We take a different approach. Every Network Fish managed support client gets a full, layered security stack deployed and managed as part of their contract. Not as an add-on. Not as a separate engagement. Included.
Here is what that looks like.
The security stack we manage for every client
Antivirus (Datto AV)
Managed antivirus deployed across every Windows and macOS device, monitored centrally. We see every device’s protection status in real time. If a definition update fails, if a device drops off, if a threat is detected, we know about it immediately and deal with it. Not installed and forgotten — actively managed.
Advanced threat detection (Datto EDR: Endpoint Detection and Response)
Your antivirus catches threats it already recognises. Datto EDR catches everything else. It watches how every device is behaving around the clock and detects suspicious activity — including new ransomware variants and zero-day attacks — even when no matching signature exists. It works across Windows, macOS, and Linux. If a threat is detected, EDR can contain it automatically, isolating the affected device before the infection spreads.
Web-level threat blocking (DNS Filtering)
Before your team’s browser connects to a malicious website, we block the connection at the network level. Phishing links, malware download sites, fake login pages, and command-and-control domains are stopped before they load — whether your team is in the office, at home, or travelling.
Two-step login, enforced for everyone (MFA: Multi-Factor Authentication)
We enforce multi-factor authentication across every account and every system in your business: Microsoft 365, Google Workspace, VPN, and any other business-critical application. Even if an attacker has a password, they cannot get in without the second verification step. It is included in your platform licences at no extra cost. We make sure it is switched on and enforced.
Device hardening
Out-of-the-box device settings are not secure. We apply a recognised security baseline to every device: disabling unnecessary services, restricting local admin rights, enforcing strong login policies, and controlling removable media. This is done at onboarding and reviewed regularly, and it maps directly to the Cyber Essentials technical controls.
Automatic patch management
Outdated software is the most common entry point for attackers. We deploy operating system and application updates automatically, on a tested schedule, across every device. Critical security patches are fast-tracked. You never need to think about it.
Full-disk encryption (FDE)
Every device in your business should be encrypted so that a lost or stolen laptop cannot be read by anyone who finds it. We enforce BitLocker on Windows devices with recovery key escrow, FileVault on macOS, and verify encryption status across the estate. This is also a GDPR requirement and a Cyber Essentials control.
Vulnerability scanning
We run continuous internal and external vulnerability scans across your network and devices. Think of it as a constant health check: finding unpatched software, misconfigured settings, and exposed ports before an attacker does. Issues are raised as helpdesk tickets and resolved. Every quarter you receive a written report of what was found and what was done about it.
Cyber Essentials readiness
We hold Cyber Essentials certification ourselves. For managed support clients, the gap analysis, remediation guidance, and support through the certification process are included in your contract at no extra charge. The only additional cost is the certifying body fee, currently around £300, paid directly to the certifying body.
Cyber Essentials Plus (an independently audited higher level of certification) and CREST-certified penetration testing are available as additional services for businesses that need independent, audited assurance.
Email defence
We configure anti-phishing policies, safe links, safe attachments, and outbound filtering within your Microsoft 365 or Google Workspace environment, alongside SPF, DKIM, and DMARC sender authentication records for your domain. Email is the most common entry point for attackers. We close that door properly.
Why layers matter
No single security control is sufficient on its own. Antivirus misses new threats. MFA can be bypassed if a device is already compromised. Patching helps, but only covers known vulnerabilities. DNS filtering stops web-based threats but not email-borne ones.
Effective security is a set of overlapping controls, each covering the gaps left by the others. When one control fails or is bypassed, the next one catches what it missed.
That is what we build and manage for every client — a set of controls that work together, all monitored centrally, all included in one monthly fee.
What this is not
We do not sell security as a consulting engagement. We do not produce reports and leave implementation to you. We deploy, configure, monitor, and manage every control described above as a managed service, as part of your ongoing support contract, alongside the helpdesk, on-site support, network management, and backup services that make up the complete package.
One monthly fee. One number to call.
The day-to-day risk of keeping your business secure becomes our job, not yours.
