Managed Backup
Backup is a core serviceIf something happens to your data, how quickly and reliably could you recover and continue working?
Learn more →Practical protection for small organizations
As computer and data security breaches become more frequent, more severe, more costly, and more sophisticated - especially with the growing use of AI - it is increasingly important to establish a minimum level of protection for every client. That minimum level of protection starts with three core services - managed backup, patching/updates, and EDR (endpoint detection and response).
Most clients already have some or all of these core services in place. The information below explains them, along with other risks or concerns that may be relevant to your organization, and the services available to address them.
We can meet in person or virtually to review your current protection, confirm what is working well, and discuss any changes that may be appropriate.
The foundation
Together, these services support recovery, close known security gaps, and detect suspicious activity before it becomes a larger incident.
Risk areas
Start with the three essentials, then add safeguards for cloud data, users, and the browser.
If something happens to your data, how quickly and reliably could you recover and continue working?
Learn more →Computers need regular updates to their operating systems (Windows, macOS, or Linux) and third-party applications.
Learn more →Computers need protection from attacks, malicious software, and other suspicious activity.
Learn more →Your email and data - both on your devices and in cloud services such as Teams and SharePoint - need protection from unauthorized access, email redirection, impersonation, and theft.
Learn more →Attackers today often don't hack in, they log in using stolen or bypassed credentials. Anyone can make a mistake. We click, we paste, we call, we install. Oops!
Learn more →Much of our daily work now happens in the browser, and it's time to take control of it.
Learn more →If something happens to your data, how quickly and reliably could you recover and continue working?
Whether the cause is a computer failure, damaged hardware, data corruption, ransomware, or a malicious employee, the reliability and quality of your backup will largely determine how quickly you recover, what recovery costs, and how much damage was done.
Managed Backup
Versioned, automated, and monitored backup provides a reliable foundation for recovery, and is an absolute minimum.
Computers need regular updates to their operating systems (Windows, macOS, or Linux) and third-party applications.
An unpatched computer has known security gaps. The operating system and installed applications must be kept up to date, but manual updates are easy to postpone or overlook. Most users plan to, but most users don't.
Once a vulnerability becomes public, attackers can exploit it quickly, so timely security updates are critical. Third-party applications, often overlooked by users, also require attention. One example is outdated Adobe PDF readers, a well-known example of software that has been widely exploited when left unpatched.
OS and Software Patching
Updates and patches are automated, scheduled, and monitored. Critical and security updates are usually approved automatically, while recommended updates can be delayed or declined when appropriate.
Patching also includes system monitoring, which tracks device health indicators such as temperatures, system errors, failed logins, unusually high workloads, and other early indicators of problems.
Computers need protection from attacks, malicious software, and other suspicious activity.
Traditional antivirus software is no longer enough to keep pace with the speed and sophistication of modern attacks, including those created or enhanced with AI.
Modern endpoint security monitors activity in real time and looks for unusual or malicious behaviour, not just known viruses.
EDR — Endpoint Detection and Response monitors computers for unusual or malicious behaviour.
MDR — Managed Detection and Response adds a 24/7 response team of real humans that review every incident, assess the threat, and help determine the appropriate response.
Your email and data - both on your devices and in cloud services such as Teams and SharePoint - need protection from unauthorized access, email redirection, impersonation, and theft.
Your email account is often the key to accessing or recovering many of your other accounts. It may also contain sensitive information belonging to your organization, clients, donors, suppliers, and contacts.
MFA (Multi-factor authentication) adds an important layer of login protection and should be enabled everywhere it is available. Passkeys can provide an even stronger and simpler option, when supported.
Cloud services such as Microsoft 365, Teams, and SharePoint can also be monitored continuously for malicious activity, unauthorized access, and unexpected changes.
MFA is a no cost setting. Use it everywhere you can.
A Password Manager is strongly recommended.
CDR — Cloud Detection and Response monitors cloud services for risks such as unexpected email-forwarding rules, attempts to bypass MFA, and other suspicious changes.
MDR — Managed Detection and Response adds a 24/7 response team of real humans that review every incident, assess the threat, and help determine the appropriate response.
Attackers today often don't hack in, they log in using stolen or bypassed credentials. Anyone can make a mistake. We click, we paste, we call, we install. Oops!
When facing a deadline or finishing an exhausting day, any of us might click a link, accept a pop-up, or trust a craftily written message.
AI can make scam emails even more convincing by incorporating real names and details from an organization.
They are VERY convincing.
Phishing Simulation & Training
Automated awareness training and automated periodic simulated phishing emails help keep staff informed, alert, and up to date. Testing, scoring, and follow-up training are managed automatically, requiring little day-to-day administration.
This service also includes policy tracking, which records when staff receive and acknowledge required policies.
Much of our daily work now happens in the browser, and it's time to take control of it.
Fake login sites, AI use, deceptive search results, the dark web, and dangerous ads all happen in the browser.
Rather than relying on staff to recognize every risk on their own, technical safeguards can help prevent unsafe browser activity - prevent access to malicious sites and login scams, monitor/control data going to AI, prevent privacy breaches like copy/paste of client data, test passwords for strength and existing hacks.
Activity reports and user scores help to identify areas of security risks or privacy breaches.
DNS filtering can limit access to unsafe or inappropriate websites.
Password protection can help confirm that users are signing in only to legitimate services, with safe passwords.
Read-only browsing can limit how users interact with web pages.
Secure browsing can provide safer access to higher-risk websites.
Identity protection can prevent users from entering or pasting private information into web forms, including AI sites.
Service notes
Meet in person or virtually to confirm what is working and discuss sensible next steps.