The advice on a cybersecurity site can affect whether a real business stays safe or gets breached. We take that seriously. This page explains exactly how we test products, research our guides, stay independent, and correct ourselves when we get something wrong.

Our single guiding principle: be useful and honest to a small business owner who doesn’t have an IT team — even when that’s less profitable for us.

Our editorial principles

  • Independence first. Vendors cannot buy a review, a ranking, or favourable coverage.
  • Reader before revenue. We’d rather lose a commission than recommend a tool you don’t need.
  • Show our work. We cite primary sources and explain the reasoning behind our picks.
  • Plain English. If a small business owner can’t act on it, we haven’t finished writing it.
  • Kept current. Security moves fast, so our guidance is dated and refreshed.

How we test security tools

When we review a product — antivirus, EDR, a password manager, a VPN, backup, or email security — we put it through a consistent, hands-on process rather than rewriting a vendor’s marketing.

  1. We get hands-on. We buy or trial the product and set it up the way a real small business would — typically without dedicated IT staff.
  2. We use it in realistic scenarios. We test core features, run it day-to-day, and note where it helps or gets in the way.
  3. We cross-check with independent labs. Where relevant, we compare our experience with results from recognised test labs such as AV-Comparatives and AV-TEST, rather than relying on our impressions alone.
  4. We score against fixed criteria (below), so different products are judged the same way.
  5. We re-test on a schedule and when a product meaningfully changes, updating the review and its date.

What we score

Every tool review is rated against the things that actually matter to a small business:

CriterionWhat we’re asking
Protection / effectivenessDoes it actually stop the threats it claims to?
Ease of setupCan a non-technical owner get it running without help?
Day-to-day usabilityDoes it stay out of the way, or create friction for staff?
Price & valueIs it fair for a small-business budget, with transparent pricing?
SupportIs help available and useful when something breaks?
SMB fitIs it sized for a small team — not stripped-down enterprise software?

If a product is great for enterprises but wrong for a 10-person business, we’ll say so plainly.

How we research our guides

For explainer and how-to content, accuracy beats speed. We:

  • Rely on primary sources — research such as the Verizon Data Breach Investigations Report (DBIR), government surveys (e.g., the UK Cyber Security Breaches Survey), and standards bodies like NIST and CISA — rather than other blogs.
  • Attribute statistics to their original source and link out where possible.
  • Avoid disputed or poorly-sourced claims, even popular ones, and flag them when relevant.
  • Have content reviewed by someone with relevant experience before it’s published.

Editorial independence and how we make money

SMB Security HQ is funded by affiliate commissions and, where applicable, display advertising. Here’s the firewall between that and our editorial work:

  • Commissions and ad revenue never influence rankings, scores, or verdicts.
  • We disclose affiliate relationships clearly — see our Affiliate Disclosure.
  • Advertisers and affiliate partners get no review or approval over our content.
  • We recommend free or lower-cost options whenever they’re the right answer, even when they earn us nothing.

How we use AI

We use AI tools to assist with research, drafting, and editing — but every published piece is reviewed, fact-checked, and approved by a human with relevant knowledge before it goes live. We do not publish unreviewed AI output, and the editorial judgement and testing behind our recommendations are human.

Keeping content accurate and current

  • Key guides and reviews display a “last updated” date.
  • We review high-traffic and time-sensitive content at least quarterly and when the underlying product or threat changes.
  • Outdated content is updated or clearly marked.

Corrections policy

We get things wrong sometimes, and when we do, we fix them openly. If you spot an error, email [corrections@smbsecurityhq.com]. We’ll review it promptly, correct confirmed mistakes, and note significant corrections where appropriate.

Who creates our content

Our guidance is written and reviewed by people with real experience helping small businesses with IT and security. Meet the people behind it on our About and Meet the Experts pages.

Contact

Questions about our methods, or a product you’d like us to test? Email [hello@smbsecurityhq.com] — we read every message.


SMB Security HQ provides general information, not legal, financial, or professional security advice. See our Affiliate Disclosure and Privacy Policy.