Cyber security
Find the gaps before somebody else does.
Small-business cyber security starts with finding out how your business actually handles its information. Then you close the openings a stranger could use. For most small companies the risk isn't a sophisticated attack. It is a reused password, an unpatched machine, or a backup nobody has tested.
What small-business cyber security actually means
Cyber security for a small business isn't the same discipline that a bank practises, and treating it as though it were is how small companies end up paying for tools they can't run. At this scale it is mostly an inventory problem. Which machines exist. Who can sign in to them. Where the data lives. And what happens when one of them is lost or encrypted.
The threats that actually reach small businesses are ordinary. Phishing email that borrows a supplier's name and asks for a payment detail to be changed. Credential stuffing, where a password leaked from an unrelated site is tried against your email. Ransomware that arrives through an attachment and encrypts a shared folder. None of these are exotic, and all of them are cheaper to prevent than to survive.
The defences are correspondingly ordinary, which is the good news. Multi-factor authentication on email. A password manager instead of a shared spreadsheet. Operating systems and browsers kept current. Backups that are separated from the machines they protect, and restored occasionally so you know they work. Most of the gap between a business that gets hurt and one that doesn't is whether somebody sat down and checked.
What actually reaches you
-
Phishing
An email borrowing a supplier's name, asking for a payment detail to be changed.
-
Credential stuffing
A password leaked from an unrelated site, tried against your email.
-
Ransomware
An attachment that encrypts a shared folder.
None of these are exotic, and all of them are cheaper to prevent than to survive.
So it starts as an inventory
- Which machines exist
- Who can sign in to them
- Where the data actually lives
- What happens when one is lost or encrypted
Not the discipline a bank practises. Treating it as though it were is how small companies end up paying for tools they can't run.
How we handle it
The published rates apply here as they do to everything else: on-site by the hour, or remote by the quarter-hour if nothing needs hands on the hardware.
- 01
Look at what is actually there
Which machines, which accounts, which services, and who has access to each. Most businesses haven't written this down, and the list itself usually surfaces the first problem.
- 02
Find the gaps in how information is handled
Where data is stored, who can reach it, how it leaves the building, and what would happen if a laptop went missing on a Friday afternoon.
- 03
Close the ones that matter first
Fixing everything at once isn't realistic for a business that also has to trade. The point is to work down from the openings that would do the most damage.
Who this is for
-
Businesses with no IT person, where security has been whatever the last laptop shipped with. If nobody has ever checked, the check is worth more than any single product.
-
Businesses that handle information belonging to other people: client records, payment details, medical or legal paperwork. There the cost of an incident isn't only your own downtime.
Common questions
Answered plainly, and without a discovery call first.
- Is my small business really a target?
- Targeting is mostly automated, so size isn't much protection. Scanners look for open services and known weaknesses across whole address ranges without caring whose they are, and phishing is sent in bulk. What changes with size isn't whether you're approached but whether you can absorb the outcome. A business with no IT person and no tested backup has fewer ways to recover from an ordinary incident than a larger one does.
- What is the single most useful thing to do first?
- Turn on multi-factor authentication for email, then check that a backup exists and can actually be restored. Email is the account that resets every other account, so protecting it protects the rest by extension. A backup that has never been restored is an assumption rather than a safeguard, and finding out it doesn't work during an incident is the worst possible time.
- Do we need antivirus software as well?
- Current versions of Windows and macOS have real-time protection built in. For many small businesses that is a reasonable baseline, not a compromise. Whether an additional product earns its cost depends on what you handle and what you're required to demonstrate. That is a conversation about your specific situation, not a product recommendation we would make sight unseen.
- How does cyber security relate to backups?
- Closely, because backups are what turns ransomware from a catastrophe into an interruption. If a current copy of your data exists somewhere the attacker couldn't reach, the negotiation becomes optional. That is why backup separation matters: a backup drive left permanently connected to the machine it protects gets encrypted alongside it.
- Can you do this remotely?
- A good deal of it, yes. Reviewing accounts, checking update status, looking at how storage and sharing are configured, and setting up multi-factor authentication are all screen-share work. Anything involving physical hardware, such as a machine that needs opening or network equipment that needs moving, is on-site. Remote is billed per quarter-hour and on-site by the hour.
- What if we find something serious?
- You get told plainly what it is and what it would take to close, before anything is booked. Nothing here is sold on the basis of alarming you, and the rates are published so you can see the cost of the work in advance rather than after a discovery call.
Not sure whether this is what you need?
Describe the problem on the phone. If it isn't something we handle, you will be told.
702-514-0787