FAQ
Frequently Asked Questions
Clear answers about our cybersecurity assessments, Microsoft 365 security, managed services and how we work with SMEs.
How does remote cybersecurity work?
Most of our cybersecurity services can be delivered securely and remotely. Before work begins, we agree the scope, systems involved, access requirements and any operational restrictions with you. We do not access or test systems without appropriate permission.
Do you support businesses outside the UK?
Yes. Jamola Cybersec Services Limited is a remote-first cybersecurity consultancy and can support organisations in the UK and internationally. Meetings and technical activities can be arranged around mutually suitable time zones.
What size businesses do you work with?
We primarily support small and medium-sized businesses that need professional cybersecurity expertise without building a large internal security team. We can work directly with business owners, management, internal IT teams or your existing managed service provider.
What industries do you work with?
We work with organisations across sectors including professional services, technology, legal, healthcare, manufacturing, construction, retail, education, financial services and charities. Each engagement is scoped around the organisation's systems, requirements and risks.
What happens during a cybersecurity assessment?
We begin by understanding your organisation, technology environment and security concerns. Once the scope is agreed, we review the relevant systems, configurations and security controls. Depending on the engagement, this may include vulnerabilities, identity controls, Microsoft 365, cloud services and other security weaknesses.
Will a security assessment disrupt our business?
We aim to minimise disruption to normal business operations. Systems in scope, testing activities and any sensitive production environments are discussed before work begins. Where an activity could affect normal operations, we discuss it with you in advance.
Do you need administrator access to our systems?
Not always. The level of access required depends on the service. We request only the access reasonably necessary for the agreed work and, where appropriate, temporary or dedicated accounts can be used and removed after the engagement.
Do you test systems without permission?
No. Security testing is carried out only within an agreed scope and with appropriate authorisation. The systems, accounts and services included in the assessment are established before technical testing begins.
What happens after the security audit?
Depending on the engagement, you may receive an executive summary, detailed security findings, risk and severity ratings, technical evidence where appropriate, prioritised recommendations, remediation guidance and a practical improvement roadmap. We explain what was found, why it matters and what should be addressed first.
Can you help us fix the issues you find?
Yes. Your existing IT team or MSP can use our findings, or we can assist with remediation and security improvements where appropriate. Our objective is not simply to identify weaknesses but to help reduce the underlying business risk.
How long does a cybersecurity assessment take?
Timescales depend on the size and complexity of your environment and the agreed scope. We discuss expected delivery arrangements before work begins and will speak with you if anything arises that could materially affect the agreed scope or timescale.
Can you help secure Microsoft 365?
Yes. We can assess and improve Microsoft 365 security, including Microsoft Entra ID, multi-factor authentication, Conditional Access, privileged accounts and relevant Microsoft Defender security controls. The aim is to reduce risks such as account compromise, phishing, unauthorised access and insecure configuration.
We already use MFA. Do we still need a Microsoft 365 review?
Potentially. MFA is an important security control, but it is only one component of Microsoft 365 security. Conditional Access, privileged accounts, identity configuration, monitoring and other settings can all affect your overall security posture.
Do you offer ongoing cybersecurity support?
Yes. We offer ongoing security services including managed security monitoring, Microsoft 365 monitoring and virtual CISO support. The appropriate level of support depends on your organisation, systems, risks and requirements.
What is a virtual CISO?
A virtual Chief Information Security Officer, or vCISO, provides senior cybersecurity guidance on an outsourced basis. Support can include security strategy, risk management, governance, policy development and security improvement planning without the cost of employing a full-time CISO.
Do you provide 24/7 security monitoring?
24/7 threat detection and alert investigation is available through our managed security offering. The exact monitoring coverage, response arrangements and responsibilities are defined as part of the selected service.
Can you help if we suspect a cyber incident?
We may be able to assist with suspected cybersecurity incidents depending on the nature of the incident, support required and availability. Contact us with a brief description of the situation so appropriate next steps can be discussed.
Do you sign NDAs?
Yes. We are happy to review and sign an appropriate Non-Disclosure Agreement before an engagement where required. If your organisation has specific supplier security, privacy or data-handling requirements, these can also be discussed before work begins.
How do you handle confidential information?
We limit access to information required to perform the agreed engagement and use appropriate methods when handling client information. Any specific security, privacy or data-handling requirements can be agreed during the scoping process.
Can you work with our existing IT company or MSP?
Yes. We can work collaboratively with your existing IT provider, MSP or internal IT department. We can provide technical findings and remediation guidance to your IT team while helping management understand the associated risks and priorities.
Are you replacing our IT provider?
Not necessarily. Traditional IT support and specialist cybersecurity services perform different but complementary roles. We can provide independent cybersecurity expertise and security oversight while your existing provider continues managing your normal IT environment.
Do we need technical knowledge to work with you?
No. We explain cybersecurity risks in straightforward business language while providing the technical detail required by IT professionals. You do not need to know which security product or technical control you require before contacting us.
How much do your cybersecurity services cost?
Pricing depends on the service, environment and agreed scope. Where standard starting prices are available, we aim to publish them clearly. Custom engagements are scoped and priced before work begins.
Are there any hidden costs?
We aim to agree the scope and pricing before work begins. If circumstances require additional work outside the original scope, this will be discussed with you before proceeding.
What if we're not sure which service we need?
That's fine. Tell us about your organisation, IT environment and the security concerns you have. We can help identify the areas that deserve attention and recommend an appropriate starting point.
How do we get started?
Start with a free 30-minute consultation. We'll discuss your business, current security concerns and what you want to achieve. The initial conversation is an opportunity to understand your requirements and determine an appropriate next step.