How Focus Technology Europe cut client risk scores from 85%+ to under 20% with usecure

Published on
September 25, 2026
Read time
5 mins

How Focus Technology Europe cut client risk scores from 85%+ to under 20% with usecure

Publicado el
September 25, 2026
Tiempo de lectura
5 min de lectura
Categoría
5 min de lectura

How Focus Technology Europe cut client risk scores from 85%+ to under 20% with usecure

Publicado el
25 Sep 26

Table of contents

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

KEY TAKEAWAYS

  • Insurance questionnaires and Cyber Essentials turned policy management from a nice-to-have into something Focus Technology Europe’s clients increasingly needed to evidence.
  • Focus had previously paid £5,000 for a single professionally written contract. With clients typically needing five to ten policies, usecure gave the MSP a far more scalable way to provide them.
  • Alongside policy management, Focus says average client risk scores have fallen from above 85% to below 20%. usecure is now part of its standard stack for every new customer.

No policies, no certification, no contract: how Focus Technology Europe made policy management part of its standard stack

As insurers and Cyber Essentials started asking for evidence, Focus Technology Europe needed a better way to help clients get their policies in order.

Focus Technology Europe is an eight-person MSP based in Cornwall, supporting businesses across hospitality, professional services, and manufacturing.

For many of those customers, Focus effectively operates as their IT department. That means the relationship goes beyond keeping systems running. The team works with clients strategically, helping make sure their technology supports where the business is going.

And increasingly, those conversations started including something many smaller businesses had previously overlooked: policies.

Cyber insurers wanted more evidence of how businesses managed security risk. Cyber Essentials required organizations to demonstrate that appropriate processes and controls were actually in place.

The problem was that many clients had very little to show.

When the policy question suddenly mattered

Before those requirements became more common, Andrew Davenport, CEO and founder of Focus Technology Europe, says policy management among clients was often ad hoc.

Some had no policies at all. Others had documents that had not been reviewed for years or templates downloaded from the internet that were written for another country or did not properly fit the business.

Then an insurer or assessor would ask for evidence.

“We either got nothing at all, or they were suddenly on the back foot with absolutely no material to send us whatsoever.”

Clients would turn to Focus and ask whether they could simply use the MSP’s own policies.

But a security policy is not something another business can copy, change the company name, and consider finished. It needs to reflect how that particular organization operates.

The stakes also went beyond passing an assessment.

Andrew recalls one client pursuing Cyber Essentials because important contracts depended on it. The client initially viewed certification as little more than a box-ticking exercise, but Focus would not sign off controls without the evidence behind them.

As Andrew puts it:

“If you don't have the policies or you don't have the certification, you just don't get the contract.”

What had once been an administrative afterthought was becoming tied directly to a client’s ability to win business.

Finding a way to make policy management scalable

Focus already understood the work involved.

As an ISO 27001-certified business, it had gone through the process of developing policies internally. When it had previously used specialist legal support, one professionally written contract alone cost around £5,000.

That was one document.

Andrew says a typical Focus client might use five to ten policies. Asking every small or midsize customer to commission those individually was unlikely to work.

Downloading generic templates from the internet was not a good alternative either.

Focus needed something it could make part of its managed service: straightforward for its own team to administer, affordable enough to roll out across clients, and useful beyond policy management alone.

The MSP evaluated several options before choosing usecure.

Usability mattered because Focus did not want technicians spending their time administering another complicated product. Price mattered because the service had to make sense for clients. And the team wanted a vendor they could build a long-term relationship with.

For Andrew, usecure delivered on all three.

“Not just because of the quality of the product, the simplicity of the interface, the simplicity of onboarding the customers and the really brilliant price point, but actually usecure came across as the kind of company we wanted to work with.”

Focus was confident enough in the platform to start using it internally too.

Policies were the starting point, not the whole story

For many Focus clients, access to ready-to-use policy templates was the initial driver.

Instead of searching online or starting every policy from scratch, they could use uPolicy to distribute policies and record that employees had read and acknowledged them.

But the wider usecure platform gave Focus another part of the security stack it wanted to standardize: the human side of cybersecurity.

Security awareness training, phishing simulations, and credential exposure monitoring could sit alongside policy management rather than being delivered through separate tools.

That mattered because some customers were initially skeptical about awareness training.

Andrew says even some of Focus Technology Europe’s more “old school and cynical” users changed their view once they started using it.

“We really, really enjoy the videos and the animations. They're actually really fun to watch and the quizzes make sense. We actually understand what they're talking about.”

Focus also uses the reporting internally, helping demonstrate employee training completion as part of its own ISO 27001 audit trail.

Because its technicians use the same platform themselves, they can support customers from experience rather than simply reselling another product.

From above 85% risk to below 20%

The clearest result for Focus has come from watching client risk levels change.

Andrew says customers were averaging above an 85% risk factor when they started, reflecting gaps in security knowledge across their user bases.

After introducing ongoing awareness training, he saw those scores fall quickly.

“We have had a great time seeing our customers going from average above 85% risk factor down to less than 20 over a really short period of time.”

The reporting gives Focus something tangible to take back into regular client meetings.

Rather than simply saying training has been completed, the team can show how risk is changing over time, identify users who may need additional support, and adjust training when new gaps appear.

For clients, that makes the progress visible.

For Focus, it turns security awareness into an ongoing managed conversation rather than an annual checkbox.

Thousands in potential policy costs avoided

There is also a practical cost and time benefit to policy management.

Andrew says Focus clients commonly need between five and ten policies.

His own experience showed how expensive creating those documents individually could become: one specialist legal contract cost Focus around £5,000.

That does not mean every policy would otherwise cost £5,000, but it demonstrates the economics MSPs and their customers can face when every document has to be commissioned separately.

With the policy library already available through usecure, Focus no longer needs to send clients out to source each document individually or spend hours finding templates of uncertain quality.

As Andrew puts it:

“usecure does all the heavy lifting, does all the hard work. It saves hours of time and an awful lot of money.”

In the standard stack from day one

Focus has now gone a step further than offering usecure as an optional add-on.

It is part of the MSP’s standard technology stack.

Every new customer gets it.

That fits the way Focus has designed its wider service around Cyber Essentials: putting the core tools and controls in place before a customer arrives asking for help with certification.

It also keeps the proposition simple.

Instead of deciding which customers should receive security awareness, policy management, phishing simulations, or exposure monitoring, Focus can establish the same baseline across its new customer base.

And there is room to build more service around it.

For customers without internal HR resources, Focus is developing a monthly reporting service where its team can provide reports and follow up with employees who have not completed assigned security awareness training.

The platform becomes the foundation. Focus builds the managed service around it.

“Seriously, just do it”

Andrew’s recommendation to other MSPs is not particularly complicated.

At a recent industry event, he found himself standing next to another MSP owner at the usecure stand.

He effectively took over the conversation.

“I said, seriously, just do it. You won't look back.”

For Focus Technology Europe, the value comes from solving several problems through the same service.

Clients have policies ready when insurers, auditors, or certification requirements demand them. Employees receive ongoing security awareness training. Focus gets reporting it can use in client conversations. And the whole platform can be deployed consistently as part of the MSP’s standard stack.

Policy management may have been what pushed many clients toward the service.

What Focus ended up with was a more scalable way to manage the human side of security across its customer base.

Make policy management easier to scale

For MSPs, policy management becomes much harder when every customer starts from scratch.

usecure brings policy distribution and acknowledgment, security awareness training, phishing simulations, and credential exposure monitoring into one platform built for MSPs.

See how usecure can help you build human risk management into your standard client service without adding unnecessary administration.

Subscribe to newsletter

BOOK A DEMO

See usecure in action

A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.

Get a Demo

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

No policies, no certification, no contract: how Focus Technology Europe made policy management part of its standard stack

As insurers and Cyber Essentials started asking for evidence, Focus Technology Europe needed a better way to help clients get their policies in order.

Focus Technology Europe is an eight-person MSP based in Cornwall, supporting businesses across hospitality, professional services, and manufacturing.

For many of those customers, Focus effectively operates as their IT department. That means the relationship goes beyond keeping systems running. The team works with clients strategically, helping make sure their technology supports where the business is going.

And increasingly, those conversations started including something many smaller businesses had previously overlooked: policies.

Cyber insurers wanted more evidence of how businesses managed security risk. Cyber Essentials required organizations to demonstrate that appropriate processes and controls were actually in place.

The problem was that many clients had very little to show.

When the policy question suddenly mattered

Before those requirements became more common, Andrew Davenport, CEO and founder of Focus Technology Europe, says policy management among clients was often ad hoc.

Some had no policies at all. Others had documents that had not been reviewed for years or templates downloaded from the internet that were written for another country or did not properly fit the business.

Then an insurer or assessor would ask for evidence.

“We either got nothing at all, or they were suddenly on the back foot with absolutely no material to send us whatsoever.”

Clients would turn to Focus and ask whether they could simply use the MSP’s own policies.

But a security policy is not something another business can copy, change the company name, and consider finished. It needs to reflect how that particular organization operates.

The stakes also went beyond passing an assessment.

Andrew recalls one client pursuing Cyber Essentials because important contracts depended on it. The client initially viewed certification as little more than a box-ticking exercise, but Focus would not sign off controls without the evidence behind them.

As Andrew puts it:

“If you don't have the policies or you don't have the certification, you just don't get the contract.”

What had once been an administrative afterthought was becoming tied directly to a client’s ability to win business.

Finding a way to make policy management scalable

Focus already understood the work involved.

As an ISO 27001-certified business, it had gone through the process of developing policies internally. When it had previously used specialist legal support, one professionally written contract alone cost around £5,000.

That was one document.

Andrew says a typical Focus client might use five to ten policies. Asking every small or midsize customer to commission those individually was unlikely to work.

Downloading generic templates from the internet was not a good alternative either.

Focus needed something it could make part of its managed service: straightforward for its own team to administer, affordable enough to roll out across clients, and useful beyond policy management alone.

The MSP evaluated several options before choosing usecure.

Usability mattered because Focus did not want technicians spending their time administering another complicated product. Price mattered because the service had to make sense for clients. And the team wanted a vendor they could build a long-term relationship with.

For Andrew, usecure delivered on all three.

“Not just because of the quality of the product, the simplicity of the interface, the simplicity of onboarding the customers and the really brilliant price point, but actually usecure came across as the kind of company we wanted to work with.”

Focus was confident enough in the platform to start using it internally too.

Policies were the starting point, not the whole story

For many Focus clients, access to ready-to-use policy templates was the initial driver.

Instead of searching online or starting every policy from scratch, they could use uPolicy to distribute policies and record that employees had read and acknowledged them.

But the wider usecure platform gave Focus another part of the security stack it wanted to standardize: the human side of cybersecurity.

Security awareness training, phishing simulations, and credential exposure monitoring could sit alongside policy management rather than being delivered through separate tools.

That mattered because some customers were initially skeptical about awareness training.

Andrew says even some of Focus Technology Europe’s more “old school and cynical” users changed their view once they started using it.

“We really, really enjoy the videos and the animations. They're actually really fun to watch and the quizzes make sense. We actually understand what they're talking about.”

Focus also uses the reporting internally, helping demonstrate employee training completion as part of its own ISO 27001 audit trail.

Because its technicians use the same platform themselves, they can support customers from experience rather than simply reselling another product.

From above 85% risk to below 20%

The clearest result for Focus has come from watching client risk levels change.

Andrew says customers were averaging above an 85% risk factor when they started, reflecting gaps in security knowledge across their user bases.

After introducing ongoing awareness training, he saw those scores fall quickly.

“We have had a great time seeing our customers going from average above 85% risk factor down to less than 20 over a really short period of time.”

The reporting gives Focus something tangible to take back into regular client meetings.

Rather than simply saying training has been completed, the team can show how risk is changing over time, identify users who may need additional support, and adjust training when new gaps appear.

For clients, that makes the progress visible.

For Focus, it turns security awareness into an ongoing managed conversation rather than an annual checkbox.

Thousands in potential policy costs avoided

There is also a practical cost and time benefit to policy management.

Andrew says Focus clients commonly need between five and ten policies.

His own experience showed how expensive creating those documents individually could become: one specialist legal contract cost Focus around £5,000.

That does not mean every policy would otherwise cost £5,000, but it demonstrates the economics MSPs and their customers can face when every document has to be commissioned separately.

With the policy library already available through usecure, Focus no longer needs to send clients out to source each document individually or spend hours finding templates of uncertain quality.

As Andrew puts it:

“usecure does all the heavy lifting, does all the hard work. It saves hours of time and an awful lot of money.”

In the standard stack from day one

Focus has now gone a step further than offering usecure as an optional add-on.

It is part of the MSP’s standard technology stack.

Every new customer gets it.

That fits the way Focus has designed its wider service around Cyber Essentials: putting the core tools and controls in place before a customer arrives asking for help with certification.

It also keeps the proposition simple.

Instead of deciding which customers should receive security awareness, policy management, phishing simulations, or exposure monitoring, Focus can establish the same baseline across its new customer base.

And there is room to build more service around it.

For customers without internal HR resources, Focus is developing a monthly reporting service where its team can provide reports and follow up with employees who have not completed assigned security awareness training.

The platform becomes the foundation. Focus builds the managed service around it.

“Seriously, just do it”

Andrew’s recommendation to other MSPs is not particularly complicated.

At a recent industry event, he found himself standing next to another MSP owner at the usecure stand.

He effectively took over the conversation.

“I said, seriously, just do it. You won't look back.”

For Focus Technology Europe, the value comes from solving several problems through the same service.

Clients have policies ready when insurers, auditors, or certification requirements demand them. Employees receive ongoing security awareness training. Focus gets reporting it can use in client conversations. And the whole platform can be deployed consistently as part of the MSP’s standard stack.

Policy management may have been what pushed many clients toward the service.

What Focus ended up with was a more scalable way to manage the human side of security across its customer base.

Make policy management easier to scale

For MSPs, policy management becomes much harder when every customer starts from scratch.

usecure brings policy distribution and acknowledgment, security awareness training, phishing simulations, and credential exposure monitoring into one platform built for MSPs.

See how usecure can help you build human risk management into your standard client service without adding unnecessary administration.

Suscríbete al boletín

Suscríbete al boletín

Al hacer clic en Suscríbete, confirmas que aceptas nuestros términos y condiciones.
¡Gracias! Tu envío ha sido recibido!
¡Ups! Algo salió mal al enviar el formulario.

Descubre cómo las empresas de servicios profesionales reducen el riesgo humano con usecure

Descubre cómo los equipos de TI de servicios profesionales usan usecure para proteger los datos confidenciales de sus clientes, mantener el cumplimiento normativo y salvaguardar su reputación, sin interrumpir el trabajo facturable.

Related posts

Explore more insights, updates, and resources from usecure.