List prices in US dollars (USD), before taxes. Every service is subject to a written, fixed-scope proposal. Prices valid through November 30, 2026.
01
Managed Plans per User (5-user minimum)
Code SC-01
Essential
This is day-to-day IT support for your team without hiring in-house staff. We handle requests remotely during US business hours, keep computers updated, watch each device for threats, and back up your email and cloud files. Your staff stops waiting on fixes, and each month you get a clear report on the state of your technology.
Includes: Remote help desk during US business hours, remote monitoring (RMM) and patching, managed EDR, Microsoft 365 / Google Workspace backup, and a monthly report.
This plan adds a stronger security layer to Essential. A security operations center (SOC) watches your devices around the clock and responds to suspicious activity, such as ransomware trying to lock your files. We also filter malicious email, train your staff, secure passwords, and back up computers, with after-hours emergency support and a quarterly review to keep priorities on track.
Includes: Everything in Essential + MDR with a 24/7 SOC, email security, security awareness training and phishing simulations, password manager, dark web monitoring, device backup, after-hours emergency support, and a quarterly review.
Built for businesses that cannot afford days of downtime. On top of Professional, we scan your systems for weaknesses and set clear targets for how quickly you are back up and how much data you could lose in an outage (RTO/RPO), with a recovery plan to match. You get a dedicated engineer who knows your business, 24/7 critical incident response, and an annual risk assessment with written policies.
Includes: Everything in Professional + vulnerability scanning, business continuity and disaster recovery (BCDR) with defined RTO/RPO, a dedicated engineer, 24/7 critical incident response, an annual risk assessment, and policies.
For medical practices, law firms, and accounting offices that handle sensitive information. On top of Premium, we build your HIPAA or FTC Safeguards Rule compliance program, collect audit evidence, help you answer cyber insurance questionnaires, and sign a Business Associate Agreement (BAA). There is no such thing as HIPAA certification; the goal is that you can show your safeguards when an auditor, insurer, or client asks.
Includes: Everything in Premium + HIPAA / FTC Safeguards Rule program, audit evidence, cyber insurance questionnaire support, and a BAA.
For businesses that already have an IT person and want to back them up. We give your technician access to our management tools, add monitoring from our security operations center (SOC), and cover the hours when your staff is off. Your in-house person no longer carries everything alone, and your business is not left uncovered at night or during vacations.
Includes: For businesses with in-house IT staff: tools, SOC, and after-hours backup coverage.
For businesses that already have day-to-day support covered but need managed security. We protect each device with threat detection and response, manage your firewall, and collect activity logs into a system our security operations center (SOC) reviews around the clock. Every quarter we walk you through what we found and what to do next, in plain terms.
Includes: EDR/MDR, managed firewall, SIEM and 24/7 SOC, quarterly review.
We keep your server monitored, updated, and backed up remotely. We catch issues such as full disks or stopped services early, apply security patches, and confirm that backups can actually be restored. This lowers the risk of your office grinding to a halt because of a server failure, or of finding out too late that the backup did not work.
Includes: Monitoring, patching, and verified backup.
Covers computers that do not belong to one person, such as reception desks, waiting-room kiosks, or shop-floor stations. We bring them into your company's managed environment so they get the same upkeep and protection. That way a forgotten shared computer does not fall behind on updates and become an easy way into your network.
Includes: Shared or front-desk / floor workstations.
Remote monitoring (RMM) for businesses that already have their own technician. We install a lightweight agent that shows the health of each computer, such as disk space, pending updates, or devices that have gone offline. Your technician gains a view of the whole fleet and can catch problems before an employee has to report them.
Includes: Visibility for businesses with their own technician.
We remotely manage the firewall and network equipment that connect your office to the internet. We review the configuration, keep firmware up to date, and monitor how it is running. This reduces common risks such as misconfigured rules or devices with known, unpatched security flaws, and helps us spot connection problems early.
Includes: Configuration, firmware updates, and monitoring.
Managed detection and response (MDR) pairs software on each device with analysts in a security operations center (SOC) who watch it around the clock. If something suspicious shows up, such as ransomware trying to encrypt files, they can isolate the device and contain the threat. Many cyber insurance questionnaires also ask whether you have this kind of control in place.
Many incidents start with a deceptive email. Your staff gets short courses on spotting scams, and we send safe phishing simulations so they can practice. You receive a report showing who needs more help, plus a training record that insurers and rules such as HIPAA commonly ask for, without pulling people away from their work for long.
Includes: Short training modules and simulations, with reporting.
A managed company password vault where your team stores and shares passwords securely. It replaces spreadsheets, sticky notes, and reusing the same password across sites. When someone leaves the company, you can remove their access to shared logins in an orderly way instead of scrambling to change everything by hand.
We watch dark web sources where stolen data is traded and alert you if usernames or passwords tied to your company domain show up. With that alert, you can change the affected passwords before someone uses them to get into your email or other systems. It is an early warning, not a block on its own.
Every month we check your devices and systems for known weaknesses, such as outdated software or insecure settings. Instead of an endless technical list, you get a remediation plan ranked by priority. You know what to fix first, and you have documented evidence of the control to show insurers or auditors when they ask.
Microsoft and Google keep their services running, but protecting your data from deletion or attacks is largely up to you. We keep an independent backup of email, Drive/OneDrive, SharePoint, and Teams. If someone deletes a folder by mistake or ransomware hits your cloud files, the lost data can be restored from a separate copy.
Includes: Email, Drive/OneDrive, SharePoint, and Teams.
We send copies of your server to cloud storage, away from your office. If the server fails, is stolen, is damaged in a fire, or is hit by ransomware, your data is still available somewhere else for recovery. It is the foundation for no longer relying on an external drive that someone has to remember to swap.
Includes: Includes 1 TB; additional storage at $120/TB.
Business continuity and disaster recovery (BCDR) goes beyond having copies: the aim is to get your business running again soon after a major failure. We replicate your systems, test recovery every quarter, and leave a written plan with steps and owners. In an emergency, you are not improvising or discovering that the backup never worked.
Includes: Replication, quarterly recovery testing, and a documented plan.
An internet-based phone system that replaces traditional phone lines. Each user gets a US number, a mobile app, and voicemail, and can take office calls from anywhere. We port your existing numbers so clients keep dialing the same number, and you avoid maintaining an on-site phone system or being tied to a single desk.
Includes: US phone number, mobile app, and voicemail; number porting included.
We manage your AWS, Azure, or Google Cloud account so it does not go unwatched. We review spending to avoid surprise bills, control who has access, apply security best practices, and check backups. It is a good fit for businesses that rely on the cloud but have no one dedicated to looking after it.
Includes: Cost, security, identity, and backup management for your cloud account.
A 45-minute conversation and a review of what your business exposes to the outside world. You receive a short, plain-language report on the visible risks and suggested priorities. It is a practical first step to understand where you stand before making any decisions or committing to a plan.
Includes: 45-minute review + brief report of visible risks.
We review your Microsoft 365 or Google Workspace setup against the CIS Benchmarks, a widely recognized set of security best practices. Many accounts run on default settings that leave gaps, such as logins without two-step verification. You receive a report ranked by priority that shows what to fix first and why it matters.
Includes: Review against CIS Benchmarks with a prioritized report.
We put security settings in place across your Microsoft 365 or Google Workspace. We turn on multi-factor authentication (MFA), restrict sign-ins from untrusted locations or devices, set up email domain authentication to make spoofing harder, and apply email and device policies. This lowers the risk of account takeover and helps you answer cyber insurance questionnaires.
Includes: MFA, conditional access, SPF/DKIM/DMARC, and email and device policies.
We move your mailboxes from your current provider to Microsoft 365 or Google Workspace, including message history. We plan the cutover to keep disruption low so your team keeps receiving email during the transition. It is a practical way to leave behind limited email services or ones that are hard to secure.
Includes: From any provider to Microsoft 365 or Google Workspace.
We move your office server to the cloud in four stages: we assess what you have, plan the move, carry out the migration, and support the stabilization period. You stop depending on aging on-site hardware that can overheat or fail, and your team can reach its systems securely from wherever they work.
Includes: Assessment, planning, migration, and stabilization.
We assess your company's security using the NIST Cybersecurity Framework, a widely used US framework. We look at people, processes, and technology to identify your most important risks. You receive a roadmap of prioritized actions, useful for planning investments and for answering clients or insurers who ask about your security posture.
Includes: Based on the NIST CSF, with a remediation roadmap.
The HIPAA Security Rule requires healthcare practices and their vendors to analyze risks to patient information. We perform that Security Risk Assessment (SRA) and give you a risk management plan with concrete actions. It helps you meet and document this requirement; there is no HIPAA certification, but there is an obligation to carry out and maintain this analysis.
Includes: Analysis required by the HIPAA Security Rule, plus a risk management plan.
Many corporate clients ask for a SOC 2 report before signing with a vendor. We help you get ready: we identify gaps, write policies, put controls in place, and organize the evidence. The SOC 2 report itself can only be issued by an independent CPA firm, engaged separately; our job is to get you ready for that audit.
Includes: Gap analysis, policies, controls, and evidence. The audit report is issued separately by a CPA firm.
A virtual CISO (vCISO) is a security leader on a subscription basis, without the cost of a full-time hire. We keep your policies current, manage risk, handle security questionnaires from clients and insurers, and meet with leadership every quarter. Security stops being the item on the list that nobody owns, and you have someone accountable for it.
A virtual CISO (vCISO) who runs your company's full security program. Beyond policies and risk, we hold tabletop exercises where your team rehearses how to respond to an incident, and we support you through audits by clients, regulators, or insurers. It suits businesses that need steady security leadership without a full-time executive.
Includes: Full security program, tabletop exercises, and audit support.
Remote technical support by the hour for businesses without a monthly plan, or for work outside the scope of an existing contract. We work during US business hours with bilingual technicians. It is useful for fixing a one-off problem, setting up a new computer, or finishing a pending task without committing to an ongoing service.
Remote technical help by the hour for urgent issues that cannot wait until the next business day, on nights, weekends, and holidays. For example, a server down before you open on Monday or a compromised email account on a Saturday. It gives you access to help when your operation needs it, even without a plan that includes after-hours coverage.