Business IT
Data Protection & Cybersecurity Services
Practical cyber security and data protection for small and medium businesses, from a Leeds IT company that is independently assessed for Cyber Essentials Plus every year.
Protecting company data is a legal duty under UK GDPR and the Data Protection Act, and it is what your clients assume you already do. For most small businesses the risk is not a sophisticated attack. It is a reused password, a laptop left on a train, a former employee who still has access, or a backup nobody has checked.
We deal with those risks in six areas, each explained in more detail below. The approach follows the same five controls we are assessed against for Cyber Essentials Plus: firewalls, secure configuration, user access control, malware protection and keeping software up to date.
Six areas we cover

Protecting company data
Knowing what personal data you hold, why, for how long, and deleting it securely when it is no longer needed.

User access control
Staff can reach the data their role needs, and nothing else, with regular reviews of who has access.

Hardware security
Computers and phones set up securely from day one: encryption, two-factor sign-in, strong PINs and asset tracking.

Data classification
Public, internal, confidential and restricted: each kind of data labelled and protected to match.

Network configuration
Separate guest and staff Wi-Fi, unused ports locked, firmware kept current, and modern Wi-Fi security.

Company procedures
Written procedures for starters, leavers and access requests that create an audit trail without slowing the day down.

Cyber Essentials, and why we hold the Plus level
Cyber Essentials is the UK government-backed scheme that sets out five basic security controls. The standard level is a self-assessment. At the Plus level, an independent assessor tests the systems directly, including vulnerability scans and checks on how malicious email and downloads are handled.
QLine IT holds Cyber Essentials Plus, assessed by IASME, and renews it every year. We apply the same controls to the systems we look after, which helps when your insurer, a larger customer or a tender asks how your IT is secured. Read about our Cyber Essentials Plus accreditation.
GDPR in practice
UK GDPR says personal data should be kept only for as long as it is needed for its purpose (Article 5(1)(e)). In practice that means knowing what you hold, reviewing it, and securely deleting or anonymising what you no longer need. Financial records must be kept for set periods for tax, and health and social care records have their own rules, so the answer is different for every business.
We help you work out what you hold and where, set retention periods that make sense, and put the technical safeguards in place: encryption, access control, two-factor authentication and tested backups. See also business IT security and GDPR.
Free cyber security training for staff
Most breaches start with a person, not a computer. We work with West Yorkshire Police's Cyber Protect team to bring free cyber security training to businesses across Leeds and the wider region. Find out about the training.
Questions we're asked
Do we need Cyber Essentials?
It is required for some government contracts, and insurers and larger customers increasingly ask for it. Even when it is not required, its five controls are a sensible baseline for any business. We can align your systems with them.
Can you help us respond to a data breach?
Yes. We help contain the problem, work out what data was affected, and gather the information you need to decide whether to report it to the ICO, which must be done within 72 hours of becoming aware of a reportable breach.
Is cyber security included in your IT support?
Security patching, malware protection, backup and GDPR support are included in our full IT support contract. Larger pieces of work, such as a full data audit, are quoted separately.
Find out where your business is exposed
Tell us how your business works and how many people use computers. We will tell you plainly what needs attention.
Business IT
Related services
Protecting Company Data
What UK GDPR and the Data Protection Act 2018 require of a small business, what the fines are, and the practical steps that protect client d
User Access Control
Role-based access control for small businesses: staff see only the data their job needs. Meets UK GDPR and Cyber Essentials access control r
Business IT Security and GDPR
IT security and GDPR for UK businesses: encryption, malware protection, passwords and two-factor sign-in, from a Cyber Essentials Plus compa
