What we mean by cybersecurity for a small business
Cybersecurity for a 10-to-200-person business is not a product you buy or a certification you frame. It is a short list of controls, applied to every device and every account, kept current, and backed by people who know what to do when something gets through. The list is well understood. Cyber insurers publish it on their applications. HIPAA and the FTC Safeguards Rule spell it out. The gap is almost never knowledge. It's that nobody at a small business has the time to apply the list everywhere and keep it applied.
That's what we do. Security isn't a separate package here. It's built into the managed plan for every client, because in our experience the businesses that get hurt are the ones that bought "basic" IT and were told security was an upgrade.
How small businesses here actually get breached
In the incidents we've been called in to clean up across Sarasota, Manatee, and Charlotte counties, the entry point was almost never a sophisticated exploit. It was one of these:
- A staff member typed their Microsoft 365 password into a convincing fake login page. The attacker read the mailbox quietly for weeks, then used it to send a fraudulent invoice or altered wiring instructions.
- A remote desktop port had been left open to the internet by a previous provider. Automated scanners found it within hours and guessed a weak password within days.
- A password someone reused from a personal account showed up in a breach dump and was tried against the business email.
- An invoice attachment from a real vendor's compromised inbox carried the payload. Nobody questioned it because the sender was legitimate.
- A former employee's account was never disabled.
Every one of those is stopped by controls that are now standard: enforced multi-factor authentication, endpoint detection, email filtering, prompt offboarding, and staff who've seen a phishing simulation. None of them require an enterprise budget. All of them require someone to actually do them.
What's included, and why each piece is there
Endpoint detection and response (EDR). Traditional antivirus looks for known bad files. EDR watches behavior on every workstation and server, flags the patterns ransomware and credential theft produce, isolates a compromised device from the network automatically, and gives us the trail to see how an attacker got in. It's monitored 24/7.
Email security. Most attacks arrive by email. We filter phishing, lookalike domains, malicious attachments, and impersonation of your own executives before messages reach an inbox, and we configure the sending-domain records (SPF, DKIM, DMARC) that stop criminals from sending email as you.
Multi-factor authentication, enforced. "Available" MFA protects nobody. We roll it out to every user on email, remote access, and administrative accounts, enforce it through conditional access, and block the legacy protocols that bypass it.
Security awareness training. Quarterly phishing simulations and short training for every employee. The metric that matters is the click-through rate on the simulations, and it falls fast once people have been caught once by a safe one.
Managed firewall. A WatchGuard firewall with current firmware, locked-down rules, intrusion prevention, and logging, managed by us rather than left on the configuration from installation day.
Vulnerability scanning and patch verification. Continuous scanning of every device so "updates are on" is something we can prove, not assume.
Dark web monitoring. Alerts when credentials tied to your domain appear in a breach dump, so passwords get changed before they get used.
Documented incident response. A written plan that says who does what in the first hour: who isolates, who calls, who preserves evidence, who contacts the insurer and counsel. It's tested with you, not written and filed.
Penetration testing coordination. When your compliance framework or insurer requires third-party testing, we arrange it, remediate the findings, and provide the report.
What we don't do
We don't sell fear. We won't tell you that you're one click from ruin to get a signature, because it isn't a useful way to make decisions and it isn't how we want to work with you. We'll tell you plainly where you stand, what the highest-priority gap is, and what closing it costs. Many assessments end with "you're in reasonable shape, here are two things to fix."
We also don't claim certifications we don't hold. If a compliance framework requires a credential we don't have, we'll say so and help you find the right party for that piece.
Cyber insurance
Insurers in Florida have tightened underwriting sharply over the last few years. Applications and renewals now ask, line by line, whether MFA is enforced on email and remote access, whether EDR is deployed on every endpoint, whether backups are immutable and tested, whether staff are trained, and whether privileged accounts are managed. A "no" on any of those can mean a higher premium, an exclusion, or a declined policy.
We close those gaps in priority order, usually within 30 to 60 days, and give your broker documentation for each answer. If you've received a questionnaire you're not sure how to answer, send it to us. We'll walk through it with you. What insurers are asking for now.
For regulated businesses
Healthcare practices under HIPAA and dealerships under the FTC Safeguards Rule have specific technical requirements: access controls, encryption, audit logging, risk assessments, incident response, vendor oversight. The security stack above covers the controls. Our Compliance add-on adds the annual risk assessment, the written gap report, policy documentation support, and the audit-ready evidence file. See HIPAA and FTC Safeguards for exactly what we do under each.
How it works
- Assess. We scan your network and accounts for existing exposure: open ports, unpatched systems, accounts without MFA, leaked credentials, forwarding rules, former employees still active.
- Onboard. Critical gaps get closed first, usually within the first two weeks. MFA enforcement and EDR deployment come before anything else.
- Stabilize. Email security, firewall hardening, and backup verification are completed across every device and location.
- Optimize. Training and phishing simulations begin. Click-through rates fall. Vulnerability scans drive the patch schedule.
- Plan. Quarterly risk reviews track your posture against new threats, insurance requirements, and any compliance framework that applies.
Who it's for
Businesses handling sensitive client or patient data who cannot afford a breach and don't have an internal security team: medical and dermatology practices, dealerships with an F&I office, law firms, CPA firms, financial advisors, real estate brokerages, and professional services across Sarasota, Manatee, and Charlotte counties.
What it costs
Everything on this page is included in the managed plan, priced per user. Penetration testing is quoted per engagement when required. Compliance assessment and documentation are the add-on. See what's in the plan.
If you think you've been breached
Call (888) 538-6881 now. Don't turn machines off, don't pay anyone, and don't wipe anything. We'll isolate the affected systems, preserve evidence, work through notification obligations with your counsel and insurer, and get you operating again in the right order.

