services // what we do

Services

Four practices, one posture: security built in from the start, documentation the next person can follow, and priorities set by real risk.

IT Operations

Small-business IT mostly works, until the backup turns out to be empty or the M365 admin disappears. We set the boring layer under your business up properly the first time and keep it that way.

Boring infrastructure. The good kind. Network, endpoints, identity, BDR with tested runbooks. Scoped for law firms, hospitality groups, and medical practices that need IT to fail closed, recover fast, and stay out of the way.

Network, endpoint, identity, and recovery posture for trust-heavy small businesses. UniFi or Meraki for L2/L3. RMM and PSA across the endpoint fleet with remote-support tooling. Microsoft 365 with Entra ID for identity. Managed detection layered on endpoints. Tested-restore backup, documented runbooks, documented escalation. Quiet operations.

Services included

  • A network and devices set up to work together, not against each other
  • Backups that have been tested, with a written plan for what happens when they're needed
  • Microsoft 365 configured so the right people have the right access, and so it survives someone leaving
  • Help when something breaks, from someone who already knows your setup
  • Sane management of the vendors you're already paying
  • Network design on UniFi or Meraki with proper segmentation
  • Endpoint fleet management and remote support
  • Microsoft 365 administration and Entra ID identity with MFA enforced
  • Backup and DR with tested, documented runbooks
  • Vendor management and SaaS rationalization
  • Incident response and on-call for existing clients
  • L2/L3 network design on UniFi or Meraki with VLAN segmentation, RADIUS where the use case justifies it
  • Endpoint fleet management via RMM/PSA with remote-support tooling
  • Microsoft 365 tenant admin, Entra ID identity, Conditional Access, MFA enforced and documented
  • 3-2-1 backup with immutable copies, periodic restore drills, mapped to written runbooks
  • Managed detection and response on endpoints
  • Vendor management, license rationalization, procurement
  • Documented off-boarding for departing staff and access lifecycle

Cybersecurity

Most small-business security gets exposed by the same handful of things: a clicked link, an account without MFA, a vendor with bad hygiene, or credentials that should have been disabled months ago. We close those gaps without selling you a stack you do not need.

Practical security controls for the places small-business security usually breaks first. Identity, devices, networks, recovery, staff workflow. Built for trust-heavy environments where the goal is not zero risk but right-sized risk with documented response.

Identity hardening, endpoint posture, network segmentation, and incident response capability for trust-heavy small businesses. Conditional Access on Entra ID with MFA enforced. Managed detection across endpoints. Documented IR playbooks. Compliance mapping calibrated to HIPAA-adjacent and legal-adjacent obligations. Tested controls beat aspirational ones.

Services included

  • MFA turned on for the accounts that actually matter, set up to work for normal people
  • A real plan for what happens when an account is compromised or a device is lost
  • Policy and access rules written down, so they survive someone leaving
  • Practical security training that doesn't feel like a punishment
  • Help making sense of HIPAA-adjacent or legal-adjacent compliance without panic
  • MFA rollout and identity hardening
  • Breach response and forensic support
  • Policy and compliance mapping (HIPAA-adjacent, legal-adjacent)
  • Security awareness training for small teams
  • Vulnerability assessment and remediation
  • Password manager and TOTP rollout
  • Identity hardening on Entra ID with Conditional Access policies and MFA enforced
  • Managed detection and response across the endpoint fleet
  • Documented IR playbooks with defined roles, escalation, and evidence-handling
  • Vulnerability assessment, remediation prioritization, and verification
  • Password manager rollout, TOTP-to-WebAuthn migration where supported
  • Compliance mapping for HIPAA-adjacent and legal-adjacent obligations
  • Security awareness training calibrated to the firm's actual threat model

AI Consulting

Most small businesses do not need their own AI model. They need honest guidance on where AI saves real time today, where it will quietly leak client data, and how to tell the difference. We help you adopt the parts that help and skip the parts that do not.

AI consulting that starts from "do you actually need this" rather than "here is the demo we want to sell you." Local LLMs where privacy matters, workflow automation where it does not, and an honest read on vendor lock-in and TCO.

Pragmatic AI adoption for privacy-sensitive small businesses. Local model deployment via Ollama or LM Studio for sensitive workloads. Hosted API integration (Claude, ChatGPT) for non-sensitive ones. Workflow automation via n8n. Honest TCO analysis, honest vendor lock-in analysis, honest privacy posture per workload.

Services included

  • An honest look at where AI helps your specific work and where it doesn't
  • Tooling set up locally when client data shouldn't leave your machines
  • Practical workflow automation for the repetitive parts of the day
  • Staff training that focuses on what actually works, not the hype
  • Plain-language risk review for HIPAA-adjacent or legal-adjacent work
  • Local LLM deployment (Ollama, LM Studio) for privacy-sensitive work
  • Workflow automation with Claude, ChatGPT, or n8n
  • Vendor selection and total cost of ownership analysis
  • HIPAA-adjacent AI risk review
  • Staff training on practical AI use
  • Privacy-first tooling recommendations
  • Local LLM deployment on client hardware (Ollama, LM Studio) for sensitive workloads
  • Hosted API integration (Claude, ChatGPT) for non-sensitive workloads with data-residency review
  • Workflow automation via n8n or equivalent, with documented runbooks
  • Vendor selection and total cost of ownership analysis across hosted and self-hosted options
  • HIPAA-adjacent AI risk review covering data residency, vendor terms, and audit posture
  • Staff training calibrated to the firm's actual workflows, not generic AI literacy
  • Privacy-first tooling recommendations with documented decision rationale

Digital Forensics & Investigations

Something happened and you need to know what. An account taken over, a device you don't trust, a situation heading for a lawyer or insurance claim. We examine the evidence, document it the way courts expect, and explain what we found in plain language.

When something has gone wrong and you need to know exactly what. Device forensics, compromised account investigation, timeline reconstruction with chain-of-custody discipline that holds up in litigation, insurance, or regulatory contexts. Businesses and individuals.

Forensic examination of devices, accounts, and digital trails with the methodology, documentation, and chain-of-custody discipline required for litigation, insurance, and regulatory contexts. Volatile and non-volatile acquisition. Timeline reconstruction. Root cause analysis with documented evidence-handling. Available to corporate clients and individuals.

Services included

  • A careful look at devices, accounts, or files when you need to know what actually happened
  • Step-by-step reconstruction of how an account or system was compromised
  • Documentation strong enough to hold up in court, insurance claims, or formal complaints
  • Help for individuals facing identity theft or account takeover, not just companies
  • Quiet, confidential handling regardless of who you are
  • Device forensics and evidence preservation
  • Compromised account investigation and access reconstruction
  • Incident timeline reconstruction and root cause analysis
  • Chain-of-custody documentation for legal proceedings
  • Litigation, insurance, and regulatory response support
  • Individual identity theft and account takeover investigations
  • Forensically sound acquisition (volatile memory, full-disk imaging, cloud-account data export) with documented chain of custody
  • Compromised account investigation across M365 and third-party SaaS, with access reconstruction
  • Incident timeline reconstruction and root cause analysis with documented evidence handling
  • Documentation and chain-of-custody records prepared for legal proceedings
  • Support for litigation, insurance claims, and regulatory response
  • Corporate internal investigations with HR and legal coordination
  • Individual identity theft and account-takeover investigations