Service
Cybersecurity services
Six layers, each of which assumes the one above it will eventually fail. Tooling is the easy part and roughly a third of the value. The rest is somebody reviewing what the tooling reports, and closing the gaps it keeps pointing at.
Monitoring
24 / 7
alerting and critical response
Alerts are reviewed by a person. An unreviewed console is a compliance artefact, not a control.
The six layers
Security is not a product. It is a set of overlapping controls arranged so that no single failure becomes a breach. Each layer below assumes the ones before it will sometimes fail, because they will.
| Layer | What it covers |
|---|---|
| IdentityWhere most breaches now start | Multi factor authentication, conditional access, least privilege, quarterly access review |
| EndpointReplaces traditional antivirus | Endpoint detection and response on every managed device, with human review of alerts |
| EmailHighest volume attack surface | Attachment and link inspection, impersonation defence, external sender marking |
| NetworkContains an incident once it starts | Firewall policy, segmentation, DNS filtering, remote access control |
| DataThe last line when everything else fails | Immutable backups with tested restores, retention aligned to your obligations |
| PeopleThe control with the widest coverage | Phishing simulation and short, frequent training rather than an annual video |
What your insurer will ask for
Cyber insurance questionnaires have become the de facto security baseline for businesses of this size, and they are stricter every renewal. These six appear on almost every form.
- Multi factor authentication on email, remote access and administrative accounts
- Endpoint detection and response, not signature based antivirus alone
- Offsite or immutable backups, tested within a stated period
- A documented patch cadence for operating systems and applications
- Security awareness training with recorded completion
- An incident response plan naming who is called and in what order
Answering inaccurately is worse than answering badly. An overstated control can affect whether a claim is paid, which turns a bad week into an existential one.
Where the money actually goes
Most security budgets are spent on the layer that is easiest to buy, which is endpoint tooling, and underspent on the two that prevent the most incidents.
Identity is the front door
A large share of incidents at this scale begin with a working credential rather than an exploit. Multi factor authentication, conditional access and removing standing administrative rights close more attack paths than any single product purchase.
People are the widest surface
Short, frequent phishing simulation and training changes behaviour in a way an annual compliance video does not. It is also the cheapest control on the list and the one most often skipped because it is not technical.
Common questions
Answered before you ask.
Is this different from the antivirus we already have?
Substantially. Traditional antivirus matches files against a list of known bad ones, which is why it misses anything new. Endpoint detection and response watches behaviour instead: a process encrypting files in bulk, a script reaching out to an unfamiliar address, credentials being dumped from memory. It also records what happened, which is the difference between recovering from an incident and guessing at it. The tooling is only half of it. The other half is somebody reviewing the alerts, which is what a managed service adds.
We are a small business. Are we really a target?
Targeting is largely automated, so size is not much of a filter. Attackers scan for exposed remote access, unpatched systems and credentials that appear in breach data, then work through whatever they find. Small businesses are attractive precisely because the security is usually thinner and the payment decision sits with one person. The realistic question is not whether you will be probed but whether an automated attempt would succeed.
Will security tooling slow our computers down?
Modern endpoint agents are far lighter than the antivirus suites people remember, and the noticeable slowdowns in most environments come from old hardware or unpatched systems rather than from the security stack. Where there is a genuine conflict, usually with line of business software doing something unusual, it is resolved with a scoped exclusion rather than by turning protection off.
What happens if we do get breached?
Containment first: isolate affected systems, cut off the access path, preserve what is needed to understand what happened. Then assessment of what was reached, restoration from known good backups, and notification where a regulator or Washington State law requires it. Worth checking in any agreement, including ours, whether incident response labour is covered by the monthly fee or billed separately, because providers differ on this and it is an expensive thing to discover mid incident.
Related
What sits alongside this.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
IT support and help desk
Tiered support with published response targets, remote and onsite.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Find out what an attacker would find.
The assessment includes an external exposure check, an identity and MFA review, and a restore test. Written findings, no obligation.