In packages Included in Essential, Secure, or Shield. Everything else is quoted separately.
01
Protect devices
Keep every laptop, desktop, and server hardened and up to date.
Patching In packages
OS and third party app updates, tested and scheduled after hours.
EDR In packages
Endpoint detection and response on every device, catching what antivirus misses.
Ransomware Protection
Behavior based blocking, automatic device isolation, and rollback, backed by clean, tested backups.
Disk Encryption
BitLocker and FileVault enforced and tracked, so a lost laptop isn’t a data breach.
Device Hardening
Secure baseline settings, local admin rights removed, and risky features turned off.
Firewall and Wi-Fi Security
Firewall rules, guest network separation, and firmware kept current.
02
Monitor and respond
Eyes on your business around the clock, and a plan for when something happens.
24/7 MDR In packages
A security operations center watching alerts day and night and containing threats as they happen.
Domain Monitoring
Alerts on lookalike domains used for phishing, unexpected DNS changes, and expiring renewals.
Dark Web Monitoring
Alerts when company email addresses and passwords show up in breach dumps.
Microsoft 365 and Google Monitoring
Suspicious sign ins, risky mailbox forwarding rules, and account takeovers flagged fast.
Incident Response
Hands on help to contain an attack, clean up, and document what happened.
Incident Response Plan
A written, practiced plan so your team knows who to call and what to do first.
03
Email and identity
Most attacks start with an inbox or a stolen password.
Email Filtering
Phishing, malware, and impersonation emails stopped before they reach the inbox.
Phishing Training
Short training and realistic simulated phishing tests for the whole team.
SPF, DKIM, and DMARC
Stop criminals from sending email as your domain, and improve deliverability.
MFA Rollout
Multi factor sign in on email, remote access, and every critical app.
Password Manager
A business password manager deployed and adopted, so no more sticky notes.
Access Reviews
Regular checks that former employees and vendors no longer have access.
04
Test and assess
Find the gaps before someone else does.
Penetration Testing
Real, authorized attempts to break in, with a plain English report and fix list.
Vulnerability Management
Recurring internal and external scans, prioritized so you fix what matters first.
Security Risk Assessment
A full review of your people, processes, and technology, with a prioritized roadmap.
External Attack Surface Review
A look at everything you expose to the internet, from forgotten servers to open ports.
05
Backup and recovery
When something goes wrong, get back to work fast.
Microsoft 365 and Google Backup
Email, files, and calendars backed up daily, separate from Microsoft and Google.
Device and Server Backup
Image based backups for critical machines, with copies kept offsite.
Restore Testing
Backups that are actually tested, so you know they’ll work when you need them.
Disaster Recovery Planning
A clear plan for how long you can be down and how you get back up.
06
Insurance and compliance
Prove you’re secure to insurers, clients, and regulators.
Cyber Insurance Readiness
We put the controls insurers require in place, complete the security questionnaire with you, and work with your broker or carrier on renewals and claims. We don’t sell insurance.
HIPAA Security Support
Risk analysis and safeguards for health care practices, home health, and hospice.
Security Policies
Plain English policies for acceptable use, passwords, remote work, and incident response.
Client Security Questionnaires
Help answering the security questionnaires your larger clients and vendors send you.