OPSWORQ

Cybersecurity

Security aimed at the attacks that actually cost businesses money.

Email fraud, stolen passwords and unpatched software. We close them in order of what they cost, and hand you the evidence your insurer and auditor ask for.

MFA required on email · Critical patches in 72 hours · Evidence every month

An orange hardware security key resting on a closed black laptop.

Where breaches begin

Two figures that decide what to fix first.

The most common way in is now a known flaw that wasn’t patched. Nearly half of breaches involve someone else’s access.

Initial accessSourced

31%

of breaches began by exploiting a vulnerability: the leading way in, ahead of stolen credentials for the first time.

An unpatched system is the open door. That’s why critical patches land within 72 hours.

Verizon, 2026 Data Breach Investigations Report, 19 May 2026.

Third partiesSourced

48%

of breaches involved a third party: a vendor, a software supplier, or someone with access to your accounts.

Vendor access is reviewed and limited like any other account.

Verizon, 2026 Data Breach Investigations Report, 19 May 2026.

The layers

Six layers, closed in the order that removes the most risk first.

An attacker has to get through every one of them. We add them in this order, and each one leaves a record.

01IDENTITYMulti-factor, conditional access02EMAILFiltering, SPF, DKIM and DMARC03ENDPOINTSDetection and response04PATCHINGCritical fixes inside 72 hours05BACKUPKept apart, restore-tested06EVIDENCEA record for every control
  1. 01IdentityMulti-factor, conditional access
  2. 02EmailFiltering, SPF, DKIM and DMARC
  3. 03EndpointsDetection and response
  4. 04PatchingCritical fixes inside 72 hours
  5. 05BackupKept apart, restore-tested
  6. 06EvidenceA record for every control
  • Identity. Multi-factor authentication on email and every remote path, with an owner for every account.
  • Email. Filtering for phishing, spoofing and malicious attachments, and SPF, DKIM and DMARC so nobody can send as you.
  • Endpoints. Detection and response on every managed device, alerting to us.
  • Patching. Critical security patches within 72 hours, reported monthly.
  • Backup. Monitored daily, kept apart from your network and restore-tested, so ransomware is an inconvenience rather than an ending.
  • Evidence. Every control leaves a record you can hand to whoever asks.

Identity

The cheapest control is the one that matters most.

This is why a client who refuses multi-factor authentication on email is refused the engagement. Every other exception is written down, dated and owned.

Lower risk of account compromise with multi-factor authenticationSourced
Lower risk of account compromise with multi-factor authentication
All accounts studied99.22%
Where the password had leaked98.56%

Meyer et al., “How effective is multifactor authentication at deterring cyberattacks?”, Microsoft Research, May 2023.

What gets reported

What businesses actually report to the FBI.

Reports are self-selected, so these figures understate the total. They still show where the money goes.

Reported losses, 2025Sourced
Reported losses, 2025
All internet crime (1,008,597 complaints)$20.877B
Business email compromise (24,768 complaints)$3.05B

FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

Complaints by type, 2025Sourced
Complaints by type, 2025
Business email compromise (Reported losses $3.05B)24,768
Ransomware (Reported losses $32.3M)3,611

FBI Internet Crime Complaint Center, 2025 Internet Crime Report. IC3’s own caveat: the ransomware figure “does not include estimates of lost business, time, wages, files, or equipment, or any third-party remediation services acquired by an entity.”

Close to home: Virginia filed 25,314 complaints with $476.1 million in reported losses; North Carolina filed 25,940 with $431.6 million. Same report, state tables.

Evidence

A control that leaves no record doesn’t count.

Insurers, auditors and your own clients don’t ask whether you’re secure. They ask you to show it. Managed clients get an evidence pack that answers without a scramble.

  • Enforcement status. Where multi-factor authentication is enforced, and every dated exception.
  • Patch compliance. Reported monthly, with each unpatched device explained.
  • Backup and restore records. Job results and the dated restore tests.
  • Endpoint coverage. Which devices are protected, and which aren’t.
  • Access review. Who has access to what, reviewed on a schedule.
  • Incident record. What happened, what was done and when.

Compliance

We support your compliance. We don’t certify it.

We build and run the technical controls frameworks and questionnaires ask about, and we keep the evidence. Your auditor certifies, and your attorney decides what a law requires.

WISP for tax and accounting

The written security plan the IRS expects, with the controls actually in place.
Accounting & tax

HIPAA Security Rule

The technical safeguards, in place and documented.
Medical & dental

CMMC Level 1

The basic safeguarding requirements for federal contract information.
Manufacturing

Cyber insurance forms

Every question mapped to a control and the evidence.
Readiness review
In your IT lead’s languageThe control set, for an IT person, auditor or insurer.
  • Multi-factor authentication enforced on email and all remote access; conditional access and risky sign-in review on Secured and Complete.
  • Endpoint detection and response on every managed device; alert triage continuous on Secured and Complete, best effort in business hours on Essential.
  • Email filtering; SPF, DKIM and DMARC published and moved to an enforced policy in stages.
  • Patch windows: critical 72 hours, high 7 days, standard 30 days; exceptions carry an owner, a compensating control and a review date.
  • Backup monitored daily, isolated from the production network, restore-tested monthly (quarterly on Essential) with dated evidence.
  • Vulnerability scanning monthly on Secured and Complete, critical findings remediated within 72 hours.
  • Local administrator rights removed; access reviewed quarterly on Secured and Complete; offboarding within four business hours.
  • Aligned to the CIS Controls, Implementation Group 1, as the floor. Records exportable on request.
  • Run by CompTIA Security+ certified engineers.

Questions

Straight answers about security.

Is antivirus enough?
Not on its own. Endpoint detection and response watches what programs do, not just what they’re called, so it can catch an attack no antivirus has a signature for yet. It’s on every managed device, with alerts triaged on Secured and Complete.
Where do we start?
With multi-factor authentication on email and the patch backlog. Together they close the doors most breaches come through. The IT Risk Check tells you where you stand in about 90 seconds.
Can you guarantee we won’t be breached?
Nobody honestly can. We close the common doors, watch for what gets through, keep a backup that restores, and show you the evidence for all of it.
Do you certify compliance?
No. We build and run the technical controls and keep the evidence. Your auditor certifies, and your attorney decides what a law requires of your business.
What does it cost?
Security is part of the managed plans rather than a separate bill. Secured, from $175 a user a month, is where the full set starts. Compare the plans.

Get started

Find out which door to close first.

1‑855‑OPSWORQ

855‑677‑9677 · Mon–Fri, 8am–5pm ET

If the business has stopped, call. Don’t use the form.

Twenty minutes on what you run. You leave knowing where you stand, and what closing each gap would cost.

What’s it about? Select all that apply.

A sentence is plenty.

A person replies within one business day. Nothing is sold, and you’re not added to a mailing list.

Prefer to talk? Pick a time for a 20‑minute review Or call 1‑855‑OPSWORQ.

Call Get your price