Knowledge base
No jargon, and nothing you need a contract with us to read. If your own IT person tells you something different and can explain why, listen to them — they know your setup.
The basics
One company takes responsibility for your technology working, for an agreed monthly fee, instead of billing you by the hour after something breaks.
The real difference is who carries the risk. On hourly break-fix, a bad month is expensive for you. On a managed agreement, a bad month is expensive for us — which is why we spend the quiet months preventing it.
Because it stops the most damage for the least money. A stolen password on its own becomes useless.
Most successful attacks on businesses your size start with one working password — bought, guessed, or typed into a convincing fake login page. MFA breaks that chain. It is also the first question on nearly every cyber insurance renewal.
No. A backup job reporting success means the job finished, not that what it wrote can be turned back into a working system.
The only test that counts is a restore. Ask whoever manages your IT when they last restored something from your backups, and what they got back. If the answer is vague, that is your answer.
An email designed to make you do something in a hurry — log in, pay an invoice, change bank details, open an attachment.
The tell is almost always urgency plus a change to money or credentials. A genuine supplier who changes their bank account will not mind you ringing a number you already had to confirm it. Make that a standing rule rather than a judgement call, so nobody has to be clever under pressure.
Budget four to five years. It is rarely a dramatic failure that gets you — it is the slow slide where everything takes fifteen seconds longer than it used to.
Multiply fifteen seconds by every task, every person, every day, and the replacement pays for itself well before the machine actually dies. That is the arithmetic the downtime calculator is doing.
That is a question for your broker, not for us. What we can tell you is that the questionnaire has become the hard part.
Insurers now ask for specific controls — MFA, tested backups, endpoint detection, documented offboarding — and answering optimistically can void a claim later. If you cannot evidence an answer, treat it as a gap to close rather than a box to tick.
You take them. Your documentation, accounts, licences and data are yours, and they are registered in your business name rather than ours.
Ask any prospective IT provider this directly and watch what happens. If the accounts are in the provider’s name, changing supplier stops being a decision and starts being a negotiation.
Safer than the alternative, which is a handful of reused passwords and a note in a drawer.
The realistic threat is not somebody breaking the manager’s encryption. It is one reused password turning up in a breach and unlocking six of your accounts. A manager fixes that, and only one password has to be memorable.
Try it yourself
These run in your browser. Nothing you type is sent to us.
See whether your domain publishes the records that stop someone sending mail as you.
Open the checkerTen questions covering what insurers and auditors actually ask about.
Score yourselfA printable list for a Texas small business, in the order we would work through it.
Open the checklistGet started
Start with an assessment. We look at what you have, tell you what is at risk, and quote what it costs to take it off your hands.