Skip to content

Small business security ยท North Dakota

Find out if your domain can be spoofed.

Most small business domains can be, and nobody has told them. Check yours in ten seconds, then decide whether you want help with the rest: Microsoft 365 hardening, endpoint security, and hardware that can still be secured.

Free. Reads public DNS only, stores nothing. Or start an assessment directly.

Security posture overview

Microsoft 365
Hardened
DMARC
p=reject
Endpoint Protection
Active
MDR
Monitoring
Security Awareness
Enrolled
Ongoing Oversight
Enabled

Most small businesses have security tools. Not a security plan.

You almost certainly already pay for the pieces. Microsoft 365 came with security features nobody switched on. Antivirus is installed. There is a backup somewhere. Every part exists and no one owns the whole.

That is the gap this practice exists to close, and it is why the first step is an assessment rather than a purchase. Buying another tool on top of tools nobody has configured makes the invoice larger and the business no harder to attack.

Services

Start with the right security step.

Learn more

Before you commit to anything.

Fit

Worth ten seconds to rule yourself out.

Neither of us gets that hour back. If the right column describes you, the honest answer is that this is not the right thing to buy, and you should hear that here rather than on a call.

This fits

  • Five to twenty people, and nobody whose actual job is security
  • Microsoft 365, and you are not sure what is switched on in it
  • An IT provider who keeps things running but does not own security
  • A customer, insurer or bank has started asking security questions
  • You have been told you need DMARC and do not know what that means
  • Something happened to a business you know and it got your attention

This does not

  • More than about twenty users, where scoping stops being honest guesswork
  • You already employ someone whose job is security. You need a peer, not this
  • You want a tool sold to you rather than your configuration fixed
  • Something is happening right now. That is incident response, not a plan
  • You want a compliance certificate without the work underneath it
  • You want the cheapest possible option. That is a real need, just not this one

Several of these are still worth a conversation, just a different one. Say which and you will get pointed at the right thing, whether or not it is this.

Common questions

Asked before anyone signs anything.

Are you replacing my IT provider?
No, and it is usually better if they stay. They keep things running. This is a second set of eyes on security specifically, which is a different job and one most providers were never hired to do. Their work gets easier when someone has written down what good looks like.
Do you need admin access to my systems?
For an assessment, read-only access is enough and that is what gets asked for. Making changes needs more, and that is a separate conversation with its own scope. You will never be asked for a password over email or the phone.
We are small. Is anyone actually targeting us?
Almost nothing that reaches a small business was aimed at it. Most of it is automatic, looking for whatever answers. Being small does not make you invisible, it makes you the cheapest thing to try, and it means there is nobody in-house whose job is to notice.
How long does this take out of my week?
The assessment needs about two hours of someone's time, mostly access and questions about who does what. The rest happens without you. Hardening work is scheduled around your business, not during it.
What if you find something bad?
You get told plainly, first, before anything is written down formally. Findings come with what they let someone do and what it takes to close them, in that order. Nothing is inflated to justify an engagement.

Not sure where you stand?

That is what the assessment is for.

Start an Assessment