Before you trust us with your systems.
The questions your auditor is going to ask.
You are about to give a technology provider access to everything. Here is how we secure our own side of that, what we run on, what we commit to — and, just as importantly, what we don't claim.
How we run our side of it
Concrete practices, not a security-sounding adjective list.
Security-first since 2013
Our roots are in cybersecurity, not in break-fix that later added a security line item. Every managed plan we sell is built on that foundation — 13+ years of it.
Multi-factor authentication, enforced
MFA is enforced on Microsoft 365 for the environments we manage. It is not an upsell and it is not optional — it is the single control that stops the most common attack we see.
Role-based, need-to-know access
Access is scoped to the role, and reviewed as staff join and leave. When someone leaves your business, they lose access the same day.
Backups that have actually been restored
We test restores rather than assuming them. An untested backup is the most common serious gap we find when we assess a new environment.
Monitoring on a managed platform
Endpoints, servers, and network devices are monitored continuously on Kaseya 365, with alerts routed to our team rather than to you.
Documentation you own
We document your environment and you keep a copy. Nothing critical lives only in one technician's head — including ours.
Our published response targets
Severity in plain language, with a number beside it.
P1You're down and nobody can work.
Critical outage — total business stop
First response30 minutes
Resolution goal2 hours
P2Something important is broken or crawling.
High impact — major degradation
First response1 hour
Resolution goal4 hours
P3One person needs something sorted.
Standard — individual request
First response2 hours
Resolution goal8 hours
Targets apply during business hours, Monday–Friday, 8:00am–5:00pm CT. Initial response is when a human has your ticket and has replied — not an autoresponder. Resolution goal is our target, not a guarantee; complex work sometimes runs longer, and we tell you when it will.
The phone is answered around the clock.
Call at 2am and a person picks up — not voicemail, not an offshore queue. We triage it on the spot.
- A genuine emergency gets a technician engaged that night. After-hours and emergency rates apply.
- Anything that can wait goes into the queue for the next business day, and you'll be told which it is.
- Round-the-clock coverage is available as an add-on for businesses that can't wait until morning — several of our clients run it.
What we don’t claim
Plenty of providers in our category imply certifications they don’t hold. If you’re comparing vendors, these are the questions worth asking all of us — including us.
- We do not hold SOC 2, ISO 27001, or a CMMC certification of our own. If a vendor tells you they are “CMMC certified”, ask which accredited C3PAO assessed them and when.
- We are not a compliance auditor. We help you meet HIPAA, PCI, and CMMC requirements your clients, regulators, or insurer impose — we do not certify you against them.
- Our published response targets are targets, not a contractual guarantee. We would rather tell you that plainly than hide it in a footnote.
The questions we get asked in procurement
Who has access to our systems, and how is it controlled?
Our technicians access your environment through our managed platform, scoped by role. Access is reviewed as our own staff change, and we can walk your auditor through the specific access model for your environment on a call.
What platform are you running our monitoring and backup on?
Kaseya 365 is our primary platform for endpoint monitoring, patching, endpoint protection, and managed backup. Microsoft 365, Defender, and Entra cover identity and mail where you run Microsoft.
What happens if we have an incident?
You get a documented set of containment steps written before an incident, not improvised during one, plus a P1 response target of 30 minutes during business hours. We will also help you complete the incident sections of a cyber-insurance questionnaire.
Can you help with our cyber-insurance questionnaire?
Yes — this is one of the most common things clients ask us for. We complete the technical sections with you and tell you honestly where your current posture will not pass.
Do you subcontract our support offshore?
No. Our team is local to Northeast Wisconsin — that is the whole point of hiring us rather than a national provider.
Question not answered here? Ask us directly — or see what a security engagement includes .
Bring us your security questionnaire.
If you're mid-procurement or renewing cyber insurance, send us the questionnaire. We'll tell you which sections your current setup passes and which it doesn't.
No obligation. No sales pressure. Just an honest conversation.