Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays [email protected]

Cybersecurity & Backup · Dallas–Fort Worth

Protected every day, backed up every night, and able to recover when it counts.

I manage endpoint protection, email security, multi-factor authentication, patching, backups and disaster recovery for small businesses in Dallas–Fort Worth, and remotely across Texas. It is for the law firm, practice or agency that cannot afford to lose a week of work or a client's trust.

  • Managed antivirus and email security
  • Backups I actually test restoring
  • Helps you meet cyber-insurance and HIPAA safeguards
15+ yearsin IT, across many industries
Month to monthno long-term contract
Dallas-basedonsite across DFW, remote across Texas

What you get

Cybersecurity, Backup & Disaster Recovery in Dallas

Fewer ways in

Every computer runs managed endpoint protection, every account has multi-factor authentication, every operating system and application is patched on a schedule. The common paths an attacker uses to get into a small office are closed, and my team and I watch the ones that remain.

A backup you have seen work

Your files, server and Microsoft 365 or Google Workspace data are backed up automatically, kept in more than one place, and restored on a test schedule so you know they are good. A backup nobody has restored from is a hope, not a plan.

A recovery plan with your name on it

You get a written, plain-English answer to the questions that matter: what happens if the server dies, if ransomware hits, if the office floods. How long until you are working again, what is lost and who does what. Then I rehearse it.

Quick facts

Service area
Onsite across Dallas–Fort Worth; remote support anywhere in Texas
Best fit
Offices of 3–60 people handling client, patient or policyholder data
Pricing
Included in managed IT (per user or per device, month to month); reviews quoted fixed
Not offered
24-hour SOC, penetration testing or formal audits; I help you prepare for them
Response
You call, I answer or call back; no written response-time promise
Responsibility
One accountable contact: Anthony, start to finish

“Anthony provides the highest level of service in each interaction and always goes the extra mile to ensure the job is done right. What's even more important is his character/integrity. I can't recommend him enough!”

Chase Bryant · Google review · read all

Included

What is included

  • Managed endpoint protection and antivirus on every computer and server, monitored and kept current by me
  • Email security: spam and phishing filtering, link and attachment checking, and SPF, DKIM and DMARC on your domain
  • Multi-factor authentication rolled out on email, remote access, banking-adjacent apps and admin accounts
  • Operating system and application patching for computers and servers on a set schedule, with reboots planned around your day
  • Managed backup of servers, workstations and Microsoft 365 or Google Workspace, kept both local and offsite
  • Scheduled restore tests, with a note to you each time saying what was restored and how long it took
  • A written disaster recovery plan covering hardware failure, ransomware, theft and the office being unusable
  • Help completing cyber-insurance questionnaires and documenting HIPAA technical safeguards truthfully
  • Plain-English security awareness for your staff: what phishing looks like now and what to do when they are not sure

Cybersecurity, backup and disaster recovery are included in managed IT, which is quoted per user or per device after a short conversation and billed month-to-month. A one-time security and backup review, or a stand-alone backup setup for an office that keeps its own IT, is quoted as a fixed project or at the hourly break/fix rates. See pricing.

A good fit if

  • A Dallas–Fort Worth office of 3 to 60 people that handles client, patient or policyholder data
  • A business renewing cyber insurance that has been asked about MFA, backups and endpoint protection
  • A dental, medical, legal or insurance office that needs its HIPAA or confidentiality safeguards documented and actually working

Probably not if

  • A company that needs a 24-hour security operations center with analysts watching screens
  • Formal penetration testing or an independent third-party audit, which I can help you prepare for but do not perform
  • Anyone who wants a promise that nothing bad will ever happen; what I offer is fewer ways in and a tested way back

How it works

What happens after you get in touch

A look at what you have

I check every computer, your email, your backups and your remote access, and tell you honestly what is protected, what is not, and what I would fix first. No scare tactics, just a list.

Close the gaps

Endpoint protection, MFA, patching and email filtering go in first because they stop the most. Backups are set up or fixed next, and the first restore test happens before I call it done.

Write the plan

You get a short recovery plan that says what happens in each kind of bad day and how long it takes to get back. Your insurer or a HIPAA risk assessment will ask for this, and now you have it.

Keep it that way

Protection, patching and backups run every day. My team reviews the routine alerts behind me, I test restores on a schedule and update the plan when your office changes. It is part of managed IT, not an extra.

Why Anthony

Facts, not promises

15+ years in IT

Across many industries and global organizations before running Cross River Tech. Nothing in a small office is new to me.

MCSA and CCNA certified

Microsoft and Cisco certifications listed on my LinkedIn profile, plus daily work with Microsoft 365, Dell, Lenovo and Pax8.

5-star Google reviews

Every review on Google names me personally, because I am the one clients deal with.

One accountable contact

You get my number. I plan cybersecurity & backup, see it through, and answer the phone afterwards. No hand-offs, no ticket queue.

Honest about scope

I tell you up front what fits a small company and what does not. If a bigger provider would serve you better, I say so on the first call.

Month to month, in writing

Managed plans have no long-term contract. Projects get a fixed written quote after a walkthrough.

Want to know what is actually protected?

I will check every computer, your email, your backups and your remote access, and tell you plainly what is covered and what I would fix first. No scare tactics, no obligation.

Questions answered

The short version is above. Each heading below answers one question a buyer actually asks, with the answer in the first sentence. You can skip straight to a quote at any point.

Deeper dives

What does a Dallas small business actually need for cybersecurity?

Five things that stay true on every computer and every account, every day: the machines are protected and patched, logins need more than a password, email is filtered, the data is backed up somewhere an attacker cannot reach, and there is a written answer to what happens when one of those fails anyway. For an office of three to sixty people, cybersecurity is that list kept true, not a product.

The threats a Dallas law firm, dental practice or insurance agency actually faces are ordinary: a phishing email that looks like a client's invoice, a reused password leaked elsewhere, a laptop left in a car, a server drive that fails on a Friday, and ransomware that encrypts the backup along with the files because both sat on the same network. Each has a known, affordable defense.

For most clients this is part of managed IT services, because protection and backups are not something you do once. For an office that manages its own computers, it is available as a one-time review and setup.

Which protections stop the most attacks on a small office?

Patching first, then multi-factor authentication, then managed endpoint protection. Most successful attacks on small businesses use a flaw the vendor had already fixed; the fix simply had not been installed. I apply operating-system and application updates on a schedule, with reboots planned around your day, and a laptop that was closed for a month gets caught up before it reconnects to anything important.

Multi-factor authentication (MFA) means a login needs something besides the password, usually a prompt on a phone. I roll it out in a fixed order: email, then remote access, then admin accounts, then the business applications that hold sensitive data.

Endpoint protection is the modern version of antivirus for every computer, laptop and server: it watches for behavior rather than only known virus files, the user cannot switch it off, and it reports to a console I monitor. The account-side baseline for email is on the Microsoft 365 and Google Workspace page.

How do you stop phishing from reaching my staff?

In layers, because no single filter catches everything. Nearly every incident I am called about started with a password typed into a fake sign-in page, followed by an attacker reading mail, adding a hidden forwarding rule and waiting for an invoice to alter.

  • Filtering checks every message for spam, phishing patterns, dangerous attachments and links that lead somewhere other than they claim.
  • SPF, DKIM and DMARC on your domain stop attackers sending mail that appears to come from you, and stop your legitimate mail being rejected by clients whose systems check.
  • Alerts on new forwarding rules, unusual sign-in locations and mass deletions catch a compromised mailbox in hours rather than months.
  • Your people. I do not run corporate training programs, but I spend a few plain-English minutes with staff on what phishing looks like now, why an urgent wire request from the managing partner deserves a phone call, and what to do when unsure: forward it to me.

For law firms, where a compromised mailbox is also a confidentiality breach, law firm cybersecurity and client confidentiality goes deeper.

Where should a small business keep its backups?

In more than one copy, in more than one place, with at least one copy that cannot be changed or deleted from your network. That rules out the external drive plugged into the server, the copy on the same network share, and the assumption that Microsoft or Google keeps everything forever.

What is backed upWhere it goesHow often
Server and any line-of-business database (practice, case or agency management)Local appliance for fast restores, plus an encrypted offsite copySeveral times a day for the database, nightly for the whole server
Workstations and laptopsKey folders synced to the cloud, plus image backups for machines holding something irreplaceableContinuous for files, nightly for images
Microsoft 365 or Google Workspace mail, calendars, OneDrive, SharePoint and DriveA separate backup service outside your tenant, which an attacker with your admin login cannot reachSeveral times a day
Network configuration (firewall, switches, phone system)Exported and stored with your documentation so a replacement can be built quicklyAfter every change

Retention is set to match the business: a dental or medical practice keeps patient records far longer than a design studio keeps a draft. Backups are encrypted in transit and at rest, and the offsite copy is kept separate from the credentials that run your office, so one stolen password cannot take both.

What is in the disaster recovery plan?

For each realistic bad day, three answers: how long until you are working again, how much recent work is lost, and who does what in the first hour. It is a short document, not a binder, and I walk through it with you once a year so the steps are familiar rather than theoretical.

The scenarios are specific. A server failure means running from the local backup appliance the same day. Ransomware means isolating machines, restoring from the copy the attacker could not reach and resetting every credential. An office that is unusable after a fire or a burst pipe on the floor above means your people working from laptops on cloud files while the space is sorted out.

The plan is only worth something because the restores behind it are tested; I have seen backup jobs report success every night for a year while backing up an empty folder. The scheduled restore notes are what turn a hope into a plan.

What do cyber-insurance applications and HIPAA risk assessments ask for?

The same six things in different words: MFA on email and remote access, managed endpoint protection on every device, systems patched, backups kept offsite, encrypted and tested, a written recovery plan, and security awareness for staff. The insurance form arrives at every renewal; the HIPAA one applies to anyone who handles patient information.

For a dental or medical practice, HIPAA's technical safeguards, meaning access control, audit logs, integrity checks and transmission security, map closely onto that list, and I document how each one is met in your office. What I provide is the technical side, real, current and written down, so the questionnaire is easy and the audit is boring; your policies, training records and how your people behave are the rest of the picture. Dental offices can start with HIPAA IT requirements for dental offices; insurance agencies with insurance agency cybersecurity and compliance in Texas.

What can a small IT company not do for security?

Run a 24-hour security operations center, perform penetration tests or conduct a formal audit. I can help you prepare for the last two, but I do not perform them, and a business that needs analysts watching screens around the clock needs a larger provider.

What a small company can do that a dashboard cannot is know your office. I know which computer belongs to the front desk and that your bookkeeper travels on Thursdays, so a sign-in from another country on her account at 2 AM stands out. My team handles the routine monitoring and updates behind me while I stay your point of contact, so when something does go wrong, the person answering already knows your setup and starts fixing instead of asking you to describe it.

The first step is a look at what you have: every computer, your email, your backups and your remote access, with a plain list of what is covered, what is not and what I would fix first. Ask for a security and backup review.

Questions people ask about cybersecurity & backup

Do I really need managed antivirus if Windows already has Defender?

Defender is a reasonable starting point, and on some plans I manage it as the endpoint protection. What matters is that it is turned on for every machine, cannot be disabled by the user, is kept current and reports to a console that someone actually watches. Unmanaged antivirus is only as good as the last person who clicked a warning away. Managed means I see the alert and act on it.

Is my Microsoft 365 or Google Workspace data already backed up by Microsoft or Google?

Not in the way most people assume. Both keep deleted items for a limited time and protect against their own hardware failing, but they do not protect you from a deleted mailbox after the retention window, a ransomware attack that encrypts synced files, or an attacker with your admin password emptying everything. I add a separate backup of mail, files and calendars that lives outside the tenant.

How do you test that backups actually work?

On a schedule I restore real data: a few files from last week, a mailbox from last month, and periodically the whole server to a spare machine or cloud instance, which I boot and check by opening your business software. You get a short note each time saying what was restored and how long it took. Those notes also become evidence for your insurer or a HIPAA risk assessment.

Can you help with a cyber-insurance questionnaire?

Yes, and this is now one of the most common reasons a Dallas business first calls me. I go through the application with you, make sure each control it asks about is genuinely in place, fix the ones that are not, and give you documentation to support the answers. Insurers check, and a claim can be denied when the application said MFA was on and it was not.

Will this make my dental or medical practice HIPAA compliant?

No IT company can make a practice compliant on its own, because compliance also depends on your policies, training and how staff behave. What I do is put HIPAA's technical safeguards in place, such as access control, MFA, audit logging, encryption, patching and tested backups, and document how each is met. That helps you meet the requirements and gives you evidence for a risk assessment. I do not issue any stamp or seal of compliance.

What happens if my office gets hit by ransomware?

You call me. I isolate the affected machines so it stops spreading, work out how it got in and close that door, then restore your server and files from the copy the attacker could not reach and reset every credential. How long it takes depends on your setup, which is exactly what the recovery plan documents in advance. If you have cyber insurance, I also help you follow the insurer's incident process.

Do I need managed IT to get security and backups from you?

Most clients have it as part of managed IT because protection and backups need ongoing attention. But if your office manages its own computers, I also do one-time reviews and stand-alone backup setups as a fixed project or at the hourly rate. I will tell you plainly if what you have is fine, and what I would change if it is not.

Real reviews

What clients say on Google

Copied word for word from Cross River Tech's public Google listing.

Anthony provides the highest level of service in each interaction and always goes the extra mile to ensure the job is done right. What's even more important is his character/integrity. I can't recommend him enough!

Chase Bryant · Google review

Anthony Omini and Cross River Tech are my go-to team for desktop and office LAN support. He is very skilled, professional, great with my staff, and I highly recommend him.

Neil Reid · Google review

Anthony helped me with resolve several IT issues for a presentation. He is super knowledgeable, professional, and punctual. I highly recommend Anthony at Cross River Tech for all your IT needs.

Jan Revels · Google review

Read all reviews on Google

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080