# Woodruff Training > Cyber and AI training for small businesses, plus tabletop exercises and Cyber Essentials support. Onsite from Portsmouth to Brighton, live online UK-wide. Everything below is the complete public content of https://woodrufftraining.com, generated at build time. Last built 2026-09-15. ## About the business Woodruff Training is based in Bognor Regis, West Sussex, and works onsite across Sussex and south-east Hampshire and remotely UK-wide. Your People Are Your Best Firewall. ## Areas covered We are based in Bognor Regis and deliver onsite across Sussex and south-east Hampshire, or live online anywhere in the UK. Travel is included in the price across the core area below. Further afield it is agreed in advance and shown separately, never added to an invoice after the fact. ### Bognor Regis, West Sussex This is where we are based. Cyber security and AI training in Bognor Regis. We are based in the town, so an onsite session needs no travel cost and little arranging. This is home. Woodruff Training is based in Bognor Regis, which means an onsite session here is the easy case: no travel charge, no half-day lost to driving, and a good chance we can work around your opening hours rather than the other way round. The business mix here is seaside. Hospitality, retail, holiday and leisure businesses, care providers, trades, and a long list of small independents where the owner is also the IT department, the finance department and whoever answers the phone. Training that assumes an internal IT team is no use to any of them, so ours does not. Who we work with in Bognor Regis: Hotels, guest houses, cafés and other hospitality businesses; Shops and independents in the town centre and along the seafront; Holiday, leisure and seasonal employers; Trades, contractors and small offices across the Arun district; Care providers, schools and community groups. What tends to matter here: Seasonal hiring is the thing that makes Bognor different. A business that takes people on for the summer is onboarding a new group every year, often in a hurry, often young, and often straight onto a shared till or booking system. Whatever you taught the team last spring walked out of the door in September. That is a large part of why the learning portal exists. A new starter works through the training on their first shift, in their own time, and you get the completion record without booking anything or standing over anybody. The other one is the belief that a small seaside business is too small to be worth attacking. Most attacks are not aimed at anyone in particular. They go to every address a criminal has, and a card machine, a booking system and a business bank account are worth the same to them here as they are in London. Also covered from Bognor Regis: Felpham, Middleton-on-Sea, Aldwick, Pagham, North Bersted, Barnham, Yapton, Elmer. **You are based here. Does that make it cheaper?** The price is the same across the whole core area, because onsite travel is included rather than added on. What being local changes is how easily we can fit around you. A session timed around your opening hours is much simpler to arrange for a business ten minutes down the road. **We are a two person business. Is this worth it for us?** Sometimes not, and we will tell you so on the call. If it is just the two of you, the free resources page and an hour of your own time may cover most of what you need. Where it starts to be worth paying for is when you have staff handling money, customer details or bookings, and no realistic way to train them yourself. ### Chichester, West Sussex About 20 minutes from our base in Bognor Regis. Onsite cyber security and AI training for Chichester businesses. Twenty minutes from our Bognor Regis base, with travel included. Chichester runs on professional services. Solicitors, accountants, surveyors, architects, agencies and consultancies, mostly small firms holding a great deal of other people’s money and other people’s personal data. That combination is exactly what attackers look for, which is why firms here get asked about their security by clients and insurers more often than most small businesses do. We train those teams in plain English, onsite at your office or live online. No jargon, no scare stories, and nothing that assumes anybody in the room works in IT. Who we work with in Chichester: Professional practices: solicitors, accountants, surveyors and architects; Agencies, consultancies and small offices in and around the city centre; Hospitality, retail and tourism businesses, including seasonal teams; Farms, estates and rural businesses in the surrounding villages; Schools, colleges, charities and community groups across the district. What tends to matter here: Two things come up again and again with Chichester firms. The first is payment fraud. A convincing email arrives changing the bank details on an invoice or a completion, it looks exactly like the account it claims to come from, and the money is gone before anybody thinks to check. Software will not reliably stop that one. A verification habit will, and it takes about a minute to teach. The second is Cyber Essentials. Clients, tender documents and insurers increasingly want to see it. Most firms here are closer to passing than they expect and stuck on the same two or three points, which is a fortnight of work rather than a project. Also covered from Chichester: Bosham, Fishbourne, Lavant, Tangmere, Selsey, The Witterings, Midhurst, Petworth. **Do you charge extra to come to Chichester?** No. Chichester is inside the core area, so onsite travel is included in the price. There is no mileage, no travel time and no minimum booking beyond what is already shown on the pricing section. **Some of our staff work from home. Can you cover everyone?** Yes. A live online session reaches everybody wherever they are, and plenty of clients mix the two: an onsite kick-off in the office, then online refreshers for the whole team. Anyone who misses a session can pick the same material up on the learning portal. ### Littlehampton, West Sussex About 15 minutes along the coast from Bognor Regis. Cyber security and AI training for Littlehampton businesses. Fifteen minutes from our Bognor Regis base, onsite or live online. Littlehampton is two economies sharing a postcode. There is the seafront and the harbour, which is retail, hospitality and a summer that pays for the winter. Then there are the trade counters, workshops and light industrial units set back from it, quietly supplying builders, installers and larger firms up and down the coast. The second group is the one that surprises people. A firm of eight with a workshop, a van fleet and one laptop that runs the invoicing is carrying more risk than it realises, and it almost never has anybody whose job is to think about that. Who we work with in Littlehampton: Trade suppliers, workshops and light industrial businesses; Builders, installers and contractors with staff out on jobs; Seafront retail, hospitality and holiday businesses; Marine and harbour trades along the Arun; Small offices, care providers and community groups across the town. What tends to matter here: For the trade and supply businesses, the risk that actually costs money is invoice fraud. You deal with a long list of suppliers and subcontractors, payment details genuinely do change from time to time, and an email saying so does not look strange. That is precisely why it works. The fix is a rule about verifying changes on a number you already had, which costs nothing and has to be taught once. The other one is concentration. In a lot of businesses here, everything runs through one machine and one person: the quotes, the invoicing, the supplier logins, the passwords. If that laptop is encrypted by ransomware on a Friday, or the person holding it is in hospital, the business stops. That is a resilience problem as much as a security one, and it is usually fixed with a tested backup and making sure more than one person can get into the accounts that matter. Larger customers are also starting to ask their suppliers for Cyber Essentials. If you sell into a contractor, a council or a national brand, that request is coming whether or not you were expecting it. Also covered from Littlehampton: Rustington, East Preston, Angmering, Wick, Climping, Poling, Ford, Lyminster. **Half our staff are out on jobs all day. How does training work?** Two ways, and most businesses like yours use both. The live session runs early or at a quiet point in the day for whoever can be in one place, and everyone else works through the same material on the learning portal from a phone, in a van or at home. Completion is recorded either way, so you can see who has actually done it. **Is there a travel charge to Littlehampton?** No. Littlehampton is fifteen minutes from us and well inside the core area, so onsite travel is included in the published price. ### Arundel, West Sussex About 20 minutes inland from Bognor Regis. Cyber security and AI training for Arundel businesses. Twenty minutes from our Bognor Regis base, and sized for very small teams. Arundel is a small town that takes a lot of visitors, which shapes almost every business in it. Independent shops, galleries, antiques, places to eat and stay, tour operators and the events that fill the summer. Most of them are tiny, most are seasonal to some degree, and almost all of them take money online before the customer ever arrives. Alongside that sits a quieter group: consultants, designers, therapists and small professional practices working from an office over a shop or a room at home. Different work, same problem, which is that there is nobody to ask when something looks wrong. Who we work with in Arundel: Independent shops, galleries and antiques businesses; Pubs, restaurants, cafés and places to stay; Tourism, events and visitor attractions; Consultants, designers and small professional practices; Charities, heritage organisations and community groups. What tends to matter here: If you take bookings and deposits, your customers are the target as much as you are. A criminal who gets into a booking inbox does not need to break anything. They wait, read, and then reply to a real enquiry with real details and their own bank account. The customer pays, and the first you hear of it is somebody arriving expecting a room. Multi-factor authentication on the inbox stops most of that, and it takes about ten minutes to switch on. The second thing is card and customer data. A very small business handling payments and personal details has the same legal duties as a large one, and often a much less tidy setup: a spreadsheet of guests, a shared email password, a card terminal nobody has looked at since it arrived. None of that is difficult to put right once somebody has walked you through it. For the charities and heritage organisations, add donor data and volunteers. Volunteers are wonderful and they turn over constantly, which makes joining and leaving properly the single most useful thing to get right. Also covered from Arundel: Amberley, Slindon, Walberton, Fontwell, Burpham, Warningcamp, Storrington, Pulborough. **We are seasonal. When is the best time to do this?** The quiet months, without question. Training in February is calm, cheap in attention and means the habits are in place before the season starts. It also gives you time to sort the dull but important things, like getting multi-factor authentication onto the booking inbox, while nobody is waiting at the counter. **There are only four of us. Is a whole session overkill?** A full workshop probably is, and we will say so. For a team that size the sensible starting point is usually the learning portal, which you can buy for four people just as easily as forty, or a single session shared with another local business. Ask and we will tell you honestly which of those fits, or whether the free resources will do the job on their own. ### Emsworth, Hampshire About 30 minutes from Bognor Regis, over the Hampshire border. Cyber security and AI training for Emsworth businesses. We cover the Hampshire side of Chichester Harbour at the same price. Emsworth is in Hampshire, not West Sussex. That is worth saying plainly, because most of this site says West Sussex and it would be easy to read that as somebody else’s patch. It is not. We are about half an hour away, Emsworth is inside the core area, and the travel is included exactly as it is in Chichester. The businesses here are mostly small and independently run. Shops, studios, food and drink, marine and waterfront trades, and professional people working from an office above the street or a room at home. Almost none of them have an IT department, which is exactly why the training is written the way it is. Who we work with in Emsworth: Independent shops, studios and food and drink businesses; Marine, boatyard and waterfront trades around the harbour; Small professional practices and consultancies; Holiday lets, moorings and visitor businesses; Schools, charities and community groups. What tends to matter here: Owner-run businesses share a particular weak point: everything depends on one person, and that person is busy. The passwords, the bank access, the supplier contacts and the knowledge of how any of it actually works all sit in the same head. That is a security problem and a resilience problem at once, and it is usually solved with an afternoon of work rather than a product. For anyone taking deposits, whether that is a booking, a berth or a commission, invoice and payment fraud is the thing worth spending real time on. A criminal only needs your customers to believe one email about changed bank details, and the reputational damage lands on you even though the fraud was aimed at them. Also covered from Emsworth: Westbourne, Southbourne, Prinsted, Chidham, Nutbourne, Thorney Island, Hermitage, Warblington. **You say West Sussex everywhere. Do you actually come to Hampshire?** Yes. Emsworth, Havant, Hayling Island and the surrounding villages are all inside the core area, at the same price and with travel included. The West Sussex wording describes where we are based, not a boundary we stop at. **Is online just as good if we cannot spare the time for a visit?** For a small team, often yes. The live online sessions run the same content for the same length, and nobody loses half a morning to travel. Onsite earns its place when you want the whole team in one room, or when the session is a tabletop disaster exercise and the conversation around the table is most of the value. ### Havant, Hampshire About 35 minutes from Bognor Regis, over the Hampshire border. Cyber security and AI training for Havant and Hayling Island businesses, with Cyber Essentials support for suppliers. Havant is where the character of the coast changes. Alongside the town centre and Hayling Island there are business parks, industrial units, workshops and distribution operations, a good number of which supply into much larger organisations around the Solent. That supply relationship is the thing that makes Havant different from the villages either side of it. When your customer is a large manufacturer, a public body or a prime contractor, their security requirements arrive on your desk whether or not you have anybody to deal with them. Who we work with in Havant and Hayling Island: Manufacturing, engineering and light industrial businesses; Distribution, logistics and trade suppliers; Firms supplying into larger marine, defence and industrial customers; Retail, hospitality and holiday businesses on Hayling Island; Care providers, schools and charities across the borough. What tends to matter here: Cyber Essentials comes up more often in Havant than almost anywhere else we work, and it is usually not the business owner who decided to care about it. It arrives in a contract renewal or a supplier questionnaire from a customer who has been told to check their own supply chain. Public sector and defence-related contracts in particular push those requirements down to the suppliers, and "we are only small" is not an answer that gets accepted. The good news is that the five controls are basic on purpose, and most firms already do three of them without knowing it. The work is usually scope, which is deciding exactly which devices and cloud services are in, and then two or three specific fixes. It is a fortnight, not a project. The other thing worth naming is the mix of office and workshop. Training written for an office assumes everybody has a desk, an email address and a laptop. That is not true of a workshop or a warehouse, where staff may share a terminal and rarely read email. Sessions here get built around that rather than pretending it is not the case. Also covered from Havant: Hayling Island, Bedhampton, Denvilles, Langstone, Leigh Park, Waterlooville, Purbrook, Rowlands Castle. **A customer has asked us for Cyber Essentials. Where do we start?** With the free readiness checklist on this site, which covers scope and all five controls in thirty plain-English questions. Work through it and you will know whether you are looking at an afternoon or a fortnight. If you would rather not do it alone, our Cyber Essentials readiness service does the gap review, the fixes and the draft answers. The certificate itself is issued by an IASME-licensed certification body, never by us. **Most of our staff are on the shop floor, not at a desk. Does that work?** Yes, and it is worth saying up front so we can build the session for it. Shop floor sessions are shorter, use examples from the floor rather than from an office, and cover the things that genuinely apply: shared terminals, personal phones, USB sticks, and who to tell when something looks wrong. The portal modules work on a phone, so nobody needs a company laptop to complete them. ### Worthing, West Sussex About 40 minutes along the coast from Bognor Regis. Cyber security and AI training for Worthing and Adur businesses. Practical sessions for care providers, agencies and offices. Worthing is the largest town in West Sussex and its business mix shows it. A growing digital and creative sector sits alongside a substantial health and social care presence, plus the usual run of small offices, shops and trades. Those businesses do not face the same security questions, so they should not get the same training. We come along the coast to you, or run the session live online if your team is spread across sites. Either way it is written for people who do not work in IT and would rather not sit through a lecture. Who we work with in Worthing: Care homes, domiciliary care and other health and social care providers; Digital, creative and marketing agencies; Accountants, brokers and financial services firms; Shops, salons and hospitality in the town centre and along the seafront; Schools, charities and community groups across Worthing and Adur. What tends to matter here: Care providers carry the heaviest data burden of any small business we work with. Health and care records are special category data under UK GDPR, staff work shifts across more than one site, and a shared login on a communal machine in the office is still a common arrangement. Fixing that is mostly habits and a handful of settings rather than anything expensive. For the agencies and consultancies the pressure comes from the other direction. Clients ask to see Cyber Essentials or a security policy before they will sign, and increasingly they ask what your team does with AI tools and where the client data goes. Having a straight answer ready is worth more than most of what gets sold as security. Also covered from Worthing: Goring-by-Sea, Ferring, Findon, Durrington, High Salvington, Storrington, Washington, Patching. **We have three sites around Worthing. Can everyone be trained at once?** Yes. A live online session puts every site in the same room without anybody driving anywhere, and completion is recorded for all of them. If you would rather have someone in the building, we can run it at your main site and put the rest of the team on the learning portal to work through in their own time. **Is there a travel charge to Worthing?** No. Worthing is inside the core area, so onsite travel is included in the published price. Travel is only quoted separately for the towns further out, and we would tell you before you booked. ### Shoreham-by-Sea, West Sussex About 50 minutes along the coast from Bognor Regis. Cyber security and AI training for Shoreham-by-Sea and Lancing businesses. Built for technical teams, consultancies and studios. Shoreham has an unusual business mix for a town its size. A working commercial port and the logistics around it, an airport, a cluster of engineering and technical consultancies, and a steady flow of studios and small digital firms priced out of Brighton along the road. What most of those have in common is that their people are not frightened of a computer. That changes the training completely. There is no point explaining what a password manager is to a room of engineers. The useful conversation is about the things technical confidence does not protect you from. Who we work with in Shoreham-by-Sea: Engineering, design and technical consultancies; Digital studios, software firms and creative agencies; Port, logistics and transport businesses; Marine trades and businesses along the harbour arm; Small offices, retail and hospitality across Shoreham and Lancing. What tends to matter here: For a firm whose value is in its drawings, designs, code or client work, the thing worth protecting is not the laptop, it is the intellectual property on it. That points at unglamorous controls: who still has access after they leave, what a contractor can reach, where work is backed up, and whether anybody would notice a large download. AI is the live one. Technical teams adopt AI tools faster than anybody, usually without asking, and the risk is not that the tool is malicious. It is that client designs, source code or commercially confidential material gets pasted into a service whose terms nobody has read, and then it is out of your hands and possibly in breach of a client contract. The answer is not a ban, which never holds. It is an acceptable-use policy people can actually follow and a session on where the line sits. Technical confidence also has a specific blind spot. Highly capable people are not immune to a well-timed message from someone claiming to be a director, and they are considerably less likely to report it afterwards, because they feel they should have known. A no-blame reporting culture matters more here than the technical content. Also covered from Shoreham-by-Sea: Lancing, Southwick, Portslade, Sompting, Steyning, Bramber, Upper Beeding, Fishersgate. **Our team is technical. Will they find this patronising?** They would find the standard awareness session patronising, which is why we would not run it for you as written. For a technical team the session shifts to the parts skill does not cover: policy and evidence for client contracts, access and offboarding, what goes into AI tools, and reporting without blame. We work that out on the first call rather than turning up with the wrong deck. **We use AI tools heavily. Can you cover that specifically?** Yes, and for a firm like yours it is usually the more valuable half. The Using AI Safely at Work course covers choosing tools you can trust, keeping client and confidential material out of them, and checking output before you rely on it. There is also a free acceptable use policy template on the resources page you can adopt and adapt without us. ### Portsmouth, Hampshire About 50 minutes from Bognor Regis. Cyber security and AI training for Portsmouth businesses. Cyber Essentials readiness for the marine and defence supply chain. Portsmouth is a working waterfront city, and the businesses that matter to us here are the ones in the supply chain behind it: marine and engineering firms, fabricators, logistics, specialist services, and the professional practices that support them. The security question in Portsmouth is rarely "do we need this?". It is "our customer has asked for evidence and we do not know what to send them". That is a solvable problem, and it is mostly paperwork, habits and a handful of settings rather than anything you have to buy. Who we work with in Portsmouth: Marine, engineering and fabrication businesses; Suppliers into defence, aerospace and large industrial customers; Logistics, distribution and port-related services; Professional practices, agencies and small offices across the city; Retail, hospitality and visitor businesses on the waterfront. What tends to matter here: Supply chain requirements dominate. Large customers, and public sector and defence contracts in particular, carry cyber clauses that flow down to their suppliers, and Cyber Essentials is the usual minimum bar. If you supply a prime contractor, that requirement is arriving at your renewal whether or not anybody in the business has thought about it. The trap is assuming it is a technical project. It is mostly not. The single most common blocker we see is scope: working out exactly which devices, cloud services and home-working setups are in, and being honest about the ones you had forgotten. Get the scope right and most firms are two or three fixes from a defensible answer. Alongside that sits the everyday risk, which has not gone anywhere. Payment redirection fraud against firms that raise large invoices, and staff who have never been shown what a convincing phishing message looks like in 2026. The certificate satisfies your customer. The training is what stops the money leaving. Also covered from Portsmouth: Southsea, Cosham, Fratton, Portchester, Farlington, Hilsea, Fareham, Gosport. **Is there a travel charge to Portsmouth?** Portsmouth sits outside our core area, so onsite travel is agreed in advance and shown separately on the quote rather than being included in the headline price. It is not a large figure and you will see it before you commit to anything. A live online session carries no travel at all, and for many teams it is the better option anyway. **Can you help us pass Cyber Essentials, not just train the staff?** Yes. Cyber Essentials readiness is a service in its own right: a gap review across scope and the five controls, a prioritised list of what to change, the technical work if you want us to do it, and draft answers to the self-assessment. What we cannot do is issue the certificate or promise a pass. That is marked independently by an IASME-licensed certification body, and the answers have to be true. ### Brighton & Hove, East Sussex About an hour from Bognor Regis. Cyber security and AI training for Brighton and Hove businesses. Built for agencies, tech firms and studios, not beginners. Brighton has the densest concentration of digital and creative businesses on the south coast, and the security conversation here is different from anywhere else we work. These are not businesses that need to be told what phishing is. Plenty of them have people who could explain it better than most IT departments. What they tend to be missing is everything around that: a written policy, evidence they can hand a client, a rule about AI tools that people actually follow, and any plan at all for the week something goes wrong. Those gaps are what lose contracts, not a lack of technical knowledge. Who we work with in Brighton & Hove: Digital agencies, studios and software firms; Startups and small tech businesses handling client or user data; Creative, media and production companies; Professional practices, consultancies and coworking members; Hospitality, retail and visitor businesses across the city. What tends to matter here: Client security questionnaires are the usual trigger. A larger client asks for Cyber Essentials, a security policy, a data processing agreement and evidence of staff training, and suddenly a fifteen person agency needs paperwork it has never produced. Turning that into a genuine, honest set of answers is a fortnight of work, and it makes the next ten questionnaires trivial. AI is the second one, and in Brighton it is urgent rather than theoretical. Client work, source code, unreleased material and personal data get pasted into whatever tool is fastest, often by the most capable people in the building, often in breach of a client contract nobody has reread. A ban does not hold for a week. A short, specific acceptable-use policy and an hour explaining where the line sits does. The third is people. Agencies run on freelancers, contractors and short projects, which means access is granted constantly and revoked almost never. Half the security work in a business like yours is a leavers process that actually happens, and knowing who still has a key to what. Also covered from Brighton & Hove: Hove, Portslade, Rottingdean, Saltdean, Peacehaven, Falmer, Lewes, Newhaven. **We are a technical team. What would you actually teach us?** Not the basics. For a Brighton agency the session is usually about the things skill does not cover: what goes into AI tools and what must not, access and offboarding for freelancers, answering client security questionnaires honestly, and what the first hour looks like if a client says their data is on a forum. If the honest answer is that you do not need us, we will tell you that on the call. **Is there a travel charge to Brighton?** Brighton and Hove sit outside our core area, so travel is agreed in advance and shown separately rather than being included in the price. You will see the figure before you commit. Live online sessions carry no travel at all, and for a single team in one office they work just as well. ### Horsham, West Sussex About an hour north of Bognor Regis. Cyber security and AI training for Horsham businesses. Practical help for small firms facing corporate security questionnaires. Horsham has a more corporate business base than a market town of its size would suggest. Professional services, finance and insurance, consultancies and a good number of offices belonging to much larger organisations, plus the small firms that grew up supplying and advising them. That proximity is the defining feature. Small businesses in Horsham get asked corporate questions. Vendor security assessments, data processing agreements, evidence of staff training. Those requests are written for a company with a compliance team, and they land on someone who also does the invoicing. Who we work with in Horsham: Professional services: accountants, solicitors, consultants and brokers; Finance, insurance and back office service firms; Small businesses supplying or advising larger corporate clients; Agencies, IT services and technical consultancies; Schools, charities and community organisations across the district. What tends to matter here: The recurring problem is a mismatch of scale. A twelve page vendor security questionnaire assumes you have documented policies, a named security owner, tested backups and an incident response plan. You may well do most of the underlying things properly and simply have nothing written down, which reads to the client as a fail. Writing it down honestly, rather than inventing controls you do not have, is usually a couple of days of work and it is reusable forever. Hybrid and commuting patterns add the second one. Horsham has a lot of people working part of the week from home, on home broadband, sometimes on personal devices, occasionally on a train. That is entirely workable, but it needs deciding rather than drifting into, and it is the area where Cyber Essentials scope most often trips businesses up. Third, and least popular: testing the response. A firm advising corporate clients is expected to know what it would do in the week it cannot work, and increasingly to show it has tried that out. Most never have. A tabletop exercise takes half a day, and it usually finds something worth knowing. Also covered from Horsham: Southwater, Billingshurst, Warnham, Cowfold, Rudgwick, Barns Green, Storrington, Pulborough. **A client has sent us a security questionnaire we cannot answer. Can you help?** That is one of the more common reasons people ring. We go through it with you, separate the questions where you genuinely do the thing but have not written it down from the ones where there is a real gap, and deal with each accordingly. The important rule is that we will not help you word around something that is not true. If a control is missing, the answer is to put it in place or say so. **Is there a travel charge to Horsham?** Horsham is outside our core area, so onsite travel is agreed in advance and shown separately on the quote. It is never added afterwards. Live online sessions carry no travel, and for an office-based team they lose nothing. ### Crawley, West Sussex About an hour and a quarter north of Bognor Regis. Cyber security and AI training for Crawley and Gatwick businesses. Built for aviation and logistics suppliers, and shift teams. Crawley is one of the largest business concentrations in the South East, and the shape of it is unusual: business parks and industrial estates rather than a high street, aviation and logistics rather than retail, and a great many firms whose work is tied directly to the airport next door. Two things follow from that. The businesses here are used to contractual obligations arriving from customers, and they are used to operating around the clock. Both change what useful training looks like. Who we work with in Crawley: Aviation, ground handling and airport supply chain businesses; Logistics, distribution and warehousing operations; Engineering, technical services and facilities firms; Offices and professional services across the business parks; Retail, hospitality and hotels serving the airport. What tends to matter here: Shift work breaks most security training, and almost nobody designing it accounts for that. If your operation runs across three shifts, a single session at eleven on a Tuesday reaches a third of the people who need it, and the other two thirds get told about it second hand. Sessions here get built around that: short, repeated, and backed by portal modules people complete on a phone at the start of a shift rather than in a meeting room. Contractual security requirements are the other constant. Aviation and logistics customers push obligations down their supply chain aggressively, and Cyber Essentials is often the least of it. The practical answer is the same as everywhere: settle your scope, fix the two or three real gaps, write down what you already do, and keep evidence that staff have been trained. Disruption deserves a mention here more than in most towns. Businesses tied to an airport already understand what a sudden operational stop costs them, because they plan for weather and disruption as a matter of routine. Extending that same thinking to losing your systems, rather than losing your flights, is usually an easy conversation and a genuinely useful tabletop exercise. Also covered from Crawley: Manor Royal, Gatwick, Three Bridges, Ifield, Copthorne, Turners Hill, Horley, East Grinstead. **We run three shifts. How do you train everybody?** Not with one session, which is the usual mistake. The pattern that works is short live sessions repeated to catch each shift, or one live session for supervisors plus portal modules that staff complete on a phone in their own time. Completion is tracked either way, so you can show a customer or an auditor exactly who has done what rather than guessing. **Is there a travel charge to Crawley?** Yes. Crawley is the furthest point we cover regularly and it sits well outside the core area, so travel is agreed in advance and shown separately on the quote. You will see it before you commit to anything, and it is never added afterwards. For a single office team, a live online session avoids it entirely. ## Services ### Training & Awareness Turn your team into the part of your defences that works. - Live staff awareness workshops - Annual refresher training - Onboarding training for new starters ### AI Adoption & Safe Use Put AI to work in your business without opening a new security hole. - Finding where AI genuinely helps your workflow - Choosing reputable AI tools you can trust - Staff training on using AI safely and sensibly - Keeping sensitive data out of AI tools ### Checks & Readiness Find the obvious gaps and get ready for the standards clients ask about. - Domain & email exposure checks - Cyber Essentials readiness support ### Resilience & Response Decide what you would do while everything is still working. - Tabletop disaster exercises - Incident response roles and contacts - Annual re-tests with a fresh scenario ## Courses Practical, plain-English courses that upskill your team on cyber security and safe AI use. Delivered onsite across Sussex and south-east Hampshire, live online UK-wide, or self-paced through the learning portal. Every course is built around a real small business, not an enterprise. Every course ends with a certificate of completion for each person, issued automatically and recorded on the portal, so you have evidence to show an insurer, a client or an auditor. ### Cyber Security Awareness Onsite or live online. 90 minutes. For All staff. The core session: how attacks actually happen, and the everyday habits that stop them. - Spotting phishing and scam messages - Strong passwords and password managers - Safe handling of data and devices - What to do when something looks wrong Outcome: Staff who can spot and report the most common attacks before they cost you anything. ### Using AI Safely at Work Onsite or live online. 60 to 90 minutes. For All staff and managers. Get the benefits of AI tools without leaking data or trusting the wrong answer. - Where AI genuinely helps, and where it does not - Choosing reputable tools you can trust - Keeping confidential and personal data out of AI - Checking AI output before you rely on it Outcome: A team that uses AI confidently, with a simple acceptable-use approach to follow. ### Managers & Owners: Building a Security Culture Onsite or live online. 60 minutes. For Owners and managers. Practical steps to lead on security, meet client and insurer expectations, and keep it going. - Cyber Essentials, in plain English - The policies your business actually needs - MFA, backups and the basics that matter most - Responding calmly when something goes wrong Outcome: A clear, prioritised action list sized to your business and budget. ### AI Adoption for Decision Makers (free) Online, self-paced. Short modules. For Owners, managers & decision makers. A practical grounding for leaders deciding where AI fits, what it risks, and how to roll it out responsibly. - Spotting where AI adds real value in your business - The risks to weigh: data, accuracy, cost and compliance - Choosing tools and setting an acceptable-use policy - Rolling AI out to your team with confidence Outcome: A clear, informed plan for adopting AI safely, with a policy your team can follow. Take it self-paced on the portal: https://portal.woodrufftraining.com/lms/courses/ai-for-decision-makers Your online learning portal: A self-paced portal where your team works through short courses on using AI safely in your business and on cyber security awareness, in their own time. The courses are not off-the-shelf. Every one is written and built in house, so the content stays practical, current and pitched at a real small business. Perfect for onboarding new starters, with completion tracked and certificates issued automatically. The portal is at https://portal.woodrufftraining.com. ## Services in detail ### Bespoke courses for your organisation From £1,950. Per course, including the first year of hosting on the portal. Takes: Four to six weeks from brief to launch. For: Organisations whose systems, sector or regulator do not fit an off-the-shelf course. Staff can tell when training was written for somebody else. Generic awareness courses use screenshots of software nobody here uses and scenarios that could not happen in this building, and people switch off within two slides. The content might be correct, but nobody remembers it on a Tuesday morning when the real email arrives. A bespoke course fixes that by using your systems, your terminology and the situations your people genuinely run into. We write it, build it and host it on our learning portal, so your team works through it in their own time and you get the completion records without chasing anybody. - **Work out what it actually needs to cover**: A short discovery session: which systems your staff use every day, what data they handle, what has gone wrong before or nearly gone wrong, and what any client, insurer or regulator has asked you to demonstrate. This is also where we agree whether the course is about cyber security, safe AI use, or both. - **Write it around your business**: We script it in plain English, using your tools and your scenarios rather than stock examples. You see and approve the script before anything gets built, because changing a sentence at that stage costs nothing and changing it afterwards does not. - **Build it on the portal**: Short modules that fit in a coffee break, with knowledge checks along the way and a certificate at the end. It works on a phone as well as a desktop, so people who are rarely at a computer can still do it. - **Launch it, then keep it current**: We enrol your team, set new starters to be assigned it automatically, and show whoever manages it how to see who has finished. When you change a system or a new risk turns up, we update the course rather than leaving it to go stale. What you get: A course written specifically for your organisation, not a template with your logo dropped in; Modules on cyber security, safe AI use, or a mix of the two; Knowledge checks and a certificate issued automatically on completion; Completion tracking you can show an insurer, a client or an auditor; New starters enrolled automatically, so onboarding looks after itself; Content updated as your systems and your risks change. When you do not need this: Most small businesses do not. Our standard courses cover the great majority of what a team needs, and at a fraction of the price. This is worth paying for when something about your situation is genuinely unusual: software nobody else uses, a regulator with specific expectations, an incident you need everyone to learn from properly, or an AI rollout with rules particular to your business. If a standard course would do the job, we will tell you that on the first call rather than sell you this. ### Cyber Essentials readiness From £695. Excludes the certification body’s own assessment fee. Takes: Usually two to four weeks, depending on what needs changing. For: Small businesses whose clients, insurers or tender documents have started asking for it. Cyber Essentials is the government-backed scheme, run by IASME on behalf of the NCSC, that more and more clients and insurers expect a supplier to hold. It asks you to have five basic controls in place and to answer honestly about them. Most small businesses are further along than they think, and stuck on the same two or three points. The work is rarely difficult. Knowing which questions are really being asked, and what counts as an acceptable answer, is the part that trips people up. - **Find out where you stand**: We go through your devices, cloud services and working setup, including staff who work from home and anyone using their own phone for work. Scope is what most applications get wrong, so we settle it first. - **A plain list of what needs to change**: You get the gaps written down in order of what matters, with an honest note on which ones you can do yourself and which are worth paying for. - **Close the gaps**: We work through the list with you, from tidying up admin accounts to retiring software that no longer gets updates. Or we can point and you can do it. Whichever is cheaper for you. - **Get your answers ready**: We prepare your responses to the self-assessment so the wording matches what the assessor is looking for, and you are not guessing on the day. What you get: A written gap report covering scope and all five controls; A prioritised action list, sized to your business and budget; The technical work done, or clear instructions if you would rather do it; Draft answers to the self-assessment questions; Someone to ring while your application is in progress. What we cannot do: We cannot issue the certificate, and nobody who prepares you can. Cyber Essentials is awarded by a certification body licensed by IASME, who mark your self-assessment independently. We also cannot promise a pass: the answers have to be true, and if something is not in place we will tell you rather than word around it. What we can do is make sure there are no surprises. ### Tabletop disaster exercises From £595. Half a day, onsite across Sussex and south-east Hampshire, or live online. Takes: Two to three hours, plus a short call beforehand. For: Owners, managers, finance and whoever looks after IT, in the same room. A tabletop exercise is a conversation, not a technical test. Everyone sits down, a realistic disaster unfolds, and the group works out what they would do. Nothing is plugged in, nothing is attacked, and nobody needs to be technical. It is the cheapest way to find out that three people each think a fourth has the backups, that the only person who can lock an account is on holiday, or that nobody knows who rings the customers. Those discoveries are uncomfortable in a meeting room and expensive at eight on a Monday morning. Not every disaster is a cyber attack. Fire, flood, a burst pipe upstairs, a key supplier going under and the one person who understands the invoicing being in hospital all stop a business just as effectively, and the response is largely the same set of decisions. - **A short call first**: We pick a scenario that could genuinely happen to you. A ransomware note on the shared drive, no access to the building on a Monday, an invoice paid to a criminal, a supplier that has stopped answering the phone. Generic scenarios get generic answers. - **The session**: The scenario unfolds in stages. New information arrives as you go, the way it does in reality, and the group decides what to do at each point. We facilitate, keep it moving and make sure the quiet people get heard. - **The awkward questions**: Who rings the bank. Who talks to customers. What do we tell staff. When do we notify the ICO. Who decides whether to pay. These are the questions that stall a real response. - **Debrief and write-up**: We finish with what went well and what did not, then send a short written report a few days later while it is still fresh. What you get: A scenario built around your business, not a template; Two to three hours of facilitated discussion; A written report on what worked and where the response stalled; A prioritised action list, usually shorter and cheaper than people expect; Something concrete to show an insurer or a client who asks whether you have tested your response. What this is not: It is not a penetration test and not a technical assessment. Nobody attacks your systems and nothing gets broken. If what you want is somebody trying to get in, that is a different piece of work and we will say so. It also only pays off if something changes afterwards: an exercise shows you where the gaps are, and if nobody acts on the list the same gaps are there next year. A tabletop tells you about decisions, roles and communication, which is where most small business disruptions actually go wrong. ## Pricing ### Learning Portal: From £8 per person, per year Self-paced courses for everyone in the business. £8 for a single course, £12 for the lot. - Any single course, £8 per person - All courses for £12 per person, including the free one for decision makers - New courses added to the bundle at no extra cost - New starters train themselves on day one - Progress tracked and certificates issued automatically - No minimum: one freelancer or a whole team ### Portal + Training: £895 up to 30 staff The portal, plus live sessions that make it stick. - A year on the portal for the whole team, all courses included - Two live sessions, onsite or online - Completion certificates for everyone who attends - A refresher session within 12 months - Cyber Essentials readiness checklist ### Ongoing: From £1,750 a year, 30+ staff Multi-site teams and businesses with clients who ask questions. - Everything above, refreshed through the year - Quarterly refresher sessions on what has changed - Monthly micro-training on the portal - Named point of contact - Annual review with your leadership ### Priced separately - Tabletop disaster exercise: From £595. A realistic scenario, walked through with your team - Extra live session: From £295. Any course, for a team already on the portal - Domain & email exposure check: £195. What a criminal can find before they start - Cyber Essentials readiness: From £695. Gap review and the work to close it - AI adoption support: From £750. Where AI helps, plus a policy your team can follow All prices exclude VAT. Onsite travel is included across the core area, from Chichester through Bognor and Littlehampton to Worthing and Shoreham. Further out, in Portsmouth, Brighton, Horsham and Crawley, travel is agreed in advance and shown separately rather than added later. Multi-site and larger pieces of work are quoted per project, and schools, charities and community groups pay considerably less. ## Frequently asked questions ### Do you only offer training? No. Training is the core, but we also run tabletop disaster exercises, help your team adopt AI tools safely, run domain and email exposure checks, and prepare you for Cyber Essentials. Most clients start with one thing and build from there. ### What is a tabletop disaster exercise? Everyone who would have to deal with a crisis sits down together, a realistic scenario unfolds, and the group works out what they would actually do. Ransomware on the shared drive, no access to the building on a Monday morning, a supplier that has stopped answering the phone. Nothing is plugged in and nobody needs to be technical. It usually takes two to three hours, and it is the cheapest way to find out that three people each thought a fourth had the backups. ### Do our staff need to be technical? Not at all. Every session is built for everyday employees and deliberately avoids jargon. If your team can use email, they will follow the training and take something useful away. ### Do you deliver onsite or online? Both. We run in-person sessions across Sussex and south-east Hampshire, and live, interactive sessions online for teams anywhere in the UK. Plenty of clients mix the two: an onsite kick-off, then online refreshers. ### Do you cover our town? We are based in Bognor Regis. Travel is included across the core area, so Chichester, Littlehampton, Arundel, Emsworth, Havant, Worthing and Shoreham are all normal onsite work at the published price. We also work regularly in Portsmouth, Brighton, Horsham and Crawley, where the travel is agreed in advance and shown separately on the quote rather than added afterwards. There is a page for each town setting out what we see locally. Anywhere else in the UK, a live online session covers you with nobody losing a morning to travel. ### How long does a session take? A core awareness workshop runs around 60 to 90 minutes. Ongoing programmes use much shorter monthly refreshers designed to fit around a normal working day. ### Will this help with Cyber Essentials or our insurance? Staff awareness is a growing requirement for cyber insurance and a sensible step toward Cyber Essentials. We will show you what matters and get you ready, though the formal certificate itself is issued by a licensed certification body, not by us. ### How often should we train? An initial workshop followed by refreshers is far more effective than a one-off. For most small businesses, a session when people join plus quarterly or annual top-ups works well. ## Articles ### What to switch off when someone leaves Published 2026-09-14. Topics: Access control, Quick wins. Web version: https://woodrufftraining.com/blog/closing-accounts-when-staff-leave When somebody leaves a small business, the laptop comes back and the keys go on the hook. The logins tend to stay live. Nobody decides to leave them open. Access just builds up over a few years across a dozen different systems, nobody writes it down, and on the leaver's last day there is no list to work from. ## Why a forgotten account matters months later The risk here is rarely the person who left. It is the account they left behind. A dormant account still works, still has the same password, and that password may already be sitting in a breach list somewhere for anyone to buy. Worse, nobody is watching it. If a stranger logs into the mailbox of someone who left in March, there is no colleague to notice odd behaviour and no reason for anyone to question it. We wrote about how [stolen logins get traded](/blog/stolen-logins-for-sale) if you want the background. There are duller reasons too. Company email still arriving on a personal phone. A subscription you are paying for every month because it was set up on somebody's own card. An old admin account on the website that no longer has a person attached to it. ## The ones people forget Email and the laptop are easy to remember. These are the accounts that slip through: - **Mail forwarding and shared mailboxes.** Check whether a forwarding rule was ever set up, and whether the leaver still has delegated access to the info@ or accounts@ inbox. - **The website.** WordPress and similar systems accumulate admin users. Look at the full list, not just the obvious one. - **Social media.** Often linked to a personal Facebook or LinkedIn profile rather than a company account. - **Accounting, payroll and banking.** Including read-only access and anyone named as a payment approver. - **File storage.** Dropbox, Google Drive, OneDrive, and any folder shared to a personal address. - **Mobile devices.** A phone that still holds company email needs the account removed from it, not just a promise that it was deleted. - **Shared logins.** If several people used one password, that password has now walked out of the door. Change it. - **Doors and alarms.** Key fobs, door codes and the alarm panel code, if it was one everybody knew. ## A list you write on day one The trick is to stop treating this as a leaving job. Every time you give a new starter access to something, add it to a short list kept with their file. Then leaving day is twenty minutes of working down that list instead of an afternoon of guessing. Two other habits help. Disable accounts before you delete them, so the email and files stay available while you work out what you need. And move away from shared passwords where you can, because a login with one name on it can be switched off cleanly, whereas a login four people know has to be changed and redistributed every time anyone moves on. If you are working towards Cyber Essentials, this is already part of it: the scheme asks you to remove access promptly when someone no longer needs it, and to be able to show how. Our [free checklist](/cyber-essentials-checklist) covers what that looks like in practice. The short version is that leaving day should be boring. If you cannot say today which systems your last leaver still has access to, that is the thing worth an hour this week. [Get in touch](/#contact) if you would like help putting the list together. --- ### The backup you have never tested is not a backup Published 2026-08-25. Topics: Backups, Quick wins. Web version: https://woodrufftraining.com/blog/testing-your-backups Ask a small business owner whether they back up their data and almost everyone says yes. Ask when somebody last restored a file from that backup and the answer is usually a pause. That pause is the problem, because a backup is not a thing you own. It is a thing that either works on the worst morning of your year or it does not, and the only way to know which is to try it while nothing is wrong. ## Where backups quietly fail The failures we see are rarely dramatic. They are small and boring, and they sit there for months. - **It covers the wrong things.** The laptops are backed up but the accounting package is not, or the shared drive is included and the one folder the business runs on lives on somebody's desktop. - **It stopped, and the warning email went to a mailbox nobody reads.** Backups fail quietly by design. A disk fills up, a password changes, and the last good copy is from March. - **The only spare copy is plugged into the machine it is protecting.** That is fine against a hard drive dying. It is no help against a fire, a burglary, or ransomware, which now goes looking for connected backup drives on purpose. - **Someone assumed Microsoft 365 or Google Workspace was doing it.** These sync your files, which is not the same thing. Delete a file in a synced folder and it disappears everywhere. Both have a limited recycle bin window and it is shorter than most people imagine. ## Three copies, two places, one out of reach The old rule still holds up. Keep three copies of anything you would hate to lose, on at least two different types of storage, with one of them off-site or offline. For a small business that usually means the working copy on your systems, a cloud backup service running daily, and either a second cloud copy or a drive that gets swapped and taken home. The important word is offline. One copy needs to sit somewhere an everyday login cannot reach and cannot delete, because if a criminal gets into your email they will try the backup next. ## The hour that proves it Put this in the diary and actually do it. - Pick a real file from a month ago and restore it yourself. Not a test document you made this morning. Time how long it takes. - Check the last successful backup date on every system, not just the obvious one. Write the dates down. - Ask who gets the failure alerts, and check that person still works here and still reads them. - Try restoring something bigger, or ask your IT provider to walk you through how a full recovery would go and how long it would take. - Confirm at least one copy cannot be deleted by someone logged in as you. That last exercise tends to be the useful one, because it turns a vague comfort into a number. If getting back to work would take four days, you now know something worth knowing, and you can decide whether four days is acceptable or whether it is worth paying to make it one. The real question was never whether you have a backup. It is how long you would be out of action, and who is doing the restoring while the phone rings. A [tabletop exercise](/services/tabletop-exercises) is a good way to find out before it matters, or [get in touch](/#contact) and we can talk it through. --- ### AI will answer any question you ask it. That is the risk. Published 2026-08-09. Topics: AI, Business advice. Web version: https://woodrufftraining.com/blog/asking-ai-for-business-advice Somewhere between the quote you did not want to pay for and the accountant you did not want to bother at nine on a Sunday evening, there is now a chatbot that will answer anything, instantly, for nothing. Small business owners have noticed. Redundancy questions, contract wording, what a clause in the insurance schedule actually means: it all goes into the same box now. That is not a foolish thing to do. It just needs one piece of judgement that nobody hands you with the tool. ## Confident is not the same as correct An AI tool writes every answer in the same assured tone. It has no sense of the difference between something it has seen a thousand times and something it is more or less guessing at, so the answer about your dismissal process arrives sounding exactly as certain as the answer about how long to boil an egg. Four things go wrong more than owners expect: - **It answers as if you were American.** A great deal of what these tools learned came from the United States. Employment advice that would be perfectly sound in Texas can walk you straight into a tribunal claim here. - **It may be working from an older version of the world.** Thresholds, rates and rules change with each Budget. The tool will quote you the figure it learned without mentioning that it has moved. - **It invents specifics that sound real.** Ask which regulation applies and you can get an official-sounding name with a section number attached to it that does not exist. Lawyers have been caught filing court documents citing cases that were never heard. - **It knows nothing about you.** It does not know one of your staff is on a contract from 2014, that your insurer requires a particular control, or that you took a payment holiday two years ago. It answers the general question, and your question is never the general one. The same applies to technical fixes, which is where we see it most. Somebody cannot receive email from a supplier, asks an AI tool why, and gets a workable instruction to relax a filter or add an allow rule. The email starts arriving. A protection you were relying on is now off, and nobody wrote that down anywhere. ## Where it earns its place None of this is an argument for banning it, any more than it is for [staff using AI day to day](/blog/staff-using-ai-safely). Used properly it saves real money: - **Translating jargon.** Paste in the paragraph of the contract or the insurance schedule you cannot follow and ask what it means in ordinary English. Low risk, and it makes you a better reader of your own paperwork. - **First drafts.** A job advert, a policy, an awkward email to a customer. You were going to rewrite it anyway. - **Preparing for the professional.** Ask it what you should be asking your accountant or solicitor. Turning up with sharp questions is the cheapest way to shorten a billable hour, and almost nobody does it. - **Getting through something long** you would otherwise never read at all. Notice what those have in common. Every one of them uses AI to help you think, and not one of them lets it decide. ## Ask what being wrong would cost That is the whole test, and it takes about two seconds. If a wrong answer costs you an afternoon, go ahead and trust it. If a wrong answer costs you money, someone's job, a client, or a letter from a regulator, then AI is where you start rather than where you stop. Employment, tax, contracts, data protection and anything a regulator oversees all sit firmly in the second group. Worth remembering too: "the AI told me" has never once worked as a defence. HMRC, the ICO and an employment tribunal will hold you responsible for the decision, whatever helped you reach it. The tool takes none of the risk, which is rather the point of it being free. If you would rather your managers made that call consistently, our [free AI course for decision makers](/courses) covers this ground, and we are happy to [talk it through](/#contact). --- ### A client has asked if we have Cyber Essentials. What now? Published 2026-08-02. Topics: Cyber Essentials, Compliance. Web version: https://woodrufftraining.com/blog/client-asked-for-cyber-essentials It usually arrives in a tender document, or an email from a client's procurement team, phrased as though you will obviously know what it means. Do you hold Cyber Essentials? For most small businesses the honest answer is no. The second honest answer is that it is more achievable than it sounds. ## What they are actually asking for Cyber Essentials is a government-backed scheme. The NCSC owns it and IASME runs it on their behalf. It asks you to have five basic technical controls in place, and then to answer a questionnaire about them truthfully. A certification body licensed by IASME marks those answers and issues the certificate. Nobody comes to your office. There are two levels, and it is worth pinning down which one you need before you spend anything. The standard certification is that self-assessment. Cyber Essentials Plus covers exactly the same five controls, but somebody from the certification body tests them hands-on, which costs more and takes longer. Ask your client which they mean. Plenty of procurement teams write "Cyber Essentials" when the standard certification would satisfy them perfectly well, and a few are working from a template and have no firm requirement at all. ## The five controls None of it is exotic. - **Firewalls.** Something sensible between your devices and the internet, including for people working from home. - **Secure configuration.** Default passwords changed, software and accounts nobody uses removed, devices that lock themselves. - **Security update management.** Updates applied promptly, and nothing still running that the vendor has stopped supporting. - **User access control.** Everyone on their own account, administrator rights used only for administrator work, and [multi-factor authentication](/blog/mfa-small-business) on your cloud services. - **Malware protection.** Anti-malware kept current, or only allowing applications from an approved list. Most businesses are already further along than they expect. Multi-factor authentication and retiring old software are the two that usually need real work. ## Where applications come unstuck Scope, more than anything else. Before you answer a single question, decide what is being certified: the whole organisation, or a clearly defined part of it. That decision has to account for laptops, phones, staff working from home and every cloud service people log into. It is tempting to quietly leave out the awkward machine in the corner, and that is exactly the thing that unravels later. The other one is answering hopefully. The questionnaire is a declaration you are signing, and "we are getting round to it" is not a yes. If a control is not in place, put it in place and then answer. ## What to do this week Work out roughly where you stand before you commit any money, then get a quote from a certification body and remember their fee sits on top of any help you pay for. It is also worth asking what else comes with certification, because for smaller UK organisations it can include a limited cyber insurance option. Check the current terms rather than assuming, since they change. Being asked is good news, in a roundabout way. It means somebody wants to work with you and has a box that needs ticking. Most small businesses get there in a few weeks rather than a few months. If you want to know where you stand before speaking to anyone, our [free readiness checklist](/cyber-essentials-checklist) covers scope and all five controls in thirty plain-English questions. If it turns up more than you fancy tackling on your own, [that is the work we do](/services/cyber-essentials-readiness). --- ### Why telling staff off makes your security worse Published 2026-07-27. Topics: Staff training, Culture. Web version: https://woodrufftraining.com/blog/carrot-not-stick-security-culture The employee who clicks a phishing link is not your biggest problem. The one who clicks it, realises something is wrong, and says nothing for three days is. That gap is where the damage happens, and the way you handle the first mistake decides how long the gap will be next time. ## Fear buys you silence Hardly any owner sets out to run security by telling people off. It creeps in anyway. Someone falls for a convincing email, there is an awkward meeting about it, word gets round the office, and the lesson everybody quietly takes away is that owning up is expensive. So the next person who clicks something odd sits on it. They hope it was nothing, wait to see whether anything happens, then get on with their afternoon. Meanwhile the criminal has a free run: reading the mailbox, learning who pays the invoices, and setting up a rule that hides their own replies from the person whose account it is. Phishing simulations run as a trap do the same damage. Once the results turn into a list of names, staff stop treating the test as practice and start tipping each other off. You end up with a flattering number that tells you nothing about how the team would cope with the real thing. ## Measure reporting, not clicking Click rate is the figure everyone reaches for. Reporting rate is the one worth watching, because it tells you how fast you would hear about a genuine attack, and speed is what limits the damage. A team where a third of people click but everyone reports within ten minutes is in better shape than a team where nobody clicks and nobody speaks up either. Push the reporting number up. The clicking number usually falls on its own once people are paying attention. ## What works instead - Thank people for reporting, out loud, including the false alarms. Someone forwarding a real invoice just in case is doing exactly what you want them to do. - Make reporting take one click. A button in Outlook, or one address everybody knows. If it needs a written explanation, most people will not bother. - Keep individual results private. Share the team's overall figures, and coach anyone who is struggling quietly, without an audience. - Train during work hours and keep sessions short. Asking staff to do security learning in their own evening tells them precisely what you think it is worth. - Go first yourself. When the owner admits they nearly fell for something last month, it stops being a test of competence and becomes a normal part of the job. None of this is soft. A business where people put their hand up early gets an incident closed in an afternoon instead of a fortnight, and the difference shows up in what it costs you. The other half of this is knowing what happens next. We have put that on a one-page [first hour incident card](/resources/first-hour-incident-card.pdf) you can print and keep by the phone. If you cannot fill in the "who to call" lines today, that is worth half an hour of somebody's time this week. If you want a hand building that habit, our [course for managers and owners](/courses) is built around exactly this. [Get in touch](/#contact) and we'll talk it through. --- ### If your website runs WordPress, update it this week Published 2026-07-19. Topics: Websites, Quick wins. Web version: https://woodrufftraining.com/blog/wordpress-update-now WordPress runs a large slice of the world's websites, so there is a good chance this affects you. In mid-July 2026, WordPress released an urgent update after researchers found a flaw serious enough that an attacker could take over a website without ever logging in. By the time the fix appeared, criminals were already using it. The good news is that the fix itself is simple. Update WordPress, and the door closes. ## What actually happened WordPress powers a huge share of the world's sites, plenty of them small business ones, from the local plumber to the village shop. The flaw, patched in WordPress version 7.0.2 on 17 July, let an attacker with no password and no account run their own code on a vulnerable site. In plain terms, a stranger could hijack the site: deface it, plant scam pages, redirect your customers, or quietly use it to send spam in your name. The United States cyber agency added the flaw to its list of bugs being actively exploited. That is as clear a signal as you get to patch now rather than later. ## What to do If someone else looks after your website, send them one line: "Please confirm we are on WordPress 7.0.2 or later." That is the whole job. If you manage it yourself: - Log in to your WordPress dashboard and update to the latest version (7.0.2 or newer) today. - Update your plugins and themes while you are there. Out-of-date plugins are the other common way in. - Turn on automatic updates for WordPress itself, so the next urgent fix installs on its own. - Take a fresh backup before you start, and keep taking them regularly. ## Why this keeps happening Websites are software, and software gets flaws. That is normal, and not a reason to panic. What matters is how fast you apply the fixes. A site that updates promptly is a hard target. A site still running last year's version is the one attackers go looking for. If keeping your site patched and backed up is one more job you never quite get to, we can set it up to look after itself. [Ask us to take a look](/#contact) at your current setup. --- ### The best password is no password Published 2026-07-12. Topics: Passwords, MFA, Quick wins. Web version: https://woodrufftraining.com/blog/best-password-is-no-password Almost all password advice is damage limitation. Make it long, make it different on every site, and keep it in a password manager. That is sound, and we still recommend it, but it works around the flaw rather than fixing it. A password is a secret you hand over to prove who you are, so anyone who persuades you to hand it over somewhere else now has it too. Passkeys deal with that by getting rid of the secret. ## Why the password rules kept changing The National Cyber Security Centre, the government body that advises UK organisations on security, has spent years undoing password habits that made things worse rather than better. It advises against forcing staff to change their password every 90 days. People respond to that with Summer2025, then Summer2026, and the account ends up weaker. It suggests three random words instead of a jumble of symbols, because length does more work than complexity and people can actually remember it. It is comfortable with password managers, including the one built into your browser, on the grounds that almost anything beats using the same password everywhere. Sensible advice, and worth following. But it is still a password, still typed into a box, and a convincing fake login page still collects it. ## What a passkey actually is When you set up a passkey, your device creates two matched keys. One stays on your phone or laptop and never leaves. The other goes to the website, where it is useless on its own. Signing in means your device proving it holds the private half, which it does once you unlock it with a fingerprint, your face, or the PIN you already use to open the phone. A few things follow from that: - Phishing stops working. Your device checks the web address before it responds, so a lookalike page gets nothing even if the person is completely taken in. - A breach at the supplier costs you little. Attackers walk away with the half of the key that does nothing without your device. - Your fingerprint never leaves your phone. The biometric only unlocks the key sitting on the device. This is the part that worries people most, and it is the part they need not worry about. ## Where to start - Turn on passkeys for your Microsoft 365 or Google Workspace account first. Email resets every other account you own, so it deserves the strongest protection you have. - Add them anywhere else they are offered. Banks, accounting software and the bigger online services are steadily adding support. - Keep multi-factor authentication switched on everywhere else. Most systems will not offer passkeys yet, and MFA remains the [best free thing you can do](/blog/mfa-small-business) for an account. - Work out recovery before you need it. Know how someone gets back in after a lost phone, and make sure more than one person can reach the business accounts. Passwords are not going away this year, and you will run both side by side for a while yet. Start with the accounts that would hurt most to lose, and let the rest follow. If you want an honest read on the passwords in your business today, our [password checker](/password-check) will tell you in a few seconds. [Get in touch](/#contact) if you would like to talk it through. --- ### Your staff are already using AI. Are they doing it safely? Published 2026-07-04. Topics: AI, Data protection, Staff training. Web version: https://woodrufftraining.com/blog/staff-using-ai-safely If you have not handed your team an AI tool, some of them are almost certainly using one anyway. A quick draft knocked out by ChatGPT, a spreadsheet tidied up by Copilot, a tricky email reworded in seconds. People reach for these tools because they genuinely make the work quicker, and that is not something to stamp out. The question is not whether your staff use AI. It is what they are typing into it. ## The quiet risk is what goes in Most AI chatbots are run by third parties. When someone pastes text into one, that text leaves your business and lands on a company's servers somewhere else. Usually that is harmless. It stops being harmless the moment the text contains personal or confidential information. Picture the everyday examples: - A member of staff pastes a customer list into an AI tool to "tidy up the formatting". - Someone drops a client contract in and asks for a plain-English summary. - An employee's details, a supplier's bank information, or a list of names and email addresses gets shared to save five minutes. Each of those is personal or commercial data going to an outside company you may never have checked. Some tools, particularly the free consumer versions, may use what people type to improve their systems, depending on the settings. Under UK data protection law, personal data stays your responsibility even when a well-meaning employee is the one who pasted it in. Nobody did anything malicious. That is exactly why it keeps happening. ## Banning it does not work The gut reaction is to forbid AI outright. In practice that just drives it underground. People use it on their phones instead, and you lose any say over how. The businesses that handle this well do the opposite: they accept that AI is useful, then make it safe to use. That comes down to a few simple ground rules everyone can follow: - Never paste customer, staff, or financial data into a public AI tool. If in doubt, leave it out. - Strip out names and identifying details before asking for help with a document. - Use a business-grade version of a tool where you can. Paid and business tiers usually keep your data private and do not train on it, unlike some free ones. - Agree which tools are approved, and only install them from the official source. Lookalike AI apps are a [real scam](/blog/fake-ai-tools-scams). ## Turn shadow use into safe use The aim is not to slow your team down. It is to let them keep the speed AI gives them without the data leak that can come with it. A short, honest conversation and a one-page set of rules gets you most of the way. Training people on what is and is not safe to share gets you the rest. We have written those rules up as an [AI acceptable use policy template](/resources/ai-acceptable-use-policy-template.pdf) you can adopt as your own. It leaves blanks for the tools you approve and the person to tell when something goes in that should not have. Change whatever does not match how you work, then put your name on it. That is exactly what we help small businesses do, so your team can use AI with confidence rather than in secret. If you are not sure what your staff are already pasting into these tools, [let us take a look](/#contact), or see how our [AI adoption and safe use](/#services) support works. --- ### The fake AI tool problem, and how to download safely Published 2026-06-26. Topics: Scams, AI, Quick wins. Web version: https://woodrufftraining.com/blog/fake-ai-tools-scams Small businesses are trying out AI tools faster than almost anyone, and criminals have noticed. Across the first four months of 2026, security researchers at Kaspersky counted more than 33,000 attacks that hid malware inside apps pretending to be popular AI services. That is a rise of almost 500% on a year earlier. The fakes look like the real thing. Behind the familiar logo, some quietly install software that steals passwords or hands an attacker a way onto your computer. None of this means you should avoid AI. It means you should be a little careful about where you get it. ## How the scam works The pattern is simple. You search for a well-known AI assistant, a "free" version of a paid tool, or a browser add-on that promises to write your emails for you. One of the results is fake. It might be an app, a download, or a subscription page that takes your card details and gives you nothing useful in return. The worst ones install something harmful at the same time. Criminals do this because they know people trust these names. A logo you recognise lowers your guard, which is exactly the point. The best-known AI tools are impersonated most, precisely because so many people are looking for them. ## Staying safe without missing out A few habits keep you on the right side of this: - Go to the official website directly. Type the address yourself or use a saved bookmark, rather than clicking a search advert or a link someone sent you. - Treat "free premium" offers with suspicion. If a paid tool is suddenly free from some other site, that is a warning sign, not a bargain. - Read the web address carefully before you enter card or login details. Fakes use names that are close but not quite right. - Install browser add-ons only from the official store, and only ones with a genuine track record. - Do not grant an app more access than its job needs. If a note-taking tool asks to read every file on your computer, stop. ## Decide your tools, then tell your team The simplest protection is to choose which AI tools your business actually uses, get them from the official source, and let staff know that is the approved list. When everyone knows what normal looks like, the odd fake stands out a mile. If you would like help choosing tools safely, or training your team to spot the fakes, [that is part of what we do](/#services). [Get in touch](/#contact) for a quick chat. --- ### There is a market for stolen business logins. Stay off it. Published 2026-06-19. Topics: Passwords, Staff training. Web version: https://woodrufftraining.com/blog/stolen-logins-for-sale Here is an uncomfortable fact. When criminals break into a business, they often do not use the access themselves. They sell it. There is a working market where one group steals logins and another buys them to launch a scam or a ransomware attack. And small businesses are the bulk of the stock. In one 2026 analysis by Kaspersky, more than half of these "access for sale" listings concerned small and medium organisations. The reassuring part is that you do not need to be a security expert to stay off that list. You need a few habits that make your accounts more trouble than they are worth. ## How your login ends up for sale Usually it is nothing dramatic. A staff member reuses the same password across several sites. One of those sites is breached, the password leaks, and criminals quietly try it everywhere else, including your email and your accounting. Or someone types their details into a convincing fake login page. Either way, a working username and password is now worth money to somebody. ## The habits that keep you off the list - Turn on multi-factor authentication everywhere it is offered. Even if a password leaks, it is not enough on its own. This is the big one, and we wrote a [separate note on it](/blog/mfa-small-business). - Use a password manager so every account has its own long, unique password. Then a leak from one site cannot unlock the others. - Close accounts for people who have left, and old logins nobody uses. Every unused account is a door left unlocked. - Watch for sign-ins from odd places or at odd hours, and act on the alerts your systems send you. ## Find out if you are already exposed Some of your passwords may already be out there from past breaches, and it is worth knowing which. A quick check of your business email addresses against known leaks shows you where to focus first. We run exactly that as a [domain and email exposure check](/#services), and it is often a sobering but genuinely useful place to start. Stay off the list, and most of these attacks never get going. [Get in touch](/#contact) if you would like a hand. --- ### Five phishing red flags every employee should know Published 2026-06-11. Topics: Phishing, Staff training. Web version: https://woodrufftraining.com/blog/spotting-phishing-emails Nine times out of ten, an attack on a small business does not start with clever hacking. It starts with an email that looks normal enough for a busy person to click without thinking. The good news is that the same handful of warning signs show up again and again, and once your team knows them, most of these emails get spotted and deleted. ## 1. A sense of urgency "Your account will be closed in 24 hours." "Pay this invoice today to avoid a late fee." Attackers push you to act before you think. A genuine supplier or bank is almost never that dramatic. If an email is rushing you, slow down. ## 2. The address is *almost* right The display name might say your bank, but the real address behind it is something like `security@bank-alerts-uk.com`. On a phone this is easy to miss. Teach staff to press and hold (or hover on a desktop) to see the true sender before trusting anything. ## 3. It asks you to change how you get paid Any email asking to update bank details, redirect a payment, or "confirm" account information deserves a second channel. **Phone the supplier on a number you already have** (never the one in the email) and confirm before moving a penny. This one habit stops most invoice fraud. ## 4. Unexpected attachments or links An invoice you were not expecting. A "delivery" you did not order. A shared document from someone you barely know. When in doubt, don't open it. Check with the person first. ## 5. It just feels slightly off Odd phrasing, a greeting that isn't quite how a colleague speaks, a logo that looks stretched. Trust that instinct. It is usually right, and it costs nothing to double-check. ## Make it a habit, not a one-off Reading a list once does not change behaviour. Short, regular reminders keep these signs fresh, which is exactly what our [awareness training](/#services) is built to do. We have put these five flags on a one-page poster you can [print and pin up in the office](/resources/phishing-red-flags-poster.pdf). There is a blank line at the bottom to write in whoever your staff should report to, which is the detail people forget when it matters. *Want a plain-English session for your team? [Get in touch](/#contact).* --- ### MFA, the best £0 you'll spend on security Published 2026-06-03. Topics: MFA, Quick wins. Web version: https://woodrufftraining.com/blog/mfa-small-business If you only do one thing after reading this, make it this: **turn on multi-factor authentication.** It is free on almost every business system you already use, and it stops the single most common way small businesses get breached: someone else logging in with a password that has been guessed, reused, or stolen. ## What MFA actually is MFA (sometimes called two-factor or 2FA) simply means a password is not enough on its own. After the password, the system asks for a second thing, usually a code from an app on your phone, or a tap to approve. Even if a criminal has your password, they cannot get in without that second step. ## Why it matters so much Passwords leak constantly. People reuse the same one across their email, their bank, and a dozen websites, and when any of those sites is breached, that password ends up on a list criminals buy and try everywhere. MFA breaks that chain. Microsoft and others have repeatedly found it blocks the overwhelming majority of these automated account-takeover attempts. ## Where to switch it on first Start with the accounts that would hurt most if someone else got in: - **Email**: the master key. Whoever controls your email can reset the password on everything else. - **Online banking and accounting**: the obvious target. - **Microsoft 365 / Google Workspace**: where your files and staff accounts live. - **Your website and domain host**: so nobody can hijack your address. ## Do it properly A few things make MFA far more effective: 1. Use an **authenticator app** (or a hardware key) rather than SMS text codes where you can. Text messages can be intercepted. 2. Turn it on for **every staff member**, not just the owner. 3. Save the **backup codes** somewhere safe so nobody gets locked out. It really is an afternoon's work for most small teams, and it is one of the highest-value hours you will spend all year. If your team would find it easier with someone explaining why it matters, it is part of what our [courses](/courses) cover. --- ### Invoice and QR-code scams to watch for on the South Coast Published 2026-05-27. Topics: Scams, Local. Web version: https://woodrufftraining.com/blog/invoice-and-qr-scams-south-coast Speak to enough small businesses along the South Coast (the cafés, letting agents, trades and small offices between Brighton, Worthing and Portsmouth) and the same handful of scams come up again and again. Two in particular are worth knowing about, because they are cheap for criminals to run and surprisingly effective. > This post describes common, widely reported scam patterns so you can recognise them. It is general guidance, not a report of a specific incident. ## 1. The changed bank details ("invoice redirection") This is the one that costs businesses the most. It usually goes like this: 1. A criminal gets into, or convincingly imitates, a supplier's email. 2. You receive a real-looking invoice, or a note that "our bank details have changed." 3. You pay as normal. The money goes straight to the criminal, and it is very hard to get back. **How to stop it:** treat *any* change of bank details as a red flag. Before paying, call the supplier on a number you already have on file (never the number printed on the new invoice) and confirm the change verbally. Build this into your payment process so it does not depend on one person remembering. ## 2. Fake QR codes ("quishing") QR codes are everywhere now, on parking meters, menus, and payment terminals, and criminals have noticed. The trick is simple: a sticker with a malicious QR code is placed over a genuine one, or sent by email. Scan it and you land on a convincing fake page asking for card or login details. **How to stop it:** - Be wary of QR codes on **stickers**, especially in car parks and on payment machines. Check for anything stuck over the original. - Look at the **web address** the code opens before typing anything. If it is not the official site, close it. - For anything involving payment, **type the address yourself** or use the official app instead of scanning. ## The common thread Both scams work by catching a busy person on autopilot. The defence is not clever technology. It is a small pause and a habit of verifying through a second channel. Sharing this with your team, and practising it, is most of the battle. *We help South Coast businesses build these habits through [staff training](/#services). [Get in touch](/#contact) if you would like a hand.* ---