Cybersecurity
Security aimed at the attacks that actually cost businesses money.
Email fraud, stolen passwords and unpatched software. We close them in order of what they cost, and hand you the evidence your insurer and auditor ask for.
MFA required on email · Critical patches in 72 hours · Evidence every month

Where breaches begin
Two figures that decide what to fix first.
The most common way in is now a known flaw that wasn’t patched. Nearly half of breaches involve someone else’s access.
31%
of breaches began by exploiting a vulnerability: the leading way in, ahead of stolen credentials for the first time.
An unpatched system is the open door. That’s why critical patches land within 72 hours.
Verizon, 2026 Data Breach Investigations Report, 19 May 2026.
48%
of breaches involved a third party: a vendor, a software supplier, or someone with access to your accounts.
Vendor access is reviewed and limited like any other account.
Verizon, 2026 Data Breach Investigations Report, 19 May 2026.
The layers
Six layers, closed in the order that removes the most risk first.
An attacker has to get through every one of them. We add them in this order, and each one leaves a record.
- 01IdentityMulti-factor, conditional access
- 02EmailFiltering, SPF, DKIM and DMARC
- 03EndpointsDetection and response
- 04PatchingCritical fixes inside 72 hours
- 05BackupKept apart, restore-tested
- 06EvidenceA record for every control
- Identity. Multi-factor authentication on email and every remote path, with an owner for every account.
- Email. Filtering for phishing, spoofing and malicious attachments, and SPF, DKIM and DMARC so nobody can send as you.
- Endpoints. Detection and response on every managed device, alerting to us.
- Patching. Critical security patches within 72 hours, reported monthly.
- Backup. Monitored daily, kept apart from your network and restore-tested, so ransomware is an inconvenience rather than an ending.
- Evidence. Every control leaves a record you can hand to whoever asks.
Identity
The cheapest control is the one that matters most.
This is why a client who refuses multi-factor authentication on email is refused the engagement. Every other exception is written down, dated and owned.
| All accounts studied | 99.22% |
|---|---|
| Where the password had leaked | 98.56% |
Meyer et al., “How effective is multifactor authentication at deterring cyberattacks?”, Microsoft Research, May 2023.
What gets reported
What businesses actually report to the FBI.
Reports are self-selected, so these figures understate the total. They still show where the money goes.
| All internet crime (1,008,597 complaints) | $20.877B |
|---|---|
| Business email compromise (24,768 complaints) | $3.05B |
FBI Internet Crime Complaint Center, 2025 Internet Crime Report.
| Business email compromise (Reported losses $3.05B) | 24,768 |
|---|---|
| Ransomware (Reported losses $32.3M) | 3,611 |
FBI Internet Crime Complaint Center, 2025 Internet Crime Report. IC3’s own caveat: the ransomware figure “does not include estimates of lost business, time, wages, files, or equipment, or any third-party remediation services acquired by an entity.”
Close to home: Virginia filed 25,314 complaints with $476.1 million in reported losses; North Carolina filed 25,940 with $431.6 million. Same report, state tables.
Evidence
A control that leaves no record doesn’t count.
Insurers, auditors and your own clients don’t ask whether you’re secure. They ask you to show it. Managed clients get an evidence pack that answers without a scramble.
- Enforcement status. Where multi-factor authentication is enforced, and every dated exception.
- Patch compliance. Reported monthly, with each unpatched device explained.
- Backup and restore records. Job results and the dated restore tests.
- Endpoint coverage. Which devices are protected, and which aren’t.
- Access review. Who has access to what, reviewed on a schedule.
- Incident record. What happened, what was done and when.
Compliance
We support your compliance. We don’t certify it.
We build and run the technical controls frameworks and questionnaires ask about, and we keep the evidence. Your auditor certifies, and your attorney decides what a law requires.
WISP for tax and accounting
In your IT lead’s languageThe control set, for an IT person, auditor or insurer.
- Multi-factor authentication enforced on email and all remote access; conditional access and risky sign-in review on Secured and Complete.
- Endpoint detection and response on every managed device; alert triage continuous on Secured and Complete, best effort in business hours on Essential.
- Email filtering; SPF, DKIM and DMARC published and moved to an enforced policy in stages.
- Patch windows: critical 72 hours, high 7 days, standard 30 days; exceptions carry an owner, a compensating control and a review date.
- Backup monitored daily, isolated from the production network, restore-tested monthly (quarterly on Essential) with dated evidence.
- Vulnerability scanning monthly on Secured and Complete, critical findings remediated within 72 hours.
- Local administrator rights removed; access reviewed quarterly on Secured and Complete; offboarding within four business hours.
- Aligned to the CIS Controls, Implementation Group 1, as the floor. Records exportable on request.
- Run by CompTIA Security+ certified engineers.
Questions
Straight answers about security.
Is antivirus enough?
Where do we start?
Can you guarantee we won’t be breached?
Do you certify compliance?
What does it cost?
Get started
Find out which door to close first.
1‑855‑OPSWORQ855‑677‑9677 · Mon–Fri, 8am–5pm ET
If the business has stopped, call. Don’t use the form.
Twenty minutes on what you run. You leave knowing where you stand, and what closing each gap would cost.