
Quick Answer
You may not know immediately.
A business being hacked does not always result in computers going offline, files being encrypted or a ransom message appearing on the screen.
Sometimes the first sign is much smaller.
You might notice:
A Microsoft 365 login you don't recognise
Emails being sent from your account that you didn't send
Customers telling you they have received strange emails from you
Password reset messages you weren't expecting
Changes to email forwarding rules
Staff suddenly being locked out of accounts
Unusual payments or requests to change bank details
Computers behaving differently or becoming unexpectedly slow
Security settings being changed without explanation
The National Cyber Security Centre (NCSC) lists unusual emails, unrecognised login alerts, unexpected device behaviour and unauthorised payments among the warning signs that a business may be experiencing a cyber attack.
The important thing is not to assume everything is fine simply because the computers are still working.
No.
This is one of the biggest misconceptions about cyber attacks.
People often imagine a hacker breaking into a computer and immediately causing damage.
In reality, somebody who gains access to one of your accounts may deliberately try to avoid being noticed.
For example, if someone gets into an employee's email account, they might quietly watch emails for days or weeks.
They could be looking for:
Invoices
Payment information
Customers and suppliers
Password reset emails
Conversations with accountants
Details of upcoming payments
Opportunities to impersonate somebody in the business
If they immediately break everything, you know something is wrong.
If they quietly read emails, they may be much harder to spot.
There isn't one single sign that proves a business has been hacked.
Instead, you normally need to look for unusual activity.
Microsoft 365 and many other online services record information about account logins.
You may see a login from:
A country you don't normally operate in
An unfamiliar device
An unusual IP address
A time when the employee wasn't working
One unusual login does not automatically mean somebody has hacked the account.
Mobile networks, VPNs and other services can sometimes make login locations look unusual.
But it is something worth investigating.
This is a particularly important warning sign.
A customer might contact you and say:
"Did you send me this invoice?"
or:
"Why are you asking me to pay into a different bank account?"
If the email genuinely came from one of your business accounts and nobody in your company sent it, you need to investigate immediately.
The NCSC specifically identifies people receiving strange emails from your domain as a possible sign of a cyber incident.
This is something business owners rarely think to check.
Someone who gets into an email account can sometimes create a rule that automatically forwards copies of messages elsewhere.
The employee may continue using their email normally and never realise it is happening.
The NCSC specifically recommends checking email filters and forwarding rules when you suspect an account has been compromised.
This is one reason simply changing a password may not always be enough.
You also need to understand what was changed while the account was accessible.
If an employee says:
"My password doesn't work anymore."
don't automatically assume they have forgotten it.
Someone who gains access to an account may change:
The password
Recovery information
Security settings
Multi-factor authentication settings
The NCSC lists being unable to log into an account and unexplained changes to security settings as possible indicators that an account has been compromised.
You may receive messages saying someone has requested a password reset.
One message could simply be someone entering the wrong email address.
Repeated attempts across different accounts deserve more attention.
This can indicate someone is trying to gain access.
If you use multi-factor authentication and an employee suddenly receives an approval request they didn't initiate, they should not approve it.
Someone may already have that employee's password and be trying to complete the login.
Staff should know that unexpected login approval requests need to be reported rather than simply dismissed.
Sometimes the first obvious sign of an attack is financial.
For example:
A supplier's bank details appear to change
An employee receives an urgent request from the managing director
An invoice is altered
A payment is redirected
Money leaves the company account unexpectedly
If you think money has been stolen, contact your bank immediately using contact details you obtain independently.
For businesses in England, Wales and Northern Ireland, cyber crime and fraud can also be reported through Report Fraud. Businesses experiencing a live cyber attack can currently call 0300 123 2040.
Sometimes there are more obvious signs.
You might see:
Computers becoming unusually slow
Applications opening or closing unexpectedly
Security software being disabled
Files becoming inaccessible
New software appearing
Internet searches being redirected
Ransom messages
Large numbers of files suddenly changing
These are worth investigating, but a slow computer on its own does not mean you have been hacked.
There are plenty of perfectly innocent reasons for a computer to become slow.
You need to look at the bigger picture.
Yes, and for many small businesses this is one of the first places I would look.
Microsoft 365 contains logs and security information that can help establish what has happened.
Depending on your Microsoft 365 setup and licences, you may be able to investigate things such as:
Account login activity
Unusual login attempts
Changes to accounts
Email forwarding rules
Mailbox activity
Security alerts
Multi-factor authentication changes
Administrator activity
The important point is that you shouldn't just ask:
"Can the employee still log in?"
You want to establish whether somebody else has also been able to log in.
Multi-factor authentication makes account compromise considerably harder and is one of the most important protections a business can use.
But it does not mean an account can never be compromised.
There are attacks designed to trick users into approving logins or giving criminals access to authenticated sessions.
That doesn't make MFA pointless.
Quite the opposite.
You should still have it enabled.
It simply means security should not depend on one protection alone.
The first priority is to work out what is happening and prevent the problem getting worse.
Depending on the incident, this might include:
Contact your IT or cybersecurity provider
Secure affected accounts
Change compromised passwords
Log affected accounts out of existing sessions
Check email forwarding and mailbox rules
Review login activity
Check whether other accounts are affected
Preserve logs and evidence
Check bank and payment activity if relevant
Record what happened and when
The NCSC recommends identifying what happened, which systems or accounts are affected and taking steps to resolve and contain the incident.
Try not to start randomly deleting things before you understand what has happened.
Information that looks unimportant now may help establish how somebody got in later.
Possibly.
It depends on what happened.
If the incident involves personal information, you also need to consider whether it is a reportable personal data breach.
The Information Commissioner's Office says that where a personal data breach meets the reporting threshold, organisations must report it without undue delay and within 72 hours of becoming aware of it.
The ICO also recommends starting a record of what happened, who was involved and what actions you took even if you later determine that the incident does not need to be reported.
A cyber incident can also be reported to the NCSC, although an NCSC report does not replace any separate legal or regulatory reporting obligations you may have.
This is where things become more difficult.
The absence of an obvious warning does not prove that nobody has accessed your systems.
If you're concerned, you can have someone review the security of your environment.
For a small business, I would normally want to understand things like:
Who has access to your Microsoft 365 environment
Whether MFA is enabled properly
Whether there are suspicious login events
Whether old or unused accounts still exist
Whether unexpected email forwarding rules are present
Who has administrator access
Whether devices are properly protected
Whether important security settings have been changed
Whether backups are working
Whether obvious vulnerabilities are present
You're essentially trying to answer two questions:
Is there anything here that suggests somebody has already got in?
and:
Is there anything here that would make it unnecessarily easy for somebody to get in?
Those are slightly different questions, but both matter.
Usually, yes.
If you already have an IT provider, speak to them first.
They know your systems and may already have security monitoring or logs available.
Ask them specifically whether they can check for:
Suspicious Microsoft 365 logins
Compromised accounts
Unusual mailbox rules
Administrator changes
Malware alerts
Unexpected remote access
Security configuration problems
You don't necessarily need to replace your IT company or buy another managed service.
Sometimes you simply need somebody to independently check the security side and then work with your existing IT provider to fix anything that is found.
Unfortunately, nobody can honestly promise that with absolute certainty.
Cybersecurity doesn't work like an MOT where someone can inspect a business and guarantee nothing bad has ever happened.
What you can do is gather evidence.
You can review the accounts, logs, devices, security settings and activity available to you and look for indications of compromise.
You can also improve monitoring so that suspicious activity is more likely to be detected in future.
The better your logging and monitoring, the easier it becomes to answer the question:
"What happened?"
when something doesn't look right.
Probably the biggest point to take away from this is that a cyber attack does not have to be dramatic.
Your computers can still work.
Your email can still work.
Your website can still work.
And someone could still have access to something they shouldn't.
The warning might simply be an unexpected login, a strange email or a customer asking why your bank details have changed.
Small signs are worth investigating.
It is much easier to deal with a suspicious login today than a fraudulent payment, stolen data or ransomware attack next week.
If something doesn't look right, start with your IT provider.
Ask them to check the affected account or system and establish exactly what has happened.
If you want an independent look at your cybersecurity, Systems Secure can review your existing setup and explain the findings in plain English.
We don't replace your IT company or provide general IT support.
We focus specifically on cybersecurity and can work alongside your existing IT team or IT provider.
Systems Secure
https://systemssecure.uk
Being hacked does not always cause an obvious outage
Strange logins, unexpected emails and unusual account changes can all be warning signs
Microsoft 365 activity is an important place to investigate
Check forwarding rules and security changes, not just passwords
Unexpected MFA prompts should never simply be approved
Financial changes or unusual payment requests need immediate attention
Keep a record of what happened and what you did
If personal data is involved, consider whether the incident needs reporting
Your existing IT provider should normally be your first call
If you're still unsure, an independent cybersecurity review can help establish what is happening and identify weaknesses before they become bigger problems
Your IT team keeps the business running. We check it is protected — finding the risks, telling your IT team what to fix, and showing you the proof every month in plain English.
Per computer, sole trader. Excludes VAT.
Three packages, sized by how many people you have — £35, £204 and £710 a month. Every price is on this page.
Systems Secure Ltd is an independent cyber security company based in Copthorne, West Sussex, run by James Batt and working with businesses across the UK. Its managed service, QuantumCare, works alongside your existing IT support rather than replacing it — finding the risks, telling your IT team what to fix, and checking that important protections are still working.
This is cyber security, not IT support. Prices are published on this site, starting at £35 a month. Cyber security should give you clear answers — not long reports, confusing alerts or guesswork.
There's a reason a company's accounts are prepared by one firm and audited by another. It isn't that accountants can't be trusted — it's that nobody, however good, is well placed to check their own work.
Keeps your systems, users and everyday technology running. In-house or outsourced, they stay involved throughout — and receive clear, specific actions from us whenever their help is needed.
Finds the cyber risks, strengthens protection, and checks that important security controls are still working. You get an independent view of what's protected, what has changed, and what should happen next.
Good IT teams tend to welcome this. An independent report is often the evidence they've been trying to get budget on for months.
One person, one computer
From £35
per computer, per month
Priced per Microsoft 365 or Google account
From £204
per month
Priced per Microsoft 365 or Google account
From £710
per month
No setup fees. No minimum contract. No penalty for changing your mind. All prices exclude VAT. Compare all packages side by side
QuantumCare CISO is the mirror image of the packages above — all people, no software. A qualified security officer for a business of 10 to 250 people, from £1,200 a month. Five published prices, and no quote to ask for.
See CISO pricesOne-off work with James at a fixed price agreed before anything starts. £450 to review one system — your Microsoft 365, your firewall, your backups. £795 for the whole business. Got a question first? There's no charge for finding out whether you need us.
See consulting pricesNo form to fill in first, and no sales call needed to find out the number.
Three QuantumCare packages, sized by how many people you have, from £35 a month. Every price is published on this site.
A conversation, not a pitch. We confirm which package fits — and if the honest answer is that you don't need us, we'll say so.
We install it, configure it and check it is working — usually inside a week from agreement, and mostly without you noticing.
Monitoring, updates applied in the background, and problems dealt with rather than just flagged up. Micro Business and Business Pro add a plain-English summary each month.
Month to month on 30 days' notice, no setup fee and no penalty for changing your mind. A 12-month option is there if you'd rather freeze your price — a choice, not a requirement.
If your business is compromised while you're following the agreed security plan, you get three months' fees back. No security company can promise you'll never be attacked, and we don't.
The managed security list is capped at 20, so the person checking your security is actually paying attention — and you deal with the same person every time.
We will not take on a direct competitor of an existing client, and every price on this site is the price you pay.
In IT, networks and cyber security since 1995
Systems Secure trading, full time on cyber security since 2016
Defences strengthened, risk reduced, peace of mind delivered
Trained to spot threats, stop breaches and protect businesses
The gold standard in cyber security, recognised worldwide.
Certified to run a security programme — governance, risk and reporting to a board.
Qualified to think like a hacker and find your weaknesses first.
Certified in structured cyber risk management using the NIST framework.
Globally recognised qualification in cyber security best practice.
Most cyber security experts talk in acronyms. I talk like a business owner — because I am one.
I went into the oil and gas industry in 1995, doing IT, networks and security for global corporations, and led multi-million-dollar projects across America and Europe. Twenty-one years of it — and security was part of the job from the first day. I'm not an IT man who retrained into it later.
In 2010 I started Systems Secure as a sideline and ran it alongside the day job for six years. By 2016 it had outgrown the evenings and weekends, so I sat the Certified Ethical Hacker exam, left a good salary and better benefits behind, and turned the company from IT to cyber security — because security was, and still is, the weakness most smaller businesses have.
Sixteen years on, I've helped 200+ UK organisations strengthen their defences, pass compliance audits, and sleep easier knowing their data — and their reputation — are protected. You deal with me, not a rotating support desk.
Written for the person who owns the business, not the person who runs the servers. No acronyms, no scare stories, and nothing you need a technical background to act on.
We'll email you the PDF. The button opens a short form — one name, one email address.
Send me the guide In a hurry? The ten-point checklist is on the site already, with nothing to fill in.The main ones that come up on almost every call, answered here so you don't have to book one to find out.
Systems Secure managed cyber security starts at £35 per computer per month for a sole trader, £204 per month for a business of one to nine people, and £710 per month for a business of ten or more. All prices exclude VAT and there are no setup fees.
What you pay depends on how many people you have. The Sole Trader package is priced per computer. Micro Business and Business Pro are priced per Microsoft 365 or Google account, so the cost scales with your team rather than a fixed licence block. Every price is published on the website — you don't need to sit through a sales call to find out the number.
QuantumCare is Systems Secure's cyber security service: three managed packages priced by how many people you have — Sole Trader from £35 a month, Micro Business from £204 and Business Pro from £710 — plus QuantumCare CISO, a separate service from £1,200 a month for businesses of 10 to 250 that need a qualified security officer rather than more software.
It is cyber security, not IT support — it works alongside whoever runs your systems rather than replacing them, finding the risks, telling your IT team what to fix, and checking that important protections are still working.
No. Every Systems Secure package runs on a rolling monthly basis with 30 days' notice and no cancellation penalty. There is no minimum term.
A 12-month option is available if you'd rather freeze your price, which saves £2 per account per month. It's a choice, not a requirement.
No. There are no setup fees and nothing to pay upfront on any Systems Secure package. You pay monthly, starting from the month the service begins.
No. All Systems Secure prices are quoted excluding VAT. VAT is added to your invoice at the prevailing UK rate.
Yes. Fixed-price consulting is available with no ongoing commitment: £150 for a single question answered in writing within two working days, £250 for a second opinion, £450 for a review of one system, and £795 for a full review of your business. All prices exclude VAT.
These prices are built for businesses of up to 25 staff. Above that, the price rises with headcount.
No. Systems Secure is designed to work alongside your existing IT support, not replace it. Whether your IT is outsourced or in-house, they carry on running your systems, users and everyday technology, and receive clear, specific actions from us whenever their help is needed.
The two roles are different jobs. Your IT team keeps the business running; Systems Secure checks that it's actually protected. You get an independent view of what's protected, what has changed and what should happen next — without disrupting a relationship that's already working.
Usually yes — and it tends to help them rather than undermine them. An in-house IT manager is responsible for keeping everything running, which means security competes with a hundred other urgent things every week. It also means they would be reporting on the quality of their own work, which isn't a fair position to put anyone in.
Systems Secure gives your IT manager a specialist to escalate to and a second pair of eyes on the things that matter, and gives you a view that doesn't depend on one person's workload or judgement.
IT support keeps your technology working: fixing problems, setting up new starters, keeping systems online. Cyber security is a separate job — finding weaknesses before an attacker does, strengthening protection, and checking that important controls are still working months after they were switched on.
Good IT teams, in-house or outsourced, do handle parts of security — including updates, backups and access control. What they rarely provide is independent oversight: someone whose only job is to look for the gaps, and who has no reason to report that everything is fine.
Possibly not — and Systems Secure will tell you honestly if that's the case. But two things are worth knowing: nobody is well placed to audit their own work, and IT providers are themselves a target for attackers looking for a route into their customers' networks.
In a joint advisory, the UK's National Cyber Security Centre — alongside CISA, the NSA, the FBI and their Australian, Canadian and New Zealand counterparts — warned that managed service providers are granted privileged access to a customer's network, which can create opportunities for attackers.
That isn't hypothetical. In July 2021 attackers exploited a flaw in Kaseya VSA, remote management software used by IT providers, and reached an estimated 800 to 1,500 businesses through around 60 providers. None of those businesses did anything wrong. They were reached through a supplier they trusted.
So the question worth asking isn't "do you handle security?" It's "when did you last check that it's working, and can I see the evidence?"
No. In the last 12 months, 46% of UK small businesses and 42% of micro businesses identified a cyber security breach or attack, according to the Government's Cyber Security Breaches Survey 2025/26.
Most attacks aren't personally chosen — they're automated. Software scans the internet looking for weaknesses and takes whatever it finds. A business with three staff and a website nobody visits still gets probed daily. Phishing remains by far the most common method, experienced by 38% of businesses.
No. Antivirus catches known threats, but most modern attacks don't rely on a recognisable file. Phishing, stolen passwords and misconfigured settings all bypass antivirus entirely.
Proper protection needs several layers: monitoring that spots unusual behaviour, multi-factor authentication, patching, backups you've actually tested, and staff who can recognise a convincing fake email.
No. Most cyber insurance policies require you to prove you took reasonable precautions — multi-factor authentication, staff training, patch management. If you can't demonstrate those, a claim can be reduced or refused entirely.
Insurers increasingly expect standards such as Cyber Essentials before they'll offer cover or renew it. Insurance is worth having, but it pays out after the damage. It doesn't prevent it.
No security company can promise you'll never be attacked, and Systems Secure doesn't make that promise. What it does offer is a three-month refund guarantee: if your business is compromised while you're following the agreed security plan, you get three months' fees back.
The realistic goal is fewer incidents, caught earlier and contained faster.
Every package includes round-the-clock monitoring, automatic updates, protection against viruses and ransomware, blocking of dangerous websites, and staff training. Larger packages add cloud backup, alerts when a login is stolen, regular checks for weak spots, firewall and network reviews, written security policies and a quarterly review.
Micro Business and Business Pro also include a short monthly summary showing what's protected, what changed and what needs attention — written in plain English rather than as a long technical report.
From sole traders up to businesses of around 250 staff. There are three packages: Sole Trader for one person, Micro Business for one to nine people, and Business Pro for ten to 250. Business Pro has a minimum of ten accounts.
No. Systems Secure is based in Copthorne, West Sussex, and works with businesses across the UK. Almost all of the work is done remotely, so your location doesn't affect the service or the price.
On-site visits are available and charged separately: £240 for a visit of up to two hours, £400 for a half day and £760 for a full day.
Yes. Cyber Essentials readiness support is included in the Business Pro package. That means reviewing your current setup against the requirements, telling you what needs to change, and getting you to the point where you can pass.
Worth knowing: Cyber Essentials reflects the day of assessment, not a permanent state. Ongoing patching, access reviews and vulnerability checks are what keep the certificate meaningful between renewals.
James Batt. Systems Secure deliberately caps its managed security client list at 20, so you deal with the same person every time rather than a rotating support desk.
Systems Secure will also never take on a direct competitor of an existing client.
James Batt holds CISSP, C|CISO (Certified Chief Information Security Officer), CEH (Certified Ethical Hacker), NCSP Practitioner and CompTIA Security+.
Behind those: 21 years designing multi-million-dollar IT systems for the oil and gas industry, and 16 years running Systems Secure. The company was named Cybersecurity Company of the Year at the West Sussex Business Awards 2025, and Security Solution Specialists of the Year at the E2 Media Awards 2025.
Because security oversight is only worth paying for if someone is genuinely paying attention. Capping the list at 20 clients means each one gets real scrutiny rather than an automated dashboard nobody reads.
It also means Systems Secure can be honest about capacity rather than selling a service it can't properly deliver.
A conversation, not a pitch. We'll confirm which package fits — and if the honest answer is that you don't need us, we'll say so.

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.