MCR Business Tech Solutions

Services

Cybersecurity

We Know We Need Cybersecurity. We Just Do Not Know What to Buy First.

MCR Business Tech SolutionsSeptember 15, 20269 min read

The office manager at a 28-person title and settlement agency in Boardman had three browser tabs open and a sticky note that said "security???" in the owner's handwriting. One tab was a vendor selling endpoint detection. One was a firm selling a vulnerability scan. The third was a bundle called "complete protection" that listed eleven services, four of which she had never heard of. The agency's largest lender partner had just sent a vendor review asking how the company protected borrower information, and a competitor across Mahoning County had nearly wired a six-figure closing payment to a fake account the month before. Everyone agreed they needed cybersecurity services for a small business their size. Nobody could say which of those three tabs was the right first call, or whether all three were selling the same thing under different names.

That confusion is not a knowledge failure on her part. The security industry names its products for other security people. The result is that small and mid-sized businesses across Western Pennsylvania and eastern Ohio either buy the first thing a salesperson explains well, or they buy nothing because the decision feels too big. Both outcomes leave the same gaps open.

This post is the plain-English version: what the services are, what order to buy them in, and how to know you got your money's worth.

What do cybersecurity services for a small business actually include?

Most of what gets sold falls into a short list. The names vary by vendor, but the jobs do not.

  • Assessment. Someone looks at what you actually have and writes down what is exposed. This is the map everything else is planned from. We covered it in depth in what a cyber security audit actually examines.
  • Vulnerability scanning. Software checks your computers, servers, firewall, and anything facing the internet for known weaknesses (missing updates, old software, open doors that should be closed). A vulnerability scan is a snapshot. Run regularly, it becomes a trend line.
  • Identity protection. Multi-factor authentication on email and remote access, cleanup of old accounts, and rules about who has administrator rights. Cheap, unglamorous, and responsible for stopping more real attacks than anything else on this list.
  • Email security. Filtering that catches phishing, impersonation, and malicious attachments before an employee has to judge them. For a title agency, this is where wire fraud starts, so email security is not optional.
  • Endpoint protection. Software on every laptop and desktop that watches for attack behavior, plus people who respond when it alerts. "Endpoint detection and response" is the current name for it, and it replaced plain antivirus for a reason.
  • Patch management. Operating system and application updates applied on a schedule and verified, instead of whenever someone clicks "remind me later" for the fortieth time.
  • Firewall configuration. The device at the edge of your network set up deliberately, with remote access locked down, rather than left on whatever the installer configured years ago.
  • Backup protection. Copies of your data that an attacker already inside your network cannot reach or delete, tested by actually restoring from them.
  • Security awareness training. Short, regular lessons and simulated phishing so staff learn on a harmless fake. What a good version looks like is in our walkthrough of a real awareness program.
  • Incident response. A written plan, and a phone number that gets answered, for the first hour of something going wrong.

When a vendor's "complete protection" bundle lists eleven items, most of them are these ten, split or renamed. Ask any vendor to map their line items onto this list. If they cannot, that tells you something.

Which cybersecurity services should a small business buy first?

If budget were unlimited, you would do everything at once. It is not, so order matters. The sequence below reflects where small business breaches actually come from, and it lines up with the lightweight tier of the CIS Critical Security Controls, a framework written specifically so smaller organizations have a starting point.

First: find out what you have. An assessment and an initial vulnerability scan. Spending before this step means guessing. The Boardman agency discovered during its assessment that a former closer still had an active email account eight months after leaving, and that the "server" everyone worried about was fine while two unpatched laptops at the front desk were the real exposure. That changed what they bought. Second: close the doors attackers actually use. Multi-factor authentication on every email account and every remote access path, removal of stale accounts, and email security filtering. These are fast, relatively inexpensive, and they address the two ways most small businesses get breached: stolen passwords and convincing email. Third: protect the machines. Managed endpoint protection on every computer and a real patching schedule. This is where an attack that gets past the first layer gets caught before it spreads. Fourth: make sure you can recover. Backups separated from the network and a test restore. If everything above fails, this is what decides whether you have a bad week or lose the business. Fifth: make it a habit. Awareness training, a written incident response plan, and a firewall review. These matter a great deal. They simply do less good when the doors in step two are still open.

A small business can usually move through the first three steps within a quarter. The order is more important than the speed.

Which cybersecurity services are one-time projects and which have to be ongoing?

This is where a lot of small businesses overpay or underprotect, because the difference is rarely explained.

Genuinely one-time (or occasional): the initial assessment, the firewall rebuild, setting up multi-factor authentication, cleaning up accounts and administrator rights, writing the incident response plan. You pay for these as projects and revisit them yearly or when something changes. Has to be ongoing: endpoint monitoring, patching, email filtering, backup verification, vulnerability scanning, and training. Every one of these decays the moment nobody is doing it. A patch schedule that stopped in March is not a patch schedule. A scan from last year describes a network that no longer exists.

The practical test for any proposal: which line items are you paying for every month, and what specifically happens each month for that money? If the monthly fee covers software licenses but nobody is reviewing the alerts, you are paying for a log file. That same question explains a lot of the gap between proposals, which we unpacked in why three IT quotes can look so different.

Should cybersecurity services come from our IT company or a separate security firm?

For most businesses between 5 and 50 employees, one accountable provider is better than two, as long as that provider actually runs a security program and is not just fixing things when they break.

The problem with splitting it is the handoff. A separate security firm detects something at 2 a.m. and emails your IT company, which does not open the email until 8. The security firm recommends a firewall change, and the IT company, which manages the firewall, disagrees or never gets to it. Each side reasonably assumes the other owns the gap. Attackers do very well in that seam.

There are good reasons to bring in an outside firm: an independent penetration test, a compliance audit where your auditor wants separation from the people who built the system, or a specialized requirement from a large customer. Those are periodic checks on the work, not replacements for someone owning it daily.

If you are not sure whether your current IT company is doing the security half at all, we wrote about the simple test (ask for last month's security report) in what outsourcing cyber security actually looks like.

Is there a legal benefit to having a written cybersecurity program?

In Ohio, there is a specific one, and it matters for businesses in Mahoning, Trumbull, and Columbiana counties.

Ohio's Data Protection Act gives businesses an affirmative defense against certain lawsuits after a data breach, if the business had created and was following a written cybersecurity program that reasonably conforms to a recognized framework such as the NIST Cybersecurity Framework or the CIS Controls. In plain terms: if you are sued for failing to protect customer information, having done the work in a documented, framework-aligned way gives you a defense that a business with good intentions and no paperwork does not have. Ask your attorney how it applies to your situation, because the details matter.

This is an Ohio law, so a Pennsylvania office does not get that defense from it. The underlying lesson still crosses the state line. Lenders reviewing a title agency, insurers reviewing a cyber policy application, and regulators reviewing a medical practice all ask the same kind of question: can you show what you do, not just say it? A HIPAA-bound dental office in Slippery Rock needs documented risk analysis and safeguards. A restaurant group taking cards answers to PCI requirements. An accounting firm holding Social Security numbers carries Pennsylvania breach notification obligations. In every case, cybersecurity services that produce documentation are worth more than the same protections running undocumented.

How do we know the cybersecurity services are working?

You should get evidence on a schedule, in language you can read. At minimum, a monthly or quarterly report should tell you:

  • How many computers are protected, and which ones are not (with a reason and a date for fixing it)
  • Patch status: what percentage of machines are current, and what is outstanding
  • What was detected and blocked, and whether anything required a human response
  • Vulnerability scan results compared with last time, so you can see whether the list is shrinking
  • Backup status, including the date of the most recent test restore
  • Training completion and simulated phishing results, especially the report rate

If a provider cannot produce that, the services may exist on an invoice and not much further. If they can, you now have exactly what the lender, the insurer, or the auditor is going to ask for.

The Boardman agency answered its lender's vendor review six weeks after the sticky note, with a written program, an assessment report, and a first month of reporting attached. The office manager closed two of the three browser tabs. The third, it turned out, was only selling one piece of a much longer list.

MCR Business Tech Solutions provides cybersecurity services for small businesses across Mercer, Lawrence, Butler, Crawford, Erie, and Allegheny counties in Western Pennsylvania, and across Mahoning and Trumbull counties in eastern Ohio (from Hermitage and Grove City to Boardman and Warren). If you have a vendor review, an insurance questionnaire, or just a sticky note that says "security???" on your desk, call 833-859-9021 or Request an IT assessment through our contact page, and we will start by showing you what you actually have and what to fix first.

cybersecurity services for small businesscyber security services for small businesssmall business cybersecurity servicesmanaged security services for small businesscybersecurity for small businessohio data protection actmahoning countywestern pa

Talk to us

Ready for IT
that just works?

No commitment. No sales pitch. Just a straightforward conversation about your tech.

Keep reading

Related articles

Cybersecurity

We Are 22 People. We Cannot Hire a Security Expert, and Honestly We Would Not Know What to Ask One to Do.

A twelve-page cyber insurance questionnaire lands on your desk and you cannot honestly answer yes to most of it. You are not going to hire a full-time security specialist at 22 employees, and one person could not cover nights and weekends anyway. Outsourcing cyber security is how small and mid-sized businesses in Western Pennsylvania get real, round-the-clock protection without building a department. Here is what an outsourced security program actually includes, how to tell whether your current IT company is really doing it, why the insurance questionnaire matters more than most owners realize, and the questions that separate genuine security from a sales pitch.

Cybersecurity

Our Biggest Customer Sent Us a Security Questionnaire and Nobody Here Can Answer It

Most small businesses do not go looking for cyber security audit services. They get asked for one: by a cyber liability insurer at renewal, by a large customer running a vendor security review, or by a regulator. Here is what a cyber security audit actually examines, how it differs from a vulnerability scan and from cyber security risk assessment services, what happens when the findings are bad, how long it takes, and how often a 5 to 50 employee business in Western Pennsylvania actually needs one.

Cybersecurity

Our Bookkeeper Almost Wired $38,000 to a Supplier That Does Not Exist.

The attack that actually hits small businesses is not a hacker breaking through your firewall. It is a polite email that looks exactly like a real one, sent to an employee who is trying to do their job. A cybersecurity awareness program is how you turn your staff from the easiest way into your business into the control that catches the attempt. Here is what business email compromise looks like from the inside, why the once-a-year training video does nothing, what an ongoing employee cyber security training program actually contains, why your insurer and (for medical, dental, and retail businesses) your regulators now treat it as a required control, and how to measure whether it is working.

Call 833-859-9021Get Assessment