Security & maintenance

The stack that keeps your organization running and out of the headlines.

Eight services, run as one. Every client gets the full stack — we don't sell security piecemeal, because attackers don't attack piecemeal.

01 · Managed endpoint detection & response

Antivirus looks for known threats. Managed EDR watches for attackers.

Every managed computer runs managed EDR that looks for the behavior of an attack in progress: persistence mechanisms, suspicious processes, and early signs of ransomware. Detections are reviewed by a security operations center (SOC) around the clock, so a threat at 2 a.m. gets a response at 2 a.m., not when someone checks email in the morning.

It works alongside Microsoft Defender Antivirus, and we tune it for your line-of-business software so protection doesn't break the applications you depend on.

What's included

24/7 monitoring and threat review by a security operations center
Detection of ransomware, persistence, and hands-on-keyboard attacks
Isolation of a compromised computer from the network
Guided remediation and cleanup by our technicians
Microsoft Defender Antivirus managed and monitored
02 · Managed identity threat detection & response

Stolen sign-ins are caught and shut down — day or night.

Most business email compromise starts with a stolen password or a hijacked session, not malware. Managed identity threat detection and response (ITDR) watches your Microsoft 365 accounts around the clock for signs of account takeover. When an account is compromised, the response is immediate: the account is locked and its active sessions are cut off.

What's included

Sign-ins from unusual locations, devices, or VPNs flagged
Session token theft and session hijacking detected
Malicious inbox rules and mail forwarding caught
Risky third-party app consents identified
Compromised accounts disabled and sessions revoked, 24/7
Rapid identity triage

Any account, investigated in minutes

When something looks off, we search any user by username and pull up their sign-in timeline and activity for the last 24 hours, along with current risk signals. If we need more history, we widen the view to 48 hours or 7 days.

jsmith@yourorganization.org
24 hours 48 hours 7 days
Sign-in, Orange County, CANormal
New inbox rule createdReview
Sign-in from new countryHigh risk
Account locked, sessions revokedContained

Illustrative example

03 · Endpoint security posture management

A protected computer is only as strong as its settings.

Security tools can't help if the firewall is off, encryption was never finished, or antivirus quietly stopped updating. We continuously check every managed computer's security configuration against best practice and fix what drifts — before an attacker finds it.

What's included

Continuous checks of each computer's security settings
Firewall, antivirus, and disk encryption status verified
Risky or outdated configurations flagged
Unsupported operating systems identified
Misconfigurations corrected by our technicians
04 · Remote monitoring & maintenance

Most outages are a skipped update or a full disk away.

Our monitoring agent watches each device's health and reports to us continuously. Windows and common third-party applications are patched on a tested schedule, and routine problems are fixed by automation before anyone files a ticket.

What's included

Device health monitoring and alerting
Scheduled Windows and third-party application patching
Hardware and software inventory for every device
Disk encryption (BitLocker) status and recovery key tracking
Automated remediation scripts for common issues
Software deployment to new and existing machines
05 · Identity & access

Attackers don't break in. They sign in.

Stolen passwords are the most common way into a business. We enforce multi-factor authentication and write access policies that decide who can sign in, from where, and on which devices — in Microsoft Entra and Google Workspace alike.

Our own admin access to your tenant uses least-privilege, time-limited delegated roles, never shared passwords.

What's included

MFA enforced for every user and every admin
Conditional Access policies (block legacy sign-ins, require compliant devices)
Emergency “break-glass” admin accounts so you're never locked out
Admin role cleanup and least-privilege delegated access
Stale-account cleanup
Staff onboarding and offboarding, same day
06 · Backup & recovery

Microsoft and Google keep your data available — not necessarily recoverable.

Deleted mailboxes, overwritten files, and ransomware-encrypted folders can all outlast the cloud's built-in retention. We back up your cloud data and critical machines separately, and we test restores.

What's included

Microsoft 365 or Google Workspace backup: mail, files, sites
Backup of servers and critical workstations
Backup job monitoring and failure alerts
Periodic restore tests, documented
07 · Email & domain security

Make sure no one else can send email as you.

We configure SPF, DKIM, and DMARC so receiving servers can verify your mail and reject impersonators, and we manage the DNS records your domain depends on. Phishing filters in Microsoft 365 or Gmail are set to their protective settings, not their defaults.

What's included

SPF, DKIM, and DMARC setup with monitoring
Anti-phishing and anti-spam policy hardening
Domain registrar and DNS management
Investigation of reported phishing messages
08 · Security reviews

Configuration drifts. We check it on a schedule.

Platforms change their defaults and retire features constantly. We audit your Microsoft 365 or Google Workspace tenant against current security baselines and deliver a short report: the facts of your environment, then findings ranked by severity, with what we're doing about each.

Sample report structure
Environment factsUsers, licenses, devices
Critical findingsFix now
High findingsThis month
RecommendationsNext review

Find out where your gaps are before someone else does.

Request an assessment