Security
Enterprise-grade security for Greater Boston businesses that do not need an enterprise-sized MSP. Here is exactly what runs on your systems, what is included, and what it costs.
Example environment with illustrative values
Included in fully managed IT
No extra line items for the basics. These run on every managed device from day one.
Security software on every managed computer, kept current and checked to be running, not just installed.
MDR watches every managed device around the clock for signs of an attack, and a compromised computer can be isolated from the network right away.
Windows, macOS, and common applications are patched on a schedule, so known holes get closed before they are used.
Multi-factor authentication on Microsoft 365 or Google Workspace, plus Conditional Access through Entra ID on Microsoft 365, so a stolen password is not enough.
Add-ons
| Add-on | What it does | Price |
|---|---|---|
| DNS filtering | Blocks known malicious and phishing sites before a computer reaches them | $4 per device |
| Email security | Filters phishing, malware, and impersonation attempts before they reach the inbox | $4 per mailbox |
| Security awareness training | Short, regular training so your people spot phishing and scams | $3 per user |
| SIEM, logging and monitoring | Central security logs, kept and watched, for investigations and audits | $2 per user |
| Mobile device management (MDM) | Policies, encryption, and remote wipe for laptops and phones | $5 per device |
| EDR / XDR | Advanced endpoint detection and response across devices | $2 per device |
| MDR for co-managed clients | Included in fully managed; available to co-managed clients | $2 per device |
| Workstation and server backup | Monitored backups with tested restores, your last line of defense against ransomware | $10 per workstation, $20 per server |
| vCIO | Security roadmap, risk register, and board or insurer reporting (fully managed only) | Quoted |
Monthly prices. Nonprofits receive 10% off. Guaranteed after-hours response is a separate add-on, quoted per client.
When something goes wrong
Every client gets this response. Clients on the After-Hours Critical Support add-on get guaranteed after-hours response times.
01
MDR flags suspicious activity on a device or account at any hour.
02
The affected computer can be isolated from the network, and compromised accounts are locked and reset.
03
We clean or rebuild what was affected and restore data from monitored backups.
04
You get a written account of what happened and what changed, for your insurer, your auditor, or your board.
Compliance and insurance
Controls designed and documented for the frameworks our healthcare, financial, and biotech clients answer to. How we handle compliance.
We help you answer the security questionnaire honestly and put the controls insurers ask for (MFA, EDR, backups, training) in place before renewal.
Massachusetts requires a written information security program. Build a draft with our free WISP generator.
Partners
Questions
No. Antivirus blocks known threats on one computer. MDR watches behavior across every managed device around the clock and responds when something looks like an attack, including isolating a computer from the network.
Microsoft 365 includes basic filtering. Email security adds stronger phishing and impersonation protection, which is where most attacks on small businesses start. We will tell you plainly if you do not need it.
It covers the controls insurers ask about most: MFA, endpoint detection, patching, backups, and training. We help you answer the questionnaire accurately, which matters if you ever file a claim.
Endpoint security, MDR, patching, and secure sign-in are included in fully managed IT at $125 per user per month. Add-ons are priced per device, mailbox, or user, listed above and in the pricing calculator.
Client results
Free technical assessment