Questions answered
The short version is above. Each heading below answers one question a buyer actually asks, with the answer in the first sentence. You can skip straight to a quote at any point.
Deeper dives
- Microsoft 365 security for a small businessA Microsoft 365 tenant is not secure just because it is Microsoft. Here are the settings I turn on for every small business I manage, in the order they matter, and what each one protects you from.
- Law firm cybersecurity and client confidentialityYour duty to keep client information confidential does not change because the files are digital. Here is what that duty looks like as IT settings, in plain words, from someone who sets them up for Dallas firms.
- Better backups for a Dallas insurance agency: what I set upAn independent agency's data lives in more places than one server. Here is what a proper backup covers, how I set it up for Dallas agencies, and how you know it works.
- HIPAA-compliant IT for dental offices in DallasThe HIPAA Security Rule's administrative, physical and technical safeguards explained in plain language, what a risk assessment actually is, and how a single-location Dallas dental office gets there affordably.
What does a Dallas small business actually need for cybersecurity?
Five things that stay true on every computer and every account, every day: the machines are protected and patched, logins need more than a password, email is filtered, the data is backed up somewhere an attacker cannot reach, and there is a written answer to what happens when one of those fails anyway. For an office of three to sixty people, cybersecurity is that list kept true, not a product.
The threats a Dallas law firm, dental practice or insurance agency actually faces are ordinary: a phishing email that looks like a client's invoice, a reused password leaked elsewhere, a laptop left in a car, a server drive that fails on a Friday, and ransomware that encrypts the backup along with the files because both sat on the same network. Each has a known, affordable defense.
For most clients this is part of managed IT services, because protection and backups are not something you do once. For an office that manages its own computers, it is available as a one-time review and setup.
Which protections stop the most attacks on a small office?
Patching first, then multi-factor authentication, then managed endpoint protection. Most successful attacks on small businesses use a flaw the vendor had already fixed; the fix simply had not been installed. I apply operating-system and application updates on a schedule, with reboots planned around your day, and a laptop that was closed for a month gets caught up before it reconnects to anything important.
Multi-factor authentication (MFA) means a login needs something besides the password, usually a prompt on a phone. I roll it out in a fixed order: email, then remote access, then admin accounts, then the business applications that hold sensitive data.
Endpoint protection is the modern version of antivirus for every computer, laptop and server: it watches for behavior rather than only known virus files, the user cannot switch it off, and it reports to a console I monitor. The account-side baseline for email is on the Microsoft 365 and Google Workspace page.
How do you stop phishing from reaching my staff?
In layers, because no single filter catches everything. Nearly every incident I am called about started with a password typed into a fake sign-in page, followed by an attacker reading mail, adding a hidden forwarding rule and waiting for an invoice to alter.
- Filtering checks every message for spam, phishing patterns, dangerous attachments and links that lead somewhere other than they claim.
- SPF, DKIM and DMARC on your domain stop attackers sending mail that appears to come from you, and stop your legitimate mail being rejected by clients whose systems check.
- Alerts on new forwarding rules, unusual sign-in locations and mass deletions catch a compromised mailbox in hours rather than months.
- Your people. I do not run corporate training programs, but I spend a few plain-English minutes with staff on what phishing looks like now, why an urgent wire request from the managing partner deserves a phone call, and what to do when unsure: forward it to me.
For law firms, where a compromised mailbox is also a confidentiality breach, law firm cybersecurity and client confidentiality goes deeper.
Where should a small business keep its backups?
In more than one copy, in more than one place, with at least one copy that cannot be changed or deleted from your network. That rules out the external drive plugged into the server, the copy on the same network share, and the assumption that Microsoft or Google keeps everything forever.
| What is backed up | Where it goes | How often |
|---|---|---|
| Server and any line-of-business database (practice, case or agency management) | Local appliance for fast restores, plus an encrypted offsite copy | Several times a day for the database, nightly for the whole server |
| Workstations and laptops | Key folders synced to the cloud, plus image backups for machines holding something irreplaceable | Continuous for files, nightly for images |
| Microsoft 365 or Google Workspace mail, calendars, OneDrive, SharePoint and Drive | A separate backup service outside your tenant, which an attacker with your admin login cannot reach | Several times a day |
| Network configuration (firewall, switches, phone system) | Exported and stored with your documentation so a replacement can be built quickly | After every change |
Retention is set to match the business: a dental or medical practice keeps patient records far longer than a design studio keeps a draft. Backups are encrypted in transit and at rest, and the offsite copy is kept separate from the credentials that run your office, so one stolen password cannot take both.
What is in the disaster recovery plan?
For each realistic bad day, three answers: how long until you are working again, how much recent work is lost, and who does what in the first hour. It is a short document, not a binder, and I walk through it with you once a year so the steps are familiar rather than theoretical.
The scenarios are specific. A server failure means running from the local backup appliance the same day. Ransomware means isolating machines, restoring from the copy the attacker could not reach and resetting every credential. An office that is unusable after a fire or a burst pipe on the floor above means your people working from laptops on cloud files while the space is sorted out.
The plan is only worth something because the restores behind it are tested; I have seen backup jobs report success every night for a year while backing up an empty folder. The scheduled restore notes are what turn a hope into a plan.
What do cyber-insurance applications and HIPAA risk assessments ask for?
The same six things in different words: MFA on email and remote access, managed endpoint protection on every device, systems patched, backups kept offsite, encrypted and tested, a written recovery plan, and security awareness for staff. The insurance form arrives at every renewal; the HIPAA one applies to anyone who handles patient information.
For a dental or medical practice, HIPAA's technical safeguards, meaning access control, audit logs, integrity checks and transmission security, map closely onto that list, and I document how each one is met in your office. What I provide is the technical side, real, current and written down, so the questionnaire is easy and the audit is boring; your policies, training records and how your people behave are the rest of the picture. Dental offices can start with HIPAA IT requirements for dental offices; insurance agencies with insurance agency cybersecurity and compliance in Texas.
What can a small IT company not do for security?
Run a 24-hour security operations center, perform penetration tests or conduct a formal audit. I can help you prepare for the last two, but I do not perform them, and a business that needs analysts watching screens around the clock needs a larger provider.
What a small company can do that a dashboard cannot is know your office. I know which computer belongs to the front desk and that your bookkeeper travels on Thursdays, so a sign-in from another country on her account at 2 AM stands out. My team handles the routine monitoring and updates behind me while I stay your point of contact, so when something does go wrong, the person answering already knows your setup and starts fixing instead of asking you to describe it.
The first step is a look at what you have: every computer, your email, your backups and your remote access, with a plain list of what is covered, what is not and what I would fix first. Ask for a security and backup review.
Questions people ask about cybersecurity & backup
Do I really need managed antivirus if Windows already has Defender?
Defender is a reasonable starting point, and on some plans I manage it as the endpoint protection. What matters is that it is turned on for every machine, cannot be disabled by the user, is kept current and reports to a console that someone actually watches. Unmanaged antivirus is only as good as the last person who clicked a warning away. Managed means I see the alert and act on it.
Is my Microsoft 365 or Google Workspace data already backed up by Microsoft or Google?
Not in the way most people assume. Both keep deleted items for a limited time and protect against their own hardware failing, but they do not protect you from a deleted mailbox after the retention window, a ransomware attack that encrypts synced files, or an attacker with your admin password emptying everything. I add a separate backup of mail, files and calendars that lives outside the tenant.
How do you test that backups actually work?
On a schedule I restore real data: a few files from last week, a mailbox from last month, and periodically the whole server to a spare machine or cloud instance, which I boot and check by opening your business software. You get a short note each time saying what was restored and how long it took. Those notes also become evidence for your insurer or a HIPAA risk assessment.
Can you help with a cyber-insurance questionnaire?
Yes, and this is now one of the most common reasons a Dallas business first calls me. I go through the application with you, make sure each control it asks about is genuinely in place, fix the ones that are not, and give you documentation to support the answers. Insurers check, and a claim can be denied when the application said MFA was on and it was not.
Will this make my dental or medical practice HIPAA compliant?
No IT company can make a practice compliant on its own, because compliance also depends on your policies, training and how staff behave. What I do is put HIPAA's technical safeguards in place, such as access control, MFA, audit logging, encryption, patching and tested backups, and document how each is met. That helps you meet the requirements and gives you evidence for a risk assessment. I do not issue any stamp or seal of compliance.
What happens if my office gets hit by ransomware?
You call me. I isolate the affected machines so it stops spreading, work out how it got in and close that door, then restore your server and files from the copy the attacker could not reach and reset every credential. How long it takes depends on your setup, which is exactly what the recovery plan documents in advance. If you have cyber insurance, I also help you follow the insurer's incident process.
Do I need managed IT to get security and backups from you?
Most clients have it as part of managed IT because protection and backups need ongoing attention. But if your office manages its own computers, I also do one-time reviews and stand-alone backup setups as a fixed project or at the hourly rate. I will tell you plainly if what you have is fine, and what I would change if it is not.
