National cyber advice is written for a business Shropshire does not have many of
Most published guidance assumes an office full of laptops and somebody whose job is IT. That describes very few businesses in this county, and the mismatch puts people off doing anything at all.
Read almost any piece of national cyber security guidance and picture the business it is written for. An office. Thirty or forty staff on company laptops. A managed service provider on a contract. Somebody internally who owns IT as an actual job. That business exists in Shropshire, but it is not the typical one, and guidance written for it reads to everyone else as either irrelevant or unaffordable.
We assess and test from Albrighton, which means most of the organisations we see are within an hour's drive. The pattern is consistent enough to be worth writing down, because the gap between the advice and the reality is doing real damage: it convinces capable people that security is something for bigger businesses, and so they do nothing rather than the three things that would actually help.
What the county actually looks like
Three broad groups, each badly served by generic advice.
Agricultural businesses. A working farm now runs accounting software, a bank account that moves substantial sums seasonally, telemetry on machinery, and increasingly a diversified side of the business with its own card payments: holiday lets, a farm shop, events. The IT is a laptop in a kitchen and a phone in a pocket. Nobody in that picture is going to read a twelve-page policy template, and the advice to "segment your network" is meaningless when there is one router.
Workshops and manufacturers. Telford and the surrounding estates are full of engineering, fabrication and electronics firms, a lot of them supplying defence either directly or through a prime. These businesses have machines older than their office PCs, often running software that cannot be patched because the machine's manufacturer will not support it. Generic advice says patch everything. The actual answer is to isolate the thing you cannot patch, which is a different conversation entirely.
Market-town professional firms. Solicitors, accountants, surveyors and consultancies in Shrewsbury, Ludlow, Oswestry and Bridgnorth. These are the closest to the model the guidance assumes, but they are usually a tenth of the size, with no internal IT and a provider who visits when something breaks.
What this changes, and what it does not
The controls do not change. Multi-factor authentication, patching, controlling who is an administrator, and knowing what you have are what matter regardless of whether you are in an office or a barn. Attackers are not selecting for sector, they are scanning for exposure, and a farm's remote access is as reachable from the internet as a bank's.
What changes is the implementation and the proportionality. A business with six people does not need a security committee, a risk register with twelve owners, or a policy library. It needs MFA turned on, a known list of what is connected, and somebody who will answer the phone when something looks wrong. Advice that cannot distinguish between those two situations is advice that gets ignored.
The other thing that changes is who is asking. Very few Shropshire businesses are under a regulator telling them to do this. They are under a customer. A prime contractor sends a supplier assurance questionnaire. An insurer asks about MFA at renewal. A council adds a certification requirement to a tender. That is the real driver in this county, and it is why the conversation usually starts with a document somebody has been sent rather than with a breach.
The thing specific to here, right now
If you supply the Ministry of Defence, directly or through a prime, the Defence Cyber Certification picture matters and the timing is tight. The MoD has asked industry partners to hold Level 0 by 31 December 2026, which is twelve weeks away. There are a lot of suppliers on Telford's industrial estates for whom that is relevant and who have not started, partly because the message has reached the primes and not always the second and third tier beneath them.
Worth knowing: Level 0 is three controls, not a governance programme, and Level 1 does not require Cyber Essentials Plus whatever you may have been told. We have written that up separately in DCC Level 1 and Cyber Essentials Plus, because getting it wrong costs weeks and money for a certification the contract does not ask for.
What we would tell a Shropshire business to do first
- Turn on multi-factor authentication for email and anything with your money in it. Free, and it removes the attack that actually happens.
- Write down what is connected. Not a formal asset register. A list. You cannot protect what nobody has counted, and most businesses are surprised by their own list.
- Find the thing that cannot be patched, and put it somewhere it cannot reach the internet or your office network. This is usually a machine controller or a camera system.
- Check what is visible from outside. Remote access left open from lockdown is the most common finding we have, across every sector.
- Then certify if somebody is asking, with Cyber Essentials, which is proportionate to a business of almost any size and answers most customer questionnaires outright.
That is a day of work for most organisations and it is most of the available benefit. Everything after it is refinement, and refinement is not where anybody is being compromised.
More on what we see locally on the Shropshire page, and if you would rather just ask, the conversation is free.
Common questions
We are a small business in Shropshire. Is Cyber Essentials proportionate?
Our farm has one laptop and a phone. Does any of this apply?
We have a machine that cannot be updated. Does that fail Cyber Essentials?
Do we need someone local?
Who is actually asking Shropshire businesses for certification?
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.