cyber security as a service

Dragon launches Cybersecurity-as-a-Service: The smart way to stay protected

Introducing Cybersecurity-as-a-Service from Dragon.

A successful cyberattack can be devastating for any SME business, disrupting services, damaging reputation and impacting the bottom line. For some companies, they can even prove fatal.

With attacks on the rise, it has long been a case of ‘when’ not ‘if’ an attack will happen and the latest government data shows just how widespread the issue now is.

According to the latest Cyber Security Breaches Survey, 43% of UK businesses experienced a cyber breach or attack in the past 12 months, seeing an estimated 612,000 organisations impacted nationwide. The range of attacks varies widely, from business email compromise to denial of service and ransomware attack, with phishing still the top ‘way in’ for criminals.

 

Building cyber resilience as an SME

For SMEs, understanding the evolving cyber threat and taking proactive action to reduce the risk and stay secure is an ongoing challenge. Whether that’s staying on top of updates, monitoring systems, managing staff awareness and training, or identifying and reacting to any issues.

There is also now the added pressure of supply‑chain security risk. More and more organisations, especially within the public sector, are tightening their requirements and expecting suppliers to prove they have strong cyber hygiene in place. This means staying on top of cybersecurity may not just be critical for keeping the business secure but could also be crucial for client retention, winning new business and long term growth.

Which is where Cyber Essentials comes in, a scheme that represents a minimum security baseline that businesses should aspire to and increasingly one they will be expected to demonstrate.

 

What is Cyber Essentials?

Cyber Essentials is a UK government‑backed scheme designed to help organisations prepare and defend against the most common types of cyber threats. It sets out a clear foundation of security that every business should have in place, regardless of size or sector.

Cyber Essentials focuses on five key areas:

  • Secure configuration – Making sure devices and software are set up safely, not left on risky default settings.
  • User access control – Ensuring only the right people have access to systems and data, with adequate level of permissions.
  • Malware protection – Using tools that detect and block viruses, ransomware and other malicious software.
  • Security update management – Keeping devices and applications up to date so attackers can’t exploit known vulnerabilities.
  • Firewalls – Creating a protective barrier between networks and the internet to block unwanted or dangerous traffic.

The benefits of Cyber Essentials are broad. Aside from giving organisations a stronger baseline of protection by ensuring key security controls are in place and working effectively, certification can also help build customer trust.

Many insurers view Cyber Essentials as a positive risk indicator too. While for businesses working with the public sector or larger enterprises, it can be a gateway to eligibility for contracts that require certified suppliers.

For organisations with a turnover under £20m, achieving full certification unlocks free cyber liability insurance, adding an extra layer of reassurance at no additional cost.

According to the National Cyber Security Centre (NCSC), implementing the five Cyber Essentials controls would prevent around 80% of common cyberattacks. But achieving certification and staying compliant can be harder than it looks. Settings may drift, staff may change, and new devices may appear.

Here at Dragon, we have built a service to solve exactly that problem, making Cyber Essentials implementation and ongoing compliance, simple and hassle-free.

 

Introducing Cybersecurity‑as‑a‑Service from Dragon

Cybersecurity‑as‑a‑Service from Dragon is designed to remove barriers between organisations and NCSC Cyber Essentials accreditation.

Instead of juggling multiple moving parts, such as suppliers, audits, tools and training platforms, we wrap everything within one fixed monthly subscription, with no hidden extras.

This is cybersecurity delivered as a predictable, fully managed service, giving complete peace of mind.

 

What’s included?

  • Gap Identification & Remediation – We will find the issues, prioritise risks, and fix them, so you’re certifiable from day one
  • Continuous Drift Monitoring – Cybersecurity threats are not static. We will provide continuous surveillance to ensure you stays secure and compliant 365 days a year
  • Ongoing Cyber Awareness Training – Our role‑based training helps keep staff alert to phishing, social engineering and other evolving threats.
  • IASME Accreditation Fees – We will absorb all associated third‑party certification costs
  • Free Cyber Liability Insurance – Included for all eligible organisations achieving full certification.

 

How does Cybersecurity‑as‑a‑Service work?

Dragon’s approach is designed to be straightforward:

  1. Onboard – Kick‑off call and environment discovery
  2. Assess – Gap analysis against all five Cyber Essentials controls
  3. Remediate – Fix issues and submit for IASME certification
  4. Maintain – Ongoing monitoring, training and renewal
  5. Report – Quarterly business and compliance reports

 

Microsoft 365 with Inforcer

Cyber Essentials is just one element of the service. In addition, Dragon utilises ‘Inforcer’ to build further protections into small business IT systems.

Most organisations rely heavily on Microsoft 365, but out‑of‑the‑box settings aren’t designed for strong security. Dragon uses Inforcer, a managed tenant‑hardening platform, to lock down Microsoft 365 securely and consistently.

By using Inforcer – basically a system that tightens settings, watches for changes and makes sure nothing slips through the cracks – Dragon is able to lock down Microsoft 365 in a secure and consistent way.

This approach ensures that users are not relying on the platform’s default configurations, which tend to prioritise flexibility rather than protection.

Inforcer provides a safer baseline, reduces the need for manual configuration, issues alerts when important settings change, performs nightly or on‑demand backups, and produces clear, audit‑friendly reports.

In short, security settings are continuously checked, improved, backed up, and monitored.

 

Keeping on top of Microsoft security with Inforcer

Microsoft released over 300 conditional access polices last year. This alone would require significant, dedicated resources and time for a business to keep on top of.

Inforcer eliminates this requirement, allowing for the security policy changes to be processed in a timely manner, with awareness, planning and implementation carried out within a much quicker time frame.

Many organisations do not have the resource to fulfil this need, so policies can be left and in turn, systems can become less secure and vulnerable to attack.

Inforcer is also aligned with CAS and NIST2 security frameworks, so security is implemented to meet these standards.

As a tool, Inforcer fits into a broader, ongoing journey – not just supporting the picture today but evolving for where it is going tomorrow, including the growth in AI. It can support AI readiness and adoption by using its controls for gap analysis, shadow‑AI reporting, data compliance and governance, helping organisations prepare for the wider use of AI, safely and responsibly.

 

Support with compliance and evidencing

Cyber security requirements increasingly demand proof, not just a tick‑box declaration. As part of its cyber‑security‑as‑a‑service offering, Dragon can provide clear evidence of the controls in place whenever needed.

The team can also supply information‑security policies aligned with Cyber Essentials for organisations that require them.

 

Why choose Dragon’s Cybersecurity-as-a-Service?

Cyberattacks are a major threat to businesses and Cyber Essentials is an effective, well regarded, first step to building more secure operations. While the scheme provides a strong foundation, maintaining it requires ongoing time and resource.

Dragon’s Cybersecurity‑as‑a‑Service provides organisations with a smarter, simpler way to stay protected, bringing complete peace of mind. The benefits include:

  • Fully managed Cyber Essentials
  • Continuous compliance
  • Hardened Microsoft 365 security
  • Predictable costs
  • Stronger trust with customers and partners

 

Find out more about Cybersecurity‑as‑a‑Service

Please reach out to us on 0330 363 0055 or email info@dragon-is.com.