attack type (DSIT 2025), per the government's Cyber Security Breaches Survey. AI does not change that - it makes the lures harder to spot, which raises the value of strong email security and realistic phishing simulation and training. What we deploy and recommend: - AI-aware email filtering that scores messages on behaviour and context, not just signatures. - DMARC, DKIM and SPF properly enforced so impersonation of your own domain fails at delivery. - Continuous awareness training focused on AI-specific cues, not last decade's "look for typos" advice. - A reporting button that makes "flag this" a one-click habit for every employee. ## How do you stop deepfake voice and video fraud? Stop deepfake fraud with process, not just technology. Deepfakes clone a CEO's voice or face to authorise a payment or extract data. No filter catches a phone call, so the control that works is a rule: every financial or sensitive request is verified out-of-band through a known, pre-agreed channel - no exceptions, however convincing the caller. This is the fastest-growing AI threat to mid-sized businesses. Overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), and cheap voice-cloning tools have turned a rare, high-effort scam into a repeatable one. The defence is mundane and effective: a documented verification procedure, a second authoriser for payments above a threshold, and a culture where pausing to check is praised, not penalised. We build these into client incident response playbooks so the right action is obvious under pressure. ## Can your existing security tools detect AI-powered attacks? Signature-based tools struggle, because AI generates a unique variant for every attack and there is no known signature to match. Behavioural detection through EDR and MDR is far more effective - it spots the suspicious activity (a process injecting code, credentials moving abnormally) regardless of how the payload looks. This matters because credentials are a primary target. 22% of breaches involved compromised credentials (Verizon DBIR 2025), and AI accelerates credential-harvesting at scale. Upgrading from legacy antivirus to behavioural managed detection and response is one of the highest-impact moves a UK SME can make. We run this on endpoint security built on Microsoft Defender for Endpoint, monitored by our own 24/7 SOC - one provider, security-first, Microsoft-certified, rather than a stack of disconnected tools nobody is watching. ## What practical steps should a UK SME take first? Start with the controls that blunt the most attacks for the least effort: multi-factor authentication everywhere, behavioural endpoint protection, enforced email authentication, and human monitoring. None of these are exotic. Together they remove the easy wins AI gives attackers. A pragmatic order of operations: 1. Turn on MFA everywhere - it neutralises most credential-harvesting, AI-driven or not. Microsoft's own guidance on identity and access security sets out the baseline. 2. Replace legacy antivirus with EDR/MDR so detection follows behaviour, not signatures. 3. Enforce DMARC and lock down email so your domain can't be spoofed. 4. Adopt zero trust - verify every request, assume breach. 5. Get continuous human monitoring via a 24/7 security operations centre so machine-speed attacks meet machine-speed-plus-judgement response. ## How does zero trust help against AI attacks? Zero trust assumes the perimeter will be breached and verifies every access request regardless of source. When an AI-driven attack does get a foothold - a stolen credential, a convincing phish - segmentation and continuous verification contain it, so one compromised account doesn't become a company-wide incident. The NCSC's zero trust guidance is the UK reference point. The principle is simple to state and harder to live by: never trust by default, always verify, and grant the least access needed. Applied properly through a zero trust architecture, it turns a successful AI-crafted intrusion from a breach into a blocked event. ## Frequently asked questions Q: How do AI-generated phishing emails differ from traditional ones? A: AI-generated phishing emails use flawless grammar, personalised context scraped from social media, and convincing impersonation of known contacts. Traditional phishing often contained spelling errors and generic wording trained staff could spot. With 85% of businesses that experienced a breach identifying phishing as the attack type (DSIT 2025), AI is making these attacks significantly harder to distinguish from genuine correspondence. Q: Can existing security tools detect AI-powered attacks? A: Signature-based tools struggle, because each AI-generated variant is unique with no known signature to match. Behavioural detection through EDR and MDR is far more effective, identifying suspicious activity patterns regardless of the payload's appearance. With 22% of breaches involving compromised credentials (Verizon DBIR 2025), upgrading from legacy antivirus to behavioural endpoint protection is one of the most impactful steps a business can take. Q: What are deepfake attacks and how do we defend against them? A: Deepfake attacks use AI to clone voices or create realistic video of trusted individuals - typically a CEO or supplier - to authorise fraudulent payments or extract data. Overall IC3-reported cybercrime losses increased 33% from 2023 (FBI IC3 2024 report), amplified by deepfake tools. The strongest defence is out-of-band verification for any financial or data request, regardless of how convincing the communication appears. Q: Are small businesses really a target for AI attacks? A: Yes. AI lets attackers hit thousands of targets at once, so small and mid-sized firms are swept up in automated campaigns that previously weren't worth the effort. UK SMEs are frequently chosen precisely because they assume they're too small to bother with. The NCSC maintains free, SME-focused guidance for exactly this reason. Q: Does AMVIA use AI to defend clients? A: Yes. The behavioural detection in Microsoft Defender for Endpoint uses machine learning to flag anomalous activity, and AI-aware email filtering scores messages on intent rather than keywords. The difference is that our 24/7 SOC puts human analysts over the AI, so the subtle patterns automated tools miss still get caught and acted on. Q: What is the single most important control against AI attacks? A: Multi-factor authentication, closely followed by behavioural endpoint detection. MFA neutralises most credential theft - the entry point AI scales most aggressively - while EDR/MDR catches what gets through. Neither is expensive or exotic; both should be in place before any AI-specific tooling is considered. --- # What Is a Remote Monitoring and Management (RMM) Tool? URL: https://amvia.co.uk/managed-it/questions/what-is-an-rmm-tool Last updated: 2026-03 An RMM (Remote Monitoring and Management) tool is the software a managed IT provider uses to monitor, manage and support your computers and servers remotely. It tracks device health in real time, deploys patches automatically, runs scripts and gives engineers secure remote access - so problems get fixed before your staff ever notice them. That last point is the whole game. RMM is what separates a managed IT support partner that prevents outages from a break-fix contractor who only shows up after something has already failed. At AMVIA it underpins every managed IT contract we run. ## What does an RMM tool do day-to-day? An RMM tool continuously watches every managed device - CPU and memory load, disk space, failing drives, missed updates and network connectivity - and reports it all back to one console. When a threshold is crossed, it alerts the support team automatically instead of waiting for a user to raise a ticket. In practice, a good RMM platform handles four jobs across your whole estate: - Monitoring - live device and network health, with alerts on failing hardware, low disk space or offline machines. - Patch management - scheduling and deploying operating system and application updates automatically, so nothing drifts out of date. - Automation - running scripts to fix common issues, configure settings or roll out software without touching each machine by hand. - Remote access - letting an engineer take control of a device to troubleshoot, wherever the user is working. The value is leverage in the literal sense: one engineer can keep hundreds of devices healthy because the tool does the watching. That is also why RMM is the backbone of how we cost managed IT support - the automation is what makes a per-user price viable. ## How is RMM different from antivirus? Antivirus does one job: it detects and blocks malware on a device. RMM is far broader - it monitors overall device health, deploys patches, manages configurations and enables remote support across your entire fleet. They are not competitors; antivirus is one of the things a well-run RMM platform keeps updated and reports on. Confusing the two is a common and expensive mistake. Antivirus tells you a known threat was stopped. RMM tells you a server is about to run out of disk, that twelve laptops are missing last month's security update, and that one machine has dropped off the network entirely. Patching matters because unpatched software is one of the most common ways attackers get in - and 43% of UK businesses experienced a cybersecurity breach or attack in the last 12 months (Cyber Security Breaches Survey 2025, DSIT). | | Capability | Antivirus | RMM tool | Block known malware | Yes | Via the AV it manages | Monitor device health (disk, CPU, uptime) | No | Yes | Automated OS and app patching | No | Yes | Remote access for support | No | Yes | Fleet-wide configuration management | No | Yes | Proactive alerts before failure | No | Yes If you want the deeper picture of what proactive IT actually covers, our what is managed IT explainer maps RMM onto the full service. ## Why does RMM make IT support proactive instead of reactive? RMM shifts IT support from "wait until it breaks" to "fix it before anyone notices". Because the tool is watching every device constantly, it can flag a dying hard drive, a stalled backup or a failed update as it happens - giving the support desk time to act inside business hours rather than during an outage. Reactive break-fix support is cheaper on paper and far more expensive in reality. Every hour a server is down is an hour your team can't work, and the fault is usually something RMM would have caught days earlier. The National Cyber Security Centre is blunt about the foundations here: keeping devices monitored and patched is one of the highest-value, lowest-cost things an organisation can do (NCSC guidance). RMM is how a provider delivers that at scale without a person babysitting every machine. This is also where security and IT stop being separate disciplines. The same patching discipline that keeps machines running also closes the doors attackers use - which is why we treat vulnerability management and RMM-driven patching as two sides of the same job. ## How much does an RMM tool cost? You rarely buy RMM on its own - it comes bundled inside a managed IT contract, priced per user per month. As a standalone licence, RMM software typically runs £25–£65/user/month (industry benchmark), but that figure is misleading on its own because it doesn't include the engineers, the monitoring desk or the response time that make it useful. What matters to a buyer is the all-in managed IT price. AMVIA includes RMM in every managed IT contract, with IT support from £30/user/month - the monitoring, patching and remote support sit inside that, not as an add-on. For a full breakdown of what drives the number up or down, see our IT support cost guide for the UK. One provider. Security-first. Microsoft-certified - the RMM platform is the engine, but the value is the team running it. ## Do you need an RMM tool if you outsource your IT? If you outsource IT to a credible provider, you already have RMM - it's how they deliver the service. The question to ask a prospective MSP isn't "do you use RMM?" but "what do you do with the alerts, and how fast?". A tool with no one acting on it is just a dashboard. Ask any provider three things: how quickly they respond to a critical RMM alert, whether patching is reported back to you monthly, and who is accountable when an update breaks something. Vague answers are a red flag. RMM is table stakes; the discipline around it is what you're actually paying for. ## Frequently asked questions Q: What does RMM stand for? A: RMM stands for Remote Monitoring and Management. It's the category of software that managed IT providers use to oversee, maintain and support client devices and servers remotely - covering health monitoring, automated patching, scripting and secure remote access from a single console. Q: Is RMM the same as antivirus? A: No. Antivirus only detects and blocks malware on a device. RMM is a broader operational platform that monitors device health, deploys patches, manages configurations and enables remote support across your whole estate. A good RMM platform actually manages your antivirus as one part of a much wider job. Q: Can an RMM tool automate patch management? A: Yes. RMM platforms schedule and deploy operating system and application patches automatically across every managed device, then report on what's installed and what's outstanding. This matters because unpatched software is one of the most common entry points for attackers, and automation removes the human gaps in manual updating. Q: Does RMM let an engineer see my screen? A: Only when remote support is initiated, and on managed devices your provider controls. RMM remote access is for troubleshooting - taking control of a machine to fix a problem - and reputable providers log every session. It is not covert surveillance of staff activity. Q: Is RMM enough to keep my business secure? A: No - RMM is a foundation, not a full security stack. It keeps devices monitored and patched, which closes off common attack routes, but you still need endpoint protection, email security and monitored threat detection on top. RMM and security work best as one accountable service rather than separate contracts. Q: Who manages the RMM tool - me or my provider? A: Your provider does. RMM is delivered as part of a managed IT service: the provider installs the agents, sets the alert thresholds, acts on the warnings and reports back to you. You get the outcome - devices that stay healthy and patched - without running the platform yourself. --- # What Are Typical IT Support Response Times for UK Businesses? URL: https://amvia.co.uk/managed-it/questions/it-support-response-times Last updated: 2026-03 Typical UK managed IT support response times follow a tiered SLA: P1 critical issues acknowledged within one hour, P2 standard issues within four hours, and P3 low-priority requests within eight hours. Always confirm whether your SLA measures response or resolution - the gap between the two is where most providers quietly underdeliver, and where AMVIA commits to a faster target. ## What are typical IT support response times in the UK? Most UK managed service providers structure response times by ticket priority, not by a single blanket promise. A complete server outage and a forgotten password should never sit in the same queue. The tiers below are the benchmark you should expect any credible MSP to put in writing. | | Priority | Typical issue | Industry-standard response | Who it affects | P1 - Critical | Full outage, security incident, site down | Within 1 hour | Multiple users / whole business | P2 - High | Degraded service, key app failing | Within 4 hours | A team or department | P3 - Standard | Single-user fault, how-to request | Within 8 hours | One person | P4 - Low | Scheduled change, new starter setup | Next business day | Planned work These are response targets, not resolution promises. If a provider only quotes one number, assume it is the easy one. A serious contract defines a target for every tier and states the support hours each tier is measured against. For the full picture on what a managed contract should include, read our managed IT support overview before you sign anything. ## Response time vs resolution time - what is the difference? Response time is how quickly an engineer acknowledges your ticket and starts work. Resolution time is how long until the problem is actually fixed. They are different metrics, and conflating them is the single most common way buyers get burned. A one-hour response means nothing if resolution then takes three days. Many providers advertise an aggressive response figure precisely because it is cheap to hit - an automated acknowledgement counts. Resolution is harder to guarantee because it depends on the fault. The practical answer: insist your SLA names both, and ties resolution targets to the same priority tiers. When you compare quotes, line up the resolution columns, not the headline response numbers. Our guide to managed IT support costs breaks down what those guarantees should cost you. - Ask for both metrics in writing - response and resolution, per priority tier. - Check the measurement window - is resolution measured in working hours or elapsed hours? - Confirm escalation triggers - what happens when a P1 misses target? - Read the exclusions - third-party vendor delays are often carved out. ## How are IT support tickets prioritised? Tickets are classified by business impact, not by how loudly someone complains. P1 covers complete outages affecting multiple users or an active security incident. P2 covers degraded service for a team or a critical application. P3 covers single-user faults and general requests. Each tier carries its own SLA clock. Good prioritisation is a discipline, not a guess. The triage decision should be made against documented criteria the moment a ticket lands, so the SLA clock starts on the right tier. Security events deserve special handling: a suspected breach is a P1 regardless of how many users it touches, because dwell time is what turns an incident into a disaster. The NCSC's incident management guidance sets out why early triage and containment matter more than raw speed of acknowledgement. Pair your helpdesk SLA with proper 24/7 security monitoring so a P1 security event is caught before it spreads. ## Should you expect 24/7 IT support or business hours only? Most SME managed IT contracts cover business hours - typically 8am to 6pm, Monday to Friday. Round-the-clock helpdesk support is available but costs more and is usually reserved for businesses with shift workers, customer-facing systems, or overnight processing. For everyone else, the smart split is daytime helpdesk plus always-on security monitoring. That split matters because the threat clock never stops. The UK government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber security breach or attack in the previous 12 months, and attackers deliberately strike outside office hours when no one is watching the dashboard. You may not need a human answering password resets at 3am, but you do need something watching for ransomware. This is exactly where a security-first provider differs from a general break-fix shop - read how co-managed IT extends your in-house team's cover without paying for a full night shift. ## What does the UK managed services market tell us? The UK MSP sector is large, mature, and competitive - which is good news for buyers, because it means you can hold providers to genuine standards. It is a deep market, though provider-quality varies enormously within it. - SME IT support typically costs £35–£65/user/month (typical UK 2026 range). The lesson is not that scale guarantees quality - it does not. With nearly 13,000 providers competing, the differentiator is whether yours puts measurable SLAs and security monitoring in writing, or hides behind a vague "best efforts" clause. Use the price benchmark above as a sanity check: a quote far below it usually means thin SLAs, and a quote far above it should buy you genuine round-the-clock cover. ## What response times does AMVIA commit to? AMVIA commits to an under-one-hour response for P1 critical issues that affect business operations, with a two-hour target for all other tickets - meeting the one-hour industry norm head-on. Critical means critical: a full outage or a suspected security incident jumps the queue automatically and is worked by a named engineer, not parked in a shared inbox. We run one accountable contract: managed IT and security under a single provider, with Microsoft-certified engineers and an in-house team watching the security stack. That structure is deliberate. When your connectivity, your endpoints, and your Microsoft 365 tenant are all managed by the same people, a P1 does not bounce between three vendors blaming each other. One provider. Security-first. Microsoft-certified. If your current MSP cannot tell you its P1 response target without checking, that is your answer. See how our IT helpdesk and business continuity cover fit together under one SLA. ## Frequently asked questions Q: What is a good IT support response time for a UK SME? A: A good benchmark is one hour for critical (P1) issues, four hours for high-priority (P2) issues, and eight hours for standard (P3) requests, all measured against your agreed support hours. The strongest providers beat the one-hour P1 norm. Insist these targets are written into the SLA per priority tier, not quoted as a single average. Q: What is the difference between response time and resolution time? A: Response time is how quickly an engineer acknowledges your ticket and starts work. Resolution time is how long until the issue is fully fixed. Many providers advertise fast response but make no resolution commitment, so an automated acknowledgement counts as a "response". Always confirm your contract defines both metrics, against every priority tier. Q: Does my IT support contract need to be 24/7? A: Usually not for the helpdesk. Most SMEs run an 8am–6pm helpdesk and reserve round-the-clock cover for shift work or overnight systems. Security monitoring is the exception: because attacks routinely land outside office hours, always-on monitoring is worth keeping even when your helpdesk is daytime only. The two can be priced separately. Q: How are IT support tickets prioritised? A: By business impact against documented criteria. A complete outage or active security incident is P1, degraded service for a team is P2, and a single-user fault or request is P3. The priority sets the SLA clock the moment the ticket lands. Suspected security breaches should be treated as P1 regardless of how many users are affected, because delay makes them worse. Q: Should security incidents have a faster response than IT faults? A: Yes. A suspected breach should always be a P1 because attacker dwell time is what turns an incident into a serious loss. The NCSC stresses early triage and containment over raw acknowledgement speed. Pairing a daytime helpdesk SLA with continuous security monitoring ensures a security event is caught and contained even when the helpdesk is closed. Q: What questions should I ask before signing an IT support SLA? A: Ask for response and resolution targets per priority tier, in writing. Confirm whether targets are measured in working or elapsed hours, what triggers escalation when a P1 misses, and which delays are excluded. Check support hours per tier and whether security monitoring runs outside them. If a provider cannot state its P1 target plainly, treat that as a warning. --- # Can I Get a Leased Line at My Business Address? URL: https://amvia.co.uk/leased-lines/questions/can-i-get-leased-line-my-area Last updated: 2026-03 Most UK business addresses can get a leased line, but availability, lead time and price swing hard on one factor: how far your premises sit from the nearest fibre point. AMVIA checks every major carrier in one pass and sources the best route for your exact postcode, so you see the real options before you commit. ## How do I check if a leased line is available at my address? The only reliable way is a multi-carrier postcode check. A single provider's tool only shows its own network, so it misses cheaper or faster routes next door. AMVIA runs your address against Openreach, CityFibre and Virgin Media Business together and returns a like-for-like comparison. Availability is not binary. Almost every UK address can technically take a business leased line - the question is what it costs and how long the build takes. A postcode check tells you three things at once: - Which carriers already have fibre serving or passing your building - Whether you fall inside a ready-to-connect footprint or need new civils - The realistic monthly rental and one-off install for each route If you are still weighing the technology itself, what a leased line is explains why a dedicated, uncontended circuit behaves differently from shared broadband. ## What determines whether a leased line reaches my area? Coverage is driven by national fibre rollout and by the distance between your building and the nearest carrier fibre. The UK fibre footprint has grown fast, which widens the number of addresses that can be served quickly and cheaply. Total FTTP coverage reached 78% of UK premises (23.7 million premises) in Q3 2025, according to Ofcom's Connected Nations programme (ofcom.org.uk). Gigabit-capable broadband now covers 87% of the UK as of 2025, up from 84% in 2024. Openreach is investing up to £15 billion to expand full fibre coverage to 25 million premises by December 2026. That rollout matters because a leased line is delivered over fibre. Where full-fibre infrastructure already passes your premises, install is faster and excess construction charges are far less likely. Where it does not, you can still get a circuit - it just needs a build. ## What if there is no fibre near my premises? You can still get a leased line; the carrier simply builds fibre to your door. That construction is priced as a one-off and does not change your ongoing rental, so the dedicated bandwidth you signed up for stays the same. Excess construction (ECC) adds a one-off charge - typically £1,000–£10,000 depending on distance - with unchanged monthly rental. The figure depends on how much trenching, ducting or wayleave work is needed between the nearest fibre point and your building. AMVIA gets these costs quoted up front so there are no surprises after you sign. For sites where any build is too slow or too costly, a dedicated internet access circuit on an alternative carrier route is often the answer. The point of a multi-carrier check is to find the route with the lowest combined cost, not just the first one that returns a result. ## How does availability differ between carriers? It differs a lot. Coverage, install speed and price each vary by carrier and by street, which is exactly why a single-provider quote rarely gives you the best deal. The table below shows the broad pattern AMVIA sees across UK business postcodes. | | Carrier | Coverage footprint | Typical strength | Best for | BT Openreach | Widest national reach | Reaches addresses others can't | Rural or out-of-town sites | CityFibre | Growing city networks | Competitive pricing, fast install | Urban and metro business parks | Virgin Media Business | Strong in serviced areas | Quick delivery where present | City-centre offices A leased line typically delivers a 99.99% uptime SLA regardless of which carrier delivers it, so the decision comes down to coverage, lead time and total cost. For a full breakdown of what drives the monthly figure, see the leased line cost guide. If you are deciding whether a dedicated circuit is even the right call versus shared connectivity, leased line vs broadband sets out the trade-offs in plain terms. ## How long does installation take once it is confirmed? Where fibre already serves your building, expect roughly 30–90 working days from order to live. Where new civils are required, the wayleave and construction stage extends that timeline, sometimes considerably. The postcode check flags which scenario applies before you commit. The slowest part is rarely the technology - it is wayleaves (legal permission to run fibre across land you don't own) and any street works. Getting these moving early is where a provider that chases the carrier daily earns its keep. ## What should I do about connectivity while I wait? Order a leased line for the long term, but don't leave the business exposed in the meantime. A temporary business broadband service or a 4G/5G backup keeps you trading until the dedicated circuit goes live, then becomes your failover. A leased line is uncontended and resilient, but no single circuit is immune to a fibre cut. Pairing it with backup connectivity gives you a second, independent path so an outage on one line doesn't take the business offline. This is the same security-first thinking AMVIA applies across the stack: one accountable provider, designed for resilience, not just speed. The same principle runs through the UK's own resilience guidance from the National Cyber Security Centre (ncsc.gov.uk) - a connection is only as valuable as the protection sitting behind it. ## Frequently asked questions Q: Can I get a leased line at any UK business address? A: Almost always, yes. The vast majority of UK premises can take a leased line because the carrier can build fibre to any address. The real variables are cost and lead time, not whether it is technically possible. A multi-carrier postcode check confirms the realistic options for your specific location. Q: How long does a leased line availability check take? A: A multi-carrier postcode check usually returns indicative results quickly, with firm carrier quotes following within a few working days. AMVIA checks Openreach, CityFibre and Virgin Media Business together, so you get a like-for-like comparison rather than a single network's view of your address. Q: Why does leased line pricing vary so much by location? A: Price is driven by distance to the nearest carrier fibre and by any construction needed to reach your building. Sites already passed by fibre are cheaper and faster to connect. Sites needing new trenching or ducting carry a one-off excess construction charge, while the monthly rental stays the same. Q: Does every carrier reach every postcode? A: No. Coverage varies street by street. BT Openreach has the widest national reach, while CityFibre and Virgin Media Business are strong in specific cities and serviced areas, often at lower prices or faster install. Checking all carriers at once is the only way to find the best available route. Q: Is a leased line worth it if my area only has broadband? A: Often, yes. A leased line gives you dedicated, uncontended bandwidth with symmetric upload and a firm uptime guarantee - none of which shared broadband provides. If your business relies on cloud apps, voice, or moving large files, the dedicated circuit usually pays for itself in reliability and productivity. Q: Can AMVIA secure the connection once it is installed? A: Yes. AMVIA is a security-first provider, so the circuit is only the foundation. We help protect the network behind it with Microsoft Defender and the Barracuda email and network suite, monitored by our in-house team. One provider handles connectivity and security together. --- # Is a Leased Line Faster Than Business Broadband? URL: https://amvia.co.uk/leased-lines/questions/leased-line-vs-broadband-speed Last updated: 2026-03 A leased line gives your business dedicated, symmetrical speed - typically 100Mbps to 100Gbps, identical upload and download, guaranteed to you alone. Business broadband shares capacity, so real-world speed varies with demand. For cloud-heavy teams, VoIP, and SLA-bound work, a leased line's consistency beats broadband's peak. AMVIA sizes the right connection - security-first, from one provider. The honest answer most resellers avoid: a leased line is not always the *faster* connection on a speed test, but it is almost always the *better-performing* one for a business that depends on the internet to operate. This guide breaks down the real difference for UK decision-makers - and where each option earns its place. For the full technical picture, start with our business leased line pillar guide. ## What is the core speed difference between a leased line and broadband? The core difference is dedication and symmetry, not headline numbers. A leased line reserves a fixed amount of bandwidth exclusively for your business and delivers the same speed up and down. Broadband is contended - shared with other premises - and asymmetric, so upload is a fraction of download. That distinction changes how each connection behaves under load: - Leased line: dedicated bandwidth, symmetrical (e.g. 1Gbps down *and* up), no contention, backed by a strict service level agreement. - Business broadband: shared bandwidth, asymmetric (fast down, slow up), contention ratios that throttle peak-time performance, best-efforts repair. - Practical result: a leased line holds its speed at 4pm on a busy Tuesday; broadband can sag exactly when your team needs it most. A modern fibre-to-the-premises (FTTP) broadband product can advertise speeds that *look* similar to an entry-level leased line. The gap shows up in the guarantees, the upload, and the day-to-day consistency - not the brochure. ## How do leased line and broadband speeds compare side by side? For most UK SMEs the decision comes down to five factors: symmetry, contention, the uptime guarantee, repair commitments, and cost. A leased line wins on every reliability measure; broadband wins on price and availability. The table below sets out the trade-off clearly. | | Factor | Business broadband (FTTP/FTTC) | Leased line | Bandwidth | Shared / contended | Dedicated to your business | Upload vs download | Asymmetric (upload much slower) | Symmetrical (equal up/down) | Typical speed | Up to ~1Gbps download | 100Mbps–10Gbps, scalable | Uptime guarantee | None (best efforts) | 99.99% SLA | Fix time if it fails | Days possible | Hours, backed by SLA | Indicative price | From £35/mo | From £69/mo | Best for | Smaller teams, standard apps | Cloud, VoIP, SLA-critical work The leased line "from £69/mo" entry point makes dedicated connectivity far more accessible than the £300–£600/month many businesses still assume. Compare the detail in our leased line vs broadband breakdown and the full leased line cost guide. ## Why does symmetrical upload speed matter so much for business? Upload speed is where broadband quietly fails modern businesses. Cloud backups, video calls, VoIP, large file transfers, and hosted applications all push data *up* the connection. UK fixed broadband averages 69.4 Mbps download per Ofcom's Connected Nations report (2024), but upload on many lines is only a small fraction of that. A leased line's symmetry removes that bottleneck. When 30 people are on Teams calls while overnight backups run and a designer syncs a 4GB file to the cloud, the upload path is what determines whether everything stays smooth. - VoIP and video: jittery, dropped calls are almost always an upload/contention problem, not a download one. - Cloud-first operations: SharePoint, OneDrive, and SaaS tools depend on upload to feel instant. - Resilience: symmetrical, dedicated bandwidth keeps performance flat regardless of what the neighbours are doing. If telephony reliability is the driver, pair the connection thinking with our business VoIP guidance - voice quality lives or dies on the underlying line. ## Is FTTP broadband now fast enough to skip a leased line? Often, yes - for smaller teams. FTTP rollout has transformed what broadband can deliver. Total FTTP coverage reached 78% of UK premises (23.7 million premises) in Q3 2025, and gigabit-capable broadband now covers 87% of the UK, up from 84% in 2024, per Ofcom's broadband coverage data. For many offices, FTTP is genuinely enough. But "fast enough on a speed test" and "right for the business" are different questions. FTTP is still contended and asymmetric, with no guaranteed fix time if it goes down. Public investment underlines how fast the gap is closing - the government-backed Project Gigabit programme and Openreach are investing up to £15 billion to expand full fibre to 25 million premises by December 2026 - yet the guarantees still separate the two products. Choose FTTP broadband when peak speed and price matter more than guarantees. Choose a leased line when downtime costs you money. If you want both worlds, a leased line with FTTP backup connectivity gives dedicated primary bandwidth plus a failover path. ## When is broadband enough, and when do you genuinely need a leased line? The practical tipping point is around 15–20 concurrent users, or the moment your business can no longer tolerate variable speed and occasional outages during the working day. Below that, with standard cloud apps, business broadband is usually sufficient. Above it - or once voice, video, and SLAs enter the picture - a leased line earns its cost. Signs you have outgrown broadband: - More than 15–20 people online at once during core hours. - VoIP or video conferencing is now business-critical. - Regular large file transfers or cloud backups. - You operate under client or regulatory SLAs where downtime is a breach. - Performance noticeably drops at peak times. Fixed leased line connections already dominate the UK business internet market, with a share exceeding 39% (Ofcom Connected Nations, 2024) - a reflection of how many firms have crossed that line. For a deeper foundation, read what is a leased line and dedicated internet access. ## How much faster *feels* the difference in real use? In daily use, the leased line difference is felt as predictability rather than raw speed. A 200Mbps symmetrical leased line will routinely outperform a "900Mbps" broadband line for a busy office, because the broadband figure is a best-case download under no contention - a number you rarely see when the whole team is working. The right way to size connectivity is by workload, not by the biggest number on the page. AMVIA assesses how your team actually uses the connection - concurrent users, voice, cloud dependency, and tolerance for downtime - then recommends the smallest connection that meets it reliably. One provider, security-first, Microsoft-certified engineers handling the connectivity, voice, and protection together. ## Frequently asked questions Q: Is a leased line always faster than broadband? A: No. On a raw speed test a top-tier FTTP broadband line can match or beat an entry-level leased line's download figure. The leased line advantage is symmetry, dedicated bandwidth, and a guaranteed uptime SLA - so it performs consistently under real load, where contended broadband slows down at peak times. Q: Why is upload speed more important than download for business? A: Because most business-critical traffic travels upward: cloud backups, VoIP, video calls, file syncing, and hosted apps all rely on upload. UK broadband is asymmetric, so upload is often a small fraction of download. A leased line provides identical upload and download speeds, removing the bottleneck that causes dropped calls and slow cloud performance. Q: How fast is a typical business leased line? A: Leased lines typically range from 100Mbps to 100Gbps, symmetrical, and are scalable on demand. Unlike broadband, the contracted speed is guaranteed in both directions at all times rather than advertised as an "up to" best case. AMVIA sizes the bandwidth to your concurrent users, voice load, and cloud dependency rather than to a headline number. Q: Does a leased line guarantee uptime that broadband cannot? A: Yes. Leased lines are backed by a service level agreement that typically commits to 99.99% uptime with fast, defined repair times. Business broadband is delivered on a best-efforts basis with no uptime guarantee, so an outage can last days. For SLA-bound or revenue-critical operations, that guarantee is the real reason to switch. Q: When should an SME move from broadband to a leased line? A: The usual trigger is 15–20 concurrent users, or when voice, video, large file transfers, or client SLAs make variable speed and unplanned outages unacceptable. Below that threshold, business broadband on a modern FTTP line is generally enough. Above it, a leased line's consistency and guaranteed repair times justify the cost. Q: Can I keep broadband as a backup for a leased line? A: Yes, and it is a smart resilience pattern. A leased line provides guaranteed primary bandwidth, while an FTTP or FTTC broadband line acts as automatic failover if the primary connection drops. This pairing gives dedicated everyday performance plus a low-cost safety net, keeping VoIP and cloud services running during a fault. --- # Can VoIP Work Without the Internet? URL: https://amvia.co.uk/business-voip/questions/can-voip-work-without-internet Last updated: 2026-03 No. VoIP needs an active internet connection, so a total outage stops calls on that line. But a properly designed hosted VoIP system uses automatic failover, rerouting calls to mobiles, a backup 4G line, or another site within seconds, so one accountable provider keeps your business reachable through the disruption. That is the short answer. The detail matters, because the way your phones behave during an outage is decided long before the outage happens. Below we explain how VoIP depends on connectivity, what actually breaks when a line drops, and how to design a business VoIP setup that stays up when it counts. ## Does VoIP need an internet connection to work? Yes. VoIP (Voice over Internet Protocol) carries every call as data packets across your internet connection instead of over the old copper phone network. No connection means no path for those packets, so a complete internet failure stops both inbound and outbound calls on that circuit. There is no offline fallback inside the protocol itself. This is different from a traditional analogue line, which drew power and signal from the exchange. That distinction is exactly why the country is moving on. Around 31% of UK businesses had switched to VoIP as of 2025, one of the fastest shifts in business communications, and the change is being driven by the retirement of the old network rather than by choice alone. ## What happens to VoIP calls when the internet goes down? If the internet connection carrying your calls fails and nothing else is configured, calls on that line cannot be made or received until the connection is restored. The handsets register over the internet to your hosted platform, so when the link drops, they lose registration. Voicemail and missed-call alerts still queue in the cloud, but live conversations stop. The good news: the call control lives in the provider's data centre, not in your office. That means inbound calls can be diverted elsewhere automatically the moment your line is detected as down, which is the whole point of failover. ## How does VoIP failover keep your business reachable? Failover is a pre-set rule in your hosted phone platform that redirects calls when your primary connection or handsets stop responding. Because the routing happens in the cloud, inbound callers never reach a dead line: they are sent to a mobile, a second site, or a hunt group within seconds, with no action needed from your staff. A well-built failover plan typically combines several layers: - Call divert rules that send inbound calls to nominated mobiles or another office if handsets go unregistered. - Softphone and mobile apps so staff keep making outbound calls on the business number over 4G or 5G. - A backup internet path (a 4G/5G router or second line) that the network switches to automatically. - A resilient primary circuit, such as a leased line carrying a 99.99% uptime SLA, to make outages rare in the first place. This is where design beats luck. Multi-site organisations can route a failed location's calls to a sister office automatically; see multi-site VoIP for how that is structured across branches. ## Should you add a backup internet connection for VoIP? For any business where the phone is a revenue line, yes. A secondary connection gives you automatic switchover when the primary drops, so calls keep flowing instead of failing. The cheapest effective option is usually a business-grade 4G/5G failover router, from £30 per month; the most resilient is a dedicated circuit with a hard SLA. Here is how the common options compare: | | Backup option | Typical monthly cost | Failover behaviour | Best suited to | No backup | £0 | None - calls drop until the line returns | Non-critical extensions | 4G/5G failover router | from £30 | Automatic, switches in seconds | Most SMEs | Second broadband line | Varies by provider | Automatic with SD-WAN steering | Multi-line offices | Dedicated leased line | from £69/mo | 99.99% uptime SLA | Always-on telephony If telephony is genuinely business-critical, pair a leased line with a 4G failover so you have two independent paths. Our guide to backup connectivity walks through sizing the second link, and the wider leased lines pillar covers SLA-backed primary circuits. ## Can you use VoIP on a mobile during an office outage? Yes. Almost every hosted VoIP platform includes a mobile app that runs over 4G or 5G, letting staff make and take calls on the business number even when the office internet is down. The app registers to the same cloud platform your desk phones use, so callers see no difference and your team is not stuck handing out personal numbers. This is why mobile data matters as a resilience layer. Ofcom's Connected Nations reporting tracks both fixed and mobile coverage across the UK, and for most offices a charged smartphone on 4G is a perfectly workable lifeline during a fixed-line fault. A hosted phone system makes this part of normal day-to-day working, not an emergency scramble. ## Why is the PSTN switch-off making VoIP resilience urgent? Because the old network is closing. The UK's analogue PSTN and ISDN services are being withdrawn, with the industry migration deadline now set for 31 January 2027, after which voice services run over IP. Once your phones depend on a data connection, planning for connectivity failure stops being optional. The migration is well advanced: most UK landlines have already moved to digital voice, and any business still on copper needs a plan. Read our PSTN switch-off guide for the timeline and what to do before the deadline. The practical takeaway is simple: as voice and data converge onto one connection, that connection's resilience, and its security, become the same conversation. ## How AMVIA builds VoIP that survives an outage We design phone systems the way a security partner does: assume the link will fail, then make sure the business stays reachable anyway. That means a resilient primary circuit, an automatic backup path, cloud-based call divert rules, and mobile apps configured before go-live, not after the first outage. One provider. Security-first. Microsoft-certified. Because voice now rides the same connection as your email and data, the call quality conversation is also a VoIP security conversation: encrypted SIP, fraud monitoring, and hardened handsets all sit in the same design. We build connectivity, calls, and protection as one accountable stack rather than three separate suppliers pointing at each other when something breaks. ## Frequently asked questions Q: Can VoIP work without internet? A: No. VoIP carries calls as data over your internet connection, so a complete outage stops calls on that line. However, a well-configured hosted system reroutes inbound calls to mobiles or another site automatically, and staff can keep making calls through a mobile app on 4G or 5G, so the business stays reachable during the fault. Q: What happens to my VoIP calls if the internet goes down? A: On the affected line, live calls drop and new calls cannot connect until the link returns. Because call control sits in the cloud, the platform can detect the outage and divert inbound calls to nominated mobiles or another office within seconds. Voicemail and missed-call alerts continue to queue, so nothing is silently lost. Q: Do I need a backup internet connection for VoIP? A: If your phones carry revenue, yes. A second connection, typically a 4G or 5G failover router, gives automatic switchover when the primary line drops, so calls keep flowing without staff intervention. Businesses that cannot tolerate any downtime usually pair a dedicated leased line with a mobile backup for two fully independent paths. Q: Can I make VoIP calls from my mobile during an outage? A: Yes. Most hosted VoIP platforms include a mobile app that works over 4G or 5G and registers to the same cloud system as your desk phones. Staff make and receive calls on the business number, so customers see no difference even while the office fixed line is down. It is the simplest resilience layer to switch on. Q: Is VoIP reliable enough to replace a landline? A: Yes, when it is designed with resilience in mind. A leased line with a strong uptime SLA, an automatic backup path, and cloud failover routing gives availability that matches or beats old copper lines. The difference is that VoIP reliability is engineered through your connectivity choices rather than assumed, which is why design and provider matter. Q: When is the PSTN landline network switching off? A: The UK's analogue PSTN and ISDN network is being retired, with the industry migration deadline currently set for 31 January 2027. After that, voice services run over IP connections. Most landlines have already moved to digital voice, so any business still on copper should plan its migration and connectivity resilience well ahead of the deadline. --- # Is VoIP Reliable Enough for UK Business Use? URL: https://amvia.co.uk/business-voip/questions/is-voip-reliable-uk Last updated: 2026-03 Yes - business VoIP is reliable in the UK when it runs over a stable, well-provisioned connection. On quality FTTP or a business VoIP-ready leased line with QoS configured and 4G/5G failover in place, calls match or beat the old PSTN landline. The single biggest risk is internet dependency, so you build in resilience. The honest answer most resellers skip: VoIP is only as reliable as the network underneath it and the engineering decisions made when it is set up. Get the connection, the call-prioritisation and the failover right and you will rarely think about it again. Get them wrong and you will blame "VoIP" for what is really a connectivity problem. This guide explains exactly where reliability comes from, what the numbers should look like, and how to provision a system that holds up under real business load. ## How reliable is business VoIP in the UK in 2026? Modern business VoIP is highly reliable in the UK, with hosted platforms typically advertising a 99.99% uptime SLA at the carrier level. Real-world reliability depends far more on your own connection and configuration than on the VoIP provider's data centre. The platform almost never fails - the link to it sometimes does. UK conditions favour VoIP more than they used to. Around 31% of UK businesses had switched to VoIP as of 2025, and adoption is accelerating because the legacy phone network is being retired. Full-fibre coverage and faster average speeds mean most offices now have the headroom voice traffic needs. Voice is a light load - a single HD call uses roughly 100 kbps - so capacity is rarely the constraint; consistency is. - VoIP can cut communication costs by around 25–50% (typical UK 2026 range) versus legacy line rental and call charges. - Reliability is a revenue issue, not just an IT one - missed calls are missed business. - The platform layer is enterprise-grade; the weak link is almost always the last-mile connection and how it is engineered. ## What actually makes VoIP reliable? VoIP reliability is built from four things: a stable connection, Quality of Service (QoS) prioritisation, sensible bandwidth headroom, and a failover path for when the primary link drops. Miss any one of these and call quality becomes unpredictable under load - which is what gives VoIP an undeserved bad reputation. Here is what each layer does: - A stable connection - low, consistent latency matters more than raw speed. A full-fibre or FTTP leased line gives you symmetric bandwidth and predictable performance. - QoS - prioritises voice packets over email, backups and downloads so a large file transfer can never starve a live call. - Headroom - provision bandwidth for peak simultaneous calls plus everything else the office is doing at once, not the average. - Failover - automatic backup connectivity over 4G/5G or a second line keeps calls up if the primary connection fails. This is where the practitioner view diverges from the brochure: reliability is an engineering outcome, not a product feature you buy off a price list. ## What affects VoIP call quality? Three network metrics decide whether a VoIP call sounds clean or breaks up: latency, jitter and packet loss. Speed alone does not guarantee quality - a fast line with high jitter will sound worse than a modest line with stable, prioritised traffic. Consistency beats headline megabits every time. | | Metric | Target for clean voice | What happens when it is exceeded | Latency (one-way) | Under 150 ms | Noticeable delay, people talk over each other | Jitter | Under 30 ms | Choppy, robotic audio | Packet loss | Under 1% | Dropouts, missing syllables | Bandwidth per HD call | ~100 kbps each way | Calls degrade once the link saturates For context, the UK broadband average download speed is 69.4 Mbps (Ofcom Connected Nations 2024) - far more than voice needs, which proves the point: a typical office has ample speed. Quality problems come from contention and a lack of prioritisation, not a shortage of bandwidth. You can verify the national picture in Ofcom's own reporting (ofcom.org.uk). ## Is broadband or a leased line better for VoIP reliability? For a handful of users, quality business broadband with QoS is fine. Once you are running ten or more simultaneous calls, or voice is business-critical, a leased line is the right call - it provides dedicated, uncontended bandwidth with a typical 99.99% uptime SLA, where standard broadband offers no uptime guarantee at all. | | Factor | Business broadband (FTTP) | Leased line | Bandwidth | Shared / contended | Dedicated, uncontended | Upload | Often asymmetric | Symmetric | Uptime SLA | None guaranteed | Typical 99.99% | Fix time on faults | Best-effort | Guaranteed (SLA-backed) | Best for | Small teams, light call volume | High call volume, business-critical voice The rule of thumb we give clients: if losing the phones for a morning would cost real money, the connection deserves a guarantee. That is what a leased line buys you - not speed, but accountability when something breaks. ## What happens to VoIP when your internet goes down? Internet dependency is VoIP's only genuine weakness - if the connection fails, so do the calls. The fix is failover: an automatic secondary path so the system reroutes instead of going dark. Done properly, an outage on your primary line becomes a non-event your team may not even notice. There are two layers of resilience worth having: - Connection failover - automatic backup connectivity over a 4G/5G or secondary fixed line so calls continue if the main line drops. - Platform-level continuity - because a hosted phone system lives in the cloud, calls can divert to mobiles or another site instantly if your office connection is unreachable. This is also a security question. Voice runs over the same network as everything else, so the resilience and the protection have to be designed together - which is why we treat VoIP security as part of the same conversation, not an afterthought. The NCSC's guidance on telephony and network resilience is a good external reference for the principles here (ncsc.gov.uk). ## Is VoIP more reliable than a traditional landline? On a properly provisioned connection, VoIP reliability matches or exceeds the traditional PSTN landline - and the comparison is becoming academic anyway. The UK's legacy analogue phone network is being switched off, with the PSTN switch-off scheduled for 31 January 2027, so every UK business will move to digital voice regardless. The old "copper just works" assumption no longer holds: PSTN and ISDN lines are being withdrawn, support is shrinking, and Openreach has confirmed the final migration date through Ofcom's industry programme. VoIP on a resilient, well-engineered connection is now the more reliable and future-proof option - provided it is set up by people who design for failure, not just for the demo. ## How AMVIA makes business VoIP reliable We provision VoIP the way a security-first provider should: connection, call quality, failover and protection designed as one system, not bolted together. One provider, accountable end to end, with Microsoft-certified engineers who own the network and the voice platform together - so when something goes wrong there is no finger-pointing between your line provider and your phone vendor. That means right-sizing the connection for your real call volume, configuring QoS so voice is always prioritised, building in 4G/5G failover for business-critical sites, and securing the whole path. It is the difference between VoIP that "usually works" and VoIP you stop thinking about. ## Frequently asked questions Q: Is VoIP reliable enough for a UK business to depend on? A: Yes. On a stable, well-provisioned connection with QoS and failover configured, business VoIP is reliable enough to run a UK business on, and matches or beats the old PSTN landline. Reliability comes from the connection and the engineering, not the VoIP platform itself - the cloud platform almost never fails; the link to it occasionally does. Q: What internet speed do I need for reliable VoIP? A: Less than you think. A single HD call uses roughly 100 kbps each way, so even a modest connection has the capacity. What matters is consistency: latency under 150 ms, jitter under 30 ms and packet loss under 1%. With UK average broadband speeds comfortably above what voice needs, quality problems come from contention and missing prioritisation, not a lack of speed. Q: Does reliable VoIP depend on having a leased line? A: Not always. For a small team with light call volume, quality FTTP broadband with QoS is fine. Once you are running ten or more simultaneous calls, or phones are business-critical, a leased line is worth it for the dedicated bandwidth and SLA-backed uptime. The deciding question is what an outage would actually cost you. Q: What happens to my calls if the internet goes down? A: Without failover, calls stop - internet dependency is VoIP's main weakness. With failover, an automatic 4G/5G or secondary line keeps calls running, and because the phone system is cloud-hosted, calls can divert to mobiles or another site instantly. Properly engineered, a primary-line outage becomes something your team barely notices. Q: Will I have to switch from my old landline anyway? A: Yes. The UK's analogue PSTN network is being retired, with the switch-off scheduled for 31 January 2027, so every business will move to digital voice. Rather than wait, most UK businesses are migrating now to avoid a rushed cutover and to start cutting line-rental and call costs sooner. Q: Is VoIP secure as well as reliable? A: Voice runs over the same network as your other data, so it needs the same protection - encryption, access controls and monitoring. Reliability and security should be designed together, not separately. A single provider that owns the connection, the phone platform and the security posture removes the gaps that appear when those are split across vendors. --- # What Is a BYOD Policy and Does My Business Need One? URL: https://amvia.co.uk/business-mobiles/questions/byod-policy-what-is-it Last updated: 2026-03 A BYOD (Bring Your Own Device) policy sets the rules for using personal phones and laptops to access work data. It defines permitted devices, the controls applied to corporate data, what IT can and cannot see on a personal device, and what happens to work data when someone leaves. For UK SMEs, it is the line between flexible working and an open back door. Most businesses already have BYOD whether they planned for it or not - the moment someone reads work email on their own phone, personal devices are touching company data. A written policy turns that quiet risk into a managed one. AMVIA builds and enforces BYOD policies as part of our business mobile management service, so the rules are not just on paper - they are applied to every device through Microsoft Intune. ## What does a BYOD policy actually cover? A BYOD policy defines five things: which devices and operating systems are allowed, the management controls applied to company data, acceptable use, what IT administrators can see, and what happens to work data when an employee leaves. Get these five right and you have a policy that protects data without overreaching into someone's private phone. The strongest policies are specific, not aspirational. "Keep your device secure" means nothing. "Devices must run a supported OS version, enforce a 6-digit passcode, and encrypt company apps via Intune" is enforceable. A policy you cannot technically enforce is a hope, not a control. | | Policy element | Weak version | Enforceable version | Permitted devices | "Modern smartphones" | iOS 16+ / Android 13+, vendor-supported only | Data protection | "Keep work data safe" | Company apps encrypted and containerised via Intune MAM | Access control | "Use a strong password" | Passcode + MFA enforced through Conditional Access | Leavers | "Return company data" | Selective remote wipe of work container on offboarding | Visibility | "IT may check devices" | IT sees app inventory only - never personal photos or messages The UK's National Cyber Security Centre publishes detailed BYOD device security guidance that maps closely to this structure - separate work data from personal data, and enforce baseline controls before granting access. ## Does my business actually need a BYOD policy? If any employee accesses email, Teams, SharePoint, or files on a personal device, you need a BYOD policy - even a one-page one. Without it you have no legal basis to wipe company data from a lost phone, no defined security baseline, and no clarity for staff on what is and is not allowed. The risk is not theoretical. A personal phone with cached work email, no passcode, and no wipe capability is a data breach waiting for a taxi seat. Under UK GDPR, the ICO holds you accountable for personal data wherever it sits - including on an employee's own handset. A BYOD policy is how you demonstrate you took reasonable measures. You need a formal policy if any of these are true: - Staff read work email or Teams on personal phones - Employees work remotely or hybrid for part of the week - You handle client, financial, or health data - You are pursuing or hold Cyber Essentials Plus - You have ever offboarded someone without recovering their device ## How does Microsoft Intune enforce a BYOD policy? Microsoft Intune turns a written BYOD policy into enforced technical controls. Its Mobile Application Management (MAM) protects company data inside specific apps - Outlook, Teams, OneDrive - without taking control of the whole personal device. Work data is encrypted, access is gated, and only the work container can be wiped. This is the model AMVIA recommends for almost every SME: app-level protection, not full device management, on personal hardware. Employees keep their phone private; the business keeps its data contained. Work email, files, and Teams data are encrypted and can be selectively removed without touching personal photos or apps. Microsoft 365 has over 400 million paid commercial seats (Microsoft FY2025), which makes Intune one of the most widely deployed BYOD platforms for businesses already on M365. If you run M365, the management layer is already part of your stack - see our Microsoft Intune management and the wider Microsoft 365 security approach. Microsoft documents the full BYOD enrolment model in its Intune deployment guidance. ## BYOD vs company-owned devices: which is right? BYOD removes handset procurement cost and lets staff use a device they already know, but it narrows your control and complicates support. Company-owned devices give full control and clean separation, at higher upfront and ongoing cost. Most SMEs run a hybrid: company devices for high-risk roles, managed BYOD for everyone else. | | Factor | BYOD (MAM) | Company-owned (MDM) | Hardware cost | None to the business | Full handset cost per user | Control scope | Work apps only | Entire device | Employee privacy | High - personal side untouched | Lower - device is corporate | Offboarding | Selective work-data wipe | Full device wipe/return | Best for | Email/Teams access, hybrid staff | Regulated or high-risk roles On cost, BYOD eliminates handset procurement, which can save £300–£800 per employee on device hardware alone (typical UK 2026 range). You still pay for management licensing, a support model, and sometimes a usage stipend. Even after those, many SMEs find BYOD reduces overall mobile spend - though the right answer depends on fleet size and how sensitive your data is. ## How do you secure data on personal devices? You secure BYOD data by containerising it: encrypt company apps, gate access behind MFA and Conditional Access, and keep the ability to remove work data on demand. The personal side of the device stays private and untouched. Security and privacy are not in tension here - done properly, both improve. The core controls AMVIA applies: - Containerisation - work apps encrypted and isolated from personal data - Conditional Access - block sign-in from non-compliant or risky devices - Selective wipe - remove company data without erasing the personal device, covered in our remote wipe and device security approach - Baseline enforcement - passcode, OS version, and jailbreak/root checks Because a lost personal phone is an endpoint risk, BYOD security connects directly to your wider managed cybersecurity posture and our BYOD security controls. A phone is just another endpoint - it deserves the same baseline as a laptop. ## Frequently asked questions Q: What should a BYOD policy include? A: A BYOD policy should cover permitted device types and operating systems, the management controls applied to corporate data, acceptable use rules, what happens to company data when an employee leaves, and liability for lost or stolen devices. It should also state clearly what IT administrators can and cannot see on a personal device, because transparency drives adoption and trust. Q: Is a BYOD policy a legal requirement in the UK? A: There is no law that names "BYOD policy", but UK GDPR holds you accountable for personal data wherever it is processed - including on staff-owned devices. The ICO expects reasonable technical and organisational measures. A written, enforced BYOD policy is how you demonstrate those measures and avoid liability if a personal device is lost. Q: Can my employer see everything on my personal phone under BYOD? A: No. With application-level management like Microsoft Intune MAM, IT sees only the company apps and their data - not personal photos, messages, browsing, or apps. Administrators can wipe the work container but cannot erase or read the personal side. A good BYOD policy states these boundaries explicitly so staff know exactly what is and is not visible. Q: What is the difference between MDM and MAM for BYOD? A: MDM (Mobile Device Management) controls the entire device and suits company-owned hardware. MAM (Mobile Application Management) protects only the work apps and their data, which is the right fit for personal devices. For BYOD, AMVIA almost always recommends MAM so employees keep their privacy while company data stays contained and wipeable. Q: How does BYOD affect Cyber Essentials Plus? A: Personal devices that access company data are in scope for Cyber Essentials Plus, so they must meet the same baseline as company hardware - supported OS, enforced passcode, malware protection, and access control. A documented BYOD policy with Intune enforcement is the practical way to bring personal devices into scope without buying everyone a company phone. Q: Does BYOD save money for small businesses? A: For most SMEs, yes. BYOD removes handset purchase costs and often reduces overall mobile spend once staff use devices they already own. You still pay for management licensing and support, so the saving depends on fleet size and security needs. The bigger win is usually speed and flexibility rather than raw cost. --- # AmviaIQ - Intelligent IT Management Platform URL: https://amvia.co.uk/amviaiq Last updated: 2026-03 AmviaIQ is AMVIA's security and network intelligence platform. It pulls live data from endpoints, email, firewall, identity and Microsoft 365 into one dashboard, then uses AI-driven analysis to surface threats, bottlenecks and compliance gaps before they hit your business. One provider, security-first, Microsoft-certified - built for the 1,200+ UK networks AMVIA manages. It is the visibility layer that sits on top of AMVIA's managed IT support and managed cybersecurity services, so the data and the people who act on it live under one roof. ## What is AmviaIQ in plain terms? AmviaIQ is a proprietary analytics platform that aggregates monitoring data from your network, endpoints, cloud services and security tools, then applies AI-driven analysis to flag the patterns that signal a performance problem or a security threat. It is built specifically for the environments AMVIA operates, not a generic dashboard. What sets it apart from off-the-shelf monitoring: - Pre-built integrations for the exact stack AMVIA deploys - Microsoft Defender, Barracuda email and network security, and Microsoft 365. - Alert logic tuned to real-world UK SME behaviour, not vendor defaults that drown you in noise. - A customer-facing view designed for MDs and IT managers, not just helpdesk engineers. ## What does AmviaIQ monitor and analyse? AmviaIQ gives you a single, correlated view across four domains: network performance, endpoint health, cloud services and security posture. Instead of four separate tools each showing a partial picture, you get one dashboard that connects the signals - which is where the threats and bottlenecks that matter actually show up. Across your environment it tracks: - Network performance - bandwidth, latency, packet loss and application performance by site, VLAN and app, so you spot congestion before it costs productivity. - Security threats and anomalies - correlated events from endpoints, email, identity and network, with AI-assisted prioritisation. - Endpoint health and patch compliance - device health, patch status and security agent status across every managed machine. - Backup success and failure - daily backup job results, with alerts on failures before they become data loss events. - User and admin activity - Microsoft 365 sign-in patterns and admin changes that can indicate account compromise. - Service desk trends - ticket volume, resolution time and recurring issues that point to root causes worth fixing. ## How does AmviaIQ work? AmviaIQ collects telemetry from RMM agents on managed endpoints, network monitoring probes, Microsoft 365 activity logs, firewall data and backup job results. That data is normalised and stored in UK-based cloud infrastructure, where AmviaIQ's AI models apply detection logic and trend analysis, then route anything actionable to AMVIA's in-house security team. The detection logic is calibrated against AMVIA's full managed base - over 1,200 UK business networks - so the anomaly thresholds reflect how real SMEs actually behave. That is the difference between an alert you act on and a false positive you learn to ignore. Microsoft's own guidance stresses continuous monitoring and signal correlation as the foundation of modern threat detection (Microsoft Security). ## Why do UK SMEs need unified security visibility? Most SMEs run several disconnected monitoring tools, and the signals that matter most only appear when data from multiple sources is correlated. Without a single view, an emerging threat sits hidden across four dashboards no one has time to cross-reference. For a business without a dedicated analyst, that gap is where incidents grow. The risk is not theoretical. The UK government's Cyber Security Breaches Survey 2025 found 43% of UK businesses experienced a cyber security breach or attack in the past year (gov.uk). The NCSC's guidance for small organisations makes the same point: early detection and response depend on knowing what normal looks like (NCSC). Data loss compounds the problem. Industry reporting claims "87% of IT professionals reported experiencing SaaS data loss in 2024", with malicious deletions a leading cause (2025 State of SaaS Backup and Recovery Report, The Hacker News), and that human error was "responsible for 95% of data breaches in 2024" - including accidental deletions inside Microsoft 365. Meanwhile "42% of UK SMEs" plan to increase investment in hybrid IT infrastructure, widening the surface that needs watching. ## How does AmviaIQ compare to standalone monitoring tools? AmviaIQ sits above device-level RMM and point monitoring tools, adding cross-source correlation and a business-level view. Standalone tools tell a technician what one device is doing; AmviaIQ tells an MD whether the business is working and secure, and routes anything urgent straight to AMVIA's security team. | | Capability | Standalone RMM / point tools | AmviaIQ | Scope | One domain (device, network or backup) | Network, endpoint, cloud and security in one view | Audience | Helpdesk technicians | IT managers, MDs and boards | Correlation | Manual, across separate dashboards | AI-driven, cross-source | False positives | High - generic vendor baselines | Tuned to 1,200+ UK SME networks | Action on alerts | Manual handoff | Auto-raises tickets and SOC review | Compliance reporting | Limited or manual | Automated monthly board-ready reports ## Who is AmviaIQ for? AmviaIQ is built for both non-specialist business owners and technical IT managers. The headline dashboard answers one question in plain language - "is everything working and secure?" - with network health, security posture and compliance scores. Drill-down views are there when a technical investigation is needed. For IT managers it provides the depth to manage proactively: capacity planning, device lifecycle data and security alert investigation. Monthly compliance reports are generated automatically and can be shared with boards, auditors, regulators or cyber insurers - useful evidence when you are demonstrating Microsoft 365 security controls or backup discipline. ## How does AmviaIQ connect to AMVIA's managed service? AmviaIQ is wired into AMVIA's service delivery platform. Alerts can automatically raise service desk tickets, trigger security analyst review, or kick off automated remediation depending on type and severity - so insight turns into action without a manual handoff. It is a working tool, not just a window. For managed clients, AmviaIQ data also feeds AMVIA's quarterly business reviews, giving an objective read on environment health, backup and business continuity status, and progress against agreed objectives. Alerts that need eyes-on escalate to AMVIA's 24/7 security monitoring team. ## Frequently asked questions Q: Is AmviaIQ available as a standalone product? A: AmviaIQ is available exclusively to businesses on AMVIA's managed IT support or managed connectivity plans. The platform depends on deep integration with AMVIA's RMM, security and backup tools, which supply the telemetry it analyses and correlates. That integration is what enables accurate anomaly detection with the low false-positive rate standalone monitoring tools cannot match. Q: How does AmviaIQ differ from RMM tools like Datto or NinjaRMM? A: RMM platforms give technicians device-level operational data. AmviaIQ sits above that data and adds a customer-facing analytics layer with cross-source security correlation and AI-driven anomaly detection. It delivers business-level insight - security posture scores, compliance reports and trend data - designed for IT managers and boards rather than helpdesk engineers. Q: What data does AmviaIQ collect and where is it stored? A: AmviaIQ collects telemetry from managed endpoints, network devices, Microsoft 365 activity logs and backup systems. All data is encrypted in transit and at rest, stored in UK-based cloud infrastructure, and retained in line with UK GDPR requirements. With UK government figures showing 43% of businesses hit by a breach or attack last year, that visibility is central to early detection. Q: Can AmviaIQ detect threats before they cause damage? A: Yes. AmviaIQ uses AI-driven anomaly detection, calibrated against over 1,200 UK business networks, to flag suspicious patterns - unusual sign-in locations, mass file encryption, or unexpected admin changes - before they escalate into full incidents. Alerts integrate with AMVIA's in-house security team for immediate investigation and containment. Q: What reports does AmviaIQ generate for board-level reporting? A: AmviaIQ automatically generates monthly compliance reports covering patch status, MFA adoption, backup success rates, security posture scores and service desk trends. Reports are written in plain language for board audiences and can be shared with auditors, regulators or cyber insurers. IT managers can open drill-down views for detailed technical investigation. --- # Case Study: Cubo - Scaling IT for Serviced Offices URL: https://amvia.co.uk/blog/cubo-case-study Last updated: 2026-07-16 This Cubo case study shows how AMVIA standardised managed leased line connectivity across six UK co-working sites. Replacing a patchwork of local carriers with one managed service, AMVIA cut new-site activation from 60+ days to under 30 - proving the value of a single, accountable, security-first connectivity provider. Cubo operates a growing network of premium co-working spaces across the UK. For a serviced office operator, connectivity is not a back-office utility - it is part of the product members pay for. A slow or unreliable line directly affects member retention. AMVIA was engaged to take ownership of the full connectivity estate and make every new site repeatable. ## What was the challenge for Cubo? Cubo ran each site on its own terms: separate carriers, different contract terms, mismatched hardware, and no central view of network performance. When a site had a problem, diagnosing and resolving it was slow. As the business opened new locations, every launch became a bespoke project rather than a repeatable process. The operations team needed one managed service provider to own the whole estate - circuits, hardware, faults, and monitoring. The commercial backdrop made this harder. Market pricing for a 1 Gbps leased line starts from £129/month depending on provider and postcode, with alternative carriers clustered lower than incumbents - so circuit selection had to be made site by site, not by defaulting to a single national carrier. ## What did AMVIA do for Cubo? AMVIA ran a connectivity audit across every Cubo site, reviewing existing circuits, hardware and contract positions, then designed one standardised architecture: a 1 Gbps dedicated leased line at each location, backed by 4G failover, all managed centrally. The goal was one accountable provider for the entire network. Rather than forcing the same carrier everywhere, AMVIA used its multi-carrier platform to source the best dedicated internet access circuit at each postcode - comparing Openreach, CityFibre and alternative carriers for the fastest-to-provision, most cost-effective option. This carrier-agnostic approach is the core of how AMVIA delivers multi-site connectivity without a one-size-fits-all compromise. Every site also gained resilience through backup connectivity: a 4G failover router alongside the primary circuit, so a carrier fault no longer meant total loss of service for members. ## What technology did AMVIA deploy? Each Cubo site was built to one hardware standard: a dedicated 1 Gbps leased line (carrier selected per site), a Cisco Meraki MX router with 4G failover, and Cisco Meraki MR Wi-Fi access points. Wi-Fi was segmented into separate networks for members, Cubo staff, and back-office systems. Network segmentation like this is a baseline control under the UK government's Cyber Essentials scheme - keeping guest, staff and management traffic apart limits how far any single compromise can spread. AMVIA, which holds Cyber Essentials Plus, builds that separation in by default rather than bolting it on later. Performance data from every site feeds into AmviaIQ for unified monitoring - bandwidth analytics, uptime tracking and anomaly detection across the estate. Combined with the Meraki dashboard, Cubo's IT contact and AMVIA's network team see every site from one place, with automated alerting and remote troubleshooting for minor issues - no engineer call-out required. For multi-site operators that want connectivity and security managed together, this mirrors AMVIA's SD-WAN approach. ## What were the results for Cubo? The standardised managed service changed how Cubo's network runs. New-site activation fell from the 60+ days of individual carrier negotiation and hardware procurement to a repeatable, templated deployment that AMVIA manages end to end - under 30 days from contract to live connectivity across six sites. Managed leased lines with 4G failover delivered 99.99% measured availability across the network in the 12 months after deployment, with failover typically activating within 30 seconds of a primary circuit fault. | | Aspect | Before AMVIA | After AMVIA | Carrier management | Separate carrier/ISP per site | One managed service; AMVIA owns all carriers | New-site activation | 60+ days | Under 30 days | Network visibility | No central view | Unified AmviaIQ monitoring across all sites | Resilience | Single circuit per site | Leased line + 4G failover at every site | Hardware | Mixed, site by site | Standardised Cisco Meraki MX Cubo's operations team gained central visibility instead of reacting to individual site issues. AMVIA handles all carrier relationships, fault management and hardware maintenance - a single point of contact and a consistent experience across the full estate. ## How does this Cubo case study apply to your business? Any multi-site UK business - co-working operators, retail chains, professional-services firms with branch offices - faces the same problem Cubo did: inconsistent connectivity, fragmented contracts and no single owner. A templated, carrier-agnostic managed service makes each new site as predictable as the last. As the UK communications regulator, Ofcom oversees the business connectivity market that AMVIA navigates on customers' behalf - comparing carriers so you don't have to. One provider, security-first, with Microsoft-certified engineers, removes the overhead of managing circuits, hardware and faults across a growing estate. --- # Case Study: Proactive Personnel - IT Transformation URL: https://amvia.co.uk/blog/proactive-personnel-case-study Last updated: 2026-07-16 Proactive Personnel, a national UK recruitment agency with 30+ branches, ran a patchwork of legacy IT with inconsistent security and reactive support. AMVIA delivered a phased modernisation: managed IT, a full Microsoft 365 Business Premium migration, and an enforced security baseline. Reactive helpdesk tickets fell by around 40% within six months - one accountable, security-first provider. ## What was the challenge for Proactive Personnel? Proactive Personnel is one of the UK's established national recruitment agencies, with a branch network spanning more than 30 locations. The business had grown organically, and its IT reflected that: mixed hardware generations, inconsistent software, a blend of cloud and on-premises systems, and no central IT management. The day-to-day consequences were real. Staff experiences varied branch to branch - newer laptops and fast lines in some, ageing kit and slow broadband in others. Support was reactive: issues were logged and eventually fixed, but nothing watched for problems before they hit staff. Costs were hard to forecast across per-incident fees, break-fix hardware, and ad-hoc software buys. Security was the bigger worry. With no centralised device management, posture varied across the estate: - MFA was not enforced across Microsoft 365 access. - Patch compliance was inconsistent between branches. - There was no single view of whether every device had working security software. - Legacy authentication was left enabled "just for that one app" - despite being the vector for the overwhelming majority of password spray attacks. That last point matters. Legacy authentication protocols - IMAP, POP3, SMTP, Exchange ActiveSync, MAPI - do not support MFA and remain a frequent attack vector. Microsoft reports that more than 99% of password spray attacks use legacy authentication, which is why blocking it is a foundational hardening step (Microsoft Learn). For context on scale, 68% of IT leaders in a CoreView industry survey reported attackers attempting to reach their Microsoft 365 environment weekly, daily, or constantly. ## What did AMVIA do? AMVIA proposed a phased IT modernisation across three stages, so improvements were visible to the management team throughout - not just at the end. Each phase delivered a measurable outcome before the next began, which kept risk low across a live 30-branch estate. The programme broke down as: - Phase 1 - managed service foundation. RMM agents across all devices, managed antivirus replaced with Microsoft Defender for Business, and centralised patch management. This is the core of AMVIA's managed IT support. - Phase 2 - connectivity. The most problematic branch circuits were replaced with better-performing lines, with managed routers added for centralised network visibility. Where a slow line was the main productivity constraint, AMVIA arranged business broadband upgrades. - Phase 3 - Microsoft 365 migration. A full move from on-premises email and file storage to Microsoft 365 Business Premium, with SharePoint replacing on-premises file servers. AMVIA ran this as a managed Microsoft 365 migration, branch by branch. The migration was conducted branch-by-branch, with mailbox moves scheduled outside business hours and SharePoint document libraries migrated over weekends. A 30-day parallel-run period at each branch let staff settle into the new environment before legacy systems were decommissioned. ## Which technologies did AMVIA deploy? The stack deployed across the Proactive Personnel estate was deliberately Microsoft-first and security-first - a single accountable provider rather than a tangle of point vendors. Everything below was standardised and centrally managed, so every branch ran the same hardened baseline. | | Capability | What AMVIA deployed | Why it mattered | Patch & monitoring | AMVIA RMM with automated patch management | Proactive fixes before staff reported issues | Productivity | Microsoft 365 Business Premium | Replaced on-prem Exchange, file servers and ad-hoc Office licences | Endpoint security | Microsoft Defender for Business | One managed endpoint baseline across the estate | Device management | Microsoft Intune | Compliance enforcement on every device | Identity | Conditional Access and MFA | MFA enforced for all Microsoft 365 access This is the practical shape of AMVIA's Microsoft 365 security approach: managed by Microsoft-certified engineers, configured to a security baseline, and monitored centrally. The National Cyber Security Centre lists multi-factor authentication as one of the highest-impact controls a business can turn on (NCSC guidance). ## What were the results? The impact was measurable within weeks of the managed service going live. Proactive patch management and standardised security configurations cut the estate's risk exposure, and AmviaIQ's central visibility meant AMVIA could find and fix issues before staff reported them. Reactive helpdesk tickets fell by approximately 40% within the first six months. Moving to Microsoft 365 removed the maintenance overhead of on-premises servers and simplified the environment. Branch managers could reach files and email from any device, supporting both in-branch and remote working, and Teams cut reliance on phone calls for cross-branch coordination. Remaining helpdesk issues were simpler to resolve because AMVIA had full remote access and context for every device. ## IT environment - before & after AMVIA | | Metric | Before AMVIA | After AMVIA | Devices on centralised management (%) | - | 100 | Patch compliance - 14 days (%) | - | 96 | MFA adoption (%) | - | 100 | Reactive helpdesk tickets (monthly avg) | 38 | - *Source: AMVIA managed-service reporting for Proactive Personnel.* ## Why managed IT and Microsoft 365 together? For a multi-branch business, the security win comes from standardisation: one baseline, one identity model, one provider accountable for both the IT and the security around it. Splitting connectivity, devices, and Microsoft 365 across separate suppliers is what created Proactive Personnel's inconsistency in the first place. Bringing it under one fully managed IT contract meant patching, endpoint security, identity, and migration were governed by the same policies - so every branch got the same protection without local exceptions. --- # Case Study: RatedPeople.com - Connectivity Upgrade URL: https://amvia.co.uk/blog/ratedpeople-com-case-study Last updated: 2026-07-16 RatedPeople.com, an online marketplace connecting homeowners with local tradespeople, outgrew consumer-grade broadband at its London HQ. AMVIA replaced it with a managed 1Gbps dedicated leased line, backed by a 99.99% uptime SLA and automatic 4G failover - one accountable provider, security-first, Microsoft-certified. ## What was the challenge? RatedPeople.com's London headquarters runs its engineering, product, marketing, and operations teams on cloud services, video conferencing, and collaborative tools. The business was on business broadband - fine for a small team, but straining under a growing headcount and heavier cloud usage. Two problems forced the upgrade. First, performance: peak-time degradation was disrupting video calls and access to cloud development environments, and the asymmetric broadband throttled the upload speeds developers and marketers depended on. Second, resilience: a prior broadband outage had cost several hours of disruption, and platform operations needed a contractual SLA plus a backup path during fault resolution. The wider picture explains why. Industry surveying found that "94% of small businesses in the UK experience poor internet connection; 91% encounter internet outages" (survey of 500 UK SME decision-makers, Zen Internet/YouGov 2024). Downtime hits the smallest businesses hardest, and for a connectivity-dependent marketplace, best-efforts broadband was a standing operational risk - the kind Ofcom, the UK communications regulator, tracks across business connectivity. ## What did AMVIA do? AMVIA ran a connectivity survey at the London HQ, checking availability across every carrier with network presence at the postcode. The building was on-net for two carriers - a premium metropolitan network and Openreach's national infrastructure - both quoting installation lead times of 30–90 working days. AMVIA recommended a managed 1Gbps dedicated internet access circuit on the most competitive carrier, paired with a Cisco Meraki MX router configured for automatic 4G failover. The managed service wrapped in 24/7 circuit monitoring, carrier relationship management, and AmviaIQ for real-time bandwidth analytics and capacity planning. The deployed solution comprised: - A dedicated 1Gbps symmetric leased line delivering uncontended bandwidth for the full London team - A Cisco Meraki MX security appliance acting as managed router and firewall - A 4G failover modem providing automatic backup connectivity if the primary circuit faulted - AmviaIQ integration for real-time utilisation monitoring, application performance visibility, and automated alerting to AMVIA's network operations team AMVIA managed the full installation - coordinating the carrier survey, civil works, and configuration - and pre-configured the Meraki device before delivery, so on-site work needed minimal input from the RatedPeople.com team. Gigabit-grade connectivity of this kind is exactly what the UK government's Project Gigabit programme is rolling out nationally. ## What were the results? The upgrade landed immediately. The symmetric 1Gbps connection cleared the upload bottleneck that had slowed development deployments and large file transfers, and video conferencing improved sharply as the consistent low-latency link removed the audio dropouts and video artefacts common on shared broadband. The resilience gain mattered just as much. The 99.99% SLA with a 4-hour onsite repair commitment gave the business the assurance it needed. In the months after deployment, the 4G failover activated once during a carrier-side fault - restoring team connectivity within 60 seconds and preventing any operational disruption while AMVIA managed the carrier fault resolution. Crucially, AMVIA's proactive monitoring meant the IT lead was told about the fault before any staff noticed, a clear shift from the previous reactive setup. AmviaIQ gave the IT lead ongoing visibility of bandwidth utilisation, enabling capacity planning as the team grows. ## Before and after: broadband vs the managed leased line | | Measure | Before (business broadband) | After (managed 1Gbps leased line) | Bandwidth | Asymmetric, contended | 1Gbps symmetric, uncontended | Upload performance | Throttled for developers | Full-rate for deployments and file transfers | Uptime commitment | Best-efforts, no SLA | 99.99% with 4-hour onsite repair | Outage handling | Hours of disruption | Sub-60s automatic 4G failover | Monitoring | Reactive | 24/7 proactive via AmviaIQ For context on what these circuits cost, a 1Gbps leased line starts from £129/month (AMVIA) - alternative networks such as CityFibre cluster lower than incumbents like BT and Vodafone. ## Frequently asked questions Q: What did AMVIA deliver for RatedPeople.com? A: AMVIA replaced consumer-grade broadband at RatedPeople.com's London HQ with a managed 1Gbps symmetric dedicated leased line, a Cisco Meraki MX router, and automatic 4G failover. The service carries a 99.99% uptime SLA with a 4-hour onsite repair commitment and 24/7 monitoring. Q: Why did RatedPeople.com move from broadband to a leased line? A: Business broadband could not keep pace with a growing London team's cloud usage. Peak-time slowdowns disrupted video calls and developer access, asymmetric upload speeds bottlenecked deployments, and a prior outage caused hours of downtime. The business needed contractual uptime and a backup path. Q: How fast did the 4G failover restore connectivity? A: When a carrier-side fault occurred after deployment, the Cisco Meraki MX's 4G failover restored team connectivity within 60 seconds, preventing operational disruption. AMVIA's network operations team managed the carrier fault resolution while the office stayed online throughout. Q: What is AmviaIQ and what did it provide? A: AmviaIQ is AMVIA's monitoring platform. For RatedPeople.com it delivered real-time bandwidth utilisation monitoring, application performance visibility, and automated alerting. It gave the IT lead the data to plan capacity as the team grew, and flagged the carrier fault before staff noticed. Q: How long did the leased line installation take in practice? A: For RatedPeople.com, both available carriers quoted installation lead times of 30–90 working days. Actual timelines depend on the carrier, whether the building is on-net, and any civil works required at the premises. AMVIA coordinates the survey, civils, and configuration end to end. --- # Case Study: Seven Projects - Unified Communications URL: https://amvia.co.uk/blog/seven-case-study Last updated: 2026-07-16 Seven Projects, a leading UK provider of project and programme management services, consolidated connectivity, IT support, Microsoft 365, VoIP and cybersecurity from five suppliers to one. AMVIA deployed managed VoIP with Microsoft Teams and hardened Microsoft 365 in two weeks, with no disruption to operations. The outcome: one accountable provider, security-first, Microsoft-certified engineers. ## Who is Seven Projects? Seven Projects is a leading provider of project and programme management services to clients across healthcare, education and social care in the UK. The business had grown quickly, with staff split between head office, remote consultants and people working on-site at client locations. That growth is exactly what exposed the cracks in how the team communicated and how its IT was run. - Sector: project and programme management (healthcare, education, social care) - Profile: fast-growing, distributed team across office, remote and client sites - Brief: one supplier for connectivity, IT, Microsoft 365, VoIP and cybersecurity ## What was the challenge for Seven Projects? Communication was fragmented. Staff were using different phone systems, personal mobile numbers, WhatsApp and email for client contact - making it hard to keep communications consistent or to track activity for compliance. The IT estate was just as patchy, with no central management, no monitoring and no backup of business-critical data. New starters were onboarded without a consistent process: some received properly configured devices, others set themselves up on personal equipment and consumer Microsoft 365 accounts. There was no security baseline, no single owner, and a legacy phone system never configured for the company's current size. The professional services sector handles sensitive client data, so the gaps mattered. For context on why this matters in education and skills, the source cites that *"92% of UK higher education providers have dedicated cybersecurity staffing"* - reflecting their position as significant targets - by contrast, *only 37% of further education colleges* have dedicated cyber staff *(Jisc)*. The same brief also referenced that *"87% of IT professionals reported experiencing SaaS data loss in 2024"*, with malicious deletions as the leading cause *(2025 State of SaaS Backup and Recovery Report, The Hacker News)*. Seven Projects' leadership wanted to fix the communications fragmentation and the IT maturity gap in a single programme - and with one managed supplier, not a patchwork of providers. ## What did AMVIA do? AMVIA proposed a single managed service covering connectivity, IT support, Microsoft 365, VoIP and cybersecurity, delivered on one monthly subscription. The work was phased so the highest-impact changes landed first: Microsoft 365 security hardening and VoIP deployment inside the first two weeks, then device management and backup, then the broader IT support transition. The VoIP build integrated directly with Microsoft Teams. Staff got a single client for internal messaging and external calls, with business numbers routing through Teams on laptops and mobiles - removing the need for separate desk phones at most positions. AMVIA managed the number porting end to end, transferring every existing business number and walking staff through Teams calling setup before the porting date so nothing dropped. Across Microsoft 365, AMVIA enforced multi-factor authentication, which the NCSC recommends as a baseline control, and applied Conditional Access policies that blocked the legacy authentication protocols behind most credential-compromise risk. This mirrors AMVIA's wider approach to Microsoft 365 security for SMEs. ## What technology did AMVIA deploy? The full stack combined connectivity, communications, Microsoft 365 and managed security under one provider. Each element was chosen to remove a specific gap - fragmented calling, unmanaged devices, no monitoring, and a head-office circuit that had outgrown its broadband line. - AMVIA's managed business VoIP system with Microsoft Teams Direct Routing - all external calls routed through Teams on desktop and mobile - Microsoft Teams Direct Routing for business-grade calling inside the Teams client staff already use - Microsoft 365 Business Premium with AMVIA's security baseline - Conditional Access, MFA, Microsoft Defender for Business, and email security - Microsoft Intune for device management across company-issued and BYOD devices - AMVIA's managed IT support with unlimited helpdesk and 24/7 monitoring - A managed leased line upgrade at head office, replacing a business broadband circuit no longer adequate for the team's size ## What were the results? The unified deployment changed how the whole team worked. Every member of staff - office, home or client site - could make and receive calls from their business number through Teams. Internal calls were free, call recording supported compliance with client SLAs, and an auto-attendant gave Seven Projects a more professional external image. All of it landed in two weeks. The Microsoft 365 hardening closed the most pressing gaps fast. MFA was enforced on all accounts within days, Conditional Access blocked legacy authentication, and Intune gave the IT team visibility and control across the device estate for the first time. Consolidating from five suppliers to one removed the management overhead of coordinating multiple vendors - leadership now deals with a single account manager, one monthly invoice and a dedicated escalation path. AMVIA's managed cybersecurity keeps that baseline monitored after go-live. ## Communications & IT - before and after AMVIA | | Metric | Before AMVIA | After AMVIA | Staff on unified communications (%) | - | 100 | MFA adoption (%) | - | 100 | Devices on MDM (%) | - | 100 | IT suppliers | 5 | 1 | VoIP + M365 deployment time | - | 2 weeks ## Frequently asked questions Q: What did Seven Projects consolidate with AMVIA? A: Seven Projects moved connectivity, IT support, Microsoft 365, VoIP and cybersecurity from five suppliers to one. That single managed service runs on one monthly subscription with one account manager and one invoice, replacing the overhead of coordinating multiple vendors for a fast-growing, distributed team. Q: How long did the deployment take? A: The VoIP system and Microsoft 365 hardening were deployed in two weeks, from contract to full rollout across the team, with no disruption to operations. Device management, backup and the broader IT support transition followed in later phases, so the highest-impact changes landed first. Q: How does Microsoft Teams Direct Routing work here? A: Microsoft Teams Direct Routing connects AMVIA's managed VoIP service to the Teams client staff already use. Every business number routes through Teams on laptops and mobiles, so staff make and take external calls from their business identity anywhere - removing separate desk phones and giving a consistent, professional external line. See Microsoft Teams Direct Routing. Q: What security controls did AMVIA apply to Microsoft 365? A: AMVIA enforced multi-factor authentication on all accounts, applied Conditional Access to block legacy authentication, deployed Microsoft Defender for Business and email security, and added Intune device management. Multi-factor authentication is a baseline control the NCSC recommends for every organisation handling sensitive data. Q: Can AMVIA do this for other growing UK businesses? A: Yes. The same single-provider model - connectivity, IT support, Microsoft 365, VoIP and managed security on one subscription - suits UK SMEs of 10 to 500 staff that have outgrown a patchwork of suppliers. The starting point is a review of your current setup against a security baseline. --- # Case Studies - AMVIA Client Success Stories URL: https://amvia.co.uk/case-studies Last updated: 2026-07-16 AMVIA's case studies show how UK SMEs replaced fragmented IT, connectivity and security suppliers with one accountable partner - cutting reactive tickets, raising uptime, and tightening their security posture. Each story sets out the problem, what we deployed, and the measurable outcome. One provider. Security-first. Microsoft-certified. We manage IT, connectivity, cybersecurity and communications for 1,200+ UK businesses, from serviced-office operators to national recruitment agencies. These are not testimonials in isolation - they are documented engagements with named clients, real technologies, and outcomes the client can confirm. ## What do AMVIA's case studies actually prove? They prove that consolidating IT, connectivity, security and communications under a single managed provider produces measurable operational gains - fewer tickets, higher availability, and a stronger security baseline. Every featured engagement names the client, the services delivered, and the result. Across the managed estate, AMVIA reports: - 99.97% average uptime across managed networks (2024) - 97% first-contact resolution on the helpdesk (2024) - 1,200+ UK business networks managed These figures reflect proactive monitoring, failover infrastructure and carrier SLA management across our managed IT support estate. AMVIA is certified to Cyber Essentials Plus, the UK government-backed scheme that requires a hands-on technical audit, and is a Microsoft Solutions Partner for Modern Work, Security and Infrastructure. ## Which AMVIA case studies can I read? Four engagements span the core problems UK SMEs bring to us - multi-site connectivity, IT modernisation, high-availability internet, and supplier consolidation. Each shows a different service mix delivered under one point of accountability. - Cubo - standardised managed connectivity across a growing co-working network, cutting new-site activation times and delivering consistent high-availability internet for members. - Proactive Personnel - IT modernisation across a 30+ branch recruitment agency, including Microsoft 365 migration, centralised device management, and a 40% reduction in reactive IT tickets. - RatedPeople.com - high-availability leased line deployment for a London-headquartered online marketplace, replacing consumer broadband with dedicated 1Gbps connectivity and 4G failover resilience. - Seven Projects - unified communications and IT consolidation for a leading provider of project and programme management services, delivering managed business VoIP, Microsoft 365 and cybersecurity from a single supplier. ## How does AMVIA work with its clients? AMVIA is a UK managed service provider working primarily with small and medium-sized businesses across every sector. Unlike break-fix support or single-service resellers, we deliver one fully managed service spanning IT, connectivity, security, Microsoft 365 security, VoIP and mobile - so clients hold one provider accountable for the whole estate. That single-supplier model is the thread running through every case study. It removes the finger-pointing between separate broadband, phone, security and IT vendors, and gives the client one helpdesk, one account team, and one consolidated bill. ## What does single-provider IT look like in numbers? The table below contrasts the typical fragmented-supplier setup most SMEs start with against the consolidated AMVIA model the case studies describe. | | Dimension | Typical multi-supplier setup | AMVIA managed model | Accountability | Split across 3–5 vendors | One provider, one SLA | Helpdesk | Multiple numbers, slow triage | Single helpdesk, 97% first-contact resolution | Security baseline | Inconsistent, often unmanaged | Microsoft Defender + Barracuda, monitored 24/7 | Billing | Several invoices | One consolidated bill | Microsoft 365 | Unmanaged tenant | Hardened, Solutions Partner-managed ## What connectivity benchmarks inform these projects? AMVIA scopes connectivity against current UK market pricing so clients can see where their quote sits. For dedicated internet, a 1 Gbps leased line starts from £129/month, with pricing varying by provider and location across alternative networks such as CityFibre and Hyperoptic and incumbents like BT and Vodafone. Availability matters too: in roughly 46% of UK postcode sectors (Ofcom "Area 3", 2025), competition is limited, which changes both price and lead time. Ofcom's business connectivity market reviews set the framework AMVIA uses to benchmark a client's options before recommending a route. ## What security outcomes do clients see after onboarding? Security is the connective tissue of every engagement, not an add-on. After AMVIA's initial deployment, clients consistently report a stronger, measurable baseline - multi-factor authentication enforced, devices centrally monitored, and backups tested rather than assumed. | | Metric (aggregated, post-deployment) | Value | Average MFA adoption | 100% | Average patch compliance | 97% | Sites with centralised monitoring | 100% | Clients with tested backup recovery | 100% This matters because most UK breaches still start with unmanaged basics. The NCSC's small business guidance makes clear that MFA, patching and tested backups are the controls that stop the majority of common attacks - exactly the baseline these engagements lock in. AMVIA's stack is Microsoft Defender plus the Barracuda email and network suite, monitored by our in-house team. ## How do clients rate AMVIA? Common feedback themes are consistent across the case studies: the value of one responsive IT partner, a measurable lift in security posture after the first deployment, the simplicity of consolidated billing, and the responsiveness of the helpdesk and account team. Microsoft 365 sits at the centre of most engagements; you can read what the platform covers on Microsoft's official Microsoft 365 site. ## Frequently asked questions Q: What is an AMVIA case study? A: An AMVIA case study is a documented account of a real client engagement - the problem the business faced, the services AMVIA deployed, and the measurable outcome. Each names the client and the technologies involved, covering IT support, connectivity, cybersecurity, Microsoft 365 and communications under a single accountable provider. Q: Who are AMVIA's case study clients? A: The featured clients are Cubo, a growing co-working network; Proactive Personnel, a 30+ branch recruitment agency; RatedPeople.com, a London-headquartered online marketplace; and Seven Projects, a leading provider of project and programme management services. They span serviced offices, recruitment, online marketplaces and project and programme management - a representative cross-section of UK SMEs AMVIA supports. Q: What services do these case studies cover? A: Across the four engagements, AMVIA delivered managed IT support, dedicated leased-line connectivity, business VoIP, Microsoft 365 migration and security, centralised device management, and cybersecurity monitoring. The common thread is consolidation: replacing several separate suppliers with one provider accountable for the entire IT and communications estate. Q: Is AMVIA certified to handle business security? A: Yes. AMVIA is certified to Cyber Essentials Plus, the UK government-backed scheme requiring an independent hands-on technical audit, and is a Microsoft Solutions Partner for Modern Work, Security and Infrastructure. Security is built into every engagement using Microsoft Defender and the Barracuda email and network suite, monitored by AMVIA's in-house team. Q: How does AMVIA start a new client engagement? A: AMVIA's discovery process begins by reviewing your current IT environment, understanding your business requirements and growth plans, and identifying where improvement would have the greatest impact. There is no commitment to a specific solution at this stage - the goal is to understand your situation before recommending anything. Q: Can AMVIA replace several of my existing suppliers? A: Yes - that is the model most case studies describe. AMVIA consolidates IT support, connectivity, cybersecurity, Microsoft 365, VoIP and mobile into one managed service. Clients gain a single helpdesk, one account team, and one consolidated bill, removing the gaps and finger-pointing that come from juggling multiple specialist vendors. --- # The Complete Guide to Business Leased Lines URL: https://amvia.co.uk/guides/leased-line-guide Last updated: 2026-07-21 A leased line is a private, symmetric, dedicated internet circuit installed straight into your premises by a carrier. Bandwidth is reserved for you, speed never varies, and a formal uptime SLA backs it. This leased line guide covers real UK costs, speeds and install timescales - and how AMVIA manages every circuit as one accountable provider. If you want the deeper technical primer, read our explainer on what a leased line is and the full business leased line pillar, which sets out how each option fits a UK office. ## What is a business leased line? A leased line - sometimes called an Ethernet leased line, or EFM (Ethernet in the First Mile) at lower speeds - is a private circuit connecting your premises directly to an internet exchange. Unlike contended business broadband, the bandwidth is yours alone and performance does not dip at busy times. Four properties separate a leased line from broadband: - Dedicated: the bandwidth is reserved exclusively for your business - no other customer shares it. - Symmetric: download and upload speeds are identical. A 500Mbps line delivers 500Mbps both ways at once. - SLA-backed: carriers commit to a formal uptime guarantee, typically 99.99% or better, with defined fix times and financial remedies. - Uncontended: there is no contention with other users, so throughput stays consistent. The physical link is usually a fibre cable from a local carrier point of presence to your building. Where full-fibre networks such as CityFibre or Openreach's Ethernet network already reach the site, delivery is straightforward. Ofcom's business connectivity work tracks how that wholesale market is opening up across the UK. ## How does a leased line actually work? A leased line works by engineering a continuous fibre path from your office to the wider internet, then terminating it on equipment AMVIA configures and monitors. There are four moving parts, and the "last mile" is where most cost and complexity sit. 1. Last mile: the physical cable from your building to the nearest network node. This drives most of the install cost. 2. Carrier network: the national fibre backbone carrying your traffic to an exchange. 3. Internet exchange: where the carrier hands off to the public internet. 4. CPE (Customer Premises Equipment): the router or switch at your site that terminates the circuit and serves your LAN. AMVIA manages the whole chain - choosing the right carrier for your postcode, configuring the CPE, and monitoring the live circuit through AmviaIQ. For sites that need guaranteed throughput without a full leased line, dedicated internet access options can bridge the gap. ## What speeds and costs should you expect? Ethernet leased lines come in standard speed tiers, and the right one depends on user count, applications, and growth headroom. Pricing varies heavily by location: well-served city addresses hit the low end of each range, while rural or complex sites cost more. Treat the figures below as indicative and verify per address. | | Speed | Typical use case | Approx. monthly cost | 100Mbps | 10–25 users; cloud apps, VoIP, remote access | from £69/mo | 200Mbps | 25–50 users; heavy cloud, video, backups | £250–£450/mo (typical UK 2026 range) | 500Mbps | 50–150 users; multi-site apps, hosted telephony | £350–£650/mo (typical UK 2026 range) | 1Gbps | 150–500 users; data-intensive workloads | from £129/mo | 10Gbps | Enterprise, data centres, high throughput | from £349/mo As a settled benchmark, a 100Mbps leased line starts from £69/month on a 36-month term in urban areas, rising to around £390/month in semi-rural areas. AMVIA runs a multi-carrier comparison at quotation stage to find the most competitive option for each specific address, rather than routing every order through one network. The UK's wider full-fibre rollout, tracked on gov.uk, is steadily improving coverage and pricing for business sites. ## How should you read a leased line SLA? The service level agreement is the feature buyers under-scrutinise most. Read it on like-for-like terms, because a headline availability percentage means little without the repair commitment behind it. Four components decide whether an SLA is genuinely protective. - Availability guarantee: expressed per calendar month. A 99.99% target equates to roughly 4.4 minutes of maximum downtime per month. Always check whether scheduled maintenance is excluded from the figure. - Mean Time to Repair (MTTR): the contractual fix commitment - typically an 8-hour repair target for in-network faults, with a 4-hour P1 response on premium tiers. - Compensation: most carriers credit future invoices when targets are missed, but some require an active claim. Read the small print. - Proactive monitoring: AMVIA monitors every circuit via AmviaIQ, detecting degradation and opening carrier tickets without waiting for you to report a problem. For business-critical connectivity, MTTR often matters more than the availability headline - a 99.99% guarantee with a 24-hour fix is weaker than a slightly lower target with a 4-hour fix. ## Leased line vs broadband and the alternatives? A leased line is not the only answer. It sits among full-fibre broadband, SD-WAN, and mobile failover, each with a legitimate place depending on budget and risk tolerance. The table below sets out the trade-offs an MD should weigh before committing. | | Option | Contention | Symmetry | SLA | Best for | Leased line | Uncontended | Symmetric | Formal 99.99%+ | Cloud-dependent, VoIP, hosted servers | Full-fibre (FTTP) | Contended | Asymmetric | None equivalent | Cost-sensitive download-heavy sites | SOGEA / FTTC | Contended | Asymmetric | None meaningful | Legacy - upgrade overdue | SD-WAN + broadband | Mixed | Mixed | Bonded resilience | Multi-site cost-effective resilience | 4G/5G failover | N/A | N/A | Backup only | Continuity during fibre faults Full-fibre broadband can deliver gigabit downloads for a fraction of leased line pricing, but uploads are asymmetric and there is no true SLA - a real limitation if you upload large files or run hosted services. For multi-site resilience, SD-WAN that bonds circuits is a credible architecture, and AMVIA usually pairs a line with 4G/5G backup connectivity at install rather than after the first outage. ## What does installation involve, and how long does it take? Installation runs through five stages, and standard lead times are 30–90 working days for most UK premises. Knowing the sequence helps you set realistic expectations internally and avoid operational disruption during the cutover. 1. Survey and feasibility (1–5 working days): the carrier checks whether fibre can reach you without major civils. Most urban and suburban sites are feasible at standard pricing; complex sites may attract excess construction charges. 2. Order and lead time (30–60 working days): complex installs needing new duct runs or landlord Wayleave agreements take longer. 3. Physical install: an engineer runs the external cabling and places the Network Termination Equipment - usually one half-day on site. 4. CPE configuration and testing: AMVIA configures the router, connects your LAN, tests against the contracted spec, and sets up AmviaIQ monitoring. 5. Go-live and handover: the circuit is activated, speeds and SLA terms confirmed, and any cutover from an existing line is managed to minimise downtime. ## Who actually needs a leased line? A leased line is worth serious evaluation once your business depends on consistent, symmetric bandwidth that contended broadband cannot guarantee. It is not the right fit for every site - but for the profiles below, the SLA pays for itself in avoided downtime. - 20+ users on cloud apps: Microsoft 365, Google Workspace, Salesforce and hosted VoIP all need steady upload and download. Peak-time slowdowns signal contention. - VoIP phone systems: voice is sensitive to latency, jitter and packet loss. A dedicated circuit removes the most common cause of call-quality problems - pair it with Microsoft Teams Calling for a single managed stack. - Regular large file transfers: design, engineering, media firms and cloud-backup users gain most from high symmetric upload. - Hosted servers or infrastructure: if external users or other offices reach services you host, upload speed matters as much as download. - Regulated sectors: financial services, legal and healthcare, where availability carries compliance and commercial consequences. - Multi-site operations: linked branches benefit from multi-site connectivity built on dedicated circuits. ## How should you choose a provider? Choose on carrier coverage at your exact address, SLA and MTTR terms, support quality, and route diversity - not on the headline price alone. The UK market is served by a handful of carriers and many resellers, and the right network genuinely differs street by street. - Carrier coverage: CityFibre has strong metropolitan reach; Openreach's Ethernet network covers more of the UK. AMVIA compares carriers per address rather than defaulting to one. - SLA and MTTR: compare like-for-like - a 5-hour MTTR is a different product from a 24-hour one. - Support quality: when a fault hits, you need someone who acts. AMVIA's NOC handles carrier fault reporting and escalation so you are not stuck in a support queue. - Carrier diversity: for maximum resilience, two carriers on physically separate routes remove the single point of failure. This is where AMVIA's model earns its place: one provider, security-first, with Microsoft-certified engineers managing the line as part of your wider IT and security environment - not a standalone telecoms purchase. ## Frequently asked questions Q: What is the typical lead time for a leased line installation? A: Standard lead times are 30–90 working days for most UK business premises. Complex sites needing new civil works or a landlord Wayleave agreement can take longer. AMVIA confirms a likely timescale during quotation, manages the carrier order end to end, and keeps you updated at each stage so there are no surprises for your team. Q: What is the minimum contract term for a leased line? A: Most carriers require a minimum 12-month term. 24 and 36-month terms typically attract lower monthly pricing and may include a waived installation charge. AMVIA presents options across term lengths so you can weigh the commercial trade-off, rather than defaulting you to the longest commitment a carrier prefers. Q: Can I get a leased line if I rent my office? A: Yes, in most cases. Where the circuit needs physical works to the building, you may need landlord permission through a Wayleave agreement, which AMVIA handles on your behalf. Many modern office buildings already carry fibre infrastructure, which simplifies and speeds up the install considerably. Q: What happens if my leased line develops a fault? A: AMVIA monitors every circuit via AmviaIQ and usually detects a fault automatically. We raise a ticket with the carrier immediately, manage the escalation, and keep you updated throughout. The goal is a carrier engineer response within the agreed SLA window, without you having to notice and chase the problem first. Q: Is a leased line the same as dedicated fibre broadband? A: Not exactly. "Dedicated fibre" is a marketing term for some full-fibre broadband products, but they remain contended services without a true symmetric SLA. A genuine leased line is an uncontended, symmetric circuit with a formal availability guarantee and defined repair times - a different class of service from any broadband product. Q: Can I use a leased line for VoIP phone calls? A: Yes. A leased line is an excellent choice for hosted VoIP or Microsoft Teams Calling. Its symmetric bandwidth, low latency and SLA-backed uptime address the three most common causes of poor call quality. AMVIA can deliver the line and the phone system together as one managed, accountable service. --- # PSTN Switch-Off 2027: What UK Businesses Must Do Now URL: https://amvia.co.uk/guides/pstn-switch-off Last updated: 2026-08-28 The PSTN switch off is the retirement of the UK's copper telephone network on 31 January 2027, when every analogue line, ISDN circuit and PSTN-connected device stops working. Businesses must migrate to VoIP or Microsoft Teams Calling before the deadline. AMVIA plans and runs that migration end to end - one provider, security-first, Microsoft-certified. The numbers that matter: - 31 January 2027 - hard switch-off deadline - ~2.8m lines still on the PSTN, 500,000+ at business premises (Openreach, February 2026) - VoIP and Microsoft Teams Calling - the replacement technologies - 3–6 weeks - typical migration time from sign-off If you run a phone line, an ISDN circuit, copper broadband, or any device that dials out over a telephone line, this affects you. The good news: with planning, the move to business VoIP is straightforward, usually cheaper than ISDN, and you keep your existing numbers. This guide explains exactly what changes, who is affected, and the steps to migrate without disruption. ## What is the PSTN switch off and why is it happening? The PSTN (Public Switched Telephone Network) is the UK's traditional copper-wire telephone network, carrying voice calls since the late 19th century. ISDN runs digital lines over the same infrastructure for business phone systems. BT Openreach is retiring both because the copper is ageing, costly to maintain, and incompatible with IP-based communications. Carrying voice over internet networks - the technology behind VoIP and Microsoft Teams Calling - is more efficient and far more flexible than dedicated copper circuits. The switch off does not touch the fibre Openreach has been laying. It retires only the legacy copper telephone network and the circuit-switched signalling that runs on it. The migration is well advanced: PSTN lines now account for just 19% of UK landline connections, down from 27% in 2024 (Ofcom Connected Nations 2025). ## Who is affected by the PSTN switch off? The switch off affects any business with an analogue phone line, an ISDN circuit, copper-based broadband (ADSL or FTTC), or a device that connects over a telephone line. That last category - alarms, lifts, card terminals - is the one businesses most often miss, and it carries the highest disruption risk. Check your contracts for any of the following: - PSTN phone lines: Standard analogue lines (POTS) used for voice, fax, or backup. - ISDN connections: ISDN2 or ISDN30 circuits feeding a business PBX. These cease entirely after the deadline. - ADSL or FTTC broadband: Copper-delivered broadband that depends on PSTN infrastructure. Many providers have already moved customers to SOGEA, which needs no telephone line. - Devices on telephone lines: Burglar and fire alarms with PSTN diallers, CCTV monitoring links, dial-up card terminals, door entry systems, fax machines, and lift emergency phones. If you are unsure, audit every service that references a telephone number or analogue line - including remote sites and lines installed years ago and forgotten. ## When is the PSTN switch off deadline? The deadline is 31 January 2027. After that date the PSTN and ISDN cease to function - there is no extension, no fallback, and no grace period. The programme has run in phases since 2020, with stop-sells already in force and exchange areas being migrated in waves through 2026. | | Date | What happened | 2020 | Openreach announced the switch-off date and halted new ISDN sales | 2023 | Stop-sell on new PSTN and ISDN products - no new orders accepted | 2023–2026 | Active migration of existing customers to IP alternatives | September 2025 | Several hundred exchange areas in active migration | 31 January 2027 | PSTN and ISDN cease; remaining connections terminated Businesses that have not migrated by the deadline lose telephony service on that date. Leaving it late means rushed decisions, engineer shortages, and higher costs. ## How does VoIP replace the PSTN? VoIP (Voice over Internet Protocol) carries calls over your internet connection instead of a dedicated copper circuit. It converts voice into data packets routed by a cloud platform that handles voicemail, call recording, hunt groups, and every feature an on-premise PBX once provided - with no on-site hardware. A well-built VoIP system is indistinguishable from a traditional phone, and you keep your numbers. What a successful deployment needs: - Adequate bandwidth: Each simultaneous call uses roughly 100Kbps. Twenty concurrent callers need at least 2Mbps dedicated to voice. For VoIP at scale, a dedicated leased line or quality full-fibre connection is strongly recommended. - Low latency: VoIP is sensitive to latency and jitter. Quality of Service (QoS) on your router prioritises voice traffic and protects call quality. - IP handsets or softphones: Replace desk phones with IP handsets, or use software clients on laptops and mobiles. - A hosted platform: AMVIA runs its own hosted phone system and supports Microsoft Teams Calling. You keep your existing numbers. Porting geographic (01/02) and non-geographic (03/08) numbers typically takes 2–4 weeks, and AMVIA manages it on your behalf. ## Should you choose hosted VoIP or Microsoft Teams Calling? For Microsoft 365 businesses, Microsoft Teams Calling is often the most natural path - staff make and receive calls inside the Teams app they already use. Standalone hosted VoIP suits businesses needing physical reception handsets, complex multi-site routing, or contact-centre features. Neither is universally right; the fit depends on how your people actually work. | | Factor | Hosted VoIP | Microsoft Teams Calling | Best for | Reception desks, multi-site, contact-centre needs | Microsoft 365 users consolidating voice into Teams | Hardware | IP handsets or softphones | Softphone-first; headsets and Teams-certified handsets | Number porting | Yes, managed by AMVIA | Yes, via Direct Routing | Licensing | Per-user hosted plan | M365 licence plus Teams Phone licence | Routing flexibility | High | Higher via Direct Routing than Microsoft Calling Plans Teams Calling has two deployment models. Microsoft Calling Plans supply numbers and minutes through your subscription - simpler, but less flexible and usually pricier per user. Direct Routing connects Teams to the phone network through a SIP provider such as AMVIA, giving lower per-minute costs, more control, and number portability. See Microsoft's own Teams cloud voice documentation for the technical detail. Teams Calling needs at least Microsoft 365 Business Basic plus a Teams Phone add-on licence. You can compare the platform options on the Microsoft 365 UK site. If you run a modern IP-capable PBX, a SIP trunk may connect it without replacing hardware. ## What happens to alarms, lifts and card machines on the PSTN? Devices that use telephone lines for connectivity - not voice - fail silently when the PSTN goes off unless they are upgraded first. This is the most frequently missed part of switch-off planning, and for lifts it is a legal compliance matter, not a convenience. Plan replacements early, because engineers will be stretched in late 2026. - Alarms and monitoring: Intruder and fire alarms with PSTN diallers stop reaching monitoring centres. The dialler module is usually swapped for a 4G or IP module at low cost - prompt your alarm company explicitly. - Card payment terminals: Older dial-up PDQ terminals are affected. Most modern terminals already use internet or 4G; confirm with your provider. - Lift emergency phones: Lifts must legally keep an emergency line. PSTN-connected lift phones must be migrated before the deadline - this is the building owner's responsibility. - Fax machines: Analogue fax stops working. A cloud fax service delivers faxes as email attachments for businesses with regulatory or client needs. ## How much does PSTN switch off migration cost? The switch off is usually a chance to cut telephony costs, not just maintain them. An ISDN30 circuit costing £60–£100 per month for 30 channels typically costs far less as a VoIP system with the same call capacity once inclusive bundles are factored in. Hardware spend is lower too, because softphones replace many physical handsets. Indicative migration costs from AMVIA: | | Item | Indicative cost | IP handsets | £50–£150 per handset | Hosted VoIP | £5–£15 per user per month, inc. UK landline/mobile calls | Migration and setup | Configuration, porting management and training included; project costs vary by complexity Many businesses run a mix of physical handsets and mobile softphone apps, which cuts the handset count and the upfront bill significantly. ## What should you do now to prepare for the PSTN switch off? Start now rather than waiting for a provider notice - many providers migrate customers automatically with minimal warning, and you get a better outcome by making an informed decision first. Treat connectivity and telephony together: upgrading a marginal broadband line at the same time as moving to VoIP is more efficient than doing them sequentially. 1. Audit your lines and devices. List every phone line, ISDN circuit, broadband service, and connected device. Check bills and contracts, including remote and forgotten sites. 2. Assess your internet connectivity. VoIP needs reliable, low-latency bandwidth. Marginal broadband produces poor call quality - fix it as part of the move. 3. Choose your migration path. Hosted VoIP, Microsoft Teams Calling, or SIP trunking to a modern PBX. 4. Plan connected-device replacements. Brief your alarm, lift, and terminal suppliers and agree timelines. 5. Manage number porting. Start 4–6 weeks before go-live. AMVIA schedules porting to match your cutover. ## How does AMVIA manage your PSTN switch off migration? AMVIA has run PSTN and ISDN migrations for SMEs across the UK and handles both the technical work and the business-change side. We assess your current setup, recommend the right path for your circumstances, and manage the transition so it does not disrupt operations - one provider, security-first, Microsoft-certified. We have no commercial preference between solutions. If Teams Calling is right, we deploy it; if a standalone hosted platform serves you better, we recommend that. From audit and planning through porting, installation, and user training, AMVIA owns the process end to end - and because we are a security partner first, your voice platform is configured to be defensible, not just functional. ## Frequently asked questions Q: When exactly is the PSTN switch-off? A: 31 January 2027 - the date the UK's copper telephone network is retired. Every analogue phone line, ISDN circuit and PSTN-connected device stops working then. The migration window is open now, and engineer availability tightens as the deadline approaches. Q: What equipment is affected by the PSTN switch-off? A: More than phones: alarms, door entry systems, lift lines, card terminals, fax machines and older broadband products (like FTTC with an underlying phone line) all ride the PSTN. Audit everything connected to a phone line - the non-phone devices are the ones businesses forget until they fail. Q: What should we migrate to before the switch-off? A: Voice moves to hosted VoIP (typically £5–£15 per user/month at the entry end) or Microsoft Teams calling; broadband moves to SoGEA or full-fibre FTTP, which don't need a phone line underneath. Done together, the combined bill is usually lower than the legacy stack it replaces. Q: What's the right migration sequence? A: Check what your postcode supports, order the new data connection, port your numbers to the new platform (5–15 working days), and only then cease the analogue services. Ceasing lines before porting numbers is how businesses lose numbers - never do it in that order. Q: Wasn't the PSTN switch-off supposed to happen in 2025? A: Yes - the original deadline was December 2025, which is why many businesses still search for "PSTN switch off 2025". Openreach pushed the hard cut-off to 31 January 2027 to give the industry more migration time, but the direction never changed: no new analogue services have been sold since September 2023, and every traditional line still in use must move before the 2027 date. The delay is breathing room, not a reprieve. --- # AmviaIQ vs Competitors - IT Management Platform Comparison URL: https://amvia.co.uk/amviaiq-competition Last updated: 2026-03 AmviaIQ is AMVIA's customer-facing network and security analytics platform. Unlike RMM tools such as Datto RMM, ConnectWise Automate and NinjaRMM - built for IT providers to manage client estates - AmviaIQ gives your in-house team board-level visibility of security, compliance and network health. One provider. Security-first. Microsoft-certified. This page compares AmviaIQ against the remote monitoring and management (RMM) tools most common in UK managed IT environments, so an IT manager can see exactly where the lines are drawn. RMM stands for remote monitoring and management - software a provider uses to watch and maintain devices remotely. ## What is the difference between AmviaIQ and RMM competitors? AmviaIQ is built for the businesses AMVIA supports; RMM tools are built for the providers that support them. Datto, ConnectWise and NinjaRMM monitor and manage client devices on behalf of an MSP. AmviaIQ takes that telemetry and translates it into security, compliance and performance insight your own stakeholders can read. The result is a different audience and a different output. Standard RMM platforms surface device health and patch status to engineers. AmviaIQ surfaces correlated security signals and board-level reporting to the people who carry the risk - IT directors, MDs and compliance leads. It sits on top of AMVIA's managed managed IT services rather than replacing the tooling underneath. ## How does AmviaIQ compare feature by feature? Across network analytics, security correlation, customer visibility and managed-service integration, AmviaIQ exposes capabilities to end customers that RMM tools keep inside the provider. The table below reflects standard product tiers as of March 2026. "Add-on" means the capability is available as a paid add-on or third-party integration. | | Feature | AmviaIQ | Datto RMM | ConnectWise Automate | NinjaRMM | Real-time network performance analytics | Yes | Yes | Yes | Yes | Customer-facing visibility dashboard | Yes | No | No | Add-on | AI-powered anomaly detection | Yes | No | No | No | Security event correlation (SIEM-like) | Yes | No | Add-on | No | Microsoft 365 activity monitoring | Yes | No | No | Add-on | Automated compliance reporting | Yes | Add-on | Add-on | Add-on | Backup job monitoring | Yes | Yes | Yes | Yes | Endpoint patch compliance tracking | Yes | Yes | Yes | Yes | Available to end-customers (not just MSP) | Yes | No | No | No | Integrated with AMVIA managed service | Yes | No | No | No | Standalone product available | No | Yes | Yes | Yes | Board-level reporting output | Yes | No | No | No Datto RMM, ConnectWise Automate and NinjaRMM are primarily tools for IT providers, not the businesses they support. AmviaIQ is AMVIA's customer-facing layer that sits above AMVIA's RMM tooling and turns it into insight a non-engineer can act on. ## Who is AmviaIQ built for? AmviaIQ is designed for the IT managers and senior stakeholders at the businesses AMVIA supports. It provides visibility, compliance reporting and security insight in a format that is actionable without deep technical expertise. It is deliberately not a tool for IT service providers to manage a portfolio of client estates. That is the core distinction. Datto, ConnectWise and NinjaRMM are RMM platforms an MSP uses to monitor and maintain client devices; they are not typically accessible to the end-customer businesses they watch. AMVIA uses RMM tooling as part of service delivery, then layers AmviaIQ on top to give you the view your provider usually keeps to itself. ## How does AmviaIQ add security correlation? Standard RMM tools are strong on device health and patch management but do not correlate security signals across endpoints, email, identity and network. AmviaIQ adds that correlation layer, surfacing the anomalies and patterns that indicate potential compromise rather than just a device fault. This matters because attackers exploit the gaps between tools. According to the UK Government's Cyber Security Breaches Survey 2025/26, 65% of medium businesses reported a breach or attack (gov.uk, DSIT 2025/26). Detection delays compound the damage - the average time to identify and contain a breach was 241 days. Correlated visibility shortens that window. AmviaIQ draws on AMVIA's security stack - Microsoft Defender for endpoint signals and the Barracuda suite for email and network - to connect events that single-purpose RMM tools see in isolation. For SMEs, it provides much of what a SIEM for SMEs would, without a separate analyst team to read raw logs. ## Does AmviaIQ replace a separate SIEM or security dashboard? For most SMEs, yes. AmviaIQ provides SIEM-like security event correlation alongside network performance analytics and Microsoft 365 activity monitoring, consolidating into one customer-facing dashboard what would otherwise need several tools. SIEM means security information and event management - the practice of collecting and correlating security logs to spot threats. It pairs naturally with AMVIA's wider managed cybersecurity and 24/7 security monitoring, where Microsoft Defender for Endpoint is watched by AMVIA's in-house round-the-clock SOC. AmviaIQ is the reporting and visibility layer; the monitored response sits in the managed service beneath it. It also reads Microsoft 365 security activity, flagging risky sign-in and configuration gaps directly to your team. ## What does AmviaIQ cost compared to RMM tools? AmviaIQ is included as part of AMVIA's managed IT and connectivity services - there is no separate licence fee. Datto RMM, ConnectWise Automate and NinjaRMM are purchased by managed service providers and are not typically priced or available for end-customer businesses to buy directly. | | Consideration | AmviaIQ | Standalone RMM tools | Who buys it | Included with AMVIA managed service | Purchased by the IT provider | Separate licence fee | None for AMVIA clients | Per-device/per-technician pricing | Intended user | End-customer stakeholders | MSP engineers | Customer-facing reporting | Built in | Rarely exposed If you are an AMVIA client, AmviaIQ visibility is already part of your agreement. If you are evaluating AMVIA as a provider, AmviaIQ forms part of what you receive with a managed engagement. If you are independently shopping for standalone RMM software to run yourself, tools like Datto RMM or NinjaOne offer broader provider-side integrations - they are simply solving a different problem. ## Frequently asked questions Q: How does AmviaIQ differ from standard RMM platforms like Datto or NinjaRMM? A: AmviaIQ is a customer-facing analytics platform, whereas RMM tools like Datto and NinjaRMM are designed for IT providers to manage client estates. AmviaIQ surfaces security event correlation, AI-powered anomaly detection and board-level reporting directly to business stakeholders - capabilities RMM tools do not expose to end customers. Q: Can I purchase AmviaIQ as a standalone product without AMVIA managed services? A: No. AmviaIQ is purpose-built for AMVIA's managed service stack and is included at no extra cost for AMVIA clients. It draws data from across your managed IT, connectivity and security services to provide a single unified view, rather than running as an isolated tool you license separately. Q: Does AmviaIQ replace the need for a separate SIEM or security dashboard? A: For most SMEs, yes. AmviaIQ provides SIEM-like security event correlation alongside network performance analytics and Microsoft 365 activity monitoring. It consolidates what would otherwise require multiple tools into one customer-facing dashboard, removing the need for in-house analysts to interpret raw log data. Q: What reporting does AmviaIQ provide compared to competitor platforms? A: AmviaIQ generates board-level compliance and security reports for non-technical stakeholders - something RMM platforms do not offer natively. It includes automated compliance reporting, patch compliance tracking and security anomaly summaries. Only 47% of UK businesses have two-factor authentication in place (gov.uk, DSIT 2025/26), and AmviaIQ highlights gaps like these proactively. Q: Why does it matter that AmviaIQ is built for the customer, not the provider? A: Because risk sits with the business, not the tooling. The NCSC advises that boards need clear, regular visibility of their cyber posture (ncsc.gov.uk). RMM tools keep that view inside the MSP. With AI-generated phishing now reported in 82.6% of phishing emails and 99.9% of compromised accounts lacking MFA, stakeholders need readable, correlated insight - not raw provider telemetry. Q: Should I choose AmviaIQ or a standalone RMM tool? A: If you are an existing AMVIA client, AmviaIQ is the right fit - it is purpose-built for AMVIA's managed stack and included in your agreement. If you are an IT provider buying software to manage your own client base, a standalone RMM platform is the correct category. AmviaIQ and RMM tools solve different problems for different users. --- # Best Business VoIP Providers in the UK (2026) URL: https://amvia.co.uk/best-business-voip-providers-uk Last updated: 2026-03 The best business VoIP providers in the UK for 2026 include AMVIA, RingCentral, 8x8, Vonage and BT Cloud Voice. For SMEs that want UK-based support, Microsoft Teams integration and a single accountable supplier for telephony, connectivity and security, AMVIA leads - one provider, security-first, Microsoft-certified. This comparison assesses the leading UK business VoIP options on price, features, reliability and SME suitability, so you can shortlist the right provider without wading through sales decks. ## Which business VoIP provider is best for a UK SME? The right provider depends on three things: your headcount, your existing technology stack, and how much hands-on support you want. Larger global businesses lean toward enterprise UCaaS platforms; UK SMEs that value a single supplier and a named account manager are better served by a managed provider like AMVIA. - Choose AMVIA if you want a fully managed UK VoIP service - setup, number porting, hardware and ongoing support - from a provider who can also run your IT, connectivity and cybersecurity. Best for UK SMEs wanting one supplier and hands-on support. - Choose RingCentral or 8x8 if you are a larger business with global offices needing an enterprise UCaaS platform, international calling bundles and advanced analytics. Strong platforms, but less focused on the SME managed-service model. - Choose BT Cloud Voice if you already have a BT relationship and prefer to consolidate telephony with your connectivity provider. Capable hosted telephony, though Teams integration and support responsiveness can be more limited than a specialist. ## How do the leading UK business VoIP providers compare? The table below sets the leading UK providers side by side on the features that decide SME suitability - bundled call recording, Teams Direct Routing, UK-based support and account management. AMVIA bundles call recording, a UK call package and account management into its base price; most enterprise platforms charge these as add-ons. | | Feature | AMVIA VoIP | RingCentral | 8x8 | Vonage Business | BT Cloud Voice | Unlimited UK calls included | ✓ | ✓ | ✓ | ✓ | ✓ | Microsoft Teams integration (Direct Routing) | ✓ | ✓ | ✓ | ✓ | ✗ | Auto-attendant & IVR | ✓ | ✓ | ✓ | ✓ | ✓ | Call recording included | ✓ | Add-on | ✓ | Add-on | Add-on | Mobile softphone app | ✓ | ✓ | ✓ | ✓ | ✓ | Number porting managed | ✓ | ✓ | ✓ | ✓ | ✓ | UK-based customer support | ✓ | ✗ | ✗ | ✗ | ✓ | Dedicated account manager | ✓ | Enterprise only | Enterprise only | Enterprise only | Business accounts | Hardware supply & configuration | ✓ | ✓ | ✓ | ✓ | ✓ | PSTN migration support | ✓ | ✓ | ✓ | ✓ | ✓ | Bundled with managed IT service | ✓ | ✗ | ✗ | ✗ | ✗ | CRM integrations | ✓ | ✓ | ✓ | ✓ | Limited | Typical starting price (per user/mo) | From £5.95 | From £15 | From £12 | From £14 | From £16 Prices indicative as of March 2026. Actual pricing varies by contract term, user count and feature tier. AMVIA pricing includes a UK call bundle, call recording and account management. Third-party pricing is based on published list rates - volume discounts are available from all providers. ## What should you prioritise when comparing UK VoIP providers? Prioritise UK-based support, Microsoft Teams integration via Direct Routing, whether call recording is included or charged as an add-on, and contract flexibility. Many global providers route support through overseas centres, which slows resolution when a phone outage is costing you business. Switching is common when the experience disappoints, and mobile flexibility is now a baseline expectation - staff answer business numbers on desk phones, laptops and mobiles interchangeably. With the UK PSTN switch-off scheduled for completion by January 2027 (Openreach), migration support is now a buying criterion, not a nice-to-have. Ofcom's guidance on moving landlines to digital sets out what the switchover means for businesses (ofcom.org.uk). For a deeper look, see our guide to the PSTN switch-off. ## Is VoIP cheaper than a traditional phone system? Yes - for almost every SME. A traditional on-premises PBX for a 20-user business typically needs £5,000–£15,000 in hardware and installation, plus annual maintenance and ISDN line rental. A managed VoIP service is an operating cost instead of a capital one. | | Cost factor | Traditional PBX (20 users) | Managed VoIP (20 users) | Up-front hardware & install | £5,000–£15,000 | Minimal | Per-user monthly cost | Line rental + maintenance | £12–£20 per user/mo | Typical annual cost | Hardware amortised + ISDN rental | £2,880–£4,800 inc. calls & support | Maintenance | Separate contract | Included | Scales up/down | Slow, hardware-bound | Same day A managed VoIP service costs £12–£20 per user per month - for a 20-user business that is £2,880–£4,800 per year, inclusive of calls, maintenance and support. The ROI case is strong before you even factor in flexible, cloud-based working. A hosted phone system removes the on-premises hardware entirely. ## Can you use Microsoft Teams instead of a separate VoIP provider? Yes - through Teams Direct Routing or Microsoft Calling Plans, your existing Teams environment becomes a full business phone system. Teams Phone is now widely used as a full business phone system, and for Microsoft-centric SMEs it removes the need for a second app entirely. Direct Routing via a provider like AMVIA often costs less per minute than Microsoft's own calling plans and gives you more control over number management and call routing. Microsoft's own documentation explains how Direct Routing connects Teams to the public telephone network (learn.microsoft.com). See our Microsoft Teams Direct Routing service for how AMVIA sets this up. ## The AMVIA recommendation For UK SMEs wanting UK-based support, Microsoft Teams integration and a single provider for connectivity and telephony, AMVIA VoIP is our recommendation. Larger businesses needing global PSTN replacement should weigh RingCentral. If you are Microsoft-centric, Teams Phone via AMVIA's Direct Routing service offers the smoothest experience - and because we are a security partner first, your call platform is configured with VoIP security built in, not bolted on. ## Frequently asked questions Q: Who is the best business VoIP provider in the UK? A: It depends what you're optimising for: 8x8 (from £12/user) and Vonage (from £14) compete on breadth, RingCentral (from £15) on enterprise features, BT (from £16) on brand familiarity - and AMVIA (from £5.95) on price plus the thing none of the big platforms offer: the phones, the connectivity they run on, and the support under one accountable provider. Q: Why is there such a price spread between VoIP providers? A: Entry prices span £5.95 to £16 per user/month largely on packaging: what's bundled (calling plans, integrations, support tier) versus sold as add-ons. Compare the total monthly cost for your actual call profile and user count, not the headline rate. Q: Should I buy VoIP from my internet provider? A: There's a real argument for it: call quality is a bandwidth question, and when the same provider runs both the phones and the connection, there's no gap for fault-blame to fall into. That single-accountability model is AMVIA's core case against the standalone platforms. Q: What should I check before signing a VoIP contract? A: Number porting terms (5–15 working days, sequenced before any line cease), what the calling plans actually include, contract length, Teams integration if you need it, and - most skipped - whether your internet connection can carry call volume at peak times. A cheap platform on a congested line is a false economy. --- # BeautifullyConnected Managed Desktop Services for UK Businesses URL: https://amvia.co.uk/beautifullyconnected-managed-desktop-services Last updated: 2026-03 BeautifullyConnected managed desktop services give UK businesses one monthly fee per device covering 24/7 monitoring, patching, endpoint security and UK helpdesk support - replacing reactive break-fix with a single accountable provider. Security comes first, every engineer is Microsoft-certified, and pricing is flat from £25 per desktop per month. Key credentials: - Cyber Essentials Plus certified - Microsoft Solutions Partner (Modern Work, Security, Infrastructure) This is a managed-IT offer at heart, so it sits under our managed IT support for UK SMEs and pulls in security from our managed cybersecurity and Microsoft 365 security practices. One provider, security-first, Microsoft-certified. --- ## What does the managed desktop service include? Every desktop is covered by one predictable monthly fee that bundles monitoring, patching, security, helpdesk and lifecycle management. There are no per-ticket charges and no surprise invoices - you budget once and we keep every device secure, current and performing. - 24/7 proactive monitoring - hardware health, disk space, CPU load and application errors watched around the clock, so faults are fixed before users notice. - Automated patch management - operating system and third-party patches tested and scheduled, with critical security fixes fast-tracked within 24 hours. Timely patching is one of the NCSC's core technical controls. - Endpoint security - Microsoft Defender for Business, DNS filtering, Barracuda email protection and application whitelisting included as standard from day one. - Unlimited UK helpdesk - phone, email and live chat support from UK engineers during business hours, with no ticket limits. - Desktop lifecycle management - provisioning, deployment, refresh and secure decommissioning across your whole estate. - Microsoft 365 integration - devices configured with Intune policies, OneDrive backup and Entra ID single sign-on so staff sign in once and work anywhere. ## How much do managed desktop services cost? BeautifullyConnected managed desktop services start from £25 per desktop per month, scaling with the security, support hours and management features you need. Every plan includes unlimited helpdesk tickets with no per-incident charges, so the figure on your invoice stays the same month to month. | | Cost factor | What you pay | What you avoid | Monthly desktop fee | Flat rate from £25/desktop | Unpredictable break-fix bills | Helpdesk tickets | Unlimited, included | Per-incident charges | Patching & monitoring | Included | Separate tooling contracts | Endpoint security | Microsoft Defender + Barracuda, included | Bolt-on security add-ons Flat-rate pricing means a device that needs three call-outs in a month costs the same as one that needs none. That is the point of a managed model: predictable spend instead of reactive cost. ## What performance can you expect? Across our managed desktop estate we measure delivery against defined SLAs rather than vague promises. The figures below are drawn from our own service reporting and form part of the contractual SLA you sign. - 99.97% desktop uptime delivered across the full managed estate in 2024 - Under 1-hour response to critical (P1) issues, with a 2-hour target for other desktop issues, guaranteed in the SLA - 97% first-contact resolution - most issues fixed on the first call without escalation - £0 hidden fees - flat-rate pricing per desktop, no surprise charges ## How do you onboard a desktop estate? Onboarding follows a structured, five-stage process that typically completes within 30 days, with zero disruption to your team. We document, deploy, harden and hand over in a defined sequence so nothing is missed and no device is left unmanaged. 1. Desktop audit and discovery - we document every device: hardware specs, installed software, security posture and user assignments. This baseline drives the managed service. 2. Agent deployment - monitoring, security and management agents installed silently in the background, with no user downtime. 3. Security hardening - endpoint protection enabled, patch baselines applied, local admin rights reviewed and disk encryption enforced. Hardening to a recognised baseline supports your Cyber Essentials controls. 4. User onboarding - your team is shown how to raise tickets and walked through any new security policies. 5. Managed service live - full service goes live and your named account manager books the first quarterly review. ## Why choose BeautifullyConnected for managed desktops? We built this service for UK businesses that need reliability, security and expert support from one accountable provider - not an offshore helpdesk and a stack of disconnected tools. Security is the foundation, not an afterthought, and every engineer is Microsoft-certified. - UK-based support team - engineers based in the UK who understand British compliance and infrastructure. No offshore helpdesks. - Accredited and certified - Cyber Essentials Plus and Microsoft Solutions Partner status, with endpoint security built on Microsoft Defender for Business. - 1,200+ UK businesses trust us - we manage desktops and IT for over 1,200 UK organisations across legal, finance, healthcare and professional services. - Predictable costs - one flat monthly fee per desktop, no hidden charges, no per-ticket fees. --- ## Frequently asked questions Q: What is included in BeautifullyConnected managed desktop services? A: Every desktop is covered by 24/7 proactive monitoring, automated patch management, endpoint security (Microsoft Defender for Business, DNS filtering and Barracuda email protection), unlimited UK helpdesk support, full lifecycle management and Microsoft 365 integration. It is all under one flat monthly fee per desktop, with no ticket limits and no hidden charges. Q: How much do managed desktop services cost? A: BeautifullyConnected managed desktop services start from £25 per desktop per month, scaling with the level of security, support hours and management features you need. Every plan includes unlimited helpdesk tickets with no per-incident charges, so your monthly cost stays predictable rather than spiking whenever a device needs attention. Q: Can you manage both Windows and Mac desktops? A: Yes. The service supports Windows 10, Windows 11 and macOS devices. Monitoring agents, patching schedules and security policies are configured per operating system, so a mixed estate gets consistent protection and management. You see the same dashboards, SLAs and helpdesk regardless of which platform a member of staff uses. Q: How does onboarding work when switching providers? A: Onboarding follows a structured process that typically completes within 30 days. We audit your estate, deploy monitoring and security agents, harden endpoints and introduce your team to the helpdesk. Your previous provider is contacted to arrange a clean handover. Most businesses experience no disruption during the transition because deployment runs silently in the background. Q: Do you support remote and hybrid workers? A: Yes. The service is built for modern, distributed teams. Desktops are managed through cloud-based tools regardless of location, whether staff work from the office, home or on the road. VPN, Entra ID conditional access and remote support are all included, so security policies follow the user rather than the building. Q: What contract terms are available? A: Rolling monthly contracts with no lock-in are the standard option, alongside 12-month and 24-month agreements with preferential pricing. Every contract includes defined SLAs, a named account manager and a 90-day exit clause. The aim is to earn your business each month on service quality, not to trap you in a long agreement. ---