Where each layer sits

Practical security for a 10 to 150 person business is not one product. It is a handful of controls that each catch what the others miss, configured properly and checked on a schedule. Here is where each one sits.

Identity. Multi-factor authentication is enforced for every account on every critical system, not offered as an option people can skip. Enforcement runs through conditional access policies that also block sign-ins from countries you do not operate in and from devices that are not enrolled and healthy. Most business email compromise starts with a password that leaked somewhere else. MFA plus conditional access is what turns that leak into a non-event.

Endpoints. Endpoint Detection and Response (EDR) runs on every laptop and desktop. Traditional antivirus matches known bad files. EDR watches behavior. When a process starts encrypting files or dumping credentials, the device is isolated from the network automatically and our team is alerted within minutes. Containment happens before anyone has read the alert.

Email. Filtering catches the bulk of phishing and malware before it reaches an inbox. What gets through is what the training layer is for.

People. Quarterly phishing simulations send realistic lures to your staff and measure who clicks. Results are reported by department, not by name, and the people who click get short, specific training rather than a shaming email. Over a year, click rates fall and reporting rates rise, and both numbers appear in your quarterly review. If you want a starting point before any of that, our four questions for Cybersecurity Awareness Month is the version an owner can run alone in October.

Credentials in the wild. Dark-web monitoring watches for your company’s domains and email addresses in leaked credential dumps. When a staff password shows up, it is reset the same day, before someone tries it against your Microsoft 365 tenant.

What happens during an incident

The runbook is written before anything goes wrong. When EDR flags an active threat, the device isolates itself, we confirm the alert, and we preserve what we need to understand how it got in. Then we determine the scope: which accounts, which devices, which data. Affected credentials are reset and sessions revoked. If data was encrypted, recovery comes from the immutable copies maintained under Backup and Disaster Recovery, which an attacker cannot delete or modify. Afterward you get a plain-English write-up: what happened, and what we changed so it does not happen the same way twice.

We have handled ransomware, business email compromise, and credential theft for clients. Those incidents stayed small because the controls above were already in place, not because anyone responded heroically.

Built for the insurance questionnaire

Cyber insurance applications now ask specific questions: is MFA enforced on email and remote access, is EDR deployed, are backups immutable and tested, is staff training in place. Every control in this service maps to a line on those questionnaires and to the CIS Controls and NIST Cybersecurity Framework categories underwriters reference. At renewal you answer yes with documentation behind it, which is usually the difference between a clean renewal and an exclusion.

New York specifics

New York’s SHIELD Act requires any business holding private information about New York residents to maintain reasonable administrative, technical, and physical safeguards. Financial services firms regulated by the New York Department of Financial Services carry the more specific requirements of 23 NYCRR Part 500, including MFA and an annual certification. We provide the technical controls and the documentation for both. We do not certify compliance. Only an auditor or your own attestation does that, and we will introduce you to a compliance firm when the paperwork side needs one.

Where this fits in the plans

Everything on this page is included in the Professional and Enterprise tiers. Foundation covers the operational layer and patching but not EDR, phishing simulation, or dark-web monitoring. If your clients, contracts, or insurer are asking about your security posture, Professional is the starting point. For a business with no IT support in place at all, managed IT support is where the baseline gets built.