Roadmap Cybersecurity
How to Build a Cybersecurity Roadmap: A Practical Guide for UK Businesses
A six-step framework for building a cybersecurity programme from the ground up. Covers baseline assessment, control prioritisation, budget sequencing, and how to measure progress.
20 min read Read more
Guide Cybersecurity
How to Write an Incident Response Plan: A Practical Guide for UK Businesses
Six-phase IR lifecycle, team roles, ICO 72-hour notification, NIS2 obligations, scenario playbooks for ransomware, BEC, credential theft and data breach, plus tabletop testing guidance.
17 min read Read more
COMPLIANCEISO 27001
ISO 27001: Certification and Implementation Guide
Cyvra guides businesses through ISO 27001 certification: the six steps, realistic timelines, costs, and what a full implementation engagement covers.
9 min read Read more
COMPLIANCENIS2
NIS2 Cybersecurity Readiness: The 10 Security Controls Your Organisation Needs
NIS2 requires 10 specific cybersecurity controls. Covers what they are, how to implement them, and incident notification before a breach forces your hand.
7 min read Read more
COMPLIANCEPCI DSS
PCI DSS Compliance Guide for UK Businesses (2025)
Understand PCI DSS v4.0 requirements for UK merchants. Learn which SAQ applies to your business, the 12 core requirements, and how to reduce your compliance scope.
12 min read Read more
COMPLIANCEEU
Cyber Resilience Act: A Compliance Guide for Manufacturers and Distributors
The EU Cyber Resilience Act requires security-by-design for connected products. Vulnerability reporting from September 2026; full compliance December 2027.
11 min read Read more
SECURITYARCHITECTURE
Zero Trust Architecture: The Identity-First Security Model for Remote and Hybrid Organisations
Zero Trust replaces perimeter security with identity verification on every request. Five pillars, Conditional Access, NIS2 and ISO 27001 alignment.
11 min read Read more
SECURITYMICROSOFT 365
Microsoft 365 Security Hardening: The Controls Most Organisations Miss
Most Microsoft 365 tenants run default settings built for adoption, not security. Credential attacks and phishing campaigns succeed because basic hardening controls are never...
11 min read Read more
COMPLIANCEDORA
How to Conduct a DORA Gap Analysis: A Step-by-Step Framework for FinTechs
DORA has applied since January 2025. Step-by-step gap analysis framework for FinTechs covering all five pillars and a prioritised remediation roadmap.
9 min read Read more
SECURITYIDENTITY
Passkeys and Passwordless: The Practical Guide for IT and Security Leaders
Passkeys replace passwords with device-bound cryptographic keys that cannot be phished. This guide covers how FIDO2 works, what enterprise rollout looks like, and where legacy...
14 min read Read more
INCIDENT RESPONSE
Ransomware: What to Do Before, During and After an Attack
Ransomware appeared in 88% of SMB breaches. Covers what it does, key defences, what to do in the first 48 hours, and how to recover without paying.
8 min read Read more
INCIDENT RESPONSE
Ransomware Recovery: How to Restore Your Systems Without Reinfecting Them
Ransomware hit your organisation? Cyvra responds within hours. Six recovery steps: backup validation, eradication, GDPR notification, and hardening.
9 min read Read more
COMPLIANCENIST CSF
Implementing Cybersecurity Controls for NIST CSF 2.0 and NIS2
NIST CSF 2.0 and NIS2 share the same underlying controls. Implement them once to cover both frameworks and avoid duplicated security work.
10 min read Read more
IT MANAGEMENT
How Much Should Your Business Spend on IT? A Budget Framework for SMEs
Most SMEs spend 1-2% of revenue on IT. Benchmarks suggest 4-7% for professional services. Five categories, hardware cycles, and how to build an IT budget.
8 min read Read more
IT MANAGEMENT
How to Build an IT Service Desk Without Hiring a Full Team
IT service desk essentials for SMEs: support tiers, ticketing, SLA targets and when a managed provider makes more sense than in-house IT.
7 min read Read more
AIMICROSOFT 365
Microsoft 365 Copilot: how to implement it safely and what goes wrong when you don't
Microsoft 365 Copilot amplifies data risks before it improves productivity. Covers oversharing, DLP gaps, and what to configure before you switch it on.
9 min read Read more

Not sure where your security programme stands?

We'll assess your current controls, identify gaps, and help you build a roadmap that matches your risk profile and budget.

Book a cybersecurity assessment