Skip to main content
Guardian IT

Cybersecurity

Small-business cybersecurity should be layered.

No single product makes a company secure. Protection comes from several independent controls, each one covering what the others miss.

Most attacks on businesses your size aren't sophisticated. They're a stolen password, an invoice that looks legitimate, or a laptop nobody updated. Layered controls are what turn those from an incident into a non-event.

The practical questions we answer

  • Is multi-factor authentication actually on for everyone?
  • Who holds administrator rights, and do they need them?
  • Is every device encrypted and protected?
  • Would we know if a mailbox were compromised?
  • Can we recover if data were encrypted or deleted?
  • Does access end the day an employee does?

We answer these with evidence from your environment, not assurances.

Defense in depth

Five layers, each one assuming the others might fail

This is the model we build toward. Not every business needs every control on day one — we sequence them by risk and by what your environment already has.
  1. Layer 01

    Identity & access

    Most breaches start with a working password rather than a clever exploit. Identity is the first and most valuable layer.

    • Multi-factor authentication enforced for every user, including executives and service accounts
    • Conditional access policies that limit sign-ins from unexpected locations and unmanaged devices
    • Administrator rights separated from daily-use accounts
    • Business password management with shared vaults instead of spreadsheets
    • Regular review of who has access to what, and removal of what's no longer needed
  2. Layer 02

    Devices & endpoints

    A device is where company data actually lives. An unpatched or unencrypted laptop undermines every other control.

    • Endpoint detection and response on every company device, with alerts investigated
    • Full-disk encryption enforced, with recovery keys held centrally
    • Operating system and third-party patching on a managed schedule
    • Standard users without local administrator rights
    • Remote lock and wipe for lost or stolen hardware
  3. Layer 03

    Email & web

    Email is the most common delivery route into a business, and the most common route for fraud that never involves malware at all.

    • Advanced filtering for phishing, malicious links and attachments
    • Email authentication (SPF, DKIM and DMARC) configured so your domain is harder to spoof
    • DNS and web filtering to block known-malicious destinations
    • Alerting on suspicious mailbox rules and forwarding — a common sign of account compromise
    • A clear, simple way for staff to report something that looks wrong
  4. Layer 04

    People & process

    Your team makes security decisions every day. The goal is recognition and a safe reporting habit, not suspicion of every email.

    • Short, practical security awareness training — not an annual slide deck
    • Phishing simulations used to find topics to teach, not to catch people out
    • A verification step for payment and banking-detail changes, which is what stops invoice fraud
    • Secure onboarding so access is correct from day one
    • Same-day offboarding so access ends when employment does
    • Written policies covering acceptable use, passwords, devices and incident reporting
  5. Layer 05

    Recovery & readiness

    Prevention can fail. The layer that determines whether a bad day becomes a bad quarter is whether you can recover.

    • Backups of cloud data and critical systems, independent of the platform they protect
    • Daily verification and periodic test restores so recovery is proven rather than assumed
    • Vulnerability identification and remediation tracked as ongoing work
    • A written incident response plan with named contacts and a defined first hour
    • Documentation kept current so recovery doesn't depend on one person's memory

The honest version

Security isn't a product. It's a system.

Businesses are usually sold security as a purchase — an antivirus subscription, a firewall, a training platform. Each one is useful. None of them is sufficient, and buying them one at a time tends to produce a collection of tools nobody is watching.

What actually reduces risk is a system: controls that work together, applied consistently to every user and device, maintained on a schedule, and reviewed by someone who notices when something drifts. Most incidents we read about were not caused by a missing product. They were caused by a control that existed but didn't cover everyone, or an alert nobody was looking at.

That's the work. It's less interesting than it sounds and far more effective than another subscription.

Coverage beats sophistication
MFA on 100% of accounts does more than an advanced tool deployed to 70% of them. We chase complete coverage before we chase capability.
Maintained, not installed
A control is only real while it's current and monitored. Deployment is the start of the work, not the end of it.
Someone has to be looking
Alerts that nobody reviews are just logs. We investigate what the tooling surfaces and tell you what it meant.
Written down and verifiable
If we say MFA is enforced, we can show you. Claims you can't evidence aren't security posture, they're hope.

What we won't tell you

  • That any set of controls makes a business immune to attack. No provider can promise that, and the ones who do are selling something.
  • That we can offer a penetration test or a formal regulatory audit. Those are specialist engagements, and we'll refer you if you need one.
  • That compliance is handled. We can support the technical controls behind a framework, but we don't claim certification expertise we haven't earned.

What's covered

The controls behind the layers

Grouped by what they protect. Which of these you need, and in what order, is what the assessment determines.

Identity

  • Multi-factor authentication
  • Identity and access management
  • Conditional access policies
  • Privileged account separation
  • Password management
  • Access reviews

Devices & data

  • Endpoint detection and protection
  • Device encryption
  • Patch management
  • Mobile device management
  • Backup and recovery
  • Remote wipe capability

Network & email

  • Email and phishing protection
  • Email authentication (SPF/DKIM/DMARC)
  • DNS and web protection
  • Firewall management
  • Network segmentation
  • Secure remote access

People & governance

  • Security awareness training
  • Phishing simulations
  • Secure onboarding and offboarding
  • Security policy assistance
  • Vulnerability management
  • Incident preparedness

Straight answers

What owners ask about security

The questions worth asking before you spend anything on cybersecurity.

Didn't find your question?

Ask it directly — you'll get a straight answer from someone who does the work.

Contact us
We're small. Are we really a target?

Most attacks that affect businesses your size aren't targeted at all — they're automated and opportunistic. Credential-stuffing, phishing sent to thousands of addresses and scans for unpatched systems don't check your headcount first.

The practical difference is that a larger company usually has someone whose job is to catch these. That's the gap we fill.

Isn't Microsoft 365 already secure?

Microsoft secures the platform. You're responsible for how it's configured — which users have MFA, who holds administrator rights, what sharing is allowed, whether audit logging is on, and what happens to data when someone leaves.

A default tenant has meaningful protection available and much of it switched off or unenforced. Most of the gaps we find in a 365 environment are configuration, not product limitations.

Do we still need backups if everything is in the cloud?

Yes. Cloud platforms protect against their own infrastructure failing. They don't fully protect you from a user deleting a folder, a departing employee clearing a mailbox, or an account compromise that destroys data before anyone notices.

Retention windows are also shorter than most people assume. Independent backup of your cloud data covers what the platform's own protections don't.

Can you guarantee we won't be breached?

No, and neither can anyone else. What layered security does is reduce the number of ways an attack can succeed, limit how far it spreads when something does get through, and make sure you can recover.

We'd rather be straightforward about that than make a promise that falls apart the first time something happens.

Do you do penetration testing?

No. Penetration testing is a specialist engagement and we don't present our assessment as one.

Our work is making sure the controls are in place, complete and maintained. If you need a formal penetration test — often for a client requirement or an insurance application — we'll point you toward a firm that does it properly and help you act on the findings.

Can you help with cyber insurance questionnaires?

Yes. Insurers increasingly ask specific technical questions: is MFA enforced on email and remote access, is there managed endpoint protection, are backups tested, how are privileged accounts controlled.

We can tell you accurately where you stand on those and implement what's missing. We don't advise on policy selection or coverage — that's your broker's job.

What happens if we get hit with something?

We work from a written plan: contain the affected accounts or devices, establish what was accessed, preserve what's needed for investigation, restore from backup, and close the gap that allowed it.

We'll also be honest about the limits of our role. Serious incidents can require forensic specialists, legal counsel and your insurer, and we'll say so rather than trying to handle everything ourselves.

How much security does a 20-person company actually need?

The baseline is less than most people expect and more than most businesses have: MFA everywhere, managed and patched devices with endpoint protection, email filtering, encryption, controlled admin access, tested backups and a real offboarding process.

That set covers the large majority of what actually happens to companies your size. Beyond it, additional controls should be driven by something specific — a client requirement, a regulated data type, or a risk unique to your operation.

Find out where your gaps are.

The free assessment tells you which layers are covered, which are partial, and which are missing — with evidence from your own environment rather than a generic checklist.

(385) 270-4733Serving businesses throughout Utah.