Skip to content
The UK Manufacturing Cyber Risk Gap, Explained for Financial Advisors in UK
AI & Automation12 min read

The UK Manufacturing Cyber Risk Gap, Explained for Financial Advisors in UK

Scult Team
12 min read

Nearly a third of UK manufacturers were hit by a cyber incident in the past year and half have no response plan, and that gap has direct implications for financial advisors.

Direct answer: Nearly a third of UK manufacturers were hit by a cyber incident in the past year, and half of them had no incident response plan in place when it happened. For financial advisors in the UK, this matters on two fronts at once — many of your SME clients sit in exactly this exposed position, and your own advisory practice shares the same lean-team, data-rich profile that makes manufacturers such an easy target.

The figures come from the Make UK cybersecurity report, published in August 2026, which surveyed manufacturers across the UK about their exposure to and preparedness for cyber incidents. The headline finding — close to one in three manufacturers hit within twelve months, and half of those firms operating without any documented incident response plan — is not a niche industrial statistic. It describes a structural gap: attacks are already common, but the organisational muscle to respond to them methodically is missing in roughly half of the businesses affected. For financial advisors, this is not background noise about a sector you don't touch. Manufacturing SMEs are a meaningful slice of the UK business client base that advisors serve on pensions, succession, business protection, and commercial lending advice, and the same operational fragility documented in the Make UK report tends to show up in adjacent professional services firms, including advisory practices themselves. We won't invent a precise percentage of advisory clients who are manufacturers, or a cost-per-incident figure, because the report doesn't provide one for this specific angle — but the general pattern is clear enough to act on.

What makes this particular piece of research worth sitting with is that it isn't describing a hypothetical threat. It's describing something that has already happened to close to a third of a major UK industrial sector within a single year, and it's describing an internal readiness gap that has nothing to do with the sophistication of the attackers and everything to do with basic organisational preparation. That distinction matters for how advisors should read the story: this is not primarily a story about hackers getting cleverer. It's a story about ordinary UK businesses — the kind advisors sit across the table from every week — not having written down what happens on the day something goes wrong.

What the Make UK Cybersecurity Report Actually Found

The report's two numbers work together to describe a specific kind of risk. The first — nearly a third of manufacturers experiencing a cyber incident in the past year — tells you that attacks against this sector are no longer occasional events; they are a routine part of operating a manufacturing business in the UK. The second — half lacking an incident response plan — tells you that when those incidents happen, roughly half the affected businesses are improvising rather than executing a rehearsed process.

An incident response plan, in the practical sense the report is pointing at, is not a compliance document that sits in a drawer. It's an operational playbook: who gets notified first, which systems get isolated, how customers and suppliers are informed, what regulatory notifications are triggered, and who is authorised to make decisions under pressure. Businesses without one don't just recover more slowly — they tend to make costlier decisions in the first 24-48 hours, because those decisions are being made from scratch, under stress, by people who haven't rehearsed them.

Why Manufacturing Specifically

Manufacturing businesses are attractive targets for a reason that has nothing to do with the sector being careless: they combine valuable intellectual property (designs, supplier contracts, pricing data) with operational technology that is often older, harder to patch, and directly tied to revenue-generating machinery. A ransomware incident that locks up a design server or a production scheduling system doesn't just cost data — it stops the line. That combination of high value and high fragility is exactly why the incident rate is elevated, and exactly why half the response gap matters so much: there's less margin for improvisation when a stopped production line is burning cash by the hour.

What an Unprepared Response Actually Looks Like

It's worth spelling out concretely what "no incident response plan" means in practice, because the phrase can sound abstract until you picture the actual sequence of events. A business without a plan typically discovers a problem later than a prepared one would, because nobody was specifically watching for it. Once discovered, the first hours are spent figuring out who should be told, rather than telling them, because no one was pre-designated. Decisions about whether to shut down affected systems get made by whoever happens to be senior and available, rather than by someone with the authority and the technical picture to make that call quickly. Communication to staff, customers, and suppliers happens late and inconsistently, because there's no agreed message or sequence for who hears what and when. None of this requires the attacker to be especially sophisticated — a fairly ordinary phishing compromise or ransomware attempt can turn into a multi-day disruption purely because the internal response was improvised rather than rehearsed.

This is the practical reality sitting behind the Make UK statistic, and it's the same reality that plays out in any UK SME — manufacturing or otherwise — that hasn't done this preparation work. For an advisor, understanding this sequence is useful context for two different conversations: the one you might have with a manufacturing client about their own exposure, and the one you should be having internally about your own advisory practice.

Why This Matters Specifically to Financial Advisors in the UK

There are two separate reasons a financial advisor should care about a manufacturing sector statistic, and it's worth separating them clearly.

First, your client book. If any meaningful share of your clients run manufacturing SMEs — and for advisors working with business owners across the Midlands, the North West, or other UK manufacturing hubs, that share is often substantial — this data describes a live risk sitting inside their businesses right now, whether or not it has surfaced in your conversations with them. Business protection advice, succession planning, and commercial lending guidance all assume a going-concern business with a stable valuation. A cyber incident with no response plan behind it can compress that valuation overnight, disrupt the continuity assumptions behind a succession plan, and trigger loan covenant reviews if lenders start asking about operational resilience. Advisors who never raise the topic are leaving a real, quantifiable planning gap unaddressed.

Second, your own practice. Financial advisory firms hold exactly the kind of asset that makes them targets in their own right: client financial records, pension details, identity documents, and payment instructions. Many UK advisory practices are lean operations — a handful of advisors, a small admin team, a website and portal built years ago and rarely revisited. That is structurally the same profile as the manufacturing SMEs in the Make UK report: valuable data, real exposure, and — very plausibly, though the report doesn't measure advisory firms directly — a similar likelihood of having no rehearsed incident response plan. The honest reading of this data isn't "manufacturers have a problem." It's "lean, data-holding UK businesses have a problem, and manufacturing happened to be the sector measured."

There is also a third, less obvious angle: trust as a differentiator. Financial advice is a relationship business built on confidence that a client's financial life is handled carefully. A firm that can speak plainly and specifically about how it protects client data — because it has actually done the work rather than assumed a website provider handled it — has a genuine, quiet advantage over firms that have never had the conversation internally. In a market where clients are increasingly aware of data breaches through general news coverage, being able to answer "how do you protect my information" with something more specific than "our provider handles that" is a small but real point of difference.

What Changes in Practice for an Advisory Firm's Website and Client Systems

Once you take the underlying pattern seriously, several concrete things change about how you should be thinking about your own digital footprint.

Client Portals and Document Exchange

Most advisory practices now run some form of client portal for document exchange, plan reviews, or e-signatures. These portals are a direct line to financial data, and password-only access is a weak point that's inexpensive to fix. Stronger authentication — including the kind of biometric login patterns covered in Biometric Authentication in Mobile Apps: Face ID, Fingerprint, and Beyond — meaningfully raises the cost of unauthorised access without adding friction for legitimate clients who are already used to Face ID and fingerprint unlock on their own phones. If your portal still relies on a shared login or a static password reset flow, that's the first thing worth revisiting.

Monitoring That Doesn't Depend on Someone Noticing

The "half lack a response plan" statistic usually traces back to the same root cause: nobody is watching continuously, so the incident is discovered late, by which point the response is reactive rather than planned. A three-person or ten-person advisory practice cannot staff a 24/7 security operations centre, and doesn't need to. What it can do is put automated monitoring in place — systems that watch for unusual login patterns, bulk data exports, or configuration changes and raise an alert immediately, rather than relying on a human to spot something wrong days later.

A Documented, Rehearsed Process

Even a short, specific plan — who is contacted first, which systems get isolated, how clients are notified, what the FCA notification obligations are — closes most of the gap the Make UK report describes. The plan matters less for its polish and more for the fact that it exists and has been walked through once before it's needed under pressure.

Backups and Recovery Testing

A response plan is only as good as the recovery it enables. If client records, plan documents, or portal data are backed up but the backup has never actually been restored and tested, there's a real chance it fails at the exact moment it's needed. This is a cheap, mechanical thing to fix — schedule a periodic test restore — but it's routinely skipped precisely because it doesn't feel urgent until the day it is. For an advisory practice, this matters more than for many other small businesses, because the data at stake (client financial plans, identity documents, pension transfer records) is often irreplaceable if lost rather than merely inconvenient to regenerate.

Where AI Agents and Automation Fit Into Closing the Gap

This is the part of the picture that's changed meaningfully in the last two years, and it's directly relevant to an advisory practice's size and budget constraints. Building a full internal security team is not realistic for most UK advisory firms. But automating the specific, repeatable parts of monitoring and response is now genuinely accessible.

An AI agent can sit across your client portal, email system, and file storage, watching for the specific patterns that precede or accompany an incident — an account logging in from an unusual location, a large batch of client files being downloaded outside normal hours, repeated failed login attempts against admin accounts — and take a defined first action automatically: lock the account, alert a named person, or trigger a pre-written notification sequence. That's the practical difference between the roughly one-third of manufacturers who got hit and the roughly half of those who had nothing to fall back on. Automation doesn't replace judgment, but it removes the delay between "something is wrong" and "someone knows something is wrong," which is where most of the damage in an under-prepared response actually happens.

This is exactly the territory covered by Scult's AI Agents & Automation service — building the specific monitoring agents, alerting workflows, and response automations that fit a firm's actual systems, rather than selling a generic security suite that doesn't match how a small advisory practice actually operates. For firms further along, the same underlying approach extends into broader operational automation — see AI Integration Services for Businesses for how monitoring agents typically connect into a firm's existing CRM, email, and document systems rather than sitting as a separate tool nobody checks.

What Good Monitoring Actually Covers

In practice, a well-scoped monitoring setup for an advisory firm tends to focus on a small number of high-value signals rather than trying to watch everything at once. That usually means: login attempts from unfamiliar locations or devices against the client portal and email accounts; unusually large or unusually timed data exports or downloads from the portal or document store; repeated failed authentication attempts against admin-level accounts; and changes to account permissions or forwarding rules on email, which is a common technique used to quietly intercept correspondence. None of these signals require deep technical expertise to define — they're the kind of thing a firm's own admin team can specify once, in plain language, and then have an agent watch for continuously. The value isn't in the sophistication of the detection; it's in the fact that it never stops watching, never forgets, and never gets busy with something else.

What to Do About It: A Practical Sequence

The Make UK data is a prompt to act, not a reason to panic. A sensible sequence for a UK financial advisory firm looks like this:

  1. Audit your own exposure first. Know what client data lives where — portal, CRM, email, shared drives — before deciding what to protect.
  2. Write the response plan, even a short one. A one-page document naming who does what in the first hour of a suspected incident closes most of the "half with no plan" gap on its own.
  3. Automate detection, not just documentation. A written plan only helps if someone is alerted in time to use it — this is where monitoring agents earn their keep.
  4. Raise the topic with manufacturing clients. A short, non-alarming conversation about business continuity and cyber resilience fits naturally into an existing succession or protection planning review.
  5. Build rather than bolt on, where it matters. For firms whose client-facing systems are custom-built or heavily customised, a purpose-built monitoring and response layer tends to outperform a generic add-on tool — the kind of build described in AI Software Development: Complete Guide to Building AI-Powered Applications in 2026.

Pricing Context

The cost of this kind of work varies with scope, but it typically maps onto Scult's standard service tiers rather than requiring a bespoke enterprise security budget:

Tier Typical scope for this scenario
Essential — $1,000 A focused monitoring agent on one system (e.g., portal login alerts) plus a documented response plan
Growth — $2,000 Monitoring and automated alerts across portal, email, and document storage, with defined escalation workflows
Enterprise — $4,000+ Full automation layer across all client-facing systems, integrated with existing CRM and compliance workflows, with ongoing tuning

Most single-office UK advisory practices addressing this gap for the first time fall into the Essential or Growth range; Enterprise scope tends to suit multi-office practices or firms with more complex system integrations.

Key Takeaways

  • Nearly a third of UK manufacturers had a cyber incident in the past year, and half of those had no incident response plan — a gap, not a one-off statistic (Make UK cybersecurity report, 2026).
  • Financial advisors are affected two ways: through manufacturing clients whose valuations and continuity plans this touches, and through their own firms, which share the same lean-team, data-rich exposure profile.
  • A written, rehearsed incident response plan closes most of the preparedness gap even before any new technology is added.
  • Automated monitoring agents close the detection-delay problem that turns a manageable incident into a damaging one.
  • Stronger client portal authentication, including biometric options, is a low-friction way to reduce one of the most common entry points.
  • This is scoped, tier-based work — most firms start at the Essential or Growth level, not a full enterprise security overhaul.

Closing this gap doesn't require becoming a security company overnight — it requires a short, honest audit and a few targeted automations built around how your practice actually works. If you want help figuring out where to start, book a meeting with our team.

Frequently Asked Questions

What did the Make UK cybersecurity report actually find?

The Make UK cybersecurity report, published in 2026, found that nearly a third of UK manufacturers experienced a cyber incident in the past year, and that half of the affected businesses had no incident response plan in place at the time. Those two figures together describe both a high incident rate and a significant preparedness gap in the sector.

What counts as a "cyber incident" in this context?

Generally this covers anything from a ransomware attack or data breach to unauthorised system access or a significant phishing compromise that affects business systems or data. The report doesn't break down the exact mix of incident types, so treat the headline figure as covering the broad category rather than one specific attack type.

Why does a manufacturing-sector report matter to UK financial advisory firms?

It matters for two reasons: many advisory firms serve manufacturing SME clients whose business value and continuity plans this risk touches directly, and advisory firms themselves share a similar operational profile — lean teams, valuable client data, and often under-invested security — that makes the same gap plausible in their own practices.

How many of a typical advisor's SME clients might be manufacturers?

There's no universal figure — it depends entirely on an individual practice's client base and region. Advisors working with business owners in traditional UK manufacturing regions should assume this is a meaningful share of their book and check rather than assume it's negligible.

What is an incident response plan and why do half of manufacturers lack one?

An incident response plan is a documented, rehearsed process covering who is notified first, which systems are isolated, how stakeholders are informed, and what regulatory steps follow a cyber incident. Many SMEs lack one simply because it's never been prioritised against day-to-day operational demands until an incident forces the issue.

How does a cyber incident affect a manufacturing client's business valuation?

An incident without a rehearsed response can extend downtime, damage supplier and customer relationships, and raise questions from lenders or buyers about operational resilience — all of which can compress a valuation. The size of the effect varies by business and isn't something we'd put a specific figure on without case-specific detail.

Should financial advisors ask manufacturing clients about their cyber posture?

Yes, as a natural extension of existing business protection, succession, and continuity planning conversations. It doesn't need to be framed as a technical audit — a short question about whether the client has a documented response plan is often enough to open a useful conversation.

What is the role of cyber risk in succession planning for manufacturing SMEs?

Succession plans assume a stable, transferable business. An unresolved cyber vulnerability, or an incident with no clear response history, can complicate a handover or sale by raising due-diligence concerns for the incoming owner or lender.

Can a cyber incident affect a manufacturer's ability to secure financing?

It can. Lenders increasingly ask about operational resilience as part of due diligence, and an incident with no documented response can raise questions about a business's overall risk management, which may affect loan terms or approval.

How does cyber risk exposure affect insurance underwriting for manufacturing clients?

Insurers assessing cyber or business interruption cover typically look for evidence of basic preparedness, including an incident response plan. Its absence can affect premiums or coverage terms, though exact underwriting criteria vary by insurer.

Do financial advisory firms in the UK face similar cyber exposure to manufacturers?

Structurally, yes — both tend to be lean organisations holding valuable, sensitive data with limited dedicated security staff. The Make UK report measured manufacturers specifically, but the underlying pattern of exposure plausibly extends to any similarly resourced UK SME sector, advisory practices included.

What data do financial advisory firms hold that makes them targets?

Client financial records, pension and investment details, identity documents used for verification, and payment instructions are all high-value targets, since they can be used directly for fraud or identity theft.

What regulatory obligations do UK financial advisors have around cyber security?

UK advisory firms regulated by the FCA are expected to maintain adequate systems and controls, including around operational resilience and data protection, and to notify affected parties and regulators promptly in the event of a significant breach. Specific obligations depend on firm size and permissions, so this should be checked against current FCA guidance for your firm.

What happens if an advisory firm suffers a data breach affecting client financial data?

Beyond the immediate operational disruption, a firm typically faces regulatory notification requirements, potential client communication obligations, and reputational impact. Having a rehearsed response plan significantly reduces how chaotic and costly that process becomes.

How does GDPR intersect with a cyber incident at an advisory firm?

Under UK GDPR, a personal data breach that poses a risk to individuals generally must be reported to the ICO within 72 hours of the firm becoming aware of it, and affected individuals may need to be notified directly in higher-risk cases. This is a legal requirement independent of any internal incident response plan, which is exactly why having a plan that includes this step matters.

What is an AI agent in the context of cyber incident response?

An AI agent, in this context, is an automated system that continuously monitors specific signals — logins, file access, unusual account activity — and takes a predefined action, such as sending an alert or locking an account, without requiring a person to be watching in real time.

How can AI agents help detect a cyber incident earlier?

By watching for patterns continuously rather than relying on a person to notice something unusual, agents can flag suspicious activity within minutes rather than days, which is often the difference between a contained incident and a damaging one.

Can AI automation replace a full incident response plan?

No — automation handles detection and first-response actions, but the plan itself still needs defined ownership, communication steps, and regulatory awareness. Automation makes the plan more effective; it doesn't substitute for having one.

What does Scult's AI Agents & Automation service actually do?

It covers designing and building automated monitoring, alerting, and workflow agents tailored to a firm's actual systems — client portals, CRM, email, document storage — rather than deploying a generic off-the-shelf security tool that doesn't match how the practice operates day to day.

How long does it take to build an automated monitoring and alerting system?

Timelines depend on scope, but a focused, single-system monitoring agent (for example, portal login alerts) is typically a matter of weeks rather than months, while a full multi-system automation layer takes longer.

What does a basic automated security alert setup typically cost?

For a single advisory practice addressing one system, this kind of work typically falls under Scult's Essential tier, starting around $1,000, though exact scope changes the final cost.

What falls under the Essential tier versus Growth versus Enterprise for this kind of work?

Essential ($1,000) typically covers one monitoring agent and a documented response plan. Growth ($2,000) extends monitoring and alerting across multiple systems with defined escalation steps. Enterprise ($4,000+) covers a full automation layer integrated with existing CRM and compliance workflows across a multi-office or complex practice.

Do small financial advisory practices need enterprise-level cyber automation?

Most don't, at least not initially. A single-office practice is usually better served starting at the Essential or Growth level and expanding automation as client volume and system complexity grow.

What is the difference between cybersecurity software and an incident response plan?

Cybersecurity software (monitoring tools, firewalls, endpoint protection) reduces the chance of an incident and can help detect one. An incident response plan is the human process for what happens after detection — who acts, in what order, and how stakeholders are informed. Both are needed; neither substitutes for the other.

How does client portal security relate to this trend?

Client portals are one of the most common points of entry for the kind of unauthorised access that leads to an incident, since they hold sensitive data and are internet-facing by design. Strengthening portal authentication is one of the most direct, low-cost steps a firm can take.

Should advisors offer biometric authentication on client-facing portals?

It's worth considering, since biometric login (Face ID, fingerprint) raises the difficulty of unauthorised access without adding friction for clients who already use these methods on their own devices daily. It's not the only step needed, but it's a meaningful one.

What is biometric authentication and how does it reduce cyber risk?

Biometric authentication verifies identity using a physical characteristic — a fingerprint or facial scan — rather than (or in addition to) a password. Because it can't be guessed, reused across sites, or easily phished the way a password can, it closes off a common attack path.

How does two-factor or biometric login compare to password-only access for advisor portals?

Password-only access is vulnerable to reuse, phishing, and credential-stuffing attacks. Adding a second factor, biometric or otherwise, meaningfully reduces the chance that a compromised password alone leads to account access.

What questions should advisors ask their own IT or website vendor about incident response?

Ask whether there's a documented incident response plan covering the firm's own systems, whether monitoring is continuous or manual, how quickly the vendor would notify the firm of a suspected breach, and what the firm's own role is in that process.

How can AI integration help automate compliance monitoring for advisory firms?

AI integration connects monitoring agents into existing systems — CRM, email, document management — so that compliance-relevant events (unusual access, data exports, failed logins) are flagged and logged automatically rather than depending on manual review.

What is the realistic timeline to build a custom incident response tool?

For a scoped, single-practice build, a working monitoring and alerting tool is typically achievable within a few weeks; broader integrations across multiple systems and compliance workflows take longer, generally a couple of months.

Can AI agents automatically notify clients if a data breach occurs?

They can be configured to trigger a pre-approved notification sequence once a breach is confirmed, which speeds up compliance with notification obligations, but the decision to confirm a breach and approve client communication should still involve a person.

What are common failure points that let a cyber incident go undetected?

The most common failure points are relying on manual log review, having no alerting on unusual login locations or times, and lacking any automated flag for bulk data downloads — all gaps that continuous monitoring agents are specifically built to close.

How does automation reduce the manual burden of maintaining a response plan?

Automation handles the detection and first-alert steps continuously, so the plan doesn't depend on a person remembering to check logs or noticing something unusual during a busy week — it removes the weakest link, which is human attention.

Should advisors build custom software or use off-the-shelf security tools?

It depends on how customised the firm's existing systems already are. A firm running mostly standard tools can often use off-the-shelf monitoring; a firm with bespoke portals or workflows usually gets more reliable coverage from a purpose-built integration.

What is AI software development in the context of security tooling?

It refers to building custom applications or automation layers — rather than configuring generic third-party tools — so that monitoring, alerting, and response steps match a firm's specific systems and workflows exactly.

How does staffing size affect a firm's ability to have a response plan?

Smaller firms often lack a dedicated person responsible for security, which is a large part of why the Make UK report found half of affected manufacturers had no plan — the same resourcing constraint applies to many small advisory practices.

What's the business case for investing in cyber resilience now versus after an incident?

Preparing in advance is materially cheaper and faster than responding to an active incident without a plan, both in direct cost and in the reputational and client-trust damage that comes from a visibly chaotic response.

How should advisors talk to manufacturing clients about this data without alarming them?

Frame it as a normal extension of business continuity and succession planning rather than a warning — a simple question about whether the client has a documented response plan is usually enough to start a constructive conversation.

Does a cyber incident affect a manufacturer's supply chain relationships an advisor should know about?

It can — downtime or data loss can disrupt delivery commitments and supplier trust, which is relevant context for advisors assessing a client's overall business stability, even though the Make UK report doesn't quantify this specific effect.

What's the link between operational technology risk in manufacturing and IT risk generally?

Manufacturing often runs older operational technology (production machinery, scheduling systems) alongside standard IT, and OT systems are frequently harder to patch or monitor, which is part of why the sector's incident rate is elevated relative to some others.

How often should an incident response plan be reviewed or tested?

At minimum annually, and after any significant change to systems, staff, or vendors — a plan that hasn't been reviewed in years is often as unreliable in practice as having no plan at all.

What are the warning signs a client's business is vulnerable to cyber risk?

Signs include no documented response plan, password-only system access, no dedicated IT or security contact, and reliance on ad hoc manual processes for sensitive data handling — all worth raising in a client review.

Can AI agents help triage alerts so a lean team isn't overwhelmed?

Yes — a well-configured agent filters routine, low-risk events from genuinely suspicious ones, so a small team only gets notified about what actually needs attention rather than being flooded with noise.

What happens during onboarding when Scult builds an AI Agents & Automation solution?

Onboarding typically starts with an audit of existing systems and data flows, followed by defining the specific monitoring and alert rules that matter for the firm, then building and testing the automation before it goes live.

How does this trend affect financial advisors serving clients across other UK sectors?

The underlying pattern — lean businesses with valuable data and thin security preparedness — isn't unique to manufacturing, so advisors serving clients in retail, professional services, or hospitality should treat this as a prompt to ask similar questions, even without sector-specific data for those industries.

Is this UK-specific or does the same gap show up in other markets?

The Make UK report is specific to UK manufacturers, so we can't extend its exact figures to other markets. The general pattern of SME cyber exposure outpacing preparedness is widely observed internationally, but any specific comparison would need its own sourced data.

What's the forward-looking risk if this incident response gap isn't closed by 2027?

If incident rates continue at a similar pace while half of affected businesses remain unprepared, the practical risk is more prolonged disruptions, more strained lender and insurer relationships for affected businesses, and more advisory clients facing valuation or continuity issues that could have been mitigated earlier.

How does Scult ensure client data safety while building these automation tools?

Scult designs monitoring and automation work around the client's existing data handling and access controls, scoping each integration to the minimum access needed rather than requesting broad, unnecessary permissions to sensitive systems.

Where should a financial advisory firm start if they want to address this gap?

Start with a short internal audit of where client data lives and how it's accessed, write a one-page response plan even before any new tooling is built, and then scope a focused automation project — most firms fit comfortably into the Essential or Growth tier for this first step.

Want results like this?

Keep reading