Cybersecurity · Flat Rate · US-Based

Cybersecurity Services for Small Business

Practical protection against phishing, ransomware and account takeover — sized and priced for businesses with 1–50 employees.

Get a Free IT Assessment See pricing →

Our cybersecurity services

Start with a health check, fix the gaps that matter most, then keep it managed.

🔍

Cybersecurity Health Check

A structured review of your real attack surface: MFA coverage, exposed services, patch levels, backup integrity. Know your gaps before attackers do.

Learn more →
✉️

Email Security & 2FA

Stops the #1 attack on small businesses. Filtering, SPF/DKIM/DMARC, and multi-factor authentication rolled out without workflow chaos.

Learn more →
🛡️

Endpoint Protection

Managed EDR on every laptop and server — detection, isolation and response, with an actual human reviewing the alerts.

Learn more →
🔐

Managed Cybersecurity

Ongoing security operations at a flat rate: monitoring, patching cadence, dark web alerts, and the monthly report your insurer asks for.

Learn more →

Where to start with small business security

Security vendors love to sell small businesses everything at once. The honest answer is that there’s a sequence, and following it costs far less than buying tools at random. You can’t fix what you haven’t measured, so the first step is almost always a cybersecurity health check: a structured review of your accounts, devices, email setup, backups, and access rights that ends with a plain-English list of gaps ranked by risk. For most 10–30 person companies, that list is 8–15 items, and the top three are usually fixable in a week.

Step two is nearly always the same regardless of industry: email security and two-factor authentication. Email is where most attacks start — phishing, spoofed invoices, hijacked mailboxes — and MFA blocks the overwhelming majority of account-takeover attempts. Dollar for dollar, nothing else comes close. Setting up SPF, DKIM, and DMARC plus MFA across a 20-person company is a one-time project measured in days, not months.

Step three is the devices. Endpoint protection puts modern EDR software on every laptop and desktop — the kind that watches behavior and isolates a machine the moment it starts encrypting files, not the antivirus of 2010 that only checked downloads against a list. This is also the item cyber insurance applications increasingly require by name.

Step four is making it permanent. Threats and staff both change, so managed cybersecurity services keeps the whole stack monitored and maintained month over month: alerts reviewed, patches applied, new hires onboarded securely, departed employees’ access revoked the same day.

Your situationStart here
Never had any security review; don’t know where you standCybersecurity health check
Staff keep getting phishing emails; no MFA on accountsEmail security & 2FA setup
Insurer or client contract requires EDR/antivirus on all devicesEndpoint protection
Basics in place, but nobody watches alerts or maintains themManaged cybersecurity

The threat reality for companies with 1–50 employees

The most persistent myth in small business security is “we’re too small to be a target.” That assumes a human attacker choosing victims. Almost nobody is choosing you — scripts are. Automated tools scan every public IP address and every exposed login page on the internet, continuously, and they don’t check your revenue first. A dental office and a Fortune 500 look identical to a credential-stuffing bot; the difference is the Fortune 500 has a security team and you have whoever set up the router.

The losses that actually hurt small firms cluster in two categories. Business email compromise — an attacker gets into a mailbox, watches invoice traffic for weeks, then sends your customer “updated” wire instructions — produces the largest reported dollar losses to the FBI year after year, with individual incidents routinely in the tens of thousands. Ransomware is the other: files encrypted, operations stopped, and a demand sized to what the attacker thinks you can pay. Both are largely preventable with MFA, mail authentication, tested backups, and endpoint monitoring — exactly the sequence above.

The uncomfortable arithmetic: a week of downtime for a 15-person services firm easily exceeds $20,000 in lost billing and payroll, while the preventive stack costs a fraction of that per year under our flat $49–$129 per-user pricing.

Security versus compliance — and what “we need to be compliant” usually means

Security and compliance overlap but aren’t the same. Security is whether an attacker can actually hurt you; compliance is whether you can prove to someone else — an insurer, a regulator, a big client — that you follow expected practices. When a small business owner says “we need to be compliant,” the trigger is usually one of three documents:

  • A cyber insurance questionnaire asking about MFA, EDR, backups, and employee training — answer “no” and premiums jump or coverage is denied
  • HIPAA obligations for anyone touching patient data — which at small scale mostly means access controls, encryption, MFA, and documented policies, not an enterprise audit program
  • PCI requirements from a payment processor — usually a self-assessment questionnaire whose honest answers depend on the same basics

The good news: the controls these frameworks ask about are the ones that stop real attacks anyway. A health check maps your current state against whichever questionnaire you’re facing, and managed cybersecurity keeps the evidence current so next year’s renewal is a form-filling exercise instead of a scramble.

Frequently asked questions

Do we really need a health check first, or can we skip straight to protection?

You can skip it if your gaps are obvious — no MFA anywhere is a clear starting point. But the health check regularly surfaces things owners didn’t know existed: ex-employee accounts still active, backups that stopped running months ago, admin passwords shared in a spreadsheet. Fixing the wrong gap first wastes the budget.

Will MFA annoy my employees?

Briefly. With app-based push approval and trusted-device settings, most staff see a prompt once every couple of weeks per service, not every login. Our 2FA setup includes rollout communication and a fallback process for lost phones, which is where DIY rollouts usually fail.

Is endpoint protection the same as the antivirus that came with Windows?

No. Built-in antivirus catches known malware. Managed endpoint protection adds behavioral detection, the ability to isolate an infected machine from the network remotely, and — critically — a human reviewing alerts. Software that flags a ransomware attempt at 2 a.m. only helps if someone acts on it.

The attacks that actually hit companies with 5–40 employees

Small businesses are not overlooked by attackers. They are selected. A criminal running a phishing campaign does not care whether the mailbox belongs to a Fortune 500 or a nine-person plumbing contractor — they care whether it is defended, and a company with no IT staff, no MFA and a five-year-old firewall is measurably cheaper to compromise. Roughly 43% of cyberattacks target small business, and a large share of the companies that suffer a serious incident are in real financial trouble within a year.

Business email compromise — the one that empties the bank account

BEC does more financial damage to US small businesses than ransomware, and it involves no malware at all. The pattern: a mailbox is accessed using a stolen password, the attacker sits quietly reading mail for days or weeks, learns who pays whom and in what tone, then intercepts a real invoice thread and sends updated banking details. The email is genuine, from a genuine address, on a genuine thread. Sometimes they create a hidden inbox rule that files any reply containing the word “bank” or “wire” into Deleted Items so the real supplier’s confusion never reaches you. Average losses run well into five figures, and because the transfer was authorised by your own staff, banks rarely recover it.

Spear phishing is the targeted cousin: an email that appears to come from the owner, sent on a Friday afternoon, asking the bookkeeper for an urgent payment or a batch of gift cards. Sender-display-name spoofing is trivial; the display says the owner’s name while the actual address is a lookalike domain with a swapped character.

Ransomware, and how it usually gets in

Two doors account for most small-business ransomware. The first is exposed Remote Desktop — RDP on port 3389 published to the internet so somebody could work from home in 2020, then never closed. Automated scanners find it within hours and brute-force weak passwords continuously. The second is a phishing attachment or a malicious link that drops a loader, which sits quietly, harvests credentials, spreads laterally, deletes shadow copies and backups it can reach, and only then encrypts. Modern operators also exfiltrate data first, so paying to decrypt does not stop them threatening to publish your client records.

Credential reuse and stuffing

When an unrelated website is breached, the email-and-password pairs end up in dumps traded on criminal forums. Attackers replay those pairs against Microsoft 365, Google Workspace, QuickBooks Online and banking portals — credential stuffing. It works because people reuse passwords. Dark web monitoring exists for exactly this: it tells you that an employee’s work address and password appeared in a breach, so you can force a reset before someone else uses it.

The controls that matter most, ranked by impact per dollar

You cannot buy every security product, and you do not need to. The order below is deliberate: each item stops more real-world attacks per dollar than the one after it. Do them in sequence rather than picking the interesting ones.

#ControlWhat it stopsEffort / cost
1MFA on email, remote access and finance systemsThe overwhelming majority of account takeovers and BEC — a stolen password alone stops workingIncluded in M365/Workspace. A few hours to enforce; one awkward week of habit change
2Patching OS and third-party appsExploitation of known vulnerabilities — the route for most malware that is not user-clickedAutomated via RMM; effectively zero ongoing user effort
3EDR (endpoint detection and response)Ransomware behaviour, fileless attacks and living-off-the-land techniques signature antivirus missesRoughly $5–$15 per endpoint per month, agent-based
4Close inbound RDP; use VPN or a brokerBrute-force intrusion, one of the top two ransomware entry pointsA firewall change — an afternoon, no recurring cost
5Least privilege — no daily-driver admin accountsMalware installing itself silently; one compromise becoming a whole-network compromiseFree; some friction while people adjust
6Security awareness training + simulated phishingClick-throughs on invoice fraud and gift-card scams; typically cuts click rates by more than halfA few dollars per user per month, 10 minutes a month per person
7Password manager + dark web monitoringCredential stuffing and password reuse across personal and work accounts$3–$8 per user per month
8Immutable, offsite backup — the last lineDoes not prevent anything; determines whether an incident is a bad day or the end of the businessVaries by data volume; test restores quarterly
9Written incident response planPanic. Who to call, who to notify, what to disconnect, in what orderOne afternoon, reviewed annually, printed on paper

Note what is absent: expensive perimeter appliances, threat-intelligence feeds, anything with “AI-powered” on the box. None of those help a 15-person firm that has not yet turned on multi-factor authentication.

Fake virus warnings, scareware pop-ups and the “call this number” trap

A full-screen page appears: flashing red, a siren sound, Microsoft or Apple branding, a claim that your machine is infected and your data is being transmitted, and a toll-free number to call immediately. Sometimes the browser will not close and the mouse pointer seems stuck.

Almost every one of these is a web page, not an infection. It arrived through a malicious ad on an otherwise ordinary site, and the “lock” is a JavaScript trick that re-triggers a dialog and requests full-screen mode. The real attack starts only if you call the number — then a “technician” asks for remote access, shows you harmless Event Viewer warnings as evidence of hackers, charges $299–$599 for a fictitious cleanup, and frequently installs actual remote-access software or steals banking credentials during a fake “refund”.

  • Never call the number. Neither Microsoft, Apple, nor any antivirus vendor puts a phone number in a security alert.
  • Close it properly. Press Esc to exit full screen, then Ctrl+W. If that fails, use Ctrl+Shift+Esc to open Task Manager, select the browser, and End task. On a Mac, Cmd+Option+Esc and Force Quit.
  • Do not restore the previous session when the browser reopens — that reloads the same page.
  • Never enter a password or card number on a page that arrived this way.
  • If you already granted remote access: disconnect the machine from the network, call your IT provider, change passwords from a different device, and contact your bank if any financial site was open.

A real infection does not announce itself with a phone number. It shows up as unexpected slowness, files you cannot open, or a colleague asking why you emailed them a link.

Compliance and cyber insurance: why the questionnaire got harder

Cyber liability insurance used to be a one-page form. After the ransomware losses of recent years, insurers rewrote their underwriting, and the application now functions as a technical audit. Answer the questions inaccurately and you have not bought protection — you have bought a claim that gets denied on the grounds of misrepresentation.

The recurring requirements are consistent across carriers: multi-factor authentication on email and all remote access; MFA specifically for privileged and administrator accounts; EDR rather than consumer antivirus; offline or immutable backups with documented, tested restores; a patching cadence you can evidence; security awareness training with records; and no internet-exposed RDP. Meeting these usually lowers the premium as well as securing the cover.

Regulated work adds a second layer. A medical or dental practice handling protected health information falls under the HIPAA Security Rule, which expects a documented risk analysis, access controls, audit logging, encryption of data at rest and in transit, and signed business associate agreements with any vendor that touches PHI — your IT provider included. Anyone taking card payments is subject to PCI DSS, where the practical items are network segmentation of payment devices, no shared logins, quarterly scanning where applicable, and an annual self-assessment questionnaire. Both frameworks are ultimately asking for the same controls listed in the table above, written down and demonstrable.

Documentation is the part small firms skip and regret. If you cannot show when MFA was enforced, which machines are patched, and that a restore was tested last quarter, you are relying on the goodwill of an adjuster or an auditor.

Frequently asked questions

We are tiny and we have nothing worth stealing. Why would anyone target us?

You have a bank account, an email domain your customers trust, and client data. Most attacks are automated and indiscriminate — scanners find exposed services and phishing goes to millions of addresses. Being small does not make you invisible; it makes you cheaper to compromise, which is worse.

Is Microsoft Defender good enough on its own?

Defender is a genuinely capable baseline and far better than it was. What it does not give you unmanaged is response — someone watching the alerts, isolating a machine at 2am, and investigating. That gap is what managed EDR fills, and it matters most in the first hour of a ransomware attempt, when containment is still possible.

Our staff hate MFA. Is there a less annoying way?

Yes. Push-based approval in the Microsoft Authenticator app, combined with conditional access policies that skip prompts on trusted, compliant devices in known locations, means most people authenticate once and are rarely asked again. Codes typed from a text message are the worst version and also the weakest — SIM swapping defeats it. The complaint is usually about the implementation, not the concept.

What should we do in the first ten minutes of a suspected breach?

Disconnect the affected machine from the network but leave it powered on — memory evidence matters and shutting down can trigger further encryption. Do not delete anything. Call your IT provider on +1 (202) 960-2022 from a phone, not from the compromised system. Change passwords for affected accounts from a clean device, and notify your bank if any financial credentials could have been exposed. Then work the written plan you prepared before you needed it.

Talk to a real technician today

Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.

Get a Free Assessment +1 (202) 960-2022