Security

Most people call us about security for one of two reasons. Their insurance renewal showed up with a questionnaire attached, or something happened to a business they know.

Either way the work is about the same. Here is what goes on every machine we manage, and what we add on top when you need it.

What every managed machine gets

Offsite backups. Every machine we manage gets a full image taken overnight and copied offsite. Drive dies Tuesday morning, we pull Monday night’s image, put it on a new drive, and you get the machine back with your programs and printers still set up. Usually a couple of hours. Worth knowing: OneDrive and SharePoint only cover files. They will not rebuild a computer.

Endpoint detection and response. Runs quietly on each workstation watching for behaviour that looks wrong, and reports back to us. Older antivirus waited for a virus it already had a signature for. This catches things earlier and tells us before you notice anything.

DNS filtering. Stops the dangerous site from loading at all. It also gives you a say in what should be reachable on your network, which comes up more often than people expect.

Remote support agent. A small program that lets a technician get on your screen in under a minute instead of driving out. It also tells us when a machine goes offline, so sometimes we call you first.

What we add when you need more

Multi-factor authentication. Email first, then computer logins, remote access, payroll and accounting. We check where it is missing and turn it on in an order that does not lock your staff out mid-week.

Phishing and spam training. Someone clicking a link is still the most common way in. We train your people on what the current attempts look like, and they change every year.

Patching. Windows, Mac and Office updates on a schedule, rather than whenever somebody gets around to clicking the box.

Audits and reporting. Workstation security audits, permission reviews, device inventory, network maps. Mostly this is about knowing what you own and who can reach it. The answer is often surprising.

When someone asks you to prove it

Insurance questionnaires, a customer’s vendor security review, a grant condition, a board member asking whether you are covered. These land on the owner’s desk.

We work from the CIS Controls, which is a published checklist: know what devices and software you have, protect your data, lock down configurations, manage accounts and access, patch, keep logs, protect email and browsers, handle malware. Going through them in order turns a vague worry into a list you can finish.

If you have a specific obligation like HIPAA, PCI, NIST, CMMC or SOX, we put the technical controls in place and help you gather the evidence. We are your IT provider. We are not an auditor and we do not issue certifications, so plan on us getting you ready and supporting you through somebody else’s assessment.

Easiest place to start is the cyber insurance questionnaire. Send it over and we will tell you which answers are already yes, which are a quick fix, and which are a project.