BITSS guides

Understand IT security in practical terms.

Practical articles for managing directors and IT decision-makers in SMEs, from recovery and firewall maintenance to email security, patch management, awareness and documentation.

Current guides

Specific questions from day-to-day IT operations.

Each guide addresses a defined operational or security issue and points to managed support where that is useful.

GMX · Email and internet access

Help - GMX has blocked my login

GMX says login from your current IP address is temporarily unavailable? Use this practical case to check an IP block, mobile hotspot, router and other causes.

Read guide
Backup

Testing backup restores: what really matters

A backup is dependable only after a restore has been tested. How SMEs verify recovery time, data currency and responsibilities.

Read guide
Backup strategy

3-2-1 backup for SMEs: a practical approach

The 3-2-1 principle works only when backup copies are genuinely separated. A practical guide for SMEs covering off-site copies and restores.

Read guide
Email security

SPF, DKIM and DMARC explained

SPF, DKIM and DMARC reduce sender forgery and improve visibility. What each method does and how the three work together.

Read guide
Firewall

Reviewing firewall rules: why rules become outdated

Firewall rules accumulate over time. How SMEs identify unnecessary access, missing documentation and rules without a valid owner.

Read guide
Patch management

Measure patch status instead of assuming it

Updates are controlled only when their status is measurable. Useful patch metrics for operating systems and applications in SMEs.

Read guide
IT documentation

What belongs in IT documentation

IT documentation must remain useful during an outage. The information SMEs should record about systems, access, networks and responsibilities.

Read guide
Security awareness

Recognising phishing in accounting

Fake invoices and changed bank details target payment processes directly. Controls that reduce phishing risk in accounting teams.

Read guide
Incident preparedness

Ransomware emergency plan: the first steps

A prepared process matters during a ransomware incident. The first actions SMEs should define before systems or accounts are compromised.

Read guide
Security awareness

Security awareness: planning effective exercises

Awareness improves through practical exercises, not annual slides alone. How SMEs plan short training, phishing simulations and feedback.

Read guide
Email security

Reducing email spoofing and sender forgery

Forged senders can look convincing. How SMEs combine mail authentication with organisational controls against spoofing.

Read guide
Context

Guides do not replace an assessment of your environment.

General recommendations provide direction. Whether they fit your infrastructure depends on systems, responsibilities and recovery objectives.

No-obligation initial contact

Clarify the situation first. Then decide.

If a topic from the guides is relevant to your business, a short conversation can help assess the current position.

CallBook