FAQs about IT services for SMB offices
We almost got hit with a wire-fraud email. Can you prevent this from happening again?
Yes. Business Email Compromise is the most common attack we respond to at small offices, and the playbook is consistent. We harden the mailbox layer (MFA everywhere, conditional access, modern auth only), we deploy real-time detection for new inbox forwarding and reply-to rules, we configure DMARC, SPF, and DKIM properly so lookalike domains are easier to block, and we rewrite the AP or trust-account confirmation process so a wire instruction cannot land without an out-of-band phone call to a known number. The combination is what stops repeat attempts.
We use Microsoft 365 and it works "fine." Do we still need help?
A default Microsoft 365 tenant is not secure. The security baselines that matter (modern auth only, conditional access, mailbox audit logging, retention, data loss prevention, external sharing controls, app consent governance) are off or wide open by default and the average tenant we walk into has not touched them. The mail works; that is not the same as the tenant being safe. Hardening a tenant is a one-time project that pays for itself the first time it stops an account takeover.
We have 12 people across two offices. How do we share files securely?
For most small offices, a properly governed SharePoint and OneDrive footprint beats a network file share or a generic cloud-storage account. The wins are at the governance layer: matter or client folder structures with explicit access lists, retention rules that match your professional standards, audit logging, and a default-deny posture on external sharing. Multi-office connectivity is handled at the identity layer (single sign-on, conditional access by location and device) rather than by routing all traffic through a single corporate VPN.
Our cyber-insurance renewal added 30 questions. Can you help us answer them?
Yes. Cyber-insurance underwriting has gotten sharper across every carrier and the questionnaire is now the cheapest way for them to set your rate. We answer the technical sections (MFA coverage, managed detection and response deployment, backup resilience, mean time to patch, incident response plan, vendor risk management, privileged access) with a real number rather than a checkbox, and we close the gaps in advance so the renewal lands at the rate you want.
A partner is leaving and we need to lock them out fast. What does that look like?
Same-day offboarding done right is a fifteen-minute procedure if the systems are set up for it. We script the revocations: email and SSO disabled at a specific time, MFA tokens revoked, VPN and conditional-access exceptions removed, mailbox forwarded to a designated partner for client continuity, mailbox put on legal hold for the retention window, and any matter-system access logged for the audit. If you do not have those scripts ready when a partner walks out, the right time to build them is before the next one does.
Who will I actually talk to?
Ulises Paiz, the owner, directly. There is no tier-1 queue and no offshore call center: the engineer who knows your environment answers the phone, and critical incidents carry our 4-hour notification commitment.