SOLVBEAT

Solvbeat Blog

Website security & Cyber Essentials guidance for UK businesses.

How to Set Up DMARC for a Small Business – A Step‑by‑Step Guide

16 September 2026

Learn how to protect your small business email with DMARC. Follow this practical, UK‑focused guide to configure SPF, DKIM and DMARC, monitor reports and stay Cyber Essentials ready.

The 7 website security gaps we see most in UK small businesses (2026)

16 September 2026

43% of UK businesses were breached last year and phishing is the top threat. Here are the 7 website security gaps we flag most in small-business scans, and how to fix each one.

How much should website security cost a small business in 2026?

2 September 2026

From free scanners to five-figure enterprise contracts, security pricing is all over the place. Here's a clear map of what things really cost — and what's worth paying for.

Cyber Essentials on a budget: the tools that actually get you certified

2 September 2026

You don't need an enterprise security platform to pass Cyber Essentials. Here's what actually helps a small UK business get certified — affordably.

The best website security scanners for small business (2026)

2 September 2026

A practical, honest roundup of the website and infrastructure security tools a small business should actually consider in 2026 — with who each one is really for.

The best Aikido alternatives in 2026

2 September 2026

Aikido is dev-first. If you're not a development team — or you also need server monitoring and a human pentest — here are the alternatives to look at.

The best Intruder.io alternatives for small business (2026)

2 September 2026

Intruder is good — but it's not the only option, and not always the right shape for a small team. Here are the alternatives worth knowing, and how to choose.

Solvbeat vs Qualys & Tenable: enterprise power, smaller price

2 September 2026

Qualys and Tenable are the enterprise heavyweights of vulnerability management. Here's how a small business gets most of the value without the weight — or the quote.

Solvbeat vs UpGuard: do you actually need enterprise ASM?

2 September 2026

UpGuard is powerful for attack surface and third-party risk at enterprise scale — and priced for it. Here's the affordable alternative for a smaller business.

Solvbeat vs Aikido: security beyond the dev team

2 September 2026

Aikido is excellent for developers securing code and cloud. But most small businesses aren't a dev shop. Here's where Solvbeat fits instead.

Solvbeat vs Detectify: external scanning compared (2026)

2 September 2026

Detectify is a specialist in external attack surface management. Solvbeat covers the outside and the inside. Here's how to pick the right one for a smaller team.

Solvbeat vs Intruder: which fits a small business in 2026?

2 September 2026

Intruder is a strong external vulnerability scanner. But if you're a small team that also wants internal monitoring, a SOC layer and someone to actually fix things, here's how the two really compare.

Vulnerable vs. Exploitable: Why We Verify Findings Instead of Just Flagging Them

24 August 2026

Most scanners hand you a list of maybes. We run a verification pass on anything that looks exploitable, then a certified pentester reviews it before it reaches you.

Anatomy of a Real Detection: A Privilege Escalation Attempt, Caught Live

23 August 2026

A walkthrough of a real Security Center alert — from a newly created privileged account to a scheduled task built for malware staging, and how correlation turned three separate signals into one clear incident.

What a Content-Security-Policy actually does (and why 'medium risk' undersells a missing one)

17 August 2026

A missing CSP header shows up as a routine finding in most scanners. What it actually controls — which scripts a browser will trust — is closer to the last line of defence against XSS.

DNSSEC explained: what it stops, and why we finally turned it on across our own domains

17 August 2026

DNSSEC signs your DNS responses so they can't be silently forged in transit. It's been available for two decades and most domains still don't use it — here's what changed our mind, and how it actually gets turned on.

Introducing SolveBeat Shield: 29 real checks, watching your servers around the clock

6 August 2026

Most security dashboards show you green checkmarks and hope you never ask what's behind them. SolveBeat Shield shows the real detection catalog instead — 29 checks, 8 categories, no inflated numbers.

What is a Pass-the-Hash attack, and how do you catch it?

6 August 2026

A stolen login on one server can spread across your whole network without anyone cracking a password. Here's the exact signature that gives it away.

SPF, DKIM and DMARC explained: how to stop people spoofing your email

2 August 2026

Without the right DNS records, anyone can send an email that looks like it came from your company. Here's what actually stops it.

Introducing the SolveBeat Agent: security scanning from the inside

1 August 2026

External scans show what an attacker sees from outside your website. The new SolveBeat Agent goes further — installed on your own server, it checks pending patches, SSH/RDP hardening, firewall status, and more. Included free with Starter and Business plans.

How to check if your website has missing security headers (and why it matters)

21 July 2026

Security headers are one of the most overlooked parts of running a website. They cost nothing to add, take a few lines of server config, and close off entire categories of attack.

UK Cyber Essentials: what small businesses actually need to know

21 July 2026

If you've bid for a UK government contract, worked with the NHS, or been asked by a client to prove you take security seriously, you've probably run into Cyber Essentials. Here's what it actually covers, without the jargon.