Security is incredibly important for businesses across all industries. And the service industry — especially trade businesses like electrical, gas, plumbing, and field service — is no exception. Whether you’re a solo engineer or managing a growing team, you must consider the security of your business: cyber-security breaches pose a serious threat.
Whether you’re a team of one or an organisation with 100s of engineers out onsite, it’s necessary to consider the security of your business. Cyber security is of high importance and cyber security breaches pose a high threat. In fact, the official statistics from the UK Government’s Cyber Security Breaches Survey 2025 states that 43% of businesses reported having experienced any kind of cyber security breach or attack in the last 12 months. (published 19th June 2025).
Let’s take a look at what these schemes are and what other measures are available to protect companies from cyber-attacks.
Why Cyber Security Is Critical for Trades & Small Businesses
- According to the UK Government’s Cyber Security Breaches Survey, 43% of businesses reported a cyber breach or attack in the past 12 months (2025), which has increased from 39% (2022).
- Many SMEs still assume they are “too small to be a target.” In reality, smaller businesses are often more vulnerable, since they may not have the same level of security as larger firms.
- A breach can cause a serious ripple effect: downtime, unexpected costs, damage to reputation, and loss of trust from clients — all of which can hit a small business very hard.
- At Clik, we’re deeply familiar with how trade businesses operate. We understand that when your systems go down or data is compromised, it doesn’t just cause technical issues — it disrupts real-world jobs, customer relationships, and profitability.
What is Information Security?
InfoSec refers to the set of practices, processes, and tools designed to protect your sensitive business information. That includes preventing unauthorised access, guarding against misuse, and ensuring data isn’t destroyed or disrupted.
One of the most robust ways to manage InfoSec is via an Information Security Management System (ISMS).
Information Security Management Systems (ISMS)
So how do you protect your information? Let’s look at information security management systems and how they can better prepare you and your business.
What is an ISMS?
- An ISMS is a formal framework: a set of policies and procedures that define how to protect critical business assets
- It typically includes: an information security policy, risk-treatment plan, an inventory of your key information assets, a risk assessment, and clear processes and workflows.
- Many businesses aim for ISO/IEC 27001 certification — this standard formalises how to implement and maintain an ISMS following “best practices.”
These policies set out the process of safeguarding assets and how these activities are to be managed. Typically, an ISMS contains:
- Information security policy
- Risk treatment plan
- Inventory of important information assets
- Assessment of risks to those assets
- ISMS manual
- A comprehensive suite of processes, policies, procedures and work instructions
ISO/IEC 27001:2022
ISO/IEC 27001 is an international standard for ISMS. It defines requirements that must be met in order to comply and be certified. Complying with ISO/IEC 27001 demonstrates that a business has put a system in place that respects all the best practices set out by the standard.
This International Standard adopts the ‘Plan-Do-Check-Act’ (PDCA) model, which can assist with structuring ISMS processes in line with ISO/IEC 27001. This procedure acts as a cycle to ensure there is continuous improvement at each stage.

How to Identify Weaknesses: Penetration Testing
Penetration (or “pen”) testing is essentially controlled, ethical hacking. It helps you find vulnerabilities before a real attacker does.
Key stages of penetration testing:
- Planning and intelligence gathering
- Identifying potential entry points
- Simulating attacks
- Reporting and mitigation
The goal is clear: identify weak spots, plug them, and make sure your system stays resilient.
What is Penetration Testing?
External network penetration testing, or pen testing, refers to the process of identifying vulnerabilities within a network or system. This is carried out through a series of authorised, simulated cyberattacks to find and purposely exploit any issues with the computer system’s security.
This ethical hacking method is carried out in a series of stages:
- Planning and gathering information.
- Pre-attack to identify any potential entry points.
- Attempt a simulated attack.
- Results and findings are fed back to the company’s IT/security team.
You can also choose the level of penetration testing to suit you and your business.

Cyber Essentials
Next, let’s take a look at the Cyber Essentials scheme and how it can help your business better prepare for security breaches.
What is Cyber Essentials?
Cyber Essentials is a Government-backed scheme that prepares your business for potential cyber-attacks.
It’s suitable for businesses of any size. So whether you’re a large organisation or SME (small and medium-sized enterprises), you’ll be able to utilise this scheme to fortify your IT security.
There are two levels of certification available: Cyber Essentials and Cyber Essentials Plus. The first option is a self-assessment to protect you from some of the most common types of cyber-attacks. Cyber Essentials Plus provides the protection you need from attacks as well as hands-on technical verification.

Why are Cyber Essentials and Cyber Security Important?
Cyber Essentials provides certified cyber security for your business. Reflecting on your current IT security and potential cyber risks can have many benefits.
The primary benefit is it brings attention to vulnerabilities that you need to strengthen to prevent future attacks. You can then decide how to take the necessary precautions to make sure these vulnerabilities don’t get exploited by hackers.
Cyber security is vital in our technology-driven era. Nowadays there are more potential threats and more need for safeguarding precautions. Cyber security protects your valuable data from these growing threats and reassures your customers that their data is safe with you.
Cyber Security and Clik
Here at Clik, we don’t just talk about security — we act on it.
- In August 2023, we achieved ISO 27001 compliance and successfully transitioned to ISO 27001:2022 in May 2025.
- We hold Cyber Essentials and Cyber Essentials Plus accreditations.
- We run regular pen-testing: for example, we conducted a level 2 external infrastructure penetration test, plus security testing on our mobile app Clik Cert (Field).
- Results? No critical or high-risk vulnerabilities found. We continue to review and improve our security measures.
What You Can Do Next
- Decide who in your business is responsible for cyber-security oversight.
- Run a simple risk assessment (what data you hold, how it’s accessed, where the weak points are).
- Roll out a written but simple cyber-policy covering mobile devices, passwords, and suspicious activity.
- Update all software, enable MFA on key systems.
- Train your team (office and field) regularly on cyber risks.
- Set up regular, secure backups.
- Ensure your field software (like Clik Cert) is used securely — and enforce SSL for remote access (Clik Remote).
- Review your subcontractors’ cyber process (ask for evidence).
- Check if cyber-insurance is right for you, and what is required.
- Revisit and review quarterly: evaluate incidents, near-misses, and training feedback.


For even more information about security and the methods mentioned in this blog, check out the further reading list below.
Further Reading:
- IT Governance: What an ISMS is and 5 reasons your organisation should implement one
- IT Governance: External Network Penetration Testing
- NCSC: About Cyber Essentials
This post was first published in September 2023 and has been edited with updated information.